Risk is not vulnerability: what turns a disruption into damage, and how to build the capacity to cope

Two businesses can face the same flood, supplier failure or surge in demand and fare very differently. How to find the weak points inside your business, and why seeing a risk is not coping.

A supplier fails. A highway floods. A key employee resigns. A cyber attack locks the accounts system. A large order arrives that is twice the usual size. These are familiar risks, and most businesses could list them. Yet the event alone does not decide the outcome. One business has a second supplier already approved, cross-trained staff, files stored safely off site and three months of cash. Another has a single supplier, knowledge held in one person’s head, everything on one computer and three weeks of cash. The event is identical. The damage is not.

That difference is vulnerability. Risk describes what might happen in the world around the business. Vulnerability describes what inside the business allows an event to cause disproportionate harm. Risk lists tend to focus on the first: they record events, rate their likelihood and impact, and assign owners. They rarely ask why the business is fragile in the first place, and so they rarely lead to changes in how the business is built.

This article explains the difference between hazard, exposure, sensitivity and the capacity to adapt; where vulnerability usually hides; why success can expose weakness as quickly as failure; and why being able to see a risk clearly is not the same as being able to respond to it. It is general information; for specific hazards such as flood, fire or cyber incidents, your insurer, local council and government agencies publish guidance.

Four parts of the picture

A useful way to think about any disruption has four parts:

PartQuestionExample: a heatwave
HazardWhat could happen?Several days above 42 degrees
ExposureWhat is in its path?The cool room, the delivery van, staff in a hot workshop
SensitivityHow badly does it suffer when exposed?Cool room struggles above 40 degrees; work becomes unsafe without cooling
Adaptive capacityWhat can the business do before, during and after?Backup refrigeration, shift changes, cash to hire equipment, a customer who will accept a delay

A severe hazard can do little damage where exposure is low or adaptive capacity is high. A moderate one can be serious where something critical is highly sensitive and there are few alternatives. The same lens works for floods, fires, power cuts, supply shocks, cyber incidents and the loss of key people.

Sensitivity often hides behind thresholds. Equipment works normally across a wide range, then fails sharply beyond a certain temperature or load. A supplier copes with short disruptions until its stock buffer runs out. Staff tolerate one hot day but not a week. Averages mislead; what matters is where behaviour changes suddenly.

Common misreadings

  • Vulnerability is just another word for high risk. A rare event can be serious if the business is very fragile. A frequent disruption can be manageable if the business is resilient.
  • The danger is all outside. Many weak points are internal design choices: single suppliers, concentrated knowledge, tightly linked processes, unrealistic schedules, inflexible contracts.
  • Contingency money equals resilience. Money helps only if money can fix the failure. It cannot instantly produce a licence, a specialist skill or a replacement machine with a twelve-week lead time.
  • Recording a risk deals with it. If a risk stays serious because the business is structurally fragile, the response is to change the structure, not to update the list.

Where vulnerability hides

At interfaces. Individually reliable parts can fail where they meet. A production line with good machines can still stop because one manual inspection has become a bottleneck, or because spares for one control component take months to arrive. A set of good software tools can fail because they share one login system or one fragile data link.

In people and decisions. Businesses often build redundancy into equipment while leaving human systems concentrated:

  • only one person understands a critical system or customer;
  • every decision waits for the owner;
  • nobody else can approve a payment or sign a contract;
  • supplier know-how has never been transferred to the business.

These do not cause immediate failure. They make otherwise manageable events dangerous.

Outside the fence. Resilience depends partly on the systems the business relies on: roads, power, water, internet, staff housing, emergency services, local suppliers. A workshop may stay dry in a flood while its staff cannot reach it and its supplier’s warehouse is under water.

In success. Unexpectedly high demand can expose weak points as quickly as failure. A website that crashes under a sudden rush, a product that develops quality problems because supply cannot scale, a service team that collapses under a backlog of new customers. Test whether the business can absorb good surprises as well as bad ones. The key person dependence article covers reducing reliance on individuals, one of the most common internal weak points.

A six-layer check

For each important risk on your list, ask a second question: what is it about our business that would make this event damaging? Then look across six layers:

LayerQuestionTypical weak point
StrategyWhat single assumption would remove the reason for a plan?One forecast, one customer, one interpretation of a rule
DesignWhat part or link has no practical substitute?Single point of failure, tightly linked processes
SupplyWhich outside dependency is hard to replace?Sole supplier, scarce material, proprietary support
PeopleWhere is capability concentrated?One person who knows how, no cross-training
DecisionsWhat cannot be decided quickly when conditions change?Unclear authority, everything waiting for one person
OperationsWhat would stop recovery?No spare capacity, weak maintenance, no fallback

For each weak point, decide deliberately to remove it, reduce it, transfer part of it, add a backup, build recovery capability or consciously accept it. The response acts on the business itself, not just on the likelihood rating.

Seeing a risk is not coping with it

Research on project portfolios by Jonas Teller and Alexander Kock, published in 2013, separated two qualities of risk management: transparency, the ability to identify and understand risks, and coping capacity, the ability to prevent, absorb and respond to them. Both were associated with better results. They are different things, and one does not provide the other.

Many businesses are good at the first and weak at the second. Combining the two gives four positions:

PositionCan we see it?Can we respond?What it means
Blind and fragileNoNoTrouble arrives without warning and with few options
Visible but helplessYesNoGood reporting, but no backup, money or authority to act
Capable but blindNoYesOptions exist but may be used too late
AdaptiveYesYesProblems seen early enough for responses to matter

A quick exercise: for your ten most important risks, write two sentences each. “What do we know?” and “What can we actually do?” Any risk with a strong first answer and a weak second one is a gap in capability, not in information.

Coping capacity costs something: a second supplier, cross-training, spare stock, cash reserves, flexible contracts, files that can move between systems. These are often the first things removed when a business focuses on efficiency, leaving it leaner but more brittle. The question is not resilience versus efficiency, but how much resilience is justified given how concentrated, irreversible and serious the exposure is.

Recovery is not adaptation

After a disruption, recovery restores operations. Adaptation changes the conditions that made the business vulnerable. A business that only recovers may return, repeatedly, to the same fragile state. Equipment replacement, a lease renewal, a move or a new supplier contract are natural moments to adapt: resilience is cheaper to build in when something is already changing than to retrofit under pressure. The mitigation and adaptation article covers timing adaptation investments, particularly for climate-related hazards.

A worked example

This is an illustration. Two small engineering workshops in the same regional town both lose access to the main highway for five days after a flood. Both had “flood” on their risk lists.

Workshop A buys steel just in time, so it has two days of material on hand. Half its revenue comes from one mining services customer whose own site is also cut off. Only the owner can program the CNC machine, and the owner lives on the other side of the river. Job files are on a single office computer. Cash would cover about three weeks of costs. The five-day closure turns into nearly three weeks of disruption: no material, no programmer, a customer with no work to give, and a scramble for an overdraft extension.

Workshop B keeps two weeks of its most-used materials, has two staff who can program its machines, stores job files in a cloud service, and has a standing arrangement with a workshop in a neighbouring town to share capacity in emergencies. Its largest customer accounts for a quarter of revenue, and it holds about three months of costs in reserve. It loses five days of production and recovers within a week.

After the flood, Workshop A’s owner runs the six-layer check:

  • Strategy: dependence on one customer. Response: actively develop two new customers, with a target that no customer exceeds 35% of revenue.
  • Supply: just-in-time steel. Response: hold one week of the most-used sections, accepting the cost of the stock.
  • People: only the owner can program. Response: train a second person over three months.
  • Design: files on one computer. Response: move to a backed-up cloud service.
  • Operations: no fallback capacity. Response: approach a workshop in another town about a reciprocal arrangement.
  • Accept: the highway itself. The owner cannot change it and accepts that some closures will happen.

The flood was the same for both. The difference was built over years, in ordinary decisions about stock, customers, training and files.

How this applies to a small Australian business

  • Ask “what makes this damaging?” beside each important risk.
  • Look for single points of failure in suppliers, people, systems and decisions.
  • Check thresholds: the temperature, load, stock level or cash level where things change suddenly.
  • Map what you depend on outside the business: roads, power, internet, staff access, key suppliers.
  • Test good surprises as well as bad ones.
  • Write “what do we know” and “what can we do” for your top risks.
  • Use natural change points, such as equipment replacement or lease renewal, to build resilience in.
  • Check guidance from your insurer, local council and government agencies on hazards relevant to your location.

Signals worth watching

  • One customer, supplier or person carrying a growing share of the business.
  • Risks that are well described but have no response plan.
  • Stock, cash or staffing buffers cut to the minimum in the name of efficiency.
  • Recovering from the same kind of disruption more than once.
  • Critical files, knowledge or approvals held by one person.
  • Staff who would struggle to reach work in a local emergency.

Common mistakes

  • Focusing on the event and ignoring the weakness that makes it damaging.
  • Treating contingency money as resilience.
  • Building redundancy into equipment but not people.
  • Assuming the business is only as exposed as its own premises.
  • Recovering without adapting.
  • Confusing good reporting with readiness.

Frequently asked questions

Is this just business continuity planning? It overlaps. Continuity planning prepares a response to disruption. A vulnerability check looks for the weak points that make disruption damaging, so the business can change them before the event.

How much resilience is enough? Enough to survive the disruptions that could plausibly cross your survival line, at a cost the business can sustain. Concentrated, irreversible and serious exposures justify more.

What is the cheapest resilience? Often cross-training, backed-up files and a second approved supplier. They cost little compared with the damage they prevent.

Should we hold more stock? For critical items with long lead times or fragile supply, often yes. Compare the carrying cost with the cost of being unable to work.

How often should we review vulnerability? At least annually, and after any significant disruption, growth spurt or change in customers or suppliers.

Questions to ask

  • For our top risks, what inside the business would make each one damaging?
  • Where are our single points of failure in suppliers, people, systems and decisions?
  • What outside systems do we depend on, and how fragile are they?
  • Could we cope with a sudden doubling of demand?
  • For each top risk, what do we know and what can we actually do?
  • When did we last adapt, rather than simply recover?

Bringing it together

Risk is what might happen; vulnerability is what allows it to cause damage. Look at hazard, exposure, sensitivity and the capacity to adapt separately, and pay particular attention to thresholds, interfaces, concentrated people and the outside systems you rely on. Remember that success can expose weakness too. Seeing a risk clearly is valuable, but only coping capacity, built before the event, turns that knowledge into a response. Use ordinary decisions and natural change points to reduce single points of failure, and after each disruption, adapt rather than simply recover.


Source: KEVOS notes, drawing on teaching material on project feasibility and points of vulnerability, climate vulnerability (exposure, sensitivity and adaptive capacity), and J. Teller and A. Kock, “An empirical investigation on how portfolio risk management influences project portfolio success”, International Journal of Project Management (2013). Examples in this article are illustrations. This article is general information.

Need practical engineering, manufacturing or process support? KEVOS can help move the work forward.