Every risk professional already knows their risks are connected — it is why we talk about knock-on effects, cascades and systemic risk. Yet the dominant tools have stayed lists: risks in rows, each scored on its own, on a grid of likelihood and impact.
What a list cannot do
A register tells you what exists, and at best that a dependency exists somewhere. It cannot show you how a failure travels, where stress concentrates, or which quiet, unremarkable point everything happens to pass through. You cannot see a cascade in a cell, or a single point of failure in a row.
What a network adds
Model the same risks as a connected system and the structure becomes legible: the dependencies and their directions, the single points of failure, the paths a disruption would take, and the feedback loops where risk returns to its source.
None of this is new science — the methods behind network analysis are decades old and power everything from epidemiology to supply chains. What has been missing is a way to point them at the structural questions risk management has always asked but never answered directly. The shift is overdue, not revolutionary.
Not a replacement
Network modelling does not replace your existing methods. You still assess individual risks on their own terms. You also, for the first time, see the system they sit within — and that system's structure is where the single points of failure and hidden dependencies actually live.