Milan, March 20, 2026
Resilience: from technical discipline to systemic capability
The March issue of this newsletter opens with an increasingly obvious observation:
resilience is no longer a specialized function, but a cross-cutting and systemic competence called upon to confront increasingly complex and interconnected scenarios.
The contributions collected in this edition-from the DRI International Conference to the most recent regulatory and technological developments-converge on a common point: the reference context is changing more rapidly than the traditional tools with which we have interpreted it so far.
On the one hand,geopolitical developmentsshow how regional events can turn intoglobal disruptions, with impacts extending far beyond energy markets, touching supply chains, industrial production and business continuity.
On the other hand, technological developments-particularlyartificial intelligence-introducenew opportunities, but also new forms of risk, which requiregovernanceand controlmodelsthat are still being consolidated.
In parallel, the European regulatory framework, with the entry into force of DORA, NIS2 and transposition into national frameworks, marks a decisive step: digital resilience becomes a structured regulatory requirement, no longer a discretionary element.
Finally, technical standards and international professional communities-from NFPA to DRI-also reflect this transformation, evolving to incorporate new complexities, new risks and new responsibilities.
A change of perspective
If there is one element that all these issues have in common, it is the need to move beyond a linear approach to risk. Resilience today requires:
- ability to read interdependencies
- management of nonlinear scenarios
- Integration between technical, operational and strategic dimensions
In other words, it is no longer just about “protecting,” but about understanding and governing complex systems.
This issue was created with the aim of offering some insights in this direction:
not definitive solutions, but useful keys to navigate a rapidly changing environment.
Risk&Resilience Outlook
Allianz Risk Barometer 2026
DRI International Conference 2026: clear signals on the future of resilience
The DRI International Conference 2026, held in late February in Jacksonville, USA, once again proved to be one of the most relevant moments for the global business continuity and operational resilience community.
Beyond the quality of the event, what clearly emerges is a paradigm shift:
resilience is no longer a support function, but an integrated system that combines governance, technology, operational capacity, and decision-making under conditions of uncertainty.
Among the many sessions, some stood out for their ability to offer concrete and immediately applicable insights:
Cyber resilience as a design principle (Roberto Zegarra)
One of the strongest messages came from Roberto Zegarra’s session, which overturned a traditional assumption: it is no longer about avoiding breaches, but designing organizations that can operate even under compromised conditions. The concept ofMinimum Viable Enterprise (MVE)represents a concrete evolution of BCM: ensuring continuity of critical functions through resilient infrastructure, secure data, and predefined recovery sequences.
AI governance: from opportunity to requirement (Christopher Murphy)
The increasing adoption of artificial intelligence introduces new dimensions of risk, making the adoption of structured governance models essential. AI can no longer be treated as an isolated technology issue, but must be integrated into risk management and resilience frameworks, with a focus on transparency, accountability and model oversight.
Playbook: from theory to execution (Justin Kates)
A particularly concrete contribution came from Justin Kates, who proposed playbooks as an evolution of traditional plans. The shift is clear: from static documents to operational tools that can be used in real time during a crisis, reducing decision uncertainty and improving speed of response.
AI applied to business continuity (Beth Frasure)
Beth Frasure showed how artificial intelligence can be used pragmatically to support business continuity processes, from risk analysis to scenario generation to decision support. The key point is not automation, but the ability to increase the quality and speed of decisions while maintaining human oversight at critical moments.
Lessons from the field: managing a multi-agency event (Kevin Wowk)
Among the most impactful sessions, the real-world case presented by Kevin Wowk brought attention back to the complexities of real-world crisis management. In multi-agency and multi-jurisdiction contexts, factors such as coordination, communication, and resource management become crucial. Resilience, in these scenarios, depends primarily on people’s ability to make effective decisions under pressure.
Takeaway from the conference
If there is a common thread emerging from this edition, it is that resilience is evolving rapidly:
- From documentation to actual operational capability
- From prevention to managing the inevitable
- From separate approaches to integration of cybersecurity, AI, and operational risks
A transformation that makes it increasingly clear that resilience is now a strategic competence, no longer just a technical one.
At the top of the Resilience Manager’s list.
Resilience vs. AI
Top of the Resilience Manager’s list: governing AI before it’s too late
If there is one topic that is rapidly climbing the priority list for those concerned with resilience, it is undoubtedly artificial intelligence. Not so much because of its potential-now obvious-but because of the speed with which it is entering business processes, often without an adequate governance, control and resilience framework.
It is a message that also emerged clearly during the recentDRI International Conference 2026 in Jacksonville,where several speakers highlighted how AI is introducing new operational dependencies and new forms of risk that are still unstructured in traditional models.
The key point: AI is already in critical processes
The most common mistake today is to consider AI as an innovation or IT issue. In reality, AI-based systems are already:
- influencing operational decisions
- supporting core processes
- Introducing dependencies on models, data, and suppliers
In other words: AI is already part of thebusiness continuity perimeter, although formally it often is not yet.
ISO/IEC 42001: from technical standard to strategic lever
In this context, ISO/IEC 42001:2023 represents the first real attempt to bring order by introducing a structured and certifiable artificial intelligence management system (AIMS). As highlighted by several contributions from experts and practitioners, this standard has a key function:to translate the principles of the AI Act into concrete organizational practices.
In other words:
- AI Act says what needs to be done
- ISO 42001 helps you understand how to do it
Not surprisingly, the standard covers such central elements as:
- governance and accountability
- AI risk management
- transparency and traceability
- model life cycle control
And it integrates seamlessly with other already popular management systems, such as ISO 27001 and ISO 22301
Experts’ point: AI = strategic asset, not technology
Several practitioners are highlighting this shift in perspective. For example,Fabrizio Cirillihighlights how artificial intelligence is rapidly becoming a strategic asset for organizations, yet requiring new skills and, above all, a solid framework to be governed in a secure and transparent way. Similarly, other contributors highlight how ISO 42001 representsa true bridge between compliance and corporate governance,translating regulatory principles into concrete and auditable processes
The issue then is no longer technological, but organizational and strategic.
Real risk: new disruption scenarios
For a resilience manager, the question is not whether to adopt AI, but:
What happens when an AI system stops working properly?
Concrete examples:
- model drift and performance degradation
- incorrect but plausible outputs
- critical dependencies on AI vendors
- Absence of fallback or human supervision
These are not theoreticalrisks-they are new forms of operational disruption.
Integrating AI into resilience frameworks.
Thus, the key step is to treat AI as a critical component of the business system.
This implies:
- include it in the Business Impact Analysis (BIA)
- mapping dependencies (data, models, suppliers)
- define fallback strategies
- Testing nontraditional failure scenarios
- update playbook and crisis management
In short: bring AI inside the perimeter of resilience.
Takeaway
Artificial intelligence is no longer an emerging issue-it is already a structural component of operational risk. Standards such as ISO/IEC 42001 are a key step, but they do not solve the problem alone. For resilience practitioners, the real challenge is another:
transform AI from a source of ungoverned risk to a controlled and resilient element of the business system.
Professional development
Upcoming Continuitaly courses – DRI Italy – DRI France – NFPA
Upcoming professional training courses we deliver in Italy in collaboration withDRI InternationalandNFPA
Cyber Resilience – Certification Course – DRI Italy
March 3-4, 2026 – Online – Italian
Intensive course on cyber risk management.
Learn more
Business Continuity Management – Certification Course – DRI Italy
March 10-11-17-18, 2026 – Online – Italian
In-depth course on BCM principles and practices.
Learn more
Business Continuity Management – Certification Course – DRI France
April 14-15, 2026 – Online – French
Intensive course on BCM principles and practices.
Learn more
Business Continuity Management – Certification Course – DRI France
April 14-15-21-22, 2026 – Online – FrenchIn-depth course on BCM principles and practices.
Learn more
Business Continuity Management – Certification Course – DRI Italy
May 5-6, 2026 – Online – Italian
Intensive course on BCM principles and practices.
Learn more
NFPA 13 – Standards for Sprinkler Systems
May 11-12-13, 2026 – In-person – Milan
Official NFPA course dedicated to the design of sprinkler systems.
Learn more
NFPA 20 – Standards for Fire Supplies
May 14-15, 2026 – In Attendance – Milan
Official NFPA course dedicated to the design of fire supply systems.
Learn more
Cyber Resilience – Certification Course – DRI Italy
May 19-20-26-27, 2026 – Online – Italian
In-depth course on cyber risk management.
Learn more
It really happened! Operational reflections from real cases
WAR
Geopolitics and resilience: beyond oil prices, the systemic iceberg
The recent evolution of the geopolitical environment in the Middle East-with compromised flows through the Strait of Hormuz and attacks on energy infrastructure-is bringing scenarios that, until a few months ago, were classified as extreme stress scenarios back to the forefront. The markets’ immediate reaction is well-known and widely visible: rising oil prices.
However, as pointed out by numerous analysis centers, this representsonly the surface manifestation of a much more complex dynamic.
Discontinuity of flows and limited capacity for adaptation
According to analysis by theCenter for Strategic and International Studies (CSIS), even with alternative routes and bypass infrastructure, “the global capacity to offset a significant reduction in flows through the Strait of Hormuz remains structurally limited.” In operational terms, this implies that the global energy system does not enter a binary condition (availability vs. unavailability), but a state ofprogressive degradation, characterized by:
- intermittent availability
- volatility in delivery times
- difficulty in planning
Economic and industrial effects: beyond price signal
Allianz Tradeassessments indicate that under severe scenarios, crude oil prices could exceed $100-130 per barrel, with direct effects on inflation and macroeconomic stability. However, as also pointed out byReuters, the most significant impact occurs in physical markets:refineries reducing run rates, forced reorganization of shipping lanes, increased insurance premiums, and reduced available logistics capacity.
In this context, price is not the main problem, but theanticipatory signal of a broader systemic tension.
Industrial interdependencies: the unseen level of risk
As noted byS&P Global, the consequences quickly extend beyond the energy sector, affecting seemingly distant industrial supply chains. One significant example involvestechnical gases, including helium, which is essential for semiconductor production and advanced medical and scientific applications. The geographic concentration of production and dependence on energy infrastructure make these supply chains particularly vulnerable. In similar terms, as highlighted byChatham House, reduced energy flows also directly impact:
- petrochemistry
- fertilizers
- intermediate materials
with indirect effects on agriculture, manufacturing and food security.
LNG, energy and business continuity
S&P Global‘s analysis also indicates that prolonged impairment of the Strait of Hormuz may result in a significant reduction inLNGflows, with direct impacts on:
- energy availability
- industrial competitiveness
- business continuity in energy-intensive sectors
In this scenario, the risk to organizations is no longer exclusively economic, but becomesoperational and structural.
From energy crisis to demand management
A particularly relevant and often overlooked element concernsenergy demand management measures. TheInternational Energy Agency (IEA)has repeatedly pointed out, including in recent publications, that in contexts of energy stress, governments can use consumption reduction tools, including:
- diffusion ofsmart working
- operational limitations for energy-intensive industries
- reductions in available power
- Scheduled management of loads (including micro-interruptions)
These measures, which have already been observed in recent contexts, represent a crucial shift: the crisis is no longer managed only on the supply side, but also on thedemandsideand organizational behavior.
Implications for the Resilience Manager
In light of this evidence, the role of the resilience manager takes on a different dimension: no longer focused exclusively on managing events, but onanticipating systemic fragilities.Three lines of thinkingturn out to be particularly relevant:
1. Mapping real interdependencies
As the CSIS and S&P Global analyses implicitly point out, critical dependencies are not always visible.
The question to ask is:
which components of our operations depend, directly or indirectly, on energy or logistics supply chains exposed to this crisis?
2. Operational capacity under degraded conditions
In a context of flow reduction and demand management, it becomes essential to understand:what is the minimum sustainable level of operation in the presence of energy, logistical, or regulatory constraints?
This includes scenarios such as:
- extended or mandatory remote work
- Re-balancing of production capacity in areas less exposed to energy shortages
- Constraints on energy consumption at certain times of day
3. Validity of alternative strategies
As noted by multiple analysts, many alternatives exist only theoretically.
So the question is:
are our continuity and fallback strategies really actionable, or do they depend on conditions we have never tested?
Conclusion
The evidence converges on one point: the crisis is not the rise in the price of oil, but thefragility of the interdependencies that that price reflects. In an environment of flow discontinuities, energy constraints and demand-side interventions, resilience is measured in the ability to operate under non-ideal, prolonged and systemic conditions.
he price of oil is an indicator.
Resilience is also measured in the ability to perform at its best when that indicator signals that the system is entering a crisis.
Regulatory news to monitor
Circular 285
Regulatory news: Circular 285 fully enters the DORA era
La Bank of Italy Circular No. 285has for years represented the main regulatory reference for the organization, risk governance and internal control systems of Italian banks.
It is, in fact, the regulatory lintel through which prudential supervisory principles are translated into operational requirements, with direct impacts on governance, ICT, business continuity and overall resilience of intermediaries.
This is precisely why each of its updates is never merely formal, but reflects a substantive evolution of the regulator’s expectations.
Among the most relevant regulatory developments in recent weeks in Italy is certainly worth mentioning the51st update, published by act of February 3, 2026 and in the Official Gazette on February 18, 2026. The act implements the Regulation (EU) 2022/2554 (DORA) and Directive (EU) 2022/2556,amending in particular Chapter 4 “The Information System” and Chapter 5 “Business Continuity,”as well as some reconciliations in the introductory provisions, in Chapter 1 on authorization for banking and in Chapter 3 on internal controls.
The most important difference from the previous framework is conceptual even before it is editorial. The “previous” framework on ICT and continuity,essentially built on the 40th update of 2022,had been shaped to implement EBA guidance on ICT and security risk management. With the 51st update, however, the Bank of Italyperforms a real reorganization:many national sections that regulated in detail ICT governance, ICT and security risk management, ICT information and operations security, ICT project and change management, and ICT service outsourcing are repealed and replaced by a direct reference to the now directly applicable DORA provisions and related RTS/ITS. In other words, Circular 285 ceases to be the “primary” text of detail on these issues and becomes the national point of connection with the European framework.
I refer to DORA
This change in regulatory architecture is most visible in Chapter 4, which now opens by stating that the subject matter is directly governed by DORA and its delegated acts, including those on contractual arrangements for ICT services in support of essential or important functions and on the subcontracting of such services. This is also a very operationally relevant step, because it reinforces the idea that compliance can no longer be read only from a local perspective:for ICT governance, third-party risk, significant incidents and contractual safeguards, the main reference is now European.
Another point of note is thatthe discipline on the data management system, which is not covered directly by DORA, is retained and relocated to Chapter 3 on internal controls, with a special Annex D. This is a consistent choice: what remains in 285 is what continues to be an organizational and internal control oversight of the bank, while the strictly ICT/digital resilience part is absorbed into the DORA perimeter.
Operational continuity
On the business continuity front, the 51st update amends Chapter 5 to align it with the changes introduced by the DORA Directive.Here the difference from the previous version is very stark: the ICT business continuity requirements are removed from the Circular, because they are now directly presided over by DORA and the related delegated regulation on IT risk management.Instead, the core “general business” business continuity requirements,applicable to banks as operators,remain, while digital continuity is definitively Europeanized. Banca d’Italia also clarified that it has not yet amended Annex A, Section III, on systemically important processes, for the time being, because broader investigations involving financial operators other than banks are underway.
Then there is a less conspicuous but important aspect: the section on payment service-specific provisions has been updated in light of the EBA Guidelines of February 11, 2025, keeping in place, alongside DORA, the relevant references for managing the relationship with payment service users. This confirms that the final set-up is not a pure “one-for-one” replacement, but a regulatory mosaic in which DORA becomes the backbone, while some vertical principals remain anchored in specialized sources such as PSD2/EBA.
Comments and opinions
Outside commentators also converge on this reading.Banking Lawdescribes the intervention as a “reordering” of the framework in light of DORA and highlights precisely the repeal of the old national sections on governance and ICT risk, replaced by references to the European regulation and delegated acts.Studio Marchetti, in turn, points out that the parts that are no longer consistent with the new European framework are removed, whileCesare Gallotti, from an information security perspective, notes that the most significant novelties are concentrated in Title IV and that Chapter 4 now refers substantially in full to the DORA requirements and related RTS/ITS.
Conclusion
In practical terms, the message for banks, supervisory functions, ICT risk managers, and continuity managers is clear:DORA does not simply add to Circular 285, but redesigns its center of gravity.285 remains essential as a national supervisory framework, but for digital resilience, ICT outsourcing, incident management and ICT continuity, the center of gravity has now shifted to the European body of law. The new provisions came into effect the day after publication in the Official Gazette,while for changes to Chapter 5 Bank of Italy has set aside six months for compliance.
The technical corner
ESFR: what is it all about?
ESFR – when the sprinkler stops “controlling” and starts “suppressing”
In the world of fire protection, few acronyms are as relevant asESFR (Early Suppression Fast Response).This is an advanced type of sprinkler designed not simply to control a fire, but to suppress it quickly in its early stages, before it can develop and involve the entire compartment.
What distinguishes an ESFR from traditional sprinklers
Traditional sprinklers (so-called control mode) have a clear goal: to contain the fire until manual intervention
ESFRs, on the other hand, introduce a paradigm shift: direct and massive attack on the fire, with the goal of extinguishing or drastically reducing it very quickly
This is made possible by three key features:
- Fast Response: very rapid activation thermal bulb
- High flow rate: large amounts of water delivered in a short period of time
- Optimized distribution: discharge pattern designed to penetrate the thermal column
Why ESFRs have become so important
Their use is closely linked to the evolution of logistics and industrial layouts. Modern warehouses with:
- high altitudes
- intensive storage
- high-calorific plastic materials
often make traditional solutions insufficient.
ESFRs allow, in many cases:
- Avoid heads inside the shelves
- simplify the system
- increase the level of security
The role of standards
The design and use of ESFRs are strictly defined by National Fire Protection Association standards.
In particular:
- NFPA 13
- NFPA 25
- NFPA 20
It is precisely NFPA 13 that defines in detail:
- design criteria
- limits of application
- storage configurations
- Hydraulic parameters (K-factor, pressure, density)
What about in Europe? The reference to the EN standards
Even in the European context, the topic of sprinklers-including rapid response sprinklers-is governed by established technical standards, in particularEN 12845. However, it is important to note that:
- the EN standard now adopts a more traditional approach (control mode)
- ESFR applications are not developed with the same level of detail found in NFPA
In practice:ESFRs are also recognized and usable in Europe,but their design often refers directly to NFPA logics and criteria, especially in more complex industrial and logistics contexts.
This explains why, in many international or insurance projects, a hybrid approach is observed:
- European regulatory compliance
- engineering design based on NFPA standards
Warning: they are not a universal solution
Despite their effectiveness, ESFRs are not applicable in every context. Their proper implementation requires:
- detailed risk analysis
- compatibility with layouts and goods
- Strict adherence to regulatory limits
Uncontrolled changes (e.g., storage changes) can affect performance.
Takeaway
ESFRs represent one of the best examples of evolution in fire protection:
from systems designed to “contain” to systems designed to intervene decisively and immediately.
But it is the combination of:
- available technology
- standards (NFPA and EN)
- proper design
to determine the true level of security.
Insight&Inspirations
Suggestions of the month
Suggestions of the month
In this column, we continue to point out content that we find useful not so much for acquiring new knowledge but for refining the way we read risk, uncertainty, and strategic decisions in complex contexts.
Book of the Month: The Resilient Enterprise – Yossi Sheffi
An evergreen classic that explores how organizations can deal with complex disruptions, from logistical crises to global shocks.
Particularly relevant today, in light of geopolitical tensions, because it introduces a key concept: resilience is not just protection, but the ability to adapt quickly to interconnected and unstable systems.
Podcast of the Month: CSIS – “The Trade Guys”
An extremely useful podcast for understanding the dynamics between geopolitics, international trade, and the real economy. In a context marked by energy tensions and possible disruption in global flows, it offers a concrete reading of how regional crises and political decisions translate into operational impacts for businesses and supply chains. Resilience today requires a vision that goes beyond corporate boundaries: understanding how global events translate into local operational impacts is now an essential skill.
Updates from National Fire Protection Association (NFPA)
News from the international Fire Safey community
NFPA 70 (NEC 2026): a key update for those operating in the U.S.
Among the most notable updates in the National Fire Protection Association’s 2026 cycle is the publication of the new edition ofNFPA 70 (NEC 2026).This is the gold standard for thedesign and construction of electrical systems in the United States, adopted-with possible local adaptations-in almost all jurisdictions. In practical terms, the NEC is not just a technical guideline, but a mandatory code, compliance with which is a necessary condition for:
- authorizations
- testing
- operation of facilities
Because it is also relevant to many Italian companies that:
- design facilities
- realize establishments
- provide machinery or systems in the United States
Knowledge of the NEC is not optional, but essential.
A plant that complies with European standards (EN/IEC) does not automatically comply with the NEC.
Differences may include:
- mode of installation
- protection criteria
- classification of areas
- electrical safety requirements
With concrete impacts on:
- project times
- need for re-engineering
- costs
- Approvals from local authorities (AHJ – Authorities Having Jurisdiction).
The main directions of the 2026 edition
The 2026 edition of the NEC is part of an evolutionary journey that reflects the increasing complexity of modern electrical systems. Among the most relevant themes:
- Integration with energy storage systems and distributed generation
- Increased attention to electrical resilience
- Updates related to emerging technologies and digitization
- Reorganization of some sections to improve clarity and applicability
The common thread is clear:the electrical system is no longer a “passive” infrastructure, but a central element of operational resilience.
Operational implications
For those working on international projects, this translates into a very real need:
- Involve local expertise (US) from the initial stages
- Verify NEC compliance early in the design phase
- Avoiding “adapted a posteriori” approaches
In many cases, deviations between European and NEC standards emerge too late, with consequences for time and cost.
Takeaway
NFPA 70 (NEC 2026)is not simply a technical standard, but a key element in ensuring the viability and operational compliance of projects in the United States.
Updates from Disaster Recovery Institute International (DRI)
News from the global community of certified professionals in resilience
As anticipated in the opening section of this newsletter, the recentDRI International Conference2026 confirmed the central role of the global resilience community in reading and interpreting emerging risks. Looking ahead to upcoming events, thenext edition of the conferencehas already been announced, to be heldFebruary 21-24, 2027, in Arlington, Texas.
New certification coming soon: focus on supply chain resilience
Among the most relevant announcements that emerged during the last conference, the launch-expected soon-of a new skills certification pathway dedicated to the supply chain resilience.
A very clear signal: supply chain resilience is becoming an autonomous and increasingly central competency within organizations.
This development is consistent with findings in other areas covered in this newsletter:
- growing exposure to geopolitical risks
- Increasingly complex global interdependencies
- Need for integrated approaches between operational risk, logistics, and continuity
Resilience is no longer a monolithic discipline, but an increasingly specialized set of skills. The supply chain now represents one of the main fronts on which the ability of organizations to withstand and adapt to complex scenarios will be played out.
PhoenITx srl
Via Pietro Calvi, 2
20129 Milan, Italy
www.continuitaly.it
This post is also available in:
Would you like to find out more about our training programmes?
Discover the official international certification courses offered by DRI Italy and DRI France on Business Continuity and Cyber Resilience, or the NFPA courses on fire protection systems and all the other Continuitaly courses.














