Practice 06 / 06

Risk & Resilience

In a world of polycrisis — geopolitical fragmentation, cyber warfare, climate disruption, regulatory acceleration, and supply chain volatility — risk management has become the defining strategic imperative of our era.

90+
Risk & resilience engagements
$3.8B
Estimated losses prevented
50+
Cyber readiness reviews
Practice Overview

Enterprise risk was once a compliance function — a box to check, a report to file, a committee to staff. That era is over. The organizations that will thrive in the next decade are those that treat risk not as a constraint but as a strategic capability — one that enables faster decision-making, bolder investments, and more resilient operations. Our Risk & Resilience practice helps boards and C-suites build the foresight, governance, and response capabilities to navigate uncertainty without paralysis. We do not build risk frameworks that gather dust. We build risk intelligence systems that inform every strategic decision, every capital allocation, and every board conversation — in real time.

Our service areas

Enterprise Risk Management

We design enterprise risk frameworks that connect strategic, operational, financial, and compliance risks into a unified view — enabling boards and management teams to make risk-informed decisions at speed. Our frameworks are not theoretical. They integrate directly into strategic planning cycles, capital allocation processes, and performance management systems to ensure risk intelligence shapes every material decision.

Risk Appetite DesignKRI DashboardsBoard Risk ReportingThree Lines ModelRisk Culture Assessment
Cybersecurity & Digital Risk

We provide strategic cybersecurity advisory for boards and C-suites — not implementation, but the governance, investment prioritization, and organizational design that make cyber programs effective. Our approach focuses on the questions that matter: Are we investing in the right controls? Can we detect a breach in time to contain it? What is our board's fiduciary exposure? How do we communicate cyber risk to investors and regulators?

Cyber Maturity AssessmentBoard Cyber GovernanceIncident Response PlanningThird-Party Cyber RiskRansomware Readiness
Geopolitical & Regulatory Risk

We help multinationals navigate geopolitical fragmentation, sanctions regimes, trade wars, and regulatory divergence — building scenario-based playbooks that enable fast, coordinated responses to emerging crises. Our geopolitical intelligence combines in-house analysis with a network of former government officials, intelligence analysts, and regulatory experts across 40 jurisdictions.

Scenario PlanningSanctions ComplianceRegulatory MappingCrisis PlaybooksPolitical Risk Assessment
Business Continuity & Crisis Management

When crisis hits, the quality of preparation determines the outcome. We design, stress-test, and validate business continuity plans, crisis management protocols, and crisis communication strategies through rigorous tabletop exercises and full-scale simulations. Our crisis response teams have supported clients through ransomware attacks, supply chain collapses, product recalls, regulatory investigations, and natural disasters.

BCP DesignCrisis SimulationTabletop ExercisesCrisis CommunicationsPost-Crisis Review
Financial Risk & Controls

We help organizations strengthen their financial risk management — from treasury and liquidity risk to fraud detection and internal controls. Our engagements range from designing SOX-compliant control frameworks to building real-time fraud detection systems that leverage AI pattern recognition across transaction data, procurement workflows, and expense reporting.

Internal Controls DesignSOX ComplianceFraud DetectionTreasury RiskFinancial Crime Prevention
Third-Party & Supply Chain Risk

Your risk surface extends far beyond your organization. We map, assess, and monitor third-party risk across critical vendors, suppliers, outsourcing partners, and joint ventures — identifying concentration risk, geopolitical exposure, cyber vulnerabilities, and financial fragility in the extended enterprise before they become front-page problems.

Vendor Risk AssessmentConcentration RiskSupply Chain MappingFourth-Party RiskContinuous Monitoring
Our Approach

Five phases, from diagnosis to resilience

1
Risk Landscape Assessment
We map the full risk universe — strategic, operational, financial, compliance, and emerging — and benchmark your current risk posture against industry peers, regulatory expectations, and best-in-class frameworks.
Weeks 1–3
2
Vulnerability & Scenario Analysis
We stress-test your enterprise against realistic adversarial scenarios — cyberattack, geopolitical shock, supply chain collapse, regulatory enforcement, pandemic resurgence — quantifying potential impact and identifying cascading failure modes.
Weeks 3–6
3
Risk Architecture Design
We design the governance structure, risk appetite framework, KRI dashboard, escalation protocols, and reporting cadences that connect risk intelligence to strategic decision-making. No framework survives contact with reality unless it is embedded in how the organization actually operates.
Weeks 6–10
4
Crisis Readiness & Testing
We design and execute tabletop exercises, crisis simulations, and red-team assessments that expose gaps in response capability before a real crisis does. We test not just the plan — but the people, the decision-making processes, and the communication chains that must function under pressure.
Weeks 10–14
5
Resilience Embedding
Risk is not a project — it is a capability. We embed risk intelligence into strategic planning, M&A diligence, new market entry decisions, vendor onboarding, and board reporting to ensure the organization builds resilience as a permanent competitive advantage.
Weeks 14–20+

Selected engagements

Results our clients have permitted us to share.

Global Financial Institution
Board-level cyber governance program after a near-miss ransomware event
$340M
Estimated loss prevented
6mo
To full readiness

Redesigned the board's cyber risk oversight framework, implemented a real-time threat intelligence dashboard, and conducted three crisis simulations that identified critical decision-making gaps. The institution detected and contained a subsequent attack within 4 hours — compared to an industry average of 204 days.

Read full case
Multinational Manufacturer
Geopolitical risk playbook for operations across 14 countries
14
Country playbooks developed
72hr
Response activation time

Built country-specific risk playbooks covering sanctions, political instability, supply chain disruption, and regulatory change. When export restrictions were imposed on a key market, the client activated the playbook within 72 hours — rerouting production, notifying customers, and maintaining 94% of revenue.

Read full case
Fortune 200 Retailer
Third-party risk program identifying critical vendor concentration
2,400
Vendors assessed
$890M
Concentration risk identified

Mapped the retailer's 2,400 critical vendors across financial stability, cyber maturity, geopolitical exposure, and operational resilience — discovering that 40% of revenue depended on 12 vendors in a single geographic region. Designed and executed a diversification program that reduced concentration risk by 62% within 18 months.

Read full case
Healthcare System
Enterprise risk transformation integrating clinical, financial, and operational risk
35
Hospitals unified
40%
Reduction in risk incidents

Unified clinical safety, financial risk, compliance, and operational risk into a single enterprise risk framework across 35 hospitals. Implemented real-time KRI dashboards that enabled proactive intervention, reducing risk incidents 40% and earning a 15% malpractice insurance premium reduction.

Read full case
Practice Leadership

Meet the partners who lead this work

EM
Elena Marchetti
Global Head, Risk & Resilience
Former Chief Risk Officer of a G-SIB bank. 25 years in enterprise risk, regulatory affairs, and crisis management across financial services, energy, and healthcare. MBA, Columbia.
TK
Thomas Kessler
Partner, Cybersecurity & Digital Risk
Former NSA senior advisor and Fortune 50 CISO. Leads board-level cyber governance engagements. Expert in threat intelligence, incident response, and regulatory cyber compliance. MS, Carnegie Mellon.
NR
Nadia Rostova
Partner, Geopolitical Risk
Former State Department senior policy advisor and NATO strategic analyst. Leads geopolitical scenario planning engagements for multinationals operating in contested markets. PhD, Georgetown SAIS.
MB
Marcus Blackwell
Partner, Business Continuity & Crisis
Led crisis response for three Fortune 100 companies across ransomware attacks, product recalls, and regulatory enforcement actions. Former FEMA advisor. MBA, Kellogg.

When the sanctions hit, we activated the Meridian playbook within 72 hours. We rerouted production, notified customers, and filed compliance documentation before our competitors had finished their first legal review. That preparation — the scenario modeling, the decision trees, the pre-negotiated alternatives — saved us $200 million in revenue that would have evaporated. Risk management is not a cost center. It is the reason we are still operating in that market.

Chief Operating Officer
Global Manufacturing Division
Fortune 200 Industrial Corporation

Related thinking

Cyber Risk
Board Cyber Governance in 2026: What Directors Must Know
10 min read · March 2026
Geopolitics
Navigating the New Sanctions Landscape: A Decision Framework
14 min read · February 2026
Resilience
From Business Continuity to Competitive Advantage: The Resilience Imperative
8 min read · January 2026
Third-Party Risk
The Hidden Concentration Risk in Your Supply Chain
12 min read · December 2025
Build Resilience

Ready to turn risk into advantage?

Our senior partners are available for a confidential conversation about how we can help your organization build the foresight and resilience to thrive in uncertainty.