Knowledge Base · Requirements & Direction

Organisation, sector and global: the three spheres

Conundrum methodology · 3 min read · Updated September 2026

The spheres of influence are three concentric rings of factors acting on an organisation: the business sphere it controls, the micro sphere of its industry and partners, and the macro sphere of politics, economics and society. Control diminishes as the spheres widen, and sorting influences into the right ring is what makes it obvious where effort can change an outcome and where it can only prepare for one.

Read first: The intelligence cycle

Risk does not arrive from one direction. Some of what threatens an organisation is inside its own walls and entirely within its gift to change, some belongs to its industry, and some is the weather: global, impersonal and unmoved by anything a single company decides. Sorting influences by which of those categories they belong to is more useful than it sounds, because the category determines what you can actually do about them.

The three rings

The business sphere is innermost, and covers what the organisation directly controls: its people and their skills, its budget, its locations and facilities, its products and services, its internal audit and compliance. These are the most manageable influences, because they can simply be changed.

The micro sphere sits around it: competitors, suppliers, customers, partners, the technology available in the market, and the regulations the industry answers to. The business has some influence here, exercised through relationships and negotiation, but it does not have control.

The macro sphere is outermost and the least tractable: politics and policy, economic cycles, social and cultural change, environmental factors, conflict. These are determined by global and regional dynamics. The organisation can adapt to them and must anticipate them, but it cannot shape them.

Control diminishes as the spheres widen

That is the observation the whole model turns on, and it has a direct operational consequence: effort should be concentrated where the business can drive change, in the business and micro spheres, while the macro sphere is watched and planned around rather than argued with.

The failure this prevents is a function that spends its attention on enormous, genuinely important macro factors and produces nothing anybody can act on. A briefing about geopolitical instability that ends without a decision is a weather report.

Labelling is the work

Identifying an influence is not enough. It has to be labelled with the sphere it belongs to, because that is what converts a list of concerns into something structured enough to prioritise. Two threats of equal severity, one in the business sphere and one in the macro, warrant completely different responses, and without the label the difference is invisible.

The practical routine is to map the factors in each sphere, prioritise by how much control you have over them, and review the mapping periodically, because factors move between spheres as an organisation changes and as the external environment does.

How this becomes a requirement structure

The spheres map directly onto how intelligence requirements should be tiered. Questions about your own organisation belong at the innermost tier. Questions about your sector and the companies you depend on belong at the middle tier. Questions about the global threat landscape belong at the outermost.

Tiering this way does two things a flat requirement list cannot. It makes coverage inspectable, since it is immediately clear whether anything is being asked about your own organisation as distinct from your industry. And it stops tiers competing: a global question and an organisation-specific question are not the same kind of thing and should not be ranked against each other as though they were.

How this maps to the platform

Conundrum implements the three spheres as three requirement tiers: organisation, sector and global. They are nested rather than parallel, which is the part worth understanding. Anything matching a requirement at the organisation tier also belongs to the sector and global tiers above it, because a threat aimed at you specifically is by definition part of the wider picture.

Getting that nesting wrong is a real failure mode, and it was one we had to correct: treating the tiers as separate buckets made the broadest tier the hardest to match rather than the easiest, which inverts what a reader expects.