top of page

Commentary

Breakfast Briefing Series | Part 2: From Resilience in Theory to Resilience in Practice

The second Chief Risk, Resilience, and Security Officers Breakfast Briefing, convened through the partnership between Toro Solutions and The Institute of Strategic Risk Management at the National Liberal Club, marked a clear shift in the conversation.

 

Where the first session explored the why of resilience—trust, uncertainty, and the changing nature of risk—this discussion moved decisively into the how. Not in abstract terms, but in the practical realities of what it takes to build, test, and sustain resilience in organisations operating under real-world complexity and consequence.

 

From the outset, there was a noticeable difference in tone. This was not a room focused on frameworks in isolation, but one grounded in experience—leaders dealing daily with disruption, interdependency, and the limitations of legacy approaches. The energy reflected that: less about defining the problem, more about confronting it.

 

Resilience is Built Through People, Not Systems

A consistent thread throughout the discussion was the centrality of people. Not as a supporting component of resilience—but as its defining feature.

 

In a threat landscape where physical, digital, and cognitive domains are increasingly fused, the traditional boundaries of risk are dissolving. Attackers are no longer simply targeting systems; they are targeting behaviours, decision-making, and trust. The idea that adversaries “hack the human before the machine” is no longer a metaphor—it is an operating reality.

 

This reframes the resilience challenge entirely. Investment in technology alone is insufficient. Organisations must instead prioritise:

  • judgement under pressure

  • behavioural awareness

  • leadership capability

 

Because in moments of crisis, it is people—not process—that determine outcomes.

 

From Siloed Risk to Converged Resilience

 

If the first briefing highlighted complexity, this session made clear that organisational structures have not kept pace with it.

 

Risk, security, resilience, and operational functions continue to operate in parallel, often with limited integration. Yet the threats they face are increasingly interconnected—blending cyber, physical, supply chain, and human vulnerabilities into single points of systemic exposure.

 

The implication is stark: siloed models are no longer just inefficient; they are a risk in themselves. What is required instead is convergence:

  • shared situational awareness

  • integrated decision-making

  • alignment across physical, digital, and human domains

 

This extends beyond the organisation. Supply chains and third-party dependencies—often optimised for efficiency—have become critical pressure points. The reframing of “third parties” as strategic delivery partners reflects a necessary shift in both accountability and mindset.

 

Stress Testing the System—To the Point of Discomfort

 

One of the most direct challenges put forward in the session was aimed at how organisations test resilience. Too often, exercises are designed to succeed.

 

They validate plans rather than expose their weaknesses. They reinforce confidence rather than challenge assumptions. The consensus in the room was clear: this model is no longer fit for purpose.

 

Resilience is built through stress testing that pushes systems—and people—to the point of failure in controlled environments. Through red teaming, scenario exercises, and immersive simulations, organisations can:

  • identify hidden vulnerabilities

  • test decision-making under pressure

  • build the muscle memory required for real incidents

 

Crucially, this requires a cultural shift. Failure in training must be seen not as a weakness, but as a necessary condition for learning. Because the alternative is far more costly: failure in reality.

 

Complexity, Interdependency, and the Limits of Control

A defining feature of the modern risk environment is not simply the presence of risk, but the nature of its connectivity.

 

Efforts to eliminate single points of failure have led to increasingly distributed and redundant systems. Yet in doing so, they have also created layers of hidden interdependency—relationships that are often poorly understood until they fail.

This creates a paradox.

 

The more resilient systems become in isolation, the more vulnerable they may be at the systemic level. Cascading failures, supply chain disruptions, and digital dependencies all point to the same conclusion: resilience cannot be managed purely within organisational boundaries. It must be understood as a property of systems.

 

For leadership, this introduces a new requirement—decision-making in conditions of uncertainty, with incomplete visibility, and often without the luxury of time.

 

Governance, Accountability, and the Shift to Outcomes

 

Alongside operational challenges, the session highlighted growing tension within governance models. Many existing frameworks remain process-heavy and compliance-driven, struggling to keep pace with the speed and complexity of change. In some cases, governance itself is becoming a constraint—slowing decision-making at the very moment agility is required.

 

At the same time, external pressures are increasing. Regulatory scrutiny, legal liability, and insurance considerations are all elevating the stakes of resilience failure.

The direction of travel is clear:

  • from process to outcomes

  • from documentation to demonstrable capability

  • from static frameworks to adaptive systems

 

This demands clarity—not just in policy, but in roles, responsibilities, and decision authority. Because in crisis conditions, ambiguity is itself a risk.

 

From Efficiency to Preparedness

For decades, organisational design—particularly in supply chains—has prioritised efficiency. Lean systems, cost optimisation, and just-in-time models have delivered significant gains. But they have also reduced tolerance for disruption.

 

This session reinforced a growing recognition: efficiency and resilience are not always aligned. Building resilience requires:

  • redundancy

  • flexibility

  • investment in preparedness

 

And, critically, a willingness to confront the cost of inaction.

Because the question is no longer “can we afford to invest in resilience?” but “what is the cost if we don’t?”

 

Building a Culture That Can Withstand Pressure

Underlying every theme discussed was the role of culture.

Resilience cannot be imposed through frameworks alone. It must be embedded through:

  • trust

  • transparency

  • shared understanding

 

Leaders must create environments where:

 

  • challenge is encouraged

  • failure is used as a learning tool

  • decision-making is enabled at the right levels

 

This includes moving away from rigid hierarchies toward more decentralised, mission-oriented approaches—where individuals are equipped and empowered to act under pressure. In this sense, resilience is as much about mindset as it is about capability.

 

Closing Reflection: From Conversation to Capability

 

If the first Breakfast Briefing established the importance of resilience in a world defined by uncertainty, this second session made something else clear:

 

Understanding resilience is not enough—organisations must now operationalise it and incorporate it into their core business operation, not just as a part of business continuity or layered emergency management.

 

This involves advancing from frameworks to practical application,

from plans to actual performance,

from discussion to disciplined action.

 

What emerged from the session was not a singular solution, but a shared path forward—one rooted in experience, influenced by complexity, and driven by the realities of implementation.

 

This, perhaps, is the defining strength of this community. Not only are they discussing resilience, but they are actively working to build it.

 
 
 

Comments


bottom of page