Skip to main content
Blue global map with green data lines.

Operational Resilience Amid Geopolitical Tension: Key Shifts

Operational resilience requires integrated, recovery-focused action across risk, security, and more.

Not long ago, a six-step business resilience framework was designed for a world reacting to events, such as the Russia-Ukraine war and post-pandemic supply chain fractures. That type of framework focused on foundational practices of establishing an enterprise risk management (ERM) culture, monitoring macro-level threats, modeling scenarios with key risk indicators, integrating governance risk compliance (GRC) platforms, gathering stakeholder feedback, and building data-driven dashboards.

Each of those steps still matters, but the operating environment has changed. Geopolitical conflict, cyber incidents, supplier failures, infrastructure constraints, regulatory change, and workforce disruption increasingly overlap and persist.

The central resilience question is no longer whether an organization can respond to a single event. It is whether the organization can continue delivering its most important products and services through sustained disruption, and recover within acceptable limits. That requires leaders to understand how people, processes, technology, data, facilities, and third parties combine to support critical operations.

What’s Changed

The 2022 business resilience framework was designed for a world confronting acute shocks, including war in Europe, supply chain backlogs, and elevated inflation. Organizations needed to establish core risk management capabilities quickly, and the framework provided a strong foundation.

In 2026, volatility is less episodic and more sustained. As discussed in the webinar, “Geopolitical Risk: When Uncertainty Is the Operating Model,” leaders who treat pricing volatility and supply disruption as persistent operating conditions may be better positioned than those waiting for a return to normal.

Risks now need to be managed with greater persistence, specificity, integration, and board-visible execution. Five changes in particular should shape how risk, operations, compliance, technology, and security leaders manage resilience.

Five Shifts Enterprise Leaders Should Prioritize

Governance: From Awareness to Documented Accountability

Previously, governance conversations centered on building an ERM culture and establishing a top-down policy. That was a great starting point.

However, the bar is higher today.

Boards and executive teams face growing expectations to demonstrate active supervision of operational resilience, not merely awareness of individual risks. Organizations should document ownership of important business services, decision rights, escalation triggers, recovery priorities, and the roles of operations, risk, compliance, technology, security, legal, communications, and third parties. For public companies, this enterprise model should also connect to evolving regulatory expectations, including cybersecurity incident disclosure and risk governance requirements.

Supply Chain: Dependency Mapping & Concentration Analysis

The old framework emphasized knowing suppliers and identifying trapped capital. Today, organizations need an end-to-end view of the dependencies supporting their most important business services. That includes direct and downstream vendors, logistics, facilities, utilities, key personnel, data, cloud platforms, technology providers, AI models, open-source components, and other shared resources. Mapping these relationships helps reveal single points of failure, geographic exposure, substitutability constraints, and concentration risk that a traditional vendor inventory may miss.

During “Navigating Geopolitical Risk Through Operational Resilience,” professionals from energy, manufacturing, transportation, and technology described a market where repricing often trails disruption and contracts move cautiously and unevenly. Companies are shifting from pure efficiency models toward risk-informed decisions about sourcing, inventory, capacity, and redundancy. CROs, COOs, CCOs, CIOs, and CISOs should evaluate these tradeoffs together, focusing first on dependencies whose failure could interrupt critical services.

Business Continuity: Part of Resilience Planning

Traditional incident response often concentrates on identifying, containing, and resolving a discrete event. Operational resilience asks a broader question: can the organization maintain critical services, execute workable alternatives, and recover within defined tolerances when disruption is prolonged or widespread?

A wiper-style cyber event is one useful example: systems may be technically contained while business interruption continues. The same operating challenge can arise from a supplier failure, utility outage, facility loss, workforce constraint, or geopolitical restriction. Resilience planning should therefore define minimum service levels, manual workarounds, restoration sequencing, regulatory and customer obligations, and the maximum duration and severity of disruption that the organization is prepared to accept.

Monitoring: Continuous Reviews & Cross-Functional Readiness

The 2022 framework recommended periodic stakeholder feedback and news monitoring. Those practices remain valuable, but quarterly review cycles may not keep pace with rapidly changing geopolitical, operational, regulatory, supplier, and cyber conditions. Organizations need integrated indicators and risk based monitoring that show when exposure is approaching a disruption tolerance, a dependency is weakening, or an executive decision is required.

When webinar attendees were polled on how long their organizations sit with geopolitical effects before making high-impact changes, 37% said they act within three to six months, while 39% said they wait six to twelve months. Neither timeline is inherently wrong, but organizations that maintain cross-functional indicators and rehearse severe but plausible scenarios may be better prepared to act when thresholds are crossed. Exercises should test executive decisions, operating workarounds, regulatory obligations, communications, vendor coordination, and technology recovery—not only the IT security response.

Reporting: Risk Visualization, Decision Support, & More

In 2022, dashboards helped organizations move beyond static spreadsheets and communicate emerging risks more effectively. The next step is to make reporting decision-oriented rather than merely descriptive.

Executives and boards should be able to see which important services are exposed, what dependencies could cause cascading disruption, whether recovery can occur within approved tolerances, and which decisions or investments are needed. Useful measures may include service availability, recovery performance against tolerance, unresolved dependency gaps, concentration exposure, scenario exercise outcomes, workaround readiness, and remediation aging. These metrics connect operational conditions to choices about risk acceptance, resources, customer commitments, and regulatory obligations.

Next Steps for Enterprise Leaders

CROs, COOs, CCOs, CIOs, CISOs, and their teams should consider the following actions to strengthen operational resilience:

  • Identify the organization’s most important and/or critical business services and the customers, markets, regulatory obligations, and strategic outcomes they support.
  • Define disruption tolerances and recovery priorities, including minimum acceptable service levels, escalation thresholds, and restoration sequencing.
  • Map critical dependencies and concentration risk across people, processes, technology, data, facilities, utilities, direct vendors, and downstream providers.
  • Test severe but plausible scenarios through cross-functional exercises that evaluate executive decisions, operating workarounds, communications, compliance obligations, vendor coordination, and technical recovery.
  • Establish accountable decision makers and escalation paths so teams know who can accept risk, authorize workarounds, allocate resources, and communicate with stakeholders during disruption.
  • Report recovery readiness to executives and the board using service-level, tolerance, dependency, exercise, and remediation metrics that support timely decisions.

The foundational practices from 2022 still hold, but the operating context has changed. Resilience is now an enterprise capability that connects risk governance, critical services, business continuity, third-party dependencies, technology and cyber recovery, compliance obligations, and executive decision making. The path forward is not to replace existing programs, but to integrate and strengthen them with the persistence, specificity, and board-visible execution required for sustained volatility.

How Forvis Mazars Can Help

Operational resilience amid geopolitical tension requires planning. Forvis Mazars can help leaders identify important business services, map critical dependencies, assess concentration and third-party risk, define disruption tolerances and recovery priorities, evaluate governance and reporting, and conduct cross-functional scenario exercises. Our teams also provide cybersecurity risk assessments and technology resilience support as part of a broader enterprise approach. Connect with a professional to discuss your organization’s resilience priorities.

Related Reading

Related FORsights

Like what you see?
Subscribe to receive tailored insights directly to your inbox.