Start with two numbers: RTO and RPO
Set RTO and RPO per system, not for the whole business. A payments platform may need minutes; an archive may tolerate days. These two numbers drive every technical and cost decision that follows.
- Recovery Time Objective (RTO): how long a system can be down before the impact becomes unacceptable.
- Recovery Point Objective (RPO): how much data, measured in time, you can afford to lose — the gap between the last good backup and the failure.
The 3-2-1 backup rule
- 3 copies of your data (the original plus two backups).
- 2 different types of storage media.
- 1 copy kept off-site — ideally encrypted and isolated so ransomware cannot reach it.
Risks to plan for in Kenya
- Power outages and surges: UPS, generators and proper shutdown procedures protect hardware and data.
- Connectivity failures: redundant links from different providers for critical sites.
- Ransomware and cyber attacks: offline or immutable backups and a practised recovery plan.
- Hardware failure, theft, fire and flooding: off-site replicas and documented rebuild procedures.
- Human error: versioned backups that let you roll back accidental deletions.
Test it — or assume it does not work
A backup that has never been restored is a hope, not a plan. Schedule regular restore tests, run at least an annual failover exercise for critical systems, and record how long recovery actually took against your RTO.
A simple roadmap
- Carry out a risk assessment and business-impact analysis.
- Set RTO and RPO for each critical system.
- Design backup, replication and failover to meet them.
- Document the recovery runbook and assign responsibilities.
- Test, measure and improve every quarter.
How we help
Technology Abreast provides managed failover across servers and networks, real-time data replication, automated encrypted off-site backup, and a free infrastructure audit when implementing a disaster-recovery plan.

