Operational resilience and the shift from policy to proof

Cyber Resilience 23 June 2026

If a serious incident happened tomorrow, could you confidently explain your organisation’s decisions to a regulator, a board, or a customer six months later?

For many senior leaders, this question now matters more than whether policies exist or controls are documented.

UK regulators are increasingly judging organisations not on intent, but on how they behave under pressure, how quickly issues are understood, how decisions are made, and whether those decisions still stand up when scrutiny arrives after the event.

This reflects a broader change in how oversight works. Regulators are no longer satisfied that organisations intended to manage risk well. They are focused on whether organisations can explain, evidence, and defend their actions when something has already gone wrong.

This does not mean prevention has become less important. Regulators continue to expect organisations to invest in proportionate and preventative controls.

However, when incidents occur, the focus moves quickly to how well organisations recognise failure, how decisions are made under pressure, and whether those decisions remain defensible with hindsight.

Across financial services, critical national infrastructure, and technology-enabled supply chains, the same questions surface after incidents:

  • What actually failed?
  • How quickly was it understood?
  • Who decided what to do next?
  • Were those decisions defensible under pressure?

These questions carry weight because incidents are now seen as the most reliable way to assess how an organisation operates. They bypass strategy documents and diagrams and expose how escalation, governance, and dependency management function under stress.

Why operational resilience now matters more than ever

Operational resilience now sits at the centre of these discussions because regulators increasingly recognise that disruption is inevitable. The expectation is no longer that organisations can prevent every incident from occurring. Instead, organisations are expected to demonstrate that they can continue operating, protect important services, make sound decisions, and recover in a controlled and proportionate way.

This represents a significant cultural shift. Historically, many organisations approached resilience as a technical or compliance exercise. Operational resilience was often treated as something owned by IT, risk, or compliance teams rather than as an organisation-wide capability. Today, that position is becoming difficult to defend.

Modern incidents expose weaknesses that sit far beyond technology. A ransomware attack might begin with a compromised endpoint, but the wider impact often reveals deeper issues around governance, communication, supplier management, escalation pathways, and leadership confidence under pressure.

In practice, this means operational resilience is becoming inseparable from organisational behaviour. Regulators are examining not only whether plans existed, but whether people understood them, whether responsibilities were clear, and whether decisions could be justified when normal operating conditions no longer applied.

For senior leadership teams, this changes the nature of preparedness entirely. Operational resilience is no longer demonstrated by the existence of a framework sitting in a shared drive. It is demonstrated through awareness, coordination, communication, and evidence that critical decisions were made in a structured and proportionate manner.

Moving beyond technical resilience

For many organisations, the concept of operational resilience still feels heavily associated with technology. While cyber resilience and infrastructure remain important, resilience today extends far beyond systems and networks.

A technically secure organisation can still struggle operationally if leadership communication breaks down, decision-making becomes fragmented, or dependencies are poorly understood. Likewise, organisations with mature governance structures often navigate incidents more effectively because accountability and escalation are already embedded into day-to-day operations.

This is one of the reasons regulators increasingly focus on operational behaviour rather than isolated technical controls. They want to understand whether organisations can continue functioning under pressure when information is incomplete, priorities are shifting, and time-sensitive decisions must be made quickly.

In reality, operational resilience depends on how well people, processes, suppliers, and technology operate together during disruption. Weakness in any one of those areas can quickly undermine the others.

A broader, more connected regulatory lens

This shift is not driven by a single authority. It reflects the combined effect of several different types of regulators, each with a distinct role but a shared interest in operational reality.

Financial regulators and operational continuity

Financial regulators, such as the FCA and PRA, focus on operational resilience: whether firms can continue delivering important services to customers, particularly where disruption could cause harm or instability.

These expectations increasingly extend beyond traditional financial controls. Regulators are examining whether organisations understand their critical business services, whether disruption tolerances are realistic, and whether leadership teams can maintain oversight during major incidents.

Cyber oversight and recovery expectations

Cyber oversight bodies, using tools like the Cyber Assessment Framework, assess whether organisations can detect incidents, limit impact, and recover essential functions.

Importantly, these assessments are no longer focused purely on technical prevention. Increasingly, they consider how organisations respond operationally once disruption begins. Detection capability, escalation processes, data backup and recovery, and situational awareness all form part of the wider resilience picture.

Data protection and accountability

Data protection regulators, most notably the ICO, increasingly examine not only whether data was protected in principle, but whether access, use, and breach response decisions were timely, proportionate, and justified.

This means organisations are often assessed not simply on whether an incident occurred, but on how effectively they responded once risks became apparent. Delayed reporting, unclear accountability, or poor communication can significantly increase regulatory scrutiny even where the original technical issue was relatively limited.

National resilience and supply chain scrutiny

Critical infrastructure and national resilience regimes, including NIS reforms and the forthcoming Cyber Security and Resilience Bill, extend these expectations beyond regulated sectors and into supply chains and service providers.

Although these regulators speak different languages and operate under different legislation, their lines of enquiry are converging. When disruption occurs, they are all interested in the same core issues: situational awareness, decision-making, accountability, and recovery.

This convergence is one of the reasons operational resilience now feels more visible and more urgent across multiple sectors at once. Organisations are increasingly facing overlapping expectations from customers, insurers, regulators, and supply chain partners, all asking broadly similar questions about preparedness and control.

Importantly, this does not necessarily mean regulation is becoming more complicated for the sake of complexity. In many ways, it reflects a growing recognition that incidents rarely stay confined to one area of risk. A cyber incident can quickly become a data protection issue, an operational outage, a customer trust problem, and a board-level governance challenge simultaneously.

Regulators are responding to that reality by assessing organisations through a wider lens. They want to understand how information flows during disruption, how leadership teams communicate, and whether accountability remains clear when pressure increases.

Why third-party risk now sits at the centre

One of the clearest drivers of this convergence is the growing role of third-party and supply chain failure. Incidents increasingly originate outside the organisation being examined, in service providers, technology platforms, outsourced operations, or shared infrastructure.

As a result, regulators are no longer prepared to treat supplier issues as peripheral. If a third-party outage interrupts services, exposes data, or delays recovery, it becomes a first-order regulatory concern.

The growing challenge of dependency

This has changed how incidents are interpreted. Questions now extend beyond “what did you do?” to include:

  • How well did you understand your dependencies?
  • How quickly did your suppliers respond?
  • What information were you given, and when?
  • How did that affect your own decisions during the incident?

For many organisations, this is where operational resilience becomes particularly challenging. Modern businesses rely on interconnected systems, outsourced support providers, cloud platforms, and shared infrastructure to deliver day-to-day services. That interconnectedness creates efficiency, but it also creates dependency.

The issue is not simply whether suppliers have controls in place. Increasingly, the focus is on whether organisations genuinely understand how dependent they are on those suppliers and whether realistic contingencies exist if those relationships fail under pressure.

When supplier failure becomes your problem

In some cases, organisations discover during an incident that escalation routes are unclear, contractual obligations do not guarantee timely support, or critical knowledge sits almost entirely with an external provider. These are not theoretical concerns. They become operational realities very quickly during disruption.

As regulators continue placing greater emphasis on third-party oversight, operational resilience is becoming closely tied to visibility across the supply chain. Organisations are expected to know which services matter most, where concentration risk exists, and how quickly alternative arrangements could realistically be implemented.

This shift also places greater pressure on leadership teams to understand operational dependencies outside traditional procurement or IT functions. Supplier resilience is no longer viewed as purely contractual. It is increasingly viewed as a core component of organisational resilience itself.

Incident reporting as evidence, not administration

This is why incident reporting is becoming more structured, more demanding, and more visible. Reports are no longer administrative notifications that simply describe an event. They are used to reconstruct decision paths, test governance arrangements, and examine how organisations behaved when normal conditions fell away. In effect, incidents have become evidence.

They show whether escalation routes worked, whether judgement was applied appropriately, and whether an organisation was in control or reacting late to unfolding events. For many organisations, this marks a clear end to compliance that exists mainly on paper. Policies, frameworks, and documented controls still matter, but they no longer provide protection on their own.

What now matters most is behaviour, judgement, and recovery in real-world conditions, and whether the choices made during disruption remain explainable and defensible under pressure when regulators ask questions later.

Building resilience that stands up under scrutiny

The direction of travel is becoming increasingly clear. Regulators are moving beyond static assessments of policies and controls and focusing instead on how organisations behave when disruption occurs.

Operational resilience is no longer demonstrated through documentation alone. It is demonstrated through awareness, coordination, leadership, and the ability to make reasoned decisions under pressure.

For organisations across regulated sectors and connected supply chains, this changes the conversation entirely. Preparedness is no longer about proving that controls existed on paper. It is about being able to explain what happened, why decisions were made, and how the organisation remained in control during uncertainty.

The organisations that will adapt most effectively to this shift are unlikely to be those chasing perfect compliance documentation. They will be the organisations that build resilience into everyday operations, strengthen decision-making structures, understand their dependencies, and regularly test how they respond under pressure.

As regulatory scrutiny continues to evolve, one principle increasingly sits at the centre of operational resilience: when disruption happens, organisations must be able to demonstrate that their actions were credible, proportionate, and defensible under pressure.

This is also where a more joined-up resilience approach becomes increasingly valuable. Business Resilience as a Service brings together cyber resilience, IT support, operational continuity, monitoring, awareness training, and recovery planning into a single, coordinated framework designed to help organisations maintain operations.

Rather than treating resilience, compliance, cyber security, and operational continuity as separate conversations, organisations are increasingly recognising the need for a connected strategy that supports both day-to-day operations and high-pressure decision-making when incidents occur.

For leadership teams, now is the time to sense-check whether existing approaches would genuinely stand up to that level of scrutiny when it matters most. Get in touch to find out how we can support your business.

Further reading:

Defence, protection, security. We've got you covered.

Whether you need to enhance your approach to cyber threats, overhaul your IT infrastructure or improve your communications, we’re here to help and advise. Talk to a specialist today and take the next step towards being a stronger, more resilient business.

Speak to us today

Need support? Take Control.

The button below is to be used when instructed by our technical support team. This will allow a file to be downloaded to your device for them to take control and help solve the issues you are having.

ND Take Control

exe · 7.70MB

Please note: only to be used when instructed by a member of our support team. Windows devices only.