
Resilience is usually sold as redundancy: a second of everything. That framing is expensive and incomplete. Redundancy protects against component failure. It does nothing for a bad change, a corrupted dataset or an operator who is on a plane when the alert fires.
The regional context sharpens this. Power quality varies, replacement parts arrive on a shipping schedule and technical depth is concentrated in a handful of people. An architecture that assumes next-day hardware replacement is not resilient here, whatever the datasheet says.
The practical version is narrower and more practical: know which systems must survive, know how long they may be down, and prove regularly that you can bring them back within that window with the people who will actually be on shift.
