From crisis thinking to the capacity to act
Why security needs to be rethought
GfKV Newsletter #18 • 31.01.2026
Recent events – from the power cut in Berlin to increasing cyber attacks and tense energy markets – reveal a structural problem: we analyse, discuss and plan, but we act too little. Security is thought about, but not lived.
The dynamic is familiar. A crisis is followed by media attention, then classification by experts, political reassurance and finally a return to the status quo. What remains are isolated measures – but rarely real adaptation. This pattern can be described as “crisis dementia”: the ability to react in the short term is there, but lasting learning does not take place.
The misunderstanding of security
A central problem lies in the prevailing understanding of security. Security is often defined through plans, responsibilities and regulations. Once a concept has been drawn up, the problem is considered solved. But this form of “abstract security” creates a dangerous illusion of control.
In practice it turns out that plans are merely assumptions about an uncertain future. They offer orientation but do not replace the competence to act. As soon as real events occur, they collide with the complexity of reality.
Added to this is a phenomenon common in IT security: “security by obscurity”. Here, an attempt is made to create security through secrecy – an approach that simulates activity rather than actually reducing risks.
Resilience is more than resistance
The term resilience has gained a great deal of importance in recent years, but at the same time it has become blurred. It is often reduced to “resistance”. In fact, however, resilience describes the ability to adapt dynamically to change, to anticipate disruptions and to emerge from them stronger.
The concept of antifragility, coined by Nassim Taleb, goes even further. Antifragile systems benefit from disruptions. They become stronger under stress – provided this happens in a controlled and regular way.
An example of this can be found in IT: so-called “chaos monkeys”. Systems are deliberately disrupted in order to detect weak points early and train the ability to respond. It is precisely this approach that is missing in many social and organisational structures.
The increasing fragility of our systems
Paradoxically, the attempt to avoid risks completely leads to more fragility. Over-regulation, efficiency thinking and the removal of redundancies reduce costs in the short term, but increase vulnerability in the long term.
When unexpected events then occur, both the resources and the competence to act are lacking. Systems do not collapse despite their apparent optimisation, but because of it.
This development is reinforced by another problem: diffusion of responsibility. Responsibilities are distributed, decisions are delayed or avoided. At the same time, a culture emerges in which meeting requirements is more important than actual effectiveness.
Operational resilience instead of paper strategy
The decisive difference lies between declarative and operational resilience. The former exists on paper, the latter in the behaviour of people and organisations.
Operational resilience comes from:
- regular, realistic exercises
- decentralised competence to act
- clear decision logic under uncertainty
- a functioning culture of learning from mistakes
Simulations such as “Neustart” (restart) show how important it is to train under realistic conditions. For crises are not isolated events but interconnected, cascading processes.
Error culture as a security factor
An often underestimated aspect is the culture of dealing with mistakes. Organisations that punish or hush up mistakes prevent learning. Risks are ignored until they escalate. A robust security culture, by contrast, promotes transparency, critical thinking and the early addressing of weak points. The goal is not perfection, but continuous improvement.
From “whether” to “when”
The decisive shift in thinking is no longer to ask whether a crisis will occur, but when. This results in a new priority: preparation instead of reassurance.
- In concrete terms, this means: What happens in the first hour?
- What after six or 24 hours?
- Who acts when planned structures fail?
These questions do not require perfect answers, but trained decision-making ability.
![]()
For years I have been publishing extensive analyses on my website for the event of a blackout.
Since 2019 also in cooperation with GAIA: my newsletters are also published here for interested readers when they appear.

Notes on content provided by authors
Comments
Loading comments …
Become a member to comment publicly. GAIA members write comments in the members' portal — under their nickname, visible to everyone.