There's a story engineering teams tell about each other. Someone watched a senior engineer work an outage — site down, revenue stopping, the chat channel filling up faster than anyone can read — and that engineer just didn't flinch. Worked the problem. Asked for the right log. Rolled back the right change. The room exhales. And afterwards everyone says the same thing: she's just calm under pressure. That's who she is.
It's meant as a compliment. It's also the most useless explanation available, because it gives you nothing you can use. If calm is a temperament — something you either have or you don't — then the rest of us are simply out of luck, and the only move in a crisis is to hope the right person is online.
That's wrong, and believing it is expensive.
Calm Is a Residue, Not a Trait
The engineer who didn't flinch wasn't born without a stress response. She was running on a smaller surface of unknown than everyone else in the channel. Where to look, how to roll back safely, who to pull in, what that metric actually means under load — none of it cost her anything, because she'd done each of those things enough times that they'd stopped requiring thought. Her attention was free. She could spend all of it on the one part of the situation that was genuinely new.
That's what calm is. Not the absence of pressure. The absence of competition for your attention at the moment you can least afford it.
What Panic Actually Is
Panic is what happens when too many things demand attention at once and there isn't enough to go around.
A real crisis always has a novel core — the thing you haven't seen before, the reason this is a crisis and not a ticket. But around that core sits a ring of things that should be automatic and often aren't: where's the runbook, how do I take a safe snapshot before I touch anything, who has the authority to call it, what's the rollback path, is this the cause or a symptom. When those aren't automatic, they compete with the novel core for the same scarce working memory. The system overloads. The overload is the panic.
Discipline doesn't make the crisis smaller. The unknown stays exactly as unknown as it was. What discipline does is clear the ring — make the routine genuinely routine — so that when the hard moment arrives, your whole attention is available for the part that deserves it. You don't face less unknown. You face it with your hands free.
This is why "stay calm" is such bad advice in the moment. You can't decide to have spare attention you never built. Calm in the crisis is bought earlier, in the unglamorous reps nobody applauds.
Discipline Is Not Rigidity
I'm aware "discipline" is a word that makes good engineers tense. It sounds like process worship — a runbook for everything, a form to fill before you're allowed to think, a checklist standing between you and the work. So let me be precise about what I mean, because it's almost the opposite.
Drilled fundamentals are what buy the freedom to improvise. The musician who has practised scales until they're automatic isn't more rigid on stage — she's freer, because her hands handle the mechanics while her attention goes to the music. The pilot who has run the engine-failure procedure a hundred times in a simulator doesn't fly more like a robot when it happens for real — he has the spare capacity to handle the part the procedure didn't cover, the gust of wind, the second failure, the thing the manual never imagined.
Discipline is the precondition for adaptability, not its enemy. You rehearse the known so you can meet the unknown with everything you've got. A team that has never practised a rollback will improvise the rollback and the diagnosis at the same time, under load, with the clock running — and do both worse. A team that can roll back in its sleep gets to spend the whole crisis on the one question that matters: what actually broke.
The rigidity people fear comes from the opposite of real discipline. It comes from process adopted as ritual — steps performed because they're the steps, not because anyone understands what they buy. That's cargo cult, and it adds to the ring of distractions rather than clearing it. True discipline is ruthless about what's worth making automatic and refuses to automate the rest.
The Two Scales of the Same Move
This is the individual-scale version of something I've written about before at the level of the organisation. Don't Panic — the principle, not the towel — is the claim that a calm engineering organisation isn't a lucky accident of temperament either. It's manufactured the same way, one size up: prepare what can genuinely be planned, so that when the unplannable arrives, the team meets it with its hands free.
The two are the same move at different sizes.
At the org scale: you build the rhythms, the ownership, the incident structure, the shared frame — all the boring infrastructure — before you need them, so that a crisis doesn't also require inventing who's in charge. The roles in a well-run incident — the one watching the broad picture, the one with hands on the system, the one shielding the responders from the noise — those aren't improvised when the page fires. They're practised before they're needed, so that under pressure people fall into them rather than negotiate them.
At the individual scale: you drill the fundamentals until they cost nothing, so that your own attention is free for the novel core.
Neither is a personality. Both are preparation. The calm you see on the surface — in a person or in a whole team — is the visible residue of invisible reps.
The Quiet Reps Matter More Than the Loud Ones
Everything so far has been about the dramatic moment — the outage, the page at 3am. But the same mechanism runs, less visibly, through ordinary weeks.
Operations people know there are really two organisational structures, not one. There's the peacetime structure — the normal hierarchy and rhythm that gets the work done, in good order, over the long haul. And there's the incident structure — a different shape entirely, with its own roles and clear lines of authority, built to move decisions and resources fast enough to resolve a crisis. The crisis one isn't the everyday org trying harder; it's a structure you switch into, and it only works if its roles were established and rehearsed before they were needed.
Both demand discipline. The wartime kind is the readiness to switch cleanly into incident command and operate inside it under pressure — the dramatic, visible discipline everyone respects. The peacetime kind is holding the everyday structure when nothing is forcing you to: keeping the rhythm, protecting the planning moment, making the call inside the frame rather than around it. That one is quieter, less respected, and harder — because the pressure is always to break it.
A team without that peacetime discipline is in a low-grade version of the crisis state all the time. Every week, the same questions compete for attention that should already be settled: what are we working on, who decides, is this urgent or does it just feel urgent, why did the plan change again. None of it is automatic, so all of it costs attention — and the team runs permanently a little overloaded, a little reactive, a little frayed. That's not a crisis. It's worse, because it never resolves.
Rhythm is the discipline that clears that ring at the scale of the quarter rather than the incident. A steady cadence — a known cycle, a protected planning moment, a clear and visible set of priorities — makes the recurring questions cost nothing, because they're answered the same way every time. The team stops spending attention on how we work and gets it back for the work. Calm, again, as the residue of something made automatic.
And here's the part that's easy to miss: holding that rhythm is itself the hard discipline. The pressure is always to break it — to chase the thing that surfaced this morning, to skip the planning moment because this week is busy, to make the urgent call outside the frame because it's faster right now. Each break feels efficient, and each one re-introduces a question the rhythm had settled. The teams that stay calm over months aren't the ones with the best crisis response. They're the ones disciplined enough to keep the rhythm when breaking it would have been easier.
This is where calm stops being about bad days and becomes a way of operating. The incident structure keeps you steady in the rare emergency. The peacetime discipline — the unglamorous business of holding a rhythm no one is forcing you to hold — is what means you have fewer emergencies to be steady through.
What This Means If You're Buying It
When a company brings in outside engineering leadership, what they often think they want is someone who "stays calm under pressure" — a steady presence for the bad days. That framing quietly repeats the mistake. It treats calm as a vibe one person carries into the room.
The calm worth paying for isn't a vibe. It's the visible surface of preparation that happened earlier — the runbooks that exist, the rollback that's been rehearsed, the roles that are known before the page fires, the fundamentals the team no longer has to think about. A leader's job isn't to be the calm one. It's to build the conditions under which the team gets to be calm, because the ring of distractions has been cleared in advance and the only thing left to face is the part that's genuinely new.
You don't stay calm under pressure. You prepare to. And preparation, unlike temperament, is something you can choose — and something you can build into a team on purpose.
That's the whole offer. Not a steadier personality in the room. The reps that make the steadiness unnecessary to hope for.
Thomas Riboulet is a Fractional VP of Engineering working with European tech companies. He writes about engineering leadership, team structure, and sustainable delivery at insights.wa-systems.eu.