For years, resilience was something organizations claimed rather than measured: a continuity plan on file, a crisis framework in a deck, a line in the annual report. This year, that claim got tested against something harder to argue with than a slide.
When the Strait of Hormuz shut down in the wake of the 2026 Iran war, throughput collapsed from roughly 16-20 million barrels a day to 1-2 million, according to APCO’s Geopolitical Radar. Brent crude peaked above $138 a barrel in April and held above $100 into mid-year. Suez Canal traffic dropped well below pre-crisis levels, with the Cape of Good Hope becoming the default Asia–Europe route, adding time, cost and uncertainty to already stretched networks. Marine insurers began repricing Gulf transits, in some cases moving to voyage-by-voyage terms.
None of this was a scenario exercise. It was the operating environment, for months, for every organization with exposure to the region.
The System That Held and the System That Didn’t
From the outside, most organizations came through it looking steady. Deliveries continued. Decisions got made. Clients were served on schedule, more or less. Judged by outcomes alone, resilience appeared intact.
But looking intact and being intact aren’t the same thing.
In a large number of cases, what held the system together wasn’t the plan. It was a small number of people absorbing the difference between what the process was built for and what actually happened: rerouting manually, escalating outside normal channels, making calls no documented process anticipated. From a leadership seat, that looks identical to a system working as designed. From the inside, it’s a system being kept alive by whoever happened to be paying attention at the right moment.
The distinction matters because the two only diverge under real pressure, and pressure at this scale doesn’t arrive often enough for most organizations to have learned the difference. Most leadership teams would say their resilience is documented. Ask where the documentation actually lives, and in a lot of companies, the honest answer is: in a few people’s heads, not in the system itself.
Resilience That Isn’t Documented Isn’t Resilience
Across the organizations I’ve advised through this period, almost none described their operating environment as stable, even the ones that came through the last six months looking composed from the outside. Instability isn’t the exception leadership teams plan around anymore. It’s the baseline they’re already operating inside, whether their systems reflect that or not.
Oxford’s Corporate Affairs Academy, in research conducted with GlobeScan, found geopolitical risk and uncertainty cited as a top business risk by 76 percent of corporate affairs professionals in 2025, up from 70 percent the year before.
The gap between perceived and tested readiness shows up clearly in adjacent risk categories. The World Economic Forum’s Global Risks Report 2026 ranks misinformation and disinformation as the second most severe global risk over the next two years, behind only geoeconomic confrontation. More striking is the trajectory: “adverse outcomes of AI” registers the largest ranking jump in the report’s history, moving from 30th place in the two-year outlook to fifth over a ten-year horizon. That’s a risk accelerating far faster than the governance structures most organizations have built to manage it, and a reasonable proxy for how many other capabilities carry the same untested confidence.
The Ratio Every Leadership Team Should Be Able to Answer
Surviving the last disruption isn’t the test. Most organizations did. What matters is whether leadership can explain how: of the decisions and workarounds that kept operations running through the last period of real pressure, what share ran on a documented process, and what share ran on a specific person’s judgment, made in the moment, with no process behind it?
Few leadership teams can answer that with any precision, because the question is rarely asked until the person who provided that judgment is unavailable, has moved on, or is asked to do it again at a scale beyond what one person can absorb. At that point, the answer arrives as a failure rather than a finding.
This is a solvable problem, but it requires treating the last disruption as a source of data rather than a story about having come through it. That means identifying, specifically, which parts of the operation depended on individual judgment rather than defined process, and converting enough of that judgment into process before the next disruption asks the same people to do it again, faster and with less margin.
Execution, Not Optimism, Is the Advantage
The organizations with a real advantage going into the next disruption won’t be the ones who looked calmest through this one. They’ll be the ones who went back afterward, found out exactly what had been holding things together, and made sure it no longer depended on one person being in the right place at the right time.
That’s a less comfortable exercise than declaring the test passed. It’s also the only version of resilience that holds up the next time it’s tested.











