Skip to Content

Hazards, Vulnerabilities & "Risk": Enterprise Security & Risk Management

You cannot control the storm, but vulnerability is the variable every organisation can actually manage
22 July 2026 by
Quick answer: Hazards are probabilities an organisation cannot control; vulnerability is the variable it can. The real maturity gap in enterprise security and risk management sits in supply chain fragility and how vulnerability, not hazard, actually gets managed.

Originally published on LinkedIn: 4 March 2026.

A hazard, a flood or a cyber-attack, is a physical phenomenon with measurable parameters and a specific probability of occurrence. It only becomes a disaster when it interacts with a system predisposed to damage. Vulnerability, by contrast, is a socioeconomic parameter reflecting the susceptibility of people, property or systems to that damage, shaped by social, economic, institutional and environmental factors. Risk is commonly expressed as hazard multiplied by vulnerability, which means the external hazard's probability is often fixed, but vulnerability is the variable an organisation can actually reduce.

The double structure of exposure

Vulnerability has an external side, exposure shaped by an organisation's position within a wider ecosystem, and an internal side, coping capacity anchored in human capital, institutional endowments and access to assets. A highly exposed organisation can remain resilient if its internal coping mechanisms, formal policies, adaptive resourcing, are genuinely robust. True maturity sits in strengthening adaptive capacity before stressors trigger system-wide failure, not in hoping exposure stays low.

The maturity gap with your adversary

Vulnerability can also be read as the measurable distance between an organisation's current capability and its adversary's current capability, across systems, capability, competency, resourcing, knowledge and experience. Leaders often focus on an aspirational state years out while the adversary operates in the present. If resourcing and competency stagnate while the adversary's experience grows, vulnerability increases regardless of long-term ambition.

Supply chains as a design problem

In modern supply chains, vulnerability is frequently a design flaw wearing the costume of efficiency. Low-cost sourcing and centralisation optimise short-term balance sheets while creating fragility points that produce catastrophic failure under disruption. The most critical drivers are reliance on single or critical suppliers, long lead times, excessive supply chain complexity, misaligned incentives between partners, and a lack of trust and information-sharing across the network.

Recovery is a choice, not a default

Following a disruption, an organisation can recover to a worse state, having failed to learn and left the system structurally weaker; recover to its original state, ignoring the vulnerability that caused the event and ensuring it repeats; or recover to a better state through genuine continuous improvement. Which outcome occurs is determined largely by whether the organisation treats the event as evidence to build new internal capacity or simply as a problem to be closed out.

Recent frameworks integrate both sides

Contemporary approaches, including the MOVE framework, increasingly treat hazard and vulnerability as interdependent rather than separate problems, combining exposure, sensitivity, resilience and adaptive capacity into a single systems-based model. Organisational vulnerability is reduced through comprehensive security policy, regular training, strong risk culture, and proactive monitoring of external shifts in market demand, political conditions and natural risk, integrated directly into strategic decision-making rather than treated as a separate compliance function.

Where you actually have leverage

Weak strength of knowledge about your own system's barriers is itself a vulnerability. If you do not understand your defences, you are inherently at risk regardless of how the external threat environment behaves. The practical question for any organisation is not whether the storm will come, but whether it is obsessing over external threats it cannot influence, or architecting the internal conditions it can.

If your organisation's risk register is dominated by external threats it has no control over, while the internal vulnerabilities that actually determine impact go unmapped, that is where Tony Ridley focuses most of his advisory work. He helps boards and executive teams close the maturity gap between current capability and current threat, and build supply chain and organisational resilience around vulnerabilities that are genuinely within their control. Contact us to discuss your requirements.

Risk Management Framework: Victorian Government (VGRMF)
Nine mandatory requirements every Victorian public sector agency must meet, and why most overlook several of them