Why resilience plans fail when it matters
Most organisations discover their resilience gaps during a disruption, which is the most expensive possible time to find out. The patterns behind plans that look solid and collapse anyway.
Operational resilience is easy to claim and hard to prove. After years of working with organisations before, during and after real disruptions, the failures we see are rarely exotic. They are the same handful of weaknesses, present in documentation that looked perfectly convincing right up until the moment it was needed.
The plan was never tested under pressure
A plan that has only ever been read is an untested hypothesis. Tabletop walkthroughs in a comfortable meeting room tell you the document is coherent, not that your people can execute it at speed with incomplete information. Until you have run realistic crisis exercises with time pressure and difficult injects, you simply do not know how the plan performs.
Critical knowledge lives in one person's head
If your response depends on a specific individual being available, contactable and on form, you have a single point of failure with a name on it. Resilient organisations document decision logic, cross-train deputies for every critical role and test what happens when the obvious person is on a plane.
Nobody agreed the priorities in advance
Ask five senior people which services the organisation could least afford to lose, and for how long, and watch how quickly the answers diverge. In a real disruption that disagreement does not disappear, it just happens live, in public, while resources flow to whoever shouts loudest. Agreeing important business services and their tolerances in advance is unglamorous work that pays for itself the first time it is needed.
Third parties were a blind spot
Your resilience is only as strong as your least resilient critical supplier. Organisations routinely discover, mid-incident, that they cannot say how a key provider would handle its own disruption or what they would do while it recovered. If that dependency has never been examined, it is an unquantified risk sitting in the middle of your operations.
Lessons went into a document, not into the organisation
The clearest predictor of the next failure is the last incident review whose actions were never implemented. A debrief that produces a report rather than change guarantees that the next incident will look remarkably like the last one. Closing that loop, with named owners and deadlines, is where resilience actually gets built.
Building the capability properly
Genuine resilience is a learnable discipline with established frameworks behind it. The Certified Operational Resilience Manager (CORM®) gives individuals the methods to do it properly through distance learning, and our operational resilience consulting helps organisations embed the capability across their operations rather than in a binder.
Related services
More insights
Keep reading.
Related thinking from the Oakwood team.
Operational resilience: what 'beyond March 2025' actually looks like
The FCA's transitional period has closed. The interesting question now isn't whether you're compliant — it's whether the framework you built is doing any real work.
Supply chain resilience: five lessons from a disruptive 2025
From Red Sea disruption to concentrated cloud outages, last year was an unusually clean test of how resilient your suppliers really are. The results were not flattering.
Why most business continuity plans fail under pressure
The plan is rarely the problem. The problem is the gap between the document and the organisation's ability to operate it.
