Disaster recovery occupies a strange position on the corporate agenda. It carries board-level consequences, regulatory exposure, and, in healthcare, direct clinical risk. It is almost universally delegated to the technical function and reviewed once a year at most. Nick F. Hernandez argues the delegation is the failure. Recovery capability is a commitment about how much interruption an organization can tolerate and how much data it can afford to lose. Both are business judgments that leadership makes by default when it declines to make them explicitly.
He describes what that abdication produces: a clinician waiting on a patient record, systems down, and nobody in the building able to say when they will return. “That moment is not an IT problem,” he says. “It is a governance failure.” Hernandez, Chief Technical Officer at Zydoc Medical Transcription, has spent more than 20 years securing healthcare infrastructure where recovery is measured against patient care, and regulators are watching. His approach moves the entire subject out of the technical function and onto the leadership agenda where the decisions actually belong.
Recovery Targets Are Business Decisions
The practice begins with naming the critical systems and establishing how long each can be down and how much data the organization can afford to lose. Hernandez then brings those figures to leadership for approval on the same footing as a budget. The approval changes their status:
• Targets set inside a technical function carry the authority of that function, which means they can be revised when a quarter tightens, and no one outside IT will register the change.
• Targets a leadership team has approved become organizational commitments with visible ownership.
He extends the same requirement to vendors, who are asked to commit to matching numbers in writing rather than describe their capabilities in a sales conversation. “Now recovery is a standard,” he says, “and standards have owners.”
Evidence on a Fixed Cadence
An approved target is a stated intention until the organization demonstrates it can meet it. Hernandez runs the failover, times the restore, and measures the result against what was signed. Each exercise concludes with written findings, a named owner, and a due date, which distinguishes a test that changes something from a test that merely took place. Those results then reach the leadership table on a fixed cadence.
“What gets reported gets funded,” he says. Recovery capability competes for investment against initiatives that produce visible returns, while regular reporting keeps it in front of the people allocating capital rather than surfacing only after an incident has made the case for it.
Authority Assigned Before It Is Needed
The third practice governs the first hour of an incident, where ambiguity is most costly. Hernandez resolves the questions in advance, naming who declares a disaster, who briefs clients and regulators, and who runs the restore. Those assignments are documented and rehearsed, which is what allows the opening hour to be executed rather than negotiated. An organization that waits until its systems are down to decide who is in charge is using its most valuable hour to resolve a question that should have been settled long before the incident occurred. In a regulated environment, that delay can compound into notification failures and compliance exposure that extend well beyond the outage itself.
Approved numbers, tested proof, and named owners are what separate a recovery document from genuine governance. Each moves a decision out of the technical function and into the place where accountability sits, which is the only arrangement that holds when an incident is underway. As Hernandez puts it, security is a streak you cannot afford to break. To learn more, connect with Nick F. Hernandez on LinkedIn.