Contact Us

Continuity Insights Management Conference

Is Operational Resilience A Competitive Advantage?

As the risk environment evolves, operational resilience is becoming increasingly important, according to a new report From The Conference Board.

Intensified geopolitical turmoil, natural disasters, cybersecurity breaches, supply chain disruptions, and other challenges are testing the resiliency of companies like never before. A new report from The Conference Board finds that CEOs are far less confident in their organizations’ ability to prepare for, respond to, and recover from crises, as compared to executives who have direct responsibility for crisis management and business continuity.

Developed in collaboration with Agility Recovery and Preparis, the report recommends that CEOs take this opportunity to ensure their company has a consistent view of the risks it faces and its state of resilience. The report also encourages boards and CEOs to view resilience as strategically important: it can be a competitive advantage, not just a cost center; and as companies focus on sustainability in the long run, they first need to be resilient in the near term. 

Operational resilience is becoming increasingly important because the risk environment is evolving, according to the report: 90% of resilience professionals (those involved in crisis management, business continuity, and related areas) expect threats to increase over the next three years.

“CEOs should close the gap between their own and their resilience teams’ understanding of their organization’s preparedness,” said Paul Washington, Executive Director of The Conference Board ESG Center. “To do so, management needs to reach a common understanding of the full impact that key risks can have on the organization, the programs in place to address those risks, and the quantifiable financial impact that investing in operational resilience can have.”

The report is based on a survey of 147 resilience professionals, and insights provided at a roundtable that brought together 85 corporate leaders.

Additional insights from the report include:

Operational resilience is becoming increasingly important and complex:

  • 90% of resilience professionals surveyed expect threats to their organization to increase over the next three years. That is especially the case for risks related to cyberattacks, the economy, supply chain, climate change, and talent retention, which cut across corporate functions.
  • With risks becoming increasingly interconnected, companies need to adopt a cross-functional approach to managing operational resilience. For example, both technological attacks and weather events can disrupt supply chains, which in turn can have a significant impact on the economy.

Companies may be less prepared to respond to crises because of the impact of remote work, heightening the need to focus on the human element of operational resilience:

  • Resilience professionals are concerned about several risks posed by remote work, including burnout (cited by 74%), along with diminished employee engagement (81%) and reduced collaboration (79%). These factors and others can reduce companies’ ability to respond quickly and creatively to disruptions.
  • “While most companies have expanded their investments in operational resilience in recent years and expect to increase them further in the years ahead, those investments should go beyond buildings, equipment, and technology,” said Jon Bahl, CEO of Agility Recovery and Preparis. “It is vital that employees at all levels of the organization understand what operational resilience is, know what their role is in advancing it, and be resilient themselves.”

As risks are rising, companies should revisit where responsibility for operational resilience sits within the organization:

  • Half of respondents say operational resilience often sits with information technology or physical security, which focus on components of operational resilience.
  • Most respondents believe responsibility for resilience should sit with a part of the organization that has an enterprise-wide remit and is closely aligned with the business, such as risk management (77%) or operations (56%).

“Nearly half of the companies say that responsibility for resilience sits three to four levels below the CEO,” said Tim Mathews, Executive Director of Enterprise Resiliency at ETS and Program Director of The Conference Board’s Enterprise Resilience and Crisis Leadership Council. “However, it’s important that the resilience leader sits high enough in the organization to effectively coordinate and draw upon the relevant functional expertise and ensure alignment with the business strategy.”

Resilience and sustainability are complementary disciplines and can learn from each other:

  • 43% of firms say their resilience and sustainability strategies are only “somewhat” aligned.
  • Companies have an opportunity to bring these areas into greater alignment. Many of the environmental and social risks that concern resilience professionals are also the focus of sustainability programs.
  • Resilience professionals can adapt and apply many of the organizational, programmatic, and reporting practices from sustainability while avoiding some of the pitfalls associated with sustainability initiatives, such as increased politicization and regulation.

You can download a copy of the report here.

Click here to read more about Operational Resilience on Continuity Insights.

Continuity Insights

Similar Articles

New York ACP Metro Announces May Meeting Date and Speaker

The New York City Metro ACP Chapter has announced that “Building Cyber Resilience: Effectively Managing Critical  Business Functions During Crisis” will be the topic of discussion at its May meeting. …

New Report: The State of Email Security

Email security and cyber resilience provider Mimecast’s annual “The State of Email Security” report shows enterprises faced unprecedented cybersecurity risk in 2020 from increasing attack volume, the pandemic-driven digital transformation …

Employees on the Way Out – Addressing Rampant Data Theft

We spend a significant amount of time protecting company assets from “outside incidents,” primarily cyber criminals looking to steal proprietary data. But what about employee data theft? “Insider incidents” have …

Leave a Comment

Share to...