Manage cookies
This site uses cookies to collect information about your browsing activities in order to provide you with more relevant content and promotional materials, and help us understand your interests and enhance the site. Visit our cookie policy to learn more.
Manage cookies
Cookie Settings
Cookies necessary for the correct operation of the site are always enabled.
Other cookies are configurable.
Essential cookies
Always On. These cookies are essential so that you can use the website and use its functions. They cannot be turned off. They're set in response to requests made by you, such as setting your privacy preferences, logging in or filling in forms.
Analytics cookies
Disabled
These cookies collect information to help us understand how our Websites are being used or how effective our marketing campaigns are, or to help us customise our Websites for you. See a list of the analytics cookies we use here.
Advertising cookies
Disabled
These cookies provide advertising companies with information about your online activity to help them deliver more relevant online advertising to you or to limit how many times you see an ad. This information may be shared with other advertising companies. See a list of the advertising cookies we use here.
Resilience and Business Continuity Consulting in Switzerland | Resilience Guard
Home Consulting
Consulting

Resilience consulting, led by senior practitioners.

Business continuity, crisis management, cyber resilience, risk and regulatory compliance, designed and delivered by the people who have run real incidents, from our Swiss headquarters across Europe and the UAE.

The practice

Who you are working with

Resilience Guard GmbH is a Swiss, practitioner led resilience, risk and business continuity advisory, founded in Zurich in 2014 and headquartered today in Steinhausen, Canton of Zug, serving organisations across Switzerland, Europe and the UAE.

Our consultants are senior practitioners who have personally led incidents, built programmes and faced regulators, not career advisors working from a methodology binder. That experience shapes everything: engagements are scoped to the decision the client actually needs to make, deliverables are built to survive a real disruption, and every recommendation is one we have seen work under pressure.

The practice is organised around four disciplines, continuity and resilience, risk and governance, cyber and security, and regulation and crisis, delivered by one team that also runs our training academy and resilience platform, so strategy, capability and tooling arrive joined up rather than in silos.

Founded
2014, Steinhausen, Zug
Team
21 professionals
Reach
Switzerland, Europe, UAE
Sectors
12 industries served
ONE PRACTICE, FOUR DISCIPLINES, TWELVE SERVICES, ONE FRAMEWORKContinuity and resilienceBusiness ContinuityOrganisational ResilienceBC ExercisesRisk and governance7A FrameworkRisk ManagementAI GovernanceCyber and securityCyber ResilienceInformation SecuritySupply Chain SecurityRegulation and crisisNIS2DORACrisis ManagementDAEDALUS Airport Resilience EcosystemAll four disciplines applied to one sector, the airport and its ecosystemSenior practitioner deliveryOne team across consulting, training and platformEvery engagement can draw on the full architecture: assess once, act everywhere.
The consulting architecture: twelve services across four disciplines, crowned by DAEDALUS, the sector framework that applies all four to the airport, delivered by one senior practitioner team.
The services

Twelve services and one sector framework

Continuity and resilience

Business Continuity Management

BIA, ISO 22301 aligned strategy, plans and validation: a continuity programme built to survive contact with a real disruption.

Explore the service ›
Continuity and resilience

Organisational Resilience

The structure above the plans: risk, continuity, crisis, cyber and people on one governed foundation, per ISO 22316.

Explore the service ›
Continuity and resilience

Business Continuity Exercises

Tabletop, functional, cyber and full scale exercises that prove the plans and evidence ISO 22301, NIS2 and DORA.

Explore the service ›
Risk and governance

7A Risk Management Framework

Our proprietary decision centric operating model: exposure and decision confidence measured separately, for the board.

Explore the service ›
Risk and governance

Risk Management

From risk universe to governed risk: identification, stress aware assessment, owned treatment and live monitoring.

Explore the service ›
Risk and governance

AI Governance and Resilience

Governance wrapped around every layer of intelligent systems, from model behaviour to board accountability and ISO 42001.

Explore the service ›
Cyber and security

Cyber Resilience

Beyond prevention: the capacity to withstand, respond and recover while essential services keep running.

Explore the service ›
Cyber and security

Information Security

Confidentiality, integrity and availability protected through a living ISMS aligned to ISO 27001.

Explore the service ›
Cyber and security

Supply Chain Security

The risk you inherit from suppliers and shared platforms: mapped, assured, contracted and exercised, per ISO 28000, NIS2 and DORA.

Explore the service ›
Regulation and crisis

NIS2 Compliance

From scope determination to Article 21 measures and 24 hour reporting readiness under Directive (EU) 2022/2555.

Explore the service ›
Regulation and crisis

DORA Compliance

The five pillars of Regulation (EU) 2022/2554 implemented for financial entities and their critical ICT providers.

Explore the service ›
Sector framework

DAEDALUS Airport Resilience Framework

The Airport Resilience Framework: five domains as one operating model across the aerodrome, powered by the 7A engine, in commercial, freight and business aviation editions.

Explore the service ›
Regulation and crisis

Crisis Management

Doctrine, structures and communications that contain the peak and shorten the recovery, anchored on ISO 22361.

Explore the service ›
Clear boundaries

Which service do you need?

Information security or cyber resilience? Information security builds the ISMS that protects your data and earns ISO 27001; cyber resilience keeps essential services running when protection fails. Certification and control maturity: start with information security. Continuity of operations under attack: start with cyber resilience. Mature organisations build both, in that order.
Risk management or the 7A Framework? Risk management is the ISO 31000 discipline: the process, governance and reporting every organisation needs. The 7A Framework is our proprietary operating model layered on top for boards whose risk process no longer informs decisions. No capability yet: risk management. A capability that produces heatmaps nobody acts on: 7A.
Business continuity or organisational resilience? Business continuity keeps critical activities running: one pillar, deep. Organisational resilience is the structure that integrates that pillar with risk, crisis, cyber and people under one governance. Missing plans: business continuity. Five programmes that never meet: organisational resilience.
NIS2 or DORA? Sector decides. Financial entities and their critical ICT providers fall under DORA, which takes precedence as lex specialis; other essential and important sectors fall under NIS2. Groups spanning both get one capability mapped to two regimes.
Crisis consulting, training or exercises? Consulting builds the capability, training embeds it in your people, and exercises prove it and produce the regulatory evidence. A complete programme cycles through all three.
How we engage

From first conversation to embedded capability

Diagnose. A focused assessment of where you stand: maturity, gaps, regulatory exposure and the decisions your leadership needs to make. Weeks, not months.
Design. The programme, framework or plan itself, built to your organisation, your sector and your regulators, with clear owners and defensible evidence from day one.
Deliver. Implementation alongside your team: policies made operational, structures stood up, plans written by people who have used plans at three in the morning.
Prove. Exercises, audits and reviews that validate the capability and produce the record your board, certifier or supervisor expects, then a cycle of continual improvement.
Questions

Frequently asked questions

What does Resilience Guard's consulting practice cover?+

Twelve services across four disciplines, business continuity, organisational resilience and exercising; risk management, the proprietary 7A Framework and AI governance; cyber resilience, information security and supply chain security; and NIS2, DORA and crisis management. Above them sits DAEDALUS, our proprietary sector framework that applies the full architecture to airports. All are delivered by one senior practitioner team.

What makes a practitioner led advisory different?+

Our consultants have personally led incidents, built programmes and faced regulators. Engagements are scoped to real decisions, deliverables are built for real disruptions, and every recommendation is one we have seen work under pressure rather than in theory.

Which standards and regulations do you work to?+

ISO 22301 and ISO 22313 for business continuity, ISO 22361 for crisis management, ISO 22316 for organisational resilience, ISO 31000 for risk, ISO 27001 for information security and ISO 42001 for AI, alongside NIS2, DORA, KRITIS and the Swiss Information Security Act.

Where do you operate?+

From our headquarters in Steinhausen, Canton of Zug, we serve organisations across Switzerland, Europe and the UAE, in twelve industry sectors, with delivery on site or remote.

Can consulting and training be combined?+

Yes, and they usually should be. Programmes we design are embedded through our training academy and validated through our exercise formats, so the capability lives in your people, not in a binder.

Next step

Start with the decision you need to make.

Tell us where you are and what your board, certifier or regulator expects; we will scope the shortest path there.

Book a consultation
All consultations are treated with strict confidentiality.