What Changed Between the DRI Glossary 2018 and 2026?

The language of resilience is telling us something important

Sometimes the biggest change in a profession is not seen only in regulations, frameworks, or audit findings. Sometimes, it appears in the words we use.

Introduction

When I reviewed the DRI International Glossary for Resilience 2018 and compared it with the 2026 version, I noticed that the update is not only about adding new terms. It reflects a bigger shift in how the resilience profession is evolving.

The 2018 glossary was more connected to traditional business continuity, disaster recovery, emergency management, recovery sites, crisis response, and IT continuity. The 2026 glossary is broader and more aligned with today’s environment, where organizations must deal with operational resilience, cyber threats, third-party dependencies, artificial intelligence, data risk, and regulatory expectations.

The language changed because the nature of disruption changed.

High-Level Comparison

Area 2018 DRI Glossary 2026 DRI Glossary What Changed
Version Version 2 — July 2018 Rev. 2 / 2020 Version 3 — February 2026 The 2026 version is a major update, not only a wording refresh.
Purpose Collected and presented existing definitions from recognized sources. Provides refreshed and harmonized DRI glossary terms. Shift from source selection to DRI-led harmonization.
Source approach DRI acted as an arbiter of existing definitions. DRI is the source entity for its glossary terms. More consistent ownership of terminology.
Structure Some terms were nested or grouped under related terms. Terms appear alphabetically for ease of use. Easier to reference in practice and training.
Language style More formal and standards-based. Simpler, clearer, and more practical. More useful for awareness, policies, and internal frameworks.
Scope BCM, DR, emergency response, recovery sites, and IT continuity. Operational resilience, cyber resilience, third-party risk, AI, data, and regulation. The profession became broader and more strategic.

The Change in Numbers

From a definition perspective, the 2026 version expanded noticeably. The numbers below are approximate because some terms were renamed, merged, moved from nested similar terms into standalone terms, or simplified.

Category Approximate Count Comment
Definitions / terms in 2018 268 Traditional BCM/DR-heavy terminology.
Definitions / terms in 2026 334 Expanded resilience and operational resilience terminology.
New standalone definitions added in 2026 78 Many related to cyber, third parties, AI, operational resilience, and regulation.
2018 terms no longer standalone in 2026 11 Some were removed, renamed, merged, or reframed.
Net increase +66 Reflects the wider scope of the resilience profession.

What the 2018 Glossary Represents

The 2018 version represents a strong traditional foundation for resilience terminology. It supported common language across business continuity, disaster recovery, emergency management, information technology, and crisis response.

2018 Focus Area Examples Practical Meaning
Business Continuity BCP, BCM, BCMS, BIA, Business Recovery Focus on continuity planning, business impact, and recovery procedures.
Disaster Recovery Data Recovery, Application Recovery, Alternate Site, Cold Site Focus on restoring technology and operations after disruption.
Emergency and Crisis Response Activation, Alert, Command Center, Crisis Management Team Focus on response structure and incident escalation.
IT Continuity Availability, Cloud Computing, Application Management, Architecture Technology was present, but mostly from IT service and recovery angles.
Governance and Controls Audit, Control, Corrective Action, Corporate Governance Terminology supported compliance, review, and management control.

The value of the 2018 glossary is that it helped reduce ambiguity. In crisis and disruption situations, unclear terminology can create confusion. Having common language supports better coordination between BCM, IT, crisis teams, risk, compliance, and business units.

What the 2026 Glossary Represents

The 2026 glossary reflects a more modern environment. It recognizes that disruption can come from many sources: cyberattacks, third-party failure, technology platforms, data issues, climate-related events, regulatory expectations, and even misinformation or deepfake technology.

2026 Stronger Area Example Terms Why It Matters
Operational Resilience Operational Resilience, Critical Operations, Impact Tolerance, Important Business Services, Tolerance for Disruption The focus moves from only recovery to maintaining critical services during disruption.
Cyber Resilience Ransomware, Phishing, Zero-Day Attack, Deepfake Technology, Insider Threat, Brute Force Attack Cyber events are now major business disruption scenarios, not only technical issues.
Third-Party and Supply Chain Risk Critical Third Parties, Third-Party Service Provider, Supply Chain Mapping, Vendor, Sole Source Organizations rely heavily on external providers; their failure can disrupt critical operations.
Technology and Data Artificial Intelligence, Machine Learning, Automated Monitoring, Data Risk, Digital Twin Testing Resilience is increasingly connected to data, automation, and digital operating models.
Risk and Regulation DORA, KRIs, Regulatory Risk, Reputational Risk, Risk and Control Assessments Resilience is now linked more directly to governance, risk, and regulatory expectations.
Crisis and People Impact Crisis Communications, Crisis Fatigue Communication and human endurance are critical during long or repeated disruptions.

Examples of Important Definition Changes

Many definitions in the 2026 version became shorter, more practical, and more focused on outcomes. This helps non-specialists understand the terms and apply them in real situations.

Term 2018 Direction 2026 Direction Value of the Change
Activation Focused on implementing BC procedures during an incident, emergency, event, or crisis. Focused on initiating plans and procedures, predefined thresholds, communications, and coordination. Activation becomes a clearer decision and coordination process.
Business Impact Analysis (BIA) Focused on identifying the effect of failing to perform a function or requirement. Focused on determining the effect of disruption on the entity and its assets. BIA becomes broader and more connected to dependencies and resilience outcomes.
Business Continuity Plan (BCP) A documented collection of procedures and information used during an incident. A document outlining strategies and steps to maintain critical functions and recover from disruptions. Simpler and easier to apply in practical planning.
Cyber Resilience Focused on continuing delivery of products and services despite cyber events. Ability to anticipate, withstand, recover from, and adapt to adverse cyber events. More aligned with modern cyber resilience thinking.
Crisis A critical event that may impact profitability, reputation, or ability to operate. A severe or widespread event that threatens or disrupts an entity, group, or society. Broader view of crisis beyond only business impact.
Critical Infrastructure Focused mainly on physical assets whose loss would have a debilitating impact. Focused on assets of strategic importance to critical functions and operations. More aligned with operational resilience and critical services.
Availability Focused mainly on data or information being accessible and usable. Focused on readiness of systems, resources, and services. Availability becomes broader than IT or data access.

New Standalone Definitions Added in 2026

The following examples show the type of new standalone definitions introduced or strengthened in the 2026 glossary. They reflect the wider direction of the profession.

Category Examples of New 2026 Definitions
Operational resilience Operational Resilience; Critical Operations; Important Business Services; Impact Tolerance; Tolerance for Disruption; Operational Capability; Operational Continuity; Operational Risk; Operational Risk Profile
Cyber and digital threats Ransomware; Phishing; Zero-Day Attack; Deepfake Technology; Brute Force Attack; Insider Threat; Key Logger; Spyware; Trojan Horse; Virus; Worm; Cyber Insurance
Technology and data Artificial Intelligence; Machine Learning; Automated Monitoring; Digital Twin Testing; Data Risk; Platform Outage; Multifactor Authentication
Third-party and supply chain Critical Third Parties; Third-Party Service Provider; Supply Chain Mapping; Vendor; Single Source Supplier; Sole Source; Just-in-Case Supply Chain
Risk and regulation DORA; KRIs; Inherent Risk; Regulatory Risk; Reputational Risk; Financial Risk; Legal Risk; Risk and Control Assessments; Risk Response Strategies
Crisis and emergency Crisis Communications; Crisis Fatigue; Emergency Plan; Occupant Emergency Plan; Disaster Risk; Disaster Management; Natural Hazards; Operations Centers

Terms Removed, Renamed, or No Longer Standalone

Some 2018 terms are not shown as standalone terms in the 2026 glossary. This does not always mean the concept disappeared. In many cases, the idea was renamed, merged, simplified, or reframed using more modern terminology.

2018 Term 2026 Treatment Comment
Application Portfolio No longer standalone May be covered through application management or broader technology terminology.
Continuity Manager No longer standalone Role concepts may be embedded in broader BCM responsibilities.
Manual Procedures No longer standalone Manual workarounds remain important but may be treated within continuity procedures.
Organization Head No longer standalone Leadership accountability is covered through governance and roles.
Wallet Card No longer standalone Likely reduced due to modern digital communication and plan access methods.
Denial of Service Reframed as Denial of Service Attack More clearly connected to cyberattack terminology.
Distributed Denial of Service Reframed as Distributed Denial of Service Attack Aligns with modern cyber language.
Risk Assessment / Analysis Simplified into Risk Assessment Cleaner and easier terminology.
Natural Hazard Reframed as Natural Hazards Broader category language.
Mutual Aid Reframed or merged with agreement concepts Concept remains relevant but language changed.
Disaster / Emergency Management Reframed into clearer disaster and emergency planning terms More specific terminology in 2026.

Why This Change Is Valuable

The most valuable message from the 2026 glossary is that resilience is no longer only about having a business continuity plan or disaster recovery plan. Those are still important, but they are not enough by themselves.

Question Organizations Should Ask Why It Matters
What are our most critical operations? Not every process has the same priority during disruption. Critical operations must be clearly identified.
What level of disruption can we tolerate? Impact tolerance supports decision-making and helps leaders understand unacceptable harm.
Which third parties are critical to our services? A vendor failure can become an organizational disruption or crisis.
Can we continue operating during a cyber incident? Cyber events can stop services even without physical damage.
Are our RTOs supported by real recovery capability? A target is not enough unless it is tested, evidenced, and achievable.
Do we understand dependencies and interdependencies? Processes depend on people, systems, data, premises, suppliers, and workarounds.
Do we communicate early enough during incidents? Communication should not wait until the impact becomes major.

Human Reflection

In the past, many organizations looked at resilience mainly from the recovery side: “If something happens, how fast can we recover?”

Today, the question is wider: “Can we continue delivering our critical services while disruption is happening?”

That is the real shift. The 2026 glossary reflects a profession that is becoming more strategic, more connected to risk, and more aligned with the reality of modern disruption. It reminds us that resilience is not only about documentation. It is about capability, dependency understanding, decision-making, communication, and the ability to adapt under pressure.

Practical Use for BCM and Resilience Teams

Practical Area How the 2026 Glossary Helps
Policies and frameworks Uses modern language aligned with current resilience expectations.
BIA templates Encourages wider thinking about assets, dependencies, critical operations, and impact tolerance.
Crisis management plans Strengthens language around activation, communication, and coordination.
Cyber resilience planning Connects cyber incidents to business disruption and continuity requirements.
Third-party risk management Supports better identification of critical suppliers and service providers.
Training and awareness Makes definitions easier for non-specialists to understand.
Executive reporting Helps explain resilience in business language rather than only technical language.

Conclusion

The change between the DRI International Glossary 2018 and 2026 is more than a glossary update. It reflects the maturity of the resilience profession.

The 2018 version was valuable because it supported common language for traditional BCM, DR, and crisis response. The 2026 version goes further by reflecting a world where disruption is more complex, more connected, more digital, and more dependent on third parties.

The key takeaway is simple: the language of resilience changed because the nature of disruption changed.

For resilience professionals, this means our role is evolving. We are not only plan owners or recovery coordinators. We help the organization understand what is critical, what can fail, what level of disruption can be tolerated, and how to continue operating when conditions are not normal.

Sources Reviewed

 

 

 

 

 

Turki Mohammed D. Alqahtani, MBCP is a business continuity, crisis management, and operational resilience professional with extensive experience in strengthening organizational preparedness, response, and recovery. With certifications including MBCP, CBCP, Lead Operational Resilience Manager, Lead Crisis Manager, and Risk Manager, I bring a practical and structured approach to resilience. My experience covers business impact analysis, crisis response, continuity planning, simulations, risk management, and stakeholder engagement, with a strong focus on protecting critical services and improving organizational resilience. 

Turki Mohammed D. Alqahtani