The risk is already there; you just haven’t discovered it yet

Kuba Nagórski
Author Kuba Nagórski

The Pentagon has contingency plans ready for every eventuality. Somewhere in the thick files gathering dust in Washington, there are plans for the collapse of NATO, a nuclear war with China, an alien invasion, and reportedly even a zombie apocalypse. It sounds crazy, but the principle behind it is perfectly rational. It’s about the habit of thinking that every risk can be identified and considered before it occurs; and also that the cost of analyzing a problem (even an absurd one) will always be lower than the cost of being completely caught off guard.

Most companies operate exactly the opposite way. They don’t plan anything until something goes wrong, and then, on the fly, with trembling hands, they try to write out a plan of action. Only then does it usually resemble putting out a fire without a bucket.

Risk won’t wait

Let’s start with terminology, because the word “risk” is overused to the point of absurdity in business conversations. We use it every day when we mean uncertainty. We resort to it when we’re afraid of making a decision. Finally, we use this word in the context of a potential disaster – something very bad that happens to others and is best avoided at all costs.

Meanwhile, a useful definition of risk in a strategic context sounds completely different. Risk is anything that can slow down, limit, or halt an organization’s growth. Not just the specter of a financial crisis, not just a pandemic, not just war, not just the sudden emergence of a competitor with a better product. A key employee with an overloaded schedule, a single client generating 70% of revenue, and the lack of written procedures in a place where all knowledge exists solely in one person’s head can just as easily turn out to be a risk.

This shift in perspective seems subtle, but it is of fundamental importance. If we understand risk to mean only huge, spectacular disasters – we can easily ignore them, because the probability of such an event usually remains marginal. However, if we call risk everything that can hinder growth – suddenly it turns out that it accompanies us every day, and we don’t even realize it.

Want to grow? Pay the price

There is a certain paradox in the approach to risk that I observe in many entrepreneurs and which, to be honest, I also know from personal experience in a sense. It consists in the fact that the better a company is doing, the less time we devote to thinking about what could go wrong. It’s a natural course of events: everything is working, so why invite negative thoughts into our minds?

Except that this isn’t logic based on any analysis, but merely an illusion of security. Good times don’t eliminate risk; they just mask it. The better we’re doing, the harder it is to see it.

The IT market in recent years seems like a great example. For a long time, software houses operated in an environment where demand so clearly outstripped supply that the strategy of “hire programmers and raise rates” was the answer to everything. For years, no one thought about building their own product, diversifying revenue, or specializing. Why bother? Money was coming in from every direction and filling up the wallet on its own. However, the market suddenly changed – AI entered the scene, budgets for technological development were slashed, clients began counting every penny – and within just a year, it turned out that several dozen percent of companies in the IT industry had no Plan B. They spent what they earned as they went along, assuming it would always be that way.

But nothing lasts forever. And certainly not in business.

Smart companies – those that, during the good years, thought about what might change – either set aside capital or built their own product alongside their services. Others pursued deep specialization to become irreplaceable in a specific, narrow niche. Today, such companies defend themselves most effectively because they managed to build resilience against market volatility. Not because their owners were pessimists looking for disaster, but because they interpreted the unstable reality with maturity.

Many processes, such as scaling operations, by definition involve venturing into the unknown. Sometimes it’s almost like a spaceflight. New markets, new customers, new operating models, new people on the team. Each of these steps carries an element of risk, and the only way to avoid venturing into deep water with your eyes closed is to map them out in advance. We’ll never eliminate all risk – that’s just the nature of business – but the more risk factors you identify at the start, the smaller the chance that you’ll stumble painfully.

“We can never eliminate all risk – that’s just the nature of business – but the more risk factors you identify at the outset, the smaller the chance that you’ll take a painful fall.”

It’s easy to forget that risk doesn’t lurk only on the outside. Sometimes, rapid success itself turns out to be a trap – and one of the most treacherous, because it’s masked by euphoria and the feeling that we’re just catching the wind in our sails. A company that grows without properly scalable structures begins to quietly lose control of its finances. Decisions are made on increasingly murky grounds, the quality of reporting declines, and the organization’s complexity grows faster than its ability to manage processes. In other words: growth that isn’t accompanied by organizational maturity automatically generates risk.

Don't just fix the symptoms. Start with a diagnosis

Prevention is better than chemotherapy

There is one metaphor that really resonates with me when I think about risk in an organization. Each of us carries damaged cells in our bodies that, under the influence of environmental or genetic factors, can begin to multiply, leading in the worst case to cancer. Similarly, risk in business rarely has anything to do with a sudden accident, but more often with a dormant source of disease. Such a factor may not show clear symptoms for a long time, but it already exists and is just waiting to wreak havoc. 

Following this line of reasoning, risk exists regardless of whether we can pinpoint it today. We can ignore this fact and hope for a stroke of luck. Perhaps no defective “cell” will begin to divide uncontrollably. But if a risk factor finds fertile ground and escalates, without having previously defined the symptoms and a response protocol, we may not be able to intervene in time.

That is precisely why, just as in healthcare, prevention is paramount. We must make a daily effort to ensure we never develop this cancer. Not because this will reduce the risk to zero (which is impossible), but because prevention also involves regular visits to the doctor, which, at worst, will allow for earlier detection of the problem. And an earlier diagnosis means a much better chance of a full recovery.

The analogy with oncology is surprisingly precise here. The earlier, the better. Conversely, the number of available options drops dramatically as time passes.

In a business context, this means the following: once a risk materializes, we can only act reactively. We limit our range of treatments to the most invasive and physically taxing options. When we map risks in advance, however, we have a full set of options at our disposal: prevention, mitigation, alternative paths, and prepared decision-making scenarios. And just as importantly, we make all decisions calmly, rather than in a state of panic.

The worst decisions in my company’s history were ones I made personally when “the house was already on fire.” I tried to salvage the situation in a rush, at any cost, and made mistakes I would never have made under normal circumstances. None of those decisions were based on a well-thought-out plan. They were all improvisations made under the pressure of time and emotion.

A matrix that shifts perspectives

When I work with clients on the topic of risk in the strategic process, I most often use a tool that – though it sounds technical – is exceptionally intuitive in practice. It’s a risk matrix based on two variables: the likelihood of a given risk occurring and its impact on the organization.

I start with a standard brainstorming session. At this stage, there are no “silly” risk factors. We gather absolutely everything, including historical risks, industry risks, personnel risks, financial risks, operational risks, and product risks. The larger the team and the more diverse the participants’ experiences, the more comprehensive the map. A single person – even a very experienced one – always has blind spots. I’ll go further: the widest blind spots are usually not found in those who know the least, but in those who know the most. An owner who knows the company inside and out is also the person most prone to cognitive biases – because their knowledge is inextricably intertwined with emotions, habits, and years of decisions that are hard to challenge. That is why this stage should never be a solo exercise.

Then we move on to prioritization. Risks with a high probability of occurrence and a significant impact on the organization are the ones we address first. Risks that are virtually impossible and have a marginal impact – we let them go, at least for now. We evaluate everything in between through the lens of potential consequences. Because a risk with a relatively low probability of occurrence but catastrophic consequences cannot be ignored simply because “it’s too unlikely.”

But even the most thoroughly developed risk assessment process has at least one weak point: the person conducting it. Overconfidence is a classic trap. As I mentioned, this applies in particular to those who know the organization best – namely, its owners and management. The deeper you are in the subject matter, the harder it is to identify your own blind spots. So it’s worth asking yourself not only “what risks do we see?” but also “what unverified assumptions influence what we consider significant?” – and whether we have enough external perspectives to challenge those assumptions. Without this, the entire process may appear very efficient, but it will systematically overlook precisely those risks whose existence we find hardest to admit, as well as those that lie beyond the reach of our perception.

Few people realize that NASA, for example, maintains a catalog of nearly 40,000 asteroids and comets classified as near-Earth objects. It’s a bit scary, but precisely because we monitor their orbits, they don’t keep astronomers up at night. What really worries experts are space rocks – even small ones – whose existence we have no clue about, and which could take us completely by surprise. Just as in 2013, when a meteor explosion took the residents of Chelyabinsk by surprise.

Fortunately, no company has to monitor the trajectories of tens of thousands of “asteroids.” The point is to identify ten, fifteen, or twenty risk factors that could halt growth in the future – and then develop action plans for them, complete with a described scenario, a designated owner, and defined warning signs that will alert us to an impending threat before it’s too late.

Turn risk into opportunity

There is another dimension to this topic that often gets overlooked in discussions. Most organizations treat risk analysis solely as a defensive exercise – a sort of shield against bad things. However, in my view, risk mapping also carries a completely different value: it forces us to act faster and smarter than we would without awareness of the threat.

When we know there is a risk that our current business line might cease to function under certain circumstances, we begin actively seeking ways to diversify. Suddenly, this becomes urgent because the horizon has narrowed, and a vague possibility has become concrete. When we realize that a key employee is a bottleneck, we start thinking about knowledge transfer, redundancy of skills, and succession planning. When we understand that a single client generates 70% of our revenue, we look for new ones before that client slips away for any reason.

The very awareness of risk motivates action. When you think you always have time to make corrections, it’s easier to procrastinate. The moment you crunch the numbers and realize that, in the event of complications, you have six months left to live – everything you’ve been putting off suddenly becomes urgent. Risk is therefore not only a warning but also an accelerator.

“Risk is therefore not only a warning but also an accelerator.”

Can you afford not to have a Plan B?

This dynamic – from threat to opportunity, from weakness to strength – is at the heart of strategic thinking. It’s a bit like a classic SWOT analysis: weaknesses and threats exist to be transformed, not just documented and tucked away in a drawer. Simply realizing that a problem looms on the horizon already triggers adaptive processes that, without proper reflection, simply wouldn’t exist.

Companies that emerged from crises unscathed (and there are far more of them than we think) usually weren’t luckier or had better products than their competitors. Instead, they had better-prepared contingency plans. They knew what to tell their teams and knew what decisions to make and in what order. Thanks to this, they acted faster, more efficiently, and with greater composure – which, in a crisis, becomes an absolute advantage.

Of course, I’m not claiming that risk mapping is easy, nor that a single assessment will suffice forever. It should be a living document that requires updates as the organization grows, the market changes, and new variables emerge. But dedicating a week’s work to this – calmly, with the right people in the room – can protect you from months of crisis and costs that no one could have predicted beforehand.

Not every uncertainty can be eliminated, but most risk factors can be identified, assessed, and managed before they begin to threaten the company. If you want to see where your organization’s resilience truly ends today, talk to our experts.

Don't just fix the symptoms. Start with a diagnosis

Related