Operational Resilience: Turning Regulatory Pressure Into Delivery Strength 

Pietro Furfaro
Pietro Furfaro

Overview 

Operational resilience is no longer a compliance exercise that can sit within Risk or Technology. For financial institutions operating across complex technology estates, resilience has become a business critical delivery challenge. 

Regulatory expectations continue to expand across ICT risk, cybersecurity, third party dependency, incident management, business continuity and critical service continuity. DORA, NIS2, Basel operational resilience principles and other frameworks all place greater emphasis on whether organisations can continue delivering critical services when disruption occurs. 

The challenge is not understanding the regulations. 

The challenge is turning those requirements into operational capability that works when the organisation is under pressure. 

That requires experienced delivery leadership, strong governance and the ability to connect risk, technology, business operations and regulatory requirements into one executable programme. 

This is where Brickendon delivers. 

Resilience cannot be built in isolation 

Operational resilience crosses every part of a modern financial institution. 

Critical services depend on applications, infrastructure, data, people, suppliers, cloud platforms and third party providers. A failure in one area can quickly create consequences somewhere else. 

That makes fragmented delivery particularly dangerous. 

A resilience programme managed purely as a compliance initiative can identify gaps without actually resolving them. A technology programme focused only on infrastructure can overlook business impact. A risk programme can define tolerances without ensuring that technology and operational teams can meet them. 

Brickendon’s approach connects these disciplines. 

Our consultants support organisations across the programme, portfolio and project lifecycle, bringing together governance, risk management, technology delivery, operational requirements and stakeholder management to move resilience from policy into execution. 

The objective is not another assessment. It is a stronger organisation that can demonstrate resilience when it matters. 

Regulatory requirements are creating delivery pressure 

The regulatory landscape is becoming increasingly demanding. 

DORA establishes requirements covering ICT risk management, operational resilience testing, incident reporting, third party ICT risk and information sharing across the EU financial sector. 

NIS2 introduces stronger cybersecurity, governance, supply chain and incident reporting expectations across critical sectors. 

Basel principles place further emphasis on identifying important business services, understanding dependencies and establishing impact tolerances for internationally active banks. 

These requirements create a common challenge. 

Organisations need to demonstrate that resilience exists not only within documentation, but across the operating environment. 

That means identifying critical services, mapping dependencies, strengthening controls, testing scenarios and proving that weaknesses can be addressed through structured remediation. 

Compliance creates the requirement. Delivery creates the result. 

Brickendon delivers resilience as a transformation programme 

Building operational resilience requires more than defining policies. 

It requires coordinated execution across business and technology. 

Brickendon can support organisations through the full lifecycle of resilience transformation, from establishing governance and identifying critical services through to remediation, implementation, testing and ongoing improvement. 

Our delivery approach brings structure to complex environments by connecting: 

• Critical business services 

• Technology and application dependencies 

• Data and infrastructure 

• Cybersecurity requirements 

• Third party and supplier risk 

• Business continuity 

• Incident response 

• Governance and reporting 

• Regulatory remediation 

The result is a single delivery view across areas that are often managed separately. 

This enables leadership teams to understand where resilience is strong, where exposure remains and what needs to happen next. 

We do not simply identify the problem. We help organisations deliver the solution. 

Resilience must be tested before disruption tests it for you 

A resilience framework is only valuable if it works under pressure. 

Organisations therefore need to understand how critical services perform during severe but plausible disruption. This requires structured testing, clear impact tolerances and an understanding of the dependencies that can determine whether services continue or fail. 

Brickendon’s delivery experience enables organisations to move beyond theoretical resilience. 

We help establish the governance, controls, operating models and delivery structures required to identify weaknesses early and create practical remediation plans. 

This is particularly important where multiple regulatory obligations overlap. 

Instead of treating DORA, cybersecurity, operational risk and business continuity as separate programmes, organisations can establish a coordinated resilience framework that addresses common dependencies and delivery requirements. 

The strongest resilience programmes do not prepare for one regulation. They prepare the organisation to withstand disruption. 

The next resilience challenge is already emerging 

Operational resilience is not static. 

Technology is changing rapidly. Cloud adoption is increasing. Third party dependencies are becoming more complex. Artificial intelligence is introducing new capabilities alongside new operational and cybersecurity risks. The source material highlights the growing intersection between AI development and operational resilience, particularly as increasingly autonomous technologies introduce new vulnerabilities. 

This means resilience programmes cannot be treated as one time compliance projects. 

Organisations need capabilities that can evolve as technology, regulation and business models change. 

That requires continuous governance, testing, monitoring and remediation. 

Resilience is not achieved when the programme closes. It is achieved when the organisation can continue to adapt. 

Build operational resilience that delivers under pressure 

Regulatory expectations will continue to evolve. 

The organisations best positioned to respond will be those that have already established the governance, technology and delivery capabilities needed to manage change proactively. 

Brickendon supports financial institutions in building operational resilience across complex programmes, helping connect regulatory requirements with practical implementation and measurable delivery outcomes.  

Operational resilience is becoming a priority 

Do not wait for the next disruption to expose the gaps. 

Sources: 

Regulation (EU) 2022/2554

Digital Operational Resilience Act (DORA)

Cyber Resilience Act

Principles for operational resilience

Basel III: international regulatory framework for banks

ISO 22301:2019

ISO/IEC 27001:2022 – Information security management systems 

COBIT®| Control Objectives for Information Technologies® 

ISO/IEC 27031:2025 – Cybersecurity — Information and communication technology readiness for business continuity 

FFIEC IT Examination Handbook InfoBase – Business Continuity Management