ProcureTech Insider
What Does Operational Resilience Actually Mean?
Operational Resilience in procurement means one thing. The service keeps running while the things underneath it take hits. Not that nothing goes wrong. That the business carries on when it does.
That is how Jesse Lee, Co-founder and CEO of Brooklyn Solutions, defined it on the Art of Procurement ProcureTech Insider podcast with Jyothi Hartley. The definition is deliberately unglamorous. It is also harder to meet than it sounds.
Jesse Lee on the Art of Procurement ProcureTech Insider podcast with Jyothi Hartley.
Why is that Definition Harder than it Sounds?
Because of what it leaves out. There is no technology in it. There is no mention of preventing disruption. It sets a bar for the outcome and stays silent on the method.
Jesse Lee puts the same idea more bluntly elsewhere in the conversation. “At the core of all of it is operational resilience,” he says. “The business must persist.”
That silence on method is the point. Disruption is not the thing you are managing. Your exposure to it is. A definition built on prevention fails the first time something unforeseen happens, and something unforeseen always happens.
The Stuck Boat is not a Thought Experiment
Jesse Lee reaches for the Suez Canal as a hypothetical. It stopped being one some time ago.
Attacks on shipping that began in 2023 pushed many vessels onto the long route around Africa instead of through the canal. As of April 2026 the IMF reports that transits through the Bab el-Mandeb strait “remain stuck at roughly half their pre-attack level”. UNCTAD had already recorded the collapse: by mid-October 2024, an average of 33 transits a day, 57% below the previous peak.
Read those two figures together and the lesson changes. This is not one boat, stuck for a week. It is a major trade route running at half capacity for years.
Which reframes what resilience is for. Not a plan for a bad fortnight. A standing operating condition.
What do Resilient Practices Actually Look Like?
Deliberately inefficient, in calm weather. Jesse Lee names two, and neither is sophisticated.
“So we have practices built in and are ready for a bit of a rainy day. Maybe we bought more than we need, maybe we sourced from more than one place. So when the one boat gets stuck, we’ve got a few others.”
Both cost you something when nothing goes wrong. That is precisely why they get cut.
| Practice | What it costs in calm weather | What it buys in a storm |
|---|---|---|
| Buying more than you need | Working capital tied up in stock nobody is using yet | Time. The buffer that absorbs the delay while you react |
| Sourcing from more than one place | Volume leverage split, and more relationships to govern | An alternative that already exists, qualified, when a route closes |
Note the tense in that last column. Already exists. A second supplier you have to go and find during the disruption is not resilience. It is procurement under pressure, which is where the bad contracts get signed.
The prior question
Which Service has to Continue, and For How Long?
“The service continues” only means something once you have named the service. Resilience spending has no target until you have.
Which service?
The ones whose failure customers or regulators would actually notice. Not every process you run.
For how long?
How much disruption is survivable before real harm lands. Stated as a number, not a feeling.
How have Regulators Defined the Same Thing?
With the same two questions, made mandatory. UK financial services firms have had to answer them formally, and the framing travels well beyond that sector.
The FCA requires firms to identify their important business services, those that, if disrupted, “could cause intolerable harm to consumers and markets”. For each one, firms set an impact tolerance: “the maximum tolerable disruption to your important business services without causing harm to consumers, firms or markets”. The rules came into force in March 2022. Firms had until 31 March 2025 to have mapped and tested that they can stay inside those tolerances.
Strip out the regulatory language and you have a working method. Name the services that matter. Put a number on the disruption each can absorb. Then test whether that number survives contact with reality.
Jesse Lee makes the related point about where responsibility sits. “Years ago, regulators said you could no longer outsource responsibility for data protection to your suppliers. You are responsible.” The same logic now applies to continuity. Your supplier’s outage is your outage.
Why Resilience is a Data Problem Before it is a Sourcing Problem
Because you cannot diversify a supply base you cannot see. Sourcing from more than one place assumes you know which suppliers serve which service today. Most organisations cannot answer that quickly.
The information exists. It sits in contracts, risk registers and supplier records that were never designed to be read together. Jesse Lee’s line on where the relationship really starts is worth keeping in view here.
“The contract is really the birth certificate. After that, you’re in a relationship together.”
Practically, resilience needs three things joined up. Which suppliers support each important service. What each contract commits them to. What risks are already logged against them. Brooklyn connects third-party risk management, supplier relationship management and contract lifecycle management so those three answers come from one record rather than three teams. For regulated groups, the DORA and governance, risk and compliance views sit on the same data.
This is the same argument as digitally embedded policy, seen from the other end. Policy sets what you expect. Connected data tells you whether it is holding.
The Failure Mode that Multi-Sourcing Misses
Two suppliers, one dependency. That is the trap. You can source from more than one place and still hold a single point of failure. It happens whenever both suppliers lean on the same thing further down the chain.
It might be one logistics provider. One cloud region. One component plant. One certification body. On paper you have diversified. In practice a single incident closes both routes at once.
Jesse Lee’s word for what resilience protects repays reading literally. The underpinnings. Not your suppliers — what holds your suppliers up.
Regulators reached the same conclusion and pushed past the first tier. Under DORA, which entered into application on 17 January 2025, subcontracting arrangements are in scope, not just direct contracts.
So the useful question is not how many suppliers you have. It is how many genuinely independent routes you have to the same outcome. Answering that means mapping dependencies rather than counting vendors.
What does Resilience Buy Beyond Survival?
Room to do something other than firefight. This is the part that gets left out of the business case.
Jesse Lee lists three things supplier governance is for: value for money, operational resilience, and — once in a while — an innovation pursuit. The third depends on the second. An organisation absorbing constant disruption has no capacity spare for anything ambitious.
He is also clear that the stakes rise with scale. “If your business is getting bigger, then supplier management is going to be ever more important to you.” More suppliers means more underpinnings. More underpinnings means more places for a wobble to start.
Hear the Full Conversation
Jesse Lee and Jyothi Hartley cover supplier management as a connected discipline on the Art of Procurement ProcureTech Insider podcast — what the scope really includes today, why operational resilience sits at the core of it, and what to look for in a solution.