Outside any one business
These shocks affect an entire region, industry, or economy at once, prevention isn't the point, response is.
Volume 10, Chapter 5
External risks don't create new weaknesses, they expose the ones that were always there. General resilience prepares for the category, even when the specific event can't be predicted.
A pandemic, political instability, or a cyberattack campaign happens regardless of what any single business does. General resilience, reserves, documented systems, more than one supplier, prepares for the category, not the specific event.
These shocks affect an entire region, industry, or economy at once, prevention isn't the point, response is.
A resilient business survives not by predicting the crisis, but by already having reserves, systems, and diversification.
A second-approval rule stopped a phishing transfer cold, before any expensive lesson was needed.
One supplier, one region, or one channel turns any external disruption into a direct hit.
Imagine a phishing email (a scam message pretending to be someone the business trusts) lands in a shared inbox, nearly tricking a staff member into transferring funds to a fraudulent account. Nothing about that attempt was preventable by the business, someone somewhere decided to target them, and no policy could have stopped the email from arriving. What stopped the money from actually leaving was a boring internal rule: any payment above a set amount needs a second person's approval first. The attack itself was outside anyone's control. Whether it succeeded was not.
are large-scale shocks that originate completely outside the business and outside any individual customer or employee, affecting an entire region, industry, or economy at once. They are the hardest risks to prevent and the most important to prepare responses for.
Nothing in this chapter can be stopped by the business alone. A pandemic, political instability, or a cyberattack campaign happens regardless of what any single business does. What the business can control is how ready it is to adapt: could it operate with restricted movement? Could it survive a supply disruption? Could it recover from a digital breach?
Threatens in-person operations, supply chains, customer demand.
Defend: flexibilityThreatens supply chains, currency, physical safety, regulation.
Defend: diversifyThreatens digital systems, customer data, financial accounts.
Defend: security basics| Risk | What It Threatens | Primary Defense |
|---|---|---|
| Pandemic / public health crisis | In-person operations, supply chains, customer demand | Remote/flexible operating capability, emergency fund |
| Political instability | Supply chains, currency, physical safety, regulation | Using more than one supplier, reserves, not depending too much on one region |
| Cyberattack | Digital systems, customer data, financial accounts | Volume 20: Technology & Cybersecurity, backups, strong passwords |
A genuine external shock rarely arrives alone, it tends to test every defense built elsewhere in this manual simultaneously: the emergency fund (can the business survive without normal revenue for months?), documented systems (can work continue if key people can't be physically present?), and supplier diversification (is there a backup if one source disappears?).
External risks don't create new weaknesses, they expose the ones that were always there. A business with real systems, reserves, and diversified suppliers survives an external shock not because it predicted the specific crisis, but because it was already resilient in general.
Here's the full version of the phishing story from the start of this chapter.
A phishing attempt targeting MANIAC MINDZ's shared email account nearly succeeded in tricking a staff member into transferring funds to a fraudulent account, caught only because a second-approval rule for payments above a set amount (Volume 11: Internal Controls) required a second person to review the transfer first. No money was lost, but the near-miss prompted immediate password changes, two-step login (a phone code plus a password) where available, and staff training on recognizing similar attempts, a cheap lesson learned before an expensive one was necessary.
You can't predict which external shock will happen, but general resilience (reserves, systems, diversification) prepares for the category, not the specific event.
As the phishing story shows, simple controls (second approval, strong passwords) catch attacks that would otherwise succeed.
Relying on one supplier, one region, or one communication channel multiplies exposure to any external disruption affecting that single point.
Add pandemic, political instability, and cyberattack to your Risk Register. For each, ask: does our general resilience (reserves, documented systems, diversified suppliers, digital security) already cover this, or is there a specific gap?