Build business resilience that works
Business resilience is becoming essential as risks grow more complex. In this webinar you gain insights into the evolving threat landscape and learn how organisations can build stronger and more effective resilience programs that create lasting impact.
Overview of the session
The webinar introduces the concept of business resilience and why the pace and complexity of global risks demand a new approach. It highlights key challenges organisations face, including geo economic tensions, cyber threats and societal polarisation. You hear how these risks influence operations and why resilience requires involvement across the entire organisation.
The six resilience dimensions
The presenters outline six dimensions that shape holistic resilience work. These include brand trust, operations, digital technology, business models, people and culture, and financial resilience. Real examples illustrate how priorities are shifting from isolated compliance tasks to long term, strategic investments that span multiple functions and require strong leadership mandates.
From analysis to implementation
A four phase approach is used to build and implement resilience programs. The presenters explain how organisations move from assessing risks and ambitions to developing remediation initiatives, managing complex cross functional portfolios and sustaining change through long term governance. Transparency and strong program structures are emphasised as critical success factors.
Ensuring lasting change
Finally, the session highlights why resilience must become part of everyday work. Leaders and teams need capabilities, ownership and clarity to embed new practices. The speakers underline that lasting impact is achieved when strategic direction, daily execution and organisational engagement work together as one coherent program.
Build business resilience that works
Business resilience is becoming essential as risks grow more complex. In this webinar you gain insights into the evolving threat landscape and learn how organisations can build stronger and more effective resilience programs that create lasting impact.
Overview of the session
The webinar introduces the concept of business resilience and why the pace and complexity of global risks demand a new approach. It highlights key challenges organisations face, including geo economic tensions, cyber threats and societal polarisation. You hear how these risks influence operations and why resilience requires involvement across the entire organisation.
The six resilience dimensions
The presenters outline six dimensions that shape holistic resilience work. These include brand trust, operations, digital technology, business models, people and culture, and financial resilience. Real examples illustrate how priorities are shifting from isolated compliance tasks to long term, strategic investments that span multiple functions and require strong leadership mandates.
From analysis to implementation
A four phase approach is used to build and implement resilience programs. The presenters explain how organisations move from assessing risks and ambitions to developing remediation initiatives, managing complex cross functional portfolios and sustaining change through long term governance. Transparency and strong program structures are emphasised as critical success factors.
Ensuring lasting change
Finally, the session highlights why resilience must become part of everyday work. Leaders and teams need capabilities, ownership and clarity to embed new practices. The speakers underline that lasting impact is achieved when strategic direction, daily execution and organisational engagement work together as one coherent program.
View transcript
Welcome everyone this morning to this webinar about business resilience. Thank you for dialing in this morning and joining us. Myself and my two colleagues Joel and Torvald will be your hosts today for the next 30 minutes we have together. Throughout the session please write your comments and questions in the chat. We will come back to you with a response within the coming days. And after the webinar you will receive an email with the presentation and a link to the webinar recording. Business resilience is about minimizing the impact of adverse change. It's about surviving and even thriving under disturbance. It's a big, broad and very relevant topic in today's business environment. And today we will focus on exploring how to effectively set up and drive business resilience development programs. Let us take a look at what we will go through today. We will take a quick look into the current security landscape. Afterwards we will zoom in on the dimensions of business resilience. We will give you some perspectives on how the current risk landscape impacts resilience efforts in organizations. And lastly we will give you some insights into how we drive resilience programs and implement. Including the specific characteristics of these types of initiatives and what is required to succeed. I will hand it over to Torvald that will take us through the first points on the agenda. The world is changing. But that is not really a new thing. But the pace, the frequency and the complexity are unprecedented. And for organizations and companies, big or small, that means navigating uncertainty requires more than ever. In implement, we help organizations and companies to navigate that uncertainty, not only to just survive, but actually being able to thrive. So what risks are organizations facing in 2026? Since you joined this event, I am sure you have already seen the writing on the wall and you do have a fair understanding of what we are looking into. The World Economic Forum has just released its global risk outlook for 2026 and the trend is clear. In short term, geo-economic confrontation, misinformation and disinformation, and societal polarization ranks as the top risks. Further down the list, we still see cyber security, extreme weather events, and even armed conflict. Each of these risks could potentially impact the way your business operates. So the question is now, how will these risks impact your organization? And if the impact is severe enough, what can you do to prepare and protect your organizations? This is not an easy task to take risks like geo-economic confrontation or cyber security that may seem a bit intangible for a lot of people in the organization, and then mobilize teams that need to mitigate those risks in a way where it makes sense and create value in the organization. That requires planning and that requires efforts. All roads lead to Rome, but in this session we will share our experiences on mobilizing teams and programs to execute resilience efforts. But before we get to that, we would like to hear from you. What's already on your radar when it comes to risks and threats? In other words, please write in the chat what keeps you up at night. And I have to say, if you say the next audit from the local authorities, you are kind of missing the point. Even though it is important, non-compliance is actually not the true enemy. So while you are texting, I can share something that I personally find very concerning. A couple of weeks ago, I overheard a speech by a chairman of the board of a large company that does a significant amount of business in the US. And he shared a view that I find quite worrying. His observation was that the way the current US administration acts spreads out to the rest of the society, including businesses. So agreed rules, agreed contracts, deals and so on are being completely ignored. And if this way of thinking spreads and more companies adapt this way of acting and the common rules I ignore, I think it will become extremely difficult to do business in that environment. Supply chain security, major risk. I think a lot of companies have struggled with that. And of course, no webinar or speech without also mentioning AI. Very much agree. Thank you. So the diverse and volatile risk landscapes requires efforts from the entire organizations, not just the security department, not just IT, not just corporate affairs. The entire organizations. In our projects, we have benefited from working across six resilience dimensions. These serves as reminders of what and who we should include when building resilience capabilities in our organizations. The six dimensions are brand trust and credibility, operations, digital technology and enablement, resilient business models, people, culture and organization, and last but not least, financial resilience. The topics we work with like business continuity, crisis management, supply chain resilience often needs involvement from all stakeholders across the different dimensions. And especially in big organizations, establishing that collaborations requires huge efforts and a clear and strong mandate from senior leadership. Working with the six resilience dimensions, we have identified a number of areas in our projects where we can see priorities and approaches are evolving. In general, bigger risk means increased attention from senior management, which might trigger bigger investments. And this ultimately gives bigger responsibility to deliver impact. So what is it that we see in the projects? What we see is that we are going from executing projects where isolated compliance actions are being executed. We have projects where individual department responsibility is sort of the way we work. We also see low cost tactical measures and a quite reactive post-incident approach and doing it on a very al-hoc project by project fixes. But the way we are going is to this. Now being a more integrated and strategic initiative, we have much more cross-functional involvement and we are seeing significant capital expenditures and long-term investments. We also see companies adapting a lot more proactive risk-based approach and we see companies elevating this to being done on enterprise-level program management. I want to highlight two examples where we think companies have a huge potential if they can keep up with these evolving demands. The first example relates to the long-term investments and is actually from a project where a company wanted help to quantify to which extent their security investments were benefiting the business. Together with the security team, we built a business case. That is a language that a CFO or CFO or whoever you are addressing understands compared to just knocking on the door and asking for a bigger budget to increase your cybersecurity. You can apply proven financial modeling to quantify your security investments. You can measure outcomes. You can run simulations and clearly demonstrate the return on investments. So we move beyond that security gut feeling to actually presenting evidence-based decisions. The second example is one that I think many of you will relate to. How and where should we prioritize our resources? And yes, you guessed it. This is about enterprise risk. This is a question we are asked a lot. A chief security officer or a chief risk officer asking, hey, I have an increased budget. What should I do? Should I choose segmentation of our IT infrastructure? Should I choose to enhance our physical security? Or should I put more efforts into testing and training our business continuity plans? In other words, what gives me, what gives the organizations the most resilience? And to be able to answer that question, we need to be able to compare apples and oranges. And to compare apples and oranges, we need a mature enterprise risk management. The risks we are trying to address often have different risk owners. And if those risk owners do not have proper guidance on how to assess and evaluate risk, we will never gain a solid insight into how we should prioritize our resources. And you can be absolutely sure that all risk owners will see their own risk as the absolute most important one to address. By helping to build a functioning wide enterprise system, we avoid working in silos and reset the preconditions of doing this on enterprise program level. So on that note, maybe you could begin asking yourself questions like this. Have senior management been actively involved in defining my organization's risk tolerance? When we have two risks competing for funding, what criteria do we actually use to decide? Or maybe ask, how often do enterprise level insights actually change decisions on security and resilience investments, rather than just documenting risk after decisions have already been made? We have touched upon the risk landscape, the six resilience dimensions, and the new reality organizations need to navigate. Yet one crucial question remains. How do we execute resilience programs that rise to the challenge of this new reality? And to address this question, I would like to hand over to Joel. Please Joel, the floor is yours. Thank you Torvald. And I'll try to ground that by taking you through how these programs actually unfold in our experience. And also how the nature of the work changes along the way. So below you see the four phases that take us from analysis to implementations normally. And I'll go through them one by one and put some words to what we see in these phases typically. Starting with the first phase, current state and ambition. We always start here, even though it sounds a little bit obvious, but we need to start with establishing a security and resilience ambition. That one has to be grounded in the risk appetite that Torvald talked about before. And we need to be clear on what we protect and where we actually accept risk. The way we do that is by starting to analyze the as-is state in our company. We look at the risks. We look at our current maturity. And we look at our weak points. And based on that, we try to define a credible to be state. Now that doesn't mean that we have to be completely perfect, but it's our intention with this whole program. What we're looking to set up. This beginning phase works really well with a small core team and the right experts. We then move on to the second phase, which is the gap assessment. This is where the ambition that we set out before begins to meet reality. We compare the current state against regulations, our internal standards, and the risk appetite that we talked about before. And then we try to identify where are our gaps and how do we prioritize those. The reason we do that is because that enables us to translate it into a scope, the dependencies, and the resource needs that are there for us to close those gaps. And I just want to pause here because up until this point, things might feel pretty structured still. It's still a relatively small team driving analysis internally in our organization, and everything is under control. But when we then move on to the third phase, which we call remediation development and implementation, that's where we sometimes see some programs starting to struggle a little bit. So what happens in this phase? Gaps start turning into remediation initiatives, meaning we actually start working on these. These remediation initiatives might be spread across functions in our company, in different domains in the company, or even in some cases, different geographies. That leads to some common failure points that we see. One would be that initiatives scatter, so they're all over the organization. And the collective overview that we're sort of looking to have is lost because they sit in different functions, domains, or countries. And that leads to reporting on this whole program becoming super fragmented. And suddenly we're in a situation where we can't clearly see how all of this ties back to the original ambition. We then move on to the last phase, which is called post-program governance and monitoring. Now, this phase can often be treated sort of as an afterthought, or in some cases, it might even be overlooked, and it shouldn't be. Because this is where we establish the long-term governance in order to sustain this change. This is where we anchor the ownership after the program actually ends, so we can continue to monitor the compliance and the resilience performance we set out to improve in the original phase. And this is what done actually looks like when we look at a program in this context. Not just delivered initiatives, but a governance that actually lives on in the organization and ensures that we have lasting change. So, to close this section, I just wanted to say what is consistently underestimated and how much this setup sort of changes. In the first two phases, there is a core team, a few amount of experts, and some central control to kind of keep the whole thing together. Meaning it's a relatively small team of people working together. That's why it's easier to handle. But as we move on to phase three and four, there's a range of portfolios, or a range of initiatives, sorry, many owners and many competing priorities, which is what we know characterizes a program. And that's why this can't be run as business as usual. Again, going back to Torvald's point earlier, if safety and resilience is no longer viewed as being one-off projects, we also have to rethink how we approach them. That means it has to be enabled by best practice program management approach. So, in doing so, I would like to introduce a program management approach we know from experience works in this context. We lean on our best practice at implement, which at its core is deliberately simple. There are three equally important dimensions, which you see on screen right now. The first one would be steering the transformation. That means setting the direction. The next one would be directing execution on a day-to-day basis. And the last one will be engaging the organization to change. I'll go a little bit more in depth into what each of these means in this context. But before that, I just wanted to pinpoint that experience shows when working with these that they only really work when they come together. That means if one dominates, one domain dominates, usually that would be, for example, execution. We start losing impact. So, all of these three domains have to operate as one ecosystem. So, I'll share some examples on what this actually looks like when it unfolds in practice within a security and resilience context. So, starting off with the first dimension, steering transformation. In safety and resilience, steering starts with an ambition like I talked about when I walked through the different phases. Not an abstract ambition. The ambition has to be grounded in our real risk appetite. And that's where we ask ourselves some questions such as, what is the level of resilience that we actually need? And what and where are we consciously accepting risk? And then we have to anchor that in some sort of ambition or a vision that everyone in the organization can get behind. And I'll get back to why that is important later. Once we have that ambition, we start translating that into objectives, explicit priorities, and visible trade-offs. And then further breaking that down into a scope we can actually begin executing on properly. That scope can spread across physical security, cyber, business continuity, crisis management, and so forth. But the important thing here is that we have a scope where there is no overlaps and where we, most importantly, do not have blind spots. The last one will be organizing for effective delivery. And this one is a critical one in this context. This is where we set a steering committee that actually has mandate. And the reason why I mention that is because we often see steer co's with a somewhat limited mandate. Or that they're too far away from the business that's actually impacted in the last end. So instead we need a steer co with the benefit owners of the final solution. That means the people who will ultimately be held accountable for the changes and will own the solutions in their end of the business. We need that so we ensure that we have the right decision power in our steering co, steer co, before execution even starts. Moving on to the second dimension which is called driving progress. This is where this dimension really kicks in once we enter the remediation phase. Those were the two last phases that I talked about before. And we move from having a relatively small core team to a portfolio of initiatives. At this point complexity is somewhat of a given. And the way that we combat that is by increasing the transparency in our program. In order to avoid the pitfalls that I talked about earlier where the reporting becomes scattered. So we begin with establishing a governance and a rhythm for day to day execution. That means clear forums and decision rights where a lot of different stakeholders in the context of these types of programs often have to come together and collaborate. And most of the time all of these stakeholders come from completely different backgrounds for how they're used to work. So we need to set up for success there. Next, we look to establish a reporting across all of these remediation initiatives that I say could scatter across the organization. That means that we're able to answer a few questions in regards to the progress, the dependencies and perhaps even the inherent risks in the program. This means that we're able to deliver one integrated view and not a fragmented status update across these initiatives. It is that transparency which in the end will enable effective steering from the steering committee that I just talked about. It allows our leaders to make informed tradeoffs and decisions based on the real data. And it allows us to stay anchored with the original resilience ambition that we set out to achieve. Moving on to the last phase, engage to change. That's the third dimension. And it's often the one that we see is underestimated or sometimes even overlooked. But it determines whether the resilience actually sticks. In safety and security, it can't just be about communication. It's real changes in the receiving organization. That means we change roles. We might change accountability. And we might even change the way of working. And therefore, we have to build up the right capabilities to actually sustain this change and ensure that leaders are equipped to drive it once the program actually ends. Recently, we were with a client where the emphasis on this last phase in the program really got put into perspective. We had just hosted our steering committee meeting and signed off on a bunch of initiatives and presented the full status of these remediation initiatives. And then one of the country GMs stopped us and he said, this is only really the first step. Given the world that we operate in, going back to some of the points that Torvald also mentioned, resilience and security cannot be treated as just a one-off program. Instead, he made a point that really stuck with me, which was increased resilience means it's now part of everybody's job. And it requires a cultural shift in our organization to actually sustain that. So where safety and resilience becomes part of how everybody thinks and acts. And that's exactly why this third dimension is about lasting change. So all of these three dimensions are inseparable. They can't live in different parts of the organization, but they sort of have to come together and they can't be switched on and off one at a time. But only when they work together, we see programs that stay coherent and that makes better decisions under pressure. And that leave the organization fundamentally more resilient, which is what we set out to do. It goes without saying there's a lot more to this whole framework. So if you're interested in knowing more, please check out our full series on the transformation program management, which will be linked in the material you'll receive after this. Now to end up, I'll hand over the talking stick to my good colleague, Emilia, to close off. Thank you so much, Joe. And thank you so much, Torda. I hope that it has been interesting and insightful for you all to take part in this webinar this morning. Time is almost up for today. Today, we've given you insights into the dimensions of business resilience. We've given you perspectives on how the current threat landscape impacts your resilience efforts. And we've introduced you to our program approach and the specific elements of high importance to resilience programs. But before we let you go, we would like to ask you to reflect on a question, perhaps on your way to the next meeting or when you're brewing your next coffee. And the question is on your screen now. What would you wish you could say about your organization's business resilience that you cannot say today? I'll just give you 20 seconds. And I hope that if you have any immediate reflections that you will write them in the chat now. When we speak with you again, and of course, we hope that we will speak to all of you again, we will be very interested in hearing your response to this question. Thank you so much for your time and commitment this morning. We hope it has been insightful. We will send you the presentation and the video recording of the webinar, and you are welcome to share it with your network. If you've asked a question in the chat, we'll come back to you with a response over the coming days. Thank you so much and have a great day.