• +1 602-922-5990
  • This email address is being protected from spambots. You need JavaScript enabled to view it.
  • Mon - Fri 8:00a - 5:00p PDT

The PECB Certified Lead Operational Resilience Manager course is designed to equip professionals with the knowledge and skills to lead and manage an organization’s operational resilience efforts. This training course covers fundamental concepts, good practices, and recent trends in operational resilience, emphasizing the importance of identifying and maintaining critical business functions in the face of disruptions.

Why should you attend?

As organizations face increasingly complex and interconnected risks, such as cyber threats, natural disasters, evolving regulatory landscapes, and geopolitical tensions, a structured and holistic approach to operational resilience has become essential. This training course is built around the assumption that disruptions to business operations are inevitable; therefore, it aims to equip you with the knowledge and skills necessary to help organizations define an operational resilience strategy, conduct business impact analyses and risk assessments, and implement the necessary operational control measures to prepare for, respond to, and learn from disruptions.

Furthermore, attending this training course demonstrates your dedication to professional growth and sets you on a path to becoming a leader in the dynamic and ever-changing field of operational resilience. After completing the training course and passing the exam, you can apply for the “PECB Certified Lead Operational Resilience Manager” certification.

Who should attend?

This training course is intended for:

  • Managers and other functions responsible for steering organizations to prepare for, respond to, and recover from operational disruptions
  • Consultants seeking to help organizations improve their operational resilience
  • Individuals responsible for promoting operational resilience within an organization
  • Individuals seeking to gain knowledge of the main approaches to operational resilience management
  • Business continuity managers and risk managers

Learning objectives

After completing this training course, you will be able to:

  1. Explain the fundamental concepts and principles related to operational resilience
  2. Identify critical business functions, map the interdependencies within an organization, and set impact tolerance
  3. Conduct business impact analysis, assess risks, and manage resources effectively
  4. Plan and implement changes in organizational processes and strategies to integrate best practices into operational resilience framework
  5. Conduct comprehensive resilience testing and assessment, performance measurements, and continually improve operational resilience

Educational approach

  • The training course incorporates interactive elements, such as essay-type exercises and multiple-choice quizzes, including some that are scenario-based.
  • Participants are strongly encouraged to communicate and engage in discussions.
  • The quizzes are designed in a manner that closely resembles the format of the certification exam.

Prerequisites

The main requirement for participating in this training course is having a fundamental understanding of operational resilience and business continuity concepts and principles.

COURSE AGENDA

Day 1: The foundations of operational resilience

Day 2: Planning operational resilience management framework

Day 3: Establishing operational resilience management practices

Day 4: Testing and improving operational resilience

Day 5: Certification exam

EXAMINATION

The “PECB Certified Lead Operational Resilience Manager” exam meets the PECB Examination and Certification Program (ECP) requirements, and it covers the following competency domains:

Domain 1: Fundamental concepts of operational resilience

Domain 2: Planning operational resilience management framework

Domain 3: Establishing business resilience and digital and cyber resilience management practices

Domain 4: Establishing third-party resilience management practices and resilience organizational culture

Domain 5: Testing and continually improving operational resilience

CERTIFICATION

After successfully passing the exam, you can apply for one of the credentials shown below. You will receive the certificate once you comply with all the requirements related to the selected credential.

The requirements for certifications are as follows:

Credential Exam Professional experience Risk Management experience Other requirements
PECB Certified Operational Resilience Provisional Manager PECB Certified Lead Operational Resilience Manager exam or equivalent None None Signing the PECB Code of Ethics
PECB Certified Operational Resilience Manager PECB Certified Lead Operational Resilience Manager exam or equivalent Two years: At least one year of work experience in operational resilience management At least 200 hours of project activities Signing the PECB Code of Ethics
PECB Certified Lead Operational Resilience Manager PECB Certified Lead Operational Resilience Manager exam or equivalent Five years: At least two years of work experience in operational resilience management At least 300 hours of project activities Signing the PECB Code of Ethics
PECB Certified Senior Lead Operational Resilience Manager PECB Certified Lead Operational Resilience Manager exam or equivalent Ten years: At least seven years of work experience in operational resilience management At least 1,000 hours of project activities Signing the PECB Code of Ethics

The operational resilience experience should follow best practices and include the following:

  • Identifying critical business services
  • Setting up impact tolerance
  • Conducting business impact analysis
  • Managing and improving operational, digital, and cyber resilience
  • Managing third-party and supply chain resilience
  • Conducting operational resilience scenario testing
  • Conducing operational resilience self-assessment
  • Improving the performance of the operational resilience

GENERAL INFORMATION

  • Certification and examination fees are included in the price of the training course
  • Participants will receive the training course material, which contains over 450 pages of explanatory information, examples, best practices, exercises, and quizzes.
  • Participants who have attended the training course will receive an attestation of course completion worth 31 CPD (Continuing Professional Development) credits.
  • If candidates fail the exam, they can retake it for free within 12 months following the initial attempt.

Business Continuity Management Is Not Operational Resilience: Why the Distinction Matters!

For the past few years, I have watched organizations, consultants, vendors, regulators, and practitioners use the terms Business Continuity Management (BCM) and Operational Resilience interchangeably. While the two disciplines are undeniably connected and mutually reinforcing, they are far from equals. In fact, one of the most significant barriers to organizational maturity is the failure to recognize where Business Continuity ends and Operational Resilience begins.

Understanding this distinction is not merely an academic exercise. It is one of the first and most important steps in moving an organization toward true resilience. Unfortunately, that realization rarely starts at the practitioner level. It must be embraced in the boardroom and championed by senior leadership. Without executive sponsorship, operational resilience initiatives often struggle to gain traction, regardless of how passionate or capable the Business Continuity team may be.

The Problem: Treating BCM and Resilience as the Same Thing

Many organizations still believe that having a Business Continuity Plan, conducting annual exercises, and maintaining a recovery strategy means they are resilient. While those activities are valuable and necessary, they represent only a fraction of what resilience requires.

Business Continuity Management focuses on preparing for disruptions and recovering critical activities following an event. It is fundamentally concerned with questions such as:

  • How do we respond to an incident?
  • How quickly can we recover?
  • What resources are needed to restore operations?
  • What processes are critical to the organization?

These are important questions, but they are largely operational and recovery-focused.

Operational Resilience asks a much broader question:

Can the organization continue delivering its most important products and services, within acceptable levels, regardless of what disruption occurs?

That subtle difference changes everything.

Resilience is not solely about recovering. It is about anticipating, absorbing, adapting, responding, recovering, and evolving. It encompasses governance, risk management, cybersecurity, third-party dependencies, technology resilience, crisis management, workforce resilience, supply chain resilience, and strategic decision-making.

Simply put:

Business Continuity Management helps an organization recover from disruption. Operational Resilience helps an organization continue delivering value through disruption.

One supports the other, but they are not the same thing.

A Helpful Analogy

Think of BCM as the organization's emergency response and recovery capability.

Think of Operational Resilience as the organization's overall health, endurance, and adaptability.

An athlete may have an excellent emergency medical plan if they become injured. That does not automatically make them healthy, adaptable, conditioned, or capable of performing under stress.

Likewise, a company can possess world-class continuity plans and still fail when faced with complex, interconnected challenges involving technology failures, cyber-attacks, supplier disruptions, regulatory pressures, workforce shortages, or cascading operational events.

Recovery plans alone do not create resilience.

Why the Distinction Matters

Organizations that confuse BCM with resilience often make three common mistakes.

  1. They Focus on Recovery Instead of Service Delivery
    • Traditional BCM programs often concentrate on processes, recovery times, and site-level contingency planning.
    • Operational resilience shifts the focus toward the continuity of critical business services and the customer outcomes they support.
    • Boards do not care whether a server was restored in four hours. 
    • They care whether customers could continue receiving services.
  2. They Treat Resilience as a Program Rather Than a Strategy
    • Many continuity practitioners are tasked with "building resilience" despite having little authority outside their own department.
    • The challenge is obvious.
    • How can a BCM manager influence cybersecurity investments, vendor management practices, enterprise risk decisions, technology modernization, workforce planning, or organizational culture?
    • They usually cannot.
    • Resilience is not a department.
    • It is an enterprise capability that must be directed and governed at the executive level.
  3. They Underestimate Interdependencies
    • Operational resilience recognizes that business services depend on a complex network of people, processes, technology, facilities, data, suppliers, and governance structures.
    • A disruption rarely affects just one area.
    • The modern organization is interconnected.
    • You cannot understand resilience by looking at continuity plans alone.
    • You must understand the ecosystem that delivers critical outcomes.

The Practitioner's Challenge

One of the most frustrating realities for Business Continuity professionals is that they often understand these limitations better than anyone else.

Many practitioners see the gaps.

They recognize that resilience requires broader governance, executive accountability, and integration across risk, compliance, cybersecurity, technology, and operations.

Yet they frequently lack the authority to drive those changes.

This creates a difficult dynamic.

The people closest to the problem are often the furthest away from the decision-makers who can solve it.

Attempting to push operational resilience upward from within a continuity function can feel like climbing a mountain while carrying the mountain on your back.

The practitioner can educate.

The practitioner can advocate.

The practitioner can demonstrate value.

But ultimately, organizational transformation requires leadership commitment.

Why Executive Sponsorship Is Non-Negotiable

Organizations that successfully mature from continuity-focused programs into resilience-focused enterprises almost always have one thing in common:

An executive champion.

Someone at the Board, C-Suite, or senior leadership level recognizes resilience as a strategic business imperative.

That leader understands that resilience is not a compliance exercise.

It is not an audit requirement.

It is not a collection of recovery plans.

It is an organizational capability that protects customers, revenue, reputation, operations, and long-term viability.

When executive sponsorship exists:

  • Silos become easier to break down.
  • Cross-functional collaboration improves.
  • Funding becomes available.
  • Governance structures mature.
  • Critical business services gain visibility.
  • Resilience metrics reach the boardroom.
  • Strategic decisions begin incorporating resilience considerations.

Without executive sponsorship, even the most talented Business Continuity teams often find themselves managing documentation rather than driving transformation.

The Board's Role

Boards and executive leaders must begin asking different questions.

Instead of asking:

  • Do we have continuity plans?
  • When was our last exercise?
  • Are our recovery objectives current?

They should ask:

  • What are our most important business services?
  • What level of disruption can we tolerate?
  • What vulnerabilities threaten those services?
  • Where are our concentration risks?
  • How resilient are our critical third parties?
  • Can we operate through a severe but plausible disruption?
  • How are we measuring resilience over time?

These questions move the conversation from recovery planning to organizational endurance.

The Path Forward

Business Continuity Management remains a critical discipline. No mature resilience program exists without strong continuity capabilities.

However, BCM should be viewed as one component of a much larger resilience ecosystem.

The goal should not be to replace BCM with Operational Resilience.

The goal should be to elevate BCM into a broader enterprise strategy that aligns governance, risk management, technology resilience, cyber resilience, third-party risk management, crisis management, and business continuity around a common objective:

The sustained delivery of critical business services under adverse conditions.

Organizations that understand this distinction gain a competitive advantage. Organizations that blur the lines often mistake preparedness for resilience.

They are not the same.

And perhaps the most important lesson of all is this:

Operational Resilience cannot be delegated downward and expected to succeed. While Business Continuity practitioners may light the path, resilience must be led from the top. Without an executive champion, resilience remains an aspiration. With one, it becomes an enterprise capability.


Respond: Coordinated Action When Operational Disruption Occurs

No organization can eliminate every risk. Even with strong governance, mature controls, resilient architectures, and proactive monitoring, disruptions will still occur.

The difference between a contained incident and an organizational crisis often depends on the quality of the response.

The Respond phase focuses on how the organization acts when disruption occurs. It brings together incident response, crisis management, operational decision-making, executive leadership, communications, regulatory awareness, and business continuity coordination.

The goal is not simply to react. The goal is to preserve control, protect stakeholders, maintain confidence, and prevent operational disruption from escalating beyond acceptable tolerances.

The Respond phase asks:

When disruption occurs, can we make the right decisions quickly, communicate effectively, and coordinate action across the enterprise?


Key Inputs

Response activities depend on current, accurate, and decision-ready information, including:

  • Incident alerts
  • Detection triggers
  • Escalation criteria
  • Crisis management plans
  • Incident response plans
  • Business continuity plans
  • Cyber incident playbooks
  • Communications templates
  • Regulatory notification requirements
  • Stakeholder contact lists
  • Critical service maps
  • Impact tolerance thresholds
  • Supplier escalation contacts
  • Executive decision protocols
  • Situation reports
  • Legal and compliance guidance

These inputs help response teams understand what happened, what is affected, who needs to act, and what decisions are required.


Lifecycle Process

A mature Respond process establishes clear roles, repeatable workflows, and coordinated decision-making.

Core response activities include:

1. Recognize and Classify the Event

Determine whether the event is an operational incident, cyber event, supplier disruption, technology outage, compliance issue, crisis, or combined event.

2. Escalate Based on Impact

Use severity levels and impact tolerance thresholds to determine when leadership, crisis teams, regulators, customers, or suppliers must be engaged.

3. Activate Response Structures

Mobilize incident response teams, crisis management teams, business continuity teams, technology recovery teams, communications teams, and executive leadership as needed.

4. Develop a Common Operating Picture

Establish a shared understanding of what happened, what services are impacted, what dependencies are affected, and what actions are underway.

5. Make Timely Decisions

Enable executives and operational leaders to make informed decisions regarding service prioritization, resource allocation, customer communication, workarounds, recovery sequencing, and risk acceptance.

6. Communicate Clearly and Consistently

Coordinate internal, external, customer, supplier, regulator, media, and executive communications.

7. Track Actions and Decisions

Maintain decision logs, action registers, situation updates, and evidence for post-incident review.


Key Outputs

The Respond phase should generate structured, auditable outputs such as:

  • Incident classification record
  • Situation reports
  • Crisis management meeting records
  • Decision logs
  • Action trackers
  • Stakeholder communication notices
  • Regulatory notification records
  • Executive briefings
  • Service impact assessments
  • Escalation reports
  • Response timeline
  • Supplier coordination records
  • Customer communication updates
  • Incident containment documentation
  • Transition plan to Withstand or Recover activities

Why This Phase Matters

Poor response creates secondary damage. Confusion, delayed escalation, conflicting communication, unclear leadership, and undocumented decisions can increase operational, reputational, legal, and regulatory exposure.

A strong response capability allows organizations to act with discipline under pressure. It ensures that teams know their roles, executives receive meaningful information, customers receive appropriate communication, and critical services remain the central focus.


OpResONE Perspective

At OpResONE, we help organizations integrate crisis management, cyber incident response, business continuity, disaster recovery, supplier coordination, and executive decision-making into a single response model.

This is critical because real disruptions do not respect organizational silos. A cyber incident may become a customer service issue. A supplier failure may become a regulatory issue. A technology outage may become an executive crisis.

Operational resilience requires response structures that are integrated, practiced, and aligned to critical outcomes.

*Possible Integrated Dashboard


Adapt: Turning Disruption Into Continuous Resilience Improvement

Operational resilience is never finished.

Every incident, exercise, audit, near miss, supplier issue, cyber event, technology outage, and operational challenge creates new intelligence. The question is whether the organization uses that intelligence to improve.

The Adapt phase turns experience into action. It ensures resilience remains aligned with business strategy, technology modernization, regulatory expectations, customer needs, and emerging threats.

Organizations that adapt become stronger over time. Organizations that do not adapt repeat the same failures.

The Adapt phase asks:

What did we learn, what must change, and how do we make the organization more resilient going forward?

Key Inputs

The Adapt phase relies on evidence from across the resilience lifecycle, including:

  • Incident reports
  • Post-incident reviews
  • Lessons learned results
  • Exercise findings
  • Audit findings
  • Control testing results
  • Maturity assessments
  • Performance metrics
  • Impact tolerance breaches
  • Recovery validation results
  • Supplier performance reviews
  • Cyber event analysis
  • Regulatory feedback
  • Customer complaints
  • Risk assessments
  • Executive governance decisions
  • Program benchmarking results

These inputs allow the organization to identify recurring weaknesses, improvement opportunities, investment needs, and governance gaps.

Lifecycle Process

The Adapt phase creates a structured process for continuous improvement.

Core adaptation activities include:

  1. Capture lessons learned
    Gather insights from incidents, exercises, failed controls, near misses, audits, and operational events.

  2. Analyze root causes
    Determine whether issues were caused by process failure, technology weakness, supplier dependency, control gaps, unclear roles, poor escalation, insufficient training, or governance failure.

  3. Prioritize improvements
    Rank corrective actions based on risk reduction, critical service impact, regulatory importance, cost, complexity, and strategic value.

  4. Update resilience capabilities
    Revise plans, controls, operating models, playbooks, supplier requirements, continuity strategies, monitoring indicators, and governance reporting.

  5. Measure progress
    Track remediation, resilience maturity, control effectiveness, test performance, incident trends, and impact tolerance alignment.

  6. Report to leadership
    Provide executive-level visibility into resilience posture, improvement progress, persistent risk, investment needs, and strategic roadmap priorities.

  7. Feed lessons back into the lifecycle
    Ensure improvements inform the next Anticipate, Detect, Respond, Withstand, and Recover cycles.

Key Outputs

The Adapt phase should create outputs that support measurable improvement, including:

  • Lessons learned report
  • Root cause analysis
  • Corrective action plan
  • Continuous improvement roadmap
  • Updated resilience maturity assessment
  • Control optimization plan
  • Updated business continuity plans
  • Updated disaster recovery plans
  • Updated incident response playbooks
  • Updated supplier resilience requirements
  • Updated KRIs, KPIs, and KCIs
  • Governance review report
  • Executive resilience performance dashboard
  • Strategic resilience roadmap
  • Board-level resilience briefing

Why This Phase Matters

Without adaptation, resilience programs become stale. Plans become outdated. Controls lose effectiveness. Supplier assumptions become inaccurate. Technology dependencies change. Regulations evolve. Business priorities shift.

Adaptation ensures that operational resilience remains dynamic and relevant.

This phase also helps organizations demonstrate continuous improvement to executives, regulators, auditors, customers, and stakeholders.

OpResONE Perspective

At OpResONE, we believe Adapt is where resilience becomes a true management system. It transforms operational resilience from a one-time project into an embedded, measurable, and continuously improving capability.

Adaptation connects governance, risk management, control improvement, audit remediation, technology modernization, supplier oversight, and strategic planning. It ensures the organization does not simply survive disruption, but becomes stronger because of it.

*Possible integrated dashboard


Recover: Restoring Critical Services With Confidence and Control

Even the most resilient organizations can experience disruptions that exceed preventative controls or operating capacity. When this happens, recovery capabilities become essential.

The Recover phase focuses on restoring critical services, business operations, technology, communications, customer outcomes, and stakeholder confidence within defined impact tolerances.

Recovery is often associated with business continuity and disaster recovery. While these disciplines remain essential, operational resilience expands recovery beyond restoring systems or relocating work. Recovery must be aligned to business priorities, customer expectations, regulatory obligations, and impact tolerance thresholds.

The Recover phase asks:

Can we restore critical services and outcomes before disruption causes unacceptable harm?

Key Inputs

The Recover phase depends on information and capabilities developed throughout the lifecycle, including:

  • Business continuity plans
  • Disaster recovery plans
  • Critical service maps
  • Recovery time objectives
  • Recovery point objectives
  • Impact tolerance thresholds
  • Technology restoration procedures
  • Application dependency maps
  • Data backup and restoration procedures
  • Manual workaround procedures
  • Crisis communication plans
  • Supplier recovery commitments
  • Workforce recovery strategies
  • Customer communication templates
  • Regulatory notification requirements
  • Incident response documentation
  • Situation reports and decision logs

These inputs guide recovery sequencing, restoration priorities, communication needs, and validation activities.

Lifecycle Process

A strong recovery process ensures restoration efforts are organized, prioritized, tested, and aligned to critical outcomes.

Core recovery activities include:

  1. Confirm service impact and recovery priorities
    Determine which services, systems, processes, customers, and dependencies are affected.

  2. Align recovery to impact tolerances
    Prioritize restoration based on customer harm, regulatory exposure, financial loss, operational dependency, and strategic importance.

  3. Activate recovery plans
    Execute business continuity, disaster recovery, technology restoration, supplier recovery, facility recovery, or manual workaround procedures.

  4. Coordinate across business and technology teams
    Ensure business operations, IT, cybersecurity, suppliers, communications, and leadership remain aligned.

  5. Communicate recovery status
    Provide timely updates to employees, customers, executives, regulators, suppliers, and other stakeholders.

  6. Validate restoration
    Confirm that systems, data, processes, controls, and service outcomes are functioning as required.

  7. Transition to steady-state operations
    Move from recovery mode back to controlled operations while monitoring for residual issues.

Key Outputs

The Recover phase should produce documented and validated outputs such as:

  • Recovery activation records
  • Business continuity execution logs
  • Disaster recovery execution logs
  • Service restoration reports
  • Technology recovery validation results
  • Data restoration confirmation
  • Customer communication updates
  • Regulatory communication records
  • Recovery timeline
  • Impact tolerance breach analysis
  • Recovery metric reports
  • Residual risk assessment
  • Transition to normal operations checklist
  • Post-incident review package

Why This Phase Matters

Recovery is not simply returning to normal. It is restoring value, confidence, and control.

If recovery activities are not aligned to critical services, organizations may restore the wrong systems first, overlook customer impact, miss regulatory obligations, or fail to validate that service outcomes are truly restored.

Operational resilience requires recovery to be business-led, risk-informed, technology-enabled, and tolerance-driven.

OpResONE Perspective

At OpResONE, we help organizations connect traditional BCM and disaster recovery capabilities to the broader operational resilience lifecycle. Recovery should not exist in isolation. It should be informed by Anticipate, triggered by Detect, coordinated through Respond, strengthened by Withstand, and improved through Adapt.

This integrated approach ensures recovery activities are not merely technical exercises, but strategic capabilities that preserve organizational value.

*Possible Integrated Dashboard