Operational resilience maturity across seven pillars, practitioner-authored. Most resilience tools stop at business continuity. This module covers the full picture - strategy, business, technology, supplier, cyber, AI system resilience, and crisis management.

Most resilience tools focus on business continuity and disaster recovery. That's one slice of the picture. Real operational resilience needs seven connected disciplines - strategy at the top, crisis at the bottom, with five domain-specific resilience layers in between.
Each pillar is practitioner-authored, scored on the unified 0–4 scale, and weighted into the cross-domain cascade. Together they answer the only question that matters: can the organisation absorb shock and keep operating?
Board-approved resilience strategy, executive accountability, three-lines model, risk appetite cascade, committee charters, regulatory alignment.
Critical operations, customer-impact assessment, tolerance levels, BCP framework, RTO/RPO discipline, recovery strategies and exercise discipline.
Application and infrastructure resilience, redundancy, failover, capacity, change management, technology lifecycle, cloud and platform dependencies.
Material service provider resilience, exit planning, joint testing, contractual resilience clauses, fourth-party visibility, concentration risk.
Ransomware-specific scenarios, immutable backup posture, recovery testing, integration with cyber module, secure-by-design recovery.
Model failure modes, drift detection, fallback paths, AI dependency mapping, autonomous-decision recovery, model retraining discipline.
Crisis team activation, severity model, internal and external communications, stakeholder management, regulator engagement, post-incident discipline.
Every resilience pillar is scored on the 0–4 maturity scale - the same scale every other MaturityOne module uses. So resilience maturity reconciles directly with Cyber, Third Party Risk and Compliance.
Every regulatory add-on is a clause-level mapping from the resilience maturity score to a specific standard. Four add-ons live today, covering the full AU regulatory landscape.
Full mapping to CPS 230 operational resilience requirements. The Australian prudential standard for operational risk. Maps critical operations, tolerance levels, BCP, scenario testing, and material service providers. Required by July 2025.
The Australian prudential standard for information security. Maps resilience to CPS 234 capability requirements, control implementation and incident notification. Relevant for the cyber-resilience overlap.
The international standard for business continuity management systems. Maps maturity to ISO 22301 clauses 4–10 - context, leadership, planning, support, operation, and performance evaluation.
Annex A control mapping for resilience-relevant controls. Maps to controls covering business continuity, incident management, supplier relationships and physical security.
NIST Cybersecurity Framework 2.0 - Recover function focus. Particularly the Recover (RC) and the new Govern (GV) function added in CSF 2.0. Widely adopted globally.
The EU Digital Operational Resilience Act - covers ICT risk management, incident reporting, testing, and third-party risk. Required by EU financial entities since Jan 2025.
You cannot run a resilience program without knowing which services are critical. MaturityOne wires Resilience into the specialist modules that define its scope.
Board-set risk appetite drives recovery objectives by criticality tier. Critical service classification from Enterprise Risk drives the resilience module's in-scope list.
Failed disaster recovery tests and lessons-learned flow back into Enterprise Risk as residual risk signals. Tolerance breaches flow into Compliance for reporting.
A material cyber incident automatically triggers a resilience tolerance review. A critical vendor incident triggers a recalculation. Live, not annual.
The resilience lead sees granular detail across all 7 pillars and underlying capabilities. The board sees a single score, the cascade impact, and CPS 230 conformity status.
Resilience lead sees per-question scores, evidence references, reviewer comments, and the gap-to-target.
Executive sees a single number, downstream cascade, regulatory conformity, and a plain-English board narrative.
A walkthrough of the Resilience module isn't a product demo. It's a practitioner showing you how the seven pillars score, how CPS 230 maps clause-by-clause, and the honest picture of what it can and can't do. If we're not the right fit, we'll tell you.