A CEO once told me how his company lost over $2.5 million, without a single hacker, no fire, no fraud. The culprit? A silent risk named vendor lock-in. They had outsourced their core platform to a firm that coded everything in a proprietary language. When the contract ended, no other developer could touch the code without rewriting it from scratch. The entire tech stack became a tombstone.
He watched it unfold, month after month. Emails flagged the concern. Engineers warned him. But there was no fire, just fog. By the time the board stepped in, the platform was obsolete, the customers had moved on, and their tech team had walked. It was like waking up and realizing your house has termites. The roof hasn’t caved in, but you’re standing on rot.
Here’s the point: silent risks don’t bang. They knock. Politely. They come wrapped in jargon, in routine. They sit in your “known unknowns” list and sip coffee while you focus on firefighting.
There are three common types of silent risk I see in East African firms:
a) Key man dependency, one staff member who knows everything. If he resigns, you lose the entire process. No documentation. No backup.
b) Technical debt, decisions made to “go live quickly” that are never revisited. They pile up like dirty dishes in a sink until you need a system upgrade, and discover the plumbing is broken.
c) Unmeasured reputation risk, you think your brand is strong. But then a minor scandal goes viral, and you’re stuck reacting with no crisis comms strategy in place.
"Next time you hear a knock at the door, don’t assume it’s opportunity. It might be oversight. Open it with caution, and a flashlight.”
Tweet
The real leadership challenge
Many executives have become skilled at reacting. But reacting is not the same as scanning. Strategic leaders don’t wait for reports. They ask uncomfortable questions:
, What is the one risk no one is talking about here?
, What would cripple us if it happened silently over 18 months?
, Which system, if corrupted today, would not be noticed until Q3?
Silent risks hate structure. That’s how you expose them. I always advise boards to do a Silent Risk Scan twice a year, an off-calendar review where you don’t wait for KPIs. You interrogate assumptions. You audit dependencies. You kill blindspots before they kill momentum.
Silent Risk Rada
- List all “invisible assets”, your trust, data integrity, team morale, vendor relations.
- Map their risk dependencies, Who manages them? What tools support them? Are they monitored?
- Score detection delay, If something went wrong, how long before we notice?
- Simulate failure, Run a tabletop drill. Not fire. Fog.
In my experience working with many companies across the region, we’ve seen empires fall not from explosions, but erosion. You don’t lose your company in one day. You bleed it in silence.
So, next time you hear a knock at the door, don’t assume it’s opportunity. It might be oversight. Open it with caution, and a flashlight.
