Close Menu
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
More items
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
X (Twitter) LinkedIn
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
Login
LinkedIn Bluesky
Resilience Forward
Subscribe Now
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
Resilience Forward
You are at:Home»2026 Predictions»Resilience in an age of structural uncertainty: a look ahead (Page 3)
2026 Predictions

Resilience in an age of structural uncertainty: a look ahead

Rachael Elliott highlights key themes from the recently published DRI 2026 Predictions Report.
January 15, 20269 Mins Read
An image of the globe, with swirls illustrating geopolitical uncertainty.

The DRI 2026 Predictions Report presents a reflection on the accelerating complexity of risks faced by organizations operating in an increasingly unpredictable environment. Developed by the DRI International Future Vision Committee (FVC), the report does not attempt to forecast with certainty. Instead, it offers an interpretation – by practitioner and academic experts – of emerging geopolitical, economic, technological, and societal pressures that are likely to shape organizational risk landscapes over the coming year.

For resilience professionals, the value of the report lies in its capacity to prompt structured foresight. It highlights how interrelated risks – from geopolitical instability and supply chain fragility to cyber insecurity and climate volatility – are no longer isolated concerns but ones which cascade into each other. The implications for organizational resilience are therefore primarily systemic, with functional risk only in second place.

Three characteristics emerge:

  • Interconnected disruption: events in one geography or sector escalate across supply chains, labour markets, and digital systems.
  • Compressed decision timeframes: organizations are increasingly required to act with incomplete information.
  • Lack of predictability: traditional planning assumptions become less reliable when ‘unknowns’ are thrown into the equation against a backdrop of changing geopolitical alignment, new technologies (both from a productive and destructive perspective), and workforce stability.

All of these characteristics require movement towards more agile and adaptable resilience frameworks. This is consistent with the FVC’s observation that resilience professionals must move beyond static planning and instead support organizational agility and decision-making under uncertainty.

The following sections outline some of the most important prediction themes of the 2026 Predictions Report:

Prediction theme: geopolitical and economic fragmentation

One of the major themes coming out of the Predictions Report is deepening geopolitical tension, particularly between the United States and China, alongside sustained instability in the Middle East and parts of Europe. These developments are not just standalone geopolitical concerns: supply chain continuity, access to markets and customers, workforce mobility, and regulatory alignment will be impacted.

China’s dominance in rare earth processing, as cited in the Predictions Report, is a very real and industry-critical example. With its control over approximately 90 percent of global rare earth separation capacity, geopolitical friction has the potential to disrupt manufacturing across automotive, defence, and technology sectors. This finding is backed up by various sources: Reuters describes how licensing requirements have halted shipments at ports while applications are processed, while the Center for Strategic and International Studies (CSIS) warns that new Chinese rare earth and magnet restrictions can threaten downstream defence and industrial supply chains.

The point for resilience professionals is straightforward: dependency on a concentrated and geopolitically sensitive supply chain is an operational continuity risk, not a sourcing inconvenience. That is why the Predictions Report examines how firms are exploring product redesign, alternative motor technologies, and stockpiling strategies.

Similarly, ongoing conflict in the Middle East continues to affect global logistics, particularly maritime trade routes. The report explains that instability in this region has implications far beyond energy markets and extends to global disruption in the form of higher insurance costs, limitations on workforce mobility, and civil stability.

For resilience professionals, this highlights the importance of:

  • Understanding geopolitical risk as a business continuity issue rather than one which is consigned to an international relations department.
  • Embedding company-relevant geopolitical intelligence into risk assessments and business impact analyses.
  •  Strengthening supplier visibility, understanding weaknesses of second (suppliers’ suppliers) and third (suppliers’ suppliers’ suppliers) tier suppliers, and the importance of diversification strategies.

How does this play out in practical terms for the practitioner?

In organizations with an advanced resilience programme, geopolitical monitoring is increasingly adopted into routine governance cycles, for example:

  • Updating BIAs with assumptions about lead time volatility and alternative sourcing feasibility.
  • Running tabletop exercises that model trade restrictions, export licensing delays, or shipping route closures, for example.
  • Integrating legal and regulatory analysis to ensure that the company is prepared for potential issues with cross-border compliance.

It could be argued that these are just extensions of what a mature business continuity programme already does – but applied to a faster-moving and more politicised context.

Prediction theme: cyber risk as a systemic business threat

he Predictions Report identifies cyber attacks as one of the most persistent and increasing threats, particularly as artificial intelligence enhances both defensive and offensive capabilities, as well as increasing the number of possible attack vectors.

Backing up the report findings, the WEF’s Global Cybersecurity Outlook 2026 frames the cybersecurity landscape as being reshaped by geopolitical fragmentation, AI adoption, and widening cyber inequity. This supports the FVC’s point that cyber is now a strategic risk, and it helps justify why resilience leaders need to be at the boardroom table when cyber scenarios are discussed.

Most notable is the convergence of cyber risk with operational disruption. Recent incidents show that cyber events can halt manufacturing, disrupt logistics, stall sales, damage brand reputation, and undermine investor confidence. The report also highlights that many successful attacks exploit governance weaknesses rather than technical flaws alone.

For resilience professionals, this highlights the importance of:

  • Compromise of trust in executive communications.
  • Financial control failures under social engineering pressure.
  • Reputational harm when the organization is perceived as unable to protect stakeholders.

How does this play out in practical terms for the practitioner?

  • Cyber resilience must be embedded within enterprise risk management as part of the overall resilience strategy.
  • Incident response planning must account for prolonged system unavailability rather than assuming that rapid recovery can be achieved.
  • Leadership decision-making during a cyber attack is as critical as technical remediation.
  • Verification protocols for high-risk transactions and credential resets must be strengthened.
  • Exercising cross-functional decision-making (legal, finance, IT, communications, and operations) under simulated cyber stress is key.

Prediction theme: artificial intelligence and workforce disruption

The Predictions Report highlights that artificial intelligence will continue to reshape organizational structures, job roles, and skills requirements. However, the transition is unlikely to be smooth. Short-term workforce displacement, skills mismatches, and organizational friction are expected before long-term productivity gains materialise.

This sits within a new, wider macro-trend: technology-led reconfiguration of work is increasing, while governance and skills development is lagging.

For resilience professionals, this creates two main challenges. Firstly, organizations must manage workforce instability while maintaining operational continuity. Secondly, they must ensure that critical institutional knowledge is not lost when technology replaces some of the tasks previously handled by humans, as well as knowledge lost when staff are lost through restructuring.

AI-driven fraud and deepfake risk also connect directly to workforce disruption because staff are increasingly being targeted as an ‘attack surface’ via impersonation and manipulation.

The above has implications for:

  • Workforce planning, succession management, and knowledge management.
  • The need for training and awareness programmes to be better aligned with changing operational realities.
  • Human-centric crisis management approaches that recognise both operational and psychological stressors.

Importantly though, the adoption of AI within resilience functions can be considered positive: it presents opportunities to enhance scenario modelling, streamline the business impact analysis (BIA) process, and provide real-time decision support. However, these benefits will only fully materialise where governance, data quality, and human oversight are properly aligned.

How does this play out in practical terms for the practitioner?

  • Automation support: AI has the potential to speed up data collection, drafting scenarios, and collating intelligence (amongst other benefits).
  • Decision augmentation: AI can support human judgement with structured prompts, pattern recognition, and anomaly detection.
  •  Governed deployment: If AI is to be rolled out in organizations, controls will need to be put in place around data, security, regulation, and accountability.

The evolving role of the resilience professional

Taken collectively, the Predictions Report suggests that resilience professionals are increasingly required to operate as strategic advisors rather than technical specialists. The profession is shifting towards integrating risk intelligence into executive decision-making, bridging operational, technological, and human dimensions of resilience, and guiding and supporting leadership. This could be by, for example, adopting an agnostic approach to risk planning and considering how to effectively manage the effects of an event, rather than writing scenario plans for every possible type of event.

This evolution aligns closely with the intent of the DRI Professional Practices, which emphasise governance, integration, and continuous improvement rather than purely static compliance. In essence, resilience leaders are becoming ‘enterprise integrators’ of risk, business continuity, and response capability.

Practical takeaways for 2026

The table below translates the major themes of the FVC Predictions into practical actions for resilience and business continuity professionals, mapped against the relevant DRI Professional Practices.

Key Theme

Practical Actions for Resilience Professionals

Relevant DRI Professional Practices

Geopolitical instability and supply chain disruption

Strengthen supply chain mapping, diversify critical suppliers, and integrate geopolitical monitoring into risk assessments.

PP2 Risk Assessment; PP4 Business Continuity Strategies; PP10 Coordination with External Agencies

Rising cyber threats and AI-enabled attacks

Enhance cyber-incident preparedness, integrate cyber scenarios into exercises, and strengthen executive cyber decision-making.

PP5 Incident Preparedness and Response; PP8 Exercise, Test and Maintenance

Workforce disruption and AI integration

Update BIAs to reflect skills dependencies; expand training and awareness programmes to support transition.

PP3 Business Impact Analysis; PP7 Awareness and Training

Climate-driven disruption

Incorporate climate stress testing into resilience planning and validate recovery assumptions against extreme scenarios

PP2 Risk Assessment; PP4 Business Continuity Strategies

Regulatory divergence and ESG uncertainty

Align continuity governance with jurisdictional requirements and enhance board-level reporting.

PP1 Program Management; PP9 Crisis Communications

Conclusion: resilience as strategic capability

The DRI International Predictions Report reinforces an often-misunderstood concept for modern organizations: resilience is no longer about returning to normal. Instead, it is about sustaining purpose and performance when in a state of continuous disruption.

The threats outlined for 2026 are not isolated risks but are systemic risks that challenge traditional organizational boundaries. In order for an organization to remain resilient, it requires maturity in governance, clarity in decision-making, and confidence in execution. Crucially, organizations also require resilience professionals to operate as strategic enablers rather than the old, outdated image of being purely technical custodians.

The DRI Professional Practices provides an adaptable framework for meeting these challenges. When applied holistically, they enable organizations to anticipate disruption, absorb shocks, and adapt with intent rather than reaction.

The author

Rachael Elliott is Director of Global Strategy and Innovation for DRI International. Rachael has particular expertise in the technology side of resilience, and has a keen interest in how artificial intelligence can help to transform the resilience of organizations. Her research has been used in the UK Parliament to help develop government industrial strategy as well as in the BDO High Street Sales Tracker, which Elliott was instrumental in developing and is still the UK’s primary barometer for tracking high street sales performance. She maintains a keen interest in competitive intelligence and investigative research techniques.

DRI logo
Resilience Perspectives
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email WhatsApp
Previous ArticleWorld Economic Forum publishes Global Risks Report: geoeconomic confrontation emerges as the top global risk for 2026
Next Article A year on from DORA coming into effect what does the landscape look like?

Related Posts

An exploding digital padlock illustrates the requirement for post-quantum cryptography.

Research breakthrough brings reliable quantum computers and Q-day closer to reality

September 10, 2026
A danger sign on a digital background.

New blob URL phishing technique evades detection by using legitimate Microsoft services

September 10, 2026
AI risks

Unmanaged AI workflows expose EMEA organizations to rising compliance and data risks

September 9, 2026
City skyline at sunset with bright light trails and a translucent blue smart-city grid overlay and GPS pins indicating locations.

AI world models: future possibilities for organizational resilience?

September 7, 2026
DRJ and BCI logos

DRJ and BCI publish guidance for governing, managing, and using AI in resilience

September 7, 2026
Decision making with over whelming information.

AI can find the vulnerability. Accountability still sits with your crisis leadership

September 7, 2026
Advertisement
Resilience First
This week's most read articles
Under pressure: An egg cracking under pressure applied by squeezing clamps form the sides.

Managing scenario testing for operational resilience

May 16, 2024
COSO logo

New COSO ERM guidance aims to help organizations with practical implementation

May 12, 2026
Close-up of a green-brown iris peering through a jagged tear in dark paper or wall material.

The blind spots in business continuity

September 2, 2026
Latest resources
UK Resilience Academy logo

Wargaming in a Resilience Context

August 18, 2026
Load More

Subscribe to Updates

Get our Resilience Updates newsletter.

Most Popular Feature Articles
Three dark coloured light bulbs on a black background illustrate the concept of The Dark Triad in Crisis Management.

The Dark Triad in crisis management

Five stage crisis management framework

A five stage framework for a crisis management process

Blue interconnected gears and network nodes symbolizing automation and complex machinery.

Agent zero – the 2028 digital pandemic

Latest Reports
A futuristic red warning alert icon with glowing exclamation mark.

Cloud Security Alliance publishes Hugging Face Incident Initial Post-Mortem

A person hold a building door open for a person behind who is tailgating to get unauthorised access.

Security Culture: A Strategic Capability That Builds Resilience in a Volatile World

An identity icon with a map marker on it, indicating the concept of identity as a target for attackers. The icon is on a generic IT background predominantly in black and orange.

Identity-based approaches dominate initial access for ransomware attacks

A promo box for an article about resilience governance.
© 2026 Resilience Forward
  • About Resilience Forward
  • Newsletter
  • Newsfeed
  • Advertise
  • Call for Papers
  • Contact
  • Privacy Policy and Cookie Use
  • AI Use Policy

Type above and press Enter to search. Press Esc to cancel.

Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Ad Blocker Enabled!
Ad Blocker Enabled!
Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.

Sign In or Register

Welcome Back!

Login to your account below.

Lost password?