Close Menu
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
More items
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
X (Twitter) LinkedIn
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
Login
LinkedIn Bluesky
Resilience Forward
Subscribe Now
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
Resilience Forward
You are at:Home»Risk»Threatscape»Looking below the surface of the 2025 Risk and Resilience Trends Report (Page 20)
Threatscape

Looking below the surface of the 2025 Risk and Resilience Trends Report

The findings of the DRI 2025 Risk and Resilience Trends Report hint at a risk landscape shifting faster than our preparedness, as Rachael Elliott explains…
December 10, 202511 Mins Read
An iceberg seen from the side with a small proportion showing above the surface of the water and a much larger proportion hidden underneath

The DRI 2025 Risk and Resilience Trends Report was published recently. The report, now in its eleventh year, uses results from a global survey to review the top risks, threats, and strategic issues that industry professionals have encountered over the past year, and considers how organizations should improve their resilience going forward. This year’s report also contains a deep delve into cyber security – as this has remained the top risk for the past four years.

The global risk landscape in 2025: a year shaped by conflict, digital security, and climate crises

Overall, the 2025 global risk landscape was shaped by intertwined geopolitical, environmental, economic, and technological shocks. The central challenge in 2025 for governments and organizations alike lay in balancing immediate security and cost-of-living pressures with longer-term investment in climate adaptation, digital resilience, and social protection.

For practitioners, concerns naturally circle around risks that directly concern their organizations, whereas analysts in the World Economic Forum (WEF)’s Global Risks Report 2025 ranked state-based armed conflict and great-power rivalry as the dominant short-term hazards, with escalating wars and deepening trade fragmentation raising the risk of an unstable economic environment, political instability, and cross-border spillovers.

Another key risk which came to the fore in 2025 was climate risk. The pressure intensified as temperatures edged beyond the Paris Agreement’s 1.5°C ambition; the UN Emissions Gap Report 2025 projected overshoot, and the year also saw more frequent weather extremes, from Southern Europe’s heatwaves to major flooding in South Asia. In addition, technological vulnerabilities also widened: artificial intelligence (AI)-enabled cyber attacks disrupted critical infrastructure, while coordinated disinformation campaigns affected elections in multiple regions.

How does this compare to practitioners’ views? Remarkably closely, in fact. While armed conflict and terrorism still rank low in the list of organizational disruptions in the 2025 DRI Risk and Resilience Trends report, changing alliances and geopolitical conflicts are one of the five key strategic risks highlighted by the DRI Future Vision Committee (FVC). There are concerns about ongoing global stability, the rise of cyber-related warfare, and, in some cases, the physical and human consequences of conflict on workforce and their families. This can lead to corporate uncertainty because of unpredictable demand, heightened credit risks, and retreating investment.

Cyber risks, a key theme of global risk reports over the past year, is also the greatest threat to businesses over the past year according to the DRI survey. It has remained in first place for the past four years, and only briefly pushed into second place at the height of the COVID-19 pandemic in 2021 (see Table 1 below).

Risk and resilience trends
Table 1

Amongst the top ten risks, there are two which have seen particular change: firstly, financial conditions (rated in ninth place in 2021) has been rising up the top ten during the past five years and is now the third greatest concern for survey respondents; tying in with the financial risks highlighted in the IMF’s World Economic Outlook. The other risk which has had a growing impact over the past four years is that of increasing power shortages. The risk sat firmly in last place in 2021 but has risen to sixth place this year. Although power shortages are not identified in many industry risk reports, their inclusion in the DRI report is as a result of the specific impact of these events on practitioners’ organizations. These power shortages, which are normally not planned, can, for example, be caused by inclement weather, increased demands for energy, damage to power generation units through malicious physical or cyber attacks, or reduction in supply due to intra-border conflicts.

Cyber security – the top threat, year-on-year

The table above shows how cyber security has remained the top risk for organizations for the past four years – something which is emulated by other corporate risk reports such as the Allianz Risk Barometer 2025. Some risks achieve particular prominence due to events that have occurred during that year (e.g. the COVID-19 pandemic), whereas the ever-evolving nature of cyber crime means that organizations have to remain on guard to both traditional and newer threats, as well new cyber attack vectors being created through the use of AI (e.g. AI-enhanced phishing and social engineering, automated vulnerability discovery, deepfake-driven impersonation, AI-powered malware and evasion). As a result, organizations have to invest in both technology and talented staff to ensure that their organization – and their customers and suppliers – are protected against cyber criminals. For the c-suite, a successful cyber attack has the potential to stop production, bring a business offline, and affect payment systems – all affecting a company’s bottom line.

Supply chain and third-party risk management – the new battleground?

COVID-19 was a reminder to the world of the fragility of global supply chains. Air transport routes were closed overnight, container ships were unable to dock, and previously successful just-in-time production strategies failed due to the loss of the ability to acquire goods quickly. While many organizations have introduced new supplier management strategies as a result of the pandemic (e.g. nearshoring, increasing safety stock, improved supplier management), another global event with a different trajectory to COVID-19 has the potential to disrupt organizations further.

The survey shows that supply chain disruption was only in ninth place in the DRI report’s risk index this year which shows the impacts felt during COVID-19 have waned – at least for the time being. However, the need for good vendor management is more critical than ever due to the exceptionally diverse and ever-changing risk landscape. The companies that perform regular due diligence on their suppliers, map their supplier base beyond their closest – tier 1 – suppliers, and carry out regular training and exercising with their critical suppliers are set to be those that thrive ahead of their competitors at the first hint of any disruption.

AI and its impact on business resilience

The impact of AI-related cyber crime has already been discussed in this article, but survey respondents reported the impact of AI on their organizations was far greater than just the threat posed by its use in cyber crime. including:

  • The inaccuracy of AI in its current state.
  • The possible loss of institutional knowledge when AI is used without human support.
  • The risk of AI investment taking resources away from other areas, including business continuity and resilience.
  • AI automating current business continuity processes and opening the company up to new risks (e.g. total automation of the BIA without human intervention or verification, data mining unverified internal and external data sources, automation of risk management processes).

Indeed, while there are advantages to adopting AI to assist with business continuity processes and procedures (e.g. datamining, supply chain analysis), for some organizations, using AI remains a challenging prospect. Therefore, should organizations hold off adoption until the technology becomes more tried and trusted, or should they risk being left behind in terms of the potential efficiency gains that AI can offer to resilience teams? Both parts of the argument need careful consideration by all parties but, at the very least, an AI-usage policy should be drawn up for an organization so all parties are clear of their own responsibilities in using the technology, the potential risks involved, and the limitations of usage within the organization.

How should practitioners be better prepared for these risks?

Overall, the best practitioners will be prepared for any incident that could affect their organization – as well as the potential impacts of incidents that are impossible to predict (the unknown unknowns). Using a risk agnostic approach ensures preparedness for all impacts, rather than just specific scenarios. For example, in an Internet blackout – regardless of cause – the processes followed to ensure critical business activities continue to run, or if staff are suddenly unable to access an office – whether through severe weather, pandemic, or fire – they are drilled in what to do if such an impact occurs.

However, in terms of the specific risks highlighted in the 2025 Risk and Resilience Trends Report, there are several steps that practitioners can take to ensure they are better protected from the threats:

Risk

How to Prepare from a business continuity and resilience perspective

Relevant DRI Professional Practice(s)

1. Armed conflicts & global instability

  • Conduct risk assessments for geopolitical threats and cascading impacts to safety, workforce, facilities, and supply chain.
  • Prepare incident response procedures for civil unrest, evacuation, shelter-in-place, and travel restrictions.
  • Identify alternate locations, hybrid working, back-up production facilities, and remote work strategies.
  • Strengthen crisis communications for employees, their families, suppliers and other third parties.
  • Coordinate with external agencies (e.g. national and/or regional government, security services, emergency services).

PP2: Risk Assessment – assess external human-caused risks; evaluate impacts and controls.
PP4: Business Continuity Strategies – alternate sites, relocation, work-from-home.
PP5: Incident Preparedness and Response – life safety, hazard identification, incident command.
PP9: Crisis Communications – internal/external messaging planning.
PP10: Coordination with External Agencies and Resources– collaboration with public agencies.

2. Unplanned power outages

  • Identify critical systems requiring, redundant power, generators, uninterrupted power supply (UPS).
  • Assess facility vulnerabilities and backup power capabilities.
    Implement alternate-site strategies or remote working capability.
  • Ensure technology recovery plans consider power loss scenarios.
  • Exercise power-failure scenarios (e.g. manufacturing facility blackout, data centre outage, regional outage including offices and staff homes).

PP2: Risk Assessment – evaluate utility failures and technology exposures.
PP4: Business Continuity Strategies – alternate sites, manual workarounds, technology redundancy.
PP6: Plan Development and Implementation – document recovery procedures for power loss.
PP8: Business Continuity Plan Exercise/Test, Assessment, and Maintenance – test power outage recovery strategies.

3. Cyber attacks

  • Integrate cyber security considerations into risk assessment.
  • Protect backup data using air-gapping, isolation, and redundant storage.
  • Validate incident response procedures for ransomware, data breaches, and AI-driven attacks (e.g. automated phishing, deepfake threats).
  • Develop technology recovery strategies, including high availability and cloud capabilities.
  • Train staff on recognising evolving attack types.
  • Ensure a close relationship between business continuity and cyber security/IT to ensure a cohesive strategy can be drawn up effectively.

PP2: Risk Assessment – cyber security, data protection, controls review.
PP4: Business Continuity Strategies – tech recovery, cloud, multi-data-centre strategies.
PP5: Incident Preparedness and Response – cyber incident preparedness and coordination.
PP6: Plan Development and Implementation – technology recovery plans.
PP7: Awareness and Training Programs – security awareness and incident recognition training.

4. Supply chain disruption

  • Assess critical suppliers and dependencies during the BIA and risk assessment.
  • Develop multi-sourcing, substitute products, inventory strategies, and alternate suppliers.
  • Define logistics contingency processes.
  • Include supply chain recovery approaches in BC plans and exercises.
  • Expand risk assessment beyond tier 1 (i.e. tier 2 – suppliers’ suppliers, tier 3 – suppliers’ suppliers’ suppliers).
  • Build strong, mutually beneficial relationships with existing suppliers to ensure early warning of potential supply issues.

PP2: Risk Assessment – identify supply chain vulnerabilities and external dependencies.
PP3: Business Impact Analysis – capture supplier dependencies and impacts.
PP4: BC Strategies – supply chain continuity strategies and logistics alternatives.
PP8: Exercises/Tests – validate supply chain continuity via scenarios.

5. AI usage (operational & organizational risk)

  • Assess AI-related risks: system failures, data integrity issues, compliance, automation dependencies, and impact on workforce.
  • Include the risk of AI-driven job loss in risk assessments to plan for continuity of critical skills and knowledge.
  • Map where AI automates tasks and identify processes requiring human oversight or manual fallback.
  • Build succession and cross-training plans to protect against over-reliance on automated workflows.
  • Include AI-supported functions in the BIA to recovery time objectives, impacts if functions fails.
  • Define human procedures and manual alternatives in recovery plans.
  • Train staff in responsible AI use, oversight, and new skillsets needed as AI starts to grow in its organisational usage or replaces roles.

PP2: Risk Assessment – evaluate technology exposures and human-resource impacts, including emerging AI risks.
PP3: Business Impact Analysis – identify dependencies on AI-automated roles and assess impact of workforce changes.
PP4: Business Continuity Strategies – develop manual workarounds, cross-training, and redundancy where AI replaces jobs.
PP6: Plan Development and Implementation – integrate fallback processes for AI-dependent operations.
PP7: Awareness & Training – reskill employees and prepare teams for AI-enabled role transitions.

Conclusion

As this year’s Risk and Resilience Trends Report shows, the threats facing organizations are evolving, but so too are the tools, skills, and strategies available to manage them. Cyber attacks remain the dominant disruptor, yet it is the convergence of risks – geopolitical shocks, climate volatility, AI disruption, and supply chain fragility – that truly defines the resilience challenge ahead. No organization can treat these risks as isolated technical issues. They are now strategic pressures that shape culture, investment, and competitiveness.

The author

Rachael Elliott is Director of Global Strategy and Innovation for DRI International. Rachael has particular expertise in the technology side of resilience, and has a keen interest in how artificial intelligence can help to transform the resilience of organizations. Her research has been used in the UK Parliament to help develop government industrial strategy as well as in the BDO High Street Sales Tracker, which Elliott was instrumental in developing and is still the UK’s primary barometer for tracking high street sales performance. She maintains a keen interest in competitive intelligence and investigative research techniques.

DRI logo
Resilience Perspectives
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email WhatsApp
Previous ArticleRisk Outlook report: uncertainty is shaping the pace of preparedness
Next Article True cyber resilience comes from uniting people, processes, and technology

Related Posts

An exploding digital padlock illustrates the requirement for post-quantum cryptography.

Research breakthrough brings reliable quantum computers and Q-day closer to reality

September 10, 2026
A danger sign on a digital background.

New blob URL phishing technique evades detection by using legitimate Microsoft services

September 10, 2026
AI risks

Unmanaged AI workflows expose EMEA organizations to rising compliance and data risks

September 9, 2026
City skyline at sunset with bright light trails and a translucent blue smart-city grid overlay and GPS pins indicating locations.

AI world models: future possibilities for organizational resilience?

September 7, 2026
DRJ and BCI logos

DRJ and BCI publish guidance for governing, managing, and using AI in resilience

September 7, 2026
Decision making with over whelming information.

AI can find the vulnerability. Accountability still sits with your crisis leadership

September 7, 2026
Advertisement
Resilience First
This week's most read articles
Under pressure: An egg cracking under pressure applied by squeezing clamps form the sides.

Managing scenario testing for operational resilience

May 16, 2024
COSO logo

New COSO ERM guidance aims to help organizations with practical implementation

May 12, 2026
Close-up of a green-brown iris peering through a jagged tear in dark paper or wall material.

The blind spots in business continuity

September 2, 2026
Latest resources
An exploding digital padlock illustrates the requirement for post-quantum cryptography.

Board briefing: preparing for the post-quantum era

November 27, 2025
Load More

Subscribe to Updates

Get our Resilience Updates newsletter.

Most Popular Feature Articles
Three dark coloured light bulbs on a black background illustrate the concept of The Dark Triad in Crisis Management.

The Dark Triad in crisis management

Five stage crisis management framework

A five stage framework for a crisis management process

Blue interconnected gears and network nodes symbolizing automation and complex machinery.

Agent zero – the 2028 digital pandemic

Latest Reports
A futuristic red warning alert icon with glowing exclamation mark.

Cloud Security Alliance publishes Hugging Face Incident Initial Post-Mortem

A person hold a building door open for a person behind who is tailgating to get unauthorised access.

Security Culture: A Strategic Capability That Builds Resilience in a Volatile World

An identity icon with a map marker on it, indicating the concept of identity as a target for attackers. The icon is on a generic IT background predominantly in black and orange.

Identity-based approaches dominate initial access for ransomware attacks

A promo box for an article about resilience governance.
© 2026 Resilience Forward
  • About Resilience Forward
  • Newsletter
  • Newsfeed
  • Advertise
  • Call for Papers
  • Contact
  • Privacy Policy and Cookie Use
  • AI Use Policy

Type above and press Enter to search. Press Esc to cancel.

Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Ad Blocker Enabled!
Ad Blocker Enabled!
Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.

Sign In or Register

Welcome Back!

Login to your account below.

Lost password?