Identifying recovery metrics
A recovery metric is a measurable target (e.g., maximum downtime, restoration time, or acceptable data loss) that defines how quickly and completely a business capability must be restored after a cybersecurity incident. The Incident Response Plan (IRP) module helps you catalog these recovery metrics, which will be included in your exported IRP.
Note that Aurora can help you identify your recovery metrics. Give her a shot!
To add a recovery metric:
- Log in to Totem.
- Navigate to the Incident Response Plan module.

- Select Create Metric. You’ll be presented with multiple input fields; these are for describing the core business capability and its recovery metrics.

- Using the guidance below, populate the business capability and each recovery metric:
- Business Capability: Provide the name of the core business service that requires protection. In other words, if XYZ capability were disrupted, it would result in significant loss or damage to the business. These should directly reflect the core capabilities of the business and any other related/supporting capabilities.
- Examples: Shipping, process customer orders payroll, product testing, CUI file collaboration, production scheduling
- Maximum Tolerable Downtime (MTD): Set the absolute maximum outage period the business can endure before the impact is unacceptable.
- Example: 24 hours; beyond this, missed production commitments become unacceptable.
- Recovery Time Objective (RTO): Set the target time to restore and validate the capability after a disruption. It should be no longer than the MTD.
- Example: 8 hours; restore the scheduling system and confirm users can create work orders within one business shift.
- Recovery Point Objective (RPO): Set the maximum acceptable data loss, measured in time; this drives backup or replication frequency.
- Example: 4 hours; recovery must include data no older than four hours before the outage.
- Backup length storage: Define how long restore points remain available, accounting for operational recovery, investigations, CUI obligations, contractual needs, and ransomware resilience.
- Note: For Department of War contractors, DFARS 252.204-7012 has specific requirements for this!
- Example: 90 days online plus 12 monthly immutable archive copies
- Business Capability: Provide the name of the core business service that requires protection. In other words, if XYZ capability were disrupted, it would result in significant loss or damage to the business. These should directly reflect the core capabilities of the business and any other related/supporting capabilities.
- Once complete, select Create Metric. Your recovery metric will now appear in the table. Continue populating metrics for any other key business capabilities.

