Now liveThe Skillselion MCP - thousands of ranked skills, loaded into your agent mid-task. No install.Get it →
daemon-blockint-tech avatar

Bcm Disaster Recovery Specialist

  • 27 installs
  • 7 repo stars
  • Updated May 20, 2026
  • daemon-blockint-tech/agentic-enteprises-skill

Build security-focused BCM/DR: BIA and RTO/RPO for security tooling, cyber-resilient BCP/DRP, ransomware recovery playbooks, and restore tests.

About

Guides security-focused business continuity and disaster recovery covering BIA, RTO/RPO for security tooling, cyber-resilient BCP/DRP, ransomware recovery, and restore testing. A developer uses it when defining BCM/DR scope or authoring cyber recovery runbooks.

  • BIA and RTO/RPO for identity and security tooling (SIEM/EDR/IdP/KMS)
  • Ransomware recovery playbooks and immutable backup design

Bcm Disaster Recovery Specialist by the numbers

  • 27 all-time installs (skills.sh)
  • Ranked #1,530 of 2,203 Security skills by installs in the Skillselion catalog
  • Data as of Jul 29, 2026 (Skillselion catalog sync)
npx skills add https://github.com/daemon-blockint-tech/agentic-enteprises-skill --skill bcm-disaster-recovery-specialist

Add your badge

Show developers this skill is listed on Skillselion. Paste this into your README.

Listed on Skillselion
Installs27
repo stars7
Last updatedMay 20, 2026
Repositorydaemon-blockint-tech/agentic-enteprises-skill

What it does

Build security-focused BCM/DR: BIA and RTO/RPO for security tooling, cyber-resilient BCP/DRP, ransomware recovery playbooks, and restore tests.

Files

SKILL.mdMarkdownGitHub ↗

BCM & Disaster Recovery Specialist (Security-Focused)

When to Use

  • Run business impact analysis for security-critical and IT services (IdP, SIEM, EDR, SOAR, KMS, CASB, PKI)
  • Set RTO/RPO and recovery tiers for security tooling, identity, logging, and evidence retention
  • Author or refresh BCP/DRP with cyber-resilience (isolation, rebuild-from-gold, segmented recovery)
  • Build ransomware and destructive-attack recovery playbooks (decrypt vs rebuild decision tree)
  • Design backup, immutability, and air-gap patterns; schedule restore tests with pass/fail criteria
  • Coordinate crisis comms cadence with IR and executive stakeholders during prolonged recovery
  • Facilitate tabletop exercises (cyber, regional loss, identity outage, logging loss)
  • Map high-level regulatory BCM expectations to program artifacts (not legal advice)

When NOT to Use

  • Lead active security incident war room, containment, or evidence preservation → incident-responder
  • Triage SOC alerts or execute detection playbooks → soc-analyst
  • Define SEV matrices, paging, or status-page program → incident-management-engineer
  • Operate SLIs, SLOs, error budgets, and burn-rate alerts → site-reliability-engineer
  • Execute snapshot restores and access tickets without BCM program ownership → cloud-system-administrator
  • Build VPC, clusters, or new platforms → infrastructure-engineer, cloud-engineer
  • Enterprise security strategy without BCM/DR lens → cybersecurity
  • Implement SIEM/EDR/IdP controls → information-security-engineer
  • Control-by-control audit evidence automation → compliance-engineer
  • Org-wide infra portfolio and multi-year capex → vp-of-infrastructure
  • Deep forensic acquisition and super-timelines → digital-forensics-analyst

Related skills

NeedSkill
Active CSIRT response, containment, timelinesincident-responder
Incident program, SEV, on-call, postmortem processincident-management-engineer
SLO impact during outage; reliability mitigationsite-reliability-engineer
Backup/restore execution, snapshots, hygienecloud-system-administrator
Security program, IR policy, board narrativescybersecurity
SIEM/EDR/IdP/KMS implementationinformation-security-engineer
GRC program, framework scoping, audit prepcompliance-specialist
Technical evidence automationcompliance-engineer
Forensic preservation and investigation reportsdigital-forensics-analyst
Crisis and customer messaging approvalcommunication-lead
VP infra portfolio and investment trade-offsvp-of-infrastructure

Core Workflows

1. Scope and program charter

Define BCM/DR boundaries, ownership, and alignment with IR and resilience functions.

See `references/bcm_dr_scope.md`.

2. Business impact and criticality

Identify processes, dependencies, and security-service criticality; classify tiers.

See `references/business_impact_and_criticality.md`.

3. RTO, RPO, and recovery strategies

Set objectives; choose strategies (active/active, warm standby, rebuild, manual workaround).

See `references/rto_rpo_and_recovery_strategies.md`.

4. Cyber incident and ransomware recovery

Playbooks for encryption, wiper, identity compromise, and supply-chain recovery sequencing.

See `references/cyber_incident_and_ransomware_recovery.md`.

5. Backup, immutability, and restore testing

Retention, isolation, validation criteria, and evidence for auditors and leadership.

See `references/backup_restore_and_immutability.md`.

6. Tabletop exercises and governance

Exercise design, findings tracking, regulatory touchpoints, and continuous improvement.

See `references/tabletop_exercises_and_governance.md`.

Outputs

  • BIA summary — tiered services, dependencies, max tolerable downtime, data classes
  • RTO/RPO register — per service with owner, strategy, and last test date
  • BCP/DRP pack — activation criteria, roles, comms tree, recovery sequences
  • Cyber recovery playbook — ransomware/wiper/IdP paths with decision gates
  • Restore test report — scope, RPO achieved, integrity checks, gaps, remediation
  • Tabletop report — scenario, injects, decisions, gaps, action register
  • Executive BCM brief — posture, test results, top risks (for leadership; not legal advice)

Principles

  • Recover security first — identity, logging, and detection before convenience features
  • Assume compromise — prefer clean rebuild and immutable backups over in-place decrypt
  • Test restores, not backups — successful backup job ≠ recoverable data
  • Align with IR — BCM activation and comms complement, not duplicate, CSIRT runbooks
  • Document decisions — tiering and accepted gaps need explicit risk acceptance

Related skills

Securityinframonitoring

This week in AI coding

Five minutes, every Monday - the tools, releases and tactics for developers.

unsubscribe anytime.