Safety Isn't Moving Everything Back to Taiwan: Real Resilience Is How Fast You Recover After Something Breaks
Stockpiling, localization and backup systems all serve a purpose, but none of them is a synonym for resilience. What Taiwan actually needs to ask isn't how much it holds in reserve, but how much essential function it can sustain during a disruption, who can switch to an alternative, and how quickly service comes back.

Article contents01 / 07
- The OECD warns that simply moving all production back home can hurt growth and even weaken supply-chain resilience; diversification, agile risk management and international coordination matter more.
- NIST defines resilience as sustaining essential functions under adverse conditions and recovering within a time frame that meets mission needs; this column translates that into a minimum service level and a target recovery time.
- Taiwan's Whole-of-Society Resilience framework and its township resilience drills already put the central government, local governments and civil society into the same scenario; the next step should be to publish the improvement loop, not just the drill headcount.
When Taiwan talks about resilience, it tends to reach first for the things it can see: a few extra days of inventory, a higher localization ratio, a second set of backup equipment. These may all be necessary investments, but they share a blind spot: they describe how much we hold, not what we can still do once something breaks.
Taiwan's Whole-of-Society Resilience framework already puts civil defense manpower, daily necessities, energy and critical infrastructure, social welfare and medical care, and communications, transport and financial networks on the same map. [4] The 2026 township resilience drills also built in real people, real materiel, real terrain, real scenarios and real operations, testing how the central government, local governments and civil society coordinate. [5][6]
That direction is correct. But the real question only starts the moment the drill ends: which functions kept running? Which link was slowest? How much shorter does recovery time need to get next time? Without answers, resilience is still an event, not a capability.
Treating "Bring It Back" as the Answer Misses the Real Risk
When a critical material depends entirely on a single foreign source, building local capacity obviously has value. The problem is that jumping straight from "protect a critical capability" to "bring all production back home" simply trades one kind of concentration risk for another.
The OECD's supply chain resilience review points out that comprehensive re-localization can hurt growth and even weaken resilience; diversifying sources, agile risk management and international coordination are often more effective than simply pursuing domestic production. [1]
The reason is practical. If raw materials, factories, electricity, logistics and technicians are all concentrated in the same geography, an earthquake, water shortage, power outage, pandemic or cyber incident can hit the entire chain at once. Moving capacity closer does not automatically make the dependency disappear — it only changes its shape.
So localization should answer two questions: which capability is unacceptable to lose if it is interrupted? And would the market automatically supply an alternative during a crisis? The first identifies the safety-priority items; the second determines whether it is worth paying a higher cost to build a domestic minimum capacity, stockpile, or government guarantee.
Before I'll Call It Resilience, I Want Two Numbers
NIST describes resilience as sustaining essential functions under adverse conditions and recovering within a time that meets mission needs. [2] NIST's research on the functional recovery of buildings and lifelines further notes that the speed of repair is affected by inspection, design, permitting, contractors, materials and long-lead-time equipment. [3]
Translating this concept into policy and corporate language, I would ask for two numbers up front.
The first is the minimum service level: when the shock hits, which functions absolutely must continue? For healthcare that might be emergency care and medication delivery; for telecoms, critical nodes and emergency communications; for a business, receiving payment, core order processing and customer service. It is not enough to write "maintain operations" — the minimum capacity has to be spelled out.
The second is the target recovery time: how long until the system moves from minimum function back to an acceptable normal level of service? Payments might be measured in minutes, data in hours, production lines in days, and supply chain reconstruction in weeks or months. That difference directly determines whether you need real-time backup, remote backup, an alternative supplier, or just a manual workaround.
Without these two numbers, a resilience budget easily turns into "buy a bit more, feel a bit safer."
Inventory, Backup and Localization All Have to Pass the Same Test
Inventory buys time, but it does not guarantee that goods are actually reachable during a disruption. If warehousing, cold chain, electricity, roads, payments and allocation data all fail at once, a large inventory number does not equal service capacity.
Backup systems provide an alternate path, but they do not guarantee the switch actually works. Has the second supplier been certified? How far behind is the data at the second data center? Has the backup generator been load-tested? Do people even know who has the authority to flip the switch?
Localization reduces a specific external dependency, but it does not guarantee the local system has no shared single point of failure. If raw materials, equipment, electricity and technicians still rely on the same region or the same cloud service, a rising localization ratio may simply hide the risk more deeply.
All three kinds of investment have to come back to the same question: how much does it raise the minimum service level, and how much does it shorten recovery time?
That question changes the procurement order. The first thing worth investing in is not necessarily the most expensive equipment, but whatever link shortens the unacceptable downtime the most.
The Real Single Point of Failure Is Often a Dependency
A single unit can complete its own backup checklist and the whole system can still go down together. Power affects communications; communications affect payments and dispatch; payments affect logistics; logistics affects healthcare and food supply. Every link may say it has a backup, yet several of them may share the same substation, the same identity-verification service, or the same handful of people who can actually make the repair.
This is the part of resilience most easily underestimated: recovery time is not the sum of each unit's individual recovery time — it is set by whichever dependency is slowest, most shared, and hardest to replace.
So government and corporate drills should not only ask "did we finish," but also "who does our plan assume will recover first?" If the hospital assumes power comes back first, logistics assumes payments come back first, and government assumes private-sector cloud services come back first, then all the plans added together may leave no one going first.
The Other Side Has a Point Too: Some Things Really Should Come Home
If "don't fully re-localize" gets translated into "don't localize at all," that is a different mistake in the opposite direction. Healthcare, energy, communications, critical components and dual-use military-civilian capability may not have time, in a crisis, to wait for the market to re-match supply and demand. For these items, building a domestic minimum capability, a strategic stockpile, or a government guarantee can be entirely the right call.
The real disagreement is not over whether to pursue safety, but over which layer that safety should be bought at. Bringing all capacity back home may shorten shipping distances, but it can also turn earthquakes, blackouts, water shortages and talent shortages into a shared single point of failure; keeping part of the domestic capability while also diversifying international sources costs more in management complexity and cross-border coordination. Neither option is free.
Policy therefore cannot use "localization ratio" as its only metric. It should also list, side by side: minimum domestic supply capacity, the number of alternative sources, the certification time needed to switch, shared dependencies, the cost of inventory rotation, and recovery time under different scenarios. Only by putting cost and recovery effect side by side can anyone judge whether a given localization investment actually reduces risk — or simply renames it.
Taiwan's Drills Need to Move from Headcount to a Closed Improvement Loop
The Whole-of-Society Resilience framework and the township resilience drills have already put the central government, local governments and civil society into a shared scenario, which is closer to reality than each unit writing its own plan in isolation. [4][5][6]
The next step does not require publishing sensitive vulnerabilities, but it does require publishing institutional-level improvement results: what recovery time windows have been set for critical services? Have cross-county and cross-agency handoffs been completed? How many of the problems found in the last drill were fixed within deadline? Does the same bottleneck keep recurring?
Publishing only participant counts, vehicle numbers and the number of drills held shows society the scale of the activity. Publishing functional targets, gaps, the responsible agency and improvement deadlines is what lets society see the actual capability.
This also gives SMEs an actionable starting point: write a disruption card for their most important process, listing the essential function, the tolerable downtime, the alternative path, who has authority to switch, the conditions for recovery, and the last time it was actually tested. It doesn't require an expensive system — it just forces the organization to answer "who does what, within how long."
Conclusion: Resilience Isn't Never Falling Down — It's Knowing How to Get Back Up
Taiwan certainly needs inventory, domestic capacity and backup systems. What it really needs to avoid is treating them as the conclusion.
Safety policy is easily drawn to the things it can see: more warehouses, more equipment, a higher localization ratio — all of them photographable, listable, and easy to add up. Recovery capability is far less visible. It hides in who has system access, whether data can actually be restored, whether the alternate supplier has ever been drilled, whether units share a common scenario, and whether anything actually gets fixed after the drill.
When the shock hits, it is usually these invisible connections that decide how much is lost.
So every resilience investment has to answer two questions: how much does it raise the minimum service level? And how much does it shorten recovery time? If you can't answer them, "resilience" is still just a nice-sounding word. If you can, it becomes a national and corporate capability that can be drilled, compared, held accountable — and made stronger, year after year.
Sources
- OECD — Supply Chain Resilience Review: comprehensive re-localization may weaken resilience
- NIST — Resilience
- NIST — Functional Recovery of Buildings and Lifelines
- Office of the President — Introduction to the Whole-of-Society Resilience Committee
- Office of the President — Whole-of-Society Resilience Committee meeting records
- All-Out Defense Mobilization Agency — 2026 Township Resilience Drills
- BIS — Annual Economic Report 2026: From resilience to robustness?

