Ecosystem Resilience Starts at Home
Supply chain and ecosystem resilience is the headline topic at every continuity conference right now. The Middle East conflict in March 2026 showed how fast exposure can surface in places nobody had mapped, with firms discovering dependencies they'd never connected to their programmes. But most of the conversation jumps straight to supplier mapping and nth-party risk, as if interconnected resilience is built outward. In practice, it has to be built from the inside first.
Defining the Terms
Enterprise resilience is an organisation's own internal capability to absorb and recover from disruption. Operational resilience is narrower: the UK regulatory requirement (under PRA and FCA rules) to stay within impact tolerances for important business services. Third party and supply chain resilience covers exposure to direct and extended suppliers. Ecosystem resilience sits above all three. It refers to the resilience of an entire interconnected network, where a failure anywhere can ripple through entities with no direct relationship to each other.
An organisation that can't answer basic questions about its own dependencies has no chance of answering them about its suppliers, let alone the wider ecosystem. Most resilience programmes are built around plans and documentation rather than live, decision-grade visibility, and that gap shows up the moment something breaks, when the team is trying to work out what's actually impacted and how to recover.
The Cost of Not Knowing
Disruption rarely causes loss in a straight line. The NCSC's Annual Review 2025 pointed to last year's attacks on Marks & Spencer, the Co-op and Jaguar Land Rover as cases where damage spread well beyond the organisation initially hit. The same review found only 14% of UK businesses had reviewed the cyber risk of their immediate suppliers in the past year, exactly the foundational gap that turns a contained incident into a cascading one.
The financial stakes back this up. An Economist Intelligence Unit survey found disruptions cost firms six to ten percent of annual revenue on average, before reputational damage is counted. That traces to a visibility problem, when dependencies live only in documents and institutional memory, working out what's impacted becomes a manual reconstruction exercise under pressure.
Four questions define whether an organisation can respond with confidence: what is impacted, what happens next, what is the financial exposure, and what should be prioritised. Few organisations can answer them quickly, and fewer still consistently.
Why Foundational Readiness Comes First
Ecosystem-level interconnectedness is real and growing. Cloud infrastructure, SaaS platforms and extended supplier networks have created dependency structures most organisations don't fully understand. But mapping that complexity on top of an unclear internal picture produces a map that looks complete without being accurate.
Foundational readiness means having a current, validated picture of how your own services, processes, technology and teams depend on each other, before extending outward. This isn't a documentation exercise. Documentation captures a state at a point in time and goes stale the moment something changes. Foundational readiness is closer to a live model, curated continuously. Once that model exists, extending it outward becomes tractable, and the question shifts from ‘what do we even know about this’ to ‘what does this mean for us’ and ‘what should we do first’.
Building Outward, Not Sideways
None of this argues against supply chain mapping, it argues for sequencing. Organisations that build supply chain visibility before internal visibility tend to end up with two disconnected pictures, neither talking to the other when it matters most. Ecosystem level resilience is the right long-term goal, but getting there starts with an honest look at whether an organisation has earned its enterprise resilience first.
