4 minute read

Why Too Many UK & EU Programmes Aren’t Ready for What’s Coming: The Resilience Reckoning

Across the UK and EU, resilience functions are under pressure like never before. Between rising operational complexity, compound shocks, and increasingly assertive regulators, the illusion of maturity in business continuity and crisis management is being exposed.

From the outside, many organisations appear ready: risk registers are full, continuity plans are long, and simulations are on the calendar. But dig deeper, and the cracks show—plans are outdated, ownership is ambiguous, learnings aren’t embedded, and executive teams lack confidence in real-time situational readiness.

As we move into the second half of 2025, a shift is unfolding. Compliance is giving way to capability. Frameworks alone are no longer enough. The question now is: can you prove operational readiness under pressure?

Shock 1: Marks & Spencer Cyberattack

In July 2025, Marks & Spencer disclosed a significant cyberattack by the DragonForce group, which disrupted its online store for nearly seven weeks, resulting in an estimated £300 million in lost profits. This, alongside another unreported UK breach, highlights the urgent need for mandatory incident reporting and mature cyber resilience.

Shock 2: EU’s Emergency Stockpiling Strategy

The European Commission has launched plans for emergency stockpiles of critical minerals, cable repair kits, and other essential goods. This move follows sabotage incidents against critical infrastructure and signals a deeper EU-wide focus on strategic resilience.

Shock 3: UK’s “Secure by Design” Cybersecurity Strategy

The UK Public Accounts Committee recently called for a new “Secure by Design” approach, urging systemic cybersecurity improvements beyond legacy compliance tactics. It places emphasis on proactive resilience built into system lifecycles.

The Illusion of Readiness

Despite this intense regulatory push, many organisations still rely on outdated or surface-level practices:

  • Plans are updated annually but aren’t owned or tested
  • Risks are logged, but without consequence mapping
  • Exercises are conducted, but learnings are lost
  • Boards lack real-time reporting on resilience metrics

Battleground Live’s assessments often find that plan versioning, simulation data, and risk-control connections are scattered across systems, siloed in folders, or completely missing. The result? Teams can’t prove readiness when it matters most.

Reframing Resilience Maturity

Battleground propose a shift from static compliance to dynamic capability. Here’s how:

Legacy Approach

Capability-Based Resilience

BCPs stored in SharePoint

Auto-expiry tracking and role-assigned ownership

One-off BIAs

Live BIAs linked to systems, teams, and asset dependencies

Annual simulations

Scenario-logged testing tied to risk register and plan revision

Spreadsheet risk registers

Dashboard visibility with control coverage

Yearly board update

Live resilience metrics and incident insights

Battleground Live operationalises this. It connects plans, risks, controls, ownership, and reporting into a single, auditable platform.

Case Example: From ‘Prepared’ to Proving It

One healthcare organisation had over 100 BCPs, but only a handful had current owners still employed. Their simulations produced PDFs that were never revisited. No one could answer which plans were valid, tested, or ready to use.

Post-implementation of Battleground Live:

  • Plan ownership and currency are tracked in real-time
  • Simulations feed directly into plan updates and reports
  • Board members access dashboards showing BCP status and scenario readiness
  • The Trust passed EPRR audits with high assurance

The Boardroom Test

Regulators and boards are no longer satisfied with static policies. They ask:

  • Which plans are expired?
  • What breaks first during a ransomware event?
  • Who owns our top 10 risk mitigations?
  • What lessons have we implemented from exercises?
  • Can we simulate disruption today?

If your team can’t answer those confidently, the programme may not be mature. Resilience is no longer about having assets—it’s about activating them.

Conclusion: A New Standard for Resilience Leadership

2025 is the reset year. The regulatory tide, real-world shocks, and operational risks are converging. The resilience leaders who move now—to capability, to proof, to integration—will outperform. The rest will struggle to catch up.

“The next wave of resilience maturity will be owned by those who can prove performance, not produce paperwork.”

Battleground Live is purpose-built for this reality.

Join us in defining what resilient organisations truly look like.

Share this article with your network