A modern company runs on one silent assumption. The connection will be there. It almost always is. That word, almost, is where the risk lives, and no one has ever put a number on it. The day the line cuts, signing a document, releasing a payment, reaching a colleague, opening a file, all of it stops at the same moment. The outage is only the symptom. The real exposure is that no one on the org chart holds a written mandate to define what must remain possible when the line is gone.

Two cities, one symptom

In Libreville, the line dropped without warning. A video call froze mid-sentence. A file refused to upload. You relaunch, you switch to the phone, you make do. The work slows to the speed of the weakest link, and the weakest link is invisible.

Back in France, the same symptom in a different costume. A throttled connection, throughput collapsing at the wrong hours, a working day that stalls out of nowhere. Two settings with nothing in common. One shared result.

The outage passes fast. What it exposes stays. Everything I had to handle that day hung on a single thing. The line. Not the laptop, not the team, not the plan. The line. When it went, competence and goodwill counted for nothing. The company was present and unable to act.

That is the paradox. We have never been more capable and never more fragile at the same point. The capability is real. The fragility sits under it, unmeasured, until one bad hour makes it visible.

The four dependencies no one audits while things work

When a business is running well, leaders watch revenue, margin, pipeline. They rarely watch the four things that decide whether the company survives a bad day. These four wake up only during the outage, and by then it is too late to map them.

The line itself comes first. One carrier, no redundancy, no 4G or 5G failover ready to take over. The day it drops, you discover there was no fallback. You discover it at the same moment your customers do.

Authentication comes second. A single identity provider, one centralized multi-factor system, an administrator password living inside a third party you do not control. If that provider closes, errs, or gets breached, your teams no longer get in anywhere. Neither do you.

Data comes third. Three questions decide whether you own it or merely rent the illusion of owning it. Where does it actually live. Who can hand it back to you. How long would that take. If the answer is not clear in one sentence, the data is not under your control. You are holding it elsewhere, on trust.

The critical partner comes fourth. The cloud provider, the host, the box sitting at the edge of your network. Usually one actor, on whom the continuity of everything else depends. None of these four is expensive to map. Each is very expensive the day you did not.

The decision no one ever made

Ask a leadership team when they decided to give up the ability to work offline. You will get puzzled looks. No one decided it. There was never a meeting, never a vote, never a line in the minutes.

The messaging moved to the cloud. A sound call. Then the ERP. Sound too. Then the CRM, the accounting, the electronic signature, the document storage. Each brick a good decision, taken at the right time, for the right reasons. Ten reasonable choices, laid end to end, produce a company that cannot run for one hour without the internet.

The dependency was never chosen. It accumulated. That is what makes it so hard to see. There is no single culprit, no obvious mistake to point at. Every step made sense on its own. The exposure lives in the sum, and no one is responsible for the sum.

This matters because you cannot fix by accident what you built by accident. The accumulation has to be made visible on purpose, listed, named, and put in front of someone with the authority to act on it.

Resilience is a name before it is a value

In most companies, resilience is a value. It appears in the charter, in the all-hands deck, in the risk section of the board pack. It belongs to everyone, which means it belongs to no one.

Look at how the responsibilities actually split. The CIO owns the technology. The CFO owns financial risk. The COO owns execution. Each holds a column and holds it seriously. Global resilience does not sit inside any one of those columns. It lives between them. And what lives between functions has no owner by default.

As long as no name is written against the word, resilience stays an intention. A good one, shared and sincere. An intention does not restart a system at three in the morning. A mandate does. A mandate names a person. It gives that person the right to block, to arbitrate, to spend, to say no to a decision that weakens the whole while helping one part.

The difference between a company that absorbs an outage and one that is flattened by it is decided long before the outage itself. It is decided on the day a leader writes a name against the word resilience. Everything else is hope, and hope holds only as long as the line holds.

What a leader does before the line cuts

None of this calls for a six-month program or a frightening budget. It calls for three moves, in order.

Start with an inventory. List the dependencies one by one. Where the data lives, who holds the keys, which contracts have no exit, which single supplier could stop everything. Most of this can be written down in a few working sessions. The list is almost always longer than expected, and the surprise itself is useful.

Then set a priority. You do not fix everything at once. You start where the pain would be worst and where the fix is fastest. Those two are not always in the same place, which is exactly where an outside eye earns its keep.

Then assign the mandate. One person, named, with the authority to carry the subject across functions and the right to contradict a decision that creates a trap. Not to slow the company down. To make sure the company keeps a door it can walk through.

The line will cut one day. That is arithmetic, not pessimism. The only real choice is whether someone was made responsible, in advance and in writing, for what remains possible when it does. A company that made that choice barely notices the bad hour. A company that did not spends it discovering, live, everything it never priced.

FAQ

What are the four dependencies most companies never audit until an outage forces them to?

The internet connection itself (usually a single carrier with no 4G/5G failover), authentication (one identity provider or MFA system that locks everyone out if it fails), data (whether you can actually get it back, from whom, and how fast), and the critical partner — the cloud provider or host that everything else quietly depends on. None is expensive to map in advance; each is very expensive the day nobody did.

Who should own business continuity risk inside a company?

Nobody, by default — which is the problem. Resilience usually lives in the charter and the board deck as a shared value, but the CIO owns technology, the CFO owns financial risk, and the COO owns execution, while global resilience sits in the gap between those columns. It only becomes real the day one named person is given the mandate and the authority to block or arbitrate decisions that weaken the whole — not just the intention to care about it.