Operational resilience under FI, DORA and NIS2

Operational resilience: from regulatory requirement to working capability

Operational resilience is a management and supplier issue – not just IT. Starting from Sweden's FI 2026:1 stability report: how to move from requirement to a capability that holds.

Summary: Operational resilience is no longer just an IT or crisis-management issue – it is a management and supplier issue that has to work in everyday life. Taking the Swedish FSA’s (Finansinspektionen) 2026:1 stability report as a starting point, we show how to move from a regulatory requirement to a capability that holds when something actually happens.

The Swedish Financial Supervisory Authority’s (Finansinspektionen, FI) stability report 2026:1 puts its finger on something many organisations already feel in practice: operational resilience is no longer a matter for IT or the crisis organisation alone. It is a management issue, a supplier issue and a capability that needs to work in everyday life.

FI notes that the Swedish financial system is stable, but that new risks continue to develop. Financial firms therefore need to keep strengthening their operational resilience and their ability to handle, among other things, cyber threats. FI also points out that the security-policy situation, digitalisation and rapid technological development, including AI, create new and more complex risks.

It is a development we recognise from our engagements. Many organisations have policies, continuity plans, incident processes and supplier registers in place. The challenge is often getting the whole to work when something actually happens.

Operational resilience is about more than documentation

Operational resilience is about the organisation’s ability to prevent, detect, manage and recover from disruptions.

That can be cyberattacks, IT outages, supplier disruptions, errors in internal processes, weaknesses in change management or events that affect essential services.

FI’s analysis of financial firms’ DORA implementation points to exactly this. In many cases firms have basic structures in place, but FI sees development needs in ongoing follow-up, governance and documentation throughout the lifecycle of ICT contracts, as well as around which contingency measures can be taken during disruptions at ICT third-party providers.

That is an important signal. It is not enough to have a process described. The organisation needs to be able to show that the process is anchored, tested, updated and usable.

Five areas that often decide the capability

When we help organisations strengthen their operational resilience, five areas often recur.

1. Clear governance and responsibility

The first step is knowing who owns what.

Operational resilience spans several functions: IT, information security, risk, legal, procurement, the business, continuity, crisis management and executive management. If the allocation of responsibility is unclear, the work easily becomes fragmented.

Effective governance needs to clarify:

  • who owns critical processes and services
  • who is responsible for risk assessments
  • who decides on risk acceptance
  • who follows up on measures
  • who activates the incident, crisis and continuity processes
  • how reporting to management and the board is done

This is often where the difference between documented compliance and actual capability begins.

2. Risk-based current-state and gap analysis

Many organisations know they need to strengthen resilience but lack a clear picture of where to start.

A current-state analysis or gap analysis should therefore not just measure whether documents exist. It should also assess how the work functions in practice.

That means looking at, for example:

  • incident handling
  • continuity planning
  • recovery capability
  • supplier dependencies
  • information classification
  • risk management
  • technical controls
  • governance documents
  • testing and exercises
  • management reporting

The goal is to create a prioritised picture: what is critical, what is important and what can wait?

FI notes that firms’ ICT risk management is not always proactive enough relative to DORA’s requirements, which can limit the ability to ensure risk control, traceability and continuity.

3. Supplier governance through the whole lifecycle

Many of the most critical dependencies today lie outside the organisation itself.

That can be cloud services, SaaS platforms, operations providers, security vendors, development partners, integration platforms or the outsourcing of business-critical processes.

DORA has tightened the requirements on how financial firms identify and manage digital and operational vulnerabilities, including ICT services from third-party providers. FI points in particular to how complex supplier chains and concentration to certain providers can create contagion effects and affect the ability to deliver important financial services.

Practical third-party management therefore needs to cover more than procurement and contracts. It should cover the whole lifecycle:

  • supplier classification
  • supplier review
  • risk analysis
  • contract requirements
  • subcontractors
  • incident reporting
  • continuity and recovery
  • ongoing follow-up
  • exit planning

The most important thing is that the most critical suppliers are not only identified, but also followed up over time.

4. Incident, continuity and crisis need to fit together

Many organisations have separate processes for incident handling, continuity and crisis management. That can work in everyday life, but during a major disruption the processes need to fit together.

A cyber incident can quickly become a continuity issue. A supplier disruption can become a crisis-management issue. An IT outage can affect customers, regulatory reporting, communication and business-critical services at the same time.

The organisation therefore needs clear decision points:

  • When is an incident just an IT incident?
  • When should the continuity plan be activated?
  • When should crisis management be brought in?
  • When is regulatory reporting required?
  • When should a supplier or third party be escalated?
  • Who decides on reduced functionality, recovery or risk acceptance?

It is at these interfaces that many organisations discover their weaknesses.

5. Testing, exercises and verification

A plan that has not been tested is often just an assumption.

FI emphasises that firms need a systematic and governance-driven approach, with clear allocation of responsibility, documentation and regular verification that processes and controls are actually implemented in the business.

That means the organisation needs to test more than technical recovery.

Examples of relevant tests and exercises are:

  • tabletop exercises for incident and crisis
  • recovery testing of critical systems
  • supplier-based scenarios
  • communication exercises
  • escalation tests
  • testing of manual fallback routines
  • exercising regulatory reporting
  • reviewing decision paths and mandates

The purpose is not to create perfect exercises. The purpose is to find weaknesses before a real event does.

What does this mean in practice?

Operational resilience is not built through a single project. It is built through clear governance, prioritised risk measures, working processes and recurring follow-up.

For many organisations, a good first step is to answer a few concrete questions:

  • Which services and processes are most critical?
  • Which systems and suppliers do they depend on?
  • Which disruptions would have the greatest impact?
  • Which plans exist and when were they last tested?
  • Who makes decisions during a major outage?
  • How quickly can the organisation restore critical functions?
  • What needs to be reported, internally and externally?
  • Which gaps are the most urgent to address?

Once the answers exist, the work becomes more concrete. Then it is possible to prioritise, plan and carry out measures in the right order.

How Kristensson i Skåne can support the work

Kristensson i Skåne helps organisations strengthen their operational resilience through advisory, current-state analysis, gap analysis, governance and practical implementation.

We can support you in defined projects, for example by assessing the current state against DORA, NIS2/the Swedish Cybersecurity Act, ISO 27001 or internal requirements. We can also help on a more ongoing basis, as support for the information security function, risk function, IT management, GRC work or the CISO role.

Examples of support we can deliver:

  • current-state analysis and gap analysis
  • risk analysis and a prioritised action plan
  • developing a governance model and allocation of responsibility
  • support in DORA, NIS2 and ISO 27001 work
  • supplier governance and third-party management
  • review of critical suppliers
  • continuity and recovery planning
  • incident and crisis processes
  • test and exercise planning
  • follow-up of measures and controls
  • management reporting and decision support
  • ongoing GRC or CISO support as a service

Our starting point is practical: the work should not just result in documents. It should lead to clearer responsibility, better decision support and a capability that works when the business is exposed to disruptions.

From compliance to actual resilience

FI’s report clearly shows that operational resilience continues to be a priority. Especially when cyber threats, supplier dependencies, AI, geopolitical uncertainty and essential operations meet in the same risk picture.

For organisations covered by DORA, NIS2/the Swedish Cybersecurity Act or other requirements on information security and continuity, the question is therefore not only whether you have the right documentation.

The question is whether the business can actually prevent, detect, manage and recover from disruptions.

Would you like to know how strong your operational resilience is today? Read more about our work with information security and governance or contact us and we will have a first conversation about your current state, risks and next steps.

Source and further reading: Finansinspektionen (the Swedish FSA), Stability Report 2026:1 – Firms need to keep strengthening their operational resilience (in Swedish).

This is an overview and not legal advice. Every organisation needs to assess its requirements based on its operations, sector, supplier dependencies and regulatory scope.