Let's talk

What Does a Disaster Recovery Governance Lead Do — and Why Can’t Organisations Do Without One?

Placeholder image

A disaster recovery governance lead is the person who makes sure an organisation can actually recover its IT systems after a serious failure — not in theory, but with tested plans, current evidence and a clear owner for every gap. They don’t usually restore servers themselves. They make sure the people who do have a plan that works, have rehearsed it recently, and can prove both to auditors, regulators and the board.

It is one of the least visible roles in IT. It is also one of the few that regulators across Europe now effectively require.


Why has disaster recovery become a board-level issue?

Because the failures stopped being hypothetical, and the law caught up. Two events reshaped how European organisations think about recovery, and three pieces of EU legislation turned that thinking into obligations.

The incidents

On 10 March 2021, a fire destroyed one of OVHcloud’s data centres in Strasbourg. Customers who had assumed “the cloud” meant their data lived somewhere safe discovered that, in some cases, their only backups had been in the same building.

On 19 July 2024, a faulty content update to CrowdStrike’s Falcon security software crashed Windows machines worldwide. Microsoft estimated that around 8.5 million devices were affected. Airlines grounded flights, hospitals postponed procedures, broadcasters went off air. Nothing was hacked. A routine update simply went wrong — and recovery depended entirely on how well each organisation had planned for losing its own endpoints at once.

The lesson from both was the same: the organisations that recovered fastest were not the ones with the biggest budgets, but the ones that had rehearsed.

The regulation

  • DORA (Regulation (EU) 2022/2554), applicable since 17 January 2025, requires financial entities to maintain ICT business continuity policies and response and recovery plans — and to test them.
  • NIS2 (Directive (EU) 2022/2555) lists business continuity, “such as backup management and disaster recovery, and crisis management”, among the minimum cybersecurity risk-management measures for essential and important entities across 18 sectors.
  • Regulation (EU, Euratom) 2023/2841, in force since January 2024, sets a common level of cybersecurity for the EU’s own institutions, bodies, offices and agencies.

None of these laws accept “we have a plan” as an answer. They ask whether the plan is tested, maintained and owned.

💡 Key takeaway: Regulators no longer ask whether you have a disaster recovery plan. They ask you to demonstrate that it works. Demonstrating it is a full-time job.


How is DR governance different from DR engineering?

DR engineers build and execute recovery; a DR governance lead makes sure recovery is planned, tested, evidenced and improved across the whole organisation. One is the firefighting crew, the other runs the fire-safety programme for the entire building.

DR engineer / infrastructure specialistDR governance lead
Core question“Can I restore this system?”“Can we prove every critical service can be restored within its targets?”
FocusReplication, backups, failover, runbooksPlan lifecycle, test calendar, evidence, remediation, reporting
ScopeOne platform or serviceAll in-scope services and their dependencies
Works withTechnical teamsTechnical teams, Business Continuity Management, risk, audit, leadership
OutputA working recoveryA defensible, auditable state of readiness
Typical backgroundInfrastructure, cloud, storage, networkingIT operations, service management, resilience, BCM

In small organisations, one person often does both. Above a certain size — or under regulatory scrutiny — that stops working, because the engineer is too busy fixing things to maintain the paperwork that proves they were fixed.


What does a DR governance lead do day to day?

They run the recovery programme as a continuous cycle: define plans, test them, track what failed, fix it, and report readiness. The work is coordination-heavy and evidence-driven.

A typical cycle covers:

  • Plan definition and upkeep. Every in-scope service needs a recovery plan with agreed recovery time objectives (RTO — how long it may be down) and recovery point objectives (RPO — how much data it may lose). Plans go stale whenever architecture changes, so keeping them current is ongoing work.
  • Test scheduling and coordination. Recovery tests involve several teams, maintenance windows and sometimes production risk. Someone has to orchestrate them.
  • Evidence management. If a test isn’t documented, from an audit perspective it didn’t happen. The governance lead keeps evidence complete and retrievable.
  • Remediation tracking. Tests fail — that is their purpose. The value lies in making sure every failure becomes an owned, dated action that actually gets closed.
  • Readiness reporting. Dashboards that show leadership, honestly, which services are recoverable and which are not.
  • Stakeholder liaison. Acting as the bridge between technical teams and the Business Continuity Management function, which looks at the organisation as a whole rather than at systems.

A real example

At Optiveum we are currently recruiting a DR Governance Program Lead for an EU agency project in Warsaw, delivered through an IT consulting partner for an agency working in international security and border management. The role sits in the agency’s Data Centre Services team, and its scope reads like a textbook description of the function: coordinating the ICT DR workstream, maintaining DR plans for all in-scope services, running testing cycles and remediation tracking, managing readiness dashboards and evidence, and acting as the focal point towards BCM.

It is a useful illustration of where these roles now sit: not in a back office, but at the centre of an institution whose systems simply cannot be allowed to stay down.

💡 Key takeaway: The governance lead’s real product is not a document. It is confidence — backed by evidence — that the organisation knows what will happen when something breaks.


Which skills and certifications matter for DR governance roles?

The strongest candidates combine solid IT operations experience with formal business continuity training and the temperament of a programme manager. Certifications matter more here than in most IT roles, because the job is partly about speaking the language of auditors and standards.

Experience

Employers typically look for around five years in IT operations, infrastructure coordination or service governance, with at least three focused specifically on disaster recovery, business continuity or resilience. The operations background matters: a governance lead who has never sat through a real outage tends to write plans that look good and fail in practice.

Certifications commonly requested

  • ITIL 4 Foundation — the shared vocabulary of IT service management, including service continuity.
  • CBCI (Business Continuity Institute) — a widely recognised business continuity credential.
  • ABCP / CBCP (DRI International) — disaster recovery and business continuity certifications, common in regulated industries.
  • ISO 22301 Lead Implementer — the international standard for business continuity management systems.

The less obvious skills

  • Influence without authority. The governance lead rarely manages the engineers whose time they need. They have to persuade.
  • Comfort with uncomfortable truths. A readiness dashboard that is all green is usually wrong. Good governance leads report the red honestly.
  • Structured persistence. Remediation tracking is unglamorous. Closing the twentieth action item matters as much as the first.
  • Security clearance eligibility. In public-sector and defence-adjacent environments, candidates must be willing and eligible to undergo personal security clearance.

Why are DR governance leads so hard to hire?

Because the profile sits between three career paths — infrastructure, service management and business continuity — and very few people deliberately build a career at that intersection. Most arrive there by accident, after living through an incident and becoming the person who “sorted out DR afterwards”.

That creates several hiring challenges:

  • Small talent pool. Engineers move towards architecture; BCM professionals often come from risk and compliance rather than IT. The people who genuinely understand both are scarce.
  • Demand arriving all at once. DORA, NIS2 and Regulation 2023/2841 hit financial services, critical infrastructure and EU institutions within the same few years, so many organisations started looking for the same people at the same time.
  • Hard filters. Mandatory certifications, specific years of DR experience and clearance requirements quickly narrow a shortlist to a handful of names.
  • Job titles that hide the profile. The right candidate may currently be called a service continuity manager, resilience coordinator, IT risk analyst or infrastructure operations lead. Keyword searches miss them.

What we have observed at Optiveum is that relatively few candidates tick all the boxes. Many of them don’t have all the certificates needed. On the other hand, it is understandable that for such crucial roles, the clients need to hire candidates who are very well prepared. Let alone, in the government related organisations.

💡 Key takeaway: You rarely find a DR governance lead by searching for the title. You find them by recognising the career path — operations people who became the ones everyone calls when recovery matters.


Where do organisations find DR governance talent in CEE?

Increasingly, in Central and Eastern Europe. Poland in particular hosts a large concentration of shared-service centres, banking operations and EU institutions — exactly the environments where people build hands-on resilience experience under regulatory pressure. Many of these professionals already work in English and in international teams, and many operate on B2B contracts suited to long-term project engagements.

At Optiveum, resilience and service-governance profiles are part of the specialist IT market we recruit in every day. If you are building or strengthening a DR function — whether to meet DORA or NIS2 obligations or simply because your last test didn’t go as planned — it is worth talking to someone who knows where these people currently sit. You can read more about our approach to IT recruitment in Poland.

📍 Building a resilience or DR team? Book a 30-minute conversation with Marek Wróbel to discuss the profile you need and what the CEE market currently looks like for it.


Frequently Asked Questions:

What is the difference between disaster recovery and business continuity?

Business continuity is about keeping the whole organisation operating during a disruption — people, processes, suppliers and premises. Disaster recovery is the IT part of that: restoring systems and data. A DR governance lead connects the two by ensuring IT recovery plans support business continuity priorities.

Is a DR governance lead a technical role?

Partly. The role needs enough technical depth to understand recovery architectures, judge whether a plan is realistic and talk credibly with engineers. But the day-to-day work is mainly coordination, testing oversight, evidence management and reporting.

Do DORA and NIS2 require a dedicated DR governance lead?

Neither regulation names a specific job title. Both require tested, maintained recovery and continuity arrangements. In practice, larger organisations find it difficult to meet those obligations without someone owning the DR programme full-time.

What are RTO and RPO?

The recovery time objective (RTO) is the maximum acceptable time a service can be unavailable. The recovery point objective (RPO) is the maximum acceptable amount of data loss, measured in time. Both are agreed with the business and are the targets every DR test is measured against.

Which certifications should a DR governance lead hold?

Common requirements are ITIL 4 Foundation plus at least one recognised continuity or recovery credential, such as CBCI from the Business Continuity Institute, ABCP or CBCP from DRI International, or ISO 22301 Lead Implementer.


Read also


Data sources

  • Regulation (EU) 2022/2554 on digital operational resilience for the financial sector (DORA) — EUR-Lex.
  • Directive (EU) 2022/2555 (NIS2), Article 21 — EUR-Lex.
  • Regulation (EU, Euratom) 2023/2841 laying down measures for a high common level of cybersecurity at the institutions, bodies, offices and agencies of the Union — EUR-Lex.
  • Microsoft, “Helping our customers through the CrowdStrike outage”, Microsoft Official Blog, July 2024 (estimate of 8.5 million affected devices).
  • OVHcloud public statements on the SBG2 data centre fire, Strasbourg, March 2021.
  • ISO 22301:2019 Security and resilience — Business continuity management systems — ISO.
  • Role scope: Optiveum, DR Governance Program Lead (EU Agency Project) job description, October 2026.