Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

ResOps and cyber resilience: what governance gap are teams missing?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15374
Topic starter  

TL;DR: IDC’s latest ResOps research argues that cyber resilience breaks down less because of technical fragmentation than because security, infrastructure, IT, and business teams do not share recovery decisions before an incident, according to Commvault. The practical lesson is that resilience depends on operating model alignment, not just faster tooling or better backup technology.

NHIMG editorial — based on content published by Commvault: ResOps, resilience operations and the discipline that makes readiness provable

Questions worth separating out

Q: What breaks when cyber resilience planning stays inside separate teams?

A: Recovery slows when security, infrastructure, legal, communications, and business leaders each optimise for different outcomes without a shared decision model.

Q: Why do identity and privileged access controls matter in resilience planning?

A: Because recovery depends on who can approve failover, access critical systems, and execute restoration when the normal operating model is disrupted.

Q: How do organisations know whether resilience controls are actually working?

A: They know by testing under failure conditions, not by checking configuration alone.

Practitioner guidance

  • Define recovery decision rights Assign who can approve service restoration order, risk exceptions, and emergency access when an incident crosses security, infrastructure, and business functions.
  • Build a minimum viable business map Translate critical business outcomes into the applications, identities, data flows, and privileged access paths required to keep them operating.
  • Test cross-functional recovery drills Run scenarios that force security, IT, legal, communications, and business owners to make live prioritisation decisions under time pressure.

What's in the full article

Commvault's full article covers the operational detail this post intentionally leaves for the source:

  • How ResOps defines minimum viable business and turns it into recovery prioritisation guidance
  • The cross-functional decision model for security, infrastructure, legal, and business leaders during an incident
  • The article's explanation of why technology automation cannot replace governance and shared accountability
  • The full resilience framing used by Commvault Field CTO Vidya Shankaran

👉 Read Commvault's analysis of ResOps and cyber resilience governance →

ResOps and cyber resilience: what governance gap are teams missing?

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14958
 

Shared recovery authority is now a core resilience control. The article’s central contribution is that recovery fails when no one has pre-agreed authority over prioritisation, exceptions, and risk acceptance. That makes resilience a governance problem before it is a tooling problem. For identity-led programmes, the same issue appears in emergency access and privileged recovery paths. Practitioners should treat recovery authority as part of operational control design.

A question worth separating out:

Q: Who is accountable when recovery decisions affect customers, operations, and compliance at the same time?

A: Accountability should sit with the governance structure that pre-defines recovery authority, not with whichever team is most visible during the incident. In practice, that means leadership must assign decision rights for prioritisation, exception approval, and reporting before an event occurs. Frameworks that emphasise control ownership and operational resilience reinforce that approach.

👉 Read our full editorial: ResOps shows resilience fails when security and business stay siloed



   
ReplyQuote
Share: