4 minute read
Why Too Many UK & EU Programmes Aren’t Ready for What’s Coming: The Resilience Reckoning
Across the UK and EU, resilience functions are under pressure like never before. Between rising operational complexity, compound shocks, and increasingly assertive regulators, the illusion of maturity in business continuity and crisis management is being exposed.
From the outside, many organisations appear ready: risk registers are full, continuity plans are long, and simulations are on the calendar. But dig deeper, and the cracks show—plans are outdated, ownership is ambiguous, learnings aren’t embedded, and executive teams lack confidence in real-time situational readiness.
As we move into the second half of 2025, a shift is unfolding. Compliance is giving way to capability. Frameworks alone are no longer enough. The question now is: can you prove operational readiness under pressure?
Shock 1: Marks & Spencer Cyberattack
In July 2025, Marks & Spencer disclosed a significant cyberattack by the DragonForce group, which disrupted its online store for nearly seven weeks, resulting in an estimated £300 million in lost profits. This, alongside another unreported UK breach, highlights the urgent need for mandatory incident reporting and mature cyber resilience.
Shock 2: EU’s Emergency Stockpiling Strategy
The European Commission has launched plans for emergency stockpiles of critical minerals, cable repair kits, and other essential goods. This move follows sabotage incidents against critical infrastructure and signals a deeper EU-wide focus on strategic resilience.
Shock 3: UK’s “Secure by Design” Cybersecurity Strategy
The UK Public Accounts Committee recently called for a new “Secure by Design” approach, urging systemic cybersecurity improvements beyond legacy compliance tactics. It places emphasis on proactive resilience built into system lifecycles.
The Illusion of Readiness
Despite this intense regulatory push, many organisations still rely on outdated or surface-level practices:
- Plans are updated annually but aren’t owned or tested
- Risks are logged, but without consequence mapping
- Exercises are conducted, but learnings are lost
- Boards lack real-time reporting on resilience metrics
Battleground Live’s assessments often find that plan versioning, simulation data, and risk-control connections are scattered across systems, siloed in folders, or completely missing. The result? Teams can’t prove readiness when it matters most.
Reframing Resilience Maturity
Battleground propose a shift from static compliance to dynamic capability. Here’s how:
Legacy Approach | Capability-Based Resilience |
BCPs stored in SharePoint | Auto-expiry tracking and role-assigned ownership |
One-off BIAs | Live BIAs linked to systems, teams, and asset dependencies |
Annual simulations | Scenario-logged testing tied to risk register and plan revision |
Spreadsheet risk registers | Dashboard visibility with control coverage |
Yearly board update | Live resilience metrics and incident insights |
Battleground Live operationalises this. It connects plans, risks, controls, ownership, and reporting into a single, auditable platform.
Case Example: From ‘Prepared’ to Proving It
One healthcare organisation had over 100 BCPs, but only a handful had current owners still employed. Their simulations produced PDFs that were never revisited. No one could answer which plans were valid, tested, or ready to use.
Post-implementation of Battleground Live:
- Plan ownership and currency are tracked in real-time
- Simulations feed directly into plan updates and reports
- Board members access dashboards showing BCP status and scenario readiness
- The Trust passed EPRR audits with high assurance
The Boardroom Test
Regulators and boards are no longer satisfied with static policies. They ask:
- Which plans are expired?
- What breaks first during a ransomware event?
- Who owns our top 10 risk mitigations?
- What lessons have we implemented from exercises?
- Can we simulate disruption today?
If your team can’t answer those confidently, the programme may not be mature. Resilience is no longer about having assets—it’s about activating them.
Conclusion: A New Standard for Resilience Leadership
2025 is the reset year. The regulatory tide, real-world shocks, and operational risks are converging. The resilience leaders who move now—to capability, to proof, to integration—will outperform. The rest will struggle to catch up.
“The next wave of resilience maturity will be owned by those who can prove performance, not produce paperwork.”
Battleground Live is purpose-built for this reality.
Join us in defining what resilient organisations truly look like.











