Map the machinery, suppliers, materials, systems, people and sites behind delivery, then establish credible recovery time and fallback options.
Marlow Manufacturing is a composite scenario. It is not a real business, and its events, timescales and outcomes combine recurring manufacturing patterns to demonstrate how connected dependencies can affect production and delivery.
Marlow is a seventy-person injection moulder, supplying flame-retardant polymer housings to industrial and automotive customers. Two things sat behind its two highest-value product lines, neither of which anyone thought of as fragile until the week both of them failed. The flame-retardant compound used on its largest contract came from a single supplier, the only one on the customer's approved materials list qualified to that specification. And the tool for that same contract only fitted one press in the building, the sole large-tonnage machine Marlow owned capable of running it.
In the space of three weeks, the supplier had a fire that took its own production offline for months, and Marlow's press suffered a hydraulic failure that needed a part with a fourteen-week lead time from overseas. Marlow could not simply switch material suppliers, because the customer's specification did not allow it without a lengthy requalification process. It could not simply run the tool on another press, because no other press in the building had the tonnage. Two production lines that had never gone down together went down together, for reasons that had nothing to do with each other and everything to do with the fact that neither had a second option behind it.
Marlow's machines were well maintained. Its supplier was a good one. Nothing here was a failure of standards. It was a failure to ask, before either event happened, what would actually happen if either of these single points failed on its own.
The two failures were not connected in any technical sense. They were connected only by the fact that Marlow's highest-value contract had been allowed to depend on two separate single points of failure at once, without anyone stepping back to look at the contract as a whole rather than as two unrelated supply arrangements.
Operational Resilience asks: What could stop production or delivery, how long would recovery genuinely take, and could the business withstand that period?
1. Why operational resilience behaves differently in manufacturing
Manufacturing output is often physically bound to particular assets, materials, processes, approvals and places. Losing one machine, supplier, site or system can therefore remove the ability to produce a specified part even when demand, people and commercial intent remain.
Substitution is also slower and harder than it looks from outside the business. A specialist press cannot be hired for the afternoon the way a laptop can be replaced. A qualified material cannot be swapped for a chemically similar one without requalification, and where a customer specification names an approved supplier, as it did for Marlow, substitution is not a technical decision at all, it is a contractual one that takes months to clear.
Manufacturing resilience has to be planned before disruption. A workaround for a failed press, unavailable material or lost process may still need to satisfy customer specifications, safety requirements, validation and certification; those constraints cannot be waived simply because the planned route is unavailable.
Growth adds to this rather than reducing it. A business running comfortably below capacity has somewhere to absorb a shock. The same business running flat out against demand, exactly the position growth tends to create, usually has nowhere left to put the load when one part of the system stops.
The consequences also travel further than the immediate loss of output. A missed delivery on a just-in-time contract can trigger penalty clauses, damage a relationship a business spent years building, or hand the volume to a competitor who happened to have spare capacity at the right moment. The cost of a stopped line is rarely limited to the days it stayed stopped.
2. Map the dependencies behind delivery
Operational continuity depends on the same nine categories used throughout this handbook:
-
Customer and programme: which orders, approvals or revenue streams depend on the operation;
-
Site: where production, storage, utilities, testing or dispatch must occur;
-
Technology: machinery, tooling, processes and utilities required for output;
-
Digital system: software, networks, control systems, data and access needed to operate;
-
Specialist person: competence, authority or knowledge that is thinly spread;
-
Supplier and material: external capability, components, consumables and approved specifications;
-
Geography: countries, regions, transport routes or clusters shared by apparently separate sources.
The grouping is for readability, not a separate framework. The critical question is which dependencies support the same output and therefore share a failure path. A fallback person must have the competence, authority, access and recent experience to act. A fallback supplier must be capable, willing, available, approved where necessary and independent of the same upstream or geographic source.
Connected production also creates operational-technology dependency. Remote access, central scheduling, vendor support and shared control systems should be mapped, segmented where appropriate and supported by tested isolation and recovery procedures. A system that cannot be operated or restored without one vendor, credential or individual is an operational dependency even when the machine itself remains intact.
3. The supplier you never named
A single-source supplier is not automatically a problem. Plenty of manufacturers run well on one trusted source for a given material or component. The problem is not having the supplier. It is not knowing, in any structured way, what happens the day that supplier cannot deliver.
This gets harder rather than easier as a business grows and its customers become more demanding. Marlow's flame-retardant compound was not single-sourced by accident or by cost-cutting. It was single-sourced because the customer's own specification approved exactly one supplier, and using an unapproved one would have breached the contract even if a chemically equivalent alternative existed. The constraint sat with the customer, not with Marlow, which is precisely why it is easy to overlook. Nobody chose this dependency. It arrived attached to winning the business.
Knowing which suppliers sit in this position is not a procurement exercise, it is a resilience one. A short list of the handful of suppliers whose failure would actually stop production, checked against whether an alternative exists and how long qualifying it would take, tells a business more about its real exposure than most of what appears on a standard supplier scorecard.
Where a customer specification is the reason for the single source, the conversation worth having is with that customer, not just the supplier. Asking whether a second approved source could be qualified in advance, before it is needed rather than during a crisis, is a request most customers will take seriously once the risk is explained in their own terms rather than yours.
4. The machine that has no backup
Every manufacturer depends on machinery. Far fewer have asked which specific machine, if it broke down tomorrow, would stop a product line with no fallback at all.
Marlow's press was maintained properly and had never given trouble before the failure that stopped it. The issue was never how well it had been looked after. It was that nothing else in the building could do what it did, and the part that failed had a lead time measured in months rather than days. A well-maintained machine with no backup is still a single point of failure. Maintenance reduces the chance of failure. It does not remove the consequence of failure when it happens anyway.
The practical question is not whether a machine might break, because eventually most machines do. It is what the business does in the gap between the breakdown and the fix, whether that gap is measured in days because a spare exists or an alternative machine can be adapted, or in months because neither does. Knowing which answer applies to your own most critical machine, before it fails, is the entire point of this section.
A critical spares list, held for the handful of components with the longest lead times on the handful of machines that matter most, is one of the least expensive pieces of resilience a manufacturer can build. It does nothing to prevent a failure. It does a great deal to shorten the gap that follows one.
5. Recovery time is the real number
Almost every conversation about operational resilience eventually lands on the same figure, and it is rarely the one anyone expected. It is not whether a failure can be fixed. It is how long fixing it actually takes, measured against how long the business can survive without producing.
Marlow's flame-retardant material and its damaged press both had a genuine fix. The supplier would eventually rebuild. The press part would eventually arrive. Neither fact helped in the meantime, because the business was losing production and, with it, customer confidence and cash, for every week the gap lasted. A theoretical recovery that takes four months is not meaningfully different from no recovery at all if the business cannot survive four months without its two highest-value lines running.
This is the number worth establishing honestly for your own most critical dependencies, in weeks, not in the abstract language of "we'd sort something out." Chapter Five picks this up directly from the financial side, because the recovery period is not just an operational question, it is the number an insurance recovery period is meant to match, and very often does not.
Most businesses have never actually timed this. They know roughly how a normal disruption plays out, a late delivery, a short breakdown, because normal disruptions happen often enough to build a feel for them. Nobody has a feel for an event that has never happened before, which is exactly the kind of event a single point of failure produces when it finally fails.
6. How InduX examines this
The same sequence applies here as everywhere else in this handbook.
CHANGE → EXPOSURE → DEPENDENCY → IMPACT → CONTROL → DEFENSIBILITY → RESPONSE
Run Marlow's two failures through it. The change, in this case, was not a single decision but the accumulation of two contract-driven constraints, an approved single supplier and a single qualified press, both accepted without complaint because both came with winning valuable business. The exposure was production entirely dependent on two assets with no second option behind either. The dependency was the material and the machine, sitting on the same contract, so that either failure alone would have been serious and both together were close to existential. The impact was two production lines down simultaneously, for months, against customers who had their own delivery obligations to meet. The controls worth examining afterwards were whether an alternative material source had ever been explored even informally, and whether any other press in the building could have been adapted, at a cost, to run the tool. The defensibility question was whether Marlow could show its customers, honestly, that this risk had been considered in advance rather than discovered in the moment, and whether the two dependencies had ever appeared together on the same page of any review, rather than being managed by two different people who had never compared notes.
The response that followed was not about avoiding single-source relationships altogether, which is often not realistic. It was about knowing, before the next equivalent contract is signed, exactly what the fallback plan is for the assets that contract depends on, and pricing that risk into the decision rather than finding it afterwards. In practice that meant a second material source put through qualification even though it was not yet needed, and a costed option to adapt a smaller press as a genuine fallback rather than a theoretical one.
7. What This Feeds Into
The recovery time this chapter has focused on becomes a financial question the moment it is understood operationally. Chapter Five, Financial Exposure, picks up exactly where this chapter leaves off, on whether the business's financial protection is actually sized to the recovery period its own operations require. And the systems point touched on briefly in section two, the operational technology and digital systems increasingly running production directly, gets its full treatment in Chapter Eight, Emerging Risk. Neither chapter needs reading first, but both assume the honest recovery-time work in this one has already been done.
8. Five board questions
Which single machine, if it failed tomorrow, would stop a product line with no realistic backup?
Which suppliers, named or not, would stop production if they failed, and do we actually know who they are?
If our most critical single point of failure happened today, how many weeks before production genuinely resumed?
Where has a customer specification or contract quietly locked us into a single source we would not otherwise have chosen?
Have we ever tested one of these failure scenarios properly, or only assumed we would manage if it happened?
9. One immediate exercise
Identify the one machine, the one supplier and the one site your business could least afford to lose. For each, write down honestly how long recovery would actually take, not how long you would like it to take. Where you cannot answer with any confidence, that is the gap worth closing first, before the next contract adds another single point of failure on top of the ones you already have.