Skip to content Skip to footer

OCF: Operational Continuity Framework

The Problem Nobody Is Measuring
When an operation starts failing, it rarely fails in one place. One system degrades. That puts pressure on the next. Which weakens the one after. By the time the picture is clear, the window to intervene has already closed.

Every organisation monitors individual systems. Nobody measures the combined picture. Nobody calculates how fast the overall situation is deteriorating or how much time remains before recovery becomes impossible regardless of what you do.

That is the gap OCF addresses.

How It Works
OCF watches multiple operational layers simultaneously. Not each one in isolation;  the connections between them. When one layer starts failing it affects the others. The model tracks that propagation, calculates a single index showing overall operational health, and projects forward to tell you when that index will cross the threshold of no return.

The result is two numbers: 1) where you are now, and 2) how long you have left to act.

No other tool currently produces this.

What Changes When You Have It
You stop managing crises after they become unrecoverable. You see the cascade building before it closes the window. You act earlier, at lower cost, with a documented and auditable basis for the decision.

The Research

OCF is doctoral research at Cranfield University, School of Aerospace, Transport and Manufacturing, within the AI, Robotics and Space group.

Cranfield is ranked top 30 globally for aeronautical engineering and is the only university in Europe that operates its own airport and air navigation service. Its Digital Aviation Research and Technology Centre runs active research partnerships with Boeing, Thales, Saab and Spirent.

Supervised by Professor Antonios Tsourdos, Head of the Autonomous Systems Group, and Professor Ivan Petrunin, specialist in navigation systems and resilience under degraded conditions.

The research builds a quantitative model that measures operational continuity across multiple degrading layers simultaneously, calculates a single real-time index, and projects the intervention window before it closes. Validated against documented Baltic Sea GNSS interference campaigns, communications blackout exercises and Jammerfest Norway data.

While the model originates in navigation and defence resilience, the research will demonstrate its application independently across banking, manufacturing, rail, legal services, cyber and civil contingency. The same framework. Every sector. Before the window closes.

The research is seeking funded sponsors and data partners across all sectors. All material handled under NDA. Findings shared before public release. No procurement process required.

Most operations fail not because nobody acted, but because nobody knew the window was closing

Every operation has a window. A point where intervention still works. After it closes, more resources, faster decisions and better technology all produce the same result: nothing.

Regulatory Obligations
Regulators are now asking a question most boards cannot answer: how close are you to the point where your critical services can no longer be maintained?

OCF answers that question. A single real-time index showing exactly where an operation sits relative to its failure threshold, how fast it is moving, and how much time remains to act.
That answer is now a legal requirement.

DORA applies across the EU from 17 January 2025. FCA PS21/3 and PRA SS1/21 apply in the UK from 31 March 2025. FCA PS26/2 added mandatory incident reporting within 24 hours of a threshold breach.

Industries in scope:

  • Banks and credit institutions, EU and UK
  • Insurance and reinsurance undertakings, EU and UK
  • Investment firms and trading platforms, EU and UK
  • Payment and electronic money institutions, EU and UK
  • Crypto-asset service providers, EU
  • Critical ICT third-party service providers, EU and UK
  • PRA-designated investment firms, UK

Both regimes require firms to prove they can stay within tolerance. Neither specifies how to measure how close they are to breaching it.

OCF is that measurement.

Interested in OCF?
If you are dealing with operational risk, system resilience or continuity under pressure – or you have data from exercises, incidents or degradation events – the conversation is direct. No procurement process.

Data partners, named research sponsors, or sector pilots welcome.

The Scale of the Problem

This is not a technology problem. It is not a risk management problem. It is not a sector-specific problem.
It is a measurement problem.

Every industry that depends on interconnected systems is running blind to the most important number in operations: how close the combined picture is to the point where recovery stops being possible.

Banks monitor payments but not the cascade building across five systems simultaneously. Factories monitor production but not how logistics, supplier confidence and cash are degrading together. Rail operators monitor signals but not how communications, control room capacity and traffic management are failing in parallel. Law firms monitor IT incidents but not when the combined failure of filing, communications and deadlines crosses the unrecoverable threshold. Defence forces log navigation anomalies but nobody correlates them into an operational picture before the window closes.

158 bank IT failures in two years across the UK alone. 94% of European manufacturers reporting production stoppages. 4,875 cyber incidents across EU critical infrastructure in one year. 803 hours of banking downtime. 33 days. Trains stopping in tunnels. Factories shutting across continents from a single chip supplier. The European Central Bank suspending three trillion euros of daily payments from a hardware defect.

Each one logged separately. Each one managed in isolation. Nobody calculating how fast the combined picture was moving toward the threshold before it crossed it.

That is the gap OCF fills. One index. Every layer. Every sector. Before the window closes.

And OCF can foresee it

Example scenarios
Banking and Financial Services

803 hours. 158 incidents. 33 days offline. Nine of the UK’s biggest banks. Two years. That is not bad luck. That is a pattern nobody measured until customers were calling food banks.

  • Barclays, UK. The mainframe started degrading. Not failing, degrading. Payments slowing. Balances going stale. The cascade building across layer after layer while every dashboard still showed green. By the time anyone called it critical, 56% of online payments had already failed. Customers locked out for three days. Leadership went silent. The bill: up to £12.5 million in compensation. The window where a controlled fix was still possible opened and closed while nobody was watching it.
  • European Central Bank, Frankfurt. A hardware defect in the T2 settlement system suspended over three trillion euros of daily payments across the entire eurozone for seven hours. Wages, pensions and social welfare transfers across Germany, France, Italy, Spain and every eurozone country delayed simultaneously. The transactions between banks that underpin the functioning of the eurozone economy stopped. Not a cyberattack. A single infrastructure component failing and cascading across every layer that depended on it.
  • Nordea, Sweden and Finland. Technical issues affecting consumers simultaneously across both countries. App, online banking, card payments and the Swish payment system all failing together. Each layer connected to the others. Each one taking the next one down.
  • Swedbank, Sweden. Both independent backup systems failed simultaneously during a routine update. The likelihood of both going down together was described as extremely small. The combined picture was never calculated. It happened anyway.
  • Danske Bank, Denmark, Finland, Norway and Sweden. Elevated error rates across all call types hitting all four countries simultaneously in a single incident. One shared infrastructure layer degrading across four national banking systems at once.
  • Nykredit and fifteen Danish banks. A shared infrastructure failure taking down fifteen institutions simultaneously. Not fifteen separate problems. One combined picture nobody measured until it had already cascaded.
  • CaixaBank, Spain. Repeated downtime affecting payment services across the country. Each incident logged separately. The pattern of degradation across layers never measured as a combined picture.
  • UniCredit, Italy, Germany and Austria. Repeated outages across multiple countries simultaneously. One banking group, multiple national layers, zero cross-border measurement of the combined operational picture.
  • BNP Paribas and Santander, Poland. Repeated system maintenance windows causing service disruptions across Polish banking infrastructure. Poland running simultaneous upgrade programmes across multiple institutions with no combined measurement of cumulative operational risk.
  • Julius Baer, Switzerland. Core banking systems down. Clients across Europe and the US unable to pay, trade or see their money.
  • DBS, Singapore. Failed so many times the CEO lost $3 million of his salary as a direct consequence.
  • Mastercard, global. A single outage affecting customers in 65 countries simultaneously including France, Italy, Japan, the US and Australia. One payment infrastructure layer failing cascading across every bank, merchant and consumer depending on it worldwide.
  • CrowdStrike, global. One bad software update. JPMorgan, Bank of America, Nomura, trading desks from Hong Kong to Dubai to South Africa, all dark simultaneously. One software layer failing cascading into everything else.

This is not isolated incidents. This is a continent-wide, global pattern. Every country. Every year. Multiple layers degrading together. No combined picture being measured. The window closing before anyone knew it was open.

OCF does both. It watches the layers degrading together, calculates the combined picture in real time, and tells you when the window starts closing before it closes. Not a warning that you are already in trouble. A number telling you how long you still have to act.

Every business that failed had a point of no return. Not a moment of obvious collapse. A threshold, crossed quietly, weeks or months earlier, where the window to act was still open and nobody knew it was closing.

Cash runway on one slide. Staff attrition on another. Customer churn somewhere else. Supplier payment terms quietly stretching. Each one manageable in isolation. Together they were a cascade nobody calculated. By the time the board called it a crisis, the window had already closed. What followed was not a turnaround. It was a controlled collapse at best.

OCF is the tool you use before that moment arrives.

It watches every layer of your business simultaneously. Cash position, supplier confidence, staff retention, customer behaviour, operational capacity. Not as separate metrics. As a connected system, where each layer affects the others. When cash tightens, suppliers notice. When suppliers notice, terms stretch. When terms stretch, production slows. When production slows, customers leave. Each step makes the next one worse. OCF tracks that propagation in real time and calculates a single index showing how close the combined picture is to the point where recovery stops being possible.

When the index starts moving you know something is forming. When it starts accelerating you know exactly how long you have left to act.

This is what no board currently has. Not a dashboard of fifteen metrics telling fifteen different stories. A single number showing the combined state of the business, updated in real time, with a time limit attached.

A business approaching the point of no return looks different from the outside than it does in the data. Publicly it is managing. Internally the layers are degrading together. OCF sees that before the board does, before the advisers do, before the bank does. It tells you the window is closing while there is still time to use the information.

The difference between a turnaround and a collapse is not resources, talent or strategy. It is whether anyone knew the window was closing before it closed. OCF tells you. Before it closes.

Rail does not fail because a signal goes red. It fails because a signal goes red while the backup communication channel is degraded, while the control room is managing three other incidents, while driver acknowledgement times are stretching, while traffic management is rerouting on incomplete information.

No single system shows critical. Each one is within tolerance. The combined picture crossed the threshold twenty minutes ago. Nobody measured the combined picture.

Across the EU and UK, rail disruption follows the same pattern every time. The initial fault is containable. What makes it unrecoverable is the simultaneous pressure on every layer around it. Contingency plans assume the other layers will hold. They do not.

  • Germany. 2024. Deutsche Bahn network disruptions cascaded across connections into Austria, the Netherlands and Belgium. A signalling issue became a timetable collapse became a passenger crisis across four countries. Each operator managed their own layer. Nobody measured the combined cross-border picture.
  • Spain. April 2025. The Iberian grid blackout took trains offline across the peninsula in minutes. Signalling failed. Communications failed. Passengers trapped in tunnels. The grid had surplus capacity four minutes before it had zero capacity. The intervention window was there. Nobody had an instrument that measured it.
  • UK. July 2025. A single signalling failure at London Waterloo rendered 14 platforms unusable simultaneously. Tens of thousands of commuters stranded. The cascade ran across the entire south London network. A 2024 Office of Rail and Road report had already recorded a 12% rise in signalling incidents. The pattern was visible. Nobody had measured how close the combined picture was to the threshold.

  • UK. May 2026. A GSM-R radio communication failure across southern England forced widespread cancellations on the busiest routes. Driver communications gone. Control room coordination degraded. Timetable collapsed across multiple operators simultaneously. A previous GSM-R failure in December 2024 had already shown the vulnerability. The signature was there both times. Nobody read it as a combined picture before it cascaded.

  • UK. July 2025. A single signalling failure at London Waterloo rendered 14 platforms simultaneously unusable. Tens of thousands of commuters stranded. The Office of Rail and Road had already recorded a 12% rise in signalling incidents the previous year. The pattern was in the data. Nobody measured the combined picture until it collapsed.
  • Germany. Ongoing. Deutsche Bahn’s GSM-R national radio communication network degraded progressively. Pure operational failure, no external cause. The system had no middle state between full operation and full stop. When the core dependency dropped, everything followed. Punctuality: 63%. Switzerland next door: 99%. The degradation trend was measurable long before the collapse.
  • Netherlands. Same GSM-R system, same Nokia supplier, same failure mode as Germany. The cascade did not respect borders. Two countries, one degrading infrastructure layer, zero cross-border measurement of the combined picture.
  • Denmark. November 2024. A faulty software update at TDC, Denmark’s largest telecom provider, knocked out mobile networks nationwide. Banedanmark’s digital signalling system in Jutland went down simultaneously. Trains halted. Emergency services disrupted. Two layers failing together from a single software event. The transition from analogue to digital signalling had created a dependency nobody had stress-tested at network scale.
  • Italy. October 2024. An electrical fault at Roma Termini split Italy in two. Around 500 trains cancelled, 70,000 minutes of delays from Milan to Naples. Emergency systems failed to contain the cascade. RFI was simultaneously running over 1,000 infrastructure renewal projects across the network. The combined pressure on the system was measurable. Nobody was measuring it.
  • Spain. April 2025. The Iberian grid blackout took trains offline across the peninsula within minutes. Two generation losses triggered a voltage surge the grid could not absorb. Surplus capacity four minutes before zero capacity. Trains stopped in tunnels. The intervention window existed. Nobody had an instrument that measured it closing.
  • Poland. March 2022, repeated pattern. A data coding flaw in Alstom’s traffic control system halted 80% of rail traffic across Poland simultaneously. The same fault appeared in India, Singapore and Pakistan at the same time. A single software dependency cascading across four countries. Poland was simultaneously carrying two million Ukrainian refugees on free rail tickets. The operational pressure across every layer was at maximum. Nobody had measured how close the combined picture was to the point of no recovery.
  • Poland. June 2025. A rear-end collision on the Pila-Bydgoszcz line exposed the absence of automatic train protection across Poland’s conventional network. Billions invested in high-speed corridors. The conventional network running without the safety systems that would catch degrading operational conditions before they become collisions.
  • Norway. 2024. Norske Tog reported a challenging year across the Norwegian network. The Oslo-Gothenburg corridor required extended maintenance closures. Ageing infrastructure under increasing demand with no real-time measurement of how close the combined operational picture was to the threshold.
  • Finland and the Baltics. The Rail Baltica project connecting Finland, Estonia, Latvia and Lithuania is the largest infrastructure project in European history. Four countries, four legacy networks, one new corridor, zero unified operational continuity measurement across the combined system. The point of no return on a cross-border cascade has never been calculated for this network.

This is not a collection of incidents. It is a continent-wide pattern. Every country. Every year. Multiple layers degrading together. No combined picture being measured. The window closing before anyone knew it was open.

OCF does not wait for the cascade. It watches every layer simultaneously, tracks how each one affects the others, and calculates how fast the combined picture is moving toward the threshold. When signalling latency starts creeping, when control room response times stretch, when communication redundancy quietly degrades, the individual readings look manageable. Together they are not. OCF sees that long before any single alarm fires and tells you how long you have left to act. By the time your instruments show critical, OCF has already told you it was coming.

Infrastructure under deliberate stress follows the same logic. A network being probed does not get hit once. Signalling interference here. Communication degradation there. Control room workload pushed to capacity. Each individually explainable. Together a signature that precedes the actual disruption by hours.

OCF reads that signature forming earlier than a human can foresee it. Not when the cascade is underway. Hours before. It watches every layer simultaneously, calculates how fast the combined picture is moving toward the threshold, and tells you the intervention window before it closes. Not after the network is on its knees. Before the cascade becomes the headline.

94% of European companies reported production stoppages due to supply shortages. Average downtime: 36 days. 52% of European enterprises reported raw material supply shortages. European Central Bank analysis shows supply bottlenecks reduced euro area industrial production by 2.6% cumulatively. This is not a bad year. This is a structural pattern of cascading failures that nobody is measuring as a combined picture.

Manufacturing does not only mean cars. It means pharmaceuticals, aerospace, electronics, food processing, energy equipment, defence components. Every sector running on just-in-time supply chains with no buffer, no tolerance for a single layer degrading, and no instrument measuring how close the combined picture is to the point of no return.

Examples:

  • Jaguar Land Rover. August 2025. A cyberattack stopped production across all UK plants simultaneously. Not one factory. All of them. The cascade ran from IT systems into operational systems into physical production lines into the entire supplier network across multiple tiers. Hundreds of businesses supplying JLR directly and indirectly under simultaneous financial pressure. Production restarted in phases. The combined picture had already passed the threshold before a single line visibly stopped.
  • Nexperia. October 2025. A single chip supplier interrupted delivery without warning. BMW, Volkswagen, Mercedes, Stellantis, Renault, Volvo and ten more manufacturers simultaneously facing production stoppages across Europe. Every layer of every supply chain degrading at once. No single operator measuring the combined picture across the network.
  • Volkswagen Autoeuropa, Portugal. A supplier in Slovenia stopped producing engine components. 5,000 workers at the Palmela plant suspended. One supplier. One component. One factory stopped. Three months earlier the same plant had already stopped for two days due to a different parts shortage. Two separate layer failures in three months. Nobody calculating how fast the combined operational picture was moving toward unrecoverable.

This is the pattern across every sector. Logistics lead times stretch. Supplier payment terms tighten. Production buffer stock erodes. Energy costs spike. Each layer degrading independently. Each one making the others worse. No single indicator showing critical. The combined picture crossing the threshold while fifteen separate dashboards all show amber.

OCF does not wait for the line to stop. It sees the cascade forming before any human can. When logistics start stretching, when supplier confidence starts dropping, when buffer stock starts thinning, the individual readings look manageable. Together they are not. OCF calculates the combined picture in real time and tells you the window is closing before any single indicator shows a problem. By the time your operations team sees it, OCF has already told you how long you had to act.

Ransomware attacks on law firms surged 60% between 2023 and 2024. 1,055 cyberattacks per week now target the legal industry. Attack timelines have compressed from 35 hours to 24 hours between 2024 and 2025. By the time a firm knows it is under attack, the window is already closing.

Examples:

  • UK Legal Aid Agency. May 2025. A cyberattack forced the agency offline. Hundreds of solicitors and barristers across England and Wales working for free or declining new cases. Court deadlines approaching. Client communications severed. Chain of custody for case files compromised. Filing systems offline. Each layer managed separately. Nobody measuring when the combined failure crossed the point where recovery was no longer possible within the time the courts required.
  • Allen and Overy, London. November 2023. LockBit ransomware hit one of the world’s largest law firms. Storage servers disabled. Client files across every practice area and jurisdiction at risk. The firm continued operating with disruption while containment was underway. The cascade ran from IT systems into client confidentiality into regulatory reporting obligations into transaction closing timelines simultaneously.
  • CMS Legal Services, Germany. August 2025. Ransomware group Crypto24 claimed responsibility for an attack on one of Europe’s largest law firms. Government and national infrastructure project files, sensitive corporate contracts, tax authority access records and internal financial documents all compromised. The operational cascade ran across every jurisdiction CMS operates in simultaneously.
  • German Federal Bar Association, Brussels. Ransomware hit the Brussels office of the body representing the German legal profession at European institutions. 160 gigabytes of data captured. The organisation representing lawyers at the EU’s own regulatory bodies operationally compromised.
  • DLA Piper. 2017, repeated pattern. The Petya ransomware attack entered through the Madrid office and cascaded across the entire global network simultaneously. Staff ordered to shut down computers and stop all email and phone communications. A global firm with offices across Europe, the US and Asia operationally paralysed from a single entry point.

A law firm under attack does not fail because one system goes down. It fails because filing systems, client communications, court deadline management, chain of custody and regulatory compliance degrade simultaneously. Each one has a different clock. Court deadlines do not pause for IT recovery. Limitation periods do not extend for ransomware remediation. A transaction closing process halted mid-execution can collapse a billion-pound deal and trigger malpractice liability in the same hour.

The window where a controlled response is still possible is measured in hours. Sometimes less.

OCF does not wait for the deadline to be missed. It sees the cascade forming before any human can. When filing system response times degrade, when client communication channels start failing, when case management access starts dropping, the individual readings look like an IT incident. Together they are a firm-ending cascade with a closing time limit. OCF calculates that limit in real time and tells you how long you have left to act before it closes.

Attacks do not begin with the attack. They begin with preparation. Infrastructure is probed. Systems are stressed. Communications are tested. Each event is logged separately as an anomaly. Nobody measures the combined picture.

ENISA analysed 4,875 cyber incidents across the EU between July 2024 and June 2025. State-aligned hacking groups sharply escalated operations against EU critical infrastructure throughout that period. Public administration was the most targeted sector. Transport second. Digital infrastructure third. Finance fourth. Manufacturing fifth. Every critical layer of European society simultaneously under persistent probing and pressure.

In August 2025, multiple EU member states reported falling victim to Salt Typhoon, a sprawling cyber espionage campaign attributed to China’s Ministry of State Security. Not one country. Multiple countries. Multiple layers. Simultaneously. The campaign had been running for months before it was understood as a coordinated operation rather than separate incidents.

UK. The National Cyber Security Centre handled more than 200 incidents affecting critical infrastructure in the year to May 2026. Three quarters attributed to hostile states. The NCSC chief warned directly that adversaries are prepositioning throughout British critical infrastructure and that kinetic targeting in any conflict tomorrow is based on intelligence gathered today. The reconnaissance is already underway. The preparation is visible in the data right now.

This is precisely what OCF was built to detect.

When network probing increases across multiple systems simultaneously, when authentication anomalies start appearing across different layers, when communications performance quietly degrades across separate organisations, the individual readings look like background noise. Logged separately. Treated as isolated incidents. Together they are a signature. The signature of preparation. The signature of an operation already underway even though the attack has not yet been launched.

ENISA itself has concluded that a disruption in one part of critical infrastructure can ripple across the entire supply chain. That ripple is measurable. That pattern is detectable before it becomes a disruption.

OCF watches every layer simultaneously, tracks how the degradation is propagating across them, and calculates when the combined picture crosses the threshold that precedes hostile action. Not after the first incident. Not after the pattern becomes obvious. Before the decision to act was ever made on the other side.

The warning is in the data your organisation is already collecting. OCF reads it as a combined picture before any human can.

  • A force in a contested environment detects degradation across navigation, communications and command layers simultaneously. Each platform logs it separately. Nobody correlates the pattern. OCF does. The intervention window is calculated before it closes. The warning is in the data already being collected.
  • Attacks do not begin with the attack. They begin with preparation. Infrastructure is probed. Signals are tested. Communications are stressed in sequence. Each event looks like an anomaly. Together they are a signature. OCF reads that signature across all layers simultaneously and moves the index before the first hostile action. The data your force already collects is enough. Nobody has been reading it as a combined picture. Until now.

    And no, its not C2, its something much simpler and faster to implement

Before you go

Efficiency gain by using AI

Join our community for insights on AI, leadership, and business strategy.