Anubhav Sachar
Skip to content
Navigate
HomeAboutAll InsightsContact
Insights — eight domains
Artificial Intelligence12 topicsGeopolitics5 topicsDigital Economies5 topicsInnovation & Technology5 topicsLeadership & Strategy5 topicsMy Journey3 topicsFuture Horizons3 topicsGlobal Business Strategies6 topics
Ventures
World AcceleratorVisit site Global Development 50Visit site
Connect for partnerships
Strategic Resilience

Strategic Resilience: Designing for the Shock You Did Not Model

Resilient systems share a small number of structural properties. Those properties can be specified, funded and audited — which makes resilience a design choice, not a temperament.

Beyond scenario planning

Most resilience work is scenario-based: identify plausible disruptions, plan responses, rehearse. This is useful and fundamentally limited, because the disruptions that cause serious damage are usually the ones not on the list.

The alternative is to build systems that degrade gracefully under stress of any kind. This shifts the question from what might happen to how the system behaves when something does — which is answerable in advance without knowing the cause.

Four properties

Resilient systems tend to share four structural features, each specifiable and auditable.

Modularity: failure in one component does not propagate. Tight coupling is efficient and transmits shocks; loose coupling costs margin and contains them.

Substitutability: critical inputs have qualified alternatives that are actually tested. A second supplier who has never fulfilled an order is not a second supplier.

Buffers: inventory, capacity or financial reserve absorbing variation. Two decades of optimisation removed most buffers on the correct observation that they are expensive, and on the incorrect assumption that the variation they absorbed had disappeared.

Observability: the system reveals its own state early enough to act. Many failures are not sudden; they are slow and unobserved until they become sudden.

Why organisations under-invest

The economics are genuinely adverse. Resilience costs are certain, immediate and attributable. Resilience benefits are uncertain, deferred and invisible — a crisis that did not occur generates no evidence.

The manager who cuts buffers is rewarded for efficiency; the successor who experiences the resulting failure is blamed for it. Any organisation with meaningful role rotation will systematically under-provide resilience unless the incentive is corrected deliberately.

The correction is to measure resilience as a maintained capability rather than as an outcome — audit the four properties, report them, and hold current management accountable for their state rather than for the absence of crises.

Where the balance sits

Resilience is not free and maximum resilience is not the goal. The right level is a judgement about the cost of failure, and it differs by system: a payment network and a stationery supply chain should not receive the same treatment.

What is not defensible is arriving at the level by accident, through a series of local efficiency decisions that nobody aggregated. Most organisations that discovered they had no slack did not decide to have none. They simply never asked what the accumulated decisions added up to.