Since the introduction of ISO 22301 in 2012, best practices for business continuity have remained largely unchanged. However, global operational resilience mandates have introduced new expectations, raising the bar for overall resilience. This report helps resilience professionals benchmark their programs, build a business case for improvements, and understand how resilience expectations are evolving.
Compliance Mandates Drive the Transformation of Resilience
Forrester has partnered with the Disaster Recovery Journal to field annual market studies on various topics related to business continuity and disaster recovery to gather data for company comparisons and benchmarking and to publish best practices and recommendations. This year’s study focused on resilience.
With the number of worldwide operational resilience mandates already in force or coming into force soon, programs will need to move from plan-based loss scenarios tested to be severe to plausible scenarios tested and backed with detailed IT maps of critical/important services. It is the aspiration many BC programs always had but never materialized due to lack of funding, organizational support, or business priority.
Consider the following:
- Compliance forces action. Since ISO 222301 was introduced in 2012 as a standard for business continuity management systems, few other standards for resilience have emerged with the same levels of adoption. Recently, a spate of worldwide mandates for operational resilience has emerged, such as the EU Digital Operational Resilience Act (DORA), Bank of England Prudential Regulation Authority Statement of Policy on Operational Resilience (PRA Op Res), and Australian Prudential Regulation Authority’s Prudential Standard CPS 230: Operational Risk Management (APRA Op Res). These are either already in effect or will be shortly. Today, these mandates are only required for financial institutions, but adoption is growing as other industries recognize and adopt the best practices to maintain the operation of IT in support of critical/important services (see Figure 1).
- Organizations target operational resilience or business resilience goals. We separated the objectives of resilience programs into business continuity, operational resilience, and business resilience. BC programs focus primarily on creating, maintaining, and testing BC plans in preparation for an incident. Operational resilience programs focus primarily on efforts to ensure critical/important digital services (including those provided by third parties) are maintained throughout an incident. Business resilience programs focus on the planning and preparation undertaken by an organization to ensure critical/important business functions can continue during and after an incident, including all digital and nondigital processes, such as workarounds for processes, employees, and manufacturing considerations. Today, 46% of respondents primarily work in business continuity, but an inspiring 22% work in an operational resilience program, and another 32% work in a business resilience program.
- Transformation will take time. Even 24 months out, organizations are still planning to achieve operational resilience compliance. For example, only 3% of respondents claim APRA Op Res compliance today, but an additional 4% desire compliance in 24 months. The 50 respondents who either are compliant or want to comply within this two-year time horizon will have complied with an average of just over two operational resilience mandates.

Organizations Will Morph Depending on Program Goals
Resilience is a multidisciplinary program whether the goals are business continuity, operational resilience, or business resilience. However, the goals of the program have direct effects on the organization.
Reporting To the COO Is an Emerging Best Practice
Some mandates, like APRA Op Res, require programs to report to the COO or a similar role. For respondents who primarily work in operational resilience programs, this holds true: 24% said programs report to the COO. Those with programs that report elsewhere, such as the CISO (21%) or CIO (10%), will need to reorganize to match these mandates. Respondents who primarily work in a BC program and those who primarily work in business resilience are most likely to report to the CISO (22%). But that’s the only commonality for these programs. After the CISO, those who primarily work in business resilience report into “other” (17%) or the COO (14%), while those who primarily work in BC report to the COO (16%), CRO (16%), and CEO (14%). Across all programs, the prominence of programs that report to the COO indicates an emerging best practice. The COO knows how the business runs, can support a shared practice with common tools, and can remain objective and independent of the lines of business (which have a personal stake in the prioritization of services).
Most Programs Lean Toward Centralization
Resilience programs must understand what is worth protecting. For operational resilience, the mandates have dictated any customer-facing service is important/critical. However, an organization must first decide what these services are. Some organizations will decide based on a formal business impact analysis. Others will negotiate with the lines of business or executives to decide on the list annually. In any case, this process depends on centralized efforts. This is why 41% of respondents said their teams have some centralized, dedicated members – with others decentralized throughout business functions or departments (see Figure 2). This type of federated organization balances the need for centralized prioritization of services while keeping close ties to the business that resilience programs are meant to keep running. Thirty-five percent of respondents said their team was centralized; this type of organization allows for coordinated resilience efforts around a common purpose.

Practices Must Finally Evolve to Meet Operational Resilience Mandates
Some practices, such as testing frequency and type, have not significantly changed since our survey began more than 15 years ago. Operational resilience mandates came into being as a recognition that resilience practices had stalled, and firms were not maintaining critical/important customer services that depend on IT assets, especially in interconnected industries, such as financial services. IT changes quickly, and resilience practices must match this pace.
Most Organizations Conduct Simple Tests Only Once Per Year
Unfortunately, the testing situation is largely unchanged since 2008. For all test types, most organizations only test once per year with plan walk-throughs and tabletop exercises, and as tests become more extensive, test frequency declines – 41% of respondents said they never performed a full simulation (see Figure 3). Simulations not only test the incident actions, roles, responsibilities, and interactions between teams but also allow for timing of various plan steps. Timing gives a sense of whether recovery targets are realistic and where to pinpoint improvements to the plan. However, testing requires intentional time and dedicated resources across the organization as well as the inclusion of critical third parties to pinpoint bottlenecks, missing components, and communication and connection failures.

Most Tests Do Not Consider DEI
When performing tests, all voices must be heard to identify gaps, create actions, and improve planning. Unfortunately, 53% of respondents did not consider diversity, equity, and inclusion (DEI) when testing/exercising a plan, and another 14% didn’t know whether they did (see Figure 4). Despite some firms pulling back on DEI investments, the business case for inclusive experiences remains strong, as diverse teams bring a wider set of perspectives, orientations, and experiences to the organization. Using all perspectives and orientations within an organization will help unlock knowledge about how the organization runs, communication pathways, and essential workarounds the firm can implement or improve.

A Lack of Service Maps Is Common
Operational resilience mandates require critical/important service mapping down to the IT components. These maps are also critical to pivot to individual circumstances of an incident. In the past, organizations relied on the configuration management database to provide the mapping, but it was static and incomplete, and IT organizations struggled to include unapproved changes. Now, there is an acceptance IT changes happen – and that IT must track them. Unfortunately, there is still a lack of confidence in real-time completeness of data, especially for components like ephemeral microservices. Technology has improved, especially around AIOps; however, use of maps is still underwhelming. Some 16% of respondents said they used service mappings to determine and track impact on customers as well as create restoration plans for tests/exercises. Only 15% of respondents used service maps when assessing testing performance.
Adoption of Key Technologies Remains Low
To create a complete BC program – and even reach for operational resilience and business resilience program goals – resilience pros must use a wealth of tools and technologies. Unsurprisingly, threat intelligence feeds (41%) – which DORA requires to feed threat-led penetration testing – and BC continuity management platforms (40%) – which resilience pros use to create and maintain plans, perform tests, and handle incident management – have the highest numbers of respondents planning to implement or expand (see Figure 5). Critical event management software – to create incident dashboards with real-time datasets, such as severe weather, and to send customized communications during an incident to different internal and external groups – has the lowest number of respondents planning to implement or expand (24%) and the most not interested (25%). Contract lifecycle management (CLM) has similarly low numbers of respondents planning to implement or expand (28%) and not interested (20%). CLM is a must-have technology for operational resilience, as the mandates require contracts to include exit strategies and force majeure language.

Invocations Call for Greater Focus on Operational Resilience
While 30% of respondents did not invoke a critical incident/risk event (an event that has significant business, financial, or reputational impacts or disruptions) in the past 12 months, 64% of respondents had at least one, and 15% had four or more. The prevalence of IT failures (59%) and IT security incidents (29%) proves the impetus for operational resilience mandates and their focus on maintaining the IT assets that support critical/important customer services.
IT Failure Tops the List of Invocation Causes as Epidemics/Pandemics Fade
After events such as the CrowdStrike content configuration update that affected an estimated 8.5 million Windows systems worldwide, it’s no surprise IT failures topped the list of causes of invocations of a plan (see Figure 6). However, after 2023’s continued invocations due to pandemics/epidemics, which we attribute to COVID-19, only 10% of respondents continue to invoke for health and safety incidents. Extreme weather (33%) continues to plague respondents, but power outages had a smaller role in plan invocations (10%). We link these last two causes together: Organizations that don’t plan for alternative power sources can be incapacitated when extreme weather disrupts power.

Communication Tops the List of Lessons Learned
A fundamental goal of resilience planning is to get everyone to agree ahead of time on how to make decisions during a critical incident/risk event. This means communication, and the ability to make decisions based on up-to-date information, is critical. However, as we noted, 25% of respondents aren’t even interested in critical event management, which would not only provide that dashboard but also enable context-based communications that differ between those: 1) responding to the critical incident/risk event, 2) implementing workarounds, and 3) making decisions (see Figure 7). Another key operational resilience mandate is that decision-makers must have the information which ties to what is happening to affected customers. This helps executives determine what services to bring up and in what order, whether customer impact will exceed tolerance levels, and other actions — like paying a ransom during a ransomware attack.

Budget Is Increasing Not Only for Compliance but Also to Boost Best Practices
Compliance is a great motivator for budget, and 38% of respondents with increasing budgets confirmed that achieving regulatory compliance or complying with audit findings drove the budget increase. While compliance is driving new and better best practices for resilience, mandates still represent the floor of what organizations can do for resilience. Forrester defines business resilience as the ability of an organization to deliver on its vision and brand promise no matter the crisis. The good news? Fifty-two percent of respondents reported the budget increase was to mitigate increasing or evolving risks to the organization, and 38% attributed the increase to better protecting the corporate reputation and brand – closer to the aim of business resilience than compliance.
Budgets Will Decrease for Only Four Percent of Respondents
Our survey shows 37% of respondents expect funding for their resilience program to increase in the next 12 months (see Figure 8). Only 4% of respondents expected their funding for resilience to decrease.

Services For Cybersecurity Incident Response Receive the Largest Budget Increase
Additional budget will be welcome to not only meet compliance requirements but also shore up resilience practices and technologies. Services for cybersecurity incident response will see the largest bump in budget: 32% of respondents report a budget increase. The smallest bump will be for technology/services for workforce recovery (15%). During the COVID-19 pandemic, many organizations found themselves working quickly to ensure employees could work from anywhere, which “solved” the idea of workforce resilience. However, looking deeper into the data, some areas will see large increases of more than 10%, including staffing for ongoing resilience (10%), technology/services to facilitate crisis and emergency services (9%), and technology/services for IT recovery (9%) (see Figure 9). In a rush to meet mandates, organizations are looking to services as well as technologies to help fill the gaps they cannot otherwise.

Research Methodologies
Forrester and Disaster Recovery Journal conducted this joint survey from October to November 2024. The survey targeted global business continuity, disaster recovery, and security and risk professionals affiliated with Forrester and DRJ. Additional responses were gathered via LinkedIn. Respondents were screened to ensure relevant expertise and job responsibilities, creating a valuable dataset for industry benchmarking.
