8 minute read
18 Months of Crisis Exercises Reveal Four Persistent Resilience Failures
Insight from Battleground’s BCP and Crisis exercising from the past 18 months identifies four recurring themes across almost every exercise we run, and none of them are about capital, claims or payments.
- Tolerances get confirmed in the first fifteen minutes and then nobody counts against them
- The coordinator role is unassigned or defined differently in every plan, so the work lands on whoever is chairing
- Decision rights are documented one or two deep, leaving the decisions a real disruption forces unstated
- Supplier arrangements are strong on contract and untested on response
Great resilience requires discipline, not dollars.
Four themes recurred across almost every crisis and business continuity exercise we ran over the past eighteen months, and, for most organisations, addressing them is more a matter of discipline than dollars.
Tolerances were confirmed early and then forgotten. Nobody was assigned to run the room. Decision rights were undocumented or held by one unavailable person. Supplier arrangements were understood contractually but had never been rehearsed.
Exercising has changed. It used to be defensible to hold one organisation-wide continuity plan and run one organisation-wide test against it, with the lines between continuity, crisis and recovery testing left comfortably blurred. Most organisations of any size now need to test at the level of individual operations, which means more exercises, further down the organisation, involving teams who have never been tested before.
That shift has produced a much larger and more granular body of evidence about how organisations actually behave under pressure.
Battleground facilitated around forty crisis and business continuity exercises across nearly twenty APRA regulated entities over that period. The set spans superannuation, banking, health insurance, general insurance and life insurance, so it is drawn from one part of the economy, but we are confident the themes transcend.
Why? Because what is striking is that none of the four themes has anything to do with the sector. They are not about capital, or claims, or payments. They are about who is counting the clock, who is running the room, who is allowed to decide, and whether anyone has ever spoken to the supplier. Every organisation that exercises has those four questions, whatever it makes or sells.
A portfolio of that size also shows things a single exercise cannot. It reveals which gaps are common and which belong to one organisation alone, and which findings keep reappearing in the same organisation’s tests without ever being closed.
How we read the findings
We went back through the finding set from every exercise, grouped them by what had actually failed rather than by the scope area they were reported under, and looked at what recurred. Four themes dominated.
We have deliberately not put a percentage against them. The more useful measure is how many separate organisations showed the same behaviour, and on that measure these four appear across the great majority of those we worked with, at every level of maturity.
1. Tolerances exist but nobody watches the clock
Teams typically opened an exercise by locating the plan and confirming the relevant tolerance within the first fifteen minutes. They then never returned to it. An hour in, the tolerance had become background information rather than the thing driving the decision. Nobody owned the elapsed-time count, so nobody raised the alarm as the boundary approached.
In one exercise the maximum tolerable period of disruption passed without the team registering it, and the external notification that should have followed was discussed but never actioned. In another, the team’s own estimate of full recovery came to almost four times the documented tolerance for the process, which told the organisation more about the realism of its tolerance than about the team. Elsewhere teams reacted instinctively in a way that matched the intent of the minimum service level without ever citing it, and without anyone in the room being sure when the clock had started.
A tolerance is only useful if somebody is counting against it. That means ownership of the clock assigned at activation, and the elapsed count called out to the room at intervals rather than left for someone to remember.
2. Nobody is assigned to run the room
The coordinator manages the agenda, maintains the log, tracks the actions and holds a single source of truth. In most of the exercises we ran, that role was either unassigned or defined differently in every plan the organisation owned.
The work does not disappear. It lands on whoever is chairing, who then switches between running the room and administering it. We have watched capable crisis leads lose their strategic view entirely because they were also taking the notes. Where no coordinator emerged at all, the consequences showed up in the record: sitreps missed, decision logs thin, and in one case the number of affected customers varying by fifteen thousand between people sitting in the same meeting, because there was no shared source of truth.
Delegation compounds it. Alternates are named in plans but have not been briefed by their primary, so the handover happens inside the meeting and costs twenty minutes. What good looks like is a single coordinator role defined once and leveraged consistently into plan beneath the crisis plan, and alternates briefed outside the room before they are needed.
3. Decision rights are undocumented, or held by one person who is unavailable
This was the finding we saw most often in crisis exercises, and it has the shortest path to a bad outcome.
Plans routinely document one or two operational decision rights and leave the rest unstated. In one exercise the playbook named an approver for switching to an alternative supplier, but the three other consequential decisions the scenario forced had no authority statement at all. In a multi-entity group, nobody could establish which board held approval rights over a ransom decision. Elsewhere teams could not distinguish crisis decision-making authority from ordinary business delegations, so a decision that could have been made at nine in the morning waited for one individual to become available.
A related pattern is escalation that arrives too late to be a decision. More than once, a leadership team was informed of choices already taken rather than presented with options, costs and a recommendation. The escalation happened, but it ratified rather than decided.
What good looks like is a decision authority matrix covering the full set of decisions a disruption actually forces, with financial thresholds where they apply, named alternates for each, and an agreed briefing standard so escalated decisions arrive with the basis for challenge attached.
4. Supplier response is unknown
Contracts and relationship managers are well documented. Supplier escalation contacts have been tested infrequently, if at all. Joint response arrangements have not been rehearsed, and the supplier’s own continuity plan is unfamiliar to the organisation relying on it.
Where a critical supplier took part in the exercise, the quality of the response improved markedly, and the joint tests surfaced mismatched tolerances that would never have integrated during a real disruption. That is a finding worth having in a room rather than in an incident.
Escalation contacts should be tested annually in the same way a call tree is tested. At least one exercise a year should include a critical supplier. And tolerance setting should account for the tolerances of the suppliers you depend on, rather than assuming they align.
What the next eighteen months should show
None of these four are expensive. They require deciding who owns the clock, defining the coordinator role once, writing down who can commit, and putting a supplier in the room.
If organisations close them, the finding profile should move. We would expect to spend less of the next eighteen months reporting on role definition and plan quality, and more of it on the harder problems underneath: whether workarounds hold at volume, whether surge capacity exists for a disruption lasting weeks rather than hours, and whether tolerances set in a governance forum survive contact with what the team can actually deliver. Those are better problems to have. Most organisations are not there yet.
Confidence in a plan is not the same as confidence under pressure. Speak with the Battleground team about exercising the decisions, dependencies and responsibilities that matter most.











