Home/ Volume 10/ Chapter 5
Show menu button
The Golden Rule

Nothing here can be stopped by the business alone. What it controls is how ready it is to adapt.

A pandemic, political instability, or a cyberattack campaign happens regardless of what any single business does. General resilience, reserves, documented systems, more than one supplier, prepares for the category, not the specific event.

PandemicTests remote/flexible operating capability and the emergency fund.
Political instabilityTests supplier diversification and reserves against regional shocks.
CyberattackTests backups, strong passwords, and second-approval controls.

Outside any one business

These shocks affect an entire region, industry, or economy at once, prevention isn't the point, response is.

Exposes old weaknesses

A resilient business survives not by predicting the crisis, but by already having reserves, systems, and diversification.

Simple controls catch a lot

A second-approval rule stopped a phishing transfer cold, before any expensive lesson was needed.

Single-source is the multiplier

One supplier, one region, or one channel turns any external disruption into a direct hit.

1

Definition

Imagine a phishing email (a scam message pretending to be someone the business trusts) lands in a shared inbox, nearly tricking a staff member into transferring funds to a fraudulent account. Nothing about that attempt was preventable by the business, someone somewhere decided to target them, and no policy could have stopped the email from arriving. What stopped the money from actually leaving was a boring internal rule: any payment above a set amount needs a second person's approval first. The attack itself was outside anyone's control. Whether it succeeded was not.

External risks

are large-scale shocks that originate completely outside the business and outside any individual customer or employee, affecting an entire region, industry, or economy at once. They are the hardest risks to prevent and the most important to prepare responses for.

In One Sentence

Nothing in this chapter can be stopped by the business alone. A pandemic, political instability, or a cyberattack campaign happens regardless of what any single business does. What the business can control is how ready it is to adapt: could it operate with restricted movement? Could it survive a supply disruption? Could it recover from a digital breach?

2

The Three External Risks

Pandemic

Threatens in-person operations, supply chains, customer demand.

Defend: flexibility

Political Instability

Threatens supply chains, currency, physical safety, regulation.

Defend: diversify

Cyberattack

Threatens digital systems, customer data, financial accounts.

Defend: security basics
RiskWhat It ThreatensPrimary Defense
Pandemic / public health crisisIn-person operations, supply chains, customer demandRemote/flexible operating capability, emergency fund
Political instabilitySupply chains, currency, physical safety, regulationUsing more than one supplier, reserves, not depending too much on one region
CyberattackDigital systems, customer data, financial accountsVolume 20: Technology & Cybersecurity, backups, strong passwords
3

Why External Risks Test Every Other Chapter at Once

A genuine external shock rarely arrives alone, it tends to test every defense built elsewhere in this manual simultaneously: the emergency fund (can the business survive without normal revenue for months?), documented systems (can work continue if key people can't be physically present?), and supplier diversification (is there a backup if one source disappears?).

Memory Trick

External risks don't create new weaknesses, they expose the ones that were always there. A business with real systems, reserves, and diversified suppliers survives an external shock not because it predicted the specific crisis, but because it was already resilient in general.

4

Example Story: The Cyberattack That Taught a Cheap Lesson

Here's the full version of the phishing story from the start of this chapter.

A phishing attempt targeting MANIAC MINDZ's shared email account nearly succeeded in tricking a staff member into transferring funds to a fraudulent account, caught only because a second-approval rule for payments above a set amount (Volume 11: Internal Controls) required a second person to review the transfer first. No money was lost, but the near-miss prompted immediate password changes, two-step login (a phone code plus a password) where available, and staff training on recognizing similar attempts, a cheap lesson learned before an expensive one was necessary.

5

Across Industries

Nimbus Labs

External riskDirect exposure to cyberattack given its fully digital operations.

Green Fields Farm

External riskImport/export disruption from political instability affecting fertilizer supply.

Bright Path Academy

External riskPandemic-driven closures requiring a rapid shift to remote learning.
6

Common Mistakes

Common Mistake #1: Believing External Risks Are Too Unpredictable to Prepare For

You can't predict which external shock will happen, but general resilience (reserves, systems, diversification) prepares for the category, not the specific event.

Common Mistake #2: No Digital Security Basics in Place

As the phishing story shows, simple controls (second approval, strong passwords) catch attacks that would otherwise succeed.

Common Mistake #3: Single-Source Dependency

Relying on one supplier, one region, or one communication channel multiplies exposure to any external disruption affecting that single point.

7

Quiz Yourself

Quiz 1
Name the three external risks covered in this chapter.
Pandemic/public health crisis, political instability, and cyberattack.
Quiz 2
Why is it said that external risks "don't create new weaknesses, they expose the ones that were always there"?
Because a genuinely resilient business (with reserves, documented systems, and diversified suppliers) survives an external shock through general preparedness, not by having predicted the specific crisis.
Quiz 3
What specifically stopped the phishing attempt from succeeding?
A second-approval rule requiring another person to review payments above a set amount before they could be sent.
8

Practice Exercise

Add pandemic, political instability, and cyberattack to your Risk Register. For each, ask: does our general resilience (reserves, documented systems, diversified suppliers, digital security) already cover this, or is there a specific gap?

9

Quick Summary

Quick Summary

  • External risks, pandemic, political instability, cyberattack, originate outside the business and can't be prevented by it alone.
  • General resilience (reserves, systems, diversification) prepares for the category of shock, even when the specific event can't be predicted.
  • A near-miss (like a caught phishing attempt) is a cheap lesson worth acting on immediately, before an expensive one becomes necessary.