Resilience beyond business continuity
Why enterprises need to shift from static recovery plans to adaptive systems that connect operations, suppliers, people and critical dependencies.
Read articleWho knows something the business cannot afford to lose?
Critical knowledge is rarely identical to seniority or job title. It often lives with the person who understands an exception, maintains a trusted relationship, recognises a weak signal or knows why a process was designed around a constraint that documentation no longer mentions.
Map knowledge through outcomes. For each essential decision or service, ask what must be known, who can apply it unaided, how long replacement would take and what happens if it is unavailable. Prioritise knowledge that is both critical and vulnerable�a principle made explicit in the 2026 draft revision of ISO 30401.
Observe work under variation. Interviews capture stated procedure; incident reviews, complex cases and handovers reveal tacit judgement. Record not only steps, but cues, trade-offs, contacts, source authority and stop conditions. A runbook that omits rationale lets a successor repeat actions without knowing when they are wrong.
Reduce dependency through pairing, shadowing, rotation, communities of practice, decision logs and deliberate succession. Give another qualified person real responsibility while the expert is available to correct the system. Protect external knowledge held by contractors and suppliers with access, continuity and transfer provisions.
Test resilience by removing the key person from an exercise and measuring decision delay, errors and escalation. Track single-qualified roles, time to competence, stale documentation and coverage of critical cases. The goal is not to copy everything one individual knows; it is to make the organisation capable of acting when that individual cannot be reached.
Related macro
Articles
Why enterprises need to shift from static recovery plans to adaptive systems that connect operations, suppliers, people and critical dependencies.
Read articleHow realistic disruption simulations can expose hidden dependencies and reveal where resilience investment creates the greatest strategic value.
Read articleFocus
Reputational resilience begins with understanding which expectations matter enough that violating them could materially change trust or behaviour.
A resilient system survives pressure. An adaptive one also uses what happened to change structures, decisions or behaviours before the next disruption.
Strategic challenges
Distributed technology can still depend on common regions, identities, control planes, providers or services that create systemic failure points.
Scenarios that stay comfortably inside expected conditions may validate familiarity while revealing little about actual resilience limits.
POV
Sales can return while customer trust, market position or recurring economics remain permanently weaker after prolonged disruption.
If recovery is treated as a separate phase that starts after response ends, critical restoration decisions are usually made too late.
Strategic impact
Distributing essential capabilities across more than one person or team gives the organisation credible alternatives when normal capacity disappears.
Understanding how exposures interact is often more valuable than predicting which individual shock will occur next.
What we observe
We frequently see exercises confirm that a plan exists without testing whether teams can coordinate decisions and execute recovery under disruption.
We frequently see documented procedures built around assumptions about availability, dependencies and recovery times that exercises have never validated.