Highlights from the Financial Services Operational & Organisational Resilience Conference 2026

DCR Team

We were proud to exhibit at the 5th Annual Financial Services Operational & Organisational Resilience Conference 2026, held on 15 September. 

 

About the conference

Following a number of years of critical legislative change and implementation, the annual one-day conference
in central London brings together senior resilience experts from across financial services to discuss what1789748282937 comes next for the industry. It's a valuable forum for peer benchmarking and business-critical updates on achieving embedded, mature and sustained operational resilience across the sector.

Throughout the day, one theme came through clearly in the conversations on our stand: trust is the
cornerstone
. Resilience is really another name for what supports and enables trust. Every organisation in the room, regardless of size, is underpinned by its ability to deliver trust, and trust erodes quickly but takes a long time to build.

On our stand, we ran our 'Can You Spot the Major Incidents?' challenge. We filled a jar with coloured sweets, where the red sweets represented major incidents hidden among the minor ones. Delegates had to guess how many major incidents were lurking in the jar, with the closest answer winning a luxury hamper. It's a simple idea, but it mirrors the reality most financial services firms face every day. Major incidents don't announce themselves. They sit quietly among the noise of minor issues, near-misses, and business-as-usual disruptions, until one of them escalates and suddenly everyone is asking why nobody saw it coming. It opened the door to some honest conversations, reinforcing a key point: it's the incidents you don't see coming, or don't recognise as significant until they aggregate, that catch organisations out. 

 

Resilience Roulette

We also led a breakout session, Resilience Roulette, with Raj Kohli (Founder & Managing Director from DCR Partners) and Iain Wardle (Head of Security & Resilience from Skipton Group). The session explored how firms under pressure from every direction (costs, capacity, capability) are simultaneously being asked to do more, move faster, and deliver greater value to customers. When resilience decisions are made incrementally under that pressure, without being properly thought through, firms aren't managing risk, they're gambling with it. Raj and Iain shared how Skipton Group broke that cycle and built resilience that is genuinely embedded, strategically sound, and built to hold up when it matters most.

 

Key themes & highlights

  • The shift from operational to enterprise resilience. Regulation has been genuinely helpful in getting organisations moving, but the conversations pointed to a step change in scope: moving beyond what the regulator sees towards broader enterprise resilience. Part of that step change is getting tighter, not broader: being clear on what is truly critical rather than building complex processes and systems around everything. That's a sign of maturing practice.
  • Resilience has to serve business outcomes. It's easy for practitioners to pursue resilience for its own sake. The organisations having the biggest impact are those using resilience to deliver business outcomes, entering new markets, serving customers better. That framing also allows genuine prioritisation, which matters when budgets are constrained and AI is changing the picture.
  • Scale differs; the problems don't. The room held some very large, complex organisations and some much smaller ones. The opportunities and challenges were the same; what varied was scale and complexity. Strip the solutions back to their simplest form and they're broadly identical. Everyone is looking for the same answers.
  • Automated testing is moving from aspiration to practice. Firms are building continuous operational resilience validation. Citi's model showed that volume testing is achievable and delivers real insight.
  • The FCA is identifying the right problems: Cyber threats evolving, frontier AI as a step change, third-party interdependencies as critical, and polycrisis scenarios on the horizon.
  • Silos are destroying resilience. There was consensus that separating cyber, ops resilience, third-party, and technology functions undermines the whole effort. The strongest firms are bringing these together.
  • The operation layer remains undertested. Command, coordination, capacity under real pressure. Most organisations are still in the document phase. Crisis plans are documents; real plans are the written articulation of the system working as one.
  • Operational resilience and enterprise resilience are not the same thing. Firms can pass every operational resilience test and still be at risk of institutional failure if the floor is not held. The services layer is being built well. The operation layer and floor layer are assumed, not validated, and largely untested.
  • Third-party risk and minimum viable capability came up repeatedly as shared open questions the sector is still working through.

As Raj reflected, the panel sessions were excellent and useful, but the real value came off the panels: the one-to-one conversations where you learn what people are actually doing, how similar everyone's position is, and what you can take from each other. That's the real power of this kind of event.

 

Let's continue the conversation

If we didn't get a chance to connect during the event, we'd still love to hear from you. Whether you're exploring how to move from operational to enterprise resilience, strengthening your operating model, or navigating transformation in an increasingly disrupted environment, get in touch.

From Cyber Resilience through to Resilience, Incident and Crisis Management, Third-Party Risk, and Internal Audit and Risk Advisory, we work with financial services organisations to design operating models that don't just respond to disruption, but are built for it.

 

See more...