Part 2: IT Disaster Recovery in a Saas World: Building Practical IT Disaster Recovery Capabilities in a SaaS World
Introduction
![x [MTE] [Presentation Summary] [Part 2] David Tay](https://no-cache.hubspot.com/cta/default/3893111/b37ba35a-7f07-4aed-803b-74638154d0f7.png)
As organisations become increasingly dependent on SaaS providers, IT Disaster Recovery professionals face a different challenge: how can recovery readiness be demonstrated when the organisation cannot directly control or test the provider's infrastructure?
Building on the first part of the webinar, David Tay discussed practical approaches involving vendor assurance, recovery exercises, contractual reviews, and business continuity arrangements.
Managing SaaS Provider Recovery Capabilities
David explained that organisations must begin by understanding their own business requirements before evaluating vendor recovery commitments.
This includes reviewing BIA findings, RTOs, RPOs, and business continuity requirements.
Where a provider's recovery capability does not meet the organisation's needs, the organisation should identify the gap and consider remediation or alternative arrangements.
Using Third-Party Assurance Effectively
Organisations commonly rely on independent assurance reports, including SOC 2 reports and ISO 27001 certifications, when assessing SaaS providers.
However, David cautioned that obtaining an assurance report does not automatically demonstrate that all customer responsibilities have been fulfilled.
He specifically highlighted complementary user entity controls, which identify controls that customers themselves must implement.
Multi-factor authentication (MFA) was discussed as an example of a customer-managed security responsibility.
Testing IT Disaster Recovery Without Controlling the Infrastructure
Traditional IT DR exercises often involve switching operations to an alternate infrastructure or performing live recovery activities.
These approaches are more difficult when the affected application is managed entirely by a SaaS provider.
David described the use of Tabletop Exercises (TTXs), also referred to as Game Day Simulations, as a practical alternative.
These exercises bring business users, technology teams, and relevant vendors together to discuss disruption scenarios, assess response arrangements, and identify weaknesses in business continuity capabilities.
Planning for Prolonged SaaS Outages
A key issue is determining what happens when a provider cannot restore its service within the organisation's required recovery timeframe.
Even where a provider operates across multiple regions, organisations should not assume that all disruptions can be resolved through automatic failover.
David highlighted the possibility of regional failures, shared technical dependencies and failover problems.
Consequently, organisations must develop contingency arrangements for situations where SaaS applications remain unavailable.
Integrating Incident, Crisis, and Business Continuity Management
A prolonged SaaS disruption may require more than an IT response.
Incident management, crisis management, and business continuity teams may need to coordinate decisions and communicate with affected business functions.
David stressed the importance of involving executive leadership, steering committees, business application owners, and cloud providers in developing a holistic recovery approach.
Applying the Three Ps: Process, People, and Platform
David concluded his presentation by emphasising three interconnected elements:

His message was that technology platforms should support defined business processes and the people responsible for operating them.
Recovery solutions should be designed to address genuine business requirements, rather than introducing technology without a clear operational purpose.
Effective IT Disaster Recovery in a SaaS world depends on the organisation's ability to manage dependencies, validate recovery assumptions, and maintain business operations when providers fail.
Vendor assurance, contractual SLAs, and technical resilience are important, but they must be complemented by business-led recovery exercises, contingency procedures, clear governance, and coordinated incident management.
A successful recovery strategy integrates Process, People, and Platform.
This is Part 2 of the two-part summary of David Tay's presentation during BCM Institute's Meet-the-Expert webinar.
The webinar is summarised by Dr Goh Moh Heng, President of the BCM Institute.
Dr Goh Moh Heng, President of BCM Institute, summarises this webinar. If you have any questions, please speak to the author.
For Parts 1 & 2 ...
Click the icon below to continue reading parts of David Tay's presentation.






![x [MTE] [Presentation Summary] [Part 1] David Tay](https://no-cache.hubspot.com/cta/default/3893111/f82876be-095f-4222-862e-1b5cdf7ebfea.png)
![x [MTE] [Lesson Learned] David Tay](https://no-cache.hubspot.com/cta/default/3893111/d74f116e-252a-405f-bd93-29298894b8f8.png)







![Email to Sales Team [BCM Institute]](https://no-cache.hubspot.com/cta/default/3893111/3c53daeb-2836-4843-b0e0-645baee2ab9e.png)
![FAQ [BL-DR] [5] DRP-5000](https://no-cache.hubspot.com/cta/default/3893111/e1e30273-3d46-4a5b-9f9d-11d9457a377a.png)

