Close Menu
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
More items
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
X (Twitter) LinkedIn
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
Login
LinkedIn Bluesky
Resilience Forward
Subscribe Now
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
Resilience Forward
You are at:Home»Managing resilience»Supply chain resilience»Supply chain resilience is about managing persistent uncertainty – and needs active governance (Page 19)
Supply chain resilience

Supply chain resilience is about managing persistent uncertainty – and needs active governance

For a long time, supply chains were treated mainly as a commercial issue. Cost, speed, and efficiency came first. COVID changed the picture. Now geopolitical issues are changing the focus again. Gavin Wilson explains.
March 12, 20267 Mins Read
Aerial top down photo of industrial container ship loading .

Organizations now operate in a world where disruption is normal rather than exceptional. Political instability, regulation, market concentration, and environmental shocks increasingly shape supply decisions. These pressures are not temporary and they are rarely within the control of any single organization. 

As a result, supply chains must be treated as risk systems in their own right, as they have become a core part of organizational resilience. 

A different risk landscape 

The way supply chains behave is changing. Geopolitical tensions were already reshaping trade, even before the current issues created by the US and Israel attacks on Iran. The latter shows how routes and energy supplies can be quickly disrupted and that access to critical materials can change almost overnight.

More widely, sanctions and export controls are now common tools, often introduced with little warning and unclear knock-on effects. In some sectors, national security has become just as important as cost or technical capability when choosing suppliers. 

At the same time, many supply chains are more concentrated than they appear. Entire industries depend on a small number of countries or firms for key components and services. These dependencies are often hidden. At a surface level, organizations may think they are diversified, only to discover that when something breaks several of their suppliers rely on the same upstream source or region. 

Climate disruption adds further pressure. Extreme weather is damaging infrastructure, cutting production, and increasing volatility in agriculture, transport, and energy. These impacts are uneven, hard to forecast and are rarely limited to a single location. 

The above problems escalate when these risks combine. Political decisions trigger regulatory shocks, climate events spill into economic crises, and high concentration means that local failures can quickly spread. The result is a level of systemic fragility that most supply chains were never built to handle. 

Supply chain failure impacts

The consequences of supply chain disruption now extend far beyond missed delivery dates.  

Revenue impact is often the most immediate effect, particularly where unmet demand pushes customers towards competitors seen as more reliable. In regulated sectors, this is frequently compounded by contractual penalties or supervisory attention, especially where disruption affects critical services. 

Operationally, disruption increasingly leads to production shutdowns. In highly integrated environments, the loss of a single component or upstream dependency can bring entire operations to a halt. These failures are rarely purely technical; more often they reflect structural fragility created by concentrated sourcing, limited redundancy, and poor visibility beyond immediate suppliers. 

Cost pressures follow quickly. Emergency sourcing usually means weaker negotiating power, higher freight and substitution costs, and lower assurance standards. Margins erode quickly and decisions made under pressure often introduce new and unexpected risks that persist long after the original disruption has passed. 

Regulatory exposure is also increasing. Supervisors are paying closer attention to third-party risk, operational resilience, and data sovereignty.  

Reputational damage tends to last longest. Organizations that appear unprepared or slow to respond often lose trust with customers, partners, and investors, even when the original cause sits outside their control. 

In many sectors, this combination of commercial, operational, regulatory, and reputational impact has meant that supply chain failure has become a genuine threat to organizational viability. Which is where two key and inter-related areas come in: resilience and governance.

Resilience in practical terms 

Resilience is often discussed in abstract terms but in practice, when it comes to supply chains, it is largely about information and governance. 

It starts with understanding who suppliers are, what they depend on, and where real points of fragility exist. This requires visibility beyond Tier 1 and a willingness to examine dependencies that sit several layers down. 

Due diligence also needs to go beyond financial health. Cyber security, regulatory exposure, ownership structures, political risk, and operational maturity all shape real-world resilience.  

For many organizations, scenario planning only becomes meaningful once it is grounded in real-world disruption. Walking supply chains through plausible geopolitical, regulatory, or environmental shocks quickly reveals where dependencies sit and which decisions would need to be taken under pressure. Those insights are far more valuable when they shape procurement and investment choices in advance, rather than during an incident. 

Initial due diligence is only the starting point. Supplier risk changes as organizations change. Ownership shifts, new vulnerabilities appear, and controls weaken or strengthen. 

Organizations that handle this well treat supply chain risk as part of day-to-day governance and their overall security strategy. 

The limits of efficiency-led design 

Many existing supply chains were built for stability. They assume predictable markets, reliable transport, and relatively low political or environmental interference. That design logic still dominates procurement decisions in many organizations. Cost and performance remain the primary selection criteria. Resilience is often considered only after disruption occurs. 

The problem is not that efficiency is wrong, but that it is incomplete. Systems optimised for minimal redundancy and maximum throughput tend to perform poorly under stress. When disruption occurs, options are limited and expensive. 

Organizations that perform better under pressure usually share a few characteristics. They have clearer visibility into their dependencies. They maintain more active relationships with key suppliers. They involve risk, security, and compliance functions earlier in procurement decisions and they accept some degree of redundancy where the cost of failure is high. 

None of this eliminates disruption, but it does reduce the likelihood that disruption turns into a crisis the organization cannot absorb. 

Supply chains as governance issues 

One of the reasons supply chain risk persists is structural rather than technical. In most organizations, responsibility for suppliers still sits largely within procurement and commercial teams. Their incentives are cost control, performance, and continuity of service. Risk, resilience, and security considerations tend to sit elsewhere, often consulted late or only after something has gone wrong. 

This separation creates predictable blind spots. Commercial decisions shape exposure long before risk teams are involved, and by the time dependencies are properly understood, contracts are already in place and options are limited. The organization may technically ‘own’ third-party risk, but in practice has little ability to influence it. 

Where resilience is handled more effectively, the difference is less about tools and more about how decisions are made. Risk, security, and compliance functions are involved earlier in supplier selection, rather than being asked to review arrangements that are already agreed. Senior leaders have clearer sight of where dependencies are concentrated and which relationships would be difficult to replace, not just how suppliers are performing commercially. 

The practical effect is not the elimination of disruption. It is that when disruption occurs, it is better understood, managed more deliberately, and less likely to escalate into something that threatens the wider organization. 

A different way of thinking

In today’s ecosystem, supply chain resilience is about managing persistent uncertainty. 

Organizations that continue to treat supply chains as purely commercial systems are likely to remain exposed to shocks they cannot influence and dependencies they do not fully understand. 

Those that approach supply chains as risk systems tend to have better governance, clearer accountability, and more credible business continuity planning. 

In practice, the distinction is simple. Some organizations wait for disruption and then react. Others assume that disruption is inevitable and design accordingly. 

The author

Gavin Wilson, Director of Physical Security & Risk, Toro Solutions

Africa Asia Asia Pacific Australasia Europe Middle East North America UK
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email WhatsApp
Previous ArticleResearch reveals ‘stark AI visibility’ gap across organizations globally
Next Article Ransomware hits the headlines but phishing attacks have the biggest total impact

Related Posts

An exploding digital padlock illustrates the requirement for post-quantum cryptography.

Research breakthrough brings reliable quantum computers and Q-day closer to reality

September 10, 2026
A danger sign on a digital background.

New blob URL phishing technique evades detection by using legitimate Microsoft services

September 10, 2026
AI risks

Unmanaged AI workflows expose EMEA organizations to rising compliance and data risks

September 9, 2026
City skyline at sunset with bright light trails and a translucent blue smart-city grid overlay and GPS pins indicating locations.

AI world models: future possibilities for organizational resilience?

September 7, 2026
DRJ and BCI logos

DRJ and BCI publish guidance for governing, managing, and using AI in resilience

September 7, 2026
Decision making with over whelming information.

AI can find the vulnerability. Accountability still sits with your crisis leadership

September 7, 2026
Advertisement
Resilience First
This week's most read articles
Under pressure: An egg cracking under pressure applied by squeezing clamps form the sides.

Managing scenario testing for operational resilience

May 16, 2024
COSO logo

New COSO ERM guidance aims to help organizations with practical implementation

May 12, 2026
Close-up of a green-brown iris peering through a jagged tear in dark paper or wall material.

The blind spots in business continuity

September 2, 2026
Latest resources
A hand places a wooden block onto a stack of blocks forming a circular process symbol with gears and arrows, representing the building of resilient, iterative IT systems and operational foundations.

Why most IT environments aren’t ready for agentic AI – and what CIOs can do about it

December 18, 2025
Load More

Subscribe to Updates

Get our Resilience Updates newsletter.

Most Popular Feature Articles
Three dark coloured light bulbs on a black background illustrate the concept of The Dark Triad in Crisis Management.

The Dark Triad in crisis management

Five stage crisis management framework

A five stage framework for a crisis management process

Blue interconnected gears and network nodes symbolizing automation and complex machinery.

Agent zero – the 2028 digital pandemic

Latest Reports
A futuristic red warning alert icon with glowing exclamation mark.

Cloud Security Alliance publishes Hugging Face Incident Initial Post-Mortem

A person hold a building door open for a person behind who is tailgating to get unauthorised access.

Security Culture: A Strategic Capability That Builds Resilience in a Volatile World

An identity icon with a map marker on it, indicating the concept of identity as a target for attackers. The icon is on a generic IT background predominantly in black and orange.

Identity-based approaches dominate initial access for ransomware attacks

A promo box for an article about resilience governance.
© 2026 Resilience Forward
  • About Resilience Forward
  • Newsletter
  • Newsfeed
  • Advertise
  • Call for Papers
  • Contact
  • Privacy Policy and Cookie Use
  • AI Use Policy

Type above and press Enter to search. Press Esc to cancel.

Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Ad Blocker Enabled!
Ad Blocker Enabled!
Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.

Sign In or Register

Welcome Back!

Login to your account below.

Lost password?