How Organisational Silos Undermine Operational Resilience
- Julien Haye
- 2 days ago
- 17 min read

Operational resilience has become a strategic priority for organisations operating in an increasingly complex and interconnected environment. Cyber attacks, technology failures, third-party disruption, geopolitical uncertainty and operational incidents continue to test organisations' ability to maintain critical services while protecting customers, markets and stakeholders.
Many resilience programmes focus on strengthening individual capabilities such as technology resilience, business continuity, crisis management and disaster recovery. While these disciplines remain essential, they address only part of the challenge.
The ability to withstand and recover from disruption depends on far more than the effectiveness of individual functions.
Critical business services are delivered through interconnected networks of people, processes, technology, data, facilities and third-party providers. When these connections are not fully understood, organisational silos emerge. Information becomes fragmented, dependencies remain hidden, decision-making slows and recovery efforts become increasingly difficult to coordinate.
Operational resilience is built on these connections. It depends on governance that enables leaders to understand how critical services are delivered across organisational boundaries and how disruption can propagate throughout the enterprise.
Organisations that develop this enterprise-wide perspective are better positioned to anticipate disruption, coordinate effective responses and recover more quickly when operational failures occur.
This article explores how organisational silos undermine operational resilience by obscuring enterprise-wide visibility, weakening governance and reducing organisational connectivity. It also explains why connected governance provides the foundation for stronger operational resilience by improving enterprise awareness, decision quality and coordinated recovery.
Operational resilience is not determined by the strength of individual functions. It is determined by how effectively governance connects the organisation to operate as a single enterprise.
Other articles in the series
In Organisational Silos: The Hidden Cost of Fragmented Governance, discover how fragmented governance limits enterprise awareness, weakens decision-making and creates hidden organisational risks.
In How Functional Silos Weaken Risk Identification and Escalation, explore how fragmented organisational structures prevent information from flowing across the enterprise, weakening both risk identification and timely escalation.
Executive Takeaways
For readers scanning rather than reading in full, five governing insights frame the argument.
Operational resilience depends on understanding how critical services are connected across the enterprise.
Important business services are rarely delivered by a single function. They rely on interconnected people, processes, technology, data and third-party providers working together. Understanding these relationships enables organisations to identify vulnerabilities, manage dependencies and strengthen resilience before disruption occurs.
Organisational silos weaken resilience by obscuring dependencies and enterprise-wide visibility.
Individual functions often manage their own risks effectively, yet critical dependencies frequently extend beyond organisational boundaries. Connected governance provides the enterprise-wide visibility needed to understand how disruption can propagate across multiple business services and organisational functions.
Effective crisis management begins with governance, not incident declaration.
The quality of organisational recovery is largely determined before a crisis occurs. Governance establishes the decision-making, escalation, accountability and coordination that enable organisations to respond quickly, maintain situational awareness and prioritise important business services during disruption.
Scenario testing strengthens resilience by exposing governance weaknesses before operational failures occur.
The greatest value of scenario testing lies in organisational learning. Cross-functional exercises reveal communication gaps, fragmented ownership, hidden dependencies and decision bottlenecks, allowing organisations to strengthen governance before severe disruption tests it in practice.
Connected governance strengthens enterprise awareness, decision quality and operational resilience.
Operational resilience is not achieved by improving individual functions in isolation. Organisations become more resilient when governance connects information, dependencies and decision-making across the enterprise, enabling leaders to anticipate disruption, coordinate recovery and protect important business services more effectively.
Operational Resilience Is Built Before Disruption Occurs
Operational resilience is the ability to continue delivering important business services despite disruption. While effective crisis management forms an important part of resilience, it represents only one stage of a much broader organisational capability.
True resilience is established long before an incident occurs.
It is built by understanding how critical services, people, technology, data, facilities and third parties work together to support organisational objectives. It also depends on governance that connects information, enables coordinated decision-making and supports effective action when disruption occurs.
Operational resilience is therefore developed through a continuous cycle of organisational preparedness that includes:
Prevention by strengthening governance, controls and operational capabilities to reduce the likelihood of disruption.
Anticipation by identifying emerging risks, critical dependencies and plausible disruption scenarios before they materialise.
Preparation by establishing governance, response plans, roles, responsibilities and communication arrangements.
Adaptation by maintaining situational awareness, making informed decisions and adjusting operational priorities as events develop.
Recovery by restoring important business services, capturing lessons learned and strengthening resilience for future disruption.
Each stage reinforces the next. Weaknesses introduced during prevention, anticipation or preparation often remain hidden until disruption occurs, when fragmented governance, poorly understood dependencies and unclear accountability can significantly delay an effective response.
This explains why operational resilience is fundamentally a governance capability. Organisations that understand their critical services, dependencies and decision-making arrangements are better positioned to respond, adapt and recover when disruption occurs.
Figure 1 illustrates the Operational Resilience Lifecycle, demonstrating how resilience is built through continuous governance, preparation, learning and improvement rather than during the crisis itself.

Operational resilience is not measured by how organisations respond to disruption. It is determined by how well they prepare for it.
Critical Services Extend Across Organisational Boundaries
Important business services rarely belong to a single department.
They are delivered through a network of people, processes, technology, data and third parties working together to achieve a common customer outcome. Every stage depends on activities performed by different parts of the organisation, each contributing to the continuity of the service.
A customer making a digital payment, for example, experiences a single, seamless service.
Behind that experience, however, multiple organisational functions work together to deliver the outcome.
Figure 2 illustrates a simplified example.

From the customer's perspective, this appears to be a single service.
From an organisational perspective, it is a complex network of interconnected capabilities.
This distinction is fundamental to operational resilience.
Departments manage individual activities. Critical services depend on how those activities work together. A disruption affecting one function can quickly influence every subsequent stage, creating consequences far beyond the area where the incident originated.
Understanding these relationships requires organisations to map services rather than departments.
Critical service mapping identifies the people, processes, technology, facilities, information and third parties that support service delivery. More importantly, it reveals the dependencies between them, allowing organisations to understand where disruption is most likely to occur, how it could propagate across the enterprise and where resilience capabilities should be strengthened.
Without this enterprise view, organisations often optimise individual functions while overlooking the connections that determine whether a critical service can continue during disruption.
Operational resilience depends less on how individual departments perform and more on how effectively the organisation understands and manages the connections between them.
Hidden Dependencies Create Hidden Vulnerabilities
Every important business service depends on a complex network of interconnected capabilities. Some of these dependencies are well understood and actively managed. Others remain largely invisible until disruption exposes their significance.
This is one of the greatest challenges in operational resilience.
Organisations typically understand the components they own. They often have much less visibility of the connections between those components and how disruption in one area can affect service delivery across the enterprise.
Dependencies exist throughout the organisation, including:
People with specialist knowledge, decision-making authority or operational responsibilities.
Technology supporting applications, infrastructure, networks and cybersecurity.
Data required to process transactions, support decisions and meet regulatory obligations.
Facilities such as offices, data centres and operational sites.
Third parties providing critical technology, cloud services, payment infrastructure and outsourced activities.
Business processes that connect multiple functions to deliver an important business service.
Each dependency may appear manageable in isolation.
Together, they create a network of interconnected vulnerabilities.
A disruption affecting a relatively small component can quickly propagate across multiple organisational functions. Consider a failure involving a specialist technology supplier supporting a critical payment platform.

The original disruption may have affected only one supplier.
The organisational consequences extend much further.
This illustrates why dependency management is fundamental to operational resilience. Organisations that understand how critical services depend on people, technology, data, facilities, third parties and business processes are better positioned to anticipate disruption, prioritise recovery and coordinate an effective response.
Most operational failures do not begin with the collapse of an entire service. They begin with a dependency that appeared too small to matter until the wider organisation depended on it.
Third-Party Risk Is an Enterprise Governance Challenge
Few organisations deliver important business services using only their own people, processes and technology.
Cloud providers, payment networks, managed service providers, software vendors, telecommunications providers and outsourced operations have become integral to the delivery of critical services. As organisations increasingly rely on complex external ecosystems, operational resilience depends on understanding not only individual suppliers but also the connections between them.
These dependencies rarely align neatly with organisational structures.
Technology manages cloud infrastructure. Procurement owns supplier relationships. Operations relies on outsourced service delivery. Compliance oversees regulatory obligations. Risk assesses resilience exposures, while executive management remains accountable for the continuity of important business services.
Each function sees only part of the picture.
Without effective governance, no one develops a complete view of how external providers collectively support critical business services or how disruption within one part of the supply chain could affect the wider organisation.
This is where organisational silos become a resilience challenge.
Individual suppliers may be managed effectively within their respective functions, yet critical dependencies between suppliers, technologies and business services often remain poorly understood. A cloud provider may support multiple applications. A payment processor may depend on the same telecommunications network used by other critical suppliers. An outsourced service provider may subcontract activities to additional organisations beyond the firm's direct oversight.
These interconnections create dependency networks that extend well beyond contractual relationships.
Effective governance therefore requires organisations to understand:
Cloud providers supporting critical infrastructure, applications and data.
Payment networks enabling transaction processing and settlement.
Managed service providers delivering operational and technology services.
Critical suppliers supporting essential business capabilities.
Concentration risk, where multiple important business services rely on the same provider.
Sub-outsourcing arrangements that introduce additional operational dependencies.
Fourth parties supporting critical suppliers, often with limited organisational visibility.
Understanding these relationships enables organisations to identify how disruption may propagate across multiple suppliers, business services and organisational functions. A failure affecting a single provider can quickly extend beyond contractual boundaries, influencing customers, regulatory obligations, operational performance and organisational reputation.
Recent operational resilience regulations increasingly reflect this enterprise perspective. Organisations are expected not only to manage individual supplier relationships but also to identify critical dependencies, assess concentration risk and demonstrate that important business services remain resilient during severe but plausible disruption scenarios.
This requires governance that connects information across Procurement, Technology, Operations, Risk, Compliance and executive management. Only by bringing these perspectives together can organisations understand the external ecosystem supporting their critical services and make informed decisions about resilience.
Third-party resilience is not determined by how well organisations manage individual suppliers. It depends on how effectively governance connects information across the organisation to understand the dependency network supporting critical business services.

Scenario Testing Exposes Organisational Silos
Organisations rarely discover the true effectiveness of their governance during normal operations.
They discover it when disruption forces people, technology, suppliers and decision-makers to work together under pressure.
This is the true purpose of scenario testing.
While operational resilience regulations increasingly require organisations to conduct scenario testing, its greatest value lies in organisational learning rather than regulatory compliance. Well-designed exercises expose weaknesses that often remain hidden during day-to-day operations, providing valuable insight into how governance, decision-making and coordination perform when critical services are disrupted.
The objective is not to predict the next crisis.
It is to understand how the organisation would respond if a severe but plausible disruption affected one or more important business services.
This is where organisational silos become visible.
A cyber incident may initially appear to be a technology issue. As the exercise develops, however, Technology, Operations, Customer Support, Compliance, Communications, Risk, Executive Management and critical third parties all become involved. Information moves between multiple functions, priorities compete for attention and decisions must be coordinated across the organisation.
The exercise is no longer testing technology.
It is testing governance.
Effective scenario testing evaluates how well the organisation operates as an integrated enterprise by examining:
Critical dependencies supporting important business services.
Communication between business functions, executive management, regulators and customers.
Decision-making when information is incomplete and time pressures increase.
Cross-functional coordination as responsibilities transfer between teams.
Leadership and governance, including escalation, accountability and executive oversight.
Recovery coordination across internal teams, third parties and critical suppliers.
These exercises frequently reveal that the greatest barriers to resilience are organisational rather than technical.
Responsibilities may be interpreted differently across functions. Information may reach decision-makers at different times. Dependencies may be only partially understood. Recovery priorities may conflict as individual teams focus on restoring their own activities rather than the end-to-end service.
Different scenarios expose different aspects of organisational connectivity. A cyber attack may highlight technology and communication challenges. A cloud outage may reveal supplier concentration and dependency risks. A critical supplier failure may expose gaps in third-party oversight, while a payment disruption may demonstrate how operational, customer, regulatory and reputational impacts quickly become interconnected.
The greatest value of scenario testing lies in what organisations learn from these exercises. Lessons should strengthen governance, improve decision-making, clarify accountability and enhance coordination across organisational boundaries. Each exercise provides an opportunity to reduce fragmentation before a real disruption occurs.
Scenario testing does not simply validate recovery plans. It reveals where organisational silos prevent the enterprise from responding as one organisation.

Recovery Depends on Organisational Connectivity
Operational resilience is ultimately measured by an organisation's ability to recover from disruption while continuing to deliver important business services within defined impact tolerances.
Recovery, however, is rarely achieved by individual teams working independently.
It depends on the organisation functioning as a coordinated enterprise.
During a major disruption, Technology may restore critical systems, Operations may resume core processes and Customer Support may manage increased demand. Individual functions can perform effectively within their own areas of responsibility, yet the organisation may still struggle to restore the end-to-end service if activities are not coordinated.
This illustrates an important distinction.
Recovering individual functions is not the same as recovering important business services.
Critical services typically depend on multiple business functions, technology platforms, third-party providers and decision-makers working together. Operational resilience therefore requires governance that enables these interconnected activities to be prioritised, coordinated and managed as a single organisational response.
Effective recovery depends on several interconnected capabilities:
Shared priorities that focus recovery efforts on restoring important business services rather than individual departmental objectives.
Clear ownership of recovery decisions, responsibilities and accountabilities across organisational boundaries.
Timely communication between business functions, executive management, regulators, customers and critical third parties.
Coordinated resource allocation to ensure people, technology and external support are directed towards the organisation's highest priorities.
Executive decision-making supported by accurate information, enterprise-wide visibility and effective governance.
Without these capabilities, organisations often experience fragmented recovery. Individual teams may optimise their own activities while unintentionally creating delays elsewhere. Competing priorities emerge, resources become stretched and decisions are made using incomplete information. The result is that functional recovery progresses, but organisational recovery remains slow, inconsistent and difficult to coordinate.
Several high-profile operational failures illustrate this challenge. The 2018 TSB migration programme demonstrated how technology restoration alone was insufficient when customer services, communications, operational processes and governance struggled to recover at the same pace. More recently, the
CrowdStrike technology outage in 2024 affected organisations worldwide, showing that even where underlying technical issues could be addressed, the speed and effectiveness of recovery depended on coordination across technology teams, business operations, third-party providers and executive leadership.
These events demonstrate that operational resilience is determined by more than technical recovery capability. It depends on how effectively organisations connect information, coordinate decisions and align recovery activities across organisational boundaries.
Operational resilience is achieved when the organisation recovers as one enterprise, not when individual functions recover independently.

Case Study: CrowdStrike – Recovery Required More Than Technical Remediation
In July 2024, a defective CrowdStrike software update triggered one of the largest global IT disruptions in recent years. Millions of Microsoft Windows devices entered recovery loops, disrupting airlines, hospitals, financial institutions, retailers and public services worldwide.
Although the technical issue originated from a single software update, the speed and effectiveness of organisational recovery varied significantly. Some organisations restored important business services within hours, while others experienced disruption lasting several days.
The difference was not simply technology.
Organisations with mature governance arrangements were generally better positioned to establish a shared operational picture across Technology, Operations, Customer Services, Risk, Communications and executive leadership. This enabled leaders to prioritise important business services, coordinate scarce technical resources, allocate responsibilities clearly and make timely decisions as the situation evolved.
By contrast, organisations with fragmented governance often struggled to coordinate recovery across organisational boundaries. Technical teams focused on restoring systems, operational teams managed service disruption, customer-facing functions responded to increasing demand and executives sought reliable information to support critical decisions. Where these activities were poorly connected, recovery became slower, priorities competed and important business services remained disrupted despite significant technical effort.
The incident demonstrated that recovering technology is only one component of operational resilience. Restoring important business services requires connected governance that enables enterprise-wide situational awareness, coordinated decision-making and effective collaboration across internal functions and critical third parties.
Governance Lessons
Shared situational awareness enables leaders to make timely, informed recovery decisions.
Enterprise-wide prioritisation focuses recovery on restoring important business services rather than individual departmental objectives.
Clear ownership and accountability reduce delays and conflicting recovery activities.
Cross-functional coordination strengthens communication between Technology, Operations, Risk, Compliance, Customer Services and executive leadership.
Technology recovery and business service recovery are not the same. Operational resilience depends on coordinating people, processes, technology and third parties as a single enterprise.
The CrowdStrike outage demonstrated that technology may trigger disruption, but connected governance determines whether an organisation recovers as a coordinated enterprise or as a collection of individual functions.
Connected Governance Strengthens Operational Resilience
Operational resilience is often discussed in terms of technology, recovery plans and crisis response. While these capabilities remain essential, they are only part of the solution.
Throughout this article, a consistent theme has emerged.
Operational resilience is strengthened when organisations understand and manage the connections between people, processes, technology, third parties and decision-makers. Conversely, organisational silos reduce enterprise visibility, weaken decision-making and limit the organisation's ability to respond effectively when disruption occurs.
This highlights an important principle.
Operational resilience is not simply the result of strong operational capabilities.
It is the outcome of connected governance.
Connected governance enables organisations to move beyond fragmented oversight by integrating information across organisational boundaries. Rather than viewing risks, dependencies and disruption through individual functional perspectives, leaders develop an enterprise-wide understanding of how important business services are delivered and where vulnerabilities exist.
This creates enterprise awareness.
Enterprise awareness enables decision-makers to understand how events in one part of the organisation may affect customers, operations, third parties and strategic objectives elsewhere. It provides the shared operational picture needed to prioritise actions, allocate resources and coordinate responses during periods of disruption.
Better awareness leads to better decisions.
Leaders make decisions using a common understanding of risks, dependencies and organisational priorities rather than fragmented information held within individual functions. Recovery becomes more coordinated, governance becomes more effective and resilience improves across the organisation.
The relationship can be viewed as a continuous progression:
Connected Governance
↓
Enterprise Awareness
↓
Decision Quality
↓
Operational Resilience
Each stage reinforces the next. As governance becomes more connected, organisations gain greater visibility across organisational boundaries. Improved awareness strengthens the quality of decisions, while better decisions enable organisations to anticipate, withstand, respond to and recover from disruption more effectively.
This progression extends beyond operational resilience.
It provides the foundation for a broader approach to governance that connects strategy, risk management, decision-making and organisational performance into a single, integrated system.
Operational resilience is not created by individual functions working more effectively. It is created by connected governance that enables the organisation to think, decide and respond as one enterprise.
Strengthen Your Operational Resilience
Operational resilience depends on more than meeting regulatory expectations. It requires governance that connects critical business services, organisational dependencies and decision-making across the enterprise.
Aevitium helps financial institutions, FinTechs and other regulated organisations assess, design and embed operational resilience frameworks that strengthen governance, improve enterprise awareness and support sustainable resilience.
Whether you are building your operational resilience framework, preparing for regulatory review or enhancing governance maturity, we can help.
Five Questions Board Directors Should Ask About Organisational Silos and Operational Resilience
1. How do we know our important business services are understood across the organisation rather than managed within individual functions?
Important business services typically depend on multiple business functions, technology platforms and third-party providers. Directors should seek assurance that management understands these end-to-end services, including the dependencies that exist across organisational boundaries, rather than relying solely on functional reporting.
2. Does our governance provide an enterprise-wide view of dependencies and disruption?
Operational resilience depends on understanding how people, processes, technology and third parties interact to deliver critical services. Boards should consider whether governance enables enterprise awareness of these connections or whether risks, incidents and dependencies continue to be reviewed through separate functional lenses.
3. Are our crisis management and recovery arrangements designed to coordinate the organisation as a whole?
Successful recovery depends on more than restoring individual systems or departments. Directors should understand how governance supports shared situational awareness, coordinated decision-making, clear accountability and effective resource allocation during periods of disruption.
4. Does our scenario testing expose governance weaknesses as well as operational failures?
Scenario testing should do more than validate recovery plans. Boards should ask whether exercises identify organisational silos, communication gaps, decision bottlenecks and dependency risks, enabling governance to be strengthened before a real disruption occurs.
5. How confident are we that connected governance would enable the organisation to recover as one enterprise?
Operational resilience is determined not only by the strength of individual functions but by how effectively they work together under pressure. Directors should seek evidence that governance connects information, dependencies and decision-making across the organisation, enabling coordinated recovery and informed executive oversight when disruption occurs.
Conclusion
Operational resilience is often associated with technology, crisis management and recovery planning. While each of these capabilities remains essential, they cannot deliver resilience in isolation.
Throughout this article, one principle has consistently emerged.
Organisations rarely become more resilient by strengthening individual functions independently. They become more resilient by understanding how critical services are delivered across the enterprise and by connecting the people, processes, technology, third parties and governance arrangements that support them.
Organisational silos weaken that understanding. They obscure dependencies, fragment information, slow decision-making and make coordinated recovery more difficult when disruption occurs. The result is not simply operational inefficiency. It is reduced organisational resilience.
Connected governance provides the alternative.
By integrating information across organisational boundaries, organisations develop enterprise awareness of how critical services, dependencies and emerging risks interact. This enables better decisions, more effective coordination and faster, more consistent recovery when disruption occurs.
Ultimately, operational resilience is not defined by the strength of individual departments.
It is defined by the organisation's ability to think, decide and respond as a connected enterprise.
As organisations continue to operate within increasingly complex and interconnected environments, resilience will depend less on managing individual risks and more on understanding the relationships between them. Those organisations that develop connected governance will be better positioned not only to withstand disruption but also to adapt, recover and continue delivering value to customers, stakeholders and society.
Operational resilience is ultimately a measure of organisational connectivity. Organisations become resilient when governance connects people, information, decisions and dependencies across the enterprise.
About the Author: Julien Haye
Managing Director of Aevitium LTD and former Chief Risk Officer with over 26 years of experience in global financial services and non-profit organisations. Known for his pragmatic, people-first approach, Julien specialises in transforming risk and compliance into strategic enablers. He is the author of The Risk Within: Cultivating Psychological Safety for Strategic Decision-Making and hosts the RiskMasters podcast, where he shares insights from risk leaders and change makers.
Frequently Asked Questions
1. What is the difference between operational resilience and business continuity?
Although the terms are closely related, they serve different purposes. Business continuity focuses on maintaining and restoring business operations following disruption, whereas operational resilience considers the organisation's ability to prevent, adapt to, respond to and recover from disruption while continuing to deliver important business services within acceptable impact tolerances. Business continuity is one component of a broader operational resilience framework.
2. How can organisations identify hidden dependencies before they become operational risks?
Organisations can improve visibility by mapping important business services end-to-end rather than reviewing individual functions separately. This includes identifying supporting people, processes, technology, facilities, data and third-party providers, then validating these relationships through scenario testing, operational exercises and regular governance reviews.
3. Why do organisations with similar technology recover at different speeds?
Recovery speed is influenced by more than technical capability. Organisations with clear governance, effective decision-making, defined accountability and strong cross-functional coordination are often able to prioritise critical services, allocate resources more effectively and restore operations more quickly than organisations with fragmented governance arrangements.
4. What role do boards play in strengthening operational resilience?
Boards establish the governance framework that enables operational resilience. This includes defining resilience objectives, overseeing important business services, challenging management on critical dependencies, reviewing scenario testing outcomes and ensuring sufficient investment in resilience capabilities across the organisation.
5. How does operational resilience support strategic decision-making?
A mature operational resilience capability provides leaders with greater confidence when pursuing growth, transformation or outsourcing initiatives. Understanding operational dependencies enables organisations to evaluate strategic opportunities more effectively while managing the resilience implications of organisational change.
6. Can small and medium-sized organisations apply operational resilience principles?
Yes. While regulatory expectations may differ, the underlying principles remain applicable to organisations of all sizes. Smaller organisations can strengthen resilience by understanding their critical services, clarifying governance responsibilities, identifying key dependencies and establishing proportionate response and recovery arrangements.
7. How should organisations measure improvements in operational resilience?
Operational resilience should be assessed using a combination of quantitative and qualitative measures. Examples include recovery performance against impact tolerances, dependency mapping maturity, scenario testing outcomes, incident trends, governance effectiveness, decision-making quality and lessons implemented following exercises or operational events.
8. What is connected governance?
Connected governance is an enterprise-wide approach that brings together information, decision-making and accountability across organisational boundaries. Rather than managing risks, dependencies and resilience within individual functions, connected governance enables leaders to understand how these elements interact across the organisation, improving enterprise awareness, decision quality and operational resilience.
.png)
