Close Menu
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
More items
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
X (Twitter) LinkedIn
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
Login
LinkedIn Bluesky
Resilience Forward
Subscribe Now
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
Resilience Forward
You are at:Home»Managing resilience»Technology»Resilience and digital transformation: lessons from Denmark’s PostNord project (Page 7)
Technology

Resilience and digital transformation: lessons from Denmark’s PostNord project

Digital transformation is often presented as a strategic imperative - promising efficiency, accessibility, and data-driven innovation. Yet each wave of transformation brings new dependencies, new vulnerabilities, and new resilience challenges. In this article, Rachael Elliott uses a case study of a digital transformation project carried out by PostNord in Denmark to highlight resilience lessons that can be gleaned from it.
October 30, 20258 Mins Read
A digital butterfly emerging, illustrating the concept of digital transformation.

Introduction

In 2025, Denmark became the first country to announce the end of national letter delivery, with its postal operator, PostNord, transitioning fully to digital communications. From 2026, all government and most business correspondence will move through Digital Post – a legally binding, secure mailbox accessed through national digital identity (MitID).

This shift represents more than administrative reform. It is a national-scale resilience experiment – bringing benefits of cost-effectiveness, immediate direct delivery, tracking of opening, and ease of response. It is also an environmentally sustainable solution. However, it will stress test how Danish government, businesses, and society can handle the disruption of a major infrastructure change.

The lessons extend well beyond Denmark. As countries and organizations accelerate digitisation, they must ensure that resilience is not sacrificed to efficiency. The Danish experience highlights how digital transformation and resilience must be designed together – not as parallel initiatives, but as integrated dimensions of trusted digital infrastructure. Transformation projects provide an important resilience-by-design opportunity, implementing measures in the design phase which may not be possible once the new system is operational.

The rationale behind digital-only communication is compelling, yet resilience professionals will recognise that every efficiency gain introduces new dependencies.

Denmark’s Digital Post system is built on three private platforms (borger.dk, e-Boks, and mit.dk), unified by a single secure identity layer (MitID). Messages sent through these portals carry full legal effect the moment they arrive – recipients are deemed to have received them, regardless of whether they have logged in.

From a transformation standpoint, this is elegant. From a resilience perspective, it is a concentration risk. Millions of independent letterboxes are replaced by a few digital gateways. Failure in identity authentication, network access, or mailbox uptime could simultaneously paralyse access to government, legal, or financial communications.

This convergence illustrates a core principle of resilience in digital transformation: every act of centralisation must be balanced by an equal consideration of diversification, failover, and fallback.

The resilience dimension of digital transformation

Digital transformation and resilience are often treated as separate agendas: one focused on innovation and growth, the other on risk and continuity. In reality, they are interdependent. Resilience is at the heart of any digital transformation project, ensuring that the project not only launches successfully but continues to thrive as time and adversities challenge the system.

Three key resilience messages are highly relevant to digital transformation:

Design for disruption

Transformation programmes must anticipate system outages, data corruption, and loss of access – not just as IT incidents, but as governance and legal risks.

Resilience is systemic

A resilient organization designs its processes, communications, and dependencies so that no single point of failure can disable a critical function. Resilience professionals following DRI International’s Professional Practice 2 (Risk Assessment ) and Professional Practice 3 (Business Impact Analysis) should identify these concentrations, while Professional Practice 4 (Business Continuity Strategies) identifies where critical processes, technologies, or resources depend on a single (or, in this case, concentrated) asset, system, or person, and emphasises and guides on the importance of redundancy and diversification.

Digital inclusion is part of resilience

Systems that exclude users – due to digital illiteracy, disability, or connectivity gaps – create silent failures that can become social or reputational crises.

Denmark’s experience illustrates all three principles. Its model shows how resilience can be strengthened by strong identity management and traceability, but also weakened by legal rigidity and dependency concentration.

Potential resilience issues

There are four potential digital transformation resilience issues which are immediately apparent in this project:

Dependencies, concentration risk, and single points of failure

When services become entirely digital, the resilience burden moves from distributed local infrastructure to a few central providers – identity, cloud, authentication, and telecoms. This is the digital equivalent of putting all eggs in one (well-protected) basket.

The 2024 CrowdStrike global outage, which crippled millions of Windows devices, highlighted this systemic fragility. The incident was not a cyber attack, but a software update error propagated instantly worldwide. It underscored how interconnected systems magnify the impact of small mistakes.

For resilience professionals, this demands rigorous dependency mapping. Business impact analyses (BIAs) should identify which critical services rely on shared providers or platforms. Resilience strategies must then specify alternative channels, pre-approved manual workarounds, and recovery time objectives that reflect real-world digital interdependence.

Legal and process rigidity

Digital transformation often assumes technological reliability. Legal frameworks, however, can codify fragile assumptions. In Denmark, messages delivered via the new Digital Post system will have immediate legal effect: creating an operational fragility where outages or access failures could lead to legal risks, lost contracts, or regulatory breaches.

Resilient digital systems must include procedural flexibility: contingency clauses that recognise and mitigate system outages. In this case, examples include suspending legal deadlines during verified digital disruption or providing alternative authenticated delivery channels.

A resilient digital society must not penalise citizens or organizations for the failure of systems beyond their control.

Inclusion and digital access

Digital transformation succeeds only when it is universal. Exclusion – whether through disability, connectivity barriers, or socio-economic disadvantage – creates hidden points of failure.

Denmark’s exemption and delegation options for Digital Post users are progressive, but the administrative process itself requires digital literacy. True resilience involves proactive design for digital inequality: multi-channel access, assisted authentication, and offline contingencies that preserve essential communication even when users are disconnected.

DRI International’s Professional Practice 6 provides useful guidance for just this situation: helping to reduce the risk of people not receiving notifications:
Maintain up-to-date contact information for staff and key stakeholders.
Use multi-modal communication (do not rely on a single method).
Incorporate accessibility considerations (hearing/vision impairments, language differences).
Provide for two-way communication — not just pushing out alerts, but also receiving confirmation and feedback.
Integrate communications with emergency services, regulators, and the public if necessary.

Data retention, privacy, and continuity of records

Digitisation changes not only how information is transmitted, but also how it is stored and owned. In Denmark, messages in e-Boks can be deleted permanently by users, and the platform itself is not responsible for long-term content preservation.

This raises a crucial question: who is the record keeper in a digital-only world?

Resilience in digital transformation requires that organizations maintain their own independent record management, export routines, and secure backups outside vendor platforms.

Embedding resilience into digital transformation governance

Resilient digital transformation depends as much on governance as on technology. The following governance mechanisms can help organizations and public authorities strengthen resilience as they digitise:

Board oversight and accountability

Boards must treat digital transformation as a resilience issue, not just a strategic or IT investment. The board’s resilience role is to ensure that transformation projects include:

  • Defined impact tolerances: clarifying the acceptable duration and impact of digital service disruption.
  • Clear lines of accountability between digital, risk, and business continuity teams.
  • Regular resilience stress tests within digital transformation programmes.

Third-party and ecosystem risk management

Digital ecosystems depend on multiple providers: cloud services, authentication tools, APIs, and communication gateways. Regulations such as the EU’s DORA and NIS2 frameworks emphasise third-party oversight as a core resilience requirement.

Organizations must assess:

  • Which critical services depend on external providers.
  • Whether service-level agreements include resilience metrics (uptime, recovery time objectives, impact tolerance thresholds, for example).
  • How continuity or failover will occur if a key provider fails.

Testing scenarios such as ‘identity provider unavailable’ or ‘API outage during regulatory deadline’ should become standard practice.

Resilient-by-design architecture

As highlighted above, digital transformation projects should incorporate resilience at the design stage, applying principles such as:

  • Redundancy: multiple access routes (e.g. mobile app, web, hardware token).
  • Graceful degradation: systems remain at least partially functional during outages.
  • Interoperability: enabling switching between providers without data loss or lock-in.
  • Offline fallbacks: printable codes, voice systems, or delegated human verification when digital channels fail.

Human and cultural factors

Technological resilience depends on human adaptability. Staff must understand fallback procedures and how to operate without digital access. Embedding digital contingency awareness into training, crisis exercises, and communication protocols is essential.

A resilient digital culture values adaptability as much as efficiency.

Summary: digital transformation as a resilience discipline

Denmark’s PostNord transition symbolises a global trend, with analogue systems which have been in place for decades or even centuries, are rapidly reconfigured through digital transformation.

The key lessons for organizations, policymakers, and resilience professionals are clear:

Resilience must be designed in, not added later: every digital process should include fallback routes, redundancy, and human-centred exception handling.

Digital dependence equals systemic risk: organizations must map critical dependencies and test failure at ecosystem scale.

Inclusion is essential to resilience: systems that leave people behind become brittle under stress.

Governance is a key requirement: boards must own digital resilience strategy and test it as rigorously as financial or safety governance.

Denmark’s experience offers a clear lesson and only time will tell whether it is one that the Danish government has learned: digital transformation without resilience is not progress – it is fragility at scale.

The author

Rachael Elliott is Director of Global Strategy and Innovation for DRI International. Rachael has particular expertise in the technology side of resilience, and has a keen interest in how artificial intelligence can help to transform the resilience of organizations. Her research has been used in the UK Parliament to help develop government industrial strategy as well as in the BDO High Street Sales Tracker, which Elliott was instrumental in developing and is still the UK’s primary barometer for tracking high street sales performance. She maintains a keen interest in competitive intelligence and investigative research techniques.

DRI logo
Europe Resilience Perspectives UK
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email WhatsApp
Previous ArticleResilience West: new forum for South West England and South Wales
Next Article Unplanned downtime in manufacturing companies explored

Related Posts

An exploding digital padlock illustrates the requirement for post-quantum cryptography.

Research breakthrough brings reliable quantum computers and Q-day closer to reality

September 10, 2026
A danger sign on a digital background.

New blob URL phishing technique evades detection by using legitimate Microsoft services

September 10, 2026
AI risks

Unmanaged AI workflows expose EMEA organizations to rising compliance and data risks

September 9, 2026
City skyline at sunset with bright light trails and a translucent blue smart-city grid overlay and GPS pins indicating locations.

AI world models: future possibilities for organizational resilience?

September 7, 2026
DRJ and BCI logos

DRJ and BCI publish guidance for governing, managing, and using AI in resilience

September 7, 2026
Decision making with over whelming information.

AI can find the vulnerability. Accountability still sits with your crisis leadership

September 7, 2026
Advertisement
Resilience First
This week's most read articles
Under pressure: An egg cracking under pressure applied by squeezing clamps form the sides.

Managing scenario testing for operational resilience

May 16, 2024
COSO logo

New COSO ERM guidance aims to help organizations with practical implementation

May 12, 2026
Close-up of a green-brown iris peering through a jagged tear in dark paper or wall material.

The blind spots in business continuity

September 2, 2026
Latest resources
Blue interconnected gears and network nodes symbolizing automation and complex machinery.

Agent zero – the 2028 digital pandemic

July 9, 2026
Load More

Subscribe to Updates

Get our Resilience Updates newsletter.

Most Popular Feature Articles
Three dark coloured light bulbs on a black background illustrate the concept of The Dark Triad in Crisis Management.

The Dark Triad in crisis management

Five stage crisis management framework

A five stage framework for a crisis management process

Blue interconnected gears and network nodes symbolizing automation and complex machinery.

Agent zero – the 2028 digital pandemic

Latest Reports
A futuristic red warning alert icon with glowing exclamation mark.

Cloud Security Alliance publishes Hugging Face Incident Initial Post-Mortem

A person hold a building door open for a person behind who is tailgating to get unauthorised access.

Security Culture: A Strategic Capability That Builds Resilience in a Volatile World

An identity icon with a map marker on it, indicating the concept of identity as a target for attackers. The icon is on a generic IT background predominantly in black and orange.

Identity-based approaches dominate initial access for ransomware attacks

A promo box for an article about resilience governance.
© 2026 Resilience Forward
  • About Resilience Forward
  • Newsletter
  • Newsfeed
  • Advertise
  • Call for Papers
  • Contact
  • Privacy Policy and Cookie Use
  • AI Use Policy

Type above and press Enter to search. Press Esc to cancel.

Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Ad Blocker Enabled!
Ad Blocker Enabled!
Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.

Sign In or Register

Welcome Back!

Login to your account below.

Lost password?