Module · Built · End-to-end resilience

Resilience, the way it should be done. End-to-end.

Operational resilience maturity across seven pillars, practitioner-authored. Most resilience tools stop at business continuity. This module covers the full picture - strategy, business, technology, supplier, cyber, AI system resilience, and crisis management.

Resilience
Operational resilience
Built
RS
Resilience
7
Resilience pillars
CPS 230 · CPS 234
ISO 22301 · 27001
NIST CSF 2.0
Standards aligned
4
Add-ons live
0–4
Maturity scale
🇦🇺🇳🇿🇭🇰🇻🇳🇲🇾🇹🇼🇦🇪🇸🇦🇶🇦🇵🇰
01End-to-end · The differentiator

End-to-end. Not just BCP.

Most resilience tools focus on business continuity and disaster recovery. That's one slice of the picture. Real operational resilience needs seven connected disciplines - strategy at the top, crisis at the bottom, with five domain-specific resilience layers in between.

- TOP · STRATEGY
- BOTTOM · CRISIS & RECOVERY
- Typical tools×

Stop at BCP / DR.

Business continuity plans
Disaster recovery plans
×No view of supplier resilience posture
×No coverage of AI system resilience
×Cyber resilience treated as separate
×Strategy and crisis are someone else's problem
- MaturityOne

Covers the full stack.

Resilience strategy and board governance
Business, technology and supplier resilience
Cyber resilience integrated, not siloed
AI system resilience - model failure, drift, dependency
Crisis management and communications discipline
Cross-domain cascade across all seven pillars
02The seven pillars

Seven pillars. One resilience score.

Each pillar is practitioner-authored, scored on the unified 0–4 scale, and weighted into the cross-domain cascade. Together they answer the only question that matters: can the organisation absorb shock and keep operating?

02.1

Resilience Governance & Strategy

Board-approved resilience strategy, executive accountability, three-lines model, risk appetite cascade, committee charters, regulatory alignment.

02.2

Business Resilience

Critical operations, customer-impact assessment, tolerance levels, BCP framework, RTO/RPO discipline, recovery strategies and exercise discipline.

02.3

Technology Resilience

Application and infrastructure resilience, redundancy, failover, capacity, change management, technology lifecycle, cloud and platform dependencies.

02.4

Supplier Resilience

Material service provider resilience, exit planning, joint testing, contractual resilience clauses, fourth-party visibility, concentration risk.

02.5

Cyber Resilience

Ransomware-specific scenarios, immutable backup posture, recovery testing, integration with cyber module, secure-by-design recovery.

02.6

AI System Resilience

Model failure modes, drift detection, fallback paths, AI dependency mapping, autonomous-decision recovery, model retraining discipline.

02.7

Crisis Management & Communication

Crisis team activation, severity model, internal and external communications, stakeholder management, regulator engagement, post-incident discipline.

03How it scores

Five levels. One unified scale.

Every resilience pillar is scored on the 0–4 maturity scale - the same scale every other MaturityOne module uses. So resilience maturity reconciles directly with Cyber, Third Party Risk and Compliance.

0
Not Established
No capability
1
Ad Hoc
Reactive · undocumented
2
Defined
Documented · inconsistent
3
Managed
Measured · consistent
4
Optimised
Continuous improvement
How a score is calculated. Each question carries a 1–5 input scale that maps deterministically to the 0–4 output. Domain scores aggregate the practitioner-weighted question scores; module score aggregates domain scores. Reviewer adjustment is captured at every level.
04Regulatory add-ons

Score once. Map to many.

Every regulatory add-on is a clause-level mapping from the resilience maturity score to a specific standard. Four add-ons live today, covering the full AU regulatory landscape.

APRA CPS 230Operational risk management
Live

Full mapping to CPS 230 operational resilience requirements. The Australian prudential standard for operational risk. Maps critical operations, tolerance levels, BCP, scenario testing, and material service providers. Required by July 2025.

Live · 2025 deadlineCritical operations · Tolerances
APRA CPS 234Information security prudential
Live

The Australian prudential standard for information security. Maps resilience to CPS 234 capability requirements, control implementation and incident notification. Relevant for the cyber-resilience overlap.

LiveCapability · Notification
ISO 22301:2019Business continuity management
Live

The international standard for business continuity management systems. Maps maturity to ISO 22301 clauses 4–10 - context, leadership, planning, support, operation, and performance evaluation.

LiveClauses 4-10
ISO/IEC 27001:2022Information security management
Live

Annex A control mapping for resilience-relevant controls. Maps to controls covering business continuity, incident management, supplier relationships and physical security.

LiveAnnex A subset
NIST CSF 2.0Cybersecurity framework
Next

NIST Cybersecurity Framework 2.0 - Recover function focus. Particularly the Recover (RC) and the new Govern (GV) function added in CSF 2.0. Widely adopted globally.

Coming nextRC + GV functions
EU DORADigital Operational Resilience Act
Roadmap

The EU Digital Operational Resilience Act - covers ICT risk management, incident reporting, testing, and third-party risk. Required by EU financial entities since Jan 2025.

Roadmap · 2026EU financial entities
05Cross-domain integration

Resilience scope is set by other modules.

You cannot run a resilience program without knowing which services are critical. MaturityOne wires Resilience into the specialist modules that define its scope.

Appetite cascades in

From Enterprise Risk to tolerance windows

Board-set risk appetite drives recovery objectives by criticality tier. Critical service classification from Enterprise Risk drives the resilience module's in-scope list.

Findings cascade out

From tolerance breaches to residual risk

Failed disaster recovery tests and lessons-learned flow back into Enterprise Risk as residual risk signals. Tolerance breaches flow into Compliance for reporting.

Triggers fire sideways

Triggers fire from cyber and TP

A material cyber incident automatically triggers a resilience tolerance review. A critical vendor incident triggers a recalculation. Live, not annual.

What this looks like in practice. A material cyber incident affects payments. Within minutes: Resilience review opens; recovery objectives are recalculated; Compliance evaluation opens; Enterprise Risk residual reflects change. One incident. Four modules respond.
Pulls from
Enterprise RiskCriticality tier
Cyber SecurityThreat exposure
Third Party RiskCritical vendor
ComplianceRegulated service
RS
- Resilience
Feeds
Enterprise RiskResidual risk
ComplianceCPS 230 trigger
Third Party RiskVendor re-tier
Board reportingLive tolerance
06Sample output

Two views. One source of truth.

The resilience lead sees granular detail across all 7 pillars and underlying capabilities. The board sees a single score, the cascade impact, and CPS 230 conformity status.

Resilience lead viewCapture · evidence

Per-pillar breakdown with weighted markers.

2.3/ 4Defined → Managed
Resilience Governance & Strategy
Business Resilience
Technology Resilience
Supplier Resilience
Cyber Resilience
AI System Resilience
Crisis Management & Communication

Resilience lead sees per-question scores, evidence references, reviewer comments, and the gap-to-target.

Board viewRead-only · directors

Single score with CPS 230 conformity.

2.3/ 4Defined → Managed
CPS 230 conformity
CPS 234 conformity
ISO 22301 conformity
→ Compliance impact
Critical operations within tolerance

Executive sees a single number, downstream cascade, regulatory conformity, and a plain-English board narrative.

07See it work

Thirty minutes. A practitioner.

A walkthrough of the Resilience module isn't a product demo. It's a practitioner showing you how the seven pillars score, how CPS 230 maps clause-by-clause, and the honest picture of what it can and can't do. If we're not the right fit, we'll tell you.