Resilience beyond business continuity
Why enterprises need to shift from static recovery plans to adaptive systems that connect operations, suppliers, people and critical dependencies.
Read articleHow many critical suppliers depend on the same thing?
Vendor count is not diversification. Two suppliers may depend on the same cloud region, software library, subcontractor, manufacturing plant, port, energy network or specialist workforce. Contractual separation can therefore conceal a single operational exposure.
Map the service, not just the legal entity. For every critical outcome, trace prime suppliers, material subcontractors, hosting locations, control planes, data routes, logistics nodes and ultimate ownership. Record which dependencies are substitutable, the time and data needed to switch, and whether capacity would still be available during an industry-wide event.
European financial regulation offers a useful operating signal. DORA became applicable in January 2025 and requires in-scope firms to maintain registers of ICT third-party arrangements; its EU oversight framework explicitly addresses systemic and concentration risk arising from reliance on a limited number of critical providers. The mapping principle extends well beyond finance.
Test correlated scenarios: one cloud identity failure, common cyber compromise, regional power loss, export restriction, transport closure or upstream insolvency. Ask suppliers for evidence rather than assurance, include audit and notification rights, and monitor changes in subcontracting. A nominal exit clause has little value if migration takes longer than the business can tolerate.
Prioritise exposures by consequence, substitutability and switching time. Reduce them through architectural portability, inventory, dual tooling, alternate routes or explicit acceptance backed by larger buffers. The objective is not eliminating concentration; it is seeing where independent-looking choices collapse onto the same point of failure.
Related macro
Articles
Why enterprises need to shift from static recovery plans to adaptive systems that connect operations, suppliers, people and critical dependencies.
Read articleHow companies can design for revenue and value continuity when shocks disrupt customers, channels, technology or supply.
Read articleFocus
A resilient system survives pressure. An adaptive one also uses what happened to change structures, decisions or behaviours before the next disruption.
Resilience begins by identifying the business outcomes whose interruption would create unacceptable consequences, not by declaring every process critical.
Strategic challenges
Operational exposure can originate with suppliers or infrastructure providers that have no direct contractual relationship with the business.
Changes in systems, suppliers, locations and responsibilities can quietly invalidate recovery assumptions long before the next formal review.
POV
When actions and claims diverge, more communication can amplify the credibility problem rather than contain it.
If every exercise ends successfully by design, the organisation learns more about the scenario than about its actual limits.
Strategic impact
Understanding how exposures interact is often more valuable than predicting which individual shock will occur next.
Revenue depends on interconnected marketing, channels, contracting, fulfilment and service capabilities that can fail at different points.
What we observe
We frequently see strong participant performance conceal structural weaknesses in capacity, architecture, dependencies or recovery design.
We frequently see named successors for senior roles while specialist operational knowledge remains concentrated and difficult to replace.