
Identity at the Center #397 - RSM & IDAC Present - The Intersection of Resiliency, Recovery, and IAM
Jan 26, 2026
Charles John, director of operational resilience at RSM, brings crisis management and business continuity expertise. Rich Servillas, director in cyber response, leads ransomware and cloud intrusion recoveries. They discuss identity as a fragile operational dependency. Topics include building continuity plans, early incident actions, attacker tactics using credentials, reducing standing privilege, out-of-band communication, and cyber insurance gaps.
AI Snips
Chapters
Transcript
Episode notes
Resilience Is A Unified Preparedness Function
- Operational resilience combines crisis management, business continuity, and disaster recovery into a single preparedness function.
- Charles John says planning, training, and communication are the hallmarks of successful recovery.
Build Escalation Paths And Severity Matrixes
- Do create an escalation tree, clear decision makers, and out-of-band communications before an incident.
- Do build a severity matrix to trigger the right response level and team activation.
Identity Breaks First And Trust Returns Last
- Identity often becomes the first thing challenged and the last thing trusted during incidents.
- Rich Servillas frames identity as an operational dependency, not just a security layer, that multiplies blast radius when messy.
