Horizonscan Limited

Introduction

Across Risk World RIMS (Risk and Insurance Management Society, Inc.) , BIBA 2026 and the inaugural Global Risk Summit organised by the City of London Corporation and London Market Group , one message came through clearly:

Resilience is no longer a “nice to have”. It is becoming central to how organisations protect value, maintain confidence and respond to disruption.

The discussions across these events covered artificial intelligence, cyber, climate, geopolitics, supply chains, insurance capacity, data centres and crisis response.

While each event had its own focus, the themes were strongly connected. Organisations are operating in a world where risks are rarely isolated. A cyber incident can quickly become a reputational issue. A geopolitical shock can affect supply chains, finance, operations and customer confidence. Climate risk can influence site resilience, insurability and long-term investment decisions.

In this environment, organisations need more than an understanding of risk. They need practical resilience: the ability to prepare, respond and recover when disruption occurs.

1. AI Needs Governance, Not Just Adoption

Artificial intelligence was one of the most prominent themes across the events.

AI is moving rapidly from discussion to adoption. It already supports productivity, analysis, automation, customer service and decision-making. For many organisations, the opportunity is significant.

However, AI also acts as a risk multiplier.

It can expand attack surfaces, increase cyber exposure and create new governance challenges. Risks discussed across the events included:

  • More sophisticated phishing and social engineering
  • Data leakage through inappropriate AI use
  • Poor control over sensitive or confidential information
  • Misuse of AI-generated outputs
  • Overreliance on tools without sufficient validation
  • Unclear accountability for AI-supported decisions

The issue for organisations is not simply whether to use AI. The more important question is how AI should be governed.

As AI becomes more embedded in everyday operations, organisations will need clear policies, controls, training and oversight. They will also need to understand where AI could create new vulnerabilities, particularly around data protection, cyber resilience and decision-making accountability.

AI can create real value, but only where governance, trust and human judgement keep pace.

2. Cyber Is Now a Resilience Issue

Cyber remained front and centre, particularly at BIBA.

The conversation is no longer only about cyber insurance. Increasingly, cyber is being viewed as a broader resilience issue.

When a cyber incident occurs, organisations need to act quickly. They need clear roles and responsibilities, tested response plans, effective communication processes and confidence in how decisions will be made under pressure.

Insurance can provide vital support, but it cannot replace preparation.

Businesses need to understand how they would respond to a cyber disruption affecting systems, suppliers, customers, operations or reputation. This includes knowing:

  • Who leads the response?
  • How incidents are escalated
  • What information is needed to make decisions
  • How customers, regulators, insurers and stakeholders are informed
  • How critical services are maintained or recovered

Cyber resilience is therefore not just a technical issue. It is an organisational issue.

The organisations best placed to respond will be those that have already tested their plans, trained their teams and understood how a cyber event could affect the wider business.

3. Data Centres Are Creating Concentrated Risk

One of the clearest emerging risk areas discussed at Risk World was the growth of data centres.

AI and digital transformation are driving huge investment in data centre infrastructure. This growth creates significant economic opportunity, but also important risk and resilience considerations.

Key issues include:

  • Fire risk
  • Power interruption
  • Climate hazard exposure
  • Water demand
  • Construction risk
  • Supply chain dependency
  • Community opposition
  • Insurance capacity
  • Concentration of value at individual sites

In some cases, the values involved are enormous, with figures in the billions of dollars being discussed for major data centre campuses. For organisations involved in data centre development, operation, construction, investment, utilities, insurance or supply chains, resilience planning will be essential.

This includes emergency response, business continuity, fire risk planning, climate resilience, crisis management, supply chain resilience and insurance-readiness evidence. As investment in AI infrastructure continues, data centres are likely to remain a major focus for risk professionals, insurers and resilience specialists.

4. Climate Resilience Needs Practical Action

Climate risk was another recurring theme across the events.

The focus is increasingly moving from broad climate awareness to practical resilience planning. Organisations need to understand how climate-related hazards could affect their sites, operations, people, supply chains and insurability.

This may include risks such as:

  • Flooding
  • Extreme heat
  • Storms
  • Wildfire
  • Water stress
  • Infrastructure disruption
  • Access issues
  • Power interruption

For many organisations, the challenge is turning climate risk information into practical action.

That means developing site-level resilience plans, emergency response arrangements, climate hazard mapping, mitigation evidence and clear decision-making processes.

Climate resilience is not only about long-term sustainability. It is also about operational continuity, asset protection and the ability to maintain services during disruption.

As climate risks become more visible to boards, insurers, investors and customers, organisations will need to demonstrate that they understand their exposures and have taken practical steps to manage them.

5. Scenario Planning Is Now Essential

One of the strongest messages from the Global Risk Summit was that resilience cannot be improvised in the moment.

The organisations best placed to respond to disruption are those that have already tested their assumptions, trained their teams and explored difficult scenarios before they become real events.

This means moving beyond static risk registers and asking harder questions:

  • What would break first?
  • Where are our hidden dependencies?
  • How would our leadership team respond under pressure?
  • What decisions would we need to make with incomplete information?
  • Where do cyber, climate, geopolitical and supply chain risks compound?
  • How confident are we that our plans would work in practice?

Risk registers remain useful, but they are not enough on their own.

Modern risks are interconnected, fast-moving and often difficult to predict. A risk register may identify individual threats, but it may not show how those threats combine during a real incident.

Scenario planning and exercising help organisations understand not only what their plans say, but how their people, systems and decision-making structures would actually perform under pressure.

The aim is not to predict every possible event. The aim is to build the capability to respond effectively when disruption occurs.

What Organisations Should Be Thinking About Now

The themes from Risk World, BIBA and the Global Risk Summit suggest several practical questions for organisations:

AI governance: Do we have clear policies, controls and oversight for how AI is being used across the organisation?

Cyber resilience: Are our cyber response arrangements tested, understood and connected to wider crisis management plans?

Climate resilience: Do we understand which sites, assets and operations are most exposed to climate-related disruption?

Data centre and infrastructure exposure: Are we exposed to data centre growth, either directly or through clients, suppliers, utilities, technology dependency or insurance?

Insurance-readiness: Can we demonstrate practical risk controls, tested plans and evidence of resilience to insurers and brokers?

Scenario planning: Have we tested how our leadership team would respond to a complex, fast-moving disruption?

Interconnected risk: Do we understand where cyber, climate, geopolitical, supply chain and financial risks could compound?

These are not theoretical questions. They are practical questions that organisations should be asking now.

Conclusion

Risk World RIMS, BIBA 2026 and the Global Risk Summit each offered a different perspective on the same underlying reality.

Risk is becoming more interconnected. Insurance is becoming more closely linked to resilience. AI is creating both opportunity and exposure. Cyber, climate, supply chains, data centres and geopolitics are converging.

For organisations, the message is clear.

Resilience is not simply about having a plan. It is about having the confidence, capability and structure to respond when disruption occurs.

The organisations that prepare, test and challenge themselves before a crisis will be better placed to protect their people, maintain operations, support customers and recover effectively.

At Horizonscan, we help organisations build practical resilience through business continuity, crisis management, scenario exercises, operational resilience and strategic risk support.

Because in an increasingly uncertain world, the most resilient organisations will not be those that avoid every disruption.

They will be those prepared to respond when disruption inevitably arrives.

Thanks for reading

The Horizonscan Team