You cannot reduce, plan for, or fortify against a risk you have never named, and most businesses have never systematically looked.
The fault lines are already there: key-person dependence, dangerous concentration, single points of failure. They are simply invisible until one of them gives way. This is the most upstream guide in the pathway, because everything downstream depends on knowing what your risks actually are and which ones matter most. This guide finds them. It inventories the structural risks across the whole business, weighs each by how likely it is and how badly it would hurt so effort goes where it counts, and maps the places where one loss would cripple you.
Plan on a couple of honest sessions, and a real view of the people, customers, suppliers, and systems the business runs on. This is not about imagining every conceivable disaster. It is about surfacing the handful of things that could actually end the business, and putting them in order.
Surface the full range first, so nothing significant stays hidden until it fails. Work across the categories that matter: key-person, revenue and customer concentration, supplier and input dependency, operational and system single points of failure, financial fragility, and external threats. The goal is a complete, honest list, including the risks you would rather not think about.
You cannot manage a risk you have not named, and the ones that end businesses are usually the ones nobody wrote down. Aim for completeness over comfort here; the sorting comes next.
Open the Structural Risk Inventory →A long list of risks treated as equal is paralysing and useless. Weigh each on two axes, how likely it is and how badly it would hurt, so you can rank them and find the vital few that are both plausible and serious.
This is measurement applied to risk, and it is what keeps this whole pathway from becoming a catalogue of paranoia. Not every risk deserves your attention; the point is to separate the ones that do from the ones that do not.
Open the Risk Assessment Matrix →Now get specific about the sharpest risks of all: the one person, one customer, one supplier, one system whose loss would stop or seriously damage the business. Name each precisely.
Single points of failure are the most dangerous structural risks because they concentrate catastrophe in one place. Naming them precisely is exactly what makes them fixable, and each one you remove eliminates a whole category of disaster at once.
Open the Single Point of Failure Map →Pull the serious-and-plausible risks and the single points of failure into a short list to act on first, and route each to the reduction or planning work it needs. A prioritized short list turns a daunting risk picture into a manageable plan; trying to fix everything fixes nothing.
If your top risk is that everything depends on one or two people, that is its own guide, and it is usually the sharpest structural risk a business carries. Finish prioritizing here, then go straight to it. Reduce Key-Person Risk →
Build the habit of revisiting the inventory as the business grows and changes, because new dependencies, concentrations, and single points of failure form constantly. A risk picture built once and never updated is a snapshot of yesterday's fragility.
This is where identification connects to the ongoing monitoring later in the pathway; the register you build there is fed by the inventory you keep alive here.
Return to the Structural Risk Inventory →You have a complete, honest inventory of your structural risks. Each is assessed by likelihood and impact rather than treated as equal. You have mapped your single points of failure precisely, and you have a short list of the vital few to act on. That is the move from unexamined risk toward a clear, prioritized picture you can act on (Measurement and Systems: Level 2 toward Level 3).
With the risks named and ranked, you go to whichever reduction guide your top risk points to: key-person, concentration, continuity, or resilience. For most businesses the first stop is key-person risk, because it is the sharpest of all. Reduce Key-Person Risk →