Resilience Leadership Newsletter – News from the World of Business Continuity – #1-2026
Happy New Year to Italy’s Resilience Leadership!!
As the new year begins, we would first like to extend our best wishes for 2026 to the entire community of business continuity and organizational resilience professionals.
A wish that, inevitably, is accompanied by a sober but necessary reflection. The year began, in fact, with deeply shocking news, even on an emotional level. The fire that occurred in Crans-Montana, a renowned ski resort, within a setting one would expect to be safe, regulated, and technologically advanced, claimed the lives of dozens of very young people. An event that is striking not only for the severity of its consequences, but for what it represents: the manifestation of a risk that was wrongly considered improbable, if not downright unthinkable.
This situation is compounded by an equally complex and troubling international landscape, marked by the persistence and spread of both old and new conflicts, geopolitical instability, and growing difficulties for public and private organizations to operate in predictable and controllable environments.
These are two distinct levels—the local and the global—that nevertheless converge on certain fundamental considerations. In the case of Crans-Montana, the themes of training, preparedness, risk awareness, and appropriate behaviors emerge as key priorities: a topic we will revisit later in one of the sections of this issue. On the international level, the themes of organizational resilience, dependence on third parties, the fragility of supply chains, and companies’ ability to adapt to rapidly and continuously changing scenarios are once again central.
Our job, as risk and business continuity professionals, is not to simply endure these events or view them as unfortunate exceptions. Rather, it is to analyze them, understand them, assess their implications, and turn them into opportunities for learning, improvement, and strengthening organizational systems.
It is in this spirit that we continue on our journey, and it is in this spirit that this new issue of the newsletter takes shape.
Risk&Resilience Outlook
World Economic Forum – The Global Risks Report 2026
In each issue of our newsletter, we want to reserve space for a publication that we believe is particularly significant to the community of business continuity, risk management, and organizational resilience professionals. Reports and analyses that are not intended to make predictions, but to help read the context, understand the dynamics at work, and reflect on the practical implications for organizations.
In this issue, we have chosen to focus on one of the world’s leading publications: theWorld Economic Forum’s Global Risks Report 2026.
A world on the brink of permanent instability
The report’s underlying message is clear: uncertainty is no longer the exception, but rather the structural condition in which governments, businesses, and institutions operate. More than half of the experts surveyed anticipate a “turbulent or stormy” global environment in both the short and medium-to-long term. The World Economic Forum explicitly refers to an “age of competition,” characterized by geopolitical fragmentation, the weakening of multilateral mechanisms, and growing difficulties in international cooperation.
The most significant global risks in the short term
In the short term, the risks perceived as most critical are dominated by geopolitical and geoeconomic factors. In particular, geoeconomic competition—defined as the use of economic tools—such as sanctions, tariffs, and technology restrictions—as actual levers of pressure and conflict between states—is emerging as a major concern. This is compounded by armed conflicts between states, which continue to pose a systemic threat, with direct impacts on energy, trade, and supply chains.
Alongside these “traditional” risks, the report highlights the growing significance of less visible but equally destabilizing factors: disinformation, social polarization, cyber risks, and the first adverse effects associated with the large-scale adoption of artificial intelligence. These risks not only affect information systems but also undermine trust, social cohesion, and organizations’ decision-making capabilities.
A Long-Term Perspective: Environmental and Systemic Risks
When we broaden the time horizon, the picture changes but does not become any less complex. In the long term, environmental risks dominate: extreme weather events, loss of biodiversity, critical changes in natural systems, and resource scarcity. These risks are no longer perceived as distant possibilities, but as structural factors destined to permanently influence infrastructure, supply chains, and business models.
At the same time, technological risks—particularly those related to artificial intelligence—are showing the most significant increase in both the short and long term, indicating growing concern about unintended consequences for employment, security, and governance.
The implications for the Italian context
A country-by-country analysis shows that, for economies such as Italy’s, global risks translate into very real challenges: economic slowdown, inflation, infrastructure fragility, dependence on suppliers and third parties, cyber risks, and supply chain disruptions. Added to these are social factors, such as polarization and loss of trust, which indirectly affect the operational stability of organizations.
A useful read for anyone involved in business continuity and resilience
For business continuity and resilience professionals, the 2026 Global Risks Report reinforces a concept that has become central: risks no longer operate in isolation. On the contrary, they combine, amplify each other, and spread rapidly from one area to another.
This requires a shift in perspective: from managing individual threats to understanding interdependencies, from reactive responses to structured preparedness, and from mere regulatory compliance to a genuine capacity for adaptation. In this sense, the report does not offer ready-made solutions, but rather encourages deep reflection on how to rethink models of resilience in an increasingly complex and competitive world.
At the top of the Resilience Manager’s list.
Climate Change!
If we were to identify one of the main concerns shared byresilience managerstoday, we could hardly overlook climate change. Not as an abstract concept or an environmental issue in the broadest sense, but as a set of concrete changes in the operating conditions under which organizations find themselves working.
When we talk aboutclimate change, we must first and foremost consider how the characteristics of our regions are changing: an increase in the frequency and intensity of extreme weather events, flash floods, flooding, and landslides. These phenomena expose factories, warehouses, critical infrastructure, and transportation networks to risks that, until just a few years ago, were considered marginal or statistically insignificant.
Alongside the effects on the local area, the implications for plant design and operations are becoming increasingly apparent. Increasingly intense and prolonged heat waves are putting a strain onair conditioning and cooling systems, which are often designed based on climate data that is now outdated. In many industrial settings, it is necessary to review the capacity, redundancy, and operating logic of HVAC systems to ensure process continuity and personal safety.
Rising temperatures also have a direct impact onelectrical systems. Higher loads, more demanding operating conditions, and increased thermal stress can lead to overloads, accelerated component degradation, and an increased risk of failure. This calls for a reevaluation of electrical panels, transformer substations, and ventilation and heat dissipation systems—factors often overlooked in traditional risk analyses.
For somesupplychains, climate change ultimately introduces a critical variable affectingsupply continuity. This is the case, for example, in the food industry, where extreme weather events can compromise production areas, reduce yields, disrupt established supply markets, and trigger sudden cost increases. Organizations are thus forced to explore alternative suppliers, new markets, and untested sourcing strategies.
It’s true: these changes don’t happen overnight. But it’s also true that they’re happening quickly, and the most obvious signs are already plain for all to see, particularly in the form ofan increase in extreme weather events.
For the risk manager, all of this translates into a clear need: to systematically reassess risks, taking into account not only technical and operational aspects, but also financial and insurance considerations. In light of new laws and regulations that introduce or strengthenthe requirement to cover catastrophic risks, it becomes essential to verify whether such risks have been properly identified, assessed, transferred, and insured.
Climate change is no longer a future scenario: it is a current reality that directly affects the resilience of organizations. And it is, without a doubt, one of the concerns keeping resilience managers up at night.
Professional development
Upcoming Continuitaly courses – DRI Italy – DRI France – NFPA
Business Continuity Management – Certification Course – DRI Italy
January 28–29, 2026 – Online – Italian
Intensive course on the principles and practices of BCM.
Learn more
Business Continuity Management – Certification Course – DRI France
January 28–29, 2026 – Online – French
Intensive course on the principles and practices of BCM.
Learn more
Cyber Resilience – Certification Course – DRI Italy
March 3-4, 2026 – Online – Italian
Intensive course on cyber risk management.
Learn more
Business Continuity Management – Certification Course – DRI Italy
March 10-11-17-18, 2026 – Online – Italian
In-depth course on BCM principles and practices.
Learn more
Business Continuity Management – Certification Course – DRI France
April 14-15, 2026 – Online – French
Intensive course on BCM principles and practices.
Learn more
Business Continuity Management – Certification Course – DRI France
April 14, 15, 21, and 22, 2026 – Online – French
An in-depth course on the principles and practices of BCM.
Learn more
NFPA 13 – Standards for Sprinkler Systems
May 11-12-13, 2026 – In-person – Milan
Official NFPA course dedicated to the design of sprinkler systems.
Learn more
NFPA 20 – Standards for Fire Supplies
May 14-15, 2026 – In Attendance – Milan
Official NFPA course dedicated to the design of fire supply systems.
Learn more
It really happened! Operational reflections from real cases
Crans-Montana
This column is devoted to the analysis of real events, with the aim of stimulating responsible and future-oriented thinking. In this case, it is particularly difficult to write about it, but avoiding any comparison with what happened would be neither helpful nor fair.
Regardless of individual responsibilities or the judicial investigations that will need to be conducted by the relevant authorities, certain events call for immediate reflection among those involved in risk management, safety, and organizational resilience. What happened in Crans-Montana is one such event. Among the many aspects that could be analyzed, there is one that deserves particular attention from a technical standpoint:the use of combustible insulation materials. In this specific case, it was not thermal insulation but acoustic insulation. However, the principle remains the same.
The material used—aplastic foam, possibly polyurethane-based—played a decisive role in the development and rapid spread of the fire. This is by no means a minor issue. Combustible plastic materials continue to be marketed and widely used, both in industry and in residential construction, in the form of sandwich panels, cladding, wall linings, drop ceilings, or room dividers, often for reasons of cost, ease of installation, or insulation performance. In many cases, these solutions are adopted without a full understanding of the risks involved, or worse, by ignoring them entirely or assuming that such risks are negligible. The reality is different.The use of combustible insulation materials—especially when not strictly necessary—can lead to unforeseen fire scenarios, with rapid progression, the production of toxic fumes, and conditions rendering the space uninhabitable in a very short time. This is exactly what happened in Crans-Montana. In the industry, it is not uncommon to encounter similar situations: cold storage rooms made with plastic-core sandwich panels, internal partitions constructed with combustible materials, and roofing and cladding that, in the event of a fire, become a risk multiplier rather than a neutral element. Often these materials have been in use “for as long as anyone can remember” and are no longer questioned.
The point to bring to the CEO’s attention is therefore simple, but by no means trivial:whenever evaluating an insulation material—for roofs, walls, room partitions, or acoustic and thermal applications—choosing non-combustible or certified non-combustible solutions, even if more expensive, is a necessary step. Not only in terms of personal safety, but also of operational continuity, asset protection, and risk sustainability in the medium to long term. It is fair to say that if the material used for acoustic insulation in the Crans-Montana venue had been non-combustible, we likely would not be here discussing this today. This observation, however uncomfortable, is one of the clearest lessons this tragedy teaches us. Other aspects—escape routes, overcrowding, emergency management—must be rigorously and impartially analyzed by the competent authorities. But when it comes to materials, especially in industrial and infrastructure contexts, responsibility already lies with those who design, manage, and make decisions. And that is why it is worth stating clearly: it really did happen.
And yes, it is a topic worth discussing—again.
Regulatory news to monitor
Focus on Artificial Intelligence
This issue makes its focus on regulatory developments clear from the outset: Artificial Intelligence. This is no longer an emerging topic, but a regulated field that will become fully operational for many European and Italian organizations in 2026.
The primary reference isRegulation (EU) 2024/1689, known as the AI Act, published in the Official Journal of the European Union in 2024. The regulation introduces a risk-based approach and provides for phased implementation: following the initial obligations that took effect in 2025 (prohibitions on certain practices and AI literacy requirements), August 2, 2026, is a key date, as most of the obligations will become fully applicable to providers and users of artificial intelligence systems, particularly those classified as high-risk.
For certain specific categories, which are incorporated into products already subject to regulation, longer transition periods are provided for, extending through 2027. In recent months, a debate has also emerged at the European level regarding the possible simplification of the implementation of the AI Act. In November 2025, the Commission presented a proposal for action under the so-called “Digital Omnibus on AI” (COM(2025) 836), which could result in a postponement of certain obligations for high-risk systems. It is important to emphasize that this is, at present, merely a proposal: the overall direction of the regulation remains unchanged, and the issue of AI governance remains central for 2026.
At the national level, Italy has adopted its own framework law through Law No. 132 of September 23, 2025, which entered into force in October 2025 and introduces provisions and grants the Government authority regarding artificial intelligence. The law does not replace the AI Act, but rather complements its implementation by establishing a national framework and paving the way for future implementing measures.
Alongside legislation, technical standards will play an increasingly important role, as they enable regulatory requirements to be translated into concrete and verifiable processes. In this context, the primary reference isISO/IEC 42001, published internationally in 2023 and adopted in Europe and Italy as UNI EN ISO/IEC 42001:2024, which defines a comprehensive artificial intelligence management system, following a logic similar to other ISO systems. This is complemented byISO/IEC 23894, a guide to AI risk management (adopted as UNI ISO/IEC 23894), as well as supporting standards such asISO/IEC 22989(terminology and concepts) and ISO/IEC 23053 (framework for machine learning systems).
For organizations, the message is clear: by 2026, the focus will not only be on formal compliance with the AI Act, but on the ability to demonstrate governance, risk management, accountability, and the integration of AI into business processes.In this sense, European regulations and ISO/UNI standards are not alternative paths, but complementary tools for building a credible and sustainable approach to the use of artificial intelligence.
The technical corner
Recovery Point Objective (RPO): Much More Than Just an IT Metric
In the previous issue of the newsletter, we dedicated the technical section to the topic of backup, introducing the evolution of the traditional 3-2-1 approach toward the 3-2-2-1-1-0 model. In this issue, we return to the topic of data, focusing on a concept that is often mentioned but not always truly understood or applied: theRecovery Point Objective (RPO). The Recovery Point Objective represents the maximum amount of data an organization is willing to lose following an incident. In other words, it answers a question that is simple only on the surface: how far back in time can I go without unacceptably compromising the business? The RPO is not an IT decision.
One of the most common mistakes is to view RPO as apurely technical metric, determined solely by the capabilities of backup systems or available backup windows. In reality, RPO isfirst and foremost a business decision.
It is up to business owners to determine how much data can be lost, which processes are most critical, and what operational, financial, or reputational consequences would result from the loss of hours, minutes, or even a few seconds of data. The role of IT and the business continuity function is to translate these needs into sustainable technical solutions, not to determine them independently. RPO and the actual quality of backups. Defining an RPO on paper is not enough if the backups are not actually protected. And this is where the connection to the 3-2-2-1-1-0 approach becomes crucial.
An RPO that appears to be very “aggressive” loses all meaning if:
- the copies are stored at the same location as the fire or flood scenario;
- the backups are online and vulnerable to a ransomware attack;
- the production hardware and the backup hardware share the same vulnerabilities;
- There are no offline, immutable, or physically separate copies.
In such cases, there is a risk of considering copies to be valid when, in reality, they would be destroyed or compromised by the very same event that affects the primary systems. This is why the 3-2-2-1-1-0 model is relevant to RPO. The 3-2-2-1-1-0 model reinforces the concept of RPO because it introduces requirements that go beyond the mere number of copies:
- 3 copies of the data, to reduce the likelihood of simultaneous loss;
- 2 different platforms, to mitigate technological failures;
- 2 off-site copies, physically separate from the primary site;
- 1 offline or immutable copy that cannot be tampered with;
- 0 backup errors, thanks to regular checks and tests.
Only when these conditions are met can the stated RPO be considered credible. The RPO as the result of a structured dialogue. An effective RPO stems from a structured dialogue between:
- business owner;
- EN;
- cybersecurity;
- risk management;
- insurance (particularly when cyber or property coverage is included).
The goal is not to set a fixed number once and for all, but to review it periodically in light of changes in processes, data volumes, threats, and regulatory requirements.
In short, theRecovery Point Objectiveis not merely a technical metric. It is a statement of loss tolerance that must align with the company’s strategy, be supported by an appropriate backup architecture, and be validated over time. Everything else is merely an illusion of security.
Insight&Inspirations
Suggestions of the month
Suggestions of the month
In this column, we continue to point out content that we find useful not so much for acquiring new knowledge but for refining the way we read risk, uncertainty, and strategic decisions in complex contexts.
Recommended reading: *How Big Things Get Done* – Bent Flyvbjerg, Dan Gardner.
Published in 2023, this book has quickly become a go-to resource for those dealing with complex decision-making, large-scale projects, systemic risk, and execution risk.
By analyzing thousands of infrastructure, industrial, and technology projects, the authors demonstrate how irrational optimism, cognitive biases, and weaknesses in decision-making processes are among the main causes of failures, delays, and spiraling costs.
This book is particularly recommended for professionals in the fields of resilience and enterprise risk management, as it helps shift the focus from crisis management to the quality of decisions made beforehand—a key element of any resilient organization.The book is available in print and as an ebook at major online retailers (Amazon, digital bookstores) and is also easily available as an audiobook on major streaming platforms.
Recommended podcast: McKinsey on Risk – McKinsey & Company.
McKinsey on Risk is a podcast dedicated to topics such as enterprise risk management, resilience, geopolitics, cyber risk, artificial intelligence, and supply chain management, with a strategic focus aimed at CEOs, boards, and senior leaders. The episodes combine recent research, real-world case studies, and high-level insights, while maintaining a pragmatic, decision-oriented approach. The podcast is available on major streaming platforms, including Apple Podcasts (iPhone), Spotify, and Google Podcasts, and can also be easily accessed via the McKinsey website.
Updates from National Fire Protection Association (NFPA)
News from the international Fire Safey community
As a member of theAuthorized Education Networkand an authorized NFPA training partner in Italy, we consider it part of our role to inform the professional community about the main news and developments coming from the NFPA world, with a focus on the technical, regulatory and operational impacts for companies and professionals.
TheNational Fire Protection Association (NFPA)is an international nonprofit organization and a global reference point for fire safety, life safety, and asset protection. Through the development of technical codes and standards, research, education and outreach activities, NFPA has been contributing to fire risk reduction and resilience in organizations worldwide for more than a century.
In recent months, the NFPA has introducedsignificant updatesin both regulatory and technical areas, reaffirming its strategy of ensuring that standards are increasingly aligned with the technical and operational complexity of today’s industrial and infrastructure environments.
One key development is the launch ofNFPA LiNK 3.0,the new version of the digital platform for accessing NFPA codes and standards. The platform integrates advanced AI-based features—called CASI (Codes and Standards Intelligence)—that allow users to query regulatory content in natural language, obtaining contextualized responses consistent with official references. This is complemented by operational tools for annotations, checklists, customizable dashboards, and collaboration, with the aim of supporting the daily application of standards by designers, risk engineers, and safety managers.
Official insights:
https://www.nfpa.org/about-nfpa/press-room/news-releases
https://www.nfpa.org/products/nfpa-link
On the strictly regulatory front,the NFPA has also published the new 2026 edition ofNFPAStandard855, which addresses the safety of energy storage systems (ESS).The update introduces more structured requirements for emerging storage technologies, strengthening measures to prevent and mitigate thermal runaway, design and compartmentalization criteria, emergency response plans, and the use of large-scale fire testing (LSFT). This standard continues to be adopted as a benchmark best practice even outside the United States, particularly in industrial, logistics, and infrastructure projects characterized by high energy density and operational interdependencies.
Official references:
https://www.nfpa.org/codes-and-standards
https://www.nfpa.org/codes-and-standards/all-codes-and-standards/list-of-codes-and-standards/detail?code=855
Taken together, these developments demonstrate that the NFPA is operatingon two fronts:evolving technical content to address new technological risks and modernizing the tools used to access standards, with an increasingly integrated approach that encompasses operational resilience, risk management, and business continuity.
Updates from Disaster Recovery Institute International (DRI)
News from the global community of certified professionals in resilience
As the official Affiliate ofDRI International for Italy and France, we consider it an integral part of our role to inform the professional community about the most relevant developments coming from the DRI world, with a focus on methodological trends and concrete implications for organizations, practitioners and decision makers.
DRI Internationalis the global reference organization for the development of Professional Practices for Business Continuity Management, as well as for the training and certification of resilience professionals. Through methodological standards, applied research activities and international events, DRI has been contributing to the evolution of the business continuity and crisis management discipline worldwide for more than 50 years.
Recent updatesclearly highlight a growing focus on the role of artificial intelligence as an enabler—but also as a new source of complexity—in organizational resilience programs. The shared content highlights how AI is progressively being integrated into risk analysis, decision support, crisis information management, and scenario simulation, offering new opportunities for operational effectiveness. At the same time, the need tointegrate these technologies within a robust governance frameworkis reiterated,one that keeps human oversight, decision-making accountability, and awareness of the new technological dependencies introduced at the forefront.
A recurring theme concernsthe impact of AI on critical processes and third parties,with direct implications for business continuity, cyber resilience, and operational resilience. The adoption of intelligent solutions requires that BCM programs evolve to account for new scenarios of unavailability, systemic failures, and emerging risks, strengthening the integration between operational continuity, risk management, and crisis leadership. From this perspective, DRI’s Professional Practices are increasingly viewed as a dynamic tool focused on decision-making preparedness rather than mere document compliance.
These topics will also be the focus ofDRI’s annual global conference, scheduled for late February in Jacksonville, Florida, one of the leading international events for the resilience community. The event represents a key opportunity to discuss emerging trends, real-world cases, and evolving approaches to business continuity, reaffirming DRI’s role as a leading authority on the evolution of the field.
Those interested in learning more can visit the official DRI blog on Drive, which features articles and posts on the key current topics for resilience professionals:
https://drive.drii.org/
For information on our global institutional activities, visit www.drii.org
For information about our operations in Italy and France, please visit www.dri-italy.it and www.drifrance.eu
PhoenITx srl
Via Pietro Calvi, 2
20129 Milan, Italy
www.continuitaly.it
This post is also available in:
Would you like to find out more about our training programmes?
Discover the official international certification courses offered by DRI Italy and DRI France on Business Continuity and Cyber Resilience, or the NFPA courses on fire protection systems and all the other Continuitaly courses.














