Operational Resilience Playbook
Last Updated: 2026-07-17
This playbook turns operational resilience into practices you can start before the next policy shock lands. It is organized by where you are: getting started with exposure maps, a qualified bench, and response thresholds, building consistency as the machinery runs and learns, and reaching mastery where the discipline is codified, extended to services, and paying for itself. Every tip names a trigger, an action, and a way to tell it worked.
Common Pitfalls with Operational Resilience
- Risk registers that name categories like 'geopolitical risk' instead of policies and nodes. Nothing in them is testable, so the first real shock still arrives as a surprise with an invoice attached.
- Paper qualification. An alternative that has never carried live volume fails on activation day, when failure is most expensive, and a trigger with no named decision owner starts the debate the threshold was meant to end.
- Spending the first day of a disruption deciding who decides. It is the most expensive meeting in operations, and it recurs until authority is pre-assigned and the named people can state their limits.
Frequently Asked Questions
Where should a COO start building operational resilience?
Start with the stress tests. Map which policy instruments each critical input, lane, and site depends on, then quantify what each watch-list scenario costs in landed cost, lead time, and capacity. Every other move depends on that picture: the bench gets built against the ranked exposures, triggers reference the quantified thresholds, and the response room works from the same register. A first pass in a working session with sourcing and logistics leads beats waiting for perfect data.
How do you keep alternative suppliers ready without overspending?
Qualify against the ranked exposures rather than everywhere, and keep the bench honest with cheap discipline: scheduled re-checks that capacity is still available and terms still valid, and a one-time live-volume test per critical alternative, a pilot lot or a dual-run quarter, that surfaces problems while they are fixable. The expensive version of readiness is the one bought mid-crisis at spot prices from a counterparty who knows you have no choice.
How fast should a disruption response make decisions?
Hours from detection to committed action, and the way to get there is deciding the slow parts in advance. Written activation thresholds mean nobody debates whether to convene. A pre-assigned authority matrix means nobody discovers mid-event who can commit spend or switch sources. Sessions run to a strict shape, facts, options with numbers, decision, owner, next checkpoint, with time-to-decision logged and visible, so the speed itself is managed like any other metric.
How do you justify the resilience budget to the CFO?
With revenue evidence rather than fear. Track the deals that cited continuity commitments, the accounts retained through disruptions, and the share captured while competitors allocated by panic, and bring that record to every planning cycle. A resilience posture that customers pay for, through continuity service levels, allocation priority, and dual-sourced supply, defends itself. One framed purely as insurance shrinks every cycle the disruption does not come.
Unlock Skill Progression
Related Playbooks
CEO Geopolitical Risk Management Playbook
Practical CEO moves for geopolitical risk: build watch lists, run scenarios, strengthen resilience, decide markets, and engage policy early.
CEO Enterprise Risk Management Playbook
Practical CEO moves for enterprise risk: build the portfolio, set risk appetite, oversee exposure, and strengthen crisis response.
Execution Operating System Playbook
Turn strategy into daily behavior: one plan, one cadence, instrumented decisions, escalation discipline, and closed loops. Practices to run this quarter.