A backup retention policy answers three questions: how far back can we go, how many copies do we keep, and how often is one taken. Backup retention is the first; backup retention best practices, backup retention policy best practice and backup retention policy best practices are the trade's three ways of asking for the numbers; and RPO cybersecurity, the recovery point objective, is the third question turned round: how much work the organisation agrees to lose, which is the gap between the last backup and the failure. For the owner or office manager who has been handed security, the numbers are a policy in the written set, and the free policy sheet on this site sizes that set from the organisation's own facts with no account.
The three numbers
How far back: long enough to restore from before a problem that went unnoticed for weeks, which is why ransomware makes short retention dangerous. How many: at least one copy off the site and off the network, because a backup the attacker can reach is not a backup. How often: at least daily for the systems the organisation cannot rebuild by hand, which is where the recovery point comes from.
RPO, in plain words
If backups run nightly, the organisation agrees to lose up to a day's work; if hourly, up to an hour. The recovery point objective is that agreement written down, and the policy says which systems get which. CISA's small-business guidance names backup among the basic controls; the policy is what makes it a decision rather than a default.
The policy in the set
Backup is one of the six core policies every organisation's set carries, beside acceptable use, sign-in, data handling, incident response and access. The policy sheet on this site sizes the set: 12 people, 8 systems with their own login, remote work, card payments and personal devices is a set of nine policies, 27 hours to draft, 13.5 hours a year to keep reviewed and $1,822.50 in the first year at $45 an hour. Hardenvo Pro generates the backup policy with the organisation's three numbers in it and keeps it current at one flat price.
Questions people ask about backup retention policy
What should a backup retention policy say?
How far back the organisation can go, how many copies it keeps and where, and how often one is taken; and which systems get which.
What is RPO in cybersecurity?
The recovery point objective: how much work the organisation agrees to lose between the last backup and a failure; nightly backups mean up to a day.
Is the backup policy part of the set?
Yes, one of the six core policies; the free policy sheet sizes the set and Hardenvo Pro writes the policy with your numbers.