More capability, more dependency
As organisations become more dependent on external digital services, resilience becomes less about control and more about preparedness.
Few organisations today operate technology entirely within their own walls. Businesses have embraced cloud platforms, SaaS applications, managed services, specialist providers, and digital partnerships to reduce complexity, accelerate innovation, and gain access to capabilities that would be difficult or uneconomical to build independently.
In many respects, this evolution has been an enormous success. Digital ecosystems have helped organisations become more agile, more responsive, and more capable than ever before. Rather than building and operating every component themselves, they can draw on specialist expertise from across a broader digital supply chain.
But this success has also changed the nature of control, risk, and resilience.
Every new capability introduced through a platform, provider, or external service also creates a new dependency. As organisations expand what they can achieve through interconnected technologies, they also become increasingly reliant on components that sit beyond their direct control.
Resilience can no longer be tied to control alone
In an interconnected ecosystem, organisations cannot control every platform, provider, or external service on which they depend. Resilience increasingly relies on their ability to anticipate disruption, understand dependencies, and prepare an effective response.
and resilience
How dependencies create systemic risk
Because organisations are no longer affected solely by the systems they own and operate, they are increasingly exposed to events occurring elsewhere within the ecosystem of providers and services on which they depend.
Shared digital service
Multiple organisations rely on the same external platform, provider, or infrastructure.
Concentrated dependency
Critical capabilities become concentrated among a relatively small number of providers.
Provider disruption
An incident affects a service that sits beyond each organisation’s direct control.
Cross-sector impact
The disruption spreads simultaneously across otherwise unrelated organisations and sectors.
The result is an important change in the nature of digital risk. In an interconnected ecosystem, disruptions no longer remain confined to the organisation where they originate. The same ecosystem that enables growth and innovation also creates new paths through which disruption spreads.
The effect is amplified by the growing concentration of certain digital services. Many organisations now rely on a relatively small number of cloud platforms, identity providers, and AI services.
These shared dependencies create efficiency and scale, but they can also create common points of exposure.
Its effects are not confined to a single organisation. A disruption affecting one widely used service can impact multiple businesses simultaneously.
What characterises systemic risk is that its effects are not confined to a single organisation. A disruption affecting a widely used provider, platform, or external service can impact multiple businesses simultaneously, even if they operate in different sectors and have no direct relationship with one another.
Systemic dependencies across cloud and AI providers
Ryan Terpstra explores how provider concentration can increase the potential for disruption to propagate across multiple organisations at once.
Resilience beyond organisational boundaries
Resilience is no longer limited to the systems an organisation owns and operates. It increasingly depends on how well the organisation understands, anticipates, and responds to events across its wider digital ecosystem.
If risks are wider-reaching than any one organisation has control over, what does that mean for the nature of resilience?
From identifying who failed to assessing who was prepared
Provider responsibility
“Whose system failed?”
An outage affecting an external provider was primarily considered the provider’s problem. Responsibility was closely associated with ownership and direct control.
have shifted
Organisational preparedness
“Why wasn’t the organisation prepared?”
Customers, partners, and business stakeholders now focus less on where the disruption originated and more on how effectively the organisation managed its impact.
A decade ago, an outage affecting an external provider might have been viewed primarily as the provider’s problem. Today, customers, partners, and business stakeholders are more likely to focus on the impact.
The question is less likely to be “Whose system failed?” and more likely to be “Why wasn’t the organisation prepared for the disruption?”
This shift in expectations reflects a broader change in the nature of resilience. As organisations increase their reliance on external services, resilience has become less about controlling every component and more about understanding the dependencies that support critical services.
Preparedness depends on four connected capabilities
Understand dependencies
Identify the providers, platforms, APIs, and services that support critical business operations.
Anticipate disruption
Consider how failures outside direct control could affect services, users, and internal teams.
Absorb the impact
Maintain essential operations while limiting the consequences of a wider ecosystem disruption.
Continue operating
Preserve critical services and recover effectively, regardless of where the incident originated.
The origin of the disruption matters less than the ability to absorb its impact
Resilience is no longer defined solely by the reliability of individual systems. The question is not whether a disruption originated inside or outside the organisation, but how prepared the organisation was to absorb the impact and continue operating when it occurred.
Preparedness over control
Digital ecosystems have brought extraordinary gains in agility, innovation, and scale. But they have also changed the nature of resilience.
From owning every component to preparing for disruption
Resilience through control
Reliability was closely associated with the systems, infrastructure, and services an organisation directly owned and operated.
has evolved
Resilience through preparedness
Organisations must understand the wider ecosystem on which they rely and be prepared when an external component fails.
In an age of shared dependencies, resilience is no longer defined solely by what an organisation owns or operates. It increasingly depends on understanding the ecosystem on which it relies and being prepared when part of that ecosystem fails.
Organisations are increasingly judged not by whether a dependency failed, but by how effectively they anticipated, absorbed, and responded to the impact.
Modern digital services operate within interconnected ecosystems. Shared platforms, external services, providers, APIs, and complex digital supply chains all contribute to the delivery of critical services.
Four capabilities support resilience beyond direct control
Understand dependencies
Identify the external providers, platforms, services, and supply-chain components supporting critical operations.
Anticipate disruption
Consider how a failure outside direct control could affect services, users, and business outcomes.
Absorb the impact
Limit disruption and protect essential operations while the underlying incident is being resolved.
Maintain critical services
Continue delivering the services that customers, employees, and business stakeholders depend on.
Resilience depends on maintaining critical services when disruption occurs
As organisations continue to rely on shared platforms, external services, and complex digital supply chains, resilience becomes less about controlling every component and more about understanding dependencies, preparing for disruption, and continuing to operate when part of the ecosystem fails.