Imagine the production manager reporting to the board: "On average, our IT outages last only four hours." A collective sigh of relief. Four hours—you can survive that. Unfortunately, this average is made up of many small disruptions lasting just a few minutes and a single total outage lasting forty days. The CFO looks at the figure again; the risk manager looks at the production calendar. Both see the same company—but clearly not the same risk. The average says: four hours. Reality says: forty days of production downtime, angry customers, contractual penalties, a serious threat to the company's survival, and very intense weeks for the board of directors.
That is precisely the pitfall of averages. They are mathematically correct, appear credible, and have the wonderful ability to smooth over unpleasant extremes. Many small incidents and one event that threatens the company's very existence result in a figure that's perfect for designing PowerPoint slides. Unfortunately, companies don't pay for their crises based on averages. No supplier fails "on average," no ransomware encrypts "on average" 37 percent of the ERP system, and no liquidity crisis cares that everything has actually gone quite smoothly over the past five years.
The average isn't wrong, therefore. It just often answers the wrong question. Anyone who wants to understand risks should ask less often, "What usually happens?" and more often, "What can happen if several things go wrong at the same time?" How long could production actually be halted? What happens if ERP, logistics, and invoicing are all affected simultaneously? How far can a supplier failure ripple through the company due to interdependencies? And at what point does a technical glitch turn into a profit problem, the profit problem into a liquidity problem, and the liquidity problem into a call to a restructuring consultant? This is exactly where scenario analysis, simulation, and the study of probability distributions start to get interesting. Not because they predict the future, but because they reveal which futures could turn out to be particularly unpleasant.
Good risk management therefore focuses not primarily on the comfortable center of a distribution, but on the scenarios where things really hurt. That doesn't mean assuming the end of the world is imminent everywhere. It means systematically addressing plausible critical developments before they become reality. Average values help us understand what usually happens. Critical scenarios help us survive when something unusual happens.
Or to put it another way: If a river is, on average, 1.20 meters deep, that's an interesting piece of information. But to decide whether to wade across, a second piece of information would be quite helpful: Where is the five-meter-deep hole?




