The Strait of Hormuz is a geopolitical crisis. For operators, investors and infrastructure owners, it is also an operational stress test.
In its July 2026 outlook, the US Energy Information Administration described the Strait as having been effectively closed from 28 February until the 18 June agreement to reopen it. The International Energy Agency reported that total Gulf oil exports recovered to 16.1 million barrels a day in June, still below the pre-disruption average of 24 million.
The route began moving again, but recovery was not instantaneous. Production, inventories, shipping, contracting and customer decisions had already been forced to adjust. That is the operational lesson.
What happens inside an organisation when one of the assumptions underpinning its operating model changes almost overnight?
The most useful answer is not a geopolitical forecast. It is a clear view of the organisation itself: what it depends on, what management can see, who can decide, where maintenance is vulnerable and which emergency measures should remain temporary.
01Critical dependencies extend beyond tier-one suppliers
Most resilience reviews begin with a supplier list. That is necessary, but incomplete. An operating plan depends on a chain of processes, people, systems, contractors, spares and logistics. A tier-one supplier may appear secure while relying on a specialist subcontractor, a single transport corridor, one data interface or a component with no approved substitute.
The question is not simply, "Who supplies us?" It is, "What must continue to work for the operating plan to remain credible?"
- Processes: the activities that connect demand, planning, procurement, maintenance and operations.
- People: scarce roles, licence holders and individuals carrying knowledge that is not documented.
- Systems and data: interfaces, master data and reports on which operational decisions depend.
- Contractors: OEM support, inspection, lifting, access, marine, logistics and other specialist capability.
- Spares and routes: critical parts, approved alternatives, storage locations, customs requirements and the physical paths by which they arrive.
A credible dependency map links each external dependency to the process it supports, the asset or outcome at risk, the time before impact and the available alternative. Without that chain, management sees a vendor issue when it is already becoming an operating issue.
02Operational visibility must arrive before the consequence
Visibility is often confused with reporting. A weekly dashboard can be accurate and still be too late.
During disruption, leaders need to know which dependency has changed, which operating assumptions are no longer valid and how long they have before the consequence reaches production, safety, service or cash. Supplier status alone is insufficient. Management also needs a joined-up view of inventory accuracy, lead times, work-order priorities, contractor availability, maintenance backlog, operating limits and customer commitments.
The discipline is to define these signals before disruption occurs. Otherwise, the organisation spends the first critical days debating the data instead of acting on it.
03Decision rights must survive pressure
Normal governance is designed for normal conditions. Papers are prepared, committees meet and authority moves through established levels. Under pressure, that cadence may become the constraint.
Resilient organisations are explicit about who can change production plans, approve alternative suppliers, defer non-critical work, use contingency stock, vary customer commitments or accept a temporary operating control. They also define the boundaries within which that authority applies.
This is not an argument for weaker governance. It is an argument for pre-agreed decision rights, thresholds and escalation routes. Fast decisions still need a record, an owner, an expiry point and a clear understanding of safety, regulatory and commercial consequences.
If authority is unclear in calm conditions, disruption will not make it clearer.
04Maintenance resilience is usually where hidden exposure surfaces
Maintenance plans often assume that critical spares will arrive, specialist contractors will mobilise and corrective work can be absorbed without destabilising the schedule. A disrupted route tests all three assumptions at once.
Corrective-maintenance exposure matters because reactive work consumes planning capacity, competes for scarce labour and makes demand for spares less predictable. In an offshore gas operating-model study I led, around 80% of maintenance hours were corrective. The work was not only to identify a better technology. It was to redesign the maintenance approach, governance and ways of working so that activity could shift towards predictive and preventive intervention.
Executives should ask whether the critical-spares list reflects current failure modes and operating priorities, whether stock records match physical reality, which parts have approved equivalents, and which tasks depend on a single OEM or specialist contractor. They should also understand what happens when deferred maintenance, contractor delay and a new equipment failure coincide.
Holding more stock is not automatically the answer. The better response may involve revised task strategies, local repair capability, alternative specifications, framework arrangements, improved preservation, condition monitoring or clearer prioritisation. The right intervention depends on the operating evidence.
05A workaround is not yet an operating model
Disruption produces workarounds: manual reports replace failed interfaces, alternative suppliers are approved, maintenance is resequenced, controls are intensified and decisions move to temporary forums. Some are necessary and effective.
The danger begins when a temporary response becomes permanent by inertia. Workarounds often sit outside standard controls, rely on exceptional effort and obscure the true cost of keeping the operation stable. They should therefore be recorded with an owner, risk assessment, review date and exit condition.
A structural operating-model change is different. It may alter roles, decision rights, process design, data ownership, contractor strategy, inventory policy or performance measures. It should be designed deliberately, tested against the operating context and embedded across the organisation.
The distinction is commercially important. Some problems can be resolved through better ways of working within business as usual. Others genuinely require system or capital change. Treating every weakness as a technology problem wastes money. Treating a structural weakness as a temporary exception stores up risk.
06A five-question executive stress test
Before commissioning a large resilience programme, an executive team should be able to answer five questions plainly.
- What are the five external dependencies whose loss would materially affect our operating plan?
- How quickly would management know that one of them had failed?
- Who has authority to change the operating plan, and is that authority understood across the organisation?
- Which existing operational weaknesses would become significantly worse during disruption?
- Which interventions can be handled through better ways of working, and which genuinely require system or capital change?
These questions do not produce a complete resilience plan. They reveal whether management understands the operating model well enough to direct one. Hesitation, conflicting answers or dependence on one person's knowledge are findings in their own right.
07From stress test to deliberate change
The Oclas method starts with the operation as it is, not as a policy or system describes it.
Map documented process → validate beside people doing the work → quantify differences → separate BAU fixes from system change → embed through KPIs, training and coaching.
That sequence matters in resilience work. The documented process establishes the intended controls. Validation beside operators, maintainers, planners and contractors shows what actually happens. Quantification identifies which differences are material. Separation prevents everyday fixes from becoming oversized transformation programmes, while ensuring that genuine system or capital requirements are not disguised as local workarounds.
Embedding is the final test. New decision rights, priorities and controls have little value if they remain in a report. They need to appear in performance measures, role expectations, training, coaching and the routines through which the operation is managed.
The Strait of Hormuz is an acute example, but the operating question is wider. Routes close. Contractors withdraw. Systems fail. Regulations change. Skilled people become unavailable. Demand moves faster than the plan. An organisation cannot predict every disruption, but it can understand the assumptions on which its operation depends.
Resilience is not simply the ability to survive disruption. It is knowing enough about your operating model to change it deliberately when the assumptions beneath it change.
OC