Manage cookies
This site uses cookies to collect information about your browsing activities in order to provide you with more relevant content and promotional materials, and help us understand your interests and enhance the site. Visit our cookie policy to learn more.
Manage cookies
Cookie Settings
Cookies necessary for the correct operation of the site are always enabled.
Other cookies are configurable.
Essential cookies
Always On. These cookies are essential so that you can use the website and use its functions. They cannot be turned off. They're set in response to requests made by you, such as setting your privacy preferences, logging in or filling in forms.
Analytics cookies
Disabled
These cookies collect information to help us understand how our Websites are being used or how effective our marketing campaigns are, or to help us customise our Websites for you. See a list of the analytics cookies we use here.
Advertising cookies
Disabled
These cookies provide advertising companies with information about your online activity to help them deliver more relevant online advertising to you or to limit how many times you see an ad. This information may be shared with other advertising companies. See a list of the advertising cookies we use here.
Organisational Resilience Consulting, ISO 22316 | Resilience Guard
Organisational resilience consulting

One structure that holds when any part of it is hit.

Risk, continuity, crisis, cyber and people are usually built as separate programmes. Organisational resilience is the discipline of making them one structure on one foundation of governance, culture and leadership, guided by ISO 22316.

The service

What is organisational resilience?

Organisational resilience is the ability of an organisation to anticipate, prepare for, respond and adapt to incremental change and sudden disruption in order to survive and prosper, built from coordinated capabilities in risk, continuity, crisis, cyber and people on a shared foundation of governance, culture and leadership, as described by ISO 22316.

Most organisations own the parts: a risk register, continuity plans, a crisis team, security controls, training records. What they lack is the structure that makes the parts one capability, so a cyber incident is also handled as a continuity event and a crisis, decisions escalate along one path, and the board sees one picture rather than five programme reports.

Our consulting builds that structure. We assess the maturity of each capability and, more importantly, the connections between them; design the governance that gives resilience an owner, an appetite and a reporting rhythm; and close the gaps in whichever pillar is weakest, drawing on the full practice from risk to crisis.

Guide
ISO 22316
Pillars
Risk, continuity, crisis, cyber, people
Foundation
Governance, culture, leadership
Output
One capability, one picture
RESILIENCE IS A STRUCTURE, NOT A DOCUMENTOrganisational resilienceRiskAnticipatedContinuityPlannedCrisisLedCyberWithstoodPeoplePreparedGovernance, culture and leadershipThe foundation everything stands onFive capabilities on one foundation, holding one roof: the structure ISO 22316 describes.
The resilience structure: five capabilities as pillars on a foundation of governance, culture and leadership, carrying one roof.
What we deliver

From five programmes to one structure

Resilience maturity assessment. Each pillar scored, and the joints between them tested: does detection reach the crisis team, does the BIA inform security priorities, does anyone own the whole?
Governance and operating model. Ownership, appetite, committee structure and a reporting rhythm that gives the board one resilience picture instead of five programme updates.
Integration design. Shared scenarios, one escalation path, one exercise programme and one improvement loop across risk, continuity, crisis, cyber and people.
Pillar remediation. Whichever capability the assessment finds weakest, strengthened through the relevant service line, from a missing BIA to an untested crisis structure.
Validation. The integrated structure proven through cross functional exercises that hit several pillars at once, because real disruptions never respect programme boundaries.
Questions

Frequently asked questions

What is the difference between organisational and operational resilience?+

Organisational resilience, per ISO 22316, is the enterprise wide ability to anticipate and adapt, spanning strategy, culture and every capability. Operational resilience is narrower: keeping important business services running through disruption, the framing regulators such as DORA use. We build both; see our operational resilience overview.

What does ISO 22316 provide?+

Guidance rather than requirements: the principles and attributes of resilient organisations, from shared vision and understanding of context to effective leadership, a culture that supports resilience, and coordination across disciplines. We use it as the design guide for the structure.

We already have continuity, security and crisis programmes. What is missing?+

Usually the connections: one escalation path, shared scenarios, a single owner and a board level picture. Disruptions exploit the joints between programmes, which is exactly what an organisational resilience engagement strengthens.

How do you measure resilience maturity?+

Against a model covering each pillar and the integration between them, evidenced by artefacts, interviews and, where wanted, a live exercise. The output is a scored baseline, the gaps that matter most, and a sequenced roadmap.

How long does it take to build?+

The governance and integration design lands in months; the culture matures over cycles of exercising, incidents handled well and visible leadership. We structure engagements so the board sees the one picture early and the depth builds behind it.

Explore further

Related services

Continuity and resilience

Business Continuity Management

BIA, ISO 22301 aligned strategy, plans and validation: a continuity programme built to survive contact with a real disruption.

Explore the service ›
Regulation and crisis

Crisis Management

Doctrine, structures and communications that contain the peak and shorten the recovery, anchored on ISO 22361.

Explore the service ›
Cyber and security

Cyber Resilience

Beyond prevention: the capacity to withstand, respond and recover while essential services keep running.

Explore the service ›
Risk and governance

Risk Management

From risk universe to governed risk: identification, stress aware assessment, owned treatment and live monitoring.

Explore the service ›
Continuity and resilience

Business Continuity Exercises

Tabletop, functional, cyber and full scale exercises that prove the plans and evidence ISO 22301, NIS2 and DORA.

Explore the service ›
Cyber and security

Information Security

Confidentiality, integrity and availability protected through a living ISMS aligned to ISO 27001.

Explore the service ›
Cyber and security

Supply Chain Security

The risk you inherit from suppliers and shared platforms: mapped, assured, contracted and exercised, per ISO 28000, NIS2 and DORA.

Explore the service ›
Regulation and crisis

NIS2 Compliance

From scope determination to Article 21 measures and 24 hour reporting readiness under Directive (EU) 2022/2555.

Explore the service ›
Regulation and crisis

DORA Compliance

The five pillars of Regulation (EU) 2022/2554 implemented for financial entities and their critical ICT providers.

Explore the service ›
Risk and governance

7A Risk Management Framework

Our proprietary decision centric operating model: exposure and decision confidence measured separately, for the board.

Explore the service ›
Sector framework

DAEDALUS Airport Resilience Framework

The Airport Resilience Framework: five domains as one operating model across the aerodrome, powered by the 7A engine, in commercial, freight and business aviation editions.

Explore the service ›
Risk and governance

AI Governance and Resilience

Governance wrapped around every layer of intelligent systems, from model behaviour to board accountability and ISO 42001.

Explore the service ›
Next step

Test the joints before a disruption does.

Ask us for a resilience maturity assessment; the gaps between your programmes will be more revealing than the gaps within them.

Book a consultation
All consultations are treated with strict confidentiality.