In today’s bulletin, Charlie gives an interesting insight into his rule when working out an organisations’ recovery time objective (RTO) and shows how this can be used in our own organisations.
This week, I am continuing my theme of the last few bulletins by going back to basics and writing about some of the building blocks of business continuity. This time, I am discussing how to determine your RTO.
I want to introduce, or reintroduce for those who have had me as a CBCI trainer, the concept of ‘Charlie’s Rule of Thirds’. I first wrote about this rule in a bulletin around ten years ago. It was published on Continuity Central, which at the time was one of the key websites for publishing articles and ideas about business continuity. Unfortunately, the website has fallen into abeyance and is no longer being hosted or updated, so this week I thought I would rewrite my ‘rule’ and introduce it to a new audience.
For a long time, I have tried to find a ‘rule’ or guidance that determines the relationship between the maximum tolerable period of disruption (MTPD) and the RTO. However, I have not found anything that clearly defines the relationship between the two. The Good Practice Guidelines (GPG) states that ‘The RTO should always be less than the MTPD’, but provide no further guidance on how the two should relate. It is therefore up to the person conducting the business impact analysis (BIA) to decide where the RTO should be set.
This is a real-world issue. When you go around an organisation, it is usually not too difficult to get each part of the organisation to agree its MTPD using impact criteria determined by top management. This was the subject of my bulletin on 28 August 2026, How to Define Your Maximum Tolerable Period of Disruption 2.0.
The issue is then how to determine the RTO. Some parts of the organisation may see their RTO as a measure of their importance. The lower the RTO, the more important they may believe they, and their part of the organisation, are. In very hierarchical organisations, or those where there is a lot of competition between managers, this can become an issue. If you are a middle manager within the organisation or an external consultant, it can be difficult to tell a HR manager who likes to compete with their peers that their RTO is three weeks, when their peers have RTOs of one, two, or three days.
To avoid getting into an argument, I have always wanted a rule that, when applied, determines the RTO in relation to the MTPD. When you discuss and agree the RTO, it is then based on a recognised ‘rule’, rather than a random time that might have been chosen for reasons other than business continuity good practice and the experience of the person conducting the BIA.
I have not yet discovered anyone else who has such a rule, apart from using good common sense, so I thought I would invent one myself. Like all good rules, it is simple, easy to apply, and makes good business continuity sense.
At its most basic level, the rule works as follows:
- You work with the part of the organisation undergoing the BIA, whether this is an activity, process, product or service BIA, and determine its MTPD. This could be a single time, for example, Activity A has an MTPD of one month. Alternatively, it could be a bracketed period, such as one to three months, as I discussed in my bulletin on determining your MTPD.
- You then take the time between zero and the MTPD of one month, or the lowest point of the bracketed MTPD, which in this example is also one month, and divide it into three time bands.
- The first time band would be 0 to 10 days, the second 10 to 20 days, and the third 20 days to the end of the month.
- Applying this rule, the RTO falls within the middle third, between 10 and 20 days. I give the activity owner the choice of where they want their RTO to fall, so they have some say in the matter, but it must remain within the middle-third timeframe.
- The reason we do not place the RTO within the first time band is that, usually, the shorter the RTO, the more preparation and cost are required to achieve it. You therefore want to avoid having lots of short RTOs for parts of the organisation that do not require them.
- The RTO should also not fall within the final time band. It would be too close to the MTPD, and any delay in achieving recovery could quickly take the disruption close to, or beyond, the MTPD, which you want to avoid.
Figure 1 gives an overview of the rule.

Like all good rules, this one is simple to apply and makes good business continuity sense. If there is a strong argument for setting the RTO outside the middle third, you may need to revisit the MTPD and check whether it should be changed. By giving the activity owner a choice about where the RTO falls within the middle third, you also give them some control over their business continuity recovery arrangements, but within an agreed framework.



