Category: Operational Resilience Tags: site selection, location risk, concentration risk, business continuity, screening, real estate, market entry

The first time anyone asked me about a new site, the lease had been signed for five weeks. The request was to write the continuity plan, which is a reasonable thing to ask a resilience function and an almost useless moment to ask it. Every decision that would determine how that site failed had already been made by people optimizing for entirely sensible things: cost per square foot, the local talent pool, an incentive package, proximity to a customer, the fact that an executive already lived there. Nobody had been careless. It simply had not occurred to anyone that resilience was an input to the choice rather than a document produced afterward, so the function that understood the failure modes was handed the outcome and asked to write around it.

What made it worse was that the site was forty minutes from the existing one. On a spreadsheet that reads as convenient. On a map it reads as the same metropolitan area, the same power grid, the same regional carrier, plausibly the same flood basin, and certainly the same storm track. The company had just paid for a second location and bought almost no independence, which is the single most common expensive mistake in this whole area.

Resilience Is a Selection Criterion or It Is Nothing

The structural problem is sequencing. Location decisions run on a corporate real estate or expansion timeline with its own gates, and risk usually enters at the last gate or after it. By then the shortlist has narrowed to one, the business case is written, the incentive negotiation is done, and the political cost of saying this is the wrong city is high enough that nobody will pay it. Whatever assessment happens becomes documentation rather than input.

The fix is not a heavier process, it is an earlier and much lighter one. Resilience needs to arrive when there are still five candidates rather than one, and it needs to arrive with something small enough to be welcome: a screening pass across the longlist that takes days, not a six-week assessment that delays a deal. That reframes the function from obstacle to contributor, which is the only footing on which it gets invited back. It also puts the awkward questions at the only moment they are cheap to answer, because the cost of preferring the second-best city is a rounding error before the term sheet and enormous after it.

What Actually Varies Between Two Cities

Location risk gets discussed as though it means natural hazard, and hazard is only the most visible layer. Seismic, flood, wind, and wildfire exposure matter and are comparatively well served by public data, which is exactly why they are the part most often handled. The dimensions that decide outcomes are frequently the ones nobody pulled.

Utility and grid reliability varies enormously between places that look similar on a map, and a site in a region with a strained grid inherits an interruption profile that has nothing to do with the building. Connectivity has a physical geography: how many distinct fiber paths reach the campus, whether they share a conduit somewhere, which subsea cables the region depends on. Jurisdiction sets a slower-moving set of constraints, covering political stability, sanctions exposure, data localization rules, the practical enforceability of contracts, and how a government behaves toward foreign employers under stress. Labor and civil conditions determine whether the site can operate during disruption. Emergency services and healthcare capacity determine what happens to your people rather than your equipment. And distance from your existing footprint determines whether this site is a hedge or a duplicate.

Most of that is knowable in advance from public sources, which is the good news, and most of it lives in a different system, agency, or format from all the others, which is why it does not get pulled under deal pressure. The unlock is having the comparison assembled before the decision starts rather than commissioning it per candidate.

Correlation Is the Question Nobody Asks

If a program only ever asks one location question, it should be this one: given everything we already run, what does adding this place actually change? A site is not risky or safe on its own. It is risky or safe relative to the portfolio it joins.

Two sites on the same grid fail together. Two sites in the same seismic zone fail together. Two sites whose staff use the same airport lose access together. A primary and a recovery site inside the same regional weather system are not a primary and a recovery site, they are one site with two addresses and a much larger lease bill. And the cloud layer has quietly made this harder rather than easier, because the physical geography of your workloads now belongs to somebody else and is not visible in any real estate analysis: two applications in what look like different regions can still share a metro, and a recovery region chosen for latency can sit inside the same hazard envelope as the primary. That is the concentration argument I made in the map is the missing control, applied at the moment of purchase rather than during a review of what you already own. No register will surface it, because registers store locations as text and text does not compute distance.

Screen the Longlist, Assess the Finalists

The practical shape of this is two tiers, and being explicit about which one you are in prevents both of the usual failures. A screening pass covers every candidate cheaply and comparably, on the same criteria and the same scale, and its output is a ranking plus a short list of things that would need to be true. It is not an assessment and should never be presented as one, a distinction I take seriously enough to have written about separately in sources and methods. Screening exists to spend the expensive capacity in the right place.

Then the finalists get real work: a site visit, the actual utility and connectivity diligence, conversations with local counsel about the jurisdictional questions, insurance input, and a concrete recovery design rather than an intention. Two or three candidates can carry that depth on a deal timeline. Eleven cannot, which is precisely why programs that refuse to screen end up assessing nothing and rubber-stamping the choice that was made without them.

Put the Number in the Business Case

The last piece is where the analysis lands, because a resilience opinion that arrives as a memo gets read once and a resilience number that arrives as a line item changes decisions. If a candidate city needs a second fiber path, a generator, a larger insurance limit, or a recovery site further away than the convenient option, those are costs of choosing that city, and they belong in the comparison next to rent and payroll rather than in an appendix nobody opens.

That reframing does more for the influence of a risk function than any amount of escalation. It stops the conversation being about whether the city is dangerous, which is a matter of opinion and therefore arguable, and makes it about what the total cost of operating there actually is, which is arithmetic. Sometimes the answer is that the riskier city is still correct because the talent or the customer proximity is worth it, and that is a perfectly good outcome. The failure mode is not choosing an exposed location. It is choosing one without knowing, then discovering the bill five weeks later when someone finally asks for the continuity plan, and finding out the plan cannot be written because the constraints that would have made it possible were negotiable only before the lease was signed.

PivotRisk is a practitioner-led governance, risk, and resilience practice. Everything published here comes out of programs actually designed, launched, and run inside enterprise software, fintech, and infrastructure companies, not frameworks summarized from a distance.

Rank the longlist before the shortlist exists

The PivotRisk risk intelligence map scores any address on a 5x5 likelihood and impact scale, and takes up to 25 at once to rank a whole candidate list worst-first with CSV export. Every scored radius reports the urban population and cloud regions in range, so correlation with what you already run is visible before anyone signs anything.

Open the Risk Map