Backup Policy Template

A ready-to-adapt enterprise backup policy covering scope, RPO/RTO, retention, and testing.

1. Scope

This policy applies to all production systems, databases, and business-critical file shares owned or operated by the organisation, including virtualized and cloud-hosted workloads.

2. Objectives (RPO / RTO)

Each workload is assigned a tier with a defined RPO and RTO. Tier 1 (mission-critical): RPO ≤ 15 min, RTO ≤ 1 hr. Tier 2 (important): RPO ≤ 4 hr, RTO ≤ 8 hr. Tier 3 (standard): RPO ≤ 24 hr, RTO ≤ 48 hr.

3. Method & retention

  • Follow the 3-2-1-1-0 rule for every Tier 1 and Tier 2 workload.
  • Daily incremental and weekly full backups, retained per regulatory minimums.
  • At least one immutable / off-site copy resistant to ransomware.

4. Testing & governance

Restores are tested on a defined schedule (at minimum quarterly for Tier 1). Test outcomes are documented and reviewed by IT leadership. A failed or skipped test is treated as an incident.

Mapping this to your own estate?

Book a free discovery call →See the services