Define, deliver, and embed an enterprise-wide capability to ensure timely, predictable recovery of critical business services following cyber, technology, or operational disruptions.
Requirements
- Define and execute the enterprise BCP / DR / Cyber Resilience strategy and multi-year roadmap in line with strategy
- Establish clear recovery governance, decision authority, and escalation models
- Serve as owner for BCP/DR/CR-related audit findings, remediation plans, and reporting
- Align continuity and recovery practices with enterprise risk appetite and regulatory expectations
- Design and implement business-service-based recovery orchestration, moving beyond application-centric DR
- Establish identity-first recovery sequencing across hybrid (on-prem, cloud, SaaS) environments
- Define and operationalize clean recovery / clean-room approaches for ransomware scenarios
- Lead enterprise Business Impact Analysis (BIA) standards, certification, and lifecycle management
- Ensure business services have defined, validated RTO/RPO targets
- Translate BIAs into executable recovery priorities and sequencing
- In conjunction with IT Security, design and execute cyber-inclusive recovery testing, including regional and country-level scenarios
- Lead executive and leadership recovery simulations focused on decision-making under stress
- Ensure testing outcomes drive funded remediation and continuous improvement
- Establish a central standards / regional execution operating model
- Partner with regional IT and business leaders to validate local recovery readiness
- Assess and validate third-party and vendor recovery dependencies that could impact regional operations
- Define and maintain enterprise and regional recovery metrics, including: Immutable backup coverage, BIA certification, Validated RTO achievement, Recovery testing completion, Orchestration playbook readiness
