A supplier fails. A highway floods. A key employee resigns. A cyber attack locks the accounts system. A large order arrives that is twice the usual size. These are familiar risks, and most businesses could list them. Yet the event alone does not decide the outcome. One business has a second supplier already approved, cross-trained staff, files stored safely off site and three months of cash. Another has a single supplier, knowledge held in one person’s head, everything on one computer and three weeks of cash. The event is identical. The damage is not.
That difference is vulnerability. Risk describes what might happen in the world around the business. Vulnerability describes what inside the business allows an event to cause disproportionate harm. Risk lists tend to focus on the first: they record events, rate their likelihood and impact, and assign owners. They rarely ask why the business is fragile in the first place, and so they rarely lead to changes in how the business is built.
This article explains the difference between hazard, exposure, sensitivity and the capacity to adapt; where vulnerability usually hides; why success can expose weakness as quickly as failure; and why being able to see a risk clearly is not the same as being able to respond to it. It is general information; for specific hazards such as flood, fire or cyber incidents, your insurer, local council and government agencies publish guidance.
Four parts of the picture
A useful way to think about any disruption has four parts:
| Part | Question | Example: a heatwave |
|---|---|---|
| Hazard | What could happen? | Several days above 42 degrees |
| Exposure | What is in its path? | The cool room, the delivery van, staff in a hot workshop |
| Sensitivity | How badly does it suffer when exposed? | Cool room struggles above 40 degrees; work becomes unsafe without cooling |
| Adaptive capacity | What can the business do before, during and after? | Backup refrigeration, shift changes, cash to hire equipment, a customer who will accept a delay |
A severe hazard can do little damage where exposure is low or adaptive capacity is high. A moderate one can be serious where something critical is highly sensitive and there are few alternatives. The same lens works for floods, fires, power cuts, supply shocks, cyber incidents and the loss of key people.
Sensitivity often hides behind thresholds. Equipment works normally across a wide range, then fails sharply beyond a certain temperature or load. A supplier copes with short disruptions until its stock buffer runs out. Staff tolerate one hot day but not a week. Averages mislead; what matters is where behaviour changes suddenly.
Common misreadings
- Vulnerability is just another word for high risk. A rare event can be serious if the business is very fragile. A frequent disruption can be manageable if the business is resilient.
- The danger is all outside. Many weak points are internal design choices: single suppliers, concentrated knowledge, tightly linked processes, unrealistic schedules, inflexible contracts.
- Contingency money equals resilience. Money helps only if money can fix the failure. It cannot instantly produce a licence, a specialist skill or a replacement machine with a twelve-week lead time.
- Recording a risk deals with it. If a risk stays serious because the business is structurally fragile, the response is to change the structure, not to update the list.
Where vulnerability hides
At interfaces. Individually reliable parts can fail where they meet. A production line with good machines can still stop because one manual inspection has become a bottleneck, or because spares for one control component take months to arrive. A set of good software tools can fail because they share one login system or one fragile data link.
In people and decisions. Businesses often build redundancy into equipment while leaving human systems concentrated:
- only one person understands a critical system or customer;
- every decision waits for the owner;
- nobody else can approve a payment or sign a contract;
- supplier know-how has never been transferred to the business.
These do not cause immediate failure. They make otherwise manageable events dangerous.
Outside the fence. Resilience depends partly on the systems the business relies on: roads, power, water, internet, staff housing, emergency services, local suppliers. A workshop may stay dry in a flood while its staff cannot reach it and its supplier’s warehouse is under water.
In success. Unexpectedly high demand can expose weak points as quickly as failure. A website that crashes under a sudden rush, a product that develops quality problems because supply cannot scale, a service team that collapses under a backlog of new customers. Test whether the business can absorb good surprises as well as bad ones. The key person dependence article covers reducing reliance on individuals, one of the most common internal weak points.
A six-layer check
For each important risk on your list, ask a second question: what is it about our business that would make this event damaging? Then look across six layers:
| Layer | Question | Typical weak point |
|---|---|---|
| Strategy | What single assumption would remove the reason for a plan? | One forecast, one customer, one interpretation of a rule |
| Design | What part or link has no practical substitute? | Single point of failure, tightly linked processes |
| Supply | Which outside dependency is hard to replace? | Sole supplier, scarce material, proprietary support |
| People | Where is capability concentrated? | One person who knows how, no cross-training |
| Decisions | What cannot be decided quickly when conditions change? | Unclear authority, everything waiting for one person |
| Operations | What would stop recovery? | No spare capacity, weak maintenance, no fallback |
For each weak point, decide deliberately to remove it, reduce it, transfer part of it, add a backup, build recovery capability or consciously accept it. The response acts on the business itself, not just on the likelihood rating.
Seeing a risk is not coping with it
Research on project portfolios by Jonas Teller and Alexander Kock, published in 2013, separated two qualities of risk management: transparency, the ability to identify and understand risks, and coping capacity, the ability to prevent, absorb and respond to them. Both were associated with better results. They are different things, and one does not provide the other.
Many businesses are good at the first and weak at the second. Combining the two gives four positions:
| Position | Can we see it? | Can we respond? | What it means |
|---|---|---|---|
| Blind and fragile | No | No | Trouble arrives without warning and with few options |
| Visible but helpless | Yes | No | Good reporting, but no backup, money or authority to act |
| Capable but blind | No | Yes | Options exist but may be used too late |
| Adaptive | Yes | Yes | Problems seen early enough for responses to matter |
A quick exercise: for your ten most important risks, write two sentences each. “What do we know?” and “What can we actually do?” Any risk with a strong first answer and a weak second one is a gap in capability, not in information.
Coping capacity costs something: a second supplier, cross-training, spare stock, cash reserves, flexible contracts, files that can move between systems. These are often the first things removed when a business focuses on efficiency, leaving it leaner but more brittle. The question is not resilience versus efficiency, but how much resilience is justified given how concentrated, irreversible and serious the exposure is.
Recovery is not adaptation
After a disruption, recovery restores operations. Adaptation changes the conditions that made the business vulnerable. A business that only recovers may return, repeatedly, to the same fragile state. Equipment replacement, a lease renewal, a move or a new supplier contract are natural moments to adapt: resilience is cheaper to build in when something is already changing than to retrofit under pressure. The mitigation and adaptation article covers timing adaptation investments, particularly for climate-related hazards.
A worked example
This is an illustration. Two small engineering workshops in the same regional town both lose access to the main highway for five days after a flood. Both had “flood” on their risk lists.
Workshop A buys steel just in time, so it has two days of material on hand. Half its revenue comes from one mining services customer whose own site is also cut off. Only the owner can program the CNC machine, and the owner lives on the other side of the river. Job files are on a single office computer. Cash would cover about three weeks of costs. The five-day closure turns into nearly three weeks of disruption: no material, no programmer, a customer with no work to give, and a scramble for an overdraft extension.
Workshop B keeps two weeks of its most-used materials, has two staff who can program its machines, stores job files in a cloud service, and has a standing arrangement with a workshop in a neighbouring town to share capacity in emergencies. Its largest customer accounts for a quarter of revenue, and it holds about three months of costs in reserve. It loses five days of production and recovers within a week.
After the flood, Workshop A’s owner runs the six-layer check:
- Strategy: dependence on one customer. Response: actively develop two new customers, with a target that no customer exceeds 35% of revenue.
- Supply: just-in-time steel. Response: hold one week of the most-used sections, accepting the cost of the stock.
- People: only the owner can program. Response: train a second person over three months.
- Design: files on one computer. Response: move to a backed-up cloud service.
- Operations: no fallback capacity. Response: approach a workshop in another town about a reciprocal arrangement.
- Accept: the highway itself. The owner cannot change it and accepts that some closures will happen.
The flood was the same for both. The difference was built over years, in ordinary decisions about stock, customers, training and files.
How this applies to a small Australian business
- Ask “what makes this damaging?” beside each important risk.
- Look for single points of failure in suppliers, people, systems and decisions.
- Check thresholds: the temperature, load, stock level or cash level where things change suddenly.
- Map what you depend on outside the business: roads, power, internet, staff access, key suppliers.
- Test good surprises as well as bad ones.
- Write “what do we know” and “what can we do” for your top risks.
- Use natural change points, such as equipment replacement or lease renewal, to build resilience in.
- Check guidance from your insurer, local council and government agencies on hazards relevant to your location.
Signals worth watching
- One customer, supplier or person carrying a growing share of the business.
- Risks that are well described but have no response plan.
- Stock, cash or staffing buffers cut to the minimum in the name of efficiency.
- Recovering from the same kind of disruption more than once.
- Critical files, knowledge or approvals held by one person.
- Staff who would struggle to reach work in a local emergency.
Common mistakes
- Focusing on the event and ignoring the weakness that makes it damaging.
- Treating contingency money as resilience.
- Building redundancy into equipment but not people.
- Assuming the business is only as exposed as its own premises.
- Recovering without adapting.
- Confusing good reporting with readiness.
Frequently asked questions
Is this just business continuity planning? It overlaps. Continuity planning prepares a response to disruption. A vulnerability check looks for the weak points that make disruption damaging, so the business can change them before the event.
How much resilience is enough? Enough to survive the disruptions that could plausibly cross your survival line, at a cost the business can sustain. Concentrated, irreversible and serious exposures justify more.
What is the cheapest resilience? Often cross-training, backed-up files and a second approved supplier. They cost little compared with the damage they prevent.
Should we hold more stock? For critical items with long lead times or fragile supply, often yes. Compare the carrying cost with the cost of being unable to work.
How often should we review vulnerability? At least annually, and after any significant disruption, growth spurt or change in customers or suppliers.
Questions to ask
- For our top risks, what inside the business would make each one damaging?
- Where are our single points of failure in suppliers, people, systems and decisions?
- What outside systems do we depend on, and how fragile are they?
- Could we cope with a sudden doubling of demand?
- For each top risk, what do we know and what can we actually do?
- When did we last adapt, rather than simply recover?
Bringing it together
Risk is what might happen; vulnerability is what allows it to cause damage. Look at hazard, exposure, sensitivity and the capacity to adapt separately, and pay particular attention to thresholds, interfaces, concentrated people and the outside systems you rely on. Remember that success can expose weakness too. Seeing a risk clearly is valuable, but only coping capacity, built before the event, turns that knowledge into a response. Use ordinary decisions and natural change points to reduce single points of failure, and after each disruption, adapt rather than simply recover.
Source: KEVOS notes, drawing on teaching material on project feasibility and points of vulnerability, climate vulnerability (exposure, sensitivity and adaptive capacity), and J. Teller and A. Kock, “An empirical investigation on how portfolio risk management influences project portfolio success”, International Journal of Project Management (2013). Examples in this article are illustrations. This article is general information.