Most resilience initiatives start with a workshop and end with a heatmap: a wall of red, amber and green boxes that everyone nods at, and nobody acts on. That's useful for awareness. It rarely survives first contact with a budget conversation. The question that actually moves a resilience programme forward is not only “where are we exposed?” It is “how can we fix the exposure, and is fixing it worth the price?”
Risk stopped being a footnote
In the past few months alone, the Strait of Hormuz crisis cut deep into the world's fertiliser supply chain, a European drought split the Rhine in two and grounded inland shipping, and a fresh wave of export controls turned critical mineral supply chains into what the IEA called an “immediate economic risk.” None of that is a tail risk anymore. It's the operating environment.
We polled the audience during a recent webinar, and the picture matched what we see in client work: almost 40% of the participants said their companies understand their vulnerabilities but struggle to choose the right actions. A close second said they had mapped vulnerabilities but had a hard time prioritising between them. Few were stuck at “we know this matters but haven't started.” The bottleneck isn't awareness. It's turning awareness into a decision someone is willing to fund.
Three questions, in that order
In our experience, a resilience exercise that leads to action answers three questions.
-
Where are we exposed?
-
How critical is that exposure?
-
What should we do about it, and what is it worth?
Skip straight to solutions, and you end up funding whatever felt most urgent in the room. Answer the first two properly, and the third question — where to invest — largely answers itself.
Three steps that turn awareness into action.
1. Map: where are we exposed?
Start inside the company. Pull perspectives from procurement, planning, production, commercial, and sustainability. Each function helps answer the same question from a different angle: which suppliers, materials, or sites do we depend on, and how difficult would they be to replace?
Next, expand your view across the supply chain. Asking suppliers can help, but rarely goes far enough to build a true understanding of supply chain vulnerabilities. And you do not need traceability all the way to commodity level to identify them. Public information—such as trade statistics and sector reports—can provide a high-level view of key steps in your value chain, and where they are likely to take place.
Open-source risk databases can add another layer, by helping you identify vulnerabilities across your value chain that are linked to issues such as water stress, labour risks, or geopolitical chokepoints. Mapped onto the value chain, a Chinese fabric supplier stops being simply “a supplier in China” and becomes a set of specific risks (see figure below).
The result is a map you can act on—and a much better starting point for a supplier conversation than an audit request: “We are trying to understand the risks in our supply chain, and this is what we found. Do you recognise these risks? How are you trying to address them, and what can we do?”
Figure 1: Mapping supply chain vulnerabilities for Roosbeek Textiles, a fictitious company specialising in technical textiles and protective workwear.

2. Quantify: how critical is that exposure?
This is where most resilience efforts stall, because the obvious next question (How likely is this?) is usually very difficult to answer. Nobody can honestly estimate the probability of a specific disruption.
So don't start there. Start with Maximum Possible Loss: what would the impact of this event be like if it happened? Using bills of materials or routings, it is possible to calculate the revenues or margin that depend on each critical input. The result is a number that leadership can't wave away. One case from the webinar: a three-month disruption at a Chinese fabric supplier put €24m of one of our example companies’ annual sales at risk. That number, not a gut-feel risk score, is what makes the next conversation possible.
3. Decide: what should we do, and what is it worth?
Resilience measures behave like insurance: you pay a “small” premium to avoid a “big” potential loss. Rather than guessing whether that's worth it, calculate the probability at which it would break even and debate that instead.
In the same case, qualifying a European back-up supplier cost €1.4m more a year but cut the potential loss from €12.9m to €3.9m. Divide the premium by the €9.1m avoided, and the measure breaks even at a 15.4% annual chance of disruption — roughly once every seven years. Nobody can estimate the risk exactly, but any leadership team can debate whether a China–Europe disruption is more or less likely than the break-even probability. And thus evaluate if the investment is defensible.
Every exposure gets an owner
Run the three steps on your critical exposures, and each one ends up in one of two places: acted on now, with a plan, or moved to a watch list with a defined early-warning signal — a drought headline, a shipping-insurance premium spike, a new entity added to a forced labour prevention list. Choosing to monitor rather than act is a legitimate outcome. Not looking at all is not.
The organisations that build resilience aren't the ones with the most complete risk register. They're the ones that turn exposure into a value, and value into a decision. So: don't stop with the risk map. Continue until the euro figure — and build the case from there.
Rewatch the webinar
Recently we held a webinar on Supply Chain Resilience. Fill in the form to watch the recording.