Resilience is determined before the crisis strikes

July 24, 2026

The discussions at KRIFA Münster 2026 demonstrate why networked collaboration has become a key prerequisite for modern security preparedness.

Crises do not respect jurisdictional boundaries. A prolonged power cut affects not only energy suppliers, but also hospitals, communications networks, transport systems, public administrations, businesses and private households. A cyberattack can disrupt physical operations, whilst extreme weather events exacerbate existing supply bottlenecks. Added to this are sabotage, disinformation and hybrid influence operations.

The crucial question is therefore no longer simply which organisation is responsible for a particular scenario. Rather, it is: How can the stakeholders involved remain capable of acting collectively when multiple disruptions occur simultaneously and reinforce one another?

This question ran through numerous presentations and discussions at KRIFA Münster – the specialist conference and exhibition on security and crisis preparedness – on 15 and 16 July 2026. Representatives from civil protection, academia, the Bundeswehr, the security sector, public authorities, aid organisations and the healthcare sector discussed the security policy situation, the protection of critical infrastructure, crisis communication and the requirements for societal resilience as a whole.

The key insight: resilience is not merely the result of reacting to an event that has already occurred. It must be built up well in advance – through robust structures, realistic planning, tried-and-tested procedures, open communication and cooperation that transcends organisational boundaries.

Crises are losing their clear boundaries

Traditional crisis models often assume a recognisable beginning, a climax and a subsequent recovery phase. However, this picture increasingly fails to reflect reality. Prof. Dr Henning Görsch, Professor of Emergency Response and Civil Protection and Head of Programme at FOM University, described at the KRIFA conference the trend towards ‘boundary-less crises’.

This refers to situations that can no longer be clearly defined in terms of time, space or organisation. They can begin insidiously, affect several areas of society simultaneously and become intertwined with other disruptions. One crisis can exacerbate another or even trigger it in the first place. Hybrid attacks can also be specifically designed to capitalise on existing stress points – for example, when a heatwave is exploited to place critical infrastructure under additional pressure.

“We must respond to this de facto blurring of boundaries with a correspondingly boundary-less approach,” was Görsch’s conclusion. Administrative levels and specialist responsibilities must become more permeable. Cooperation must not be limited by national borders, ministerial boundaries or organisational structures.

This also changes the understanding of crisis management. It is no longer sufficient to have isolated plans for individual scenarios. What is needed are structures that function even when several systems are affected simultaneously and tried-and-tested procedures no longer work as intended.

For operators of critical infrastructure, this means analysing dependencies more thoroughly. The operational readiness of a hospital, for example, does not depend solely on medical staff and technical equipment. It also requires functioning electricity and water supplies, communication networks, transport capacity, medicine deliveries and resilient supply chains. If any one of these fundamentals fails, it can quickly trigger a cascade of further constraints.

Preventive measures often go unnoticed

A key challenge is that successful prevention goes largely unnoticed. If no serious damage occurs, it is difficult to determine the extent to which prior investments, redundant systems or drills contributed to this outcome. Expenditure on preventive measures therefore easily comes under pressure to be justified.

Prof. Dr Peter Bradl, Professor of Public Health Protection, reminded the audience in Münster that resilient structures must be maintained, even though they may not pay for themselves immediately during normal operations. Drawing on his time in the German Armed Forces, he referred to parallel communication routes running alongside the motorways, which could be operated deliberately independently of the regular infrastructure.

The logic behind this is uncomfortable but crucial: resilience costs money before its benefits become apparent. It requires investment in capabilities which, in the best-case scenario, are rarely needed in their entirety. Its economic value is not evident solely in day-to-day operations, but in the damage averted and in the ability to maintain essential services even under exceptional conditions.

“We must consider what security is worth to us,” emphasised Bradl. His appeal was also explicitly directed at businesses. Those who select protective measures based solely on short-term costs risk not only higher follow-on costs in the event of an incident, but also potentially the operational capability of key business areas.

Precautionary measures must therefore not be reduced to the procurement of technical systems. What is needed are clear lines of responsibility, robust contingency arrangements, up-to-date emergency plans, trained staff and regularly reviewed communication channels. Equally important is the question of whether the planned procedures actually work under realistic conditions.

A crisis management team that cannot be reached during a power cut, an emergency room without an independent power supply, or an alert system that relies exclusively on communication networks that have failed, creates only an illusion of security. Resilience is only achieved when plans are tested in practice, weaknesses are openly identified and recognised shortcomings are subsequently rectified.

The ‘Operations Plan Germany’ is not an overarching plan for society

The ‘Operations Plan Germany’ received particular attention at the KRIFA. In public debate, it is sometimes understood as a comprehensive crisis or defence plan for the whole of the Federal Republic. Retired Colonel Dirk Franke made it clear that this interpretation goes too far.

“This is not an operational plan for Germany,” explained Franke. Rather, it is a military plan that governs the Bundeswehr’s contribution to national and alliance defence, as well as other tasks of the armed forces. This also includes Germany’s role as a logistical hub for the deployment of allied forces.

However, it is precisely this that gives rise to numerous points of contact with the civilian sector. Military transports use public roads, railways, ports and airports. Service personnel require accommodation, catering, medical care, energy and fuel. At the same time, many of these services remain the responsibility of the civilian sector, even in a tense security situation.

Franke made it clear that the Bundeswehr cannot permanently undertake such tasks on its own. The more military forces are tied up with their core missions, the more important support from civilian structures becomes. “That is why coordination with the civilian sector is so important,” he emphasised.

However, this coordination must not only begin once transports are already underway or a specific threat has materialised. Local authorities, police forces, infrastructure operators, logistics companies, the healthcare sector and the security industry must clarify in advance which services are required, what capacities are available and where legal or organisational obstacles exist.

The Operations Plan Germany thus highlights a fundamental problem: military planning can only work if civilian infrastructure is resilient. Conversely, civilian actors must not assume that the Bundeswehr can provide unlimited personnel and equipment in the event of a crisis. Expectations and actual capabilities must be reconciled at an early stage.

Security often fails at the interfaces

Many organisations have contingency plans, crisis management teams and security officers. Nevertheless, gaps frequently arise in an emergency – not necessarily within a single system, but at the interfaces between different actors.

A local authority may plan on the basis that an energy supplier is available, whilst that supplier itself is dependent on external communications networks. A hospital may have medical emergency procedures in place, but without fuel supplies, it can only maintain its emergency power supply for a limited time. A company may have a crisis management team, but has not clarified how this team is to convene in the event of a failure of digital communications.

It is precisely at such interfaces that it is determined whether a disruption will develop into a protracted crisis.

In Münster, therefore, warnings have repeatedly been issued against thinking in terms of organisational silos. Government bodies, academia, the security sector, aid organisations and businesses each possess specific capabilities. However, there is often a lack of an overview of who can provide which services and how these should be coordinated in the event of an incident.

In this context, networking means more than simply exchanging contact details. It requires shared situational awareness, standardised terminology, clear reporting channels and an understanding of how each other’s organisations operate. Anyone who only clarifies during a crisis which authority is responsible, what information may be passed on or which contact person is available loses valuable time.

Regular exercises are therefore essential. They do not always have to take the form of large-scale full-scale exercises. Even joint simulation exercises can reveal where responsibilities are unclear, assumptions are unrealistic or resources have been double-booked.

At the KRIFA conference, one participant described an example from an exercise: although an emergency generator was supposed to kick in during a power cut, the designated crisis management centre was not connected to the emergency power supply. The problem lay not in a lack of technology, but in a lack of coordination between different areas of responsibility.

A resilient organisation is therefore not characterised by the fact that its plans contain no errors. It is characterised by the fact that it identifies errors before an emergency occurs and learns from them.

The public is part of the security architecture

Societal resilience cannot be achieved solely by public authorities, emergency services and businesses. The public must also know what precautions make sense, what help can be expected in the event of an incident, and in which situations personal responsibility is required.

During the discussion at KRIFA, it became clear that many citizens are fundamentally willing to help in crises. However, they often lack the knowledge of how to prepare and how they can contribute effectively. Even organisations such as the Federal Office for Civil Protection and Disaster Assistance are scarcely known to parts of the population.

Görsch therefore called for more open communication about risks. Civil protection planning must not be a ‘secret science’. Authorities should not give the impression that they can fully control every situation. Rather, there must be a transparent explanation of what services the state can provide, where the limits lie, and what precautions are expected of private households or businesses.

Whilst this honesty may initially seem uncomfortable, in the long term it strengthens people’s ability to act. Those who know that, in the event of a prolonged power cut, help will not be immediately available across the board can organise supplies, medication, means of communication and support networks in good time.

The key lies in the nature of the communication. Dramatisation can heighten fears and trigger defensive reactions. Reassurance, on the other hand, prevents risks from being taken seriously. What is needed is communication that contextualises threats in a comprehensible way, outlines concrete courses of action and generates neither panic nor a false sense of security.

In the security policy discussion at the KRIFA, too, warnings were issued against communication that either frightens the public or fails to provide sufficient information. What is needed, it was said, is conscientious and honest information about existing threats, current capabilities and any remaining shortcomings.

Resilience does not begin solely within government agencies or control centres. It begins in schools, workplaces, clubs, neighbourhoods and families. First-aid skills, local support networks, personal emergency preparedness and a basic understanding of warning systems cannot be replaced by state structures. However, they can help to bridge the initial phase of a crisis and relieve the burden on professional emergency services.

Businesses bear a dual responsibility

This development presents businesses with a dual task. On the one hand, they must safeguard their own operational capacity. On the other hand, many of them form part of socially vital supply chains – even if they are not formally classified as operators of critical infrastructure.

Suppliers, security service providers, logistics companies, IT providers, trades businesses or operators of commercial kitchens can, in the event of a crisis, provide services on which public institutions and critical infrastructure depend. If such a service provider fails, this can have far-reaching consequences.

Business continuity management should therefore not focus solely on internal processes. Companies must also understand their role within overarching supply networks. This involves analysing dependencies on energy, communications, staff, transport routes and suppliers. Equally relevant is the question of which services a company must maintain for other stakeholders in the event of a crisis, or could provide additionally.

In this context, cooperation is becoming increasingly important. Not every organisation can maintain all the necessary resources itself. Agreements with partner companies, local authorities or aid organisations can pool capacities. However, this requires that such collaborations be formally agreed in advance and regularly reviewed.

Company management also has a role to play. Resilience must not be delegated exclusively to security, IT or facilities departments. Decisions regarding redundancies, stockpiles, alternative locations and staff reserves are strategic decisions. They affect investment, liability, reputation and, ultimately, the company’s viability.

From individual responsibility to shared responsibility

The discussions at KRIFA Münster 2026 showed that Germany is not starting from scratch. Public authorities, companies, emergency services and the research community possess extensive experience and numerous tried-and-tested concepts. The key shortcoming lies not so much in a complete lack of knowledge as in its distribution.

Knowledge, resources and responsibilities are spread across many stakeholders who, in day-to-day operations, collaborate only to a limited extent. This is precisely why safety preparedness must be understood more strongly as a shared task.

This does not mean abolishing statutory responsibilities. Clear responsibilities remain indispensable. However, they must not prevent information from being shared, interdependencies from being recognised and joint solutions from being developed.

Resilience arises from the interplay of many individual capabilities: robust technology, trained staff, redundant communication channels, an effective administration, well-prepared businesses and an informed public. None of these elements can replace the others.

An emergency will reveal just how resilient individual measures actually are. However, whether this results in a manageable disruption or a far-reaching crisis is decided much earlier: in investment decisions, contingency plans and drills, in communication, and in the willingness to cooperate across institutional boundaries.

Resilience is therefore not determined only during the crisis. It is determined in the years, months and days leading up to it.

KRIFA Münster 2026

The KRIFA Münster – Specialist Conference and Exhibition on Security and Crisis Prevention took place on 15 and 16 July 2026 at the MCC Halle Münsterland. The focus was on the strategic security situation, operational threat and attack scenarios, physical protection measures, resilience and operational safety, as well as innovations and future security solutions.

According to the organiser, around 250 participants attended the specialist conference and the accompanying exhibition. The Federal Association for the Protection of Critical Infrastructure (BSKI) supported the event as a conceptual sponsor and organised the specialist conference programme. Another edition of KRIFA Münster is planned for 2027.

Related Articles

Share This