Most companies that collapse had plenty of safeguards. They had written and often certified procedures, stable teams, loyal clients, proven systems and centralised sign-off, so every element of an apparent protection was in place.
Their weakness sits somewhere else. A vulnerable company confuses visible mechanisms with real solidity, which explains why its green lights measure the wrong things.

Boeing had quality procedures. Wirecard, the German payments company, had auditors. Credit Suisse met its capital requirements, and Westpac had a regulator watching its international transfers.
Naval Group, the French naval shipbuilder, had a signed contract with the Commonwealth of Australia. Each of these mechanisms looked like a protection, and each one worked as an anaesthetic. They reassured boards and executive teams while the fragility settled in, and the value destroyed across these cases runs into tens of billions of dollars, before counting the jobs lost and the supplier networks affected.
The same mechanism plays out well below the scale of the headlines. According to ASIC, 14,722 Australian companies entered external administration for the first time in 2024-25, up 33.2% on the year before. The false securities described here are just as present in a fifty-person firm as in a listed group.
This article maps nine false securities that appear to protect a company and weaken it beneath the surface. Each one ends with a question that lets a leader test their own exposure.
| The finding | The shift | The approach |
|---|---|---|
| The protections that weakenA vulnerable company rarely lacks safeguards. Its procedures, key talent, large clients, compliance record and approved plans concentrate risk instead of spreading it, while reassuring the executive committee. | Measuring real soliditySolidity is judged by the capacity to hold under pressure, and visible mechanisms reveal little about that capacity. A false security looks exactly like a best practice, which is why it survives every internal review. | Mapping the false securitiesThe approach taken here names the most common false securities, tests exposure to each with a single question and moves the dashboard towards indicators of real solidity rather than displayed solidity. |
Why false securities are so hard to see
A false security is hard to see because it looks exactly like a best practice. It cost money to install, experts validated it, it was announced internally and it produces readable indicators. Challenging a mechanism with that history carries a psychological cost, and that cost is what keeps the false security in place.
The cognitive mechanism that protects them
When a mechanism has cost a lot, carries a consultant’s endorsement and produces tidy indicators, the organisation struggles to question it. Admitting that a protection has become a source of fragility means admitting that a past decision was wrong. That reluctance is the fuel I find behind almost every slow collapse I have studied up close.
Organisational psychology has a name for it. Escalation of commitment, a concept introduced by the organisational psychologist Barry Staw in the 1970s, describes the tendency to keep investing in a course of action because of what it has already cost.
Nokia’s leaders had identified the threat posed by the iPhone by the end of the 2000s. A study by Timo Vuori and Quy Huy published in Administrative Science Quarterly shows that shared fear among top and middle managers neutralised the strategic discussion about the future of Symbian, the company’s smartphone operating system. The security came from everyone being aligned, and that alignment contributed to the company’s fall.
The common signature inside a vulnerable company
The nine false securities share three traits. Each one produces a reassuring short-term indicator, each one concentrates risk instead of spreading it, and each one holds only as long as the environment stays stable. When an external shock exceeds their tolerance, they accelerate the fall instead of cushioning it.
In an environment that has become lastingly unstable, that tolerance threshold gets tested far more often than the people who designed these mechanisms ever expected.

False security 1: excess process
Writing procedures is reassuring, because it gives the feeling that everything has been anticipated and that compliance can be checked. This security mainly protects the legal liability of the people in charge. A procedure has never stopped a collapse, and it often makes fragility invisible by replacing judgement with compliance.
When process replaces judgement
Boeing had an extensive set of quality procedures during the certification of the 737 MAX. Concerns raised inside the company did not travel up to where decisions were made, because the formal alert channel was too costly to use, too visible and too damaging to a career. Process had taken the place of a culture of truth.
In my work with executive teams, leaders often admit that their procedures slow important decisions without reducing the risks. Procedures protect the people in charge during an audit. They offer the company very little when a rupture hits.
The removal test
To spot excess process, ask one question. If you removed part of your internal procedures tomorrow, which ones would genuinely be missed when decisions are made, and which ones would simply make daily life more comfortable for the people who wrote them? The answer sorts protection from paperwork within minutes.
Many leaders then discover that a large share of their procedures protects their own legal liability rather than the organisation itself.
False security 2: dependence on a few key people
Depending on three or four irreplaceable people is rarely seen as a risk. That dependence passes for a strength, because the best people are there, they are loyal and they hold the critical subjects. A talented person who trains nobody and documents nothing turns into a concentrated vulnerability, which shows itself the day they leave.
The risk nobody is steering
In many of the mid-sized companies I work with, a large share of critical knowledge rests on a handful of people. Those people never appear as a risk in the internal risk register. They appear as an asset, so the dependence grows without anyone ever deciding to accept it or to reduce it.
The erosion of knowledge usually precedes the erosion of the accounts. When a long-standing expert leaves, the loss of capability shows up in no financial indicator until delivery on a strategic contract starts to slip and the board asks why.
The apparent security of the loyal expert
A loyal expert who passes nothing on and has no identified successor concentrates risk instead of reducing it. The day that person leaves, falls ill or simply slows down, the organisation discovers how deep its dependence runs, usually at the worst possible moment for a client or a project.
Real security means being able to do without each person without collapsing. It rests on redundancy of knowledge, an organised transfer of skills and a refusal of expertise silos.
False security 3: the client monoculture
Making a large share of revenue with three or four big clients gives comfortable visibility, with predictable income, a well-worn relationship and focused teams. That apparent portfolio quality hides one of the most fragile architectures, because it hands negotiating power to the client and removes the company’s capacity to reinvent itself.
Concentration that passes for a strength
Client concentration becomes lethal through what it prevents during the calm periods. While a big account still looks like good commercial news, nobody invests in diversification. By the time the dependence becomes visible, the sales capacity needed to win other clients has usually been redirected to the dominant account for years.
Naval Group offers a sovereign-scale version of the mechanism. In September 2021, the Australian Government announced that Australia would no longer proceed with the Attack class submarine program with Naval Group, as it moved to nuclear-powered submarines under the AUKUS partnership.
The exit ended in a settlement of €555 million, around A$830 million. A government contract covering decades of work looked like the safest revenue in the industry, and it lasted exactly as long as the client’s strategic priorities.
The threshold beyond which security becomes a trap
I use a simple alert threshold: beyond a quarter of revenue concentrated on a single client, the negotiating balance reverses. The client sets the margins, the deadlines and the terms, and the company gradually becomes a captive supplier whose strategy is written in someone else’s procurement office.
That captivity reassures because it stabilises income, and it removes any room for strategic reinvention.
False security 4: invisible technical debt
Technical debt is the textbook false security. As long as it triggers no incident, it stays invisible, with no entry in the accounts, no executive committee indicator and no budget. In the meantime it compounds its interest and wakes up at a moment chosen by circumstances, never by the company.
The hidden cost of inaction
Technical teams spend a substantial share of their time compensating for simplification or deferral decisions taken years earlier. That cost appears on no identifiable line. It dissolves into delivery speed, quality and team morale, which makes it painless right up to the day the system breaks.
Technical debt is a metaphor coined by the software developer Ward Cunningham in 1992 to describe the future cost of shortcuts taken in a system today. The failures of critical systems I have seen up close followed from debt accumulated over a decade or more, on systems nobody had dared to rebuild during the calm periods for want of a demonstrable return on investment.
The three year rule
Any critical technology component that has not been rebuilt, replaced or seriously tested for more than three years is sleeping debt. It carries risk every day it stays untouched, and the moment it wakes up is chosen by circumstances, which are rarely favourable to the company or its clients.
Keep a register of these components, with the date of their last serious test, and put it in front of the board once a year.
False security 5: centralised decision making
Centralising important decisions at the top reassures the top, since it looks coherent, readable and consistent with a certain idea of executive responsibility. The mechanism weakens the organisation, though, because it turns the leadership team into a bottleneck and separates operational knowledge from operational decisions.
The bottleneck mistaken for rigour
An organisation in which every significant decision goes up to the executive committee turns that committee into a bottleneck. Trade-offs get made under time pressure, and the important subjects drown among those that should be settled three levels below, by the people who actually hold the information.
In the organisations I have worked with, the most centralised ones react markedly more slowly to market changes than those that genuinely distribute decisions. That gap becomes a structural competitive disadvantage the day a competitor moves faster.
What centralisation hides
Centralisation is justified by the quality of the decisions it produces, yet it usually hides unresolved problems of trust and accountability. As long as those problems stay unresolved, decentralising produces chaos. Once they are dealt with, keeping every decision at the top produces sclerosis, and the organisation pays for a caution it no longer needs.
Three realities sit behind most centralised organisations:
- a lack of trust in middle management, which the top rarely names openly;
- a difficulty at the top in letting go of decisions that feel like a personal responsibility;
- and the absence of accountability mechanisms that would make delegation safe for everyone involved.
False security 6: sustained financial performance
Ten years of steady growth and rising margins make a company look solid. That appearance deceives when the performance feeds on exhausting the foundations, through reduced research, outsourced controls and a drift of expertise from engineering to finance. The good numbers then measure the optimisation of the machine rather than its durability.
When good numbers hide the erosion
Boeing between 2010 and 2018 is the archetype. The company posted high margins, a share price that multiplied several times over and massive share buybacks. Over the same period, research spending as a share of revenue fell, quality controls were outsourced and engineering expertise migrated towards finance.
The performance measured the quality of the optimisation rather than the quality of the manufacturing. The bill arrived with a net loss of US$11.8 billion for 2024, deepened by a machinists’ work stoppage and workforce reductions.
Volkswagen in the early 2010s and Wirecard until 2019 followed the same curve, with published performance that kept improving for several years after the structural erosion had begun. Markets, analysts and boards read those numbers as proof of solidity, when they measured the speed at which each company was consuming its invisible capital.
The three ratio test
Three ratios separate healthy performance from performance that consumes the foundations. Track them over five years, side by side, and the trend tells you whether your results come from building capacity or from spending the capacity your predecessors built. The direction of the curves matters more than their level.
- The trend in the research to revenue ratio over five years.
- The trend in net productive investment relative to depreciation.
- The share of executive pay tied to criteria other than financial ones.
If the first two fall and the third tends towards zero, the performance on display measures the optimisation of the machine rather than its durability.
False security 7: regulatory compliance seen as a shield
Being in order is reassuring. Certifications, audits, reporting and an approved risk map give the feeling that the subject has been covered. Compliance measures rules written in the past, though, and it says nothing about emerging risks, toxic cultural dynamics or the gap between what the organisation says and what it does.
Compliance and solidity are two different things
Credit Suisse met its regulatory capital and liquidity requirements, according to the post-crisis review by FINMA, the Swiss Financial Market Supervisory Authority. Those ratios could not stop the loss of confidence that brought the bank to the brink of insolvency and to its takeover by UBS, a rival Swiss bank, in March 2023.
FINMA’s own report states that the bank satisfied the capital requirements and complied with the liquidity rules, and that neither was enough to prevent the crisis of confidence. Wirecard, for its part, had its accounts signed off by a Big Four audit firm year after year. Germany’s Auditor Oversight Body later found breaches of professional duty in the 2016 to 2018 audits and banned the firm from new public interest audits for two years.
Australia has its own version. The Federal Court ordered Westpac to pay a $1.3 billion penalty, the highest civil penalty in Australian history at the time, after the bank admitted to more than 23 million breaches of anti-money laundering law. AUSTRAC, the national financial intelligence agency, said breaches on that scale could have been avoided with better assurance and oversight.
In each case, compliance kept working while the underlying architecture failed. Ticking the right boxes delayed the identification of the real flaws, and compliance served as an anaesthetic rather than as a warning signal.
What compliance will never measure
Compliance measures rules set in the past. It ignores emerging risks, internal cultures that are degrading, fragile architectures and the distance between what the organisation says it does and what it actually does. A leadership team that reassures itself with its compliance record is steering by the rear-view mirror.
The mirror is useful for avoiding a repeat of past accidents, and useless for anticipating the next ones.
False security 8: the company culture on display
A values charter, offsites, engagement surveys and wellbeing programs give the feeling of having invested in the culture. In many cases, the investment goes into how the culture feels rather than into the culture itself. The gap between the declared culture and the lived culture measures exactly the vulnerability that has accumulated.
The gap between declared culture and lived culture
In most organisations I work with, the values printed on the wall and the values staff actually experience sit a long way apart. That gap measures the distance between the story the organisation tells itself and what it has become, and the wider it grows, the more the leadership loses contact with internal reality.
Rio Tinto, the Anglo-Australian mining group, shows both the mechanism and a way out of it. The external review it commissioned from Elizabeth Broderick, a former Australian Sex Discrimination Commissioner, identified bullying, sexual harassment, racism and other forms of discrimination throughout the company.
The company’s leadership then stated publicly that it felt shame to learn these behaviours were systemic across its workplaces. The declared culture had never measured the lived one, and it took a large-scale independent listening exercise to make the gap visible.
The leaver test
A simple test measures the depth of the real culture. Ask three people who left in the past six months, at different levels of the hierarchy, what made them leave and what they would tell a friend tempted to join the company. Then compare their answers with your official engagement results.
The gap between their answers and the official discourse measures the cultural debt that has accumulated.
False security 9: the written and approved strategy
A three-year strategic plan, approved by the board and broken down into roadmaps, is reassuring because it makes a shared direction visible. It is one of the hardest false securities to challenge, because everybody contributed to it and everybody has an interest in it surviving, even after the facts have contradicted it.
The trap of a plan that outlives its obsolescence
Many of the three-year plans I review are contradicted by events well before their end date. They nevertheless keep structuring the annual objectives until the last day, because no authority in the company is willing to suspend them. The plan then commits energy and budget to assumptions that nobody still believes.
An unrevised plan becomes more dangerous than having no plan at all. The organisation keeps executing with discipline, which makes the drift look like rigour.
Revising the strategy is a sign of strength
The idea that a company must stick to its plan whatever the cost runs deep and is dangerous. A strategy remains a hypothesis about the future. When the future contradicts the hypothesis, the hypothesis is what needs revising, and the leaders who revise early keep the most options open.
A solid organisation separates the long-term course, which can hold for ten years, from the execution strategy, which is revised every year and amended every quarter if conditions justify it.
Field note
The committee that believed its certifications protected it
During an executive offsite, I asked a simple question: name a mechanism that reassures you today and that, in your view, perhaps should not. Nobody answered at first. Then one director mentioned their quality certification, renewed without a hitch for eight years.
Nobody in the room had ever connected that certification to an incident it had actually prevented. It served as proof of seriousness rather than as a safety net.
Digging further, the committee realised that three of its sources of pride concentrated most of its risk: the stability of its leadership team, the loyalty of its two largest clients and the reliability of its main production site. None of those sources of pride appeared as a vulnerability in its dashboards.
A false security is spotted less through analysis than through discomfort. When a leader hesitates to answer that question, the most expensive blind spot is usually hiding right there.
The common logic of the nine false securities
The nine mechanisms share the same mental architecture. They move the measurement of risk towards what is easy to measure and leave in the blind spot what is hard to measure and decisive. Displayed solidity takes the place of real solidity, and the dashboard stays green until the day it stops meaning anything.
The shared mental architecture
Each false security substitutes a comfortable indicator for an uncomfortable reality. Process replaces judgement, compliance replaces vigilance, the plan replaces adaptation and displayed performance replaces structural health. Comfort in steering the company becomes the main symptom, and the diagnosis requires leaders to look at what disturbs them.
The overall exposure test
To assess your organisation’s overall exposure to false securities, ask nine questions, one per mechanism. Answer them with your leadership team rather than alone, and write down the answers that nobody wants to give. Those uncomfortable answers are the most reliable data you will collect in the whole exercise.
- If I removed a significant share of our procedures, which ones would genuinely be missed when decisions are made?
- How many people, if they left tomorrow, would create a major operational problem?
- What share of our revenue depends on fewer than five clients?
- Which critical technology component has not been rebuilt for more than three years?
- How many day-to-day operational decisions go up to the executive committee each month?
- Has our research to revenue ratio risen or fallen over five years?
- When did our last regulatory compliance review reveal a problem we did not already know about?
- What is the gap between our official engagement survey and what leavers actually say?
- Does our current strategic plan still rest on the assumptions that governed its approval?
The number of answers that make you uncomfortable is a fairly good measure of your organisation’s real exposure. It measures your level of vulnerability rather than your level of performance.
Measuring and moving forward
Four structural indicators track the quality of your real safeguards over time, as opposed to the safeguards on display. Three dynamics complete the dashboard by signalling drift before it becomes visible in the accounts. Together they give an executive committee a way to measure solidity instead of assuming it.
What you measure
The four structural indicators each measure a concentration of risk that the usual dashboards leave out. Review them twice a year at board level, with the same definitions each time, so that the trend becomes readable and the definitions cannot drift to flatter the result.
- The concentration of critical knowledge, meaning the share of decisive operational knowledge held by a tiny fraction of the workforce. Beyond a high threshold, the organisation enters the red zone.
- Commercial concentration, meaning the share of revenue generated with the top five clients. Beyond half, the negotiating margin turns against the company.
- Active technical debt, meaning the team time devoted to compensating for old simplification decisions. When it is too high, the company is funding its past with its present.
- The gap between declared culture and lived culture, measured by triangulating the engagement survey, exit interviews and observation in the field.
What you watch
Three dynamics signal drift earlier than the structural indicators do. They move before the numbers, which makes them uncomfortable to track and valuable to act on. Watch them every quarter, and treat any sudden change without an external explanation as a signal that deserves its own agenda item.
- Decision speed on cross-functional subjects, a reliable indicator of the real degree of centralisation. When it slows with no external reason, centralisation is tightening.
- The rate at which bad news travels upwards, measured by the alerts raised spontaneously by the middle levels all the way to the top. In my experience, its decline precedes internal crises.
- The frequency of documented challenges to the strategic plan. Fewer than one substantial revision a year signals a strategy that is outliving its obsolescence.
Over the next twelve months, run an audit of the nine false securities at a rate of one per month, starting with the three that make you most uncomfortable. Once a quarter, put a simple question on the agenda: what is reassuring us at the moment that perhaps should not be reassuring us?
How to choose the right approach to test your false securities
Leaders who want to test their false securities usually choose between four approaches: an internal audit, a formal risk management framework, a board self-review or an external diagnostic. Each one sees certain risks clearly and misses others, so the right choice depends on what you most need to see and who you need to convince.
Four approaches compared against the same criteria
The four approaches differ most on one criterion: their ability to question a mechanism the organisation is proud of. The table below compares them on what each measures well, what each tends to miss and the situation in which each one makes sense for an executive committee weighing its options.
One of them relies on ISO 31000, the international standard published by the International Organization for Standardization that sets out guidelines for managing risk across an organisation.
| Approach | What it measures well | What it tends to miss | When it makes sense |
|---|---|---|---|
| Internal audit | Compliance with existing controls and procedures | Risks nobody has written down, and mechanisms leadership regards as strengths | When a regulator, lender or board needs assurance on known risks |
| Risk framework aligned with ISO 31000 | Consistent identification and treatment of risks across the organisation | Risks hidden inside sources of pride, since the register reflects what people agree to call a risk | When the organisation lacks a shared language for risk |
| Board or executive self-review | Speed, and ownership by the people who decide | Blind spots shared by everyone at the table | When trust in the leadership team is high and a first pass is needed quickly |
| External diagnostic | Reassuring mechanisms and the distance between displayed and real solidity | Operational detail that only insiders hold | When the executive committee suspects its green lights measure the wrong things |
Which signals should guide your choice
Three signals should guide the choice: who needs convincing, how long the organisation has gone without an unpleasant surprise, and whether anyone at the table can challenge the leader without paying for it. Each signal points towards a different approach, and reading them honestly usually settles the question in one meeting.
- If the audience is external, such as a regulator or a lender, internal audit or a formal framework gives the evidence they expect.
- If the company has gone years without an unpleasant surprise, the absence of bad news is itself the warning sign, and an outside view becomes worth its cost.
- If nobody at the table can contradict the leader safely, a self-review will confirm what everyone already believes.
The approaches also combine well. A self-review can open the conversation, and a formal framework or an outside diagnostic can then test the answers the leadership team found easiest to give.
Turn your false securities into real solidity
Want to build an organisation that holds under pressure instead of one that only looks solid? Discover my full definition of the invulnerable company and the architecture it requires in the dedicated article.
How I can help you unmask your false securities
I work with executive committees that want to separate their real safeguards from the ones on display. My work combines a keynote that builds shared vocabulary, a diagnostic that turns clarity into indicators you track, and a prioritisation workshop that decides where to start among the nine.
The keynote that wakes up the blind spots
I speak to executive committees and leadership teams to make visible the mechanisms that reassure them for the wrong reasons. The keynote provides a shared vocabulary, documented examples and a reading grid that turns an abstract subject into an operational conversation the team can continue after I leave the room.
The aim is to put the uncomfortable question in the room and to give leaders collective permission to examine it head on. The content is set out on the page for the keynote on becoming an invulnerable organisation.
The false securities diagnostic
Beyond the keynote, I work with organisations that want to move from observation to measurement. The diagnostic translates the nine mechanisms into concrete indicators, identifies the priority blind spots and sets the review cadence that keeps vigilance alive over time, inside the committee meetings you already hold.
The deliverable takes the form of a dashboard of real solidity, designed to live in your committee meetings rather than sleep in a folder. You can prepare for it by taking the invulnerability diagnostic for your company.
The prioritisation workshop
The workshop deals with the only question that matters after the diagnostic: where to start among the nine. It weighs the effort each correction demands against the time left before each false security becomes irreversible, and it produces a decision rather than a plan with nine separate workstreams.
If you would like to talk through what this would mean for your organisation, contact me directly.
Conclusion
A vulnerable company almost always has protections. Its weakness lies in what those protections measure: compliance, displayed performance, the appearance of order and surface stability. None of them measures the real capacity to hold under pressure, which is the only quality that counts on the day of the shock.
Spotting these nine mechanisms is a matter of clear sight more than analysis, because what reassures you today is often what will expose you tomorrow.
A false security looks exactly like a best practice.
One question deserves a place at your next executive committee. Among the nine false securities described here, which one does your organisation regard most as a strength, and what mechanism have you installed to check that it is not turning into a vulnerability? The answer that comes least easily usually points to the most expensive blind spot of a vulnerable company.
Frequently asked questions about the vulnerable company
What makes a company vulnerable?
A company becomes vulnerable when its protective mechanisms measure something other than its real solidity. It has procedures, certifications and good results, and those reassuring signals mask a concentration of risk that reveals itself at the first serious external shock, often in a part of the business nobody was watching.
What is a false sense of security in business?
A false sense of security comes from a mechanism that produces a reassuring short-term indicator, concentrates risk instead of spreading it and holds only while the environment stays stable. The best revealer is discomfort: a mechanism nobody dares to question almost always deserves to be examined again.
Does regulatory compliance protect a company from collapse?
Compliance protects a company from the audit more than from reality. It measures rules written in the past and stays silent on emerging risks, degrading internal cultures and fragile architectures. Credit Suisse met its capital and liquidity requirements until the crisis of confidence that ended in its takeover by UBS.
Why is relying on one big client risky for a business?
Beyond roughly a quarter of revenue concentrated on one client, the balance of power reverses. The client sets the margins, the deadlines and the terms, and the business becomes a captive supplier. That stable income removes the room for strategic reinvention and leaves the company exposed to a single decision.
How can a business reduce its vulnerability?
A business reduces its vulnerability by measuring real solidity: concentration of critical knowledge, commercial concentration, active technical debt and the gap between declared and lived culture. Auditing one false security a month, starting with the one that makes the leadership team most uncomfortable, gets the movement going.




