drj logo
drj logo

Welcome to DRJ

Already registered user? Please login here

Create new account
(it's completely free). Subscribe

x

From Activity to Insight: Why Your BC/DR Reporting Isn’t Winning Executive Support

Business Continuity ManagementData Protection: Backup & RecoveryExercises: Testing & Scenario PlanningLeadership: Culture & Workforce ResilienceOperational ResilienceResilience Strategy & Program MaturityRisk Management & QuantificationSector-Specific & Critical Infrastructure Resilience
From Activity to Insight: Why Your BC/DR Reporting Isn't Winning Executive Support

Every mature business continuity program eventually hits the same wall. The plans are built, the exercises are running on schedule, the gaps you found last year are closed, and every quarter you deliver a report showing exactly how much work has been completed. And every quarter, executive engagement stays flat or gets worse.

The problem usually isn't the program. It's the report.

I learned this the hard way while building the enterprise BC/DR program for a Fortune 100 manufacturer operating in more than 30 countries. We had real maturity; plans across every region, a full exercise calendar, a growing library of business impact analyses. Every quarter I walked into a steering committee meeting with a status update, plans reviewed, exercises completed, BIAs conducted. The activity numbers climbed every quarter. Executive engagement did not. If anything, eyes glazed a little more each time, and a meeting meant to be a checkpoint on organizational risk started to feel like a compliance formality everyone was relieved to get through.

It took longer than I'd like to admit seeing why. I was reporting on effort. Executives don't manage effort, they manage risk. A report that says, “We completed 40 plan reviews this quarter,” answers a question nobody in that room was asking. The question they actually have, whether they say it out loud or not, is simpler and harder; “If something breaks tomorrow, are we exposed?”

KPI vs. KRI: The Distinction That Actually Matters

Most BC/DR reporting collapses two very different questions into one number. A key performance indicator tells you whether the program is executing to plan, plans updated on schedule, exercises completed, BIAs current. A key risk indicator tells you something different; where the organization is exposed despite all that activity. Tested recovery time against required recovery time. Vendors whose DR capability has never been independently validated. Critical applications with no confirmed failover path.

Activity reporting only ever answers the KPI question, and it answers it in a way that flatters the program regardless of actual risk posture. You can complete 100% of scheduled plan reviews and still have a two-week gap between your tested recovery time and what the business actually needs. Executives who see only the KPI side have no way to know a gap exists, and once they've been shown a few quarters of “100% complete,” they stop asking.

Put the two side by side and the difference is obvious. A KPI-only report says; 40 of 40 scheduled plan reviews completed, 12 exercises run, 95% of BIAs current. Every number is good news. A KPI/KRI report says; recovery capability is fully tested for two of your five highest-revenue applications, three carry an unvalidated gap between tested and required recovery time, and two critical vendors haven't had their DR capability independently confirmed in over a year. Same program, same underlying data set, two completely different conversations. The first gets a nod. The second gets a follow-up meeting.

The fix isn't more reporting. It's reporting the right half of the picture and reporting it as a trend rather than a snapshot.

What Changed at a Global Manufacturer

At Jabil, where I served as global head of IT resiliency and infrastructure governance, we rebuilt the enterprise BC/DR program from the ground up to ISO 22301 compliance across more than 30 countries. The program itself was sound well before the reporting caught up to it. What changed executive engagement wasn't new capability, it was retiring the activity report in favor of a KPI/KRI dashboard that answered the exposure question directly; recovery time gaps by application tier, vendor DR validation status for the critical third parties the business depended on, and trend lines showing whether exposure was closing or widening quarter over quarter.

The shift moved executive stakeholder engagement up 50%, measured by steering committee participation and follow-up requests between meetings. Not because the underlying program improved that quarter, it hadn't, materially, but because for the first time, the report was answering the question executives actually had. A CIO doesn't need to know we finished 40 plan reviews. A CIO needs to know whether the three applications that would take down order fulfillment have a tested recovery path, and if not, how long until they do.

The Same Principle in a Regulated Environment

I later applied the same framework at a large health insurance company, in a very different regulatory context, HIPAA-aligned business continuity rather than global manufacturing operations. The specifics of the metrics changed; recovery capability for systems handling protected health information, business associate DR validation status, exercise findings tied directly to patient-facing processes rather than production lines. But the underlying principle held, and so did the result: a 30% increase in executive stakeholder engagement from making the metrics meaningful rather than voluminous.

That consistency across two very different industries is the part worth paying attention to. This isn't a manufacturing framework or a healthcare framework. It's a reporting discipline that works anywhere where a program has more activity data than anyone upstream actually wants.

Building Your Own Dashboard

You don't need a sophisticated GRC platform to make this shift, the principle works with a spreadsheet, though a dashboard tool obviously helps once you've proven the concept. What matters is choosing metrics that map to exposure, not effort. A starting set that tends to translate well regardless of industry:

  • Recovery capability gap: tested RTO/RPO against the RTO/RPO the business actually requires, by application or process tier, not averaged across the portfolio.
  • Critical vendor DR validation: percentage of top-tier vendors whose recovery capability has been independently tested or attested within the last 12 months, not just contractually promised.
  • Plan currency against risk, not against calendar: a plan that's technically “current” but hasn't accounted for a system migration or org change is a KRI, not a KPI checkmark.
  • Exercise findings closure rate and aging: how many findings from the last exercise are still open, and how long they have been open, this is often the single most revealing number in the whole dashboard.
  • Trend, not snapshot: every one of the above shown across the last four to six quarters. A single data point tells you where you are. A trend tells executives whether the program is closing the gap or losing ground.

Five metrics, consistently tracked and trended, will get more executive attention than forty activity line items ever will.

Where Practitioners Go Wrong

The most common failure mode isn't picking the wrong metrics; it's refusing to cut the ones that no longer serve a purpose. Practitioners build activity reporting early in a program's life because it's genuinely useful internally, it tells you whether your own team is keeping pace. The mistake is carrying that internal management report into the executive room unchanged, assuming more data reads as more rigor. It reads as noise.

The second failure is presenting metrics without a business-risk translation attached. The phrase, “72% of plans are current,” means nothing to a board member. “Three of our five highest-revenue-impact applications have a confirmed gap between tested and required recovery time,” means something to everyone in the room, technical or not.

The third failure is format. A 12-page status deck buries the two numbers that matter under 30 that don't, and executives learn quickly which reports reward a close read and which don't. The dashboard itself should fit on a single page or screen. Five to seven metrics, each with a current value and a trend arrow, is a report a CIO can absorb 90 seconds after walking into the room, which is usually all the time you actually have before the agenda moves. Anything that requires a narrated walkthrough to be understood has failed as a dashboard, however good the underlying analysis is.

How You Present It Matters Almost as Much as What You Present

Cadence matters too. Monthly is often too frequent for metrics that don't move monthly, recovery capability gaps close over quarters, not weeks, and a dashboard that hasn't changed in 30 days trains executives to stop looking at it closely. Quarterly, tied to the natural rhythm of a steering committee or audit committee cycle, tends to match how fast the underlying risk picture actually moves, and it gives you something honest to say about direction; closing, holding, or widening.

Resist the temptation to add a metric every time someone asks an interesting one-off question in a meeting. Dashboards accumulate line items the same way activity reports did, for the same reason, every metric felt important when it was added, and none of them ever get removed. Revisit the metric set itself on an annual basis and ask whether each one is still answering an exposure question anyone is asking, or whether it has quietly reverted to measuring effort.

The Takeaway

Executive engagement in BC/DR programs isn't a communications problem you solve with better slides. It's a measurement problem. If your reporting tracks what your team did, you'll get polite nods. If it tracks what the business is exposed to, and shows whether that exposure is shrinking, you'll get the follow-up questions, the budget conversations, and the program support that activity reports never generate on their own.

The program doesn't have to be perfect for this to work. Ours wasn't, in either case above. What changed the room was telling the truth about exposure in language executives were already fluent in, risk, trend, and gap, instead of the language practitioners default to, which is effort.

ABOUT THE AUTHOR

Stuart Murray

Stuart Murray, CBCP, is managing director of Meridian Resilience, a fractional BC/DR advisory practice delivering Fortune 100-caliber resilience expertise to organizations that can't yet justify a full-time senior hire. He spent 25 years building and leading BC/DR programs for Fortune 100 organizations, including serving as global head of IT resiliency and infrastructure governance at Jabil, where he built an enterprise program to ISO 22301 certification across 34 countries, and later applied the same executive-reporting framework at Molina Healthcare. He is a FEMA-certified exercise evaluator, and a Prosci certified change manager, and has presented at more than 50 industry conferences, including DRJ. He can be reached at stuart@meridianresilience.com.

Latest News
DRJ HOT ITEMS
Webinar Spotlight
Fetching Upcoming Webinars...
Journal Categories

AI: Automation & Innovation

Business Continuity Management

Crisis Management & Emergency Response

Cyber Resilience & IT Disaster Recovery

Leadership: Culture & Workforce Resilience

Operational Resilience

Risk Management & Quantification

Sector-Specific & Critical Infrastructure Resilience

Supply Chain & Third-Party Resilience

Governance: Compliance & Regulatory Readiness

Incident Management & Response Coordination

Resilience Strategy & Program Maturity

Data Protection: Backup & Recovery

Exercises: Testing & Scenario Planning

Emerging Threats: Geopolitical & Climate Risk

Contact Us

Newsletter

The Journal, right in your inbox.