The Motivation Night event,Why has geopolitics become a real issue for companies too?

Luca TenziGeopolitics, a framework I had the opportunity to test in the field in Latin America while working for Telecom Italia in the early 2000s—namely, the replacement of the logic of military conflict with that of economic and commercial confrontation between states—is nothing new in the strategic plans of large corporations. Globalization has simply brought to the surface what had always been underlying. SMEs, historically less exposed to this confrontation, only became aware of it when they began to look beyond national borders, driven by the need to grow in new and more distant markets.

The quantum leap came with systemic crises. Patrick Trancu, a crisis manager from Lugano and one of Europe's leading experts on the subject, identifies five in the first twenty years of this century: September 11, 2001, the 2008 financial crisis, the pandemic, the war in Ukraine, and recent conflicts in the Middle East. At that point, ignoring geopolitics, or geopolitical risk, was no longer an option. For companies, large and small, this meant something concrete: geopolitical risk analysis stopped being a contextual variable and became a strategic driver. Foresight, the ability to read what is about to happen before it happens, became an organizational skill, not an exercise reserved for think tanks.

What's the most common mistake companies make when underestimating geopolitical risk?

Luca Tenzi: "The most common mistake I observe is the systematic underestimation of the indirect impact of geopolitical events. Companies, especially SMEs, tend to assess risk linearly: they look at the event itself, rarely its shockwaves. Large companies, precisely because of their more widespread presence, have more sensors that allow for a more timely reading of "local" events with regional or global reach. This is precisely where the butterfly effect comes into play, that principle of chaos theory according to which small variations in initial conditions produce amplified and unpredictable effects on complex systems. The interdependence created by globalization has made SME supply chains extraordinarily vulnerable to this dynamic. A change of government in an African country may seem distant, but it can reshape decades-old trade relations, shift access to critical raw materials, or favor a competitor that until recently operated in a marginal position. And there's no need to look that far: for Ticino, the changes in political priorities of the current Italian government have far-reaching economic and neighborly impacts.

Two concepts that I consider fundamental come into play here. The first, perhaps the best-known, is Nassim Taleb's Black Swan, the event deemed unlikely that, when it occurs, has a devastating impact that traditional risk models simply didn't contemplate. The most eloquent example remains the pandemic. The second is Michele Wucker's Gray Rhino, perhaps less well-known in our latitudes but equally insidious: the obvious, visible, high-probability risk that organizations choose, consciously or not, to ignore. US-China tensions over technologies, Europe's energy fragility, and dependence on rare earths: they were all gray rhinos long before they became emergencies. The mistake, in short, isn't always failing to see the risk. Often, it's having observed it, not having analyzed it, and consequently not having acted.

When can a company say it is truly resilient?

Luca Tenzi: "A truly resilient company doesn't aspire to return to square one. It aims to emerge from the crisis in a different position, and possibly stronger and more competitive. True resilience is a systemic capability in managing complexity that is built before the crisis hits, for example through supply chain diversification, a culture of risk management across all levels of the organization, and a structured scenario planning practice.

To make the concept concrete, I like to use a metaphor. Let's imagine a resilient company like a three-masted sailing ship: depending on the strength of the waves, currents, and winds, the captain will use more or less sail, reduce the tack, and change course. It doesn't stop, it adapts; the travel times may not be as expected, but the goal remains the same. This is what the leadership of an SME should do: consider themselves the captain of that sailing ship, with the ability to read the sea before the storm hits.

If you had a message to the entrepreneurs attending the “Motivation Night” event, what would it be?

Luca Tenzi: "I believe the message we shared during the evening is that geopolitical risk has become a business risk for Ticino SMEs as well. It's no longer a contextual variable, it's a strategic variable that belongs on every entrepreneur's agenda, regardless of company size. In Switzerland, SMEs represent approximately 95% of the business community and generate two-thirds of the country's jobs. They aren't a secondary component of the system; they are the system. And Ticino companies, due to their location and the relationships they maintain with Italy and the European market, are at the forefront of this new dynamic, not only by choice, but by territorial vocation.

What's lacking in most of the SMEs I've met isn't the ability to react—we have companies with decades of history that have demonstrated their ability to navigate rough seas—it's the habit of anticipating. Of reading weak signals before they become crises. Of distinguishing a gray rhino, a visible and ignored risk, from a problem that could have been managed earlier.

The Motivation Night event,How present is the digital front in the daily life of companies today?

Alessandro TriviliniTo answer this correctly, we need to distinguish between computerization and digitalization. Many companies today are computerized: they use software, digital tools, and platforms to work better. But being digital is another matter. True digitalization involves rethinking processes, automating them, and making them more efficient through technology. On this front, many companies are still lagging behind. Despite the progress and acceleration brought by artificial intelligence, we are still at the beginning of the journey: digital is here, but its potential is only partially exploited.

What is the most underestimated vulnerability by companies today?

Alessandro Triivilini: "The most underestimated vulnerability today is staff training. Many companies invest in advanced technologies but neglect updating their staff's skills. This is a growing problem, especially as cybercriminals are using artificial intelligence to make attacks increasingly credible and targeted. Today, a phishing email can be perfectly written or mimic real communications, making it much harder to recognize the threat. Without ongoing training, even the best security systems can be bypassed. 

Are there signs that a company tends to ignore that should actually alarm it?

The Motivation Night event,Alessandro Trivilini: "Today, one of the most alarming signs that companies tend to ignore is the evolution of security regulations, such as DORA and NIS2, which require a collaborative approach to cybersecurity management. These regulations emphasize the importance of involving not only internal employees, but also customers, suppliers, and consultants in information security. Companies must adopt strategies that include a residual risk assessment, taking into account interactions with all stakeholders in the value chain. It is essential that companies develop a security culture that promotes awareness and collective responsibility."

If a company wanted to take a real first step towards raising its security standards, where should it start?

Alessandro Trivilini: "The first concrete step is to have an incident response plan. Prevention isn't enough: you need to be ready to react. Every company should know in advance what to do in the event of an attack, who is responsible, and what actions to take in the first hours, which are the most critical. This must be accompanied by clear and tailored security governance, defining roles, responsibilities, and processes. Effective security isn't just about technology, but also about organization, preparation, and response capacity."