Quick answer: Hazards are probabilities an organisation cannot control; vulnerability is the variable it can. The real maturity gap in enterprise security and risk management sits in supply chain fragility and how vulnerability, not hazard, actually gets managed.
Originally published on LinkedIn: 4 March 2026.
A hazard, a flood or a cyber-attack, is a physical phenomenon with measurable parameters and a specific probability of occurrence. It only becomes a disaster when it interacts with a system predisposed to damage. Vulnerability, by contrast, is a socioeconomic parameter reflecting the susceptibility of people, property or systems to that damage, shaped by social, economic, institutional and environmental factors. Risk is commonly expressed as hazard multiplied by vulnerability, which means the external hazard's probability is often fixed, but vulnerability is the variable an organisation can actually reduce.
The double structure of exposure
Vulnerability has an external side, exposure shaped by an organisation's position within a wider ecosystem, and an internal side, coping capacity anchored in human capital, institutional endowments and access to assets. A highly exposed organisation can remain resilient if its internal coping mechanisms, formal policies, adaptive resourcing, are genuinely robust. True maturity sits in strengthening adaptive capacity before stressors trigger system-wide failure, not in hoping exposure stays low.
The maturity gap with your adversary
Vulnerability can also be read as the measurable distance between an organisation's current capability and its adversary's current capability, across systems, capability, competency, resourcing, knowledge and experience. Leaders often focus on an aspirational state years out while the adversary operates in the present. If resourcing and competency stagnate while the adversary's experience grows, vulnerability increases regardless of long-term ambition.
Supply chains as a design problem
In modern supply chains, vulnerability is frequently a design flaw wearing the costume of efficiency. Low-cost sourcing and centralisation optimise short-term balance sheets while creating fragility points that produce catastrophic failure under disruption. The most critical drivers are reliance on single or critical suppliers, long lead times, excessive supply chain complexity, misaligned incentives between partners, and a lack of trust and information-sharing across the network.
Recovery is a choice, not a default
Following a disruption, an organisation can recover to a worse state, having failed to learn and left the system structurally weaker; recover to its original state, ignoring the vulnerability that caused the event and ensuring it repeats; or recover to a better state through genuine continuous improvement. Which outcome occurs is determined largely by whether the organisation treats the event as evidence to build new internal capacity or simply as a problem to be closed out.
Recent frameworks integrate both sides
Contemporary approaches, including the MOVE framework, increasingly treat hazard and vulnerability as interdependent rather than separate problems, combining exposure, sensitivity, resilience and adaptive capacity into a single systems-based model. Organisational vulnerability is reduced through comprehensive security policy, regular training, strong risk culture, and proactive monitoring of external shifts in market demand, political conditions and natural risk, integrated directly into strategic decision-making rather than treated as a separate compliance function.
Where you actually have leverage
Weak strength of knowledge about your own system's barriers is itself a vulnerability. If you do not understand your defences, you are inherently at risk regardless of how the external threat environment behaves. The practical question for any organisation is not whether the storm will come, but whether it is obsessing over external threats it cannot influence, or architecting the internal conditions it can.
If your organisation's risk register is dominated by external threats it has no control over, while the internal vulnerabilities that actually determine impact go unmapped, that is where Tony Ridley focuses most of his advisory work. He helps boards and executive teams close the maturity gap between current capability and current threat, and build supply chain and organisational resilience around vulnerabilities that are genuinely within their control. Contact us to discuss your requirements.