Close Menu
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
More items
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
X (Twitter) LinkedIn
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
Login
LinkedIn Bluesky
Resilience Forward
Subscribe Now
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
Resilience Forward
You are at:Home»Risk»People risks: the traveller you cannot locate (Page 22)
Risk

People risks: the traveller you cannot locate

Travel safety apps cannot protect employees they cannot locate. Matt Atkinson examines the hidden connectivity dependency in travel risk management and the potential for mobile-network data to provide a resilient fallback.
August 7, 20267 Mins Read
A protest taking place, with burnt vehicles and rubble strewn accross the road.

At 07:20 local time in Paris, a demonstration outside a hotel in the central business district turned into something the overnight risk briefing had not predicted. By 08:00, the security team in London had opened the incident, raised the country and city risk levels, and issued a welfare message for the four employees it believed were in Paris.

Three replied within the hour. The fourth did not.

The travel risk management platform showed a last known position for the unlocated employee in central London, eleven days earlier. They had installed the safety app during onboarding, declined location permission because it was their own handset, and had not opened the app since. Their travel itinerary sat in the booking tool. Their phone was on a personal SIM over which neither IT nor the risk team had any visibility. The travel risk tools were operating exactly as specified; they simply had nothing to work with for the missing traveller.

They were safe and eventually checked in by email. That is how these stories usually end; and it is why the gap never gets fixed.

The GPS mechanism works perfectly, but only when deployed

Most duty-of-care programmes locate people through a GPS-enabled application on their smartphone. For an application to report a person’s location, three conditions must be met simultaneously: it must be installed, it must have been granted location permission, and the device must have a working cellular data connection or access to a Wi-Fi network. Each of those conditions may sit outside the organization’s direct control. The programme is only ever as good as the weakest of the three on the worst day of the year.

There is, however, a second source of location data that most programmes never touch: the mobile network itself.

The invisible vulnerability

Check-in and tracking tools are typically procured as communications tools, independently of mobile services. Budgets may sit with travel, HR, or security rather than IT. Success may be measured by app and service rollout completion and licence count, not by whether the service can access accurate location data when it is needed most. Failover testing may not be performed because location is treated as an assumed capability and IT is expected to ensure that users are always connected.

Classify the same tool under business continuity with a connectivity dependency and everything changes. It would carry a documented configuration and require a degraded or back-up mode, an evidenced test cycle and a named product owner, in the way a failover circuit or a disaster recovery site does. Instead, connectivity is taken for granted and any failure is filed as an temporary IT problem.

The tool is on the asset register. The risk created by its connectivity dependency is not on the risk register.

Why GPS and app-based location services fall down at adoption

The reasons are complex and both structural and attitudinal.

  • Location permission is fundamental to the product, but many users decline it for privacy reasons, often as a default reaction or without understanding the implications. World Travel Protection surveyed 1,000 North American business travellers in February 2024. Around seven in ten said their employer encouraged the use of a travel safety app. Only about three in ten had downloaded one. The split beneath that number matters more than the headline: 31% of US and 17% of Canadian travellers were hesitant about the recommended app, while 22% of US and 23% of Canadian travellers had simply not prioritised it. Resistance to perceived corporate tracking and apathy (‘I won’t need this’) require different remedies; and neither is solved by constant reminder emails.
  • Cellular or Wi-Fi connectivity is assumed rather than verified. Holafly’s Global eSIM and Travel Report 2025-2026 found that more than half of travellers cite slow or unreliable Internet as their main pain point abroad and 43% report losing signal when crossing a border. A border crossing is the exact moment when a location update carries the most value. However, data caps and tariff or configuration errors on corporate SIMs and devices can prevent data access even when local network coverage is available.
  • App check-in asks the person under pressure to do the administration. Asking someone in a high-risk or degraded situation to confirm that they are safe puts the burden in the worst possible place.
  • There is no defined fallback. When the app is silent, most programmes revert to international SMS and voice calls, which may be delayed, filtered, or dropped when a device is roaming.

Adoption is not always an end-user engagement problem. It is also a technical design problem.

The same gap, under rising pressure

In normal operations, the gap is invisible. Silence looks identical to safety and no one queries it. In a stress event, such as a delayed flight, systems outage, or natural disaster, the gap becomes an inconvenience. Someone in HR starts working through a spreadsheet of names and telephone numbers and the picture is assembled slowly enough to be useless but fast enough to feel adequate afterwards.

In a crisis, the first question asked by the board, the insurer, and eventually the regulator is the same: “Who was affected and when did you know?” That question cannot be answered from an unanswered check-in request. What arrives instead is a round of calls, an itinerary reconstruction, and an admission that the last confirmed position was days old.

The layer does not fail suddenly. It fails progressively and its impact is only truly visible at the end.

What the mobile network already knows

Every handset that attaches to a mobile network causes the network to generate connection and location reference information as a by-product: the country, the serving operator, and the serving cell. Once the relevant SIM or eSIM service has been provisioned, this requires no app, GPS permission, user action, or behaviour change; it is automated and passive. With appropriate end-user consent, that by-product becomes a continuity asset rather than network operational data.

Used appropriately, it answers questions that the app layer cannot answer when GPS tracking is not enabled. Which country is this person in now? When did they arrive? Have they moved into a higher-risk area? Have they been offline for longer than the policy allows?

Two qualifiers apply.

First, the data is generally coarse by design and may resolve to a country, city, city district, or airport rather than a specific street address. That level of granularity may be sufficient to inform duty-of-care decisions, while its limited precision is also relevant to privacy review.

Second, its use should be consent-based and configurable for each individual, with granularity, retention, and access rules agreed with privacy stakeholders before deployment, not afterwards.

Several specialist corporate connectivity and global eSIM providers now expose these network events to travel risk platforms through APIs and, as a by-product of their own services, provide alternative backup data connectivity for global travellers. SureSIM Global is one such example, offering near-real-time visibility of mobile connections in more than 200 destinations. The relevant point is the existence of the second source, not the choice of supplier.

What resilience leaders should be asking now

  • What percentage of our travelling population has the safety app installed, permitted, and functional today, based on evidence rather than assumption?
  • What is our documented degraded mode when the app layer produces nothing and when was it last tested end-to-end?
  • Can we answer “Who is in this city right now?” without asking anyone to check in?
  • Does our location capability depend on a single carrier relationship and a single data path?
  • Would our current evidence trail withstand review against ISO 31030, including where the capability relies on voluntary participation?

Connectivity sits at the heart of duty of care for travellers

The primary risk is not that the app malfunctions. It is that the plan quietly assumes that users can always be reached – an assumption that is rarely stress-tested or verified.

The author

Matt Atkinson is the founder and managing director of Utelize Mobile, a UK enterprise mobility management specialist and the company behind SureSIM Global

Africa Asia Asia Pacific Australasia Europe Middle East North America UK
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email WhatsApp
Previous ArticleWhat AI deploying organizations need to comply with and govern under  Article 50 of the AI Act
Next Article The stories behind the organization: how cultural narratives shape resilience

Related Posts

An exploding digital padlock illustrates the requirement for post-quantum cryptography.

Research breakthrough brings reliable quantum computers and Q-day closer to reality

September 10, 2026
A danger sign on a digital background.

New blob URL phishing technique evades detection by using legitimate Microsoft services

September 10, 2026
AI risks

Unmanaged AI workflows expose EMEA organizations to rising compliance and data risks

September 9, 2026
City skyline at sunset with bright light trails and a translucent blue smart-city grid overlay and GPS pins indicating locations.

AI world models: future possibilities for organizational resilience?

September 7, 2026
DRJ and BCI logos

DRJ and BCI publish guidance for governing, managing, and using AI in resilience

September 7, 2026
Decision making with over whelming information.

AI can find the vulnerability. Accountability still sits with your crisis leadership

September 7, 2026
Advertisement
Resilience First
This week's most read articles
Under pressure: An egg cracking under pressure applied by squeezing clamps form the sides.

Managing scenario testing for operational resilience

May 16, 2024
COSO logo

New COSO ERM guidance aims to help organizations with practical implementation

May 12, 2026
Close-up of a green-brown iris peering through a jagged tear in dark paper or wall material.

The blind spots in business continuity

September 2, 2026
Latest resources
A hand holds a glowing blue shield containing the letters AI.

Governance resources: AI in the Workplace Governance Policy Template

November 25, 2025
Load More

Subscribe to Updates

Get our Resilience Updates newsletter.

Most Popular Feature Articles
Three dark coloured light bulbs on a black background illustrate the concept of The Dark Triad in Crisis Management.

The Dark Triad in crisis management

Five stage crisis management framework

A five stage framework for a crisis management process

Blue interconnected gears and network nodes symbolizing automation and complex machinery.

Agent zero – the 2028 digital pandemic

Latest Reports
A futuristic red warning alert icon with glowing exclamation mark.

Cloud Security Alliance publishes Hugging Face Incident Initial Post-Mortem

A person hold a building door open for a person behind who is tailgating to get unauthorised access.

Security Culture: A Strategic Capability That Builds Resilience in a Volatile World

An identity icon with a map marker on it, indicating the concept of identity as a target for attackers. The icon is on a generic IT background predominantly in black and orange.

Identity-based approaches dominate initial access for ransomware attacks

A promo box for an article about resilience governance.
© 2026 Resilience Forward
  • About Resilience Forward
  • Newsletter
  • Newsfeed
  • Advertise
  • Call for Papers
  • Contact
  • Privacy Policy and Cookie Use
  • AI Use Policy

Type above and press Enter to search. Press Esc to cancel.

Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Ad Blocker Enabled!
Ad Blocker Enabled!
Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.

Sign In or Register

Welcome Back!

Login to your account below.

Lost password?