Related Big Read: When the infrastructure becomes the weapon: centralisation, blast radius, and the control boundary that actually matters
Related assets: Agentic blast radius; Intelligence has become an attack surface
Efficiency concentrates authority, so when that authority is compromised, the same systems that make work scalable also increase the potential scale of failure.
Modern organisations centralise for good reasons.
Centralisation can reduce friction and improve visibility. Shared platforms and automated workflows speed delivery, while extension ecosystems expand capability and AI tools increase reach.
But centralisation also changes the economics of failure.
If one trusted layer can reach many users, endpoints, repositories, workflows, or systems, then compromise no longer has to spread slowly. It can borrow the organisation’s own efficiency.
That is the architectural warning from the 21 March 2026 issue week.
Why blast radius belongs in design
Security teams often ask whether a system is protected.
They also need to ask what the system can damage if protection fails.
An administrative plane, developer extension, agent skill, cloud workflow, or high-trust automation layer may be well-intentioned and useful. But if it has wide reach, it is also a surface through which failure can spread.
The goal is not to eliminate centralisation. Instead, it is to understand which centralised layers would fail locally and which would fail catastrophically.
Use this checklist to examine where centralised authority could turn a local compromise into a wider failure. Work through the five areas before you accept efficiency gains without understanding the reach they create.
High-level checklist: centralised failure
Administrative concentration
Identify the cloud and management planes that can affect the largest share of endpoints, users, services, or data.
AI-accelerated threat assumptions
Update defensive assumptions for attackers who can generate lures, reconnaissance, and supporting content faster and more cheaply than before.
Runtime supply chain
Treat dependencies, extensions, agent skills, and connected workflows as live trust imports rather than one-time procurement items.
Shadow AI and visibility
Discover unofficial AI tools and workflows through telemetry and behaviour, not policy declarations alone.
Design discipline
Evaluate efficiency gains alongside the reach they create if control is lost.
The executive test
Ask which system would create the largest business consequence if it were misused for one hour with valid authority.
Sign-off rule
What can it touch, how quickly, and how do you narrow that reach before the incident?
That is where centralised failure becomes a board-level control question.