There is a particular kind of organisation that looks excellent right up until the moment it does not.

Its schedules are tight. Its staffing model is lean. Its suppliers arrive just in time. Every role is fully utilised, and every process has been stripped of anything that appears unnecessary.

On a dashboard, it looks disciplined. In a presentation, it looks modern.

Then a key person becomes unavailable. A supplier misses a delivery. Demand moves in an unexpected direction. A familiar risk arrives in an unfamiliar form.

Suddenly, there is nowhere for the pressure to go.

The organisation has removed delays, duplication and spare capacity. It has also removed many of the things that might have helped it recover.

This is the uncomfortable edge of efficiency: a system can become so well optimised for normal conditions that it loses the ability to cope with abnormal ones.

Efficiency is not the problem. It matters. Waste consumes time, money and attention that could be used elsewhere. Poorly designed processes frustrate staff and customers alike. No serious organisation should defend needless complexity simply because it has always been there.

But efficiency is a means, not a governing value.

When it becomes the sole measure of good design, it can quietly turn strength into brittleness.

The Appeal of the Perfectly Lean System

Efficiency promises something leaders understandably want: more output from fewer resources.

It rewards shorter cycle times, lower inventories, reduced staffing costs, fewer handovers and less duplication. These improvements are visible and countable. Their benefits often arrive quickly.

A resilience measure is harder to defend because its value may remain invisible for years.

Spare capacity can look like idleness. A second supplier can look unnecessarily expensive. Time reserved for reflection can look unproductive. Training someone to cover a colleague’s role can appear less urgent than completing today’s work.

The pressure, therefore, runs in one direction:

Remove the buffer. Combine the roles. Standardise the response. Fill the empty space.

Each decision can make sense on its own. Together, they change the character of the system.

A hospital operating close to full capacity may use its beds efficiently on an ordinary day, but it has little room for a sudden influx of patients.

A team dependent on one highly capable employee may appear lean, but a great deal of organisational knowledge walks out of the door when that person leaves.

A supply chain built around one low-cost provider may perform beautifully until transport disruption, political instability, extreme weather or insolvency interrupts it.

In every case, the system succeeds by assuming that tomorrow will resemble yesterday.

That assumption is doing more work than the efficiency calculation admits.

What Looks Like Waste May Be Carrying Resilience

Nature rarely builds living systems around perfect utilisation.

A healthy body has paired organs, energy reserves and overlapping ways to respond to injury. An ecosystem contains diversity that may appear redundant until conditions change. Not every part is active at maximum capacity all the time.

Organisations also depend on reserves, alternatives and overlaps. We simply give them less flattering names.

We call them excess inventory, duplicated knowledge, spare time, backup suppliers or unused capacity. Because they do not always contribute directly to today’s output, they are easy targets for removal.

Yet these margins often perform a second job.

They absorb surprise.

A little unused capacity allows a team to respond to urgent work without abandoning everything else.

Overlapping knowledge enables a colleague to step in when someone is absent.

More than one route to a critical outcome prevents a single point of failure.

Time between tasks gives people room to notice weak signals, ask questions and correct mistakes before they travel further.

This does not mean every inefficiency is secretly valuable. Some duplication is merely confusion. Some inventory really is waste. Some meetings can disappear without consequence.

The point is more precise: before removing slack, leaders should ask what function it performs under pressure.

If the answer is “none,” remove it.

If the answer is “it gives us time, options, memory or room to recover,” it is not waste in the ordinary sense.

It is resilience capacity.

Fragility Hides During Good Weather

The difficulty is that a fragile organisation can perform well for a long time.

When demand is predictable, technology behaves, staff remain in place and partners fulfil their obligations, a tightly optimised system may outperform a more cautious one. Its costs are lower and its pace is faster.

Leaders receive repeated confirmation that the design works.

But the evidence is incomplete.

The system has been tested only against expected conditions.

That distinction matters because resilience is not simply reliable performance during calm periods. It is the ability to continue, adapt and recover when the organisation’s operating assumptions no longer hold.

A bridge is not judged only by how well it carries ordinary traffic on a clear morning. Its design must also account for wind, weight, fatigue and failure.

Organisational systems deserve the same seriousness.

The question is not only:

“How efficiently does this work today?”

It is also:

“What happens when one of its assumptions fails?”

Fragility often reveals itself through concentration:

One person holds knowledge no one else can access.

One supplier supports a critical service.

One metric drives decisions across a complex operation.

One approval route brings everything to a halt when its owner is absent.

One platform carries data, communication and workflow without a credible fallback.

One standard process is expected to handle every context.

Concentration can reduce cost and coordination.

It can also turn a local failure into an organisational one.

People Become the Hidden Buffer

When formal systems are designed without enough room to absorb variation, people usually compensate.

They work through lunch. They stay late. They remember exceptions that were never documented. They maintain unofficial spreadsheets, call trusted contacts and quietly correct faults before customers notice.

The organisation appears efficient because employees are carrying its missing capacity in their bodies, memories and relationships.

This is not resilience.

It is concealed strain.

For a time, committed people can make a brittle system look robust. Their judgement, goodwill and extra effort smooth the gaps between the process as designed and reality as encountered.

Leaders may even treat this as evidence of a strong culture.

But a system that depends on routine heroics is borrowing from its future.

Fatigue accumulates. Experienced staff leave. Small errors become harder to catch. The people who remain learn that every disruption will be solved by asking more of them.

Eventually, the buffer fails.

A genuinely resilient organisation values human judgement without exploiting it. It designs roles with enough capacity for people to think, learn and respond. It makes critical knowledge shareable. It treats recovery time as part of sustainable performance, not as a reward granted after exhaustion.

The aim is not to eliminate effort.

It is to stop using extraordinary effort as an ordinary operating model.

The Danger of Optimising One Measure

Efficiency becomes especially dangerous when a single measure stands in for the health of the entire system.

A call centre reduces average handling time, but customers call back because their issues were not resolved.

A warehouse increases picking speed, but injuries and errors rise.

A public service processes more cases, but complex needs are pushed aside because they threaten the target.

A team fills every hour with delivery work, then has no time to improve the process creating the work.

The metric moves in the desired direction.

The wider system pays the bill.

This happens because people adapt to what is measured. If speed is rewarded without equal attention to quality, learning or recovery, speed will win.

If utilisation is treated as success, every available hour will be filled—even when thinking time is essential to sound work.

Useful measures should reveal trade-offs, not hide them.

Cost belongs beside continuity.

Speed belongs beside quality.

Utilisation belongs beside workload sustainability.

Output belongs beside the organisation’s ability to recover from error.

No dashboard can remove the need for judgement. It can only help people exercise it with a fuller view.

Designing for Graceful Failure

Strong systems do not pretend that failure can be eliminated.

They are designed so that failure is contained, visible and recoverable.

Engineers sometimes describe this as graceful degradation: when one part stops working, the whole system does not collapse at once. Performance may reduce, but essential functions continue.

Organisations can design for the same outcome.

They can identify the services that must continue under pressure and decide in advance what can pause.

They can cross-train people in critical roles.

They can maintain alternative suppliers or channels where the consequences of interruption are high.

They can create simple manual fallbacks for digital systems.

They can give frontline staff clear authority to respond when the standard route no longer fits.

Most importantly, they can rehearse.

A continuity plan that has never been tested is a statement of hope.

A contact list that has not been updated is not a fallback.

A deputy who has never made the decision is not yet genuine cover.

Short simulations, scenario discussions and after-action reviews expose assumptions while there is still time to act.

They also reveal something a process map often misses: how people actually communicate, improvise and make sense of incomplete information.

A Better Question Than “Can We Make This Leaner?”

Leaders do not need to choose between efficiency and resilience as if one represents discipline and the other represents caution.

The real work is deciding where efficiency is appropriate and where protective margin is essential.

That begins with better questions:

What assumptions must remain true for this process to work?

Where are our single points of failure?

Which knowledge, relationship or capability is concentrated in one place?

What is the smallest disruption that could stop a critical service?

Which apparent inefficiencies give us options under pressure?

Where are employees compensating for weak design through unpaid or invisible effort?

If demand increased sharply tomorrow, what would fail first?

How quickly could we restore the service, and have we tested that belief?

The answers will not justify unlimited reserves everywhere.

Resilience has a cost, and not every process carries the same risk. A low-consequence administrative task may be designed mainly for efficiency. A safeguarding decision, essential public service or critical data system deserves more protection.

The level of redundancy should follow the consequences of failure.

That is a strategic choice, not an operational detail.

Keep Enough Room to Move

The strongest organisations are not the ones that predict every disruption. That is impossible.

They are the ones that retain enough capacity, knowledge, trust and choice to respond when prediction fails.

They know where they can run lean and where they cannot.

They distinguish waste from protective margin.

They refuse to call chronic overwork efficiency.

They judge performance across time, not only at the end of the quarter.

This may mean accepting a small, visible cost today to avoid a much larger, hidden cost tomorrow.

It may mean keeping a second option open, giving a team breathing space or protecting work that does not produce an immediate return.

These choices can look inefficient when conditions are calm.

That is precisely when they must be made.

Once disruption arrives, spare capacity cannot always be purchased quickly. Trust cannot be commissioned overnight. Knowledge cannot be recovered from someone who has already left. A fallback cannot be invented at the same speed as a crisis unfolds.

Efficiency asks:

“How little do we need when everything works?”

Resilience asks:

“What will we wish we had kept when it does not?”

An organisation designed to endure must be able to answer both.