Andrew Ticknor provides a useful point of reference for examining how seemingly efficient operations can develop hidden dependencies that become vulnerabilities when people, suppliers, systems, or processes suddenly become unavailable.
Efficiency is valuable. It can reduce waste, control costs, and help organizations make better use of limited resources. But efficiency without resilience can create fragility. The challenge for businesses is finding the point where streamlined operations still leave enough flexibility to respond when circumstances change.
What Is Operational Fragility?
Operational fragility occurs when a business becomes unusually dependent on a small number of resources or processes.
That dependence is not necessarily obvious. A company might have excellent procedures, modern software, and highly trained employees while still having a critical vulnerability.
For example, imagine that:
- One employee is the only person who understands an important process.
- One supplier provides a critical component.
- One software platform supports several essential functions.
- One approval is required before multiple teams can move forward.
- One location handles a disproportionate share of operations.
None of these arrangements is automatically problematic. The risk emerges when there is no practical alternative if that resource becomes unavailable.
Why Efficiency Can Create Fragility
Businesses naturally look for ways to eliminate unnecessary steps.
A process with fewer employees, fewer suppliers, fewer systems, and fewer approval stages may be faster and cheaper. But every reduction can also remove a layer of redundancy.
This creates an important distinction:
Efficiency asks how much resource is required under normal conditions.
Resilience asks what happens when normal conditions disappear.
A highly optimized system can perform extremely well until it encounters an unexpected disruption.
The objective is not to abandon efficiency. It is to understand what the business is giving up in exchange for it.
Single Points of Failure Deserve Attention
A single point of failure is a resource whose loss could significantly interrupt operations.
These points can exist almost anywhere.
A business might discover one in:
- Technology infrastructure
- Supplier relationships
- Employee knowledge
- Customer acquisition
- Financial processes
- Physical facilities
- Data access
- Management approvals
Some are easy to identify. Others are hidden inside ordinary workflows.
Consider an employee who handles a specialized process that nobody else has been trained to perform. That arrangement may seem efficient because responsibilities are clearly assigned. But if that employee becomes unavailable, the organization may suddenly discover that it has an operational dependency.
The same principle applies to technology and suppliers.
The Knowledge Problem
Employee expertise is an important business asset, but concentrated knowledge can become a vulnerability.
When only one person knows how to perform a critical task, the organization becomes dependent on that individual.
This does not mean every employee needs to know everything. That would be unrealistic and inefficient.
Instead, businesses can identify their most important processes and ensure that critical knowledge is not trapped with one person.
Practical measures can include:
- Documenting essential procedures
- Cross-training employees
- Maintaining accessible process information
- Creating backup responsibilities
- Periodically testing whether another employee can complete the task
The goal is continuity, not redundancy for its own sake.
Supplier Concentration Creates Another Risk
Supplier relationships can create similar dependencies.
Working with one supplier may provide advantages such as volume discounts, consistent quality, simpler administration, and established communication.
However, that relationship can become a vulnerability if the supplier experiences:
- Production problems
- Transportation disruptions
- Financial difficulties
- Capacity constraints
- Regulatory issues
- Unexpected price increases
Businesses do not necessarily need multiple suppliers for every purchase.
Instead, they should identify which inputs are genuinely critical and evaluate whether reasonable alternatives exist.
The appropriate level of diversification depends on the cost of disruption and the availability of alternatives.
Technology Can Hide Dependencies
Modern businesses increasingly depend on software and digital infrastructure.
Cloud platforms, payment systems, customer relationship management tools, communication systems, data storage, and automation can make operations significantly more efficient.
They can also create concentration risk.
When several business functions depend on the same technology provider, a technical problem can affect multiple parts of the organization simultaneously.
This makes technology mapping useful.
Businesses should understand:
- Which systems are mission-critical
- Which systems depend on other systems
- What happens if access is interrupted
- How data can be recovered
- Whether alternative processes exist
- How quickly operations could resume
The purpose is not to assume that every system will fail. It is to understand the consequences if one does.
Process Bottlenecks Can Be Just as Serious
Operational fragility is not limited to physical resources.
A process itself can become a bottleneck.
For example, if every significant decision requires approval from one person, that individual can become a constraint on the entire organization.
As the company grows, the problem can become more noticeable.
Employees may spend time waiting for approvals. Customers may experience delays. Managers may become overloaded with routine decisions that could have been handled elsewhere.
The business may technically have enough resources, but the way those resources are organized prevents them from being used effectively.
The Balance Between Control and Flexibility
Centralized control can provide consistency. It can also reduce the risk of unauthorized decisions.
But excessive centralization can make organizations slower to respond.
A resilient operating structure considers which decisions truly require senior approval and which can be delegated.
Clear decision boundaries can help employees understand:
- What they can decide independently
- When they need approval
- Which risks require escalation
- What information should be documented
This creates flexibility without eliminating accountability.
How to Find Hidden Dependencies
Businesses do not need a complicated consulting exercise to begin identifying operational vulnerabilities.
A simple review can start with one question:
What would stop working if this resource disappeared tomorrow?
From there, teams can examine their most important processes.
For each critical function, consider:
- Who performs it?
- Which technology supports it?
- Which suppliers are involved?
- What information is required?
- What approvals are needed?
- Is there a backup?
- How quickly could the function be restored?
The answers can reveal dependencies that are easy to overlook during normal operations.
Not Every Dependency Needs to Be Eliminated
This is an important point.
Trying to eliminate every operational dependency would be expensive and impractical.
Businesses make choices about where to concentrate resources because specialization can create real advantages.
The objective is to understand those choices and determine whether the resulting risk is acceptable.
A company might reasonably choose one technology provider because its capabilities justify the concentration. It might also decide that maintaining a backup process is worthwhile because the consequences of an outage would be severe.
Resilience is therefore about informed trade-offs.
Build Backup Capacity Where It Matters Most
Once critical dependencies are identified, businesses can prioritize them.
High-priority vulnerabilities typically have two characteristics:
The resource is difficult to replace.
Its loss would have significant consequences.
Those areas may deserve additional protection.
Depending on the situation, that could mean:
- Cross-training employees
- Establishing secondary suppliers
- Maintaining data backups
- Creating alternative workflows
- Documenting critical procedures
- Establishing emergency communication channels
- Developing contingency plans
The appropriate solution depends on the specific risk.
Resilience Should Be Tested, Not Assumed
Having a backup plan does not necessarily mean the organization is prepared.
A plan that exists only on paper may fail when people actually need to use it.
Testing can reveal practical problems.
A business might conduct a controlled exercise asking what would happen if a critical employee were unavailable, a major system became inaccessible, or a supplier could not deliver.
The purpose is not to create unnecessary disruption. It is to identify weaknesses while conditions are still manageable.
Testing turns assumptions into evidence.
The Goal Is Resilient Efficiency
Efficiency and resilience do not have to be opposing concepts.
The strongest operating models often combine both.
They remove unnecessary complexity while protecting the capabilities that matter most. They use specialization where it creates value while avoiding dangerous concentrations of knowledge or resources. They streamline processes while maintaining reasonable alternatives.
This creates a more useful definition of efficiency.
The goal is not simply to operate with fewer resources.
It is to use resources intelligently without creating vulnerabilities that become expensive when circumstances change.
Designing Operations That Can Absorb Change
Every business has dependencies. The important question is whether those dependencies are understood and whether their consequences are acceptable.
Operational resilience begins with visibility.
Once businesses understand where knowledge, technology, suppliers, decisions, and processes are concentrated, they can make deliberate choices about where additional flexibility is worthwhile.
That might mean adding redundancy in one area while keeping another highly streamlined.
The answer will differ from one organization to another.
What matters is building an operating structure that can continue functioning when conditions are less predictable than they were yesterday.
Efficiency helps a business perform under normal conditions. Resilience helps it remain capable when normal conditions no longer apply. The strongest organizations recognize that they need both.
