It may seem that the companies most at risk are those that have neglected the basics: no backups, no procedures and no security specialists. In practice, the picture is often very different. The most vulnerable organisations are those that believe they are already resilient. That belief closes the discussion, and once the discussion is closed, no one continues to test the assumptions behind it.

In practice, this pattern takes several recurring forms. Four are particularly worth recognising because they appear most frequently.

Profile one: medium-sized companies running their own server rooms the way they always have. The infrastructure has operated for years, so it is assumed to be proven and reliable. Yet everything around it has changed during that time: threats, regulations, dependencies on suppliers and the scale of the business relying on it. A successful track record is often mistaken for readiness for the future.

Profile two: companies operating hybrid environments without a coherent architecture. Some systems are hosted on-premises, others in the cloud, but there is no consistency across the environment. This setup is usually not the result of a deliberate decision, but of accumulated history: each new requirement was addressed with another solution. Every component may work well on its own. The problem is that no one designed the environment as a whole, so no one knows how it will behave during a crisis.

Profile three: fast-growing companies in which technology is failing to keep pace with the business. Growth is good news, but it also has a downside. An environment designed for the company as it existed two years ago may now be supporting a business twice its original size. Every new customer and every new process places additional pressure on a structure that has not been strengthened in the meantime.

Profile four: organisations dependent on a single provider or a single technology ecosystem. We have discussed extensively in this series why such dependency has become a strategic risk. One reminder is enough here: the convenience of a single ecosystem comes at a price, and that price becomes apparent only when circumstances change on the other side.

Is this list relevant only to banks and major institutions? Not at all. None of the four profiles is defined by company size. They also apply, and perhaps apply above all, to medium-sized businesses. Their common denominator is dependence on operational continuity. Manufacturing, retail, logistics, healthcare and the public sector: in all these areas, when systems stop, core operations stop as well. The greater the dependence on continuity, the sooner an organisation needs to start thinking about resilience.

There is also a clear sign that a company is ready to change the way it thinks. The shift from operational to architectural thinking begins when IT stops being a support function and becomes a prerequisite for business operations. As long as systems merely support the business, managing them may be enough. When the company cannot manufacture, sell or serve customers without them, they need to be designed as a foundation, not treated as a tool.

The shared lesson from all four profiles is somewhat counterintuitive. The real threat is not a lack of resilience, because that can be addressed. The real threat is the certainty that resilience is already in place, because that certainty prevents further action. The best thing a company can do after reading this list is therefore to return to the questions with which we began this series and determine whether its sense of security stands up to scrutiny.