Insight · Vol. 13

The fallback.

Every plan has a first way to work. Most have never once tried the second. A fallback you have never used is not a fallback. It is a hope.

The plan assumes the lights stay on. Then, one afternoon, they do not.

On 28 April 2025 the power went out across Spain and Portugal at the same moment. Not a neighborhood. Two countries.

Payment terminals died. Mobile networks thinned and dropped. Trains stopped between stations. Traffic signals went dark. The official expert panel took nearly a year to publish its final account of how a grid that large came apart, and ruled out an attack. The cause was a cascade of technical failures.

The part that matters for anyone who runs a crisis team is simpler than the engineering. Every response plan inside that footprint rested on things no one had written down. That there would be power. That phones would work. That the screen would light up when someone needed it.

When those assumptions failed, the plans failed with them. Before anyone made a single decision.

A PACE ladder in a dim control room. The top rung, P, glows bright yellow with a figure standing on it. The next rung, A, is a dimmer yellow. The lower rungs, C and E, are drawn only as thin outlines, never used. In the background one lone figure has turned from a wall of dark, dead screens and reaches for a single glowing yellow telephone.
Primary, alternate, contingency, emergency. Most teams live on the top rung, and meet the others for the first time on the worst day.
The verdict

A fallback you have never used is not a fallback. It is an assumption wearing a fallback’s clothes.

A first way to work, and nothing tested behind it.

Most crisis plans are built around one way of working. The primary way. The email chain. The shared dashboard. The mobile phones. The building everyone drives to.

Ask a team what happens when the primary way is gone, and the answer comes back fast and confident. We would switch to the backup. Ask when they last used the backup, and the room goes quiet.

That is the pattern underneath most degraded-mode failures. The fallback exists on paper. It has a name, a page in the plan, sometimes a piece of equipment in a cupboard. What it does not have is a single hour of real use.

The emergency-communications field has a discipline for doing this properly. It is called PACE: four ways to do the one thing that cannot be allowed to stop, ranked before the day arrives.

  1. P Primary. The way you always work. The one that gets used, and the only one that reliably has been.
  2. A Alternate. A different path to the same job. Named in the plan, rarely rehearsed.
  3. C Contingency. Slower and clumsier, but it exists. Almost always untested.
  4. E Emergency. The last resort you hope never to reach, and often the least ready of all.

The framework is not the hard part. The hard part is that most teams have a real P, a vague A, and two letters that were never real. This is the failure cinten was built to surface. Not whether a fallback is written down, but whether it works when the primary is gone.

The gap is always in the letters nobody tested. Documented is not the same as exercised.

The blackout made the abstract concrete for millions of people in an afternoon. And the failure it exposed repeats, in domain after domain, for the same reason. The alternate was written down and never run. The phone tree with numbers three years out of date. The satellite phone with a flat battery. The manual process that one recently departed person was the only one who knew how to work.

The event

Two countries, one moment. The Iberian grid collapsed and took power, payments, mobile networks, and rail down together.

The dependency

Some of the systems meant to carry the load depended on the very thing that had failed.

The doctrine

Federal emergency-communications guidance is built on PACE, because primary systems fail and someone has to have planned the next three.

The gap

A plan can list four ways to communicate and still collapse to zero, if three of them never left the page.

This is diagnostic, not predictive. cinten does not forecast which system will fail on the day. It removes one, on purpose, in a controlled run, and shows what the team has left when it does. That is a diagnosis a team can act on while the only cost is exercise time.

Break your own primary, on purpose.

Readiness for degraded mode cannot be read off a document. It has to be run. Take the one capability the response cannot lose, communications, or command, or the common picture, write its PACE line, and then take the primary away in the exercise. See how far down the letters the team can actually go.

01

Write the PACE line.

For the capability you cannot lose, name the primary, the alternate, the contingency, and the emergency, before the drill starts.

02

Take the primary away.

cinten removes the main tool, channel, or place mid-run, while the scenario is still live, without pausing the exercise.

03

Watch what they reach for.

The real fallback behavior surfaces, not the one written in the plan, including whether anyone present knows how to reach it.

04

Measure the drop.

How long the team operates blind before the alternate comes online becomes a number the room can review instead of assume.

The closer

The primary always works in the rehearsal. That is exactly why the rehearsal has to break it.

Want to know if your fallback is real?

See what your team does when the primary is gone.

Book a demo and see how cinten runs an exercise in degraded mode: the primary removed on purpose, and the team’s next move read from the run itself.