A country can be politically unstable while a specific company remains relatively protected.
Another country can appear stable while a company's business model contains a single catastrophic dependency.
This is why geopolitical risk cannot be understood through country ratings alone.
The correct unit of analysis is exposure.
Exposure asks how closely a company, project, transaction or counterparty is connected to a geopolitical development.
Country exposure matters, but it is only one layer.
A serious assessment may examine:
country exposure,
sector exposure,
counterparty exposure,
transaction exposure,
financial exposure,
regulatory exposure,
supply-chain exposure,
technology exposure,
and reputational exposure.
The key principle is relational.
Risk does not exist merely because a geopolitical event exists.
Risk emerges when that event can reach something the organization depends upon.
Suppose a new export-control regime is announced.
For one company it is irrelevant.
For another it affects 5% of sales.
For a third it prevents access to a component without which its core product cannot be manufactured.
Same regulation.
Three radically different risks.
Measurement therefore begins with dependencies.
What must remain true for the business model to work?
Which licences must remain valid?
Which banks must continue providing services?
Which suppliers cannot easily be replaced?
Which technologies are mission-critical?
Which markets generate indispensable revenue?
Which people hold irreplaceable knowledge or signing authority?
Once these dependencies are identified, geopolitical scenarios can be mapped against them.
This creates a much better question than:
“How risky is Country X?”
The question becomes:
“How vulnerable is our operating model to defined changes occurring in Country X?”
This shift has major consequences for management.
It allows risk to be prioritized.
It prevents management from treating all geopolitical developments as equally urgent.
And it creates the foundation for mitigation.
Because once exposure is mapped, the organization can start asking:
Can the supplier be replaced?
Can the payment route be diversified?
Can the licence structure be changed?
Can inventory be increased?
Can the contract include exit provisions?
Can the investment be staged rather than committed at once?
Measurement therefore converts geopolitical analysis into corporate strategy.
It also reveals something uncomfortable: organizations often discover that their largest vulnerabilities are not where management expected them to be.
The obvious risk may be political instability.
The true vulnerability may be the absence of a second bank.
The visible problem may be trade restrictions.
The real breakpoint may be a single-country cloud architecture.
That is why measurement must precede mitigation.
The question now becomes:
Once exposure has been identified and measured, what can the company actually do?
That is the subject of resilience.