The Hidden Market for Resilience: Why Incentives, Not Just Enemies, Shape System Failure
Hatched by Ben H.
Jun 21, 2026
9 min read
2 views
84%
What do hospital supply contracts and critical infrastructure attacks have in common?
At first glance, they seem like different worlds. One is about buying gloves, implants, and syringes for hospitals. The other is about nation state threats, cyber intrusions, and sabotage of power grids, ports, and communications networks. But both point to the same uncomfortable truth: systems fail when the people inside them are paid to optimize the wrong thing.
That is the deeper question connecting these two domains. Not simply, “Who is attacking?” but, “What incentives make a system easy to influence, fragile to stress, and slow to correct itself?”
In hospitals, purchasing intermediaries can quietly shape what gets bought, who wins, and how much the system pays. In national security, a hostile power does not need to overpower every defense directly if it can exploit the seams in the system, target dependencies, and turn everyday infrastructure into a pressure point. In both cases, the real vulnerability is not only technical. It is structural.
The lesson is bigger than healthcare or cyber conflict. Modern institutions often look sturdy because they are large, regulated, and data rich. Yet they can still be deeply vulnerable if their incentives reward scale over resilience, familiarity over competition, and short term efficiency over long term robustness.
The strange fragility of systems that seem optimized
Hospitals spend enormous sums on supplies, and those purchases are not a side issue. They are one of the largest budget categories after payroll. That means procurement is not administrative trivia, it is a core operating function. When a system that central is routed through intermediaries with commissions, fees, and market power, you should immediately ask a basic question: optimized for whom?
This question matters because large procurement networks often promise savings while also concentrating influence. If a middle layer is paid by manufacturers, then its incentives can drift away from the end customer, even when everyone is acting legally and within formal rules. The problem is not that every intermediary is corrupt. The problem is more subtle: an arrangement can be simultaneously efficient in one dimension and distorting in another.
That same pattern appears in critical infrastructure. A hostile actor does not need to destroy everything to create strategic advantage. It can target points of reliance, map dependencies, and position itself to create disruption later. In a highly connected society, the real leverage is often in the hidden middle layers: software vendors, logistics chains, communications backbones, and the institutional routines that keep the lights on and the patients cared for.
This is why modern systems often feel secure until they are not. They are built around normalized trust. Everyone assumes that suppliers will compete fairly, that intermediaries will align with the buyer, that software updates are safe, that a foreign adversary is only stealing data rather than preparing physical disruption. But normalized trust is not resilience. It is a condition that works only until an adversary, or a badly designed incentive structure, exploits it.
The most dangerous part of a system is often the part that looks like routine.
Why intermediaries can become strategic choke points
There is a tempting myth in modern institutions: if you cannot fully trust the final product, just add a layer of experts, brokers, or gatekeepers. The idea sounds prudent. In practice, this often creates a second order problem. The gatekeeper becomes a new center of power, and that power tends to accumulate quietly because it is justified as “professional expertise” or “operational necessity.”
In hospital procurement, intermediaries can create economies of scale, standardize contracts, and reduce transaction costs. Those are real benefits. But once the intermediary controls access to volume, its role shifts from facilitator to market shaper. It can favor large manufacturers, entrench incumbents, and make it harder for smaller innovators to break in, even when those innovators offer better or cheaper solutions.
This is not merely a procurement story. It is a governance story. Whenever a system inserts a middle layer that is paid by one party while claiming to serve another, it creates an incentive triangle:
- The buyer wants lower cost, higher quality, and flexibility.
- The seller wants access, share, and margin.
- The intermediary wants volume and predictable revenue.
The intermediary says it is aligning the other two. But if its revenue grows with transaction size rather than with actual outcome quality, then its incentives may subtly favor whatever keeps the pipeline largest and most stable. Over time, the system can become less open to disruption, even as it becomes more “efficient.”
National security has an analogous structure. A state actor probing critical infrastructure is exploiting the fact that modern societies depend on a layered architecture of vendors, protocols, and access points. The attack surface is not just the obvious front door. It is the web of dependencies behind it. That is why “broad and unrelenting” threats are so hard to counter. They operate across many layers, many sectors, many assumptions.
The same logic applies to procurement. When supply chains become consolidated around a few dominant channels, resilience declines. The system may lower unit prices while raising systemic fragility. That tradeoff is often invisible until a shock arrives.
Efficiency is not the same thing as resilience
This is the key synthesis: a system can be cheap, streamlined, and still dangerously brittle.
In hospitals, purchasing arrangements that maximize discounts from a handful of large suppliers may look successful on a spreadsheet. But if those same arrangements reduce supplier diversity, suppress newer entrants, or embed conflicts of interest, then the hospital has purchased a narrow kind of efficiency at the expense of adaptability. The institution may save pennies today and pay dearly tomorrow when a supply shortage, quality failure, or price shock hits.
In critical infrastructure, the same mistake appears when organizations treat cybersecurity or supply chain management as compliance tasks instead of resilience design problems. Passing a checklist is not the same as surviving a coordinated attack. A system can be technically compliant and still operationally fragile if it has too many single points of failure, too much dependence on a small number of vendors, or too little visibility into downstream dependencies.
A useful mental model here is the difference between optimized fragility and designed resilience.
- Optimized fragility: the system looks lean, centralized, and cost effective, but one disruption cascades widely.
- Designed resilience: the system preserves redundancy, diversity, and slack so that it can absorb shocks.
The irony is that organizations often confuse slack with waste. Yet slack is what allows adaptation. In hospitals, that might mean maintaining multiple sourcing paths, not just one preferred channel. In infrastructure, it might mean segmentation, manual fallback procedures, and vendor diversity. In both cases, resilience costs money upfront, but fragility always costs more in a crisis.
Cheap systems are often just systems that have not yet been tested by the full price of failure.
The national security angle sharpens this point. A hostile power need not win a direct confrontation if it can rely on the fact that civilian systems have been optimized for convenience rather than resistance. That is why infrastructure targeting is so alarming. It exploits the gap between what institutions measure and what actually keeps society functioning under pressure.
The real question is governance, not just technology
It is easy to respond to these problems with more technology. Better software, more dashboards, more audits, more automation. Those tools help, but they do not solve the underlying issue if the incentive structure remains misaligned.
The deeper problem is governance under asymmetry. In both procurement and infrastructure defense, one side often sees the full system while the other side sees only fragments. A hospital may not fully observe how a purchasing organization’s contracts shape its long term supply options. A nation may not fully observe how hostile actors are mapping dependencies across sectors. In both cases, the most important risks are often distributed, delayed, and difficult to attribute.
That makes accountability hard. If a supply choice raises costs over three years, who gets blamed? If a cyber prepositioning campaign creates the conditions for future disruption, who notices in time? Systems with delayed consequences often drift toward the easiest visible metric, not the most important hidden one.
This is why governance must be redesigned around dependency awareness. Decision makers should ask not only, “What did this save today?” but also, “What leverage did this create tomorrow?” The goal is to make hidden concentrations visible before they become crises.
A practical framework is to evaluate any core institutional dependency through four lenses:
- Control: Who actually shapes the decision?
- Compensation: Who gets paid, and for what behavior?
- Concentration: How many alternatives exist if one channel fails?
- Contingency: What happens when the preferred path is unavailable?
If a hospital cannot answer these questions about its purchasing architecture, it is vulnerable. If a critical infrastructure operator cannot answer them about its vendor stack, software dependencies, or incident response pathways, it is vulnerable. The domain changes, but the logic does not.
What matters is not whether a system has intermediaries, vendors, or defenses. It is whether those layers are designed to promote adaptability under stress or merely efficiency under calm conditions.
Key Takeaways
-
Ask who is paid by whom. If an intermediary is compensated by the seller while claiming to serve the buyer, inspect the incentives carefully. Formal legality does not guarantee aligned outcomes.
-
Treat concentration as a risk, not only a cost saver. A small number of dominant suppliers or vendors can reduce procurement friction today while increasing fragility tomorrow.
-
Separate compliance from resilience. Passing audits or securing discounts does not mean a system can survive shocks, shortages, or attacks.
-
Map your dependencies before a crisis does it for you. For hospitals, that means procurement pathways, alternate suppliers, and substitution plans. For infrastructure, it means vendor chains, access points, and fallback procedures.
-
Measure leverage, not just price. The cheapest option may create the most expensive future dependency.
The hidden cost of convenience
The most unsettling connection between procurement and critical infrastructure is that both reveal how modern life depends on invisible arrangements that feel neutral until they are exposed as power structures. A hospital supply contract is not just a contract. It is a mechanism that shapes resilience, competition, and patient care. A foreign threat to infrastructure is not just a geopolitical headline. It is a test of whether civilian systems have been built to absorb pressure or to amplify it.
We often think fragility comes from obvious weakness. More often, it comes from hidden convenience. The system works beautifully when everyone behaves as expected, when supply chains are stable, when adversaries are quiet, and when no one asks too many questions about who benefits from the structure itself. Then the shock arrives, and the elegant machine reveals itself as a house of tightly coupled parts.
The deeper lesson is not to eliminate intermediaries or reject scale. It is to stop mistaking centralization for competence and cost savings for strength. The institutions that endure are not the ones that simply minimize friction. They are the ones that preserve enough diversity, transparency, and slack to remain governable when the environment turns hostile.
In that sense, procurement and national security are not separate topics at all. They are both about the same civilizational problem: how to build systems that can be efficient without becoming easy to break.
That may be the most important design challenge of the modern era. The question is no longer whether our institutions are connected. Of course they are. The question is whether those connections create resilience, or whether they quietly turn everyday efficiency into strategic vulnerability.
Sources
Hatch New Ideas with Glasp AI 🐣
Glasp AI allows you to hatch new ideas based on your curated content. Let's curate and create with Glasp AI :)
Start Hatching 🐣