Business Continuity Management / Disaster Recovery
,
Events
,
Governance & Risk Management
Mickey Bresman Discusses Gaps in Preparedness and Tabletop Execution
Security leaders are placing more focus on cyber resilience as regulations tighten worldwide. Mickey Bresman, CEO at Semperis, said frameworks such as the Securities and Exchange Commission’s cybersecurity disclosure rule and the European Union’s DORA regulation are forcing organizations to build and test disaster recovery plans.
See Also: How Generative AI Enables Solo Cybercriminals
Though leaders now recognize resilience as critical, many organizations face challenges in operationalizing it across the enterprise.
“The question becomes, how well are you prepared to start and put in place such a plan?” Bresman asked. One key focus area is keeping roles and responsibilities current as changes occur.
Bresman said that tabletop exercises should extend beyond security and IT. Public companies should include CEOs, legal counsel and even board members – who now carry regulatory responsibilities. He also stressed the importance of having a structured response framework, including scribing mechanisms to track decision-making and media coordination roles to avoid communication missteps during a crisis.
“You might have a playbook that assigns someone to kick off the disaster response, but if that person happens to be unreachable, it is essential to know who can step in next and what happens if that person isn’t available either. That’s why it’s critical to include a seasoned incident leader in tabletop exercises,” Bresman said.
In this video interview with Information Security Media Group at RSAC Conference 2025 Bresman also discussed:
- Why many organizations still fall short in cyber resilience planning;
- How regulatory pressure is reshaping tabletop exercises and response plans;
- The importance of contingency roles and real-time decision tracking in crisis scenarios.
Bresman leads Semperis, a leading provider of enterprise identity protection, threat research and incident response solutions. Semperis is widely recognized to offer the industry’s most comprehensive hybrid directory protection technology and services.

