Earlier this month, we attended the 2026 Airmic (Association for Insurance & Risk) Annual Conference at the ICC in Birmingham.

The theme “Back to Basics” was timely.

Across the risk and insurance community, there was no shortage of discussion about emerging risks: artificial intelligence, cyber exposure, data centres, climate volatility, geopolitical uncertainty, claims complexity and insurance protection gaps. Yet the strongest message was not that organisations need to chase every new risk in isolation. It was that the basics matter more when the environment becomes more complex.

For business continuity, resilience and crisis management professionals, this is an important point. New threats may demand new thinking, but effective resilience still depends on clear governance, understood dependencies, tested response structures, practical plans, good communication and a willingness to learn before events expose weaknesses.

Complex Risks Still Expose Basic Gaps

Airmic’s programme reflected the risk landscape many organisations are already experiencing. AI is reshaping cyber risk and decision-making. Data centres are concentrating operational, financial and infrastructure dependencies at a scale that traditional risk models may not fully capture. Climate risks are no longer abstract future scenarios; they are influencing supply chains, assets, people, insurance capacity and day-to-day operations.

June has provided a sharp reminder of this. The Met Office issued extreme heat warnings during the month, highlighting potential impacts across public health, infrastructure, transport, energy and water supply. For organisations, this is not simply a weather story. It is a continuity issue, a people issue, a facilities issue, a supplier issue and, in many cases, a customer service issue.

The same principle applies to cyber. The UK Government’s Cyber Security Breaches Survey 2025/2026 reported that 43% of businesses identified a cyber breach or attack in the previous 12 months. While many incidents may appear technical at first glance, their consequences are often operational: disrupted services, pressure on communications teams, loss of confidence, supplier impacts, regulatory scrutiny and difficult recovery decisions.

In each case, the question is not only “what is the risk?” It is “how ready are we to respond, recover and adapt?”

AI, Cyber and the Need for Human Judgment

AI was a dominant theme at Airmic 2026, particularly regarding cyber risk, insurance and organisational decision-making. The pace of adoption is creating both opportunity and exposure.

For resilience leaders, the practical challenge is to ensure that AI is neither treated as a magic solution nor as a distant concern. It is already being used by organisations, suppliers and threat actors. That means it needs to be understood in the context of business impact analysis, supplier assurance, information security, crisis communications and governance.

There are several questions worth asking now:

  • Is AI being used in prioritised activities or critical decision-making processes?
  • Do teams understand where AI tools sit within operational dependencies?
  • Have cyber and continuity teams considered how AI-enabled threats may alter response assumptions?
  • Are there clear escalation routes if AI-generated information is wrong, misleading or unavailable?
  • Where policy, procedure or insurance cover relies on human review, accountability or evidence, has that been tested?

AI may accelerate analysis, but it does not remove the need for judgment. In a crisis, leaders still need to make decisions with incomplete information, explain those decisions clearly and maintain trust with stakeholders. There needs to be a human harness.

Insurance Is Important, But It Is Not a Continuity Strategy

Another recurring discussion at Airmic (Association for Insurance & Risk) was the insurance protection gap. This is especially relevant where risks are interconnected, fast-moving or difficult to value.

Insurance has a vital role to play, but it cannot replace resilience capability. A policy may provide financial support after an event, but it does not automatically restore operations, reassure employees, communicate with customers, manage suppliers or protect reputation.

This is where business continuity management remains essential. Organisations need to understand their prioritised activities, dependencies, recovery requirements and single points of failure before a disruption occurs. They also need to understand how different response plans interact: cyber incident response, crisis management, emergency response, communications, supply chain continuity, technology recovery and business recovery.

The more connected the risk, the more important it becomes to avoid planning in silos.

Climate and Infrastructure: Testing Assumptions Before They Fail

Climate risk is often discussed in strategic terms, but its operational implications are immediate and practical.

Heat, flooding, storms, water stress, and power disruptions can affect employees, premises, transport routes, stock, data centres, third-party providers and customer access. Some impacts may be acute and visible. Others may be slower-moving, such as increased maintenance requirements, reduced productivity, insurance restrictions or changes in supplier viability.

A resilient organisation does not need a separate plan for every possible weather event. It does need a clear understanding of what conditions could interrupt its most important activities, who would be affected, what alternatives exist and how decisions would be made.

That means scenario planning and exercising should include realistic environmental pressures. Not only “what if the building is unavailable?” but also “what if several dependencies are strained at the same time?” Not only “what if a supplier fails?” but also “what if multiple suppliers are affected by the same regional event?”

The Power of Practice

At Horizonscan, we often return to a simple principle: plans become useful when people have practised using them.

Crisis simulation exercises are not about catching people out. They are about helping teams understand roles, test assumptions, improve communication and build confidence before a real disruption occurs.

This aligns closely with Airmic (Association for Insurance & Risk) Back to Basics message. In a complex risk environment, organisations need response structures that are understood, not just documented. They need communication processes that work under pressure. They need senior leaders who are comfortable making decisions in uncertainty. They need lessons identified through exercising to become lessons acted upon through maintenance, review and continual improvement.

  • A good exercise should reveal practical questions:
  • Do we know who is accountable for key decisions?
  • Can we quickly identify impacts across people, operations, suppliers and customers?
  • Are our escalation routes clear?
  • Do our plans reflect how the organisation actually works?
  • Can we communicate consistently with internal and external stakeholders?
  • What would we stop, continue, prioritise or recover first?

These questions may sound basic. That is precisely why they matter.

Returning to the Fundamentals

The pace of change across AI, cyber, climate, infrastructure and insurance can make resilience feel increasingly complicated. But the most effective organisations are often those that keep returning to the fundamentals and applying them with discipline.

That means building a fit-for-purpose continuity capability, not a shelf of documents. It means aligning risk assessment, business impact analysis, recovery strategy design, response planning, exercising and review. It means involving the right people before a disruption, not discovering critical dependencies during one.

Airmic 2026 was a useful reminder that “Back to Basics” does not mean going backwards. It means strengthening the foundations that allow organisations to face new risks with clarity, confidence and adaptability.

For resilience professionals, the message is clear: the future may be uncertain, but preparedness is practical. The organisations best placed to manage disruption will be those that understand their priorities, test their capabilities and keep learning.

Risk, resilience and readiness remain inseparable.

Thanks for reading

The Horizonscan Team