Milan, April 27, 2026

When energy stops being a certainty

For years we have built our operating, industrial, and even business continuity models on an implicit assumption: energy is always available.

  • Cost variable, sure.
  • Efficiency factor, no doubt.
  • But rarely operational constraint.

Today this assumption is no longer valid.

Geopolitical tensions, vulnerabilities in global energy routes, and increasing pressures on the European system are bringing energy back to the center of operational risk. Not as a simple economic driver, but as anenabling condition of operations itself.

In this context, talking about resilience necessarily means talking about energy.

This issue of our April newsletter was created precisely with the aim of reading this change from multiple perspectives.

In the middle section, we look at the European Union’s most recent guidance: not just emergency measures, but a real change in approach, calling for reducing, managing and rethinking energy consumption.

In the section “What Keeps the Resilience Manager Awake,” we take these issues to the ground, introducing increasingly less theoretical scenarios: prolonged power outages, logistical disruptions, weather-related operational limitations. Scenarios that do not end in one event, but develop over time, testing the ability of organizations to adapt.

The technical corner is devoted to this very transition: how to build and test these scenarios through tabletop exercises and structured simulations, moving from static plans to dynamic decision-making capabilities.

The regulatory section takes an in-depth look at developments related to the NIS2 Directive and ACN provisions, which strengthen the link between digital resilience and business continuity-a link that, increasingly, also comes through power availability.

Finally, in the thought leadership section, we review some of the most recent international publications that converge on a key point: risks are no longer isolated events, but interconnected systems. Energy, cyber, supply chain, and climate influence each other, amplifying impacts and reducing margins for prediction.

The common thread is clear: We are not entering an era of energy crises, but an era in which energy again becomes a structural constraint.

For organizations, this means one very concrete thing: It is no longer enough to be efficient.
You have to beable to continue operating even when energy is not fully available.

Happy reading!

Conrad Zana

corrado.zana@continuitaly.it

Risk&Resilience Outlook

Systemic resilience

Systemic resilience: when risks stop being events and become systems

In recent months, a number of leading international institutions have published analyses that, read together, outline a profound change: risk no longer manifests itself as an isolated event, but as a systemic and interconnected dynamic.

It is not an incremental evolution. It is a paradigm shift.

Cyber risk: from incidents to ripple effects

The most recent analysis by ENISA (European Union Agency for Cybersecurity) highlights an increasingly evident phenomenon:

“Cybersecurity incidents increasingly have cascading effects across sectors and borders.”

These are no longer circumscribed breaches. A single attack can generate:

  • Disruptions along entire digital supply chains
  • impacts on essential services
  • cross-border effects

ENISA also stresses:

“Interdependencies amplify the impact of cyber incidents.”

This is the key point: the vulnerability is not just in the technology, butin the interconnections.

A highly efficient and integrated system becomes, at the same time, highly fragile.

Supply chain: the invisible vulnerability

McKinsey & Company’s most recent analysis reinforces this picture, shifting attention to an often underestimated aspect:

“Most supply chain disruptions originate beyond tier-one suppliers.”

To wit:

  • the risk is not in the direct suppliers
  • But in later levels, often unmonitored

Added to this is a well-established fact: “Companies are experiencing supply chain disruptions lasting one month or longer every 1.4 years on average.”

The message is clear: disruptions are no longer rare events, butrecurring and structural ones.

More importantly, they are difficult to anticipate because they originateoutside the organization’s field of vision.

Energy: from economic variable to operational constraint

In its 2026 update, the International Energy Agency introduces a particularly relevant conceptual change:

“Energy security is no longer only about supply adequacy, but about system resilience.”

And again, “Disruptions in energy supply can have immediate operational consequences across industries.”

This passage is fundamental and totally agreeable. Energy is no more:

  • just a cost
  • o a competitive factor

But a platitude is reaffirmed: anecessary condition for operating

In other words: lack of energy not only impacts the margin, but alsostops the business.

The common thread: interdependent and unstable systems

If one reads these contributions together, a very strong convergence emerges:

  • cyber attacks spread beyond the organization
  • supply chains hide deep and unseen vulnerabilities
  • energy can directly limit the operational capacity

Summary:“Risks are no longer isolated events, but interconnected systems of disruption.”

This means that:

  • an initial event can generate nonlinear effects
  • the consequences are difficult to predict
  • propagation is often more relevant than the event itself

What changes for resilience

This scenario challenges a traditional approach to business continuity, based on:

  • identification of specific scenarios
  • definition of response plans
  • restoration in a defined time frame

Today, however, a different need emerges: to design organizations capable of operating even under degraded, incomplete and unstable conditions.

In other words:

  • Less emphasis on “restore quickly” to return to ‘business-as-usual’ condition
  • more emphasis oncontinuing to function anywayunder harsh and degraded conditions for a long period of time.

Conclusions

Organizations nolonger operate in complex environments, but in complex and unstable systems. In a complex system it is still possible to model, predict and optimize. In an unstable system, however, unpredictability is the dominant variable.

Resilience, today, is no longer just a protective function, but dominates adaptive capacity: the ability to continue operating even when conditions change faster than plans.

At the top of the Resilience Manager’s list.

Scenarios and tests

What keeps the Resilience Manager awake – From theoretical scenarios to operational stress tests

In recent months, a change in the way business continuity plans must be constructed has been emerging with increasing evidence. It is no longer a matter of covering “classic” events (fire, IT unavailability, site loss), but of preparing forprolonged, progressive and degraded scenarios.

In other words: not “on/off” events, but operating conditions thatworsen over time.

Three scenarios that are becoming realistic

  1. Prolonged blackout (48-72 hours)
  • Progressive depletion of backup systems
  • fuel supply difficulties
  • gradual loss of operational functionality

The critical point is not the initial interruption, buttime management.

  1. Interruption of logistics (1 week)
  • supply blockade
  • inability to ship
  • saturation of warehouses

The real risk is thecollapse of the operational chain, not the single event.

  1. Heat waves and operational limitations
  • restrictions on energy use
  • reduced ability to work
  • impacts on health, safety and productivity

Here an often ignored variable comes into play:the human sustainability of operations.

How to really build these scenarios

The quantum leap is all here.

1) Do not start from the event, but from the duration

Typical error:

  • “blackout” as an event

Correct approach:

  • blackout of4h / 24h / 72h

Why: the duration changes completely:

  • impacts
  • priority
  • decisions

2) Build the timeline of the scenario.

Each scenario should be developed in phases:

Blackout example:

  • 0-4 hours → emergency activation
  • 4-24 hours → stabilization
  • 24-72 hours → operational degradation
  • 72 hours → loss of production capacity

This allows:

  • Identify the real breaking points
  • Avoid overly “optimistic” plans

3) Mapping real dependencies

For each critical process:

  • energy
  • EN
  • people
  • suppliers
  • logistics

Key question, “what happens if this dependence is broken for X hours/days?”

4) Define different levels of acceptable operation (not just stop/go)

Traditional approach:

  • operational / non-operational

Evolved approach:

  • full operation
  • reduced operability
  • minimum operation
  • alternate still/activity
  • operation in prohibited and permitted time slots

This is critical for energy scenarios.

5) Review the scenarios in the BIA

In order to:

  • validate realistic RTOs
  • identify truly critical processes
  • highlight hidden dependencies

Many BIAs change dramatically when the “duration” factor is introduced.

6) Test progressive scenarios (not just shocks).

Typical tests:

  • fire
  • system loss

Advanced testing:

  • “2 days without power”
  • “4 days without logistics”

Here they emerge:

  • decision flows, authorization levels
  • critical organizational issues
  • undocumented limitations

7) Identify the breaking points

Each scenario should lead to a clear answer:

  • Under what conditions is the operation no longer sustainable?
  • What activities need to be stopped?
  • What decisions need to be made by management?
  • legal, compliance, etc. responsibilities?

Conclusion

The question is no longer “what happens if an event happens,” but “how do I manage the evolution of the situation and thus our operations over time?”

Professional development

Upcoming Continuitaly courses – DRI Italy – DRI France – NFPA

Upcoming professional training courses we deliver in Italy in collaboration withDRI InternationalandNFPA

Business Continuity Management – Certification Course – DRI Italy
May 5-6, 2026 – Online – Italian
Intensive course on BCM principles and practices.
Learn more

NFPA 13 – Standards for Sprinkler Systems
May 11-12-13, 2026 – In-person – Milan
Official NFPA course dedicated to the design of sprinkler systems.
Learn more

NFPA 20 – Standards for Fire Supplies
May 14-15, 2026 – In Attendance – Milan
Official NFPA course dedicated to the design of fire supply systems.
Learn more

Cyber Resilience – Certification Course – DRI Italy
May 19-20-26-27, 2026 – Online – Italian
In-depth course on cyber risk management.
Learn more

Business Continuity Management – Certification Course

DRI – June 8-9, 2026 – Online – English
Business Continuity Management intensive course with certification exam (BCP501).Learn more

Cyber Resilience – Certification Course

DRI – June 10-11, 2026 – Online – English
Cyber Resilience intensive course with certification exam (CRP501).Learn more

NFPA 13 – Standards for sprinkler systems.

June 29-July 7, 2026 – Online – Italian
Official NFPA course dedicated to sprinkler system design.Learn more

Business Continuity Management – Certification Course

DRI France – July 7-8, 2026 – Online – French
Business Continuity Management intensive course with certification exam (BCP501).Learn more

Cyber Resilience – Certification Course

DRI Italy – July 14-16, 2026 – Online – Italian
Cyber Resilience intensive course with certification exam (CRP501).Learn more

Complete and updated calendar

Regulatory news to monitor

ACN and NIS2: update

Normative Update – NIS2: ACN goes into operational detail with how to classify services

With the most recent communications published by the National Cybersecurity Agency, the implementation of the NIS2 Directive in Italy takes a decisive step: from defining the perimeter to operationally structuring the activities and services to be protected.

1) Listing and categorization: the real starting point.

The ACN has published how NIS2 subjects must:

  • Identify relevant activities and services
  • proceed to their categorization

This step is crucial because it concretely defines “what” is to be protected, even before the “how.”

Thus, it is not only a matter of being included in the NIS2 perimeter, but of:

  • Understanding which services are critical
  • Structure them in a manner consistent with regulatory obligations

2) A structured approach to classification

ACN guidance introduces a methodological approach that requires organizations to:

  • mapping in a systematic way:
    • services
    • activities
    • addictions
  • To distinguish between:
    • essential services
    • important services

Direct implication:cybersecurity becomes an exercise in shaping the organization, not just technical protection.

3) Direct connection with risk and business continuity.

This new requirement has an immediate impact on already known areas:

  • Business Impact Analysis (BIA)
  • risk management
  • business continuity

In particular:

  • categorization of services directly invokes the logic of critical functions
  • Imposes greater consistency between:
    • normative classification
    • operational priorities

4) Impacts on incident management and reporting

Classification is not a theoretical exercise:

  • determines:
    • which incidents must be reported
    • with what priority
  • influence:
    • response times
    • levels of escalation

Operational translation: without proper categorization, an NIS2 incident cannot be handled properly.

5) The significance for the legislature

NIS2 calls not only for protecting systems, but for understanding and structuring the services the organization delivers. This shifts the focus:

  • from assets → to services
  • from technology → to operability

Implications for organizations

For those involved, this means:

  • start quickly:
    • mapping activities
    • classification of services
  • align:
    • IT functions
    • operations
    • compliance
  • integrate:
    • NIS2
    • DORA (if applicable)
    • BCMS

In conclusion

The goal of NIS2 is not to implement controls, but to understand precisely what services should continue to operate, how, and why.

The technical corner

Tabletop and Desktop

Technical Corner- Tabletop and Desktop Simulation: how to design effective tutorials for energy scenarios

In today’s environment of possible prolonged disruptions in energy availability, organizations must go beyond simply making plans and begin toconcretely test their decision-making and operational capacity.

This is where so-calledtabletopanddesktop simulationcome in.

What is meant by “tabletop” and “desktop simulation”

In the language of business continuity:

  • Tabletopexercise
    discussed and guidedexercise, in which a group of participants analyze a scenario and make decisions in a structured way, without actual activation of systems.
  • Desktop simulation
    evolution of tabletop, more structured and realistic, in which:

    • the scenario evolves over time
    • “injects” (simulated events) are introduced
    • you test the consistency of decisions

Either way: you don’t test technology, you testorganizational and decision-making capacity.

What are they really for

According to the best practices ofISO 22398:2013 Societal security – Guidelines for exercises,
ISO 22361:2022 Security and resilience – Crisis management – Guidelines, DRI – Professional Practices for Business Continuity Managementexercises are used to:

  • validate existing plans
  • verify roles and responsibilities
  • test internal communication
  • identify organizational gaps

Most importantly: highlighting what is not made explicit in the plans.

Why they are critical in energy scenarios

Energy scenarios have specific characteristics:

  • evolve over time (not just instantaneous event)
  • impact multiple functions simultaneously
  • require progressive decisions

This makes them perfect for tabletop/desktop exercises.

How to build an effective tabletop (operational method)

1) Define a realistic and specific scenario.

Example:

  • progressive blackout → 72 hours
  • 30% reduction in available energy
  • Hourly or power limitations imposed by the authorities

Avoid generic scenarios (“blackouts”)
Specify:

  • duration
  • context
  • constraints

2) Structuring the scenario into stages (timeline).

Following the guidelines of ISO 22398:

  • initial phase→ trigger event
  • intermediate phase→ stabilization
  • advanced stage→ operational degradation

Example:

  • T0: power loss
  • T+12h: criticality on backup
  • T+36h: activity reduction
  • T+72h: strategic decision

3) Define the “injects” (decision stimuli).

Injections are events that force decisions.

Examples:

  • “available fuel is of lower quality/quantity than expected”
  • “an established supplier communicates unavailability”
  • “authorities impose consumption reduction and banned bands”

Best practice:

  • few but focused
  • consistent with the scenario

4) Involve the right functions

A good exercise should include (at least):

  • Operations
  • EN
  • HR
  • Supply chain
  • Top management

To facilitate discussion and make decisions that arecross-functionalin nature

5) Clearly define the objectives

Not all tabletops serve the same purpose:

  • plan validation
  • training
  • decision-making test
  • verification communication

Without clear objectives → useless exercise

6) Managing the role of the facilitator

Critical element:

  • guides the discussion
  • introduces the injectors
  • keeps the pace

It should not “help,” butstimulate real processes and decisions while maintaining realism

7) Document and evaluate the results

According to ISO 22398:

  • collection of decisions made
  • gap identification
  • definition of corrective actions

Real output: not the report, but thesystem improvement

Most common mistakes

  • scenarios that are too simple and repeated over the years
  • absence of temporal evolution
  • limited participation
  • focus on reading procedures, not decisions
  • Lack of follow-up on what was discussed

Takeaway

Tabletops are not about whether a plan exists, but about whether the organization is able to make consistent decisions regardless of slavish execution of the plan.

In the current context, one of the most useful exercises that an organization can conduct is precisely a simulation of:

  • prolonged blackout
  • controlled energy reduction
  • logistical disruption
  • impacts on resources

Not to test technology, but to answer a simple question, “How do we continue to operate when power is no longer guaranteed?”

Insight&Inspirations

Suggestions of the month

Letture consigliate per approfondire il Climate Risk

Suggestions of the month

In this column, we continue to point out content that we find useful not so much for acquiring new knowledge but for refining the way we read risk, uncertainty, and strategic decisions in complex contexts.

Reading of the Month –World Energy Outlook – International Energy Agency

Rather than a single article, the advice is to draw on the latest updates and analysis published by the IEA in 2026, which are accompanying the global energy security debate. Why read it:

  • Offers astructured and quantitativeview of the energy system
  • highlights vulnerabilities:
    • geopolitics
    • infrastructure
    • of supply/demand
  • Introduces a key concept:energy as an enabler of operations

Energy security is no longer just about adequacy of supply, but about the system’s ability to absorb shocks and continue to function. For whom it is useful:

  • resilience manager
  • risk manager
  • top management

Podcast of the Month –“The Energy Gang”

One of the most authoritative podcasts on energy, with up-to-date analysis on:

  • geopolitics of energy
  • energy transition
  • energy supply chain security

Why listen to it:

  • Translates complex issues into anoperational and understandablekey
  • colleague:
    • energy policy
    • industry
    • actual impacts

Recent episodes deal with:

  • Global tensions over energy routes
  • vulnerability of the European system
  • trade-off between security and sustainability

Both contents help to make a fundamental shift: moving away from an internal view of risk and understanding the systemic dynamics that generate it. Understanding energy today means understanding the resilience of tomorrow.

Updates from National Fire Protection Association (NFPA)

News from the international Fire Safey community

Updates from NFPA -AI and data centers: does growth outpace security?

A recent article published in
highlights an emerging and particularly relevant theme:

the explosive growth of artificial intelligence-related data centers is proceeding faster than the ability to manage security risks.

The problem: unprecedented growth

According to the published analysis, the AI boom is generating:

  • A massive increase in demand for data centers
  • Increasingly higher energy densities
  • Infrastructure designed to maximize computing power

This results in: unprecedented energy consumption and load concentration.

The critical point: fire safety under pressure

The article highlights a real risk:

  • traditional fire protection solutions
  • are not always adequate for these new environments

Emerging issues:

  • high electrical load density
  • complex cooling systems
  • Increasing use of batteries and storage systems

Consequence: fire risk evolves faster than operational standards and practices.

Energy and resilience: an increasingly close link

The most interesting point, in keeping with the theme of the newsletter, is this:

  • AI data centers are:
    • extremely energy-intensive
    • highly critical
  • But at the same time:
    • vulnerable to power outages
    • dependent on complex power systems

Key insight: the greater the dependence on energy, the greater the operational vulnerability.

Implications for design and risk management

The article implicitly suggests a change in approach:

  • it is no longer enough to design for “compliance”
  • Need to design for:
    • resilience
    • extreme scenarios
    • interdependencies

In particular:

  • Integration between:
    • fire protection
    • electrical systems
    • business continuity

A systemic, not local, risk

Another key aspect:

  • AI data centers are global critical infrastructure
  • an accident can have impacts on:
    • digital services
    • supply chain
    • business operations

This makes them: a convergence point between physical, digital and energy risk.

Takeaway for the reader

  • technological advances are creating new fire hazards
  • energy is the enabling (and critical) factor in these systems
  • resilience requires an integrated approach, not a sectoral one

The growth of artificial intelligence is redefining not only the digital world, but also physical risk models. Data centers are no longer just IT infrastructures: they are complex energy systems whose security requires a thorough rethinking of traditional approaches.

Updates from Disaster Recovery Institute International (DRI)

News from the global community of certified professionals in resilience

Updates from DRI – What really worries resilience professionals

A recent paper published by DRI International reports the results of a LinkedIn survey of business continuity and resilience professionals.

The starting point is simple but very significant:what are the main concerns for resilience practitioners today?

The themes that emerged from the survey

From the responses collected, there is a clear convergence on a few key areas:

  • cyber risk and cyber attacks
  • supply chain disruptions
  • geopolitical instability
  • extreme weather events

In other words: perceived risks are no longer isolated, but systemic and interconnected.

The most interesting data

The survey highlights a change in perspective:

  • we no longer talk only about specific events
  • But ofadaptability to complex scenarios

Resilience is becoming less and less about individual plans and more and more about cross-cutting organizational capabilities.

Implications for organizations

For those involved in business continuity, this means:

  • Strengthen the integration between:
    • cyber
    • supply chain
    • operations
  • Develop:
    • multi-risk scenarios
    • rapid decision-making skills
  • Overcoming “silo” approaches

The main concerns of resilience managers reflect a world in which risks combine and amplify. Preparing for a single event is no longer enough.

PhoenITx srl

Via Pietro Calvi, 2

20129 Milan, Italy

www.continuitaly.it

This post is also available in: ItalianFrench

Would you like to find out more about our training programmes?

Discover the official international certification courses offered by DRI Italy and DRI France on Business Continuity and Cyber Resilience, or the NFPA courses on fire protection systems and all the other Continuitaly courses.

Discover our courses →