Close Menu
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
More items
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
X (Twitter) LinkedIn
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
Login
LinkedIn Bluesky
Resilience Forward
Subscribe Now
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
Resilience Forward
You are at:Home»Managing resilience»Organizational resilience»Why robustness isn’t resilience (Page 22)
Organizational resilience

Why robustness isn’t resilience

It is easy to conflate robustness with resilience. David Honour explains why this is a mistake and why the ability to adapt is central to true resilience.
April 9, 20268 Mins Read
A paper swan turns into a flying bird which turns into a plane.

When organizations first start to consider managing their resilience, one of the first responses is often to consider how to make existing systems more robust – hardening them to try to prevent issues occurring and to protect them from attacks.

If we take an example that will be recognisable to any organization, the response to cyber attacks was to protect systems through security controls. As attacks became more frequent and more sophisticated over the years, additional layers of security were added. But successful attacks continued, with impacts escalating.

This was a robustness-led approach and, in hindsight, we can see that on its own it has clear limits. The adage that successful cyber attacks are not a matter of if but of when reflects this.

Another example comes from supply chains. For decades, the drive for efficiency has dominated management theory. Organizations have pruned ‘waste’, eliminated redundancy, and optimised every link in the supply chain for speed and cost.

A supply chain optimised for robustness might rely on a single, high-quality, high-volume vendor to ensure efficiency, consistency, and lower costs. This works perfectly – until it doesn’t. When that single point of failure is hit, the efficient system lacks the internal slack or the external resources to pivot. It is robust until the tipping point, when, suddenly, it is not.

Robustness is not resilience

Robustness is about resistance. A robust system is designed to withstand shocks without changing its form. It assumes that the world can be held at bay through strength, consistency, and control. Resilience, by contrast, is based on adaptation. A resilient system accepts that conditions will change, often in unpredictable ways, and focuses on the ability to adjust, reconfigure, and sometimes transform in response.

As the above examples show, the danger arises when organizations mistake robustness for resilience. Hardening systems may delay failure, but eventually even the most robust barrier reaches a breaking point. If the organization has not prepared for that moment, it may be left unable to adapt. This leaves the organization in a ‘brittle’ state: strong up to a tipping point, and fractured afterwards.

While robustness is about resisting the storm, resilience is about knowing when to let the storm change your organization – before it reaches a point of collapse. Despite the popular image, resilience is not about bouncing back – instead, it is adapting forward. It is the capacity of a system to absorb external and internal pressures and to reorganize in response, so as to retain its essential function and identity – or, where necessary, to transform.

Robustness and Ragnarök

This dynamic is captured with surprising clarity in the Norse myth of Ragnarök. Often misunderstood as a story of violent world-ending apocalypse, Ragnarök is better read as a myth of systemic decline. The gods of the Aesir do not fall because they are evil or incompetent. They fall because the world they preside over has changed and they are unable to adapt their roles, relationships, or assumptions. Knowing their fate, they double down on what has worked before: force, hierarchy, and heroic certainty.

This is the Red Queen effect: a situation in which a system must run faster and faster just to maintain its current position. The gods spend their final days in a frantic effort to preserve the status quo, exhausting their resources and their social capital in a desperate attempt to remain unchanged. Their robustness is their undoing. They mistake strength for viability, and in doing so, they ensure that when the end comes, it is total.

For organizations, Ragnarök is not always a moment of dramatic failure but a process: rising control costs, shrinking trust, slower decision cycles, and increasing reliance on authority rather than sense-making. The lesson is not that systems should avoid strength or structure, but that adaptation must be actively practised long before it is urgently needed.

Resilient organizations build adaptation as muscle memory. It is both an aspect of organizational culture and a capability that must be planned and exercised. Adaptive organizations create space for local experimentation and difference, tolerate ambiguity, and allow parts of the system to change, or even fail, without threatening the whole.

In a world of accelerating complexity, resilience is not about always standing firm or returning to a predefined business as usual state. True resilience is about knowing when to let go, when to reconfigure, and when to transform.

Popular concepts such as ‘bouncing back’ or ‘bending not breaking’ move beyond pure robustness by introducing the idea of flexibility, but they are still focused on maintaining the status quo.

The ability to adapt is fundamental, and any protective discipline that fails to include that capability is not, in any meaningful sense, resilience. And Ragnarök reminds us why – because systems that cannot adapt do not just fail – they exhaust themselves trying not to.

Resilience governance: practical actions for boards

If resilience is understood as the capacity to adapt rather than merely to resist, then boards and board-level executives have a critical role in shaping the conditions under which adaptation can occur. The following actions focus less on control mechanisms and more on governance for learning, flexibility, and transformation.

Actively distinguish robustness from resilience in governance discussions

Boards should explicitly test whether proposed controls are increasing resilience or merely hardening the system. This means asking:

  • Are we investing in the ability to change, or only in the ability to defend?
  • Which risks are we trying to absorb, and which require adaptation or transformation?
  • Where might additional controls be increasing brittleness rather than reducing exposure?

Every time a new control, policy, or process is proposed, the board should ask: ‘Is this making us more resilient, or just more robust?’ If the answer is ‘robust’, the follow-up question should be: ‘What is the cost of this hardening?’ Leaders must recognise that every new layer of control typically reduces the system’s ability to pivot.

Monitor early signals of brittleness, not just failure

Traditional assurance focuses on whether controls are working. Resilience governance also pays attention to stress signals, such as:

  • Increasing decision latency
  • Escalation of issues that were previously handled locally
  • Declining psychological safety or challenge
  • Growing reliance on exceptions, workarounds, or informal fixes
  • Narrative rigidity (‘This is who we are’ or ‘This is how we do things’)

These are often precursors to a Ragnarök moment, long before formal performance indicators deteriorate.

Decentralise sense-making, not accountability

Adaptation depends on local intelligence. Boards and executives should encourage:

  • Decision-making authority at the edges where complexity is felt first
  • Cross-functional forums for interpreting emerging risks and opportunities
  • Multiple perspectives on what is changing, rather than reliance on a single ‘authoritative’ view

This does not remove accountability. It relocates sense-making closer to reality, while senior leaders retain responsibility for coherence and direction.

Create safe-to-fail spaces for experimentation

Resilient organizations practise and rehearse adaptation before it becomes existential. This means:

  • Supporting small-scale experiments that explore alternative ways of operating
  • Accepting partial failure as a learning cost, not a performance defect
  • Avoiding the instinct to standardise successful experiments too quickly

Boards can support this by explicitly protecting learning initiatives from short-term performance pressures.

Treat identity as adaptable, not sacred

One of the strongest predictors of collapse is identity rigidity. Boards should periodically ask:

  • Which assumptions about ‘who we are’ may no longer serve us?
  • Which parts of our operating model are non-negotiable, and which are habits?
  • What would adaptation require us to let go of?

Resilient organizations preserve purpose while allowing form to change.

Reframe leadership from control to conditions

In quickly changing environments, leadership effectiveness shifts:

  • From decision-maker to environment-shaper
  • From certainty provider to uncertainty holder
  • From enforcing alignment to enabling coherence

Boards should support executives in making this shift, recognising that adaptive leadership often looks less decisive in the short term but is more viable in the long term.

An adaptive leader can still make viable decisions when the old ground rules no longer work and there is no clear direction of travel.

Regularly ask the ‘Ragnarök question’

Finally, boards should institutionalise one uncomfortable but vital question:

If our current model stopped working tomorrow, what would prevent us from adapting?

The answer often reveals whether resilience is genuinely embedded – or whether the organization is relying on robustness and hardening strategies that will eventually exhaust themselves.

Try running a pre-mortem exercise. Instead of a post-mortem after a failure, the board imagines the company has already collapsed and works backwards to find the cause and the related resilience lessons.

In summary

Robustness can buy time, but only adaptation buys survival. Ragnarök is not a failure of leadership; it is the consequence of mistaking strength for viability. Boards and executives who recognise this early can guide their organizations through transformation, rather than preside over the collapse that eventually follows when rigidity rules.

Resilience, in the end, is not about standing firm. It is about knowing when and how to change.

The tragedy of the Aesir in Norse mythology was not that they died, but that they exhausted themselves trying to stay exactly as they were. In the myth, Ragnarök is followed by rebirth. Out of the old world, a new one emerges – more viable because it is no longer bound by the rigidities that destroyed the last.

The author

David Honour is editor of Resilience Forward.

Africa Asia Asia Pacific Australasia Europe Middle East North America UK
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email WhatsApp
Previous ArticleNew RIMS Executive Report looks at enterprise risk management reporting to the board
Next Article Four European tech companies unveil Europe’s first fully sovereign disaster recovery solution

Related Posts

An exploding digital padlock illustrates the requirement for post-quantum cryptography.

Research breakthrough brings reliable quantum computers and Q-day closer to reality

September 10, 2026
A danger sign on a digital background.

New blob URL phishing technique evades detection by using legitimate Microsoft services

September 10, 2026
AI risks

Unmanaged AI workflows expose EMEA organizations to rising compliance and data risks

September 9, 2026
City skyline at sunset with bright light trails and a translucent blue smart-city grid overlay and GPS pins indicating locations.

AI world models: future possibilities for organizational resilience?

September 7, 2026
DRJ and BCI logos

DRJ and BCI publish guidance for governing, managing, and using AI in resilience

September 7, 2026
Decision making with over whelming information.

AI can find the vulnerability. Accountability still sits with your crisis leadership

September 7, 2026
Advertisement
Resilience First
This week's most read articles
Under pressure: An egg cracking under pressure applied by squeezing clamps form the sides.

Managing scenario testing for operational resilience

May 16, 2024
COSO logo

New COSO ERM guidance aims to help organizations with practical implementation

May 12, 2026
Close-up of a green-brown iris peering through a jagged tear in dark paper or wall material.

The blind spots in business continuity

September 2, 2026
Latest resources
A hand holds a glowing blue shield containing the letters AI.

Governance resources: AI in the Workplace Governance Policy Template

November 25, 2025
Load More

Subscribe to Updates

Get our Resilience Updates newsletter.

Most Popular Feature Articles
Three dark coloured light bulbs on a black background illustrate the concept of The Dark Triad in Crisis Management.

The Dark Triad in crisis management

Five stage crisis management framework

A five stage framework for a crisis management process

Blue interconnected gears and network nodes symbolizing automation and complex machinery.

Agent zero – the 2028 digital pandemic

Latest Reports
A futuristic red warning alert icon with glowing exclamation mark.

Cloud Security Alliance publishes Hugging Face Incident Initial Post-Mortem

A person hold a building door open for a person behind who is tailgating to get unauthorised access.

Security Culture: A Strategic Capability That Builds Resilience in a Volatile World

An identity icon with a map marker on it, indicating the concept of identity as a target for attackers. The icon is on a generic IT background predominantly in black and orange.

Identity-based approaches dominate initial access for ransomware attacks

A promo box for an article about resilience governance.
© 2026 Resilience Forward
  • About Resilience Forward
  • Newsletter
  • Newsfeed
  • Advertise
  • Call for Papers
  • Contact
  • Privacy Policy and Cookie Use
  • AI Use Policy

Type above and press Enter to search. Press Esc to cancel.

Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Ad Blocker Enabled!
Ad Blocker Enabled!
Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.

Sign In or Register

Welcome Back!

Login to your account below.

Lost password?