The Week You Can't Operate
Picture the systems going down on a Tuesday. Not a bad day, a hard stop. No order entry, no shipping labels, no access to the customer records, or the phone lines are dead, or the one plant that makes the part that goes in everything else is offline and nobody can tell you for how long. Now count. How many days can the business sit like that before something breaks that doesn't come back, a contract, a key customer, the payroll you have to make anyway?
Most owners have never run that number, and it's the exact number a careful lender or buyer runs for them. Continuity is not a fire drill you file and forget. It's a live question about how much interruption your specific business can absorb, and the honest answer sits directly under your valuation and your borrowing terms.
Two ways the lights go out
The threats that put a smaller company on the floor tend to come from two directions, and both have gotten worse, not better.
The first is a cyber event, and the data has stopped being abstract. Verizon's breach reporting found ransomware present in 44 percent of breaches in 2025, up sharply from 32 percent the year before. For a small company the damage is rarely the ransom itself, it's the days you can't operate while you dig out. And the exposure is close to existential at this size. Surveys in 2025 found roughly 40 percent of small and mid-sized businesses saying that an attack costing 100,000 dollars or less would be enough to put them out of business. That is not a story about elite hackers. That's a story about a business with no slack, meeting a problem it can't afford to sit through.
The second is the supply side, and it's every bit as common. A widely cited industry survey found that 81 percent of organizations had been hit by a supplier disruption in the prior 2 years. The reason it keeps happening is a lack of sightlines. Other reporting put the share of supply chain leaders who can see past their tier-one suppliers at just 42 percent. Plenty of smaller businesses run a single source per critical part and have never mapped what's behind it, so the first time they learn a sub-supplier's factory flooded is the week the parts stop coming.
Both of these share a shape. A single point of failure that ran fine for years, right up until the 1 day it didn't, and on that day it took the whole operation with it.
Why the other side of the table cares first
When you sell or borrow, the person across the table is making a bet on future cash flow, and interruption is the thing that kills future cash flow fastest. So they look for the single points of failure before they get excited about the growth story.
One vendor for a component with no qualified backup. One server room, one aging system, and no tested way to run without it. Customer data and login access sitting with one person and no plan if that person is unreachable during the exact crisis when you need them most. Each of those is a place where a normal Tuesday can become a business-ending event, and a diligence team is trained to find them. What they discount is not the probability that any single thing goes wrong on a given day. It's the fact that the business has no shock absorber when something does.
The frustrating part is how cheap these exposures usually are to reduce compared to what the market charges you for carrying them. Qualifying a second supplier costs some time and a little margin. A tested backup and a written recovery plan cost a fraction of one bad week. But a buyer looking at an unmitigated single point of failure doesn't price the cheap fix you didn't make. They price the expensive disaster you left the door open for.
What resilience looks like on paper
Resilience is not a bunker. For a company your size it's a short, unglamorous list of the ways you've made sure one failure can't cascade into all of them.
Map your single points of failure honestly. Walk the business and ask, at each critical step, what happens if this one thing, this vendor, this system, this person, is gone Monday morning. The ones with no answer are your list. You will find more than you expect, and finding them is most of the work.
Put a real backup behind the few that matter most. A qualified second supplier for the parts you cannot run without, even at a small premium you treat as insurance. Data backed up somewhere separate and actually restored on a test, not just assumed to work. Access and knowledge held by more than one person. You are not trying to cover every risk. You're trying to make sure no single one of them can take the whole company down.
Then write down how you'd operate through a bad week. Who does what, who gets called, how the business keeps taking orders and paying people while the main system is dark. It doesn't need to be a thick binder. It needs to exist, and it needs one dry run so you learn what's wrong with it before a real crisis does.
Run the number you've been avoiding. How many days fully dark can this business survive? If you don't like the answer, you've just found the most valuable work on your desk, and the good news is that closing the gap is almost always cheaper than the discount you'll eat for leaving it open.