The language of resilience is telling us something important
Sometimes the biggest change in a profession is not seen only in regulations, frameworks, or audit findings. Sometimes, it appears in the words we use.
Introduction
When I reviewed the DRI International Glossary for Resilience 2018 and compared it with the 2026 version, I noticed that the update is not only about adding new terms. It reflects a bigger shift in how the resilience profession is evolving.
The 2018 glossary was more connected to traditional business continuity, disaster recovery, emergency management, recovery sites, crisis response, and IT continuity. The 2026 glossary is broader and more aligned with today’s environment, where organizations must deal with operational resilience, cyber threats, third-party dependencies, artificial intelligence, data risk, and regulatory expectations.
The language changed because the nature of disruption changed.
High-Level Comparison
| Area | 2018 DRI Glossary | 2026 DRI Glossary | What Changed |
|---|---|---|---|
| Version | Version 2 — July 2018 Rev. 2 / 2020 | Version 3 — February 2026 | The 2026 version is a major update, not only a wording refresh. |
| Purpose | Collected and presented existing definitions from recognized sources. | Provides refreshed and harmonized DRI glossary terms. | Shift from source selection to DRI-led harmonization. |
| Source approach | DRI acted as an arbiter of existing definitions. | DRI is the source entity for its glossary terms. | More consistent ownership of terminology. |
| Structure | Some terms were nested or grouped under related terms. | Terms appear alphabetically for ease of use. | Easier to reference in practice and training. |
| Language style | More formal and standards-based. | Simpler, clearer, and more practical. | More useful for awareness, policies, and internal frameworks. |
| Scope | BCM, DR, emergency response, recovery sites, and IT continuity. | Operational resilience, cyber resilience, third-party risk, AI, data, and regulation. | The profession became broader and more strategic. |
The Change in Numbers
From a definition perspective, the 2026 version expanded noticeably. The numbers below are approximate because some terms were renamed, merged, moved from nested similar terms into standalone terms, or simplified.
| Category | Approximate Count | Comment |
|---|---|---|
| Definitions / terms in 2018 | 268 | Traditional BCM/DR-heavy terminology. |
| Definitions / terms in 2026 | 334 | Expanded resilience and operational resilience terminology. |
| New standalone definitions added in 2026 | 78 | Many related to cyber, third parties, AI, operational resilience, and regulation. |
| 2018 terms no longer standalone in 2026 | 11 | Some were removed, renamed, merged, or reframed. |
| Net increase | +66 | Reflects the wider scope of the resilience profession. |
What the 2018 Glossary Represents
The 2018 version represents a strong traditional foundation for resilience terminology. It supported common language across business continuity, disaster recovery, emergency management, information technology, and crisis response.
| 2018 Focus Area | Examples | Practical Meaning |
|---|---|---|
| Business Continuity | BCP, BCM, BCMS, BIA, Business Recovery | Focus on continuity planning, business impact, and recovery procedures. |
| Disaster Recovery | Data Recovery, Application Recovery, Alternate Site, Cold Site | Focus on restoring technology and operations after disruption. |
| Emergency and Crisis Response | Activation, Alert, Command Center, Crisis Management Team | Focus on response structure and incident escalation. |
| IT Continuity | Availability, Cloud Computing, Application Management, Architecture | Technology was present, but mostly from IT service and recovery angles. |
| Governance and Controls | Audit, Control, Corrective Action, Corporate Governance | Terminology supported compliance, review, and management control. |
The value of the 2018 glossary is that it helped reduce ambiguity. In crisis and disruption situations, unclear terminology can create confusion. Having common language supports better coordination between BCM, IT, crisis teams, risk, compliance, and business units.
What the 2026 Glossary Represents
The 2026 glossary reflects a more modern environment. It recognizes that disruption can come from many sources: cyberattacks, third-party failure, technology platforms, data issues, climate-related events, regulatory expectations, and even misinformation or deepfake technology.
| 2026 Stronger Area | Example Terms | Why It Matters |
|---|---|---|
| Operational Resilience | Operational Resilience, Critical Operations, Impact Tolerance, Important Business Services, Tolerance for Disruption | The focus moves from only recovery to maintaining critical services during disruption. |
| Cyber Resilience | Ransomware, Phishing, Zero-Day Attack, Deepfake Technology, Insider Threat, Brute Force Attack | Cyber events are now major business disruption scenarios, not only technical issues. |
| Third-Party and Supply Chain Risk | Critical Third Parties, Third-Party Service Provider, Supply Chain Mapping, Vendor, Sole Source | Organizations rely heavily on external providers; their failure can disrupt critical operations. |
| Technology and Data | Artificial Intelligence, Machine Learning, Automated Monitoring, Data Risk, Digital Twin Testing | Resilience is increasingly connected to data, automation, and digital operating models. |
| Risk and Regulation | DORA, KRIs, Regulatory Risk, Reputational Risk, Risk and Control Assessments | Resilience is now linked more directly to governance, risk, and regulatory expectations. |
| Crisis and People Impact | Crisis Communications, Crisis Fatigue | Communication and human endurance are critical during long or repeated disruptions. |
Examples of Important Definition Changes
Many definitions in the 2026 version became shorter, more practical, and more focused on outcomes. This helps non-specialists understand the terms and apply them in real situations.
| Term | 2018 Direction | 2026 Direction | Value of the Change |
|---|---|---|---|
| Activation | Focused on implementing BC procedures during an incident, emergency, event, or crisis. | Focused on initiating plans and procedures, predefined thresholds, communications, and coordination. | Activation becomes a clearer decision and coordination process. |
| Business Impact Analysis (BIA) | Focused on identifying the effect of failing to perform a function or requirement. | Focused on determining the effect of disruption on the entity and its assets. | BIA becomes broader and more connected to dependencies and resilience outcomes. |
| Business Continuity Plan (BCP) | A documented collection of procedures and information used during an incident. | A document outlining strategies and steps to maintain critical functions and recover from disruptions. | Simpler and easier to apply in practical planning. |
| Cyber Resilience | Focused on continuing delivery of products and services despite cyber events. | Ability to anticipate, withstand, recover from, and adapt to adverse cyber events. | More aligned with modern cyber resilience thinking. |
| Crisis | A critical event that may impact profitability, reputation, or ability to operate. | A severe or widespread event that threatens or disrupts an entity, group, or society. | Broader view of crisis beyond only business impact. |
| Critical Infrastructure | Focused mainly on physical assets whose loss would have a debilitating impact. | Focused on assets of strategic importance to critical functions and operations. | More aligned with operational resilience and critical services. |
| Availability | Focused mainly on data or information being accessible and usable. | Focused on readiness of systems, resources, and services. | Availability becomes broader than IT or data access. |
New Standalone Definitions Added in 2026
The following examples show the type of new standalone definitions introduced or strengthened in the 2026 glossary. They reflect the wider direction of the profession.
| Category | Examples of New 2026 Definitions |
|---|---|
| Operational resilience | Operational Resilience; Critical Operations; Important Business Services; Impact Tolerance; Tolerance for Disruption; Operational Capability; Operational Continuity; Operational Risk; Operational Risk Profile |
| Cyber and digital threats | Ransomware; Phishing; Zero-Day Attack; Deepfake Technology; Brute Force Attack; Insider Threat; Key Logger; Spyware; Trojan Horse; Virus; Worm; Cyber Insurance |
| Technology and data | Artificial Intelligence; Machine Learning; Automated Monitoring; Digital Twin Testing; Data Risk; Platform Outage; Multifactor Authentication |
| Third-party and supply chain | Critical Third Parties; Third-Party Service Provider; Supply Chain Mapping; Vendor; Single Source Supplier; Sole Source; Just-in-Case Supply Chain |
| Risk and regulation | DORA; KRIs; Inherent Risk; Regulatory Risk; Reputational Risk; Financial Risk; Legal Risk; Risk and Control Assessments; Risk Response Strategies |
| Crisis and emergency | Crisis Communications; Crisis Fatigue; Emergency Plan; Occupant Emergency Plan; Disaster Risk; Disaster Management; Natural Hazards; Operations Centers |
Terms Removed, Renamed, or No Longer Standalone
Some 2018 terms are not shown as standalone terms in the 2026 glossary. This does not always mean the concept disappeared. In many cases, the idea was renamed, merged, simplified, or reframed using more modern terminology.
| 2018 Term | 2026 Treatment | Comment |
|---|---|---|
| Application Portfolio | No longer standalone | May be covered through application management or broader technology terminology. |
| Continuity Manager | No longer standalone | Role concepts may be embedded in broader BCM responsibilities. |
| Manual Procedures | No longer standalone | Manual workarounds remain important but may be treated within continuity procedures. |
| Organization Head | No longer standalone | Leadership accountability is covered through governance and roles. |
| Wallet Card | No longer standalone | Likely reduced due to modern digital communication and plan access methods. |
| Denial of Service | Reframed as Denial of Service Attack | More clearly connected to cyberattack terminology. |
| Distributed Denial of Service | Reframed as Distributed Denial of Service Attack | Aligns with modern cyber language. |
| Risk Assessment / Analysis | Simplified into Risk Assessment | Cleaner and easier terminology. |
| Natural Hazard | Reframed as Natural Hazards | Broader category language. |
| Mutual Aid | Reframed or merged with agreement concepts | Concept remains relevant but language changed. |
| Disaster / Emergency Management | Reframed into clearer disaster and emergency planning terms | More specific terminology in 2026. |
Why This Change Is Valuable
The most valuable message from the 2026 glossary is that resilience is no longer only about having a business continuity plan or disaster recovery plan. Those are still important, but they are not enough by themselves.
| Question Organizations Should Ask | Why It Matters |
|---|---|
| What are our most critical operations? | Not every process has the same priority during disruption. Critical operations must be clearly identified. |
| What level of disruption can we tolerate? | Impact tolerance supports decision-making and helps leaders understand unacceptable harm. |
| Which third parties are critical to our services? | A vendor failure can become an organizational disruption or crisis. |
| Can we continue operating during a cyber incident? | Cyber events can stop services even without physical damage. |
| Are our RTOs supported by real recovery capability? | A target is not enough unless it is tested, evidenced, and achievable. |
| Do we understand dependencies and interdependencies? | Processes depend on people, systems, data, premises, suppliers, and workarounds. |
| Do we communicate early enough during incidents? | Communication should not wait until the impact becomes major. |
Human Reflection
In the past, many organizations looked at resilience mainly from the recovery side: “If something happens, how fast can we recover?”
Today, the question is wider: “Can we continue delivering our critical services while disruption is happening?”
That is the real shift. The 2026 glossary reflects a profession that is becoming more strategic, more connected to risk, and more aligned with the reality of modern disruption. It reminds us that resilience is not only about documentation. It is about capability, dependency understanding, decision-making, communication, and the ability to adapt under pressure.
Practical Use for BCM and Resilience Teams
| Practical Area | How the 2026 Glossary Helps |
|---|---|
| Policies and frameworks | Uses modern language aligned with current resilience expectations. |
| BIA templates | Encourages wider thinking about assets, dependencies, critical operations, and impact tolerance. |
| Crisis management plans | Strengthens language around activation, communication, and coordination. |
| Cyber resilience planning | Connects cyber incidents to business disruption and continuity requirements. |
| Third-party risk management | Supports better identification of critical suppliers and service providers. |
| Training and awareness | Makes definitions easier for non-specialists to understand. |
| Executive reporting | Helps explain resilience in business language rather than only technical language. |
Conclusion
The change between the DRI International Glossary 2018 and 2026 is more than a glossary update. It reflects the maturity of the resilience profession.
The 2018 version was valuable because it supported common language for traditional BCM, DR, and crisis response. The 2026 version goes further by reflecting a world where disruption is more complex, more connected, more digital, and more dependent on third parties.
The key takeaway is simple: the language of resilience changed because the nature of disruption changed.
For resilience professionals, this means our role is evolving. We are not only plan owners or recovery coordinators. We help the organization understand what is critical, what can fail, what level of disruption can be tolerated, and how to continue operating when conditions are not normal.
Sources Reviewed
- DRI International Glossary for Resilience, Version 2 — July 2018 Rev. 2 (2020). dri-malaysia.org — International_Glossary_for_Resilience_2018_REV2.pdf
- DRI International Glossary for Resilience, Version 3 — February 2026. dri-malaysia.org — International_Glossary_for_Resilience_2026.pdf
Turki Mohammed D. Alqahtani, MBCP is a business continuity, crisis management, and operational resilience professional with extensive experience in strengthening organizational preparedness, response, and recovery. With certifications including MBCP, CBCP, Lead Operational Resilience Manager, Lead Crisis Manager, and Risk Manager, I bring a practical and structured approach to resilience. My experience covers business impact analysis, crisis response, continuity planning, simulations, risk management, and stakeholder engagement, with a strong focus on protecting critical services and improving organizational resilience.
Turki Mohammed D. Alqahtani


