Close Menu
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
More items
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
X (Twitter) LinkedIn
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
Login
LinkedIn Bluesky
Resilience Forward
Subscribe Now
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
Resilience Forward
You are at:Home»News from Resilience Forward»A bold, new, resilience reality: themes from DRI2026 (Page 17)
News from Resilience Forward

A bold, new, resilience reality: themes from DRI2026

Rachael Elliott highlights the key themes that emerged from the recent DRI2026 conference.
March 27, 202611 Mins Read
Global themes concept.

DRI2026 took place in Jacksonville, Florida, from 22 to 25 February. Jacksonville offered the perfect start to the conference year, with the bright and airy venue of the Hyatt Regency providing the perfect setting. Following tradition, the DRI Foundation team spent the Saturday before the conference volunteering, this year with the Volunteers of America Florida charity. It so happened to be one of the warmest days of the year so far, and perfect for donning work boots, paintbrushes, drills, hammers, and saws.

However, as Winter Storm Hernando threatened to turn the sunshine into snow, attendees were grateful for the indoor heat as DRI2026 got underway.

The themes of this year’s conference were symptomatic of an economy that has become structurally interruption-prone and, as a result, the programme repeatedly returned loosely to five topics: supply chain resilience, third-party risk management (TPRM), cyber security, operational resilience, and the governance of AI and other emerging technologies. Sessions repeatedly confirmed the tight interlocking of these disciplines which have previously been considered as disparate areas.

It is clear that supply chain resilience has become an intrinsic part of operational resilience; operational resilience has become increasingly dependent on better data and technology governance; and both are exposed to cyber and geopolitical shocks that now travel through entire business ecosystems rather than just a single organization.

That framing was explicit in the opening plenary which spoke to how an organization’s business continuity plans (BCPs) were only as strong as their suppliers’ BCPs. The presentation’s primary argument was that ‘continuity-critical’ suppliers should be identified by impact and substitutability rather than by spend. This is something business continuity and resilience practitioners have practised for years, but it is now becoming realised in boardrooms, too.

This mirrors the way regulators and central banks are increasingly thinking about resilience, especially in finance, where firms are mandated to map the people, processes, technology, and third parties that underpin their defined important business services. The Bank of England’s operational resilience regime required firms to meet their tolerances by 31 March 2025, and in its 2026 supervisory priorities it said firms should now embed operational resilience into strategic decision-making rather than treat it as a compliance necessity.

That emphasis on interdependence was reinforced elsewhere in the programme. A powerful case study presentation showed how an organization had built a centralised but scalable TPRM model across five independently managed operating companies, connecting procurement, legal, security, and finance under a shared resilience framework. Later, a further presentation stressed that resilience is not achieved by onboarding due diligence alone but by lifecycle governance, service level oversight, incident obligations, and exit provisions.

Outside the world of business continuity, global regulations are also moving a similar way. The Basel Committee published its final principles for the sound management of third-party risk in late 2025, explicitly linking nth party exposure, concentration risk, and supply chain dependencies to banks’ ability to withstand and recover from operational disruption. In Europe, the Digital Operational Resilience Act, DORA, has applied since 17 January 2025, and regulators have already begun designating major technology firms as critical ICT third party providers to the financial sector.

However, while regulatory jargon can be difficult to put into practice, particularly for those not used to implementing operational resilience, the speakers at DRI2026 were able to effectively translate that regulatory logic into practitioner language: contracts, governance forums, supplier participation in exercises, and better dependency data.

Operational resilience – it’s living, it’s dynamic – and its pushing strategic growth

The presentations on operational resilience were equally contemporary. One presentation showed how resilience is losing its reputation as a defensive control and is fast becoming an enabler of strategic growth. Other presentations talked about how the ability to monitor, mine, and action data was pushing BCPs towards a dynamic data product rather than a static document that is updated annually. Further presentations added AI into the mix and showed how AI-enhanced incident tools can also be employed to add further efficiencies to incident management and greater realism to training and exercising.

AI is finally finding the ‘right place’ in resilience strategies

AI-themed presentations at DRI2026 were notable because they were not techno-utopian, i.e. a total technology takeover of business continuity and resilience processes by AI. Presentations focused on the relationship among models, regulations, applications, and suppliers. One presentation spoke about using AI as a tool to speed BIA, planning, and after-action reviews, but did so through a lens of human oversight and trust while another suggested that AI could pressure-test recovery assumptions and map dependencies from messy data but should not replace practitioner judgement. The implication from all these sessions was sensible: AI is becoming part of the resilience stack, but it is also a new dependency that must itself be governed.

That is closely aligned with external policy thinking. NIST’s Generative AI Profile, published in July 2024 as a companion to the AI Risk Management Framework, urged organizations to manage AI risk across the full lifecycle and to align governance, validation, and human oversight with business objectives. In policy circles, the debate has widened further, from model risk to infrastructure dependence. The Brookings Institution argued in early 2026 that ‘AI sovereignty’ is increasingly about the ability to make independent decisions regarding critical AI infrastructure, data and deployment, and is far from being purely about model development. For resilience practitioners, that means AI is both an efficiency tool and a fresh concentration risk.

Delving into supply chain resilience

Supply chain resilience was one of the most consequential themes at DRI2026. The opening plenary made that explicit by showing the importance of placing procurement as an integral part of business continuity. Other presentations showed how third-party risk becomes operationally meaningful only when it is tiered, onboarded, and monitored in business workflows, with other speakers stressing that resilience requires audit rights, disaster recovery, and business continuity plan clauses, incident obligations, termination protections, and transition safeguards. It became clear through presentations that there is now a clear, missing connective tissue: once dependencies are visible in live data, supply chain risk can be assessed as part of event response rather than – or in most cases, as well as – an annual paperwork exercise.

Supply chains have not been a manufacturing-only issue for some time now. Conference presentations sessions by manufacturers and retailers showed how downtime, shortages, and external dependencies can quickly become critical problems for customers; not only damaging reputation but also destroying sales figures and company value. However, the most revealing examples came from presentations by services organizations: they are discussing managed services, cloud providers, digital tooling, outsourced operations, legal terms, internal data architecture, and global incident coordination. The supply chain in 2026 is as much a map of contracts and software dependencies as it is of containers and components.

Academic and policy literature increasingly supports this broader view, which includes the DRI Professional Practices. Professional Practice Three: Business Impact Analysis requires dependencies to be documented across processes, technology, supply chain, and third parties. Meanwhile, Professional Practice Four: Continuity Strategies explicitly calls for identification of supply chain issues affecting both suppliers and customers and recommends potential strategies in light of the results of the risk assessment and the BIA. Also, Professional Practice Two: Risk Assessment requires risk identification across workforce, supply chain, cyber security, IT, legal, and regulatory dimensions. In other words, DRI’s own body of knowledge already treats supply chain resilience as a multi-resource dependency problem rather than a narrow logistics function.

The external evidence points the same way. The OECD’s Supply Chain Resilience Review 2025 argues for agile, adaptable, and aligned supply chains, and warns against hastily-introduced relocalisation strategies. An IMF working paper from 2025 similarly finds that while diversification of import sources can mitigate trade shocks, they do not come without efficiency trade-offs. A further National Bureau of Economic Research (NBER) work reaches a similar conclusion, showing that diversification can outperform some reshoring strategies in promoting resilience. DRI2026’s framing therefore appears to be well judged.

The fact that this thinking is emerging now is particularly critical due to current global events. Shipping and trade routes are being actively exposed to conflict and coercion. As of March 2026, reports speak of fresh disruption in Gulf and Red Sea shipping linked to the Iran crisis, with rerouting, fuel redistribution, and surcharges rippling across carriers and ports. Even before those events, the global trade system was contending with Red Sea insecurity, policy uncertainty, and a proliferation of trade restrictions.

Cyber pushes the case for supply chain resilience even further

Cyber has made the case for supply chain resilience even stronger. The ransomware tabletop in the opening session at DRI2026 explicitly posed the question of what happens when a cyber incident destroys recovery assumptions and spreads through the supply chain. Another presentation by a healthcare resilience professional also demonstrated that cyber downtime directly links to patient safety and noted the need to understand the loss of connected technologies, not merely core clinical systems.

Supply chain resilience is also now inseparable from operational resilience regulation. DORA’s focus on ICT third party providers, the Basel Committee’s TPRM principles, and the Bank of England’s insistence on mapping important business services (and third parties) all reflect a common proposition: firms do not fail alone – they fail through networks. DRI2026’s programme with significant focus on supplier management therefore demonstrates a delayed convergence between business continuity practice and regulatory reality. What practitioners used to treat as vendor management has fast become a core resilience capability.

The fact that third-party risk management has become so integral to business continuity planning was recognised by DRI in an announcement during the opening plenary that DRI is to introduce a new supply chain management course and certification to help practitioners understand the importance of the new era of supply chain management and organizational interdependencies.

Final thoughts

The practical message for practitioners is straightforward, although far from simple. Firstly, supplier management no longer needs to go deeper into the chain – it has to. Criticality is now defined by service impact and substitutability, not by spend or convenience – which is why buy-in and support from senior management is critical. Secondly, the contract process requires more rigour. Resilience clauses should not be boilerplates, and they should include legal test rights, incident obligations, transition support, sub-outsourcing visibility (or even possibility!), and meaningful service levels. Thirdly, resilience data needs to become operational – and not just sit in shared drives. There is no excuse now for not being able to collect and mine large quantities of data. Dependency mapping should connect suppliers, systems, business services, locations, and people in ways that support event response. Finally, supplier relationships matter. A weak – or even adversarial – procurement model provides an unsuitable base for crisis collaboration. Much of DRI2026’s content was really an argument for relationship-based governance backed by evidence and enforceable terms.

Those conclusions align closely with the DRI Professional Practices. Professional Practice Two: Risk Assessment calls for entity-wide collaboration across supply chain management, cyber security, legal, and other stakeholders. Professional Practice Three: Business Impact Analysis requires identification and documentation of internal and external dependencies. Professional Practice Four: Business Continuity Strategies explicitly covers supply chain strategies, third party services, cloud computing, and cost-benefit analysis. Professional Practice Five: Incident Preparedness and Response extends the frame to external agencies and response resources, while Professional Practice Eight emphasises exercise, assessment, and maintenance. In that sense DRI2026 demonstrated how the Professional Practices could be best applied in a world of cloud concentration, AI adoption, geopolitical friction, and ecosystem risk.

The author

Rachael Elliott is Director of Global Strategy and Innovation for DRI International. Rachael has particular expertise in the technology side of resilience, and has a keen interest in how artificial intelligence can help to transform the resilience of organizations. Her research has been used in the UK Parliament to help develop government industrial strategy as well as in the BDO High Street Sales Tracker, which Elliott was instrumental in developing and is still the UK’s primary barometer for tracking high street sales performance. She maintains a keen interest in competitive intelligence and investigative research techniques.

DRI logo
Resilience Perspectives
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email WhatsApp
Previous ArticleQuantum computing may be closer than you might think – but so are the threats
Next Article Ensuring climate-resilient critical infrastructure through engineering, adaptation, and accurate modelling

Related Posts

An exploding digital padlock illustrates the requirement for post-quantum cryptography.

Research breakthrough brings reliable quantum computers and Q-day closer to reality

September 10, 2026
A danger sign on a digital background.

New blob URL phishing technique evades detection by using legitimate Microsoft services

September 10, 2026
AI risks

Unmanaged AI workflows expose EMEA organizations to rising compliance and data risks

September 9, 2026
City skyline at sunset with bright light trails and a translucent blue smart-city grid overlay and GPS pins indicating locations.

AI world models: future possibilities for organizational resilience?

September 7, 2026
DRJ and BCI logos

DRJ and BCI publish guidance for governing, managing, and using AI in resilience

September 7, 2026
Decision making with over whelming information.

AI can find the vulnerability. Accountability still sits with your crisis leadership

September 7, 2026
Advertisement
Resilience First
This week's most read articles
Under pressure: An egg cracking under pressure applied by squeezing clamps form the sides.

Managing scenario testing for operational resilience

May 16, 2024
COSO logo

New COSO ERM guidance aims to help organizations with practical implementation

May 12, 2026
Close-up of a green-brown iris peering through a jagged tear in dark paper or wall material.

The blind spots in business continuity

September 2, 2026
Latest resources
Agentic AI Network workflow concept - Multi AI agents connected in a shape of a digital brain

The new identity challenge: securing AI agents through API governance

January 13, 2026
Load More

Subscribe to Updates

Get our Resilience Updates newsletter.

Most Popular Feature Articles
Three dark coloured light bulbs on a black background illustrate the concept of The Dark Triad in Crisis Management.

The Dark Triad in crisis management

Five stage crisis management framework

A five stage framework for a crisis management process

Blue interconnected gears and network nodes symbolizing automation and complex machinery.

Agent zero – the 2028 digital pandemic

Latest Reports
A futuristic red warning alert icon with glowing exclamation mark.

Cloud Security Alliance publishes Hugging Face Incident Initial Post-Mortem

A person hold a building door open for a person behind who is tailgating to get unauthorised access.

Security Culture: A Strategic Capability That Builds Resilience in a Volatile World

An identity icon with a map marker on it, indicating the concept of identity as a target for attackers. The icon is on a generic IT background predominantly in black and orange.

Identity-based approaches dominate initial access for ransomware attacks

A promo box for an article about resilience governance.
© 2026 Resilience Forward
  • About Resilience Forward
  • Newsletter
  • Newsfeed
  • Advertise
  • Call for Papers
  • Contact
  • Privacy Policy and Cookie Use
  • AI Use Policy

Type above and press Enter to search. Press Esc to cancel.

Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Ad Blocker Enabled!
Ad Blocker Enabled!
Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.

Sign In or Register

Welcome Back!

Login to your account below.

Lost password?