What happens when a business suddenly cannot operate as normal?
It could be a cyber-attack, a cloud outage, a critical supplier failing or some other major disruption. Whatever the cause, there is one thing companies cannot assume: that everything will keep running.
That raises a more fundamental question: What actually has to keep working?
For Moira Cronin, Digital Risk and Resilience Partner at PwC Ireland, the answer starts with four things: “Can we keep our customers and our people safe and away from harm? Can we remain financially viable? Can we maintain market trust? And can we meet our regulatory obligations?”
Those four questions sit at the heart of PwC’s Minimum Viable Company, or MVC, framework. The idea is relatively simple. Rather than trying to protect everything equally when a crisis hits, an organisation should know in advance which services and capabilities are essential to its survival.
It is a deceptively straightforward concept. But putting it into practice means confronting some uncomfortable questions about how much a company really knows about itself.
Rachel Higham, a strategic adviser to PwC and non-executive director who has held senior technology roles in major international companies, says the biggest problem is often what organisations do not know.
“It’s mainly what we don’t know, because very few organisations are strong at understanding their technology estate in full, its boundaries, its vulnerabilities, how it all links together and connects,” Higham says.
The human glue
Companies may appear to run smoothly every day, but that does not necessarily mean they understand how they would operate if their normal systems disappeared.
Higham describes the people inside an organisation as its “human glue”.
“It’s the corporate memory, the humans in their organisation who understand how processes work, but they’ve never written them down, so if they had to rebuild them from scratch, they have the design blueprint,” she says,
The way Higham sees it, that knowledge can become particularly important when a crisis hits.
“When you’re in a crisis, you’re always reliant on a very small number of people, usually eight to 10 people who really understand how the business sticks together to be able to describe to the technology team how to rebuild and then restore the systems that have been lost,” she says.
For Higham, resilience is ultimately about the ability to recover.
“Fundamentally it’s the ability to bounce back,” she says. “It’s how quickly and how completely you can return to the situation before the crisis hit.”
What happens when everything goes wrong?
For a board, Higham says, the first requirement is situational awareness.
“They need to be very clear on where they are and what they know. And what they don’t know? What assumptions are they making, and when will they know the next thing?” she says.
The board also needs to understand the levers available to management when the organisation is under pressure.
“You need to understand what levers you have that you can pull in terms of shrinking the services you’re offering, turning some off, degrading some, not interacting with certain suppliers, delaying payments,” Higham says.
The objective is not to keep everything going indefinitely. It is to make deliberate choices about what matters most.

“You need to understand all the things you can stop or slow down to make key decisions on what your minimum company is that you’re going to run through the crisis and give you time to recover everything else,” she says.
For Cronin, the challenge is then to turn those decisions into something operational.
“It’s about operationalising that, because they’re ultimately the concerns of the company – people first and processes follow,” she says, adding: “This could be with a critical supplier or with a third party. That third party may not be geographically located in the same country as you.”
Cronin says companies need to understand not just their own critical processes but the external dependencies that allow those processes to function.
Furthermore, she says that managing a crisis can involve a significant number of people working across different areas.
“There’s a huge operational element here that can take anywhere up to 10 to 15 people to just run one aspect of it,” she says.
Finding the Minimum Viable Company
So how do you actually identify what is critical?
Cronin says the process starts with the executive team and a simple exercise: take the services the organisation provides and test them against the four core questions.
“Typically to build out the MVC we get together in a room with a number of the Executive Team, and really what we’re doing at that point is saying ‘Okay, here are all the outcomes that we could potentially offer, and now we’re going to put each one of them through a lens, and they’re the four lenses of customer lens, your financial viability, your market trust, or your regulatory lens.”
The question is then straightforward.
“‘If we were in a crisis situation, and we did not have that service available, would it impact any of those four core questions?’ Very quickly you come to a picture of what is absolutely critical.”
The exercise is designed to strip away some of the assumptions that accumulate in a functioning organisation.
As an experienced board member, Higham says there are three questions she would ask management.
“The first is for the Executive Team as a whole, what are the five to 10 things that must keep running through a serious disruption?
“The second is for the three most critical processes. Are they prepared to run them manually for the volume of transactions that occur during a crisis outage?”
And then there is technology.
“And then from a technology perspective, how disruptively have they tested their ability to recover?” she says, adding: “If they haven’t tested the ability to rebuild into a new environment, rather than just restore into what is now a crime scene, then they haven’t really got a viable restore plan.”
Boards cannot leave it to the technology people
Higham says board members can sometimes rely too heavily on the one person around the table who has a technology background.
“Or they switch and look at the one person who has technology experience and rely on them to make the judgement of the whole board, and that’s a wrong approach,” she says.
Her view is that the responsibility belongs collectively to the board.
“All board members need to be upskilling themselves in risk resilience, technology/cyber resilience matters. They can’t delegate it to a single board member. They are collectively responsible for protecting the value of the organisation, so upskilling is a key part of being a board member,” she says.
Cronin agrees, but argues that the answer is not necessarily for executives to become technology experts.
Instead, they need to be able to ask basic questions and receive understandable answers.
“There’s also the ability to ask basic questions in business English, because that’s the way it should be delivered,” she says.
“Resilience is not just an IT issue. Resilience is a business issue. If your systems go down, the issue will be that the business cannot operate.”
AI creates another resilience problem
The rise of artificial intelligence adds another complication.
Cronin sees AI as both a potential resilience tool and a source of additional risk.
“When I look at AI from a resilience perspective, it can help, but it can also hinder,” she says.
For Higham, AI is increasingly being introduced into the core of businesses, sometimes without the technology function having full visibility of what is happening.
“We’re quietly putting AI into the mission-critical core of an organisation,” she says. “Business teams are building agents and AI solutions without technology teams potentially being aware. If a technology team doesn’t know something exists, it can’t recover it in a crisis.”
There is also a human consequence.
“Every time you hand a process over to a model or an agent, and you’re letting the people go who used to run that process, you’re eliminating your manual fallback position,” she says, explaining that this means a company can inadvertently make itself less resilient in the pursuit of greater efficiency.
“If that model or agent or vendor is unavailable, you suddenly have no one who understands the process and no one to run it in a crisis scenario,” she says.
Testing is therefore critical.
But Higham argues that many companies test in conditions that are too orderly to resemble an actual crisis.
“What I mean by that is that the reality is not an ordered, structured tabletop exercise,” she says, arguing that executives should be exposed to the kind of uncertainty they would actually face.
“It’s taking executives out of the organisation for a day/two days/three days, putting them under intense pressure, throwing an enormous amount of information that’s incomplete and inaccurate and contradictory at them, and having them practise the muscle of finding the signals in the noise, and then making decisions with imperfect information that will be judged with hindsight later on over a sustained period of time,” Higham says.
Cronin goes a step further.
“When you test your business continuity plan, it should fail,” she says,
Her reasoning is that a test which always passes may not have been sufficiently demanding.
“So, I’ll give you an example where something might actually work for 20 hours, but actually if you pushed it to 21 it’ll break. So, unless you’re seeing the breakage, then it isn’t fully tested,” she says.
Preparing before the crisis
For Cronin, the practical starting point is to define the Minimum Viable Company before it is needed.
From there, she says the organisation needs to map the processes and dependencies that sit underneath those critical outcomes.
“That’s everything from business processes down to IT and out to your critical third-party suppliers,” Cronin says.
Higham says this also means moving beyond compliance.
“I think we’re coming from a history of compliance around resilience, even in the regulated industries, in financial services, in critical national infrastructure, people have got to the point of writing down their plans, but have they disruptively tested them enough?” she says.
The regulations may require organisations to identify what must not stop in a crisis. But Higham says resilience requires another set of decisions: what can stop, what can be degraded and in what sequence should everything be restored.
That is ultimately the difference between having a plan and knowing whether the plan works.
For Cronin, the final question is one every organisation should be able to answer.
“I really want business leaders to understand what if they were in this situation? Have they defined their minimum viable company, and do they know what they would do in a scenario where none of this was available?”
And there is one final complication: the next crisis may not be a single crisis.
“Not to just look at one crisis, but actually multiple crises at the same time.”
For Higham, the message is equally direct.
“To go and look at their existing business continuity plans and IT disaster recovery plans, and check what the assumption is about how long technology will be unavailable – if it is 24-48 hours, they don’t have a realistic plan.”

The Tech Agenda with Ian Kehoe podcast series is sponsored by PwC.