Minding the gap
Something I've observed consistently across more than 30 years in business continuity and resilience consulting:
Boards are getting better at asking about risk. They're not always getting better at understanding it.
There's a meaningful difference between a board that ticks the risk register at each meeting and one that genuinely understands the interdependencies that make a threat material — or not.
I see this most clearly now in two areas: climate risk and cyber security.
Both have become fixtures on board agendas. Both attract well-meaning attention and considerable reporting. But too often, the conversation stays at the surface — headline risks, regulatory obligations, general frameworks.
What's missing is operational depth. The board asks "are we exposed to cyber risk?" when the more important question is "do we understand our critical business processes well enough to know which systems, if disrupted, would genuinely threaten our viability?"
Resilience isn't a compliance outcome. It's a strategic capability. And boards that treat it as such — by investing in genuine understanding of how their organisation actually functions under stress — make qualitatively better decisions when it matters most.
The organisations that navigate crises well don't discover their gaps during the crisis. They've already mapped them.
How is your board approaching the gap between risk awareness and risk understanding?