The Trojan Horse: An Operational Risk and Resilience Case Study

Can an organization prepare for a risk it never imagined?

Shubham Ghotankar

8/12/20266 min read

The story of the Trojan Horse is one of the most recognizable tales from the ancient world.

After years of unsuccessful attempts to breach the fortified city of Troy, the Greeks seemingly withdrew, leaving behind a large wooden horse. The Trojans brought the horse within their walls, unaware that Greek soldiers were concealed inside. Once night fell, the soldiers emerged, opened the city gates and enabled the returning Greek forces to enter.

Whether viewed through literature, mythology or popular retellings, the story presents an interesting thought experiment from an Operational Risk perspective.

Troy possessed what appeared to be formidable defences: fortified walls, guarded entry points, military capability and years of experience defending itself against an external enemy.

Yet the Greeks did not need to overpower Troy's strongest defence.

They changed the attack path.

The controls designed to protect Troy remained formidable against a conventional external assault, but the Trojan Horse exploited something deeper: an assumption about where the threat would originate and how it would materialise.

This raises an important question for modern organisations:

What happens when the assumptions underlying our strongest controls prove wrong?

1. Not Every Risk Can Be Predicted

Risk management involves identifying potential events, assessing their likelihood and impact, designing controls and preparing responses.

Techniques such as Risk and Control Self-Assessments (RCSAs), scenario analysis, emerging-risk assessments and historical loss analysis help organisations understand their exposure.

But there is an inherent limitation.

Risk identification is based, at least partly, on what we already know, have experienced or can reasonably imagine.

An organisation can construct numerous scenarios, but it cannot identify every possible combination of events through which disruption might occur.

The lesson from Troy therefore should not be:

"They should have predicted the Trojan Horse."

That would impose an unrealistic expectation on risk management.

A more useful question is:

Was the organisation prepared for the possibility that its understanding of the threat could be incomplete?

This distinction matters.

Effective risk management should improve our ability to anticipate threats, but it should also acknowledge uncertainty. There will always be scenarios that fall outside previous experience, existing models or established assumptions.

The objective cannot therefore be perfect prediction.

It must also include preparedness for the unexpected.

2. Challenge the Assumptions Behind the Controls

Perhaps the most interesting risk-management lesson in the Trojan Horse story is not the horse itself.

It is the assumption behind Troy's defence.

For years, the principal threat had been external. The city's fortifications were therefore designed around keeping an invading army outside.

The walls did not necessarily fail.

Instead, the Greeks found a way to make those walls less relevant.

Modern organisations also build controls around assumptions.

For example:

  • a critical supplier will remain available;

  • a backup system will operate when the primary system fails;

  • authorised credentials will only be used by authorised individuals;

  • a disruption affecting one business unit will remain contained within it;

  • reconciliations will identify processing errors before they create material impact;

  • employees will follow established escalation procedures.

These assumptions may be entirely reasonable.

The risk emerges when an organisation stops recognising them as assumptions.

Controls should therefore not only be tested for whether they operate as designed. Organisations should periodically challenge the assumptions upon which their design depends.

Questions such as these become important:

What has to remain true for this control to protect us?

What happens if that assumption is wrong?

Could the control be bypassed without technically failing?

What other controls would detect the resulting exposure?

A control can operate exactly as designed and still prove insufficient if the environment in which it was designed has changed.

3. Prevention Is Only One Layer of Protection

This leads to a fundamental principle of Operational Resilience.

Preventive controls matter enormously, but organisations should not build their survival around the assumption that prevention will always succeed.

Once the Trojan Horse entered Troy, the relevant question changed.

It was no longer:

How do we prevent the enemy from entering?

It became:

What capabilities exist now that the preventive defence has been circumvented?

The same transition occurs during a modern operational disruption.

A mature control environment therefore requires multiple layers:

Prevent

Reduce the probability that the event occurs.

Detect

Identify quickly when preventive controls have failed or unusual activity is occurring.

Respond

Activate appropriate decision-making, escalation and response mechanisms.

Contain

Limit the spread and impact of the disruption.

Recover

Restore critical operations within acceptable parameters.

This is where Business Continuity Management and Operational Resilience become particularly important.

BCM prepares organisations to continue or restore critical activities following disruption. Operational Resilience takes the perspective further by asking whether important business services can continue through disruption within acceptable impact tolerances.

The objective is therefore not simply to build stronger walls.

It is to ensure that the organisation can continue functioning when a wall, system, supplier, process or other critical dependency does not protect it as expected.

4. Internal Resilience Matters as Much as External Defence

The Trojan Horse also illustrates the danger of focusing disproportionately on the perimeter.

Troy's formidable external defences became far less valuable once the threat was operating inside them.

Modern organisations face a similar challenge.

Consider cybersecurity.

Strong perimeter protection may reduce the likelihood of unauthorised access, but organisations also need controls capable of detecting abnormal behaviour after access has occurred.

The same principle applies beyond cyber risk.

A third-party provider may successfully pass initial due diligence but subsequently experience a major disruption.

An automated process may pass implementation testing but later behave unexpectedly in production.

An authorised employee may possess legitimate system access but use it incorrectly or inappropriately.

A preventive control may therefore reduce exposure without eliminating it.

This is why internal monitoring, detective controls, exception management, incident response and recovery capabilities are not secondary protections.

They form part of the same defence.

The strength of an organisation's external defences should not create confidence that internal disruption cannot occur.

5. Risk Culture: Is Challenge Merely Allowed, or Is It Heard?

There is another dimension to the traditional Trojan Horse narrative that is particularly relevant to risk governance.

The decision to bring the horse into Troy was not necessarily without challenge. In traditional accounts of the story, voices warned against accepting it.

This introduces a different risk-management problem.

Sometimes the risk is not unidentified.

It is identified but insufficiently challenged, escalated or acted upon.

An organisation can have:

  • risk policies;

  • committees;

  • escalation mechanisms;

  • independent Risk and Compliance functions;

  • whistleblowing arrangements;

  • sophisticated risk assessments;

and still make poor decisions if challenge is culturally discouraged or routinely overridden.

Effective risk culture therefore involves more than allowing someone to raise a concern.

It requires an environment in which credible challenge can influence decisions.

That raises several governance questions:

Can employees challenge prevailing assumptions without fear of consequences?

Are dissenting views documented and considered?

Does seniority determine whose assessment prevails?

What happens when commercial urgency conflicts with risk concerns?

Can an issue be escalated when the initial decision-maker disagrees?

The existence of challenge is not evidence of effective governance.

What matters is what the organisation does with it.

6. From Known Scenarios to Organizational Resilience

Scenario analysis remains an important risk-management tool.

Organizations should ask what could go wrong and consider severe but plausible events.

But resilience requires another question:

What capabilities would we need if something went wrong in a way we did not anticipate?

That subtly changes the objective.

Instead of designing an individual response for every conceivable event, organizations develop capabilities that can operate across multiple disruption scenarios.

For example:

  • effective incident-management structures;

  • clearly defined decision authority;

  • alternative processing arrangements;

  • business continuity plans;

  • redundancy for critical dependencies;

  • timely management information;

  • crisis communication mechanisms;

  • escalation protocols;

  • tested recovery capabilities.

These capabilities may prove valuable even when the precise event was never anticipated.

That is one of the distinctions between trying to predict disruption and developing the capacity to withstand disruption.

Both matter.

Neither replaces the other.

7. The Often-Invisible Value of Risk Management

There is one final lesson I take from the story.

Risk management can sometimes resemble a hygiene factor within an organization.

When controls operate effectively, incidents are detected early, vulnerabilities are addressed and disruptions are contained, very little may appear to happen.

A control prevents a loss.

A reconciliation identifies an exception.

An employee escalates suspicious activity.

A continuity plan allows a critical operation to continue.

A challenge from Risk changes a decision before the exposure materialises.

The organisation continues operating.

Because the adverse outcome never occurs, the value created by preventing or containing it can be difficult to observe.

The opposite is much more visible.

When a major control fails, a disruption cannot be contained or an organisation cannot recover, the value of the missing capability becomes immediately apparent.

This creates an interesting challenge for the risk profession.

The success of risk management should not be measured only by the absence of incidents. Nor should its value become visible only after something goes wrong.

Its value lies partly in helping organisations take risk confidently while maintaining the capability to absorb the consequences when uncertainty materialises.

The Lesson from Troy

The Trojan Horse should not teach modern risk professionals that every threat can—or should—be predicted.

Quite the opposite.

It reminds us that our understanding of risk will always be incomplete.

Risk assessments matter.

Scenario analysis matters.

Preventive controls matter.

But so do the assumptions behind those controls.

And when prevention eventually fails, detection, response, containment, continuity and recovery determine whether an unexpected event remains a manageable disruption or becomes an existential one.

Perhaps the enduring Operational Risk lesson from Troy is therefore not:

"How could they have predicted the horse?"

It is:

"How prepared were they for their assumptions to be wrong?"

Organizations do not need perfect foresight.

They need the ability to challenge what they believe, detect when reality differs from those beliefs, and remain resilient when the unexpected happens.

Portfolio

Showcasing my skills, education, and experiences online.

Connect

shubhamghotankar@gmail.com

+32 0465 86 03 92

© 2025. All rights reserved.