Proactive Value · Resilience · Trust · 13 min read

How Do You Sell Something That Never Happened?

Prevention creates a peculiar commercial problem: when it works, the catastrophe disappears. Perhaps the stronger case is not what might have happened, but the capability that made failure less likely.

Joakim Domeij
By Joakim Domeij 23 September 2026 · 13 min read

Some of the hardest things to sell are the things that work perfectly.

When something fails, value is relatively easy to explain. A system goes down, customers are affected, engineers are pulled into an incident, executives become involved and eventually somebody fixes it. The organisation can usually identify at least some of the cost through lost revenue, recovery work, service credits, delayed projects or the hours consumed by people who were supposed to be doing something else. The calculation may still be incomplete, but there is an event everyone can point at and agree happened.

Prevent the same failure and the evidence looks very different. Customers continue using the service, engineers continue with their planned work and executives carry on with their day. There is no incident report, no recovery programme and no obvious financial event to measure. From the outside, successful prevention can look remarkably similar to doing nothing.

This creates a strange commercial problem for anyone selling prevention, resilience, security, workplace safety, proactive support or other capabilities designed to stop something bad from happening. How do you demonstrate the value of an event that never occurred?

The obvious answer is to calculate what the event would have cost. If an outage might have cost millions, perhaps preventing it saved millions. If a serious accident could have stopped production for days, perhaps avoiding it protected all of that revenue. The problem is that we do not know the event would have happened. A near miss is not an accident, a vulnerability is not a breach and a deteriorating system is not necessarily tomorrow's outage. The counterfactual is commercially attractive because it gives us a number, but the confidence implied by that number can easily exceed the evidence behind it.

That does not mean prevention has no measurable value. It may mean we are trying to measure the wrong thing.

Failure Is Very Good at Selling Prevention

One of the difficulties I explored in Proactive Value is that preventative work has to compete for investment before the evidence is complete. After a major failure, the argument can become remarkably simple because the organisation has experienced the consequences directly. Before it happens, somebody has to spend real money today against a future event that may never provide proof that the decision was correct.

Aviation provides an extreme example. The attacks of September 11 were not prevented; the catastrophe happened, and the consequences changed the way aviation security was approached. Measures that might have been difficult to justify against a hypothetical event became much easier to justify once the consequences were no longer hypothetical. The human loss was irreversible, while the wider disruption, economic consequences and loss of confidence extended far beyond the physical damage itself.

It is interesting to compare that response with the way risk is managed across other forms of transport and other environments where large numbers of people can be exposed to serious harm. Trains, ships, mines, oil rigs, factories and major public spaces all have extensive safety or security measures of their own, but the controls differ because the risks, operating environments and consequences differ. We cannot eliminate every conceivable risk, nor would it make sense to spend unlimited resources trying to do so.

There is nevertheless an uncomfortable distinction between deciding that a known risk is acceptable and never properly considering a risk because nothing sufficiently bad has happened yet to make it urgent. Sometimes an organisation has genuinely assessed a threat and concluded that additional prevention would be disproportionate. At other times, the absence of a recent catastrophe can gradually become evidence that one is unlikely, even when the conditions capable of producing it have not disappeared.

Failure is extremely good at making prevention feel valuable. Prevention has a much harder time producing the same evidence on its own.

Evidence Before the Consequence

Workplace safety provides an interesting way around this problem because an accident is not the only thing that can be observed. Consider a large warehouse or industrial facility that finishes the year without a serious injury. That is clearly a positive outcome, but the accident count alone tells us very little about how that outcome was achieved. The same facility might have experienced repeated situations in which vehicles passed dangerously close to people, workers crossed areas intended to separate them from machinery, or procedures were routinely bypassed because the designed process did not match the reality of how the work was being performed.

Both statements can therefore be true at the same time: nobody was seriously injured, and the conditions capable of causing serious injury occurred repeatedly.

This distinction matters because modern technology increasingly allows organisations to observe the conditions that exist before the final consequence. Near misses, unsafe proximity, recurring behaviours and patterns across locations or shifts can provide evidence of exposure without requiring somebody to be injured first. The organisation does not need to claim that a particular near miss would definitely have become an accident, because that would be impossible to prove. It can instead establish that a particular risk existed repeatedly, understand why it was occurring, change something about the environment or process and then observe what happened afterwards.

If workers repeatedly leave a designated pedestrian route in a warehouse, for example, the simplest response might be to tell them to stay inside the lines. Repeated evidence may reveal a different problem: perhaps the route conflicts with how the work actually needs to be performed, materials are placed in the wrong location, or the supposedly safe route adds enough friction that people routinely abandon it. The important information is not merely that somebody crossed a painted line. It is that the control exists on paper but may not be working in reality.

This is where Visibility becomes much more than reporting. Making a risk visible moves evidence closer to the point at which the organisation can still do something about it. After a serious accident, leaders may genuinely ask how nobody saw it coming. If the underlying conditions had already been repeatedly observed, the question changes. The organisation knew something was happening, which means it can now ask why it happened, whether the risk was understood and what should be done about it.

Visibility does not mean every warning deserves investment, and more data does not remove the need for judgement. It does, however, make it possible to replace a hypothetical argument about catastrophe with a much more defensible one about observable exposure. Instead of claiming that an intervention prevented three accidents that nobody can prove would have occurred, an organisation might be able to show that a particular high-risk interaction occurred hundreds of times, that a change was made and that the frequency subsequently fell substantially and remained lower.

Perhaps that is the first part of answering how we sell something that never happened. We stop trying to sell the missing event and instead make the conditions preceding it visible. The evidence becomes the risk that existed, the intervention that followed and the measurable change afterwards.

The same logic applies well beyond workplace safety. Observability can reveal deteriorating technology before it becomes an outage, security teams can identify and remediate vulnerabilities without pretending every vulnerability would have become a breach, and proactive enterprise support can identify recurring weaknesses before they become major customer escalations. In each case, the strongest evidence is not an imaginary disaster but an observable condition that changed because somebody acted.

When Success Makes Prevention Harder to Sell

There is another problem that appears only after prevention has worked for a while. Imagine an organisation experiences a serious failure and subsequently invests in a preventative capability. During the first year, the commercial justification is easy because everyone remembers what happened. The disruption is recent, senior leaders may have been personally involved and the people approving the investment understand exactly why it exists.

Four years later, the situation may look very different. The original problem has not returned, some of the people who experienced it have left and a new executive or procurement team inherits an annual cost without inheriting the emotional or operational memory attached to it. From their perspective, they may be looking at several years of expenditure alongside several years in which the feared event did not happen. Asking why the organisation is still paying for it is not necessarily unreasonable.

Successful prevention can gradually erase its own original business case.

Time, however, works in both directions. Imagine I start a cloud company today using a server in my house and tomorrow advertise 100 per cent uptime. The statistic could be entirely accurate and still tell a prospective customer almost nothing. A day without an outage does not establish reliability because the system has barely had an opportunity to fail. If that same service operates consistently for years, across changing demand, component failures, upgrades, incidents and all the other realities of running technology, the history begins to mean something quite different.

Major cloud providers illustrate this well, not because any particular provider is unique, but because companies operating large-scale cloud services have spent years building the capabilities underneath the service. Redundancy, monitoring, security, backup, recovery, capacity management, operational processes and specialist expertise all contribute to keeping services available. Enterprise customers may scrutinise those mechanisms carefully, particularly when assessing architecture, security or resilience, but they are not generally purchasing each preventative mechanism independently. Ultimately, they are purchasing a service that they expect to work.

The preventative machinery has effectively become part of producing the outcome.

A similar principle exists in high-risk physical environments. A mine or oil rig does not become safe simply because nobody was seriously injured last month, and years without a catastrophe do not make the controls that contributed to that record redundant. Safe operation has to be continually produced as people, equipment, conditions and processes change. The same applies to factories and warehouses, where the value of safety capability is not best understood as a collection of accidents that supposedly did not happen, but as part of maintaining an environment in which people can work with an understood and managed level of risk.

This changes what time means commercially. The passing years may weaken organisational memory of the original failure, but those same years can strengthen the evidence that the organisation has developed a capability that works. The challenge is ensuring that the second story remains visible as the first one fades.

Trust Takes Time to Build and One Failure to Damage

The difference between a claim and a track record is important because much of what we call trust is accumulated evidence.

Personal protection provides a particularly clear example. When a president or another heavily protected public figure appears at an event, the public may see a relatively small number of protection officers nearby. What is much less visible is the broader system required to make that appearance uneventful: preparation, coordination, assessment, training and many other activities performed before and around the event. Most of that work is valuable precisely because the public never needs to see its consequences.

When the system works, the person arrives, appears and leaves safely. Nothing particularly interesting happens. Yet a serious failure can immediately create questions about the entire protective system because the public expectation was not merely that individual security activities would be performed; it was that those activities would collectively produce protection.

This is closely related to what I explored in Trust. An organisation can make a promise immediately, but it cannot instantly manufacture the history required to make people believe that promise. A company can put “Safety is our number one priority” on the wall of a factory tomorrow morning, but it cannot buy a ten-year safety record tomorrow. That record has to be created through thousands of ordinary days in which risks are identified, decisions are made and people return home safely.

When that trust is damaged, the cost can also extend well beyond the event itself. A serious workplace accident can change how employees perceive management's commitment to their safety, particularly if evidence later suggests that a known risk was ignored. It can affect how families, candidates, customers or partners think about the organisation. Some consequences may be measurable through direct costs, staff turnover or other indicators, while others may never appear clearly enough to be attributed to the original failure.

A much less dramatic example occurs every day in retail. I might enter a shop intending to buy a Coke, bananas and bread, reach a self-service checkout and decide that navigating the produce menus and whatever other friction the process introduces is more trouble than the additional purchases are worth. If I scan the Coke and leave, the retailer records a successful sale. It does not record the bananas and bread I intended to buy because those transactions never existed in its system. If the experience happens often enough and I eventually start shopping somewhere else, I may never complain or explain why; I simply become revenue that no longer arrives.

This is almost the mirror image of preventative value. When prevention succeeds, something bad does not happen and we struggle to measure the value created. When trust or customer experience deteriorates, something good may not happen and we struggle to measure the value lost. Financial systems are generally much better at recording transactions and failures that occurred than opportunities or failures that disappeared before they became transactions at all.

That is why the true cost of failure is so difficult to capture. A preventative investment usually has a clear owner, budget, contract and invoice, while the consequences of failure spread across the organisation. An outage can consume engineering capacity, executive attention and customer goodwill long after the system itself has been restored. An accident can lead to investigation, disruption, remediation and damaged confidence beyond the immediate human and operational consequences. A security incident can generate costs across technical recovery, governance, customers and future investment. The easiest costs to defend in a spreadsheet are not necessarily the largest costs the organisation ultimately carries.

This connects with Deliberate Design because outcomes such as safety, reliability, retention and resilience do not normally appear by accident. If those are the outcomes we want, the organisation has to create the conditions capable of producing them repeatedly. The fact that those conditions become difficult to notice when they work does not make them free.

The Invoice Is Concentrated. The Value Is Not.

There is another reason prevention can be difficult to sell even when people broadly agree that it creates value. The person being asked to pay for it may not be the person who receives most of the benefit.

A safety capability might sit visibly in one departmental budget while its effects extend into operations, production continuity, employee confidence, recruitment, insurance, executive risk and the organisation's wider reputation. An observability platform may be paid for by Technology while part of its value appears through fewer incidents, less disruption to engineering teams, reduced customer escalation, greater service reliability and protected commercial relationships. The organisation can see the full cost of the preventative investment in one place, while the benefits are dispersed across functions that may never attempt to calculate their share.

This creates an accounting asymmetry that can make doing nothing appear surprisingly inexpensive. The proposed investment arrives as a precise number that requires approval, while the alternative is often represented as zero because nobody has produced a consolidated invoice for continuing as before. If the failure eventually occurs, the cost may appear across ten different budgets, consume weeks of work and affect outcomes that were never included in the original decision. By then, however, the preventative decision and the failure may be so far apart organisationally that nobody reconnects them.

This is not an argument that every preventative proposal should be approved because its supporters can imagine costs elsewhere. That would simply replace one weak business case with another. It does mean that selling preventative value requires understanding where the value actually lands. If the investment protects engineering capacity, customer relationships, production continuity and employee confidence, a business case judged entirely against one operational budget is missing part of the economic picture.

The commercial challenge is therefore not only to prove that something works. It is to make distributed value visible enough that the person being asked to fund the capability can understand what the organisation as a whole is buying.

Stop Selling Prevention

Perhaps mature preventative services eventually need to make the same transition that major infrastructure providers have already made: instead of asking customers to value every preventative mechanism individually, they make those mechanisms part of producing an outcome the customer already understands.

A cloud customer wants reliable access to the service and confidence that the provider can continue operating when individual components inevitably fail. A manufacturer wants people to work safely while production continues, while a mine or oil rig needs serious risks to be continuously managed as people, equipment and conditions change. An enterprise investing in resilience ultimately wants the organisation to continue functioning when something unexpected happens. In each case, prevention matters enormously, but its commercial value becomes easier to understand when it is connected to the operating condition it helps create and sustain.

Reliability, safety, resilience, security and assurance are not single interventions. They are properties that emerge from many capabilities working together over time.

This changes the renewal conversation. Asking which specific catastrophe a service prevented during the previous twelve months forces both customer and supplier into a counterfactual neither can prove. A more useful conversation begins with the capability the organisation has today because the service exists, the observable risks or conditions it allows the organisation to manage, the evidence of how those conditions have changed, and what would no longer be visible or manageable if the capability disappeared.

It also changes the way preventative services should be sold. There is an important difference between selling fear and selling evidence. Fear says that something terrible could happen if the customer stops paying. It can be enormously persuasive immediately after a serious failure because everyone still remembers the consequence, but fear depreciates as that memory fades. If five uneventful years pass, the same argument can start working against the supplier: if the catastrophe has not returned, perhaps the original threat was overstated or the protection is no longer necessary.

Evidence behaves differently. A provider does not need to claim that a near miss would have killed somebody, that a vulnerability would certainly have become a breach or that an unusual metric would inevitably have become a major outage. It can be honest about what cannot be known while demonstrating what can. The exposure existed, an intervention was made, the measurable condition changed, the improvement persisted and new risks continued to be identified as the environment evolved.

That is a much more sustainable commercial relationship because the customer is not being asked to keep buying protection from an increasingly distant nightmare. The customer is being shown a capability that exists today and the evidence that capability continues to produce.

There is also something important about credibility here. Exaggerated counterfactuals may help a business case once, but eventually somebody will challenge the assumptions. Evidence allows the commercial argument to survive scrutiny because it does not require certainty where certainty is impossible. The seller can acknowledge that nobody knows exactly what would have happened while still demonstrating that the organisation is better able to understand and manage the conditions from which failure can emerge.

What Time Leaves Behind

Continuous evidence creates something else that can survive the people who originally understood why the investment was made. Executives leave, managers change roles, teams reorganise and the people who experienced the original incident eventually become a smaller part of the organisation. Without an evidence trail, a future leader can inherit an annual cost while knowing very little about the risks, decisions and improvements that produced it.

If risks, interventions and outcomes have been recorded as part of normal operations, the organisation does not need to reconstruct that history years later. This can matter during audits, governance reviews and other forms of assurance because evidence gathered while events and decisions are taking place is generally more useful than a retrospective attempt to recreate what people knew and why they acted. The cheapest time to collect evidence is often while the evidence is being created.

That history also changes the meaning of a long period without failure. Four years without the original accident, outage or escalation could be interpreted simply as four years in which nothing happened. It could also represent four years of evidence showing how an organisation identified changing risks, responded to them and maintained the conditions required for the desired outcome. The difference between those interpretations is largely one of visibility and organisational memory.

Over enough time, that history starts to resemble an asset. A long record of reliable operation, a strong safety history, customer confidence or evidence that an organisation consistently responds to emerging risk cannot simply be purchased when somebody suddenly decides it would be useful. A new organisation can make exactly the same promise as an established one, but it cannot manufacture years of evidence that the promise has repeatedly been kept. Time is part of what gives the promise credibility.

Once a capability genuinely works, Amplification becomes relevant because the next question is where else that capability can create value. A successful intervention in one factory may inform how another location approaches the same risk, just as a reliability improvement discovered in one technical environment can become part of a broader operating standard. The important distinction is that the organisation is scaling something it has evidence works, rather than simply multiplying an assumption. Prevention becomes more commercially valuable when the learning produced in one place becomes reusable capability elsewhere.

There may eventually be another stage in this progression, where the organisation stops treating the preventative capability as something that needs to prove an individual avoided catastrophe every year and starts treating it as part of competent operation. A mine does not need a fatality to remind it that safety controls remain necessary, just as a major technology provider does not need a customer-impacting hardware failure every year to justify redundancy. Protection around a head of state does not become pointless because thousands of public appearances passed without incident. In mature environments, some capabilities become part of the standard at which the organisation has decided it must operate.

That should not make them immune from scrutiny. Controls can become outdated, technology can become unnecessarily expensive and preventative processes can survive long after they stopped producing useful outcomes. Mature organisations should continue asking if controls work, whether better alternatives exist and whether investment remains proportionate to the risk. The question simply becomes more useful than asking which specific disaster was prevented last year. It becomes a question about the capabilities required to continue operating at the standard the organisation expects.

This is an important commercial transition because prevention may begin as a response to something that happened, become sustainable through evidence that it works and eventually become embedded in the operating model because the outcome it produces is no longer considered optional. At that point, it becomes increasingly difficult to separate the preventative service from the quality of operation itself.

So How Do You Sell Something That Never Happened?

Perhaps the original question contains the wrong assumption.

If we try to sell the missing event itself, we are forced into a counterfactual we cannot prove. We start estimating the financial value of accidents that did not occur, outages that never happened, customers who might have left or security incidents that perhaps would have taken place. The numbers can become increasingly impressive while the evidence underneath them becomes increasingly hypothetical.

A stronger commercial argument starts with what can actually be observed. It identifies conditions that already exist rather than catastrophes that might exist in the future, establishes a meaningful baseline, demonstrates what changed after an intervention and continues measuring long enough to show that the improvement was not temporary. It also follows the value beyond the budget paying for the intervention, because the benefits of prevention rarely respect organisational boundaries.

As that evidence accumulates, it becomes more than proof of one successful intervention. It becomes organisational memory and, over time, a track record. That track record contributes to trust because people no longer have to rely entirely on a promise about what an organisation can do; they can look at what it has repeatedly demonstrated.

Eventually, the preventative capability can become inseparable from the outcome itself. Major cloud providers deliver services expected to be reliable because years of technology, process and operational capability sit underneath them. Mines, oil rigs, factories and other high-risk environments invest in safety because safe operation is part of operating responsibly, not merely a temporary response to the last accident. Enterprises invest in resilience because the ability to continue operating through failure is valuable even when the failure itself never arrives.

The absence of catastrophe is still part of the story, but it no longer has to carry the entire commercial argument. We do not need to prove precisely which terrible event would otherwise have happened. We can demonstrate that risk was visible, that somebody acted on it, that the exposure changed, that the change persisted and that the organisation developed a capability capable of producing the desired outcome repeatedly.

Perhaps that is how you sell something that never happened.

You don't.

You sell the capability that made its absence increasingly predictable.

Read Really, Another Leadership Book?

A practical examination of trust, judgement, ownership and leadership for the moments when the situation is more complicated than the advice.