Every organisation has people who just get stuff done. Whether it’s sales, operations, or tech support, you’ll find people with a natural knack for solving problems. Often, the harder the problem, the more they enjoy it.

Whenever I’m facilitating planning sessions and ask people what they would do in a particular situation, I regularly hear something like: “It depends” or “We’d figure it out on the day.”

And they probably would.

They’re good at troubleshooting. They’re comfortable making decisions with imperfect information and solving the problem in front of them. But sometimes that comes with a struggle to think through the hypothetical problem in advance and preload some of those decisions.

I hope you are lucky enough to have someone like that on your team who is that capable on the fly.

But what happens when those capable individuals rise through the ranks and get further away from the frontline of the organisation’s operations? How well do they shift their risk horizon? Are they able to manage a risk before it turns into an issue?

I’m reminded of a situation where an impending third-party service change was identified as potentially leaving a company vulnerable to cyber-attacks. The issue was identified during a risk assessment at least 18 months before the change date. Yet at each subsequent assessment, mitigating the risk was pushed further down the road.

Eventually, it passed the point where anything meaningful could be done before the change was applied. 

Only once the service change had occurred did the company act.  

Why?

The risk was understood well in advance. The options for a solution were understood. The timeframe was known. The resources required to act were available. Why did the managers choose to wait?

“Do nothing” may be a perfectly legitimate risk treatment, but it needs to be an explicit decision. I wonder whether sometimes the reason for inaction is more deeply baked into our psychology.

Risk isn’t certain. Likelihood is a dice roll. Maybe the risk won’t become an issue. Do we need total certainty of an outcome before we act?

And if they had decided to implement risk mitigations, but the issue still eventuated, would they be seen as having failed? Would it look like poor judgement when they had all that time to make the right decision? Would they be found wanting in front of their peers and bosses?

Can the personal risk of making the wrong call be greater than the organisational risk they are supposed to be managing?

But there’s another option for our instinctive trouble-shooter, isn’t there? 

Leave the risk until it becomes an issue.

When action is required, it’s required now. The debate changes. Money becomes available. Decisions get made quickly. And suddenly they are back in familiar territory.

They are the trouble-shooter. They can manage the company’s way out of the problem. They swing into action. The problem gets solved.

They are a hero.

But what was the real cost?

Hours, days, or weeks of stress for everyone involved. Thousands or millions of dollars spent responding. Outages. Lost productivity. Lost data. Lost business. Customer impacts.

Was it worth it?

The cost and disruption of responding to an issue can considerably exceed what it would have taken to treat the risk earlier. So why not commit to making the decision while there is still time to make it deliberately?

As we rise through the leadership ranks and move further away from frontline operations, our risk horizon needs to shift with us.

We need to look further ahead. Issues may be exciting to manage in the moment, but leadership requires us to anticipate what is coming and be prepared to invest in reducing the risks before a response becomes necessary.