Briefing

Why recovery targets fail without dependency evidence

Connect impact, systems, suppliers, and workforce assumptions before accepting a recovery target.

RESILIVANCE · Educational guide · 1 min read

A target is not proof

A recovery time objective describes how quickly an activity needs to resume. It does not establish that people, systems, facilities, suppliers, and decision makers can deliver that recovery. Treat the target as a requirement to test.

Start with the operation

Name the service, its minimum acceptable output, and the impact of its loss over time. Identify the owner who can explain those impacts and approve priorities. Connect technology dependencies to that business outcome.

Trace dependencies

Record the people, data, applications, equipment, facilities, utilities, external providers, and decision authority needed for minimum service. For each, name an owner, expected availability, evidence, and workaround. An unverified supplier promise remains an assumption.

Separate requirement from capability

Required recovery comes from business impact. Feasible recovery comes from resources and arrangements available. Demonstrated recovery comes from exercises or incidents under stated conditions. A test with extra staff or preloaded data does not prove the same result during an unplanned disruption.

Make the decision visible

Document each gap, its impact, options, accountable owner, and next validation date. Management can strengthen a dependency, test a workaround, revise a commitment, or accept a residual risk explicitly. Revisit decisions when operations change.

General educational guidance. Recommendations depend on your organization’s circumstances.