About the Author

Lee Childs
Lee Childs is the Center of Excellence lead for Risk & Compliance at Wrangu and is a certified ServiceNow IRM specialist.
He leverages over 25 years of experience in the IT industry, with extensive knowledge ranging from architectural roles to Pre Sales management, to guide clients on their Governance, Risk, and Compliance (GRC) journey. His role involves helping organisations understand and solve their business challenges using ServiceNow solutions.
“It is not the strongest of the species that survives, nor the most intelligent, but the one most responsive to change.” – Charles Darwin
The New Reality of Risk
The world today is increasingly volatile, unpredictable, and unstable. The assumption that conditions will remain steady from one year to the next no longer holds true. In recent years, we have witnessed the global disruption caused by COVID-19, the ongoing war in Ukraine, the conflict in Israel and Gaza, and rising tensions among major global powers. These are not isolated events; they are signals of a broader pattern of instability reshaping the global landscape.
Each of these crises has had a profound impact on economies, supply chains, and business operations. Goods and services once taken for granted can quickly become scarce, while essential commodities fluctuate in both price and availability. This shifting environment is forcing organisations to fundamentally rethink how they operate and how they prepare for disruption.
Building Resilience in a Volatile World
In this context, operational resilience and third-party risk management are critical to survival. Businesses must understand not only their direct suppliers, but also the extended supply chains beneath them. Mapping dependencies, identifying concentrations of risk, and establishing viable alternatives are now key sources of competitive advantage.
Traditional assurance mechanisms, such as SOC 2 reports, remain valuable, but they are not sufficient on their own. They offer a point-in-time view of controls, not a measure of resilience under real-world stress. What is required is continuous monitoring of third-party risk, supported by strong controls and a defence-in-depth approach.
Resilience planning must also evolve. Static business continuity plans are no longer enough. Organisations need dynamic, scenario-based testing that reflects real-world crises plans that have effectively been “tested in anger” across multiple scenarios to ensure they can withstand disruption when it matters most.
The Power and Limitations of Frameworks
Regulatory frameworks such as the EU’s NIS2 Directive mark this shift. Critical sectors including energy, infrastructure, and utilities are now required to demonstrate integrated risk management, robust governance, incident reporting capabilities, digital resilience testing, and effective oversight of third-party risk. They are also expected to collaborate, sharing intelligence on emerging cyber threats.
However, NIS2 should not be viewed as relevant only to critical industries. It represents a set of best practices forged from hard-learned lessons in an increasingly hostile environment. From state-sponsored cyberattacks to disruptions in energy supply and targeted attacks on infrastructure, these risks are becoming more frequent, more coordinated, and more sophisticated.
No framework can eliminate risk entirely. But by adopting these principles, organisations can equip themselves with the tools needed to navigate uncertainty. Those that invest in resilience, visibility, and adaptability will be far better positioned not only to survive, but to thrive in the face of future disruption.
The challenge now is simple, but uncomfortable: if a critical supplier failed tomorrow, if a key region became inaccessible, or if a cyberattack disrupted your operations would your organisation continue to function, or would it pause, scramble, and react? The difference between those outcomes will not be luck. It will be preparation. The organisations that ask and answer these questions today are the ones that will define tomorrow.
“Risk management is how you prepare for the unexpected, not how you safeguard against it.” – David Einhorn