Insights at a Glance
The document addresses the expanding role of chief information security officers (CISOs), who are increasingly asked to oversee business continuity and disaster recovery (BC/DR) in addition to traditional cyber resilience activities.
It is often tempting for organizations to ask the CISO to take on more responsibility outside their traditional cyber resilience remit. While that is appropriate in some circumstances, it may not always be the most effective approach. Organizations must be careful to ensure that accountability and responsibility lie in those parts of the organization where the most effective outcomes will be achieved. However, someone needs to have the vision to lead that discussion. The CISO who is being asked to take on a greater role is the ideal person to do this.
Recommendations for Action:
Communicate your vision for cyber resilience across the enterprise.
Propose alternative owners that are better suited to own noncybersecurity activities.
Be clear on decision authority and procedural roles among stakeholders.
Build a RASCI to formalize responsibilities.
Issue Context
81% of cybersecurity leaders have reported that their cyber resilience remit has expanded drastically in the past two years. More than a third are accountable for disaster recovery-related activities, while another third are leading or owning BCM-related activities (see Figure 1).1
Figure 1: Involvement of CISO in BCM/DR-related Resilience Activities

The reasons for the expansion are the increasing number of cybersecurity incidents (according to 28% of respondents).1 However, an increased focus on cyber risk doesn’t mean that you should be accountable for resolving business continuity situations that may require levels of authority or expertise that you do not have.
The middle of the storm is the wrong time to discover that you lack the control or the resources that you need to respond to an incident. This situation is a recipe for disaster, both for your organization and for your career.
Impact Brief
Accepting additional responsibility without matching resources and authority is a recipe for failure that will impact your mission and your professional reputation when things go wrong.
When CISOs fail to draw boundaries around their contribution to cyber resilience, there are several cascading effects, including:
Organizationwide recovery does not reflect actual business needs: When RTOs are decided by IT or cybersecurity, the priorities agreed may not reflect what the business truly requires. This leads to an inefficient allocation of resources, with either too much or too little investment in resilience for specific business processes.
Overstretched resources: Adding to the CISO’s mandate without expanding resources accordingly results in teams that do everything less effectively.
Worse cyber resilience: Gartner’s cybersecurity controls assessment reveals that cybersecurity teams already lag in response and recovery capabilities. Adding new responsibilities to the CISO’s remit will only make this situation worse.3
More Detail
New responsibilities in business continuity and disaster recovery-related activities are drastically expanding the traditional cyber resilience remit (see Figure 2).
Figure 2: The Cyber Resilience Remit Is Expanding

All these new responsibilities risk derailing cybersecurity priorities, and you must protect your time and resources. To do so, you must advocate against:
Owning business continuity management fully (including leading the BCM program and function)
Leading business impact assessments (BIAs) that are not within the cybersecurity function
Owning enterprise-level IT disaster recovery
The key to avoiding a confused and potentially catastrophic response is to have clarity on who should make decisions and who can be most effective in the operational response. See the recommendations below for guidance on how to navigate these conversations.
Communicate Your Vision for Cyber Resilience Across the Enterprise
This is why you must advocate against additional responsibilities:
Enterprise business continuity management: You have limited exposure to the diverse risks (e.g., geopolitical, pandemic, climate, economic) that are exposing organizations to severe disruptions and that are emerging at an unpredictable pace.
Leading business impact assessments (BIAs): You don’t know how each business unit in the entire organization operates, and the downstream and upstream dependencies of individual systems.
Enterprise-level IT disaster recovery: Many enterprise-level disasters, such as cloud provider disruptions, system configurations and data center failures have nothing to do with cybersecurity, and require a holistic understanding of business continuity planning that spans physical facilities, IT infrastructure, and operations.
Instead of becoming responsible for additional activities, you must:
Propose an alternative owner.
Be clear on decision authority and procedural roles among stakeholders.
Build a RASCI matrix to formalize responsibilities.
Propose an Alternative Owner
Know what you don’t know: When asked to expand your remit, propose an alternative owner to be responsible for specific activities (e.g., the COO, enterprise risk management for BCM activities, I&O for IT disaster recovery). Additionally, outline clearly how cybersecurity will support certain activities by providing subject-matter expertise.
Be Clear on Decision Authority and Procedural Roles Among Stakeholders
Clear boundaries ensure cybersecurity teams remain laser-focused on the rapidly evolving cyberthreat landscape and provide the greatest value and protection to the organization.
Focus your team’s efforts on activities where you have the direct expertise and authority to make a positive impact (see Figure 2). These are activities that ensure rapid threat detection, incident response and recovery to minimize the impact of cybersecurity incidents on the business (see Prioritize These Three Actions for Successful Cyber Resilience).
Figure 3: Top Priority Activities to Target Cyber Resilience

Build a RASCI Matrix to Formalize Responsibilities
Make sure that you formalize all of the activities for which your team is responsible in a RASCI (responsible, accountable, supportive, consulted, informed) matrix (see Tool: Cybersecurity Program RASCI Matrix). Socialize the document widely.
As you develop the RASCI, remember that cybersecurity is not the only function responsible for decision making. Engage with IT and non-IT executives regularly to ensure they know what their role is throughout the cyber resilience life cycle.
See how Leung Man, CISO at Insurance Corporation of British Columbia (ICBC), supported enterprise risk management to strengthen cyber resilience.
How ICBC Determines Cybersecurity’s Remit
Leung Man, CISO at Insurance Corporation of British Columbia (ICBC), recognized that cybersecurity should only be responsible for the things directly within its control: creating cybersecurity controls, setting monitoring based on criticality, and aligning cyber incident response with business value. Otherwise, it supports other teams by identifying critical data, providing monitoring guidance, and offering cybersecurity insights, such as identifying key systems that require protection and providing additional context around incidents.
Figure 1 breaks down what resilience activities cybersecurity is responsible for and how they support other business units.
Figure 4: How ICBC Determines Cybersecurity’s Remit

Remember that while it is critical that you develop clear boundaries to protect your remit, it is also important that you are still seen to be a part of the solution both for the health of the organization and for your standing as an executive. You must put as much focus on the positive role you can play to better connect cyber risk to business continuity and disaster recovery plans. This ensures you are part of a functional overall process and are also comfortable about your ability to deliver to cybersecurity’s expectations.
1 2025 Gartner Strengthening Cyber Resilience Across Silos Survey. This survey was conducted to understand organization’s approach to updating cybersecurity incident response plans, conducting tabletop exercises and assessing the role of chief information security officers (CISOs) in business continuity management and disaster recovery activities. The survey was conducted online from 30 October through 17 November 2025 and received responses from 84 cybersecurity & IT leaders across a few sources, including Gartner’s Research Circle, Gartner’s Peer Community and non-Gartner clients (prospects). Respondents were from North America (n = 39), EMEA (n = 32) and Asia/Pacific (n = 13). Disclaimer: The results of this survey do not represent global findings or the market as a whole, but reflect the sentiments of the respondents and companies surveyed.
2 Gartner Cybersecurity Controls Assessment. This benchmark tool offers a self-assessed view of controls implementation maturity against leading industry-recognized frameworks and standards. It enables cybersecurity leaders to conduct peer benchmarking relevant to their industry and level of risk exposure. The benchmark includes data from 83 organizations gathered between July 2024 and April 2025. Participating organizations represent a broad range of industries, geographies and sizes (based on revenue in U.S. dollars). This assessment revealed that one of the biggest gaps between controls implementation maturity and CISOs’ rankings is in the response and recovery functions, ranked at 2.7 out of five.