An outage doesn't change the price of redundancy

The price of redundancy after an outage is the price the week before it. What the failure moved is the burden of proof, and the burden reverts.

Share
An outage doesn't change the price of redundancy
Two tracks against one timeline, split by the failure. The price of redundancy is a flat line that never moves across it. The default answer is a step: no while the spend has to argue, yes while the exposure argues, then back to no. What the failure moved was the burden of proof, and the burden reverts.

A failure moves the burden of proof.

Before it, the spend argues against the cost of carrying the exposure. The only record is a stretch of time in which nothing happened, and that reads as evidence that carrying it is cheap. Every time the proposal loses, that counts as a decision that the exposure is acceptable.

Then the failure lands, and the same proposal no longer has to argue. The exposure now argues for yes, and the default is yes. The vendor's price list is what it was.

That reversal is what gets called a recalibration. It expires. A reversal survives only as a design constraint or a recorded deferral.

The total can be written before anything breaks

No single function owns the whole total.

Service credits are capped in the contract, and finance can read the cap off the page. Concessions get negotiated outside the contract, so the cap doesn't cover them. The renewal that doesn't happen sits on a dashboard the sales organization already maintains. The price increase assumed in next year's plan is one you don't take during a remediation year, and that plan is a document with a version number. The later terms fall into periods far enough out that nothing attributes them to the event, which is why the total remains understated even after adding them up.

A failure changes what that estimate is worth in a room. The same total that gets waved off on Monday is taken as given on Friday, and the price it is weighed against never moves.

The argument stays closed for a while, and that is all the failure bought. The changes that cost almost nothing are included in the same proposal as the second site and the warm replica, so they are rejected along with the overall price.

The list is already written, one line per proposal that lost on cost, each with the price and the date. None of them carries the value of the exposure.

A funded standby is an artifact until somebody restores from it

A failure produces a budget line about as readily as it produces a changed question, and the two are hard to tell apart for a couple of quarters.

The line item buys the thing that matches the failure—a second copy, in a second location, of the system that went down. The purchase itself is sunk on day one, and the review cycle only sees the recurring half: the standby's monthly charge, the second circuit, the support contract, the hours. Lines like that die when they lose an owner. The person who pushed it moves on, a percentage cut lands on a cost center, and nobody picks it up.

Money for the copy buys a copy. Keeping the restore proven is separate work, and it stops when urgency is the only thing driving its schedule.

So the copy keeps completing every night, and the report stays green because it checks that a copy was written. The standby it would land on comes off the budget two cycles after the incident that funded it. The next event finds the data present and unverified, with nowhere to put it; provisioning is now the first step in recovery. The clock starts when the incident does.

The changed question is short: what does it cost to carry this? It survives by moving. It shows up in the design of systems that had no part in the failure, where it constrains something not yet running. That's the test for which one a failure produced: does the question come up in reviews of systems that didn't break, raised by an engineer who wasn't in the incident?

A deferral carries a number, an owner, and a date

Full replicas of everything, in every location, can cost more than the service they protect earns, and buying them is a slower way to lose the same business the outage threatened.

So the answer stays yes, and the replicas wait on a threshold. A deferral is written down: the exposure, its value, who holds it, and the price or date that ends the wait. A reversal is remembered instead, and the memory fades. Once it does, the spend has to justify itself again. Restating an exposure quarterly is cheap. A decade of quarterly restatements with nothing shipped is a reversal wearing a calendar reminder.

Every month of the wait carries the same exposure that already landed once, and the inexpensive changes have to keep shipping through it, or the deferral is another word for the same no.

The exposure is legible on the day the line is installed

One physical path into a building, and an obligation to stay reachable through it. What answers that? A second path and a second invoice buy nothing on their own. Two vendors reselling the same last mile share the trench, and the backhoe takes both.

That reasoning runs before anything breaks. An engineer states the exposure and estimates a loss the record still says is small. When one person owns the system and signs off on both the budget and the risk, that's the easy case. Everywhere else, one person has the fact and has to get approval.

A catastrophe makes that approval free, and it stays free only as long as someone still carries the number in their head. A failure supplies evidence.

The fix was available at the same price the day before.