Skip to main content
Category: Business Continuity

Resilience

Also known as: Adaptive capacity
Simply put

Resilience is the ability to withstand, adapt to, and recover from difficult or disruptive events. The provided evidence describes it mainly in terms of individuals successfully adapting to stress and adversity, and in a physical sense as the capacity of a material to return to its original state after being deformed. In a governance, risk, and compliance context, the term is commonly extended to describe an organization's capacity to absorb disruption and continue operating, though the evidence here does not directly define that organizational usage.

Formal definition

Resilience denotes the process and outcome of successfully adapting to challenging, stressful, or disruptive conditions while maintaining or restoring functioning. The evidence supports two applicable senses: a psychological sense, defined as the capacity to adapt to stressors and sustain well-being in the face of adversity, and a physical or material sense, defined as the capability of a body to recover its size and shape after deformation. Applying these to a GRC setting, resilience typically refers to an entity's ability to anticipate, withstand, recover from, and adapt to adverse events; however, the evidence provided does not establish a formal organizational or operational-resilience definition, and any such extension should be validated against the relevant framework or regulatory guidance applicable to the jurisdiction and sector. This entry does not cover specific resilience frameworks, metrics, implementation methods, or the distinct concepts of business continuity and disaster recovery, which the evidence does not address.

Why it matters

Resilience matters because disruption is a normal feature of the operating environment rather than an exceptional one. The concept captures not only the capacity to withstand adverse events but also to adapt to and recover from them while maintaining or restoring functioning. In the psychological sense described in the evidence, resilience is the process and outcome of successfully adapting to difficult or challenging experiences and sustaining well-being in the face of adversity; in the physical sense, it is the capability of a body to recover its size and shape after deformation. Both senses share a common thread: the ability to return to a functioning state after being stressed.

Within a governance, risk, and compliance context, this framing is commonly extended to describe an organization's capacity to absorb disruption and continue operating. It is important to be clear, however, that the evidence provided defines resilience mainly at the individual and material levels and does not directly establish a formal organizational or operational-resilience definition. Practitioners applying the term to an enterprise setting should therefore validate the specific meaning against the resilience framework or regulatory guidance applicable to their jurisdiction and sector, rather than assuming a single universal definition.

The term is also frequently conflated with related but distinct disciplines. Resilience as defined here is not the same as business continuity or disaster recovery, and this entry does not address those concepts, nor does it cover specific resilience frameworks, metrics, or implementation methods, none of which are supported by the evidence.

Who it's relevant to

Risk Managers
Risk managers may use the concept of resilience to characterize an entity's capacity to absorb disruption and continue functioning after adverse events. Because the evidence does not establish a formal organizational definition, they should anchor their usage to the resilience framework or guidance applicable to their sector and jurisdiction.
Governance Professionals
Those responsible for organizational direction and decision rights may treat resilience as a strategic attribute reflecting the ability to adapt to and recover from difficult conditions. They should be careful not to conflate resilience with the distinct disciplines of business continuity or disaster recovery, which this entry does not cover.
Compliance Officers
Compliance officers may encounter resilience-related obligations, but the specific requirements commonly depend on jurisdiction, industry, and applicable regulatory guidance. They should confirm the operative definition and expectations against the relevant regulatory source rather than assuming a universal standard.
Human Resources and Well-being Functions
In the psychological sense supported by the evidence, resilience describes individuals successfully adapting to stress and adversity while maintaining well-being. Functions supporting workforce well-being may find this framing relevant, noting that resilience is associated with behaviors and practices that can be developed over time.

Inside Resilience

Operational Resilience
The ability of an organization to prevent, adapt to, respond to, recover from, and learn from operational disruptions. In several jurisdictions, financial regulators have articulated operational resilience expectations, though the specific requirements and terminology vary by jurisdiction and sector.
Business Continuity Management
The processes and arrangements for maintaining or restoring critical business functions during and after a disruption. Business continuity is commonly treated as a component contributing to resilience rather than a synonym for it.
Disaster Recovery
The narrower, typically technology-focused capability for restoring IT systems and data following a disruptive event. It is generally a subset of broader continuity and resilience arrangements, not the whole of them.
Impact Tolerance / Disruption Thresholds
The level of disruption to an important business service that an organization considers acceptable before harm becomes unacceptable. Where used, such thresholds are commonly defined by service and expressed in terms such as time or extent of disruption. Terminology and formal use differ across frameworks and jurisdictions.
Critical or Important Business Services
The services whose disruption would cause significant harm to the organization, its customers, or wider stakeholders. Identifying and mapping these services and their supporting resources (people, processes, technology, third parties) is a common foundation for resilience work.
Third-Party and Supply Chain Dependency Management
The identification and management of resilience risks arising from external providers and interconnected supply chains, given that disruptions may originate outside the organization's direct control.
Scenario Testing and Exercising
The use of plausible severe-but-not-impossible scenarios to test whether the organization can remain within its intended tolerances and to identify vulnerabilities and improvement actions.

Common questions

Answers to the questions practitioners most commonly ask about Resilience.

Is resilience just another word for business continuity?
No. Business continuity is typically one component of resilience, focused on maintaining or restoring critical operations during and after a disruption. Resilience is a broader capability spanning anticipation, absorption, adaptation, and recovery across an organization, and it commonly integrates related disciplines such as risk management, crisis management, disaster recovery, and business continuity rather than being synonymous with any single one of them. Treating the two as interchangeable understates the anticipatory and adaptive dimensions that resilience emphasizes.
Does building resilience guarantee that an organization will avoid or survive disruptions?
No. Resilience aims to improve an organization's capacity to anticipate, withstand, adapt to, and recover from disruptions, but it does not guarantee outcomes. Uncertainty, novel threats, and the severity of some events can exceed planned capabilities. Resilience is best understood as reducing the likelihood and impact of disruption and improving recovery, not as an assurance against loss or failure. Framing it as a guarantee misrepresents its purpose and limitations.
How does resilience relate to an organization's governance structures?
Resilience commonly depends on clear decision rights, accountability, and oversight so that anticipation, response, and recovery activities are directed and coordinated. Governance bodies typically set the objectives and appetite that resilience arrangements are designed to protect, while management operates the underlying capabilities. Establishing who owns resilience, how it is escalated, and how it is reported are governance considerations that shape whether resilience efforts are consistent and sustained. This entry does not prescribe a specific structure, as appropriate arrangements vary by organization size, sector, and jurisdiction.
How can resilience be assessed or measured?
Approaches vary and no single universal metric applies. Organizations commonly assess resilience through methods such as scenario analysis, stress testing, exercises and simulations, and reviews of recovery capabilities against defined objectives. Indicators may include the time to restore critical activities and the tolerance for disruption an organization is prepared to accept. Assessment is typically qualitative and forward-looking as well as backward-looking, and results should be interpreted with an understanding of their assumptions and limitations. This entry does not endorse specific tools or scoring models.
Who is responsible for resilience within an organization?
Responsibility is commonly distributed rather than held by a single function. Under a three-lines perspective, operational management typically owns and operates resilience capabilities, second-line functions may set frameworks and provide oversight, and internal audit may provide independent assurance over their design and effectiveness. It is important to keep assurance activities distinct from the management of resilience itself so that objectivity is preserved. The precise allocation of roles varies by organization and should be defined explicitly to avoid gaps or overlaps.
How is resilience connected to risk management and risk appetite?
Resilience efforts are commonly informed by risk management, which identifies and assesses the threats and vulnerabilities that could cause disruption. An organization's risk appetite and tolerance can help determine how much disruption it is prepared to accept and how much investment in resilience is warranted. In this way resilience often operationalizes risk decisions, prioritizing capabilities around the objectives and activities the organization considers most critical. The specific linkage depends on how an organization has defined its objectives, appetite, and tolerances.

Common misconceptions

Resilience is the same as business continuity or disaster recovery.
Business continuity and disaster recovery are typically components that support resilience. Resilience is generally a broader concept spanning prevention, adaptation, response, recovery, and learning across the organization, its services, and its dependencies, rather than a single plan or a technology-restoration capability.
Achieving resilience means eliminating disruption.
Resilience commonly assumes that some disruptions will occur and cannot all be prevented. The emphasis is often on limiting harm and remaining within acceptable thresholds, adapting, and recovering, rather than guaranteeing that no disruption happens.
Resilience is solely a compliance obligation driven by regulators.
While regulators in certain jurisdictions and sectors set operational resilience expectations, resilience spans governance and risk management as well. It concerns decision rights and accountability for critical services and the management of uncertainty against objectives, not only adherence to specific rules, which vary by jurisdiction and sector.

Best practices

Identify and map critical or important business services along with the people, processes, technology, and third parties that support them, so resilience effort is prioritized where disruption would cause the most harm.
Where your framework or regulator supports it, define impact tolerances or disruption thresholds for each important service, and use them as a reference point for assessing whether arrangements are adequate.
Assess and manage third-party and supply chain dependencies explicitly, recognizing that disruptions may originate outside your direct control.
Conduct scenario testing and exercising using severe-but-plausible scenarios to identify vulnerabilities and confirm whether the organization can remain within its intended tolerances.
Treat business continuity and disaster recovery as supporting components within a broader resilience approach rather than as the complete solution.
Confirm the specific operational resilience requirements applicable to your jurisdiction, sector, and organization size, and avoid assuming that expectations from one regime apply universally; seek qualified legal or regulatory input where obligations are unclear.
Promotional banner for the Pentest Readiness checklist download