Close Menu
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
More items
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
X (Twitter) LinkedIn
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
Login
LinkedIn Bluesky
Resilience Forward
Subscribe Now
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
Resilience Forward
You are at:Home»Managing resilience»UK national resilience realities: the gaps between information, awareness, and action
Managing resilience

UK national resilience realities: the gaps between information, awareness, and action

How much central government planning actually reaches the small businesses that are essential to make resilience work in practice?
July 21, 20265 Mins Read
UK resilience

By Helen Molyneux

The 2026 National Risk Register update landed with its usual mix of the obvious and the alarming – water infrastructure failure and a pandemic are both rated as catastrophic-impact risks, digital resilience failure is a new entry (hello, CrowdStrike), and the risk of disruption to Russian gas supplies has been removed because reliance on Russian gas imports has significantly reduced. All fairly predictable churn.

But here is my honest question: who in the business world actually reads this thing?

The average small business – and the overwhelming majority of UK private-sector businesses are small businesses – has almost certainly never heard of it.

Even those who do open it can encounter a scale problem. The 223 page main document is written at a genuinely national level of geography and threat. It is accompanied by a 25 page slimmed-down ‘Guide to the 2026 National Risk Register’ which includes some short example preparedness and business continuity actions, but they are unlikely to translate into “What do I do on Monday morning?” for a twelve-person accountancy firm, a care home, or a haulage company. The document is honest and well-intentioned. Whether it is the right shape for the audience that most needs to act on it is a different question. It also risks conflating two distinct purposes: the National Risk Register communicates national-level risks, while individual organizations must translate those risks into their own operating context, dependencies, vulnerabilities, and business continuity arrangements.

Which brings me to Operation ALBISTON SHADOW, described as the UK’s largest home defence exercise in decades and scheduled for 2027. It will test government preparedness for hybrid attacks, while the government’s classified crisis plans, commonly known as the ‘War Books’, are being updated for the first time since 2004. Ministers and hundreds of officials from across government and the public sector are likely to take part – a genuinely serious undertaking on paper. The obvious reading is that this is principally a story about central government and the wider public sector – they are the participants explicitly identified in the announcement.

But if COVID-19 taught us anything, it is that businesses are part of the lifeblood of national resilience, not merely adjuncts to the state. Remember the debate over who counted as a ‘critical worker’? That was not simply a bureaucratic issue. It raised questions about how clearly the country had identified the private-sector functions on which it depends to keep operating – and those questions were being addressed during the crisis, the worst possible time to do so.

This year’s new risk entries make that point sharper, not softer: cyber attacks on data infrastructure, water infrastructure, and police systems are now included as distinct risks, alongside national disruption to data infrastructure and digital resilience failure. The National Risk Register also notes that AI can automate cyber attacks, making them faster and more efficient and lowering the barrier to entry. AI-facilitated cyber attacks are not, however, a separate new risk entry.

Every one of those risks, in practice, has significant private-sector underpinning – contractors, technology suppliers, outsourced services, and critical third parties. A cyber attack on ‘water infrastructure’ is not an abstraction that stops at a reservoir gate. Somewhere in that supply chain is an ordinary private business, quite possibly one that has never opened the National Risk Register and that does not realise that it is relevant to them.

I say all this from experience, not cynicism. Some years ago, during my emergency planning career, I was asked to write content for the London mass evacuation plan – the one that, among other things, proposed using a local stadium as a reception point for evacuees. Grand in scope, sensible in principle – the kind of thing that reads well in a strategic document. At the same time, I was trying to persuade the local social services team to put together a plan for a single rest centre. Not thousands of people. Not even hundreds. Tens. I could not get it done. The capacity, the ownership, and the basic ‘who does what’ simply were not there for the small version of the problem, let alone the version involving a stadium’s worth of evacuees turning up with nowhere to go.

That gap – between what the top-level plan assumes will happen beneath it and what actually happens beneath it – does not get smaller just because the exercise gets bigger, and it does not stop at the local authority boundary either. Local authorities, voluntary-sector partners, and the private businesses that supply the water, data, and systems addressed by the National Risk Register: how consistently are they participating in relevant exercises? Or are some of them, like the social services team was when I was pushing for that single rest-centre plan, simply not resourced to think about it until it is already happening?

Whether the National Risk Register itself is the right prompt for that conversation is a fair question, given the apparent awareness gap among small businesses. But the exercise it points towards – honestly assessing how prepared your organization is for national-level risks whose consequences could disrupt it – matters regardless of where the prompt comes from. It is an awareness question that extends well below ministers and local authorities, to individual staff in ordinary businesses who have never heard of ALBISTON SHADOW or the National Risk Register but who are, in practice, part of the systems on which national resilience depends.

The author

Helen Molyneux is the founder and director of RiskReady, an e-learning platform for business continuity, information security, and crisis management training, and Cambridge Risk Solutions, an independent resilience consultancy. A certified Lead Auditor for ISO 22301 and ISO 27001, she has spent more than two decades working in business continuity and crisis management across the public and private sectors, including an earlier career in emergency planning. She writes from practice, not theory.

UK
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email WhatsApp
Previous ArticleNew research supports the general perception that AI governance is not keeping up with organizational realities
Next Article Research identifies identity management gaps in agentic AI deployments

Related Posts

An exploding digital padlock illustrates the requirement for post-quantum cryptography.

Research breakthrough brings reliable quantum computers and Q-day closer to reality

September 10, 2026
A danger sign on a digital background.

New blob URL phishing technique evades detection by using legitimate Microsoft services

September 10, 2026
AI risks

Unmanaged AI workflows expose EMEA organizations to rising compliance and data risks

September 9, 2026
City skyline at sunset with bright light trails and a translucent blue smart-city grid overlay and GPS pins indicating locations.

AI world models: future possibilities for organizational resilience?

September 7, 2026
DRJ and BCI logos

DRJ and BCI publish guidance for governing, managing, and using AI in resilience

September 7, 2026
Decision making with over whelming information.

AI can find the vulnerability. Accountability still sits with your crisis leadership

September 7, 2026
Advertisement
Resilience First
This week's most read articles
Under pressure: An egg cracking under pressure applied by squeezing clamps form the sides.

Managing scenario testing for operational resilience

May 16, 2024
COSO logo

New COSO ERM guidance aims to help organizations with practical implementation

May 12, 2026
Close-up of a green-brown iris peering through a jagged tear in dark paper or wall material.

The blind spots in business continuity

September 2, 2026
Latest resources
DRJ and BCI logos

DRJ and BCI publish guidance for governing, managing, and using AI in resilience

September 7, 2026
Load More

Subscribe to Updates

Get our Resilience Updates newsletter.

Most Popular Feature Articles
Three dark coloured light bulbs on a black background illustrate the concept of The Dark Triad in Crisis Management.

The Dark Triad in crisis management

Five stage crisis management framework

A five stage framework for a crisis management process

Blue interconnected gears and network nodes symbolizing automation and complex machinery.

Agent zero – the 2028 digital pandemic

Latest Reports
A futuristic red warning alert icon with glowing exclamation mark.

Cloud Security Alliance publishes Hugging Face Incident Initial Post-Mortem

A person hold a building door open for a person behind who is tailgating to get unauthorised access.

Security Culture: A Strategic Capability That Builds Resilience in a Volatile World

An identity icon with a map marker on it, indicating the concept of identity as a target for attackers. The icon is on a generic IT background predominantly in black and orange.

Identity-based approaches dominate initial access for ransomware attacks

A promo box for an article about resilience governance.
© 2026 Resilience Forward
  • About Resilience Forward
  • Newsletter
  • Newsfeed
  • Advertise
  • Call for Papers
  • Contact
  • Privacy Policy and Cookie Use
  • AI Use Policy

Type above and press Enter to search. Press Esc to cancel.

Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Ad Blocker Enabled!
Ad Blocker Enabled!
Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.

Sign In or Register

Welcome Back!

Login to your account below.

Lost password?