The 30-Day Resilience Review for CEOs
The next external shock rarely reaches a mid-market business as an abstract geopolitical event. It arrives as a supplier asking for 9% more on 30 days' notice, a customer delaying a project, a lender tightening terms, a software vendor changing data rules, or a delivery route that is suddenly less reliable.
By the time it reaches the board pack, it has become something more familiar: margin pressure, cash strain, service failure or a missed growth target.
That is why resilience can no longer sit in a risk register reviewed twice a year. For CEOs, founders and leadership teams, resilience is now an operating discipline. It is the ability to know where the business is exposed, how much value is at stake, which options are already available, and who can decide before the window closes.
Resilience is not the same as caution
Many leadership teams hear the word resilience and think of defensive actions: more inventory, more suppliers, more cash on the balance sheet, more compliance work, more insurance and more contingency plans.
Some of that may be necessary. Much of it may be wasteful.
Resilience is not the pursuit of maximum protection against every possible event. That is unaffordable for most mid-market companies and often strategically incoherent. A business can spend itself into safety and still lose competitiveness because it has tied up cash, slowed decision-making and duplicated too much of its operating model.
The better question is not "How do we remove all risk?"
The better question is "Where do we need optionality, and what are we prepared to pay for it?"
That turns resilience from a compliance exercise into a strategy conversation. A risk register tells you what might happen. A resilience review tells you what you will do on Monday morning if it does.
Why this has become a board-level issue
Several forces are converging at the same time.
Trade rules are becoming less predictable. Tariff changes, local content rules, sanctions, export controls and regulatory divergence can all move faster than annual planning cycles. The effect is not evenly spread. Two competitors in the same market can have radically different exposure depending on supplier location, product classification, contract terms and pricing power.
Supply-chain pressure has also become more granular. The danger is not only a missing shipment. It may be a second-tier supplier, a specialist material, a logistics route, a warehouse constraint or a quality dependency no one has mapped because the direct supplier relationship looks stable.
Technology has added another layer. Many companies are becoming more dependent on a narrow set of software platforms, data providers, cloud environments, payment systems and AI-enabled workflows. That can make the business faster and more scalable, but it can also concentrate risk in places the board does not yet monitor.
Finance is less forgiving than it was. With funding costs structurally higher than the decade many business models were built in, a disruption that would once have been absorbed as inconvenience can now change covenant headroom, working capital availability or the timing of an investment decision.
For large corporates, these issues may be handled by dedicated teams. For Allington's clients, the same questions often land directly with the CEO, CFO, COO and founder.
The answer is not to build a corporate bureaucracy. It is to run a focused 30-day resilience review.
The five exposures every CEO should test
Most companies do not need to start with a long list of risks. They need to start with five exposure categories that determine whether a shock becomes a manageable issue or a strategic problem.
1. Supplier and input exposure
This is the classic resilience category, but it is still often under-analysed. The leadership team usually knows its direct suppliers. It often knows much less about second-tier dependencies, critical materials, tooling, specialist labour, logistics routes and substitute availability.
Ask:
- Which suppliers, materials, components or service partners would stop or materially slow revenue if they failed?
- Where do we have no credible alternative within 60 days?
- Which contracts allow immediate price movement from suppliers, but do not allow equivalent pass-through to customers?
- Which inputs are small in cost but large in operational consequence?
- Which supplier relationships are held personally by one individual rather than institutionally by the business?
The issue is not simply concentration. Some concentration is efficient and strategically sensible. The danger is invisible concentration.
2. Customer and market exposure
Revenue diversification can be misleading. A company may have hundreds of customers but still depend on one customer segment, one procurement cycle, one sector budget, one channel partner or one geography for most of its profit.
Ask:
- What percentage of gross profit, not revenue, comes from the top ten customers?
- Which customers have the contractual ability to delay, cancel or rephase work without equivalent compensation?
- Which sectors in the customer base are exposed to the same economic or regulatory shock?
- Where are we over-dependent on one channel, tender route, partner or marketplace?
- Which customers would we prioritise if capacity became constrained?
This is where many boards discover that their revenue base is broader than their profit base. That distinction matters when conditions tighten.
3. Pricing and margin exposure
External shocks hurt most when the business cannot translate cost movement into commercial action. The problem may be contract structure, customer power, sales confidence, poor pricing governance or lack of visibility by product and segment.
Ask:
- Which products, projects or customers become unprofitable after a 5%, 10% or 15% input-cost movement?
- Where do contracts prevent price adjustment for too long?
- Where does the sales team discount to protect volume without seeing contribution margin?
- Which costs have moved permanently while prices are still treated as temporary?
- How quickly can the business execute a price change, and who approves exceptions?
Pricing resilience is not only about raising prices. It includes indexing, surcharge mechanisms, minimum order economics, service-level differentiation, customer prioritisation and disciplined walk-away rules.
4. Cash and funding exposure
Profit is not enough. A resilient business knows how a shock moves through working capital, debt headroom, covenant timing and investment capacity.
Ask:
- How much cash is absorbed if debtor days move out by ten days?
- Which customers or suppliers can change payment terms faster than we can respond?
- What happens to covenant headroom under the three most plausible stress scenarios?
- Which planned investments would be delayed, protected or accelerated under each scenario?
- How long could the business fund a supplier switch, stock build, relocation, systems change or hiring gap?
Many leadership teams underestimate the cash cost of resilience. Dual sourcing, inventory buffers, system redundancy and process redesign often require investment before they reduce risk. The board needs to know which resilience moves are affordable and which require funding choices.
5. Technology and data exposure
Operational resilience now includes the systems that hold data, run workflows, enable customer service and support decision-making. AI adoption increases this need because more processes depend on clean data, stable integrations, secure access and clear human oversight.
Ask:
- Which systems would stop revenue, delivery or compliance if unavailable for 48 hours?
- Which data is essential to operate, price, invoice, fulfil or report?
- Which vendors hold data in formats that would be difficult to extract or move?
- Which AI-enabled workflows depend on one model, tool, plug-in or individual expert?
- What is the manual fallback for each critical process, and when was it last tested?
Technology resilience is not an IT issue alone. It is an operating-model issue. The board does not need to understand every system detail, but it does need to know where a technology dependency could become a trading interruption.
The 30-day resilience review
The review should be short, evidence-based and chaired by someone with authority to force decisions. It does not require months of consulting work. It does require finance, operations, sales, procurement, technology and people leaders to work from the same fact base.
Here is the sequence.
Days 1 to 5: define the critical business outcomes
Start with the outcomes the business cannot compromise. These will differ by company, but they usually fall into five categories:
- Protect minimum service levels for priority customers.
- Protect gross margin or contribution margin within an agreed range.
- Protect cash headroom and covenant compliance.
- Protect delivery of the current year's most important growth commitments.
- Protect regulatory, safety, security or reputational obligations.
This matters because a resilience review without priorities becomes a list of everything that could go wrong. Priorities create the basis for trade-offs.
For example, a business may decide that continuity for its top twenty profit-contributing customers matters more than maintaining every product variant. Another may decide that cash headroom matters more than short-term margin. A third may decide that a specific regulatory obligation cannot be compromised even if it means delaying growth work.
Those are strategic choices, not administrative ones.
Days 6 to 12: map exposure
Build a simple exposure map across the five categories: supplier and input, customer and market, pricing and margin, cash and funding, technology and data.
For each exposure, capture:
- Description of the exposure.
- Current owner.
- Evidence source.
- Financial or operational consequence.
- Time to impact.
- Existing mitigation.
- Realistic alternative.
- Decision needed if the exposure moves.
Do not let the review become an essay-writing exercise. Use numbers, contracts, process maps and named owners. If the team cannot quantify the exposure yet, record that as a gap rather than hiding it in narrative.
Days 13 to 18: quantify value at stake
The leadership team should then translate exposure into value at stake. This is where the review becomes commercially useful.
The aim is not precision to the nearest pound. The aim is to separate exposures that are irritating from exposures that can change the company's strategic position.
Days 19 to 24: run three plausible scenarios
Avoid theatrical worst-case scenarios. They usually produce anxiety rather than action. Use plausible scenarios that could occur within the planning horizon.
Scenario one: cost shock. A critical input, supplier category, wage cost, logistics route or software cost rises materially and cannot be passed through immediately.
Scenario two: demand shock. A customer segment slows, a major customer delays work, a channel weakens, or a procurement cycle extends.
Scenario three: operating interruption. A supplier, system, site, route, licence, individual or partner becomes unavailable for a defined period.
For each scenario, answer six questions:
- What happens to revenue, gross margin and cash?
- Which customers, products or services are affected first?
- What would we stop, reduce, protect or accelerate?
- Which decision must be made within 48 hours?
- Who has the authority to make it?
- What information would they need and do we already have it?
The final question is often the most revealing. A business that cannot get the right information quickly is not resilient, even if it has talented people and strong instincts.
Days 25 to 30: agree the response plan
The review should end with a short board-ready response plan, not a long report.
Every material exposure should sit in one of three response lanes.
No-regret moves. These are actions worth taking now because they improve resilience without requiring a major strategic bet. Examples include adding price-adjustment language to new contracts, mapping second-tier suppliers for critical inputs, securing data export rights, testing manual fallbacks, creating a customer prioritisation rule, or improving margin reporting by customer.
Trigger moves. These actions should be prepared now but executed only if defined indicators are hit. Examples include activating a secondary supplier, passing through a surcharge, pausing lower-return work, changing credit terms, freezing discretionary spend, or reallocating capacity to priority customers.
Strategic bets. These are larger decisions that may reshape the business. Examples include regionalising supply, redesigning a product to remove a constrained input, acquiring a capability, moving to a new platform, changing channel strategy, automating a fragile process, or exiting a low-resilience product line.
This is where resilience links directly to strategy. The strongest leadership teams do not merely ask what could hurt them. They ask which moves would protect the business and improve its competitive position at the same time.
The CEO checklist
By the end of the review, a CEO should be able to answer the following questions without commissioning another report:
- Which five exposures could most damage margin, cash or customer delivery in the next twelve months?
- Which of those exposures are concentrated in one supplier, customer, person, system, geography or contract type?
- Which exposures are visible in current management information, and which are still based on anecdote?
- What is the approximate value at stake for each material exposure?
- Which customers, products or services would be protected first under constraint?
- Which costs can be passed through, and where is the business commercially trapped?
- Which resilience moves are affordable now, and which require a funding decision?
- Which trigger points have been agreed in advance?
- Who has authority to act when a trigger is hit?
- How often will the leadership team review the exposure map?
If the team cannot answer these questions, the business is not necessarily in danger. It is, however, relying on improvisation.
What not to do
There are four common mistakes.
Do not delegate resilience entirely to risk, procurement or IT. Each function owns part of the answer, but no function owns the trade-off across margin, cash, customers and strategy. That is leadership-team work.
Do not wait for certainty. The point of a resilience review is to make good decisions under uncertainty, not to forecast the future perfectly. Waiting for clarity usually means acting after competitors have already secured supply, changed terms or repositioned capacity.
Do not confuse insurance with resilience. Insurance may reduce financial loss after an event. It does not protect customer trust, operational continuity, management focus or strategic timing.
Do not spend equally across every exposure. Some risks should be accepted. Some should be monitored. Some deserve immediate investment. The discipline is knowing which is which.
Put resilience into the management rhythm
The review has limited value if it sits outside the way the business is managed. Resilience should be added to the existing leadership cadence.
A practical rhythm might look like this:
- Monthly: review the top five exposures, triggers and any change in value at stake.
- Quarterly: refresh one scenario and test whether response options remain valid.
- Twice yearly: review customer, supplier, product and technology concentration at board level.
- Annually: connect resilience choices to the strategy, budget and capital allocation process.
- Event-based: convene a rapid decision meeting when a trigger is hit.
The important point is not meeting frequency. It is decision quality. A good cadence prevents every shock from becoming a fresh debate.
Where Allington Advisors can help
For many leadership teams, the hardest part is not spotting that exposure exists. It is turning a collection of concerns into a clear decision structure.
Allington Advisors supports founders, CEOs and leadership teams with the practical work behind that structure: strategic exposure reviews, operating-model diagnostics, supplier and cost-base resilience, pricing response, transformation planning, AI implementation risk and leadership-capability assessment.
The work is deliberately commercial. It asks where value is at stake, what choices exist, what the business can afford, and how quickly decisions can be made.
If your leadership team wants a sharper view of where the business is most exposed, a focused 30-day resilience review can turn uncertainty into a practical board agenda.
