Resilience Reality Check: Entrepreneurial Preparedness for the First 72 Hours of Crisis
By Vitālijs Rakstiņš
|
18 May 2026.
The majority of national security frameworks prioritize individual preparedness, establishing a minimum duration (72 hours to seven days) that a private citizen is expected to survive without state assistance following a significant disruption. But a key question follows: are similar expectations placed on businesses and institutions?
The 72-hour standard was never intended for commercial enterprises because it originated from the household preparedness doctrine. Private companies are well aware of the importance of preparedness, but they have made a rational calculation within a permissive regulatory environment. Compliance costs money today, while noncompliance costs nothing. Investing in resilience incurs immediate, certain, and fully visible costs on a balance sheet, while the costs of failure are future.
Resilience and efficiency are structurally in tension. Secure, locally sourced supply chains are more expensive. "Just-in-case" inventory models tie up capital. Redundant systems, backup power, and cyber-resilient infrastructure all carry direct costs. Secure hardware and software from NATO and EU countries costs more than alternatives sourced outside those alliances. The market will always pressure organizations toward efficiency over redundancy. Expecting businesses to invest in preparedness without addressing this economic reality is wishful thinking.
Certain private companies are obliged to invest in resilience, either by regulation (for instance, critical infrastructure) or by compliance requests from their mother companies or investors.
Critical infrastructure operators are legally required to maintain compliance with security standards and business continuity plans. However, critical infrastructure does not operate in isolation. Most organizations depend on outsourced services, including IT support, physical security, logistics, and maintenance. The resilience of critical infrastructure is therefore inseparable from the resilience of its subcontractors. Many subcontractors hold simultaneous contracts with dozens or hundreds of organizations. If a crisis occurs, all those clients may demand the same service immediately. Can a single security firm guard hundreds of facilities during a hybrid attack? Is it possible for an IT provider to support dozens of clients at once who have been affected by ransomware, as was the case with WannaCry and NotPetya? Can backup generator suppliers deliver to all partners at once, as the 2025 Spain-Portugal electricity crisis demonstrated? This issue of interdependency is not sufficiently addressed in current preparedness frameworks.
The Nordic-Baltic planning assumption is that if essential services such as electricity, communications, banking, and water remain functional, the private sector will adapt. This has been demonstrated during the pandemic and the war in Ukraine. The EU's Union Preparedness Strategy outlines a meaningful action plan, including minimum preparedness criteria for essential services, stockpiling requirements for critical materials, and mechanisms to secure critical production lines. This is directionally correct. However, implementation will take years. Latvia's private sector needs to be resilient now. The threats are immediate and overlapping. Hybrid warfare is not a future scenario but today's reality, as unmanned aerial incidents have already occurred on Latvian soil. A parallel risk is supply chain fragility, as a US-Iran military conflict could impact Europe's access to critical medicines and manufacturing inputs with little warning.
The 2025 BRELL electricity grid disconnection in the Baltics was a useful stress test. It prompted organizations to update their crisis plans, check their generators, and verify their backup procedures. At the same time, Latvia has introduced so-called Category D critical infrastructure obligations, which primarily target subcontractors of essential service providers and require them to demonstrate preparedness and wartime functionality. Sweden is developing a national standard, SS 22306, for organizational preparedness applicable to both public and private organizations, explicitly designed for use in procurement, meaning that contracting authorities will be able to require demonstrated preparedness as a condition of commercial engagement, measured against actual operational capability.
We see different, fragmented initiatives. What is required is a methodical, ecosystem-level approach to preparedness that includes clear obligations, fair compensation mechanisms, and the genuine integration of the private sector into national security planning. While essential service providers and the CER directive partly cover this, many essential service subcontractors do not have the obligation or resources to invest in security and resiliency. This includes the ability to operate for at least 72 hours during a crisis.
Vitālijs Rakstiņš is a security and resilience practitioner with over 20 years of operational experience spanning national defense, crisis management, and business continuity. He has served as Director of Crisis Management at Latvia's Ministry of Defense, as the first Director of the reestablished conscript service department, as a non-resident Defense Advisor to Ukraine (2021–2023), and as Deputy Defense Advisor to the Latvian Delegation to NATO (2012-2015). Currently Chief Resilience Officer at Latvian Public Broadcasting (national TV/radio) and Head of Civil Defense at the Ministry of Culture, he also lectures on national security at Rīga Stradiņš University.