This book is a practical field guide for senior leaders who sense that their organizations are technically compliant yet structurally fragile. It argues that the real threat is not a lack of rules, audits, or frameworks, but the untested assumptions buried inside them. When leaders treat regulations, checklists, and dashboards as truth rather than hypotheses, they unwittingly design institutions that are optimized for passing inspections, not surviving disruption.
The narrative begins with a personal crucible: an early career episode with Boris, a seasoned District Facilities Manager who refuses to let the author hide inside the safety of a regulatory binder. Boris instructs his mentee to map everything in the regulations, then asks a deceptively simple question: “What did you not question?” That challenge exposes the hidden assumptions under supposedly precise controls. A 72-hour fuel requirement for emergency generators looks cleanly compliant, until you recall a local blackout that lasted ten days. An English-only security protocol seems efficient, until you recognize that the overwhelming majority of the local population is Spanish speaking and would be unable to follow critical instructions in an emergency. In that moment, the author realizes the difference between validating controls and validating the logic beneath them, and begins the shift from rule executor to systems refiner.
From this personal inflection point, the book widens its aperture to examine public failures that exhibit the same architectural flaw: systems built to follow rules rather than interpret reality. One anchor case is the 2018 ransomware attack on the City of Atlanta. On paper, Atlanta had all the right ingredients: policies, procedures, a continuity framework, internal audits, and documented critical systems. In practice, its digital infrastructure collapsed. Nearly two thousand known vulnerabilities had been logged, yet tolerated, because the city was meeting minimum compliance requirements. Leaders assumed legacy systems were stable enough, backups would restore cleanly, disruptions would be brief, and manual workarounds could carry the load. When ransomware struck, those untested assumptions failed at once. Courts could not function, police records were locked, residents could not access basic services, and manual processes quickly hit their limits. Atlanta did not fail because it lacked documentation or controls; it failed because no one had interrogated the assumptions those controls were built on.
The book then draws an explicit parallel to the 2016 Legionnaires disease outbreak at the University of Washington Medical Center and to a seemingly minor “locked-room” badge access anomaly inside the author’s own organization. At first glance, a hospital water-system failure and a workplace access-control glitch appear unrelated. Yet both reveal the same pattern. Weak signals surfaced early and repeatedly, but were dismissed as local inconveniences that sat below formal thresholds. Functions operated in silos, each one holding a fragment of the picture, with no cross-functional mechanism to interpret those fragments as a systemic pattern. Thresholds and alert levels had been tuned for auditors rather than for operational reality. As a result, they produced comforting reports instead of actionable warnings. When no one owns the pattern, the pattern owns the institution.
Across these crucibles, the book introduces the concept of governance architecture as the invisible scaffolding that shapes how an organization perceives, interprets, and responds to risk. Most governance regimes, the book argues, are built to capture the past. Regulations and audit checklists often describe how systems used to work, not how they operate in a world of interconnected digital, physical, and social infrastructures. Compliance becomes a mirror that reflects yesterday’s assumptions, while today’s interdependencies and failure modes remain unmodeled. The result is a deep mismatch between the world leaders think they are governing and the world they are actually in.
Resilience by Design offers a different approach. Instead of adding more rules, leaders are invited to reshape how their institutions think. Each chapter is structured around a crucible event and then moves through a consistent sequence: a resilience-by-design lens that dissects the governance architecture behind the failure, a teachable moment that surfaces the leadership behaviors that sustained the problem, a Reframe Zone that offers sharper questions to replace comforting narratives, and a Resilience Insight that captures the core design principle leaders can apply elsewhere. These sections are written in plain language but grounded in technical detail from cyber operations, healthcare safety, facilities management, and municipal services, so that leaders can see how the same patterns replay across very different domains.
The book is unapologetically candid about responsibility gaps at the top. It does not frame failures as inevitable acts of fate or as purely technical breakdowns. Instead, it shows how political avoidance, budget maneuvers, and a culture of “passing the audit” create conditions in which outdated systems, known vulnerabilities, and brittle workarounds are normalized. Rather than sensationalizing these cases or assigning personal blame, the book uses a clear ethics and learning frame. Real organizations and events are named explicitly because they are public and well documented, and because shielding leaders from the details would undercut the lessons. The aim is not to shame individuals, but to hold up a mirror for every reader who has ever prioritized optics over operational truth.
Most importantly, Resilience by Design focuses on what leaders should do instead of relying on compliance as a comfort blanket. Each chapter concludes with concrete scripts and question sets leaders can use in their own meetings. Some are probing and exploratory, designed to surface hidden assumptions about outage durations, language access, backup integrity, water treatment parameters, or access-control hierarchies. Others are purposefully directive. They set expectations for specific plans, timelines, and ownership, and, where appropriate, spell out consequences such as budget reallocation, changes in decision rights, or the postponement of launches until critical vulnerabilities are addressed. These scripts are written so leaders can either use them verbatim or adapt them into their own style, while still preserving the accountability edge that resilience requires.
By the end of the book, readers are equipped with a practical toolkit for adaptive governance. They learn how to transform audits from backward-looking scorecards into forward-looking experiments, how to redesign thresholds so that they reflect operational risk rather than documentation risk, and how to build cross-functional mechanisms that interpret weak signals in combination rather than in isolation. They gain language to differentiate between controls that exist for optics and controls that genuinely alter system behavior. They also acquire a set of disciplined habits for assumption hunting, scenario exploration, and interdependency mapping that are applicable in cyber, healthcare, physical infrastructure, and civic operations alike.
Resilience by Design is ultimately a book about identity as much as it is about systems. It invites leaders to move from the safety of being guardians of compliance toward the more demanding role of being designers of institutional intelligence. It argues that true resilience is less about how many frameworks your organization has implemented, and more about whether your rules still describe the living system you are responsible for. Leaders who take up that challenge will not eliminate failure, but they will change its character. Instead of being blindsided by crises that expose unexamined assumptions, they will face disruptions in institutions that are capable of questioning their own logic in real time. That is the work of governance in an age where rules, left unchallenged, can quietly replace thinking.