No longer good practice

Resilience has become an obligation, with deadlines.

The Critical Entities Resilience Directive covers eleven sectors — energy, transport, health, water and the rest. Designated entities must carry out risk assessments, adopt proportionate technical and organisational measures, notify incidents affecting their services, and, in several Member States, validate all of this through periodic exercises.

National resilience strategies were due by 17 January 2026, and the designation of critical entities has since taken place. Combined with NIS2 on the cyber side, this architecture turns a subject long handled internally, at the margins, into a documented and auditable obligation.

11 sectorsCovered by the CER Directive
Resilience plansRequired of designated entities
ExercisesPeriodic in several Member States
NIS2Cyber strand connected to the framework

Our method

Four stages, in this order.

An exercise is decided at the first link. If the scenario does not hold, executives do not commit to it: they tick boxes and leave. An exercise is worth what the plausibility of the situation you put to them is worth.

01

Analysis

Understanding the threats that genuinely bear on you: geopolitical environment, dependencies, supply chains, informational and regulatory exposure.

02

Scenario

Building an escalation sequence your executives cannot wave away — because it is documented, dated, and consistent with what the actors actually do.

03

Exercise

Making the people who will manage the crisis play it. Executive cell, decisions under uncertainty, communication, relations with authorities and the media.

04

Plan

Turning what the exercise revealed into a resilience and continuity plan, written in the form the regulator expects and workable by your teams.

What we bring in

A credible scenario
cannot be improvised.

For each assignment we bring in researchers in international relations and political science, whose trade is analysing power relations and shifts in opinion. Their work is not sold to you as one more note: it becomes the raw material of the scenario.

  • Analysis of power relationsEscalation sequences, state actor behaviour, hybrid threats and strategic dependencies.
  • Opinion and legitimacy dynamicsWhat tips the acceptability of a decision, fractures opinion, or collapses trust — that is, half of what makes real crisis management fail.
  • Information environmentCoordinated campaigns and information manipulation, drawing on our founder’s experience coordinating within OPSCI.AI the European Narratives Observatory operated for DG CONNECT.

“An organisation does not discover its weaknesses during the crisis. It discovers them the moment someone asks it, calmly, what it would do.”

Matthieu Blondeau, founder

Where this craft comes from

A practice older than the regulation.

Nuclear sector

Large-scale crisis exercises

2001 – 2009

Sensitive industryExercises

Organising large-scale crisis exercises for a sector where mistakes are not easily forgiven, at a time when few organisations were required to. That is where the reflexes the CER Directive now extends to eleven sectors were formed.

  • Scenario design and crisis cell facilitation
  • Crisis communication and spokesperson preparation
  • Handling authorities and media under heavy pressure

European Parliament

Coordinating actors under constraint

2013 – 2020

Seven years bringing together EU institutions, public authorities, companies and civil society. A crisis is rarely managed alone: knowing who to call, in what order, and what each can and cannot do, is learned from the inside.

Pôle d’Excellence Cyber

Pro bono mandate and sector footing

Today

CyberDefence

Pro bono mandate as Europe ambassador for a cluster founded by the French Ministry of the Armed Forces and the Brittany Region, bringing together schools, laboratories, SMEs and public institutions. The threats we build scenarios around, we discuss with the people who handle them.

Who this is for

Four audiences, four different reasons to anticipate.

Critical infrastructure operators

Energy, transport, health, water, digital. Entities designated under the CER Directive and subject to NIS2 on the cyber side.

A legal obligation, documented and auditable.

Defence and cyber manufacturers

Groups, mid-caps and SMEs across the sector, including those bidding into the European Defence Fund or EDIP.

Supply chain resilience now conditions access to markets.

Local and national authorities

Exposed territories, public service operators, organisations that must hold when an event exceeds their standard procedures.

We have worked on the territorial side, from European bids to citizen mobilisation.

European institutions and agencies

Directorates-general, agencies and networks commissioning preparedness, exercise or threat analysis work.

We know their procurement procedures from the inside, having answered and managed them.

Two ways to fund it

As a service, or in a consortium.

Directly

On a compliance or executive budget

Analysis assignment, exercise, resilience plan. The timetable is yours, the deliverable stands up to a regulator, and the budget sits under compliance — the one that does not get cut when conditions tighten.

Horizon Europe

Cluster 3 — resilient infrastructure, disaster-resilient society

The same competences can be carried into a research and innovation consortium, under the cluster 3 destinations on resilient infrastructure and disaster-resilient society. From €1m to €8m per project depending on the call, with up to 100% of costs covered.

  • We build the consortium and draft the proposal
  • Several calls require the involvement of public authorities: that partnership is built months before the deadline
  • See our EU funding practice →

You have a plan. When did you last play it?

The first conversation is there to establish what is actually achievable — including telling you when it is not.

Get in touch