FounderWiseDecisions, not feeds
← All articles FounderWise · Long-form

You have survived four failures and none of them mattered

Your record of absorbing shocks is evidence about small suppliers. It says nothing about the one you cannot replace.

06 Sep 2026 12 min read By Joshua Pi’Rwot
Share X LinkedIn

Four suppliers have failed you in three years and the company absorbed all four. You have started describing the business as resilient, and the word has made it into a board pack.

Check which four. If they were small, you have learned that you can lose a small supplier, which you already knew. Surviving random shocks is not evidence about a targeted one.

Why these three models

The decision is whether your concentration is a risk you should be paying to reduce. The features that fire are a dependency structure with uneven weights, an exposure that could reach survival capacity, and a confident conclusion drawn from a small personal sample.

Three lenses. Robustness topology produces a complex answer about how structure decides which failures are survivable. Survival sizing produces a random answer about what any single exposure may cost. The inside view produces an equilibrium answer about why your own history is the least reliable input you have here. The third exists to attack the confidence the first two might otherwise give you.

1. Robust and fragile are the same property

The first lens is the one that reframes the whole question.

Take any dependency structure, weighted by how much each node carries. Now ask two separate questions. How much of it can you lose at random before the whole thing fragments? And how much can you lose if the losses are chosen worst-first?

Those are different numbers, and in a concentrated structure they move in opposite directions. The more concentrated your dependencies, the more random failure you can absorb, because most randomly chosen nodes are small. And the less targeted failure you can absorb, because the few big ones carry everything. The tolerance is high and the vulnerability is high, at the same time, for the same reason.

That is why the chapter in the network science literature covering this is titled after Achilles’ heel.2 Robustness and fragility are not opposites to be traded off. They are one property read from two directions, and a business that has proved the first has proved nothing about the second.

One caution belongs in the body rather than a footnote, because the popular version of this idea is overstated. The claim that real networks are statistically scale-free, with a fitted power-law exponent, does not survive testing: across nearly a thousand real networks, only 4% showed the strongest evidence of scale-free structure and 52% showed the weakest.1 The mechanism used here does not need that claim. It needs only that your dependencies are unevenly weighted, which you can check on your own ledger this afternoon.

Robustness topology, the structure lens

  • Assumes: dependencies are unevenly weighted, so random and targeted removal have different consequences.
  • Fits because: a resilience claim is being made on the basis of past survival.
  • Breaks when: the weights are actually even, in which case random and targeted converge and the asymmetry disappears.
  • Evidence: grade B plus for the asymmetry. The scale-free label attached to it in the popular literature is a separate claim and is not supported.
  • Counteracts: reading absorbed shocks as general resilience.
  • May reinforce: treating concentration as purely a risk, when it is often also where the margin is.

2. What the big one would actually cost

The second lens converts a structural worry into a number.

Take your largest dependency and ask what its loss costs as a fraction of survival capacity, not of revenue. Revenue is the wrong denominator, because a business does not fail when revenue falls. It fails when it runs out of the ability to continue.

The arithmetic of ruin is unforgiving in a specific way: the probability of eventual failure rises steeply in the fraction at risk per event, not in proportion to it. A dependency that would cost a small share of survival capacity is a bad quarter. One that would cost most of it is a different category of object, and it does not become acceptable by being unlikely. The ordering is the point, and it is stated most bluntly in the trading literature that formalised it: it is impossible to make millions if you are wiped out, so you have to be able to keep playing if you are ever going to win.3

The correlated version is the one that catches people. Three suppliers who all ship through one port, price in one currency, or depend on one approval are not three dependencies. They are one dependency wearing three names, and it will not appear in any list that is sorted by supplier.

This is where the two models in this section meet. Robustness topology tells you which node matters; survival sizing tells you whether losing it is survivable. Neither is sufficient alone. A structurally central dependency that costs you a slow quarter is a manageable problem, and a peripheral one that happens to hold your operating licence is not, however small its invoice.

Survival sizing, the magnitude lens

  • Assumes: exposures come in a sequence, and zero is absorbing.
  • Fits because: the question is whether a single loss is survivable, not whether it is likely.
  • Breaks when: exposures are correlated, in which case several look independent and are not, and this model will not warn you.
  • Evidence: grade A. Structural rather than empirical, so it does not rest on a contested finding.
  • Counteracts: ranking risks by likelihood when the relevant axis is magnitude.
  • May reinforce: chronic over-diversification into dependencies too small to matter.

3. Why your own history is the worst evidence available

The third lens explains how a careful operator arrives at the wrong conclusion.

The inside view builds an estimate from the features of the case in front of you: your suppliers, your four incidents, your recovery. It feels like evidence because it is specific, and it is exactly the wrong sample. Four incidents is small, they were not randomly drawn, and they were selected by the thing you are trying to measure. Failures you survived are the ones you are able to recall as a survivor.

The denominator is missing too. Four failures out of how many supplier-years, weighted how? A resilience claim built from remembered incidents has no denominator at all, which is why it can be stated with confidence and carries almost no information.

There is a sharper version of the problem. The four failures you remember were survivable, which is why you are here to remember them. Any dependency whose loss would have ended the company is, by construction, absent from your experience of having survived. The sample is not merely small. It is systematically missing precisely the observations that would have been informative, and no amount of careful reflection on it recovers them.

The correction is not more introspection. It is to replace the recalled sample with a structural test you can run on paper, which is what the first two lenses provide.

Inside view, the sample lens

  • Assumes: estimates built from case features are systematically more confident than the evidence supports.
  • Fits because: the resilience claim rests entirely on remembered incidents.
  • Breaks when: the case genuinely is unusual and the reference class misleads, which happens more often than base-rate advocates admit.
  • Evidence: grade B. Well established in direction, and the size of the correction is context-dependent.
  • Counteracts: generalising from a small self-selected sample of survived events.
  • May reinforce: ignoring genuine local knowledge that a reference class cannot contain.

The levers, cheapest first

  • Sort your dependencies by what their loss costs, not by spend. The largest invoice and the largest exposure are frequently different rows. One afternoon with a spreadsheet.
  • Run the removal on paper. Take the top row, assume it is gone on Monday, and write down what breaks and when. This is the only test that has ever been relevant, and it costs nothing.
  • Group the correlated ones before you rank. Same port, same currency, same regulator, same founder network. Sum the group, then rank.
  • Second-source the top row before the second row. Qualification takes months, so the sequencing matters more than the intent.
  • Cap the concentration you will accept, in advance. A stated ceiling on any single dependency, set before a good deal makes an exception attractive.
  • Stop citing absorbed shocks as evidence. In board packs and in diligence, say which failures you survived and how large they were. An investor who understands this asymmetry will ask, and the unprompted version reads much better.

What to do this week

Do now, sized at one afternoon, effect immediate. Build the dependency list ranked by cost of loss as a share of survival capacity, with correlated ones grouped. Reversible, cheap, and dominant across every scenario about whether you are actually concentrated.

Hedge, where the premium is the whole loss, cover live before the next quarter. Begin qualifying a second source for the top row only. If the incumbent never fails you have spent qualification effort, and that is the entire downside.

Defer and trigger, size fixed now. Do not rebuild the supply base. Pre-commit the trigger: if the top dependency crosses a stated share of survival capacity, the second source gets funded automatically without a fresh business case. Fix that share now, while nothing is pending, because a threshold set during a crisis is set under pressure.

Watch the arrivals. The spreadsheet lands today. A qualified second source lands in months. If your trigger fires before qualification completes, the trigger was set too late, and that is a scheduling error rather than a risk-appetite one.

What usually happens next

Run the break test first. Has a rule changed, has an actor entered or left, has a measurement become a target? If your largest supplier has just been acquired, their incentives are new and your history with them describes a different counterparty.

If nothing broke, name the shape. Concentration usually rises gradually and without a decision. Each individual choice to give more volume to your best supplier is correct on its own terms, and the aggregate is a dependency nobody chose. It is success to the successful operating on your own purchase orders, and it will not announce itself.

Subtract the counterfactual before crediting your risk management. If you survived a shock while your largest supplier held steady, you have learned nothing about your resilience and something about their reliability, and those are different assets.

What this ensemble cannot see

All three lenses treat your dependency structure as given and ask how it fails. None of them asks what the concentration is buying you.

That omission matters, because concentration is frequently where the margin lives. The largest supplier is often largest because they are cheapest, fastest, or the only one who will extend terms. A second source has a real cost in price, in management attention and sometimes in quality, and none of these models prices that. Read carelessly, this framework recommends diversifying until you are safe and unprofitable.

There is also a limit on the structural test. Removing the top dependency on paper tells you what breaks mechanically. It cannot tell you how your customers, lenders and staff would react to the news, and those reactions have ended companies that were mechanically fine.

And one property none of these models contains: your largest supplier is running this same analysis. If you are their concentration risk, their second-sourcing is your churn, and it will arrive without warning.

The one action that survives the ignorance: this week, take your single largest dependency, assume it is gone on Monday, and write one page on what happens. If you cannot fill the page, you do not know your exposure. If you can, and it ends the company, you have found the thing to fix before anything else on your list.

Who has to move

The person who needs this is usually whoever signs supplier contracts, and they are optimising price and reliability, both of which push toward concentration. The cheapest first test is the one-page removal exercise on the top row. It costs an afternoon and it converts an abstract worry into a specific list of what breaks, which is the only form in which anyone acts on it.

Sources and notes

  1. Anna D. Broido and Aaron Clauset, Scale-free networks are rare, Nature Communications 10, 1017, 2019. Preprint: https://arxiv.org/pdf/1801.03400. The abstract states that the authors fit the power-law model to each degree distribution, test its statistical plausibility, and compare it via a likelihood ratio test to alternative non-scale-free models, and that across domains they find scale-free networks are rare, with only 4% exhibiting the strongest-possible evidence of scale-free structure and 52% exhibiting the weakest-possible evidence, adding that social networks are at best weakly scale free.
  2. Albert-László Barabási, Network Science, Cambridge University Press. Chapter 8, “Network Robustness”, develops the distinction used in section 1: percolation and the critical threshold, the contrast between error tolerance and attack tolerance, and cascading failures. The chapter’s summary section is titled “Achilles’ Heel”. The asymmetry is used here on its own terms; the universality and scale-free claims made elsewhere in the same volume are addressed in note 1.
  3. Courtney Smith, on money management, in Rick Bensignor (editor), New Thinking in Technical Analysis: Trading Models from the Masters, Bloomberg Press. The fixed fractional method and the worked comparison of ruin probability at different bet sizes over a long sequence appear in the money management chapter, along with the ordering claim relied on in section 2: that it is impossible to make millions if you are wiped out, so you have to be able to continue playing if you are ever going to win.

A note on using a book while disputing it. Section 1 leans on a chapter from Network Science and note 1 reports evidence against a central claim made elsewhere in the same book. That is deliberate. The robustness asymmetry stands on percolation and uneven weighting, and does not require the scale-free property to hold. Separating the two is the point, because the popular version bundles them and the bundle is what fails testing.

Joshua Agonya Pi’Rwot, Founder.

Lock in your calls.

You’ve marked 0 of 5. Now choose how often you want the signals.

Step 1 · Pick your cadence

The DispatchWeekly · your Monday 5 callsFreealways

Step 2 · Where to send it

Personalize your BriefThe Brief

Tune every edition to the markets and industries you actually act on.

🔒 Unlock personalization — The Brief, $19.99/mo →
Free Dispatch forever · upgrade anytime · we never share your details.
Know where you stand?
The Dispatch tells you what changed. Knowing what to do about it is a different question, and it is the one FounderWise answers. Start with the free Traction Audit: 12 questions, about 3 minutes, scored out of 100.
Find out where you stand →

For teams, syndicates & programs

Recommended
Team
$15/seat · mo
Daily Brief for the whole team (min 3 seats).
  • Everyone on the same signal
  • Admin + shared watch-list
  • One invoice · ~25% off solo
Get Team →
Cohort Licence
$2,900/yr
Co-branded seats for one cohort, for accelerators, funds & programmes.
  • Up to 25 founder seats
  • Your logo, your cohort
  • The record of what your cohort committed to
Talk to us →
Pass the Dispatch on
Know a founder making these calls blind? Send them this week’s five — free, every Monday.

Decisions, not feeds. · Curated by Joshua Pi’Rwot · FounderWise · Free Audit · Store · parent of Business Growth Accelerator

Call committed. We’ll hold you to it.
Know where you stand →