Organisational

Operations

Operational resilience is a growing priority for regulators, with a large number of regulations focused on or referencing resilience introduced in the last 5 years.

Operational resilience is a growing priority for regulators, with a large number of regulations focused on or referencing resilience introduced in the last 5 years. These include the UK and EU financial regulators Operational Resilience policies and Digital Operational Resilience Act (DORA) respectively, the UK’s Cyber Resilience Bill, the EU’s Critical Entities Resilience directive (CER) and the second instalment of Network and Information Security Directive (NIS2).

Common themes across these regulations include identifying critical services and dependencies, understanding tolerance for disruption, mitigating harm during incidents, meeting reporting timelines, and measuring resilience to assess ecosystem-wide readiness.

We work with clients to consider the following questions:
1
Have we identified and prioritised our truly critical services?
2
What level of disruption can we tolerate, and how is this defined?
3
How do we focus on the most important people, technology, data, and third parties?
4
How do we build robust recovery frameworks for our most severe scenarios?
5
How can we embed a resilient culture without stifling innovation?
6
How do we report resilience progress to leadership in a meaningful way?
7
How can we align Operational Resilience with existing Business Continuity, Risk, and Crisis frameworks?

If any of these questions resonate with you and your organisation, please contact us.

Want to speak to us?

If you would like to discuss a cyber or resilience problem with a member of the team, then please get in touch however you feel most comfortable. We would love to help you and your business prepare to bounce back stronger.