Local AI: Governance Before Hardware Purchase
Benedikt Langer
10 min readFour developments over two weeks show that locally operated AI goes far beyond the tech stack. ...
7 min. read
In 2026, IT resilience is no longer a separate BCM process maintained by a sub-team outside of IT. It is a core discipline converging with ICT risk management, supply chain governance, and incident response. DORA, NIS2, and ISO 22301 mandate exactly this in their frameworks. Organizations that consolidate now – rather than managing parallel structures – gain cost advantages and credible audit outcomes.
Key Takeaways
RelatedIT Integration Post-M&A: Deal Savings/CIO 2026 in the A.R.T. Framework
What is IT resilience? IT resilience refers to an organization’s ability to maintain its IT services under disruption, recover quickly, and learn from incidents. It encompasses classic business continuity planning, disaster recovery, incident response, and supply chain risk management. In 2026, these disciplines are merging into an integrated framework addressed simultaneously by DORA, NIS2, and ISO 22301.
The driver behind consolidation is operational. Organizations that have run separate business continuity teams, disaster recovery owners, and ICT risk managers repeatedly face the same question in audits: how do the three layers connect? In practice, they often connect poorly, because each group maintains its own playbooks, metrics, and review cycles. Time lost to cross-team coordination translates directly into longer recovery times during a real incident.
DORA addresses this fragmentation explicitly in Article 11. The ICT risk management framework must include a business continuity policy that is interlocked with incident response and supplier risk. NIS2 requires analogous measures in Article 21 for a broader industry base. The two regulations cover different sectors but share the same logic: resilience is a unified construct, not a collection of individual plans.
A consolidated framework follows a simple logic. It defines critical business processes, maps supporting ICT services to them, sets recovery time objectives (RTO) and recovery point objectives (RPO), and links them to concrete playbooks. In parallel, supplier risk management assesses dependencies on critical third parties. Crisis communication, incident response, and team training are integral components–not side issues.
Roles within a consolidated setup are evolving. The traditional BCM manager is becoming a resilience officer with broader responsibilities. ICT risk managers and information security officers now work within the same structures, often under the same leadership. IT operations provides the technical recovery capabilities. For CIOs, this means clear organizational anchoring and a consolidated budget for resilience investments, rather than three separate line items across different cost centers.
Where fragmented resilience fails
What drives consolidated resilience
Alignment between functions is the decisive factor. A company with a unified resilience framework responds noticeably faster during real incidents than one with three parallel structures. The key metric is Mean Time To Recover (MTTR). In practice, the difference between consolidated and fragmented organizations is a factor of two to three. For critical services, that translates to the difference between four hours of downtime and twenty-four.
ISO 22301 is the international standard for Business Continuity Management (BCM). It sets out a Plan-Do-Check-Act cycle for resilience, with clear requirements for business impact analysis, risk assessment, strategy, implementation and testing. Its strength lies in its integration with other ISO standards such as ISO 27001 (information security) and ISO 9001 (quality management). If your organisation has already implemented these standards, adding ISO 22301 on top requires only moderate effort.
For organisations subject to DORA (Digital Operational Resilience Act), ISO 22301 is not mandatory–but it is a recognised form of evidence. A BCM system certified to ISO 22301 significantly reduces the effort required to demonstrate compliance with DORA, as the documentation logic is identical. The same applies to NIS2: the measures required by law for operational continuity, crisis management and recovery can be directly derived from ISO 22301 processes. Supervisory discussions become shorter because the standard is well-known and provides a clear structure.
One practical aspect of ISO 22301 is its requirement for a Business Impact Analysis (BIA), which examines every critical business process for its IT dependencies. For many organisations, the BIA is the most valuable part of implementation, as it provides the first comprehensive picture of which systems need to be restored–and in what order. Without this BIA, all subsequent decisions lack a solid foundation. With it, investments in redundancy and backup strategies become justifiable and measurable.
Testing discipline is the second area where ISO 22301 drives systematic improvement. The standard mandates regular tests, from tabletop exercises and technical recovery drills to full outage simulations. Organisations that embrace this discipline see results not just in audit evidence, but in real incidents that are resolved in hours rather than days. This is the most important ROI factor of an implemented BCM system–though its value in euros is hard to quantify before the first real crisis hits.
However, certification itself is not the end goal. The real value lies in the implemented management system. Many organisations hold ISO certificates without truly embedding the system in their operations. For resilience, this is risky–because a certificate folder won’t solve an incident. The organisations that succeed use ISO 22301 as a structural framework and invest in active training programmes that continually bring the management system to life in practice.
Consolidation discussions are rarely purely technical–they’re an organizational challenge. The executive board must fully endorse them. A CIO driving resilience consolidation will gain the most support by clearly communicating three key points. First: regulatory obligation. DORA and NIS2 demand consolidated frameworks. Supervisory auditors will scrutinize these in the coming quarters. Second: cost reality. Fragmented structures are expensive to maintain, particularly when duplicating tabletop exercises, documentation cycles, and reporting requirements. Third: response reality. In a crisis, speed is everything–and only integrated teams deliver it.
A 12-month roadmap has proven effective in practice. First three months: inventory all existing BCM, DR, and ICT risk management structures, focusing on overlaps and gaps. Months four to six: design the consolidated framework based on ISO 22301, with clear roles and responsibilities. Months seven to nine: implementation, including tooling consolidation and training. Months ten to twelve: first exercise cycle and internal audit preparation for external DORA or NIS2 assessments.
One aspect that must not be sidelined is alignment with the executive board itself. Resilience is a board-level responsibility, not just a CIO agenda. Regular exercises involving the board demonstrate to auditors that top management takes its accountability seriously. Organizations conducting these drills quarterly respond measurably better in real incidents. Preparation is part of governance. Governance is part of leadership.
A point often overlooked in board presentations: resilience isn’t just a compliance issue, even if regulation drives it. A company with a robust resilience framework gains a competitive edge over those that stall longer during incidents. In B2B markets, resilience is increasingly a factor in supplier evaluations. Those who can transparently demonstrate their continuity practices win contracts others lose.
The mid-term investment logic is clear. A consolidated resilience organization saves more budget after two to three years than it costs to implement. This shows in reduced audit efforts, less redundant documentation, and faster incident response. For CFOs scrutinizing the business case, this timeline matters. The first twelve months are an investment; by month eighteen, the cost-benefit ratio shifts in favor of consolidation–provided the organization truly embraces the system and doesn’t let it become shelfware.
Another strategic consideration is supply chain integration. Companies relying on external providers for critical services must verify and document their resilience commitments–DORA and NIS2 require this. In practice, this means contract audits, regular review meetings, and, if necessary, the willingness to switch providers if they fail to meet resilience standards. Organizations that build this muscle early have alternatives in a crisis, not just hope. That makes the difference between controlled response and chaotic crisis management–a gap that’s nearly impossible to bridge without preparation.
Finally, a note on internal communication. Resilience is often conflated with security, given their overlap. But they’re not the same. Security protects against attacks; resilience ensures recovery from all disruptions, including technical failures, supply chain issues, and human error. Clearly distinguishing the two leads to different budget decisions and greater board attention. Both areas must be closely aligned–but not confused. Precise language matters more than technical depth in the boardroom because it prompts the right questions. Ultimately, resilience is a cultural issue shaped by language and rituals, not frameworks alone. The best frameworks only work if an organization lives them–not just files them away. Leaders who grasp this will leverage the resilience debate to their advantage by 2026, especially as external supervisory bodies increasingly demand evidence of lived resilience.
DORA does not require ISO certification. That said, ISO 22301 is a useful complement – it provides a structured approach to documentation and management requirements. In practice, many financial institutions use ISO 22301 as their framework and map DORA compliance onto it. Certification is optional; the underlying structure is almost always worth it.
At minimum, run a full simulation annually and conduct focused tabletop exercises every quarter. Critical service providers should run their own exercises every six months, with results feeding back into the overarching framework. After any significant change to infrastructure or critical services, a targeted supplementary test is strongly advisable.
Mean Time To Recover (MTTR) is the key indicator, complemented by Recovery Point Objective (RPO) and Recovery Time Objective (RTO) per service. MTTR measures how quickly your organisation actually restores operations. RPO and RTO define the targets. The gap between actual performance and those targets is the real lever for improvement.
Hyperscalers and managed service providers are critical third-party vendors under both DORA and NIS2. Their SLAs, exit clauses, and incident notifications must be formally embedded in your own resilience policy. Multi-cloud or multi-region setups are a widely used lever, but they demand disciplined architecture and continuous testing to deliver on their promise.
For a mid-market organisation with 500 to 2,000 employees, expect 150,000 to 400,000 Euro in the first year, covering consulting, tooling, and training. Ongoing costs typically fall between 80,000 and 180,000 Euro annually, depending on certification decisions. Savings from reduced duplication usually offset those costs within 18 to 24 months.
Read more on Digital Chiefs
Digital ChiefsSaaS Sprawl in the Enterprise: How CIOs Will Consolidate Their Application Portfolios by 2026Digital ChiefsIT Integration Post-M&A: What CIOs Will Learn from Failed Deal Savings by 2026Digital ChiefsThe CIO of 2026 in the A.R.T. Framework: Three Skills Companies Are Hunting For NowHeader image source: Pexels / Sergei Starostin (px:6466141)