𝗪𝗵𝗲𝗻 𝗮 𝘀𝘆𝘀𝘁𝗲𝗺 𝗮𝘁 𝗻𝗮𝘁𝗶𝗼𝗻𝗮𝗹 𝘀𝗰𝗮𝗹𝗲 𝗳𝗮𝗶𝗹𝘀, 𝘁𝗵𝗲 𝗼𝘂𝘁𝗮𝗴𝗲 𝗶𝘀𝗻'𝘁 𝘁𝗵𝗲 𝗿𝗲𝗮𝗹 𝘁𝗲𝘀𝘁. 𝗧𝗵𝗲 𝗽𝗿𝗲𝗽𝗮𝗿𝗮𝘁𝗶𝗼𝗻 𝗶𝘀.

On 8 September, a technical fault in the UK’s air traffic control flight data system led to around 2,000 flight cancellations, grounded aircraft and widespread disruption. I saw it up close: a colleague visiting me from overseas was caught up in the chaos.

I can't say how NATS prepared internally, and I won’t speculate. But as an outsider looking in, it reinforced a point I come back to often. At scale, resilience has to be designed in long before the worst day arrives, through an operating model that can ‘Plan, Prepare and Perform’, and adapt to whatever form unexpected events take.

A month before the outage, I published my framework on exactly this: The Three Ps of Performant Systems. It now feels worth revisiting. The original, in full framework, is reposted below.

→ Plan: map the blind spots, the unhappy paths and the ‘what if?’ scenarios.
→ Prepare: stress test your runbooks and escalation paths while the sun is shining, not once the storm arrives.
→ Perform: the final 10% is how your team acts under pressure, so rehearse it and build the crisis muscles before they're needed.

Forewarned really is forearmed. Resilient systems give you more than hope: if the worst happens, the way back to normal is a clear, well-trodden path.



Original Three Ps of Performant Systems publication post here:
https://www.ianfinn.co.uk/perspectives/2026/8/4/your-next-incident-wont-define-your-systems-fortunes-your-work-before-the-storm-will

The Three Ps of Performant Systems Framework (© 2026 Ian Finn. All rights reserved.)

Next
Next

The Identity Paradox: Reflections on AI from the boardroom and from the back of a taxi