The Critical Few: Why Resilience Planning Should Start With the Work That Carries the Most Consequence
- Shane Mathew
- Jun 17
- 6 min read
Most organizations do not have 200 equally critical workflows.
They may have hundreds of processes. They may have dozens of departments. They may have thousands of applications, vendors, assets, forms, reports, approvals, and handoffs.
But when disruption happens, only a smaller set of workflows usually determines whether the organization can keep operating in a meaningful way.
The work that keeps revenue moving.
The work that protects customers.
The work that keeps patients safe.
The work that fulfills regulatory obligations.
The work that sustains the mission.
The work that preserves trust.
Those are the critical few.
And in my experience, resilience planning gets much more practical when organizations start there.
The Problem With Treating Everything as Equal

A lot of business continuity and resilience programs struggle because they try to analyze too much at the same level of depth.
Every department gets the same template.
Every process gets the same set of questions.
Every system gets labeled as important.
Every stakeholder has a reason their work should be considered critical.
The result is predictable.
Lots of activity.
Lots of documentation.
Lots of meetings.
But not always a lot of clarity.
This is not usually because the continuity team is doing anything wrong. More often, it is because the starting point creates too much noise.
When everything is treated as equal, it becomes harder to see what actually matters most.
That creates several problems.
First, stakeholders get tired. If every team is asked to complete long assessments, attend repeated workshops, and maintain detailed plans, engagement drops quickly.
Second, the outputs become generic. When every process is pushed through the same method, the planning often loses connection to how the organization actually operates.
Third, leadership conversations become harder. Executives do not usually want a giant inventory of everything that matters. They want to know where the organization is most exposed and what should be done about it.
Finally, the program can become more focused on completion than usefulness.
Did we finish the assessment?
Did every department submit a plan?
Did every field get filled out?
Those questions matter administratively, but they do not always answer the bigger resilience question:
Can the organization keep its most important work moving when something breaks?
That is why I believe many organizations should start with the critical few.
The Critical Few Workflows
The critical few are the workflows that carry the most operational consequence if they fail.
They are not always the loudest processes.
They are not always the biggest departments.
They are not always the systems with the most users.
They are the flows of work that produce the outcomes the organization cannot afford to lose.
For a healthcare organization, that may include patient admission-to-discharge, medication ordering and administration, lab ordering-to-result, imaging, patient transfer, or revenue cycle.
For a manufacturing company, it may include order fulfillment, production scheduling, supplier coordination, quality release, shipping, or maintenance of specialized equipment.
For a technology company, it may include customer onboarding, incident response, platform operations, billing, customer support, or product release.
For financial services, it may include payment processing, claims intake, account access, fraud monitoring, loan origination, or regulatory reporting.
For a public sector organization, it may include emergency response, benefit distribution, permitting, public communications, or critical infrastructure support.
The names vary by industry.
The principle does not.
Some workflows carry more consequence than others.
That does not mean everything else is unimportant. It means resilience planning needs a place to start.
And the best starting point is usually the work tied most directly to revenue, safety, service delivery, customers, patients, compliance, or mission.
Why Workflows Create a Better Starting Point
Starting with workflows changes the conversation.
Instead of asking each department to explain its importance in isolation, you ask how the most important work actually moves across the organization.
That shift matters because most critical work is cross-functional.
Order-to-cash does not belong to one department. It may involve sales, customer service, finance, legal, fulfillment, warehouse operations, shipping vendors, payment systems, and technology teams.
Patient admission-to-discharge does not belong to one department. It may involve registration, nursing, providers, pharmacy, laboratory, radiology, environmental services, bed management, case management, IT systems, and external partners.
Claims processing does not belong to one team. It may involve intake, adjudication, documentation, customer communication, fraud review, payment, vendor tools, and regulatory controls.
Workflows reveal these connections.
They show the handoffs.
They show the systems.
They show the dependencies.
They show the bottlenecks.
They show the informal workarounds.
They show where one failure can ripple across the organization.
That is why workflow-centric resilience is so useful. It moves the program from a static view of organizational structure to a practical view of how value is created and sustained.
The org chart tells you who owns the function.
The workflow tells you how the work survives.
What Workflow Mapping Reveals
Once you identify a critical workflow, the next step is to map what enables it.
This is where the real resilience insights usually appear.
A workflow may depend on:
Applications
Infrastructure
Facilities
Vendors
Equipment
Data
Teams
Specialized individuals
Approvals
Communication channels
Manual workarounds
Physical documents
External partners
Institutional knowledge
Some of those dependencies will be obvious.
Others will not.
The most useful discoveries are often specific.
One vendor with no backup.
One specialist who knows how the process really works.
One application that supports multiple critical workflows.
One facility dependency that nobody connected to the business outcome.
One spreadsheet that quietly runs the operation.
One manual workaround that exists in theory but has never been tested.
One approval path that slows everything down when normal systems are unavailable.
These are the findings that make resilience practical.
They give leaders something concrete to understand and act on.
Instead of saying, “This department is critical,” you can say:
“This workflow depends on one vendor, one system, and one specialized role. If any of those fail, the organization cannot complete this outcome without a workaround.”
That is a much more useful conversation.
The Benefit of Focus
The biggest advantage of starting with the critical few is focus.
Most organizations do not need to map everything immediately.
They need to identify where disruption would create the greatest operational consequence and go deeper there first.
That focus improves almost every part of the resilience program.
It improves planning because the plan is tied to real work, not just a department name.
It improves dependency mapping because dependencies are connected to outcomes that matter.
It improves leadership reporting because the conversation becomes clearer and more operational.
It improves exercises because scenarios can test the workflows the organization actually needs to protect.
It improves investment decisions because leaders can see why a backup vendor, system improvement, training plan, or process change matters.
It improves stakeholder engagement because people are not just filling out a template. They are explaining how their work supports something important.
Focus does not make the program smaller.
It makes the program sharper.
When to Start With Workflows
Workflow-centric resilience is especially useful for organizations that are complex, cross-functional, or trying to build momentum quickly.
It works well when:
Important work crosses multiple departments.
Stakeholders are tired of long assessments.
Existing plans are stale or too generic.
Leadership wants clearer priorities.
The organization relies heavily on vendors.
Operations are spread across multiple sites.
Technology, facilities, and people dependencies are tightly connected.
The organization is growing or changing quickly.
The continuity team needs to show value faster.
The business struggles to connect planning outputs to operational decisions.
In these environments, starting with every department can create a long planning cycle before the organization sees practical value.
Starting with workflows can create traction faster.
It brings the right people into the room.
It creates a visual understanding of the work.
It exposes dependencies and weak points.
It gives the continuity team a clearer basis for deciding where deeper analysis is needed.
This Does Not Mean Ignoring Everything Else
Starting with the critical few does not mean ignoring supporting departments, regulatory obligations, or less critical processes.
It means sequencing the work intelligently.
Some departments may still need plans.
Some processes may still need analysis.
Some regulatory requirements may still require broad coverage.
Some support functions may become more important because they enable multiple critical workflows.
The point is not to abandon traditional continuity activities.
The point is to give them better direction.
Once the critical workflows are understood, the organization can make better decisions about where to apply deeper analysis, where to build recovery strategies, where to test, and where to invest.
That is a healthier model than treating every process as equally urgent from the start.
Start with the workflows that carry the most consequence.
Then expand with purpose.
The Practical Takeaway
A resilience program does not get stronger by calling everything critical.
It gets stronger by understanding what matters most, how that work actually moves, and what could stop it from moving.
That starts with the critical few.
The workflows that sustain revenue.
Protect customers.
Keep patients safe.
Maintain service delivery.
Fulfill regulatory obligations.
Support the mission.
Preserve trust.
Find those workflows first.
Map how they work.
Identify what enables them.
Look for the weak points.
Then decide where deeper planning is needed.
Because the goal is not to analyze everything equally.
The goal is to build resilience where failure would matter most.
Like this post?
If your team is trying to make resilience planning more focused and practical, we’d be glad to compare notes. Reach out to us at info@riffleresilience.com.
.png)




Comments