![[background image] image of a global map with pins (for a travel agency)](https://cdn.prod.website-files.com/6a791fd529932c5e2d7c9b68/6a7f58949c6b2072ecf64033_pexels-colwyn-davis-1763356180-33471680.jpg)
Think about what happened the last time your phone lost service for an hour. Not a disaster — an inconvenience. But notice what stopped working: your directions, your payments, your ability to reach anyone you know. Now extend that thought to the grocery store that restocks nightly from trucks it doesn't own, the pharmacy that carries three days of your medication, the bank balance that exists as an entry in a database you will never see. Modern life runs on systems we neither control nor understand, and we extend them a trust that none of them ever asked for or earned.
Here is the uncomfortable part: those systems were never designed. They accumulated. Every layer was added by someone solving the problem in front of them — cutting a cost, closing a warehouse, consolidating a supplier — with no architect and no plan. Each decision was rational. Their sum is a civilization of extraordinary capability and almost no slack.
We got a preview of what that means, and then we chose to forget it.
In 2020, the pandemic met a global logistics network that had spent decades perfecting just-in-time delivery. The system that could put anything on your doorstep in two days could not put flour on a shelf for two months. The companies that weathered it best were the unfashionable ones — the ones that had paid, year after year, for warehouses and backup suppliers that analysts called inefficient. The cost of redundancy shows up every quarter. The cost of its absence arrives all at once.
That same year, the SolarWinds breach showed the digital version of the story. Hackers didn't attack thousands of organizations individually; they compromised one piece of software that all of them shared and none of them had examined. And in early 2021, Texans burned furniture to stay warm while the state's power grid — lean, deregulated, optimized to the last decimal — buckled under a winter storm. The storm didn't create that fragility. It revealed fragility that decades of deferred investment had already built in.
Three failures, three domains, one pattern: the break never comes where the dashboard is watching. It comes through the dependency nobody priced.
The standard response to each of these episodes was a patch. Order a stockpile, issue a software fix, hold a hearing. The symptom gets treated; the structure that produced it stays intact, quietly generating the next one. What almost nobody does is the harder thing — going back to first principles and asking the questions that comfortable times let us skip. Where does this actually come from, and how many sources are there? What does this network depend on, and what happens when that dependency fails? Who would I call, and how, if the normal channels went quiet? The questions are almost childishly simple. The honest answers rarely are, and that discomfort is precisely the point.
Because here is the thing about resilience: it is not a product. You cannot buy it in a crisis, expense it in a quarter, or bolt it on after the fact. It is either present when the shock arrives or it is not.
I have spent more than three decades building things that had to survive conditions nobody promised would stay stable — a biotechnology company through multiple market cycles, a farm that produces real food at real scale, villages in rural Armenia rebuilt from post-Soviet collapse. The lesson from all of it is the same: building resilience means deliberately reversing some of the optimizations that created the exposure — and paying for the reversal. Two suppliers where one was cheaper. A mix of energy sources where a single one was simpler. People who know how to do more than one thing, in an economy that rewards knowing one thing extremely well. Every one of these choices trades measurable efficiency for unmeasurable protection, which is why spreadsheets hate them and why they will look wasteful right up until the moment they don't.
Technology can help, if it's pointed at the right target — analytics that surface stress before it becomes failure, tools that make a supply chain visible to the people who depend on it. But software layered onto a brittle structure just makes the brittleness faster. And communication, the least glamorous layer of all, is usually the one that decides the outcome. The organization that has written its crisis plan and trained its people responds in hours. The one that hasn't spends those hours finding out who's responsible for what. The difference isn't money. It's homework done in ordinary time.
There's a role for policy here — incentives for domestic capacity, real infrastructure investment, security standards with teeth — and it matters. But regulation has a habit of arriving after the failure it was written to prevent. Waiting for Washington to make your systems resilient is itself a form of fragility.
None of this requires believing that collapse is imminent. I wrote a book making the fuller argument, but this much requires only noticing what the past few years have put on the public record: the systems we depend on are more tightly coupled, more optimized, and more brittle than the people running them like to admit — and the fixes are the work of years, not weeks. Those years cannot be compressed once the stress arrives. The household, the company, the town that starts now is in a fundamentally different position from the one waiting for certainty.
The comfortable assumption is that someone, somewhere, is minding all of this. The evidence suggests otherwise. The systems will not repair themselves, and the next test is not going to schedule an appointment.
The work begins or it does not. That part, at least, is still ours to decide — and I would rather we decide it now.