
By Botan Osman, CEO & Co-Founder, Restrata
July 22, 2026
For all its history, operational resilience has been treated as a function that reported upward. Something the security or resilience team owned, the risk team monitored and the executive leaders heard about once a quarter, usually after an incident rather than before one. That started to change after COVID, and even more so over the past eighteen months. Now sharply in the first half of 2026, resilience has moved from the operations floor to the executive table. I want to use the rest of this article to explain why that shift happened, and to set out the questions every executive leader should be able to answer before the next disruption, not after.”
The 2026 conflict between Iran, Israel and the United States was, for many organisations, the moment the shift became undeniable. When traffic through the Strait of Hormuz was choked off from late February, the International Energy Agency called it the largest supply disruption in the history of the global oil market. But an executiveโs lesson was not really about oil prices. It was about exposure. Companies discovered, some in real time, that their legacy tools could not tell them where their people were fast enough, and that the assumptions underpinning their site selection, evacuation plans and regional headquarters no longer held strong.
That is why operational resilience is now an executive-level imperative. Not because threats are new, but because accountability for being unprepared can no longer be delegated.
What operational resilience actually means
Operational resilience is an organisation’s ability to keep protecting its people and running its critical operations through disruption – anticipating threats, absorbing shocks, responding at speed and recovering without lasting damage.
It spans workforce safety, security, crisis response and business continuity. Unlike traditional risk management, which asks what might go wrong, operational resilience asks a harder question: when something does go wrong, how quickly and how confidently can we act?
The distinction matters at an executive level because it reframes resilience as a measure of decision-making capability, not a checklist of controls. A CEO can no longer be satisfied that plans exist. They have to be satisfied that the organisation can execute those plans in the critical minutes and hours that decide an outcome.
Why resilience has moved to the executive table
Three forces have converged to put resilience on the executive agenda, and they reinforce each other.
The first is geopolitical instability that no longer respects borders or forecasts. The events of early 2026 were not a regional energy story. They disrupted aviation across the Gulf, forced multinational banks to close and relocate regional offices, and stranded people and assets far from the frontline. Disruption of that scale lands directly on the risks an executive team is accountable for: duty of care, operational continuity, financial exposure and reputation.
The second is scrutiny. Regulators, insurers and investors increasingly expect organisations to demonstrate resilience rather than assert it. In financial services, operational resilience is already a formal regulatory obligation. That expectation is spreading into energy, critical infrastructure, logistics and beyond, and it is being asked of the CEO, not the back office.
The third is budget and mandate. Rather than growing, resilience budgets are often being cut as firms respond to financial disruption – yet security and resilience functions are being asked to cover more ground with fewer resources. It’s not that boards are dictating where that budget goes; it’s that they now expect CEOs to be able to articulate the organisation’s resilience posture. Resilience has become a governance question, and governance questions belong on the executive table.
The regional problem is now a global problem
For years, organisations treated resilience as a function of geography. You invested where you operated in higher-risk regions and assumed relative stability everywhere else. The teams closest to live conflict understood the exposure and secured the budget to manage it. The rest of the organisation watched from a comfortable distance.
What global leadership learned in 2026 is that a crisis in one region does not stay in that region. Weโve seen real evidence of conflict spreading into previously assumed safe territories – like the UAE with the US-Iran conflict this year. Crises can now reach into supply chains, travel networks, cloud infrastructure, insurance markets and the safety of employees who never set foot near the conflict. The regional exposure became the global exposure, and the people who had been managing it locally suddenly had the global executives listening.
The implication for how organisations operate is significant. Resilience can no longer be a series of regional programmes running on different systems, to different standards, with different pictures of the truth. CEOs are beginning to demand one operational picture across the entire enterprise, because a fragmented view is precisely what fails when disruption crosses borders.
Nowhere can be assumed safe
The hardest idea for executive leaders to absorb is also the most important: you have to be ready anywhere, not just where you have historically judged the risk to be highest.
I say this often, because it runs against decades of planning habit. The organisations that coped best in early 2026 were not the ones with the most detailed regional playbooks. They were the ones that could see their people and operations everywhere, and could confidently act on what they saw without first stitching together information from a dozen disconnected systems. The companies that struggled were the ones that relied on legacy systems, simple mass comms, and travel tracking tech, as they had to spend hours piecing together a disparate picture.
One pattern from that period is instructive: many energy and banking majors moved to protect their people on the strength of their own threat assessment, days before government advisories caught up. They did not wait to be told. They already had the picture.
That capability – global visibility, connected data, and the ability to convert it into action at speed – is what separates organisations that manage disruption, from those that are managed by it. It cannot be assembled during a crisis. It has to exist before one. We call this operational confidence, which you can learn more about here.
Why executive teams are using AI to strengthen resilience – and the trap to avoid
There is another shift Iโm seeing, and it is coming from the top down. Executives are pressing all functions to embrace AI into their workflows and that includes their security and resilience leaders. Some of that is genuine conviction that AI can compress the time between a signal and a smarter decision. Some of it is the reality that resilience investment is easier to approve when it sits inside a wider digital transformation mandate. Either way, the direction of travel is clear, and it is being set by the executives.
I welcome that ambition, but it needs some guard rails, because the wrong applications of AI in a resilience context can be worse than none at all. This is where I come back to something I believe deeply. Successful operational resilience and corporate security rests on what I think of as a triangle of trust, involving software, AI and, crucially, humans.
In that triangle, software provides precision: exact calculations, great user interfaces and audit trails built on robust, accurate, well-structured data with comprehensive guard rails. AI is the interpreter, there to recognise patterns and detect anomalies across more information than any team could hold in their head. But the judgement calls are, and in my opinion always should be, made by humans. And starting by asking, โwhat are we trying to achieve, what decisions is the human making, and how can we use AI and software to enable that?โ That balance is not a limitation on the technology. It is the reason the technology can be trusted at all.
And trust is the point. When people believe in the process, they share the data that makes resilience work – the location, the movements, the operational detail they might once have been reluctant to hand over. They do it because they have faith in a system that could ultimately save their lives. A CEO evaluating AI in resilience should therefore ask not only what the technology can automate, but whether it strengthens or erodes that trust. AI grounded in your own live operational data, supporting human judgement rather than replacing it, strengthens that trust. Generic AI bolted on for its own sake does the opposite.
The questions every executive team should be asking
A useful test of resilience maturity is whether an executive team can get clear answers to a short set of questions before the next disruption, not during it:
- If an incident occurred in a region we operate in tomorrow, how quickly could we confirm exactly where our people are?
- Do our teams work from one shared operational picture, or several disconnected versions of the truth?
- Does our technology tell us what we need to know? Or does It only tell us part of the picture leaving the rest to us?
- Can we act on our own threat assessment, or are we dependent on external advisories catching up?
- When we use AI in resilience, is it grounded in our own operational data – and does a human stay accountable for every critical decision?
- Would our response hold up to scrutiny weeks later, with a defensible record of what we knew and when we acted?
- Does our technology Increase or decrease the cognitive load on our operators
If those answers require a project to produce, the organisation is not yet resilient. It is hopeful.
From cost centre to executive-team capability
The organisations getting this right have stopped treating resilience as an insurance policy and started treating it as an operating capability. They have moved from fragmented tools and manual coordination toward a single operational picture that connects their people, assets, sites, journeys and threats – and supports faster, more confident decisions when the stakes are highest. This is the shift we describe as Connected Resilience: technology, experienced practitioners and AI grounded in the organisation, working together so teams can prepare better, respond faster and recover stronger.
Operational resilience has become an executive-level imperative because the world stopped offering organisations the luxury of assuming where disruption will come from. The executives that internalise that – and build the capability to see clearly and act quickly, anywhere – will be the ones still operating with confidence when the next disruption arrives. And it will arrive.
See what one operational picture looks like for your organisation. Book a demo of resilienceOS, and we will walk your team through how leading enterprises connect their real-time data across people, assets, sites, journeys and threats – and act with confidence when it matters most.
[Book a demo โ]
FAQ
What is operational resilience? Operational resilience is an organisation’s ability to keep protecting its people and running its critical operations through disruption – anticipating threats, absorbing shocks, responding at speed and recovering without lasting damage. It brings together workforce safety, security, crisis response and business continuity into a single capability.
Why is operational resilience now an executive-level issue? Three forces have pushed it onto the executive agenda: geopolitical instability that crosses borders and disrupts operations far from any frontline, rising regulatory and investor scrutiny that expects resilience to be demonstrated rather than asserted, and growing security budgets whose outcomes executives now own. Together they make resilience a governance question, not an operational one.
How is operational resilience different from risk management? Traditional risk management asks what might go wrong and how likely it is. Operational resilience asks a harder, execution-focused question: when something does go wrong, how quickly and how confidently can the organisation act? It is measured by decision-making capability under pressure, not by the existence of plans.
What role should AI play in operational resilience? AI should act as an interpreter – recognising patterns and detecting anomalies across more data than any team can hold – while people retain accountability for critical decisions. The most effective approach is what Restrata calls a triangle of trust: software for precision, AI for interpretation, and human judgement for the decisions that matter. AI grounded in an organisation’s own live operational data supports that judgement; generic AI tends to undermine the trust the whole system depends on.
What questions should a CEO ask about operational resilience? A CEO should be able to get fast, clear answers to: how quickly we could locate our people if an incident struck a region we operate in; whether teams work from one shared operational picture; whether our AI is grounded in our own data with a human accountable for decisions; and whether our response would hold up to scrutiny with a defensible record afterwards.