Behind every measure is a decision, and a decision is only complete when you can show that it works. A plan that has never been tested is not a plan.
Make digital dependency governable
Hartwich Risk & Resilience helps executives, boards and owners see what critical processes depend on, what is vulnerable, who is accountable and where evidence is missing.

Five questions reveal what really matters
One fixed line of enquiry. Five simple questions.
ContinuityWhat must not stop?
The critical process, service, customer promise or information that is directly hit by disruption.
DependencyWhat does it depend on?
The systems, suppliers, data, access rights, processes or AI applications beneath that critical process.
ExposureWhat can go wrong?
The disruption, error, attack, decision failure or dependency that starts to matter to the business.
OwnershipWho is accountable?
The person or role accountable for the decision, the follow-up, whether it works and the reporting on it.
EvidenceWhere is the evidence?
The evidence that agreements, measures and decisions exist, are carried out and work as intended.
A lot is in place, but the overall picture is fragmented
Policies, suppliers, tools and reports only create value once it is clear which critical dependency they actually cover, who is accountable and what evidence counts.
A lot is in place
Not enough coherence
Ownership and evidence
You know what must not stop
The Reality Check examines whether those dependencies are clear enough to manage.
Governable means: clear what is critical, what it depends on, what can go wrong, who is accountable and where the evidence lies.
The Reality Check does not start with technology, compliance or standard checklists. It starts with what must not stop and tests what lies beneath it.
One concrete question defines the scope
A Reality Check is only valuable when it is clear what the executive, board or owner needs answered.
The scope follows your question
Sometimes it is cyber. Sometimes IT. Sometimes AI. Often the question touches several domains at once.
Cyber
IT
AI
Combination
A compact overview
A sharp view of what is substantiated, what rests on assumptions, where ownership is missing and which decisions are needed.
A Reality Check asks little of you and your team: a few conversations and the documents you already have. The memo gives you substantiated input for your own decision and your own communication, internally or towards your supplier.
From analysis to decision.
Responsibility becomes manageable once it is clear what needs attention first, who is accountable and what evidence is missing.
- Core question and scope
- Core picture of the critical dependencies
- Main exposure and uncertainties
- Decisions that are explicitly required
- Ownership and execution
- Available and missing evidence
- Where relevant: 30/60/90-day advice
What you do with it
A memo is only useful if something changes because of it. These are the conversations where a Reality Check earns its keep.
The management meeting
The decisions that need to be made are set out, each with an owner. The conversation shifts from "we should do something about cyber" to who decides what, and by when.
The conversation with your supplier
You stop asking whether it is all under control and start asking for the evidence that is missing. The gaps become the agenda for that meeting.
The investment decision
A quote for a tool, a migration or a certification programme can be weighed against the exposure you actually have, rather than the exposure the vendor points to.
The question from outside
When a customer, insurer or accountant asks how you manage digital risk, you have a substantiated answer rather than an assumption.
Whatever needs to happen next can then be assigned where it belongs. A Reality Check makes sure you know what you are assigning.
How findings bear on each other
A fictional example, included to show the form and the connections. This is not a client case.
Manufacturing company, 60 employees. The production line runs on a network and systems managed by a single external IT provider. Central question: can we show that we are in control of that provider?
One finding
- The observation
- IT management was outsourced years ago and has not been reviewed since. What the provider is expected to do about patching, access control and recovery after an outage is set out in a quote from 2019, not in a current contract.
- Why it matters
- Without a current contract there is no standard to hold the provider to. What actually happens may well be sound; you simply cannot establish that, and so you cannot steer on it.
This finding does not stand on its own. Other observations from the same case bear directly on it:
- OwnershipNo one is formally accountable for this provider's performance. In practice the operations manager picks it up. As long as the standard is missing, there is nothing to hold anyone to, the two keep each other in place.
- ReportingThere is monthly reporting, but it has never been set against the contract. Reporting without a standard mainly confirms that something is being measured, not that it is right.
- Recovery after an outageHow much downtime production can absorb has not been recorded anywhere, so the provider has never had to deliver against it. The same gap, one layer down.
Each of these can be addressed on its own, and doing so achieves little. Together they point to one thing: there is no recorded standard the provider is held to. That is what the decision is about. Making that connection visible is the work; a checklist does not produce it.
A scoped Reality Check with a fixed starting price
The final price depends on your question, the chosen scope and the information available.
From €4,990 excl. VAT
A scoped Reality Check with limited document review, analysis, clear interpretation and a compact memo.
- One clear core question
- A bounded scope
- No hourly rate as the starting point
A fit when you are looking for clarity you can act on
Not a fit when you want to outsource execution, certification or formal assurance.
Fits with
- A concrete question
- Uncertainty about cyber, IT or AI
- A fragmented overall picture
- Preparing a decision
- Evidence is missing or unclear
Does not fit with
- Audit or pentest
- Formal assurance statement
- Certification
- Implementation project
- Tool selection or interim CISO
Focused enquiry, limited burden, clear outcome
The method is compact: sharpen the question, review the relevant information, formulate conclusions and explain them clearly.

Fine words at director level are only valuable when the reality beneath holds up
I am Erik Hartwich. Since 1990 I have worked in the digital systems organisations run on: as a network and systems administrator, infrastructure architect and security advisor. From the data centre of a retail group to the security standards of one of the largest telecom operators in the Netherlands. Not from the boardroom, but from the operations beneath it.
That background is why a Reality Check holds up. I have seen up close where assumptions at the top and technical reality diverge, and I test whether that is the case for you.
Most of what runs in a data centre I have built, managed or improved myself. I use that depth to test whether the picture at the top matches what actually lies beneath it.
- Technical depth without unnecessary jargon
- An eye for systems, suppliers and processes
- Independent assessment
- A sharp separation of dependency, ownership and evidence
No tools, no implementation, no stake in the outcome. My full career history is on LinkedIn.
Insights on cyber, IT and AI risk
Short analyses of situations where digital dependency becomes relevant at director level.
Effectiveness you cannot demonstrate
When security measures exist, but their effectiveness is not visible enough.
Dependency becomes critical
When systems, suppliers or technical debt become business-critical.
AI use grows faster than decision-making
When AI grows faster than decision-making, permissions, logging and human approval.
Discuss your question
In a short conversation we determine whether a Reality Check fits, what scope makes sense and which decision needs preparing.
- What is the trigger?
- What must not stop?
- What must you be able to decide?

