Close Menu
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
More items
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
X (Twitter) LinkedIn
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
Login
LinkedIn Bluesky
Resilience Forward
Subscribe Now
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
Resilience Forward
You are at:Home»Resilience Resources»The UK Government Resilience Action Plan: what’s in it for resilience professionals? (Page 5)
Resilience Resources

The UK Government Resilience Action Plan: what’s in it for resilience professionals?

In the first of a series of ‘Resilience Perspectives’ articles, Rachael Elliott reviews the UK Government Resilience Action Plan and its promise to involve businesses alongside other key stakeholders in building national resilience.
July 30, 20258 Mins Read
Yellow sign reading 'Businesses Open as Usual' surrounded by traffic cones on a city street.

The UK Government experienced much criticism about its handling of the COVID-19 pandemic. In the first year of the pandemic, the country was ranked at 104 out of 136 in terms of the efficiency of its response to the virus. Although its ranking improved to 20th by 2022, many would argue the early failings in the response impacted the trajectory of how deeply the virus would continue to affect UK citizens in the years to follow.

The Government’s UK COVID-19 Inquiry highlighted its own failings in its first module, published in July 2024. It highlighted inadequate planning, dated and inadaptable plans, little consideration of existing health and social inequalities, limited scientific and inadequate training provided to Government ministers, flawed risk assessments, outdated documentation, and lack of freedom and autonomy to express different opinions – allowing ‘groupthink’ mentalities to prevail during decision making.

Resilience clearly needed to be pushed up the agenda not just in UK Government, but across agencies, companies, voluntary groups and, ultimately, the entire population.

Evolution of the UK Government Resilience Action Plan

The UK Government published its new Resilience Action Plan on 8 July. While it is clear the initial findings of the COVID-19 Inquiry helped to drive the publication of the plan, the Government also points to concerns about geopolitical risk, greater exposure to economic shocks, rapid technological change, and chronic risks such as climate change.

The three objectives the plan promises to deliver – crucially in this Parliament (which will be by August 2029 at the latest) – are as follows:

  1. Continuously assess how resilient the UK is to target interventions and resources effectively;
  2. Enable the whole of society to take action to increase their resilience;
  3. Strengthen the core public sector resilience system.

For any resilience professional, such a document is music to their ears. Any promotion of the importance of resilience serves as a catalyst to winning greater support for resilience programmes within their own organizations.

What can resilience professionals take as positives from the plan?

The Government confirms it is taking an ‘all hazards’ approach to risk planning: a major flaw which came to light was the specificity of the nation’s pandemic plan and, when the nation was hit by COVID-19, the existing plan was dated (2011) and not fit for purpose for the intricacies of the pandemic. While the Government still has plans for specific risks (such as flooding and erosion), it will now also be taking an ‘all hazards’ approach (i.e. preparing for the impact rather than the cause) – as many business continuity and risk professionals are already promoting in their own organizations – which should create a more resilient governmental approach to future crises.

Expansion of the assessment of risk: the plan acknowledges that the current National Risk Register (NRR) provides a view of the current acute risks facing the country, but admits that while this document helps organizations to prepare for a specific set of risks, it needs to go further to “understand drivers and risk interdependencies; increase sharing of our risk data to help policymakers understand and plan for different scenarios; and refocus our assessments on the underlying factors that make some people vulnerable to emergencies.”

Chronic, long-term risks to be considered for the first time: this is something that many business continuity and resilience professionals have been calling for. While organizations may have failsafe plans to recover critical activities after flooding, for example, there is often little consideration given to the increasing frequency of events. In the case of flooding, for example, the cost implications for an organization experiencing multiple incidents and having to rebuild infrastructure each time can be huge. Instead, it is preferable to incorporate proactive resilience measures that reduce the organization’s susceptibility to the effects of flooding. The new Chronic Risks Analysis, published on the same date as the plan, examines 26 chronic risks identified by the UK Government (like climate change, in the case of flooding), to specifically help risk and resilience practitioners prepare their own organizations for longer term challenges.

Data-driven measurement of effectiveness: up until now, there has been no common methodology to measure national and community resilience. The plan recognises this, and promises a new data-driven approach using a variety of individual, household, local, and national indicators. It will also develop a new Cyber Resilience Index to help better understand the cyber risk to critical national infrastructure providers (CNIs).

Whole of society resilience: better communication and collaboration between businesses, charitable and faith organizations, government departments, and local authorities is something that has been discussed in many countries as crucial to building all-of-society resilience. The five UK-specific measures outlined in the report are as follows:

  • Ask and support the public to take action, if they are able to do so, to prepare for emergencies as set out on the https://prepare.campaign.gov.uk website. This will allow urgent support to be directed towards those who need it most.
  • Better integrate the services offered by voluntary, community and faith groups into planning and response. [Author note: this is one of the most important items on this list – community and faith groups are often the first on the ground in emergency situations; and have a deep understanding of community needs, locations of critical services, and contacts within communities. Seeing this embedded into the plan is very welcoming.]
  • Improve the resilience of CNI through targeted interventions based on comprehensive data.
  • Provide the right tools to work with the private sector on risk and resilience planning.
  • Bring together organizations from across the whole of society to enhance the approach to training, exercising, and governance.

Emphasis on the resilience of CNI: there is a recognition that the resilience of the UK’s CNI needs greater attention. The Government is to create a CNI Knowledge Base which, amongst other capabilities, will provide an interactive map of all CNI in the UK to help understand vulnerabilities between the 13 CNI sectors. The Government will also be reviewing and mapping the separate standards of each of the sectors to identify any gaps.

Introduction of a National Exercising Programme (NEP): although the Government already exercises plans through tabletop exercises, walk-throughs, and simulations, it has announced that the NEP will run annual national exercises based on a range of risks involving actors from across society and thousands of individuals. The first exercise, to take place this year, will be ‘Exercise Pegasus’, covering pandemic preparedness.

Greater attention to Local Resilience Forums (LRFs): the Government also plans to provide consistency and standardisation across the Local Resilience Forums (LRFs) across the country. These will play a heightened role in ensuring the resilience of their communities. The Government is investing in ‘LRF Trailblazers’ in Northumbria, Cumbria, Greater Manchester, Suffolk, and London, which will be provided with £2.55 million of funding to pilot new structures for local resilience.

And finally – Chief Resilience Officers! Research by Deloitte showed that 79% of nearly 700 respondents in the risk and resilience industries supported the idea of the creation of a board-level Chief Resilience Officer to help organizations better understand the importance of resilience, foster greater transparency between organizational departments, and ensure that resilience is heard at the top level. The announcement by the Government that LRFs will test having Chief Resilience Officers in place will, if the tests are successful, hopefully transcend into other public sector environments and, ultimately, the private sector too.

Overall, the plan is extremely positive for those working in the resilience sector in the United Kingdom. The fact that the plan will be adapted to operate across all four countries of the United Kingdom (England, Wales, Scotland, Northern Ireland) shows that centralised planning can work across multiple jurisdictions. A more strategic, long-term approach to risk planning should help business continuity and resilience professionals gain more support from the upper echelons of management; and the promotion of greater collaboration between businesses, the public sector, charities, and other voluntary organizations could be taken straight out of a ‘how to do organizational resilience’ textbook.

What might have been welcomed would be a first national exercise that wasn’t focused on pandemic preparedness (given the documented appreciation of a much broader range of risks) and perhaps a better timeline attached to different parts of the plan. But the actionability and depth of content in the plan provides both businesses and the wider community with reassurance that resilience has been pushed up the Government’s agenda – substantially – and lessons have been learned from recent events.

The author

Rachael Elliott is Director of Global Strategy and Innovation for DRI International. Rachael has particular expertise in the technology side of resilience, and has a keen interest in how artificial intelligence can help to transform the resilience of organizations. Her research has been used in the UK Parliament to help develop government industrial strategy as well as in the BDO High Street Sales Tracker, which Elliott was instrumental in developing and is still the UK’s primary barometer for tracking high street sales performance. She maintains a keen interest in competitive intelligence and investigative research techniques.

DRI logo
Resilience Perspectives UK
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email WhatsApp
Previous Article75% of UK businesses would break a ransomware payment ban to save their company
Next Article Cyber Essentials Plus is not enough – UK board directors must take action for holistic cyber protection

Related Posts

An exploding digital padlock illustrates the requirement for post-quantum cryptography.

Research breakthrough brings reliable quantum computers and Q-day closer to reality

September 10, 2026
A danger sign on a digital background.

New blob URL phishing technique evades detection by using legitimate Microsoft services

September 10, 2026
AI risks

Unmanaged AI workflows expose EMEA organizations to rising compliance and data risks

September 9, 2026
City skyline at sunset with bright light trails and a translucent blue smart-city grid overlay and GPS pins indicating locations.

AI world models: future possibilities for organizational resilience?

September 7, 2026
DRJ and BCI logos

DRJ and BCI publish guidance for governing, managing, and using AI in resilience

September 7, 2026
Decision making with over whelming information.

AI can find the vulnerability. Accountability still sits with your crisis leadership

September 7, 2026
Advertisement
Resilience First
This week's most read articles
Under pressure: An egg cracking under pressure applied by squeezing clamps form the sides.

Managing scenario testing for operational resilience

May 16, 2024
COSO logo

New COSO ERM guidance aims to help organizations with practical implementation

May 12, 2026
Close-up of a green-brown iris peering through a jagged tear in dark paper or wall material.

The blind spots in business continuity

September 2, 2026
Latest resources
A digital twin test bay showing a large screen displaying a virtual boiler model synchronised with the physical unit during operational testing.

International cyber agencies publish guidance for isolating critical infrastructure systems during times of crisis

July 29, 2026
Load More

Subscribe to Updates

Get our Resilience Updates newsletter.

Most Popular Feature Articles
Three dark coloured light bulbs on a black background illustrate the concept of The Dark Triad in Crisis Management.

The Dark Triad in crisis management

Five stage crisis management framework

A five stage framework for a crisis management process

Blue interconnected gears and network nodes symbolizing automation and complex machinery.

Agent zero – the 2028 digital pandemic

Latest Reports
A futuristic red warning alert icon with glowing exclamation mark.

Cloud Security Alliance publishes Hugging Face Incident Initial Post-Mortem

A person hold a building door open for a person behind who is tailgating to get unauthorised access.

Security Culture: A Strategic Capability That Builds Resilience in a Volatile World

An identity icon with a map marker on it, indicating the concept of identity as a target for attackers. The icon is on a generic IT background predominantly in black and orange.

Identity-based approaches dominate initial access for ransomware attacks

A promo box for an article about resilience governance.
© 2026 Resilience Forward
  • About Resilience Forward
  • Newsletter
  • Newsfeed
  • Advertise
  • Call for Papers
  • Contact
  • Privacy Policy and Cookie Use
  • AI Use Policy

Type above and press Enter to search. Press Esc to cancel.

Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Ad Blocker Enabled!
Ad Blocker Enabled!
Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.

Sign In or Register

Welcome Back!

Login to your account below.

Lost password?