Your journey
  1. 1
  2. 2
  3. 3
  4. 4
  5. 5
  6. 6
0 of 34 units

You are in Degree 5 · Governance and resilienceunit 6 of 6Ahead of you: An approved use policy and a completed maturity assessment.

Degree 5 · Unit 5.6

Engineering resilience

Something robust resists until it breaks; something resilient bends and then comes back. The difference is that the first is betting on preventing failure altogether, while the second assumes failure will come and designs for the recovery. In an environment that changes every month, the first bet loses.

This unit closes the degree because it fortifies everything built before it. The policy, the controls, the maturity — every one of them gets tested at the moment of disturbance, never at the moment of calm.

FIG. 32 — The five principles of resilience
Redundancy
An alternative route for every critical route. What if your provider stopped tomorrow? And what if the person who knows everything were away?
Diversity
No backup of the same kind. Two providers on the same technology fall together, and two identical opinions reveal no error.
Decentralisation
A decision close to where it belongs. A system waiting for permission from the top freezes when the top is cut off.
Safe failure
When a part falls, it falls alone. Separate systems so a small fault does not bring the whole down.
Learning
Every incident changes a procedure. Without this principle the same incidents recur under different names.

Resilience in the age of agents

AI has added new kinds of dependency that belong in your reckoning. There is dependency on a provider, who may change their model, change their price, or discontinue the service entirely. There is model drift, where the behaviour of a new version changes and breaks whatever you built on the old one. And there is skill atrophy, which is what happens when a team forgets how to do the work without the tool.

The remedy is simple and almost never applied: keep the manual route alive. Carry out the critical process by hand once in a while — not because doing it by hand is faster, but so that doing it by hand remains possible at all.

Cloud intelligence against intelligence at the edge

The future is not entirely central but a deliberate distribution of the task to wherever it belongs — which is itself a principle of resilience.

FIG. B11 — Across six axes
The cloud
The edge
Where does the processing happen?
A distant server in a data centre
The device itself: a phone, a camera, a car
Connectivity
Always required
Not required at all
Latency
A round trip across the network
A fraction of a second, locally
Privacy
The data leaves the device
The data never leaves it
Capacity
Vast: training and heavy analysis
Small and deliberately limited
Suits
Large models and complex analysis
Instant decisions and work without coverage

The decisive example: identifying an unknown fruit in an area with no coverage. Where delay is a danger or the connection is gone, the cloud drops out of the equation however powerful it is — just as the automated route drops out when it is cut, and the manual route remains.

The post-incident review

This is the most useful instrument in the unit. After every incident, however small it looked, sit down for an hour and answer five questions. What exactly happened? When was it discovered, and why was it not discovered sooner? What actually worked in containing it? Which procedure is going to change, with a name and a date attached? And how will we know that it changed?

It has one condition of success: no blame. A team that gets punished for reporting will stop reporting, and the organisation loses its eyes at exactly the moment it needs them most.

Plan · do · check · act

The engine of continual improvement that keeps a management system alive after certification — and the organised form of the post-incident review.

FIG. B28 — The four-part cycle
Plan
Risk assessment · security planning · strategy
Do
Deploying controls · training · execution
The PDCA cycle for creative security ↻
Check
Audit · performance review · monitoring
Act
Corrective measures · innovation · improvement
The order: plan → do → check → act, then back to "plan" with better knowledge.

The cycle does not stop at "check": the findings are reported to management and turned into action, or the audit becomes an annual rite with no effect.

Do this

  1. 1 — In your field. Write the most dangerous single point of dependency in your work — a system or a person — then write its alternative. If it has none, that is your priority.

  2. 2 — In practice. Carry out a critical process entirely by hand. Record the time and what the team had forgotten.

  3. 3 — In writing. Apply the post-incident review to an incident that actually happened this year — however small.

Where to now? You have built a system that holds. One degree remains, and it is both the hardest and the most lasting: making something new, leading the people who make it, and leaving behind what stays after you.

GATE · LEVEL FIVE

An approved policy + a completed maturity assessment

Hand over three outputs: the system register for your organisation; the two-page policy, approved by someone with authority and communicated to the team; and the UCSMM assessment in full, twenty items, with a plan to climb one level in the weakest dimension.

The standard of success: that three employees — who had no part in the drafting — give the same answer to an applied question from the policy.

Work the gate on the programme page