
IT Disaster Recovery in a SaaS World

Webinar with David Tay, Chief Information Officer, Lendlease Asia Holdings
Introduction
This session will be presented by David Tay, Chief Information Officer – Asia at Lendlease Asia Holdings.
David brings extensive senior technology leadership experience across enterprise IT, infrastructure, managed services, cloud transformation and disaster recovery.
At Lendlease, he leads technology teams across Singapore, Malaysia, China and Japan, supporting the organisation through globalised and standardised technology platforms and solutions.
His earlier experience includes ERP transformation and cloud migration, managed services, data centre infrastructure, business continuity and disaster recovery services. He is also a Disaster Recovery Certified Expert (DRCE) awarded by BCM Institute.
Drawing on this combination of strategic CIO leadership and hands-on technology experience, David will examine a question increasingly confronting organisations:
What does IT Disaster Recovery really mean when many of the applications your business depends upon are no longer hosted, operated or fully controlled by your organisation?
Webinar Synopsis: IT Disaster Recovery in a SaaS World
Traditional IT Disaster Recovery was built around a relatively straightforward assumption: an organisation owned or controlled its applications, infrastructure, data and recovery environment.
If the primary environment failed, IT teams could invoke predefined recovery arrangements—restore systems from backups, activate alternate infrastructure, switch to a secondary data centre or recover applications according to established Recovery Time Objectives (RTOs) and Recovery Point Objectives (RPOs).
The growth of SaaS challenges this traditional model.
Today, many critical business processes depend upon applications delivered by external cloud and SaaS providers. The underlying infrastructure, application architecture, replication mechanisms, backup arrangements and recovery processes may largely sit outside the customer's direct control.
Yet the business impact of an outage remains with the organisation.
This creates an important distinction between service availability promised by a SaaS provider and recoverability required by the customer.
An organisation may have a highly available SaaS solution, but what happens when the provider suffers a prolonged outage? What happens if data is corrupted or accidentally deleted? What if an identity provider becomes unavailable and users cannot authenticate? What if an integration fails even though the SaaS platform itself remains operational? And what happens when the provider's recovery capability does not align with the organisation's business recovery requirements?
The webinar will explore how organisations should rethink IT Disaster Recovery when critical applications operate across a complex ecosystem of SaaS providers, cloud platforms, identity services, telecommunications, APIs, integrations and other third parties.
Why This Webinar Matters
Moving applications to SaaS does not eliminate disaster recovery risk. It changes the nature of the risk and redistributes responsibility.
One of the dangers is assuming that because a SaaS provider manages the technology platform, the provider also manages the organisation's disaster recovery requirements.
The reality can be considerably more complex.
The provider may be responsible for recovering its platform, but the customer must still understand whether that recovery capability supports its own critical business operations. Organisations must therefore look beyond conventional infrastructure recovery and consider the entire chain required to deliver the business service.
This means asking different questions.
Where is critical data stored and how can it be recovered? Who owns the backup? Can the organisation independently extract or restore its information? What dependencies exist on identity, connectivity and integrations? What recovery commitments are actually contained in the contract? What happens if the provider's recovery priorities differ from yours?
Most importantly:
Can your organisation continue operating when a critical SaaS application becomes unavailable for longer than expected?
The answers increasingly determine whether an organisation has genuine IT resilience—or simply confidence in its suppliers.
Key Discussion Points
During the webinar, David Tay will explore practical considerations surrounding IT Disaster Recovery in an increasingly SaaS-dependent technology environment, including:
- How SaaS changes traditional IT Disaster Recovery — understanding the transition from recovering infrastructure and applications directly to managing resilience across externally operated services.
- The shared-responsibility challenge — identifying what the SaaS provider is responsible for and what remains the responsibility of the customer.
- Availability versus recoverability — understanding why a provider's uptime commitment or Service Level Agreement does not necessarily constitute a complete disaster recovery strategy.
- RTO and RPO in a SaaS environment — determining whether provider recovery capabilities align with the organisation's business recovery requirements.
- Data protection and recovery — examining backup, retention, restoration, data portability and the organisation's ability to recover critical information.
- Hidden dependencies — recognising the role of identity services, APIs, integrations, networks, cloud platforms and other third parties in end-to-end recovery.
- SaaS provider concentration and dependency risk — considering what happens when multiple critical business processes rely on the same provider or technology ecosystem.
- Third-party assurance — understanding what organisations should evaluate when reviewing the resilience and disaster recovery capabilities of SaaS providers.
- Testing SaaS recovery assumptions — moving beyond reviewing provider documentation to testing realistic disruption scenarios and business workarounds.
- Planning for prolonged SaaS outages — identifying alternative processes, contingency arrangements and recovery strategies when the organisation cannot directly restore the affected application.
- Exit and portability considerations — considering how organisations could access their data and maintain critical operations if a SaaS relationship becomes unavailable or unsustainable.
- The evolving role of the IT DR professional — shifting from predominantly technical recovery planning towards managing end-to-end technology resilience across internal and external ecosystems.
Who Should Attend?
This webinar will be particularly relevant to professionals responsible for ensuring that critical technology-enabled business services remain available or recoverable during disruption, including:
CIOs, CTOs and Technology Leaders seeking to understand how increasing SaaS adoption changes organisational accountability for technology resilience.
IT Disaster Recovery and Technology Resilience Professionals responsible for developing, maintaining and testing recovery strategies in hybrid, cloud and SaaS environments.
Business Continuity and Operational Resilience Professionals who need to understand how SaaS dependencies affect the continuity of critical business services and operations.
Cloud, Infrastructure and Enterprise Architecture Professionals involved in designing technology environments where services span internal infrastructure, cloud platforms and third-party applications.
Cybersecurity Professionals concerned with technology recovery following cyber incidents, data corruption, credential compromise or loss of access to critical SaaS platforms.
Third-Party Risk and Vendor Management Professionals responsible for evaluating the resilience, contractual commitments and recovery capabilities of technology service providers.
Operational Risk and Enterprise Risk Professionals overseeing technology dependency, concentration risk and operational resilience.
Internal Audit and Assurance Professionals responsible for assessing whether IT Disaster Recovery arrangements remain adequate as organisations transition from internally managed applications to externally delivered services.
The Question Has Changed
For many years, IT Disaster Recovery planning centred on the question:
"How quickly can we recover our systems?"
In a SaaS world, organisations may need to ask something broader:
"How will we continue delivering critical business services when the technology we depend upon is operated by someone else?"
Join David Tay, Chief Information Officer – Asia, Lendlease Asia Holdings, on 24 September 2026 for this BCM Institute Meet-the-Expert session as we explore how IT Disaster Recovery must evolve in a world increasingly dependent on SaaS.
The technology may have moved to the cloud.
The accountability for resilience has not.
Join us by registering today.





