Introduction
In 2025, Denmark became the first country to announce the end of national letter delivery, with its postal operator, PostNord, transitioning fully to digital communications. From 2026, all government and most business correspondence will move through Digital Post – a legally binding, secure mailbox accessed through national digital identity (MitID).
This shift represents more than administrative reform. It is a national-scale resilience experiment – bringing benefits of cost-effectiveness, immediate direct delivery, tracking of opening, and ease of response. It is also an environmentally sustainable solution. However, it will stress test how Danish government, businesses, and society can handle the disruption of a major infrastructure change.
The lessons extend well beyond Denmark. As countries and organizations accelerate digitisation, they must ensure that resilience is not sacrificed to efficiency. The Danish experience highlights how digital transformation and resilience must be designed together – not as parallel initiatives, but as integrated dimensions of trusted digital infrastructure. Transformation projects provide an important resilience-by-design opportunity, implementing measures in the design phase which may not be possible once the new system is operational.
The rationale behind digital-only communication is compelling, yet resilience professionals will recognise that every efficiency gain introduces new dependencies.
Denmark’s Digital Post system is built on three private platforms (borger.dk, e-Boks, and mit.dk), unified by a single secure identity layer (MitID). Messages sent through these portals carry full legal effect the moment they arrive – recipients are deemed to have received them, regardless of whether they have logged in.
From a transformation standpoint, this is elegant. From a resilience perspective, it is a concentration risk. Millions of independent letterboxes are replaced by a few digital gateways. Failure in identity authentication, network access, or mailbox uptime could simultaneously paralyse access to government, legal, or financial communications.
This convergence illustrates a core principle of resilience in digital transformation: every act of centralisation must be balanced by an equal consideration of diversification, failover, and fallback.
The resilience dimension of digital transformation
Digital transformation and resilience are often treated as separate agendas: one focused on innovation and growth, the other on risk and continuity. In reality, they are interdependent. Resilience is at the heart of any digital transformation project, ensuring that the project not only launches successfully but continues to thrive as time and adversities challenge the system.
Three key resilience messages are highly relevant to digital transformation:
Design for disruption
Transformation programmes must anticipate system outages, data corruption, and loss of access – not just as IT incidents, but as governance and legal risks.
Resilience is systemic
A resilient organization designs its processes, communications, and dependencies so that no single point of failure can disable a critical function. Resilience professionals following DRI International’s Professional Practice 2 (Risk Assessment ) and Professional Practice 3 (Business Impact Analysis) should identify these concentrations, while Professional Practice 4 (Business Continuity Strategies) identifies where critical processes, technologies, or resources depend on a single (or, in this case, concentrated) asset, system, or person, and emphasises and guides on the importance of redundancy and diversification.
Digital inclusion is part of resilience
Systems that exclude users – due to digital illiteracy, disability, or connectivity gaps – create silent failures that can become social or reputational crises.
Denmark’s experience illustrates all three principles. Its model shows how resilience can be strengthened by strong identity management and traceability, but also weakened by legal rigidity and dependency concentration.
Potential resilience issues
There are four potential digital transformation resilience issues which are immediately apparent in this project:
Dependencies, concentration risk, and single points of failure
When services become entirely digital, the resilience burden moves from distributed local infrastructure to a few central providers – identity, cloud, authentication, and telecoms. This is the digital equivalent of putting all eggs in one (well-protected) basket.
The 2024 CrowdStrike global outage, which crippled millions of Windows devices, highlighted this systemic fragility. The incident was not a cyber attack, but a software update error propagated instantly worldwide. It underscored how interconnected systems magnify the impact of small mistakes.
For resilience professionals, this demands rigorous dependency mapping. Business impact analyses (BIAs) should identify which critical services rely on shared providers or platforms. Resilience strategies must then specify alternative channels, pre-approved manual workarounds, and recovery time objectives that reflect real-world digital interdependence.
Legal and process rigidity
Digital transformation often assumes technological reliability. Legal frameworks, however, can codify fragile assumptions. In Denmark, messages delivered via the new Digital Post system will have immediate legal effect: creating an operational fragility where outages or access failures could lead to legal risks, lost contracts, or regulatory breaches.
Resilient digital systems must include procedural flexibility: contingency clauses that recognise and mitigate system outages. In this case, examples include suspending legal deadlines during verified digital disruption or providing alternative authenticated delivery channels.
A resilient digital society must not penalise citizens or organizations for the failure of systems beyond their control.
Inclusion and digital access
Digital transformation succeeds only when it is universal. Exclusion – whether through disability, connectivity barriers, or socio-economic disadvantage – creates hidden points of failure.
Denmark’s exemption and delegation options for Digital Post users are progressive, but the administrative process itself requires digital literacy. True resilience involves proactive design for digital inequality: multi-channel access, assisted authentication, and offline contingencies that preserve essential communication even when users are disconnected.
| DRI International’s Professional Practice 6 provides useful guidance for just this situation: helping to reduce the risk of people not receiving notifications: Maintain up-to-date contact information for staff and key stakeholders. Use multi-modal communication (do not rely on a single method). Incorporate accessibility considerations (hearing/vision impairments, language differences). Provide for two-way communication — not just pushing out alerts, but also receiving confirmation and feedback. Integrate communications with emergency services, regulators, and the public if necessary. |
Data retention, privacy, and continuity of records
Digitisation changes not only how information is transmitted, but also how it is stored and owned. In Denmark, messages in e-Boks can be deleted permanently by users, and the platform itself is not responsible for long-term content preservation.
This raises a crucial question: who is the record keeper in a digital-only world?
Resilience in digital transformation requires that organizations maintain their own independent record management, export routines, and secure backups outside vendor platforms.
Embedding resilience into digital transformation governance
Resilient digital transformation depends as much on governance as on technology. The following governance mechanisms can help organizations and public authorities strengthen resilience as they digitise:
Board oversight and accountability
Boards must treat digital transformation as a resilience issue, not just a strategic or IT investment. The board’s resilience role is to ensure that transformation projects include:
- Defined impact tolerances: clarifying the acceptable duration and impact of digital service disruption.
- Clear lines of accountability between digital, risk, and business continuity teams.
- Regular resilience stress tests within digital transformation programmes.
Third-party and ecosystem risk management
Digital ecosystems depend on multiple providers: cloud services, authentication tools, APIs, and communication gateways. Regulations such as the EU’s DORA and NIS2 frameworks emphasise third-party oversight as a core resilience requirement.
Organizations must assess:
- Which critical services depend on external providers.
- Whether service-level agreements include resilience metrics (uptime, recovery time objectives, impact tolerance thresholds, for example).
- How continuity or failover will occur if a key provider fails.
Testing scenarios such as ‘identity provider unavailable’ or ‘API outage during regulatory deadline’ should become standard practice.
Resilient-by-design architecture
As highlighted above, digital transformation projects should incorporate resilience at the design stage, applying principles such as:
- Redundancy: multiple access routes (e.g. mobile app, web, hardware token).
- Graceful degradation: systems remain at least partially functional during outages.
- Interoperability: enabling switching between providers without data loss or lock-in.
- Offline fallbacks: printable codes, voice systems, or delegated human verification when digital channels fail.
Human and cultural factors
Technological resilience depends on human adaptability. Staff must understand fallback procedures and how to operate without digital access. Embedding digital contingency awareness into training, crisis exercises, and communication protocols is essential.
A resilient digital culture values adaptability as much as efficiency.
Summary: digital transformation as a resilience discipline
Denmark’s PostNord transition symbolises a global trend, with analogue systems which have been in place for decades or even centuries, are rapidly reconfigured through digital transformation.
The key lessons for organizations, policymakers, and resilience professionals are clear:
Resilience must be designed in, not added later: every digital process should include fallback routes, redundancy, and human-centred exception handling.
Digital dependence equals systemic risk: organizations must map critical dependencies and test failure at ecosystem scale.
Inclusion is essential to resilience: systems that leave people behind become brittle under stress.
Governance is a key requirement: boards must own digital resilience strategy and test it as rigorously as financial or safety governance.
Denmark’s experience offers a clear lesson and only time will tell whether it is one that the Danish government has learned: digital transformation without resilience is not progress – it is fragility at scale.
The author
Rachael Elliott is Director of Global Strategy and Innovation for DRI International. Rachael has particular expertise in the technology side of resilience, and has a keen interest in how artificial intelligence can help to transform the resilience of organizations. Her research has been used in the UK Parliament to help develop government industrial strategy as well as in the BDO High Street Sales Tracker, which Elliott was instrumental in developing and is still the UK’s primary barometer for tracking high street sales performance. She maintains a keen interest in competitive intelligence and investigative research techniques.







