Geography Isn’t a Firewall: What Regional Instability Means for Your Risk Register

A hospital trust in the north of England doesn’t source anything from the Middle East. No suppliers there, no staff posted there, no donors or partners in the region. On paper, a conflict happening a few thousand miles away has nothing to do with them.

Then a shipment of surgical consumables that was due in three weeks is suddenly due in ten, because the freight company rerouted around a stretch of water it no longer considers safe. The manufacturer is in Germany. The factory that makes a component for that manufacturer is in South Korea. The ship carrying it was never going anywhere near the conflict itself, until the conflict changed which routes were viable and every vessel on that route got slower and more expensive overnight.

Nobody at the trust decided to take on Middle East exposure. It arrived through a supply chain built for a world where that route was reliable, which it had been for so long that almost nobody thought to write down what would happen if it stopped being reliable.

This is the pattern worth paying attention to, and it is a pattern rather than a one-off. Every few years something in or near the region disrupts shipping, spikes energy prices, or triggers a wave of opportunistic cyber activity, and each time a lot of organisations discover exposure they didn’t know they had. The 2021 blockage of the Suez Canal, caused by a single grounded container ship rather than anything geopolitical, held up an estimated ten percent of global trade for six days and cost an estimated ten billion dollars a day in delayed goods. That was a shipping accident with no political dimension at all, and it still offered a preview of what happens when a channel a few hundred metres wide sits underneath a meaningful share of world trade. When the same chokepoint becomes contested rather than simply blocked, the disruption tends to last longer, spread further, and matter a great deal more.

None of this means every organisation needs to become a geopolitics shop. Most of the people running risk registers, sitting on boards, or chairing audit committees have no reason to have a view on the region’s politics, and shouldn’t need one to govern well. The organisations that get through these periods without a scramble aren’t the ones with the sharpest geopolitical analysts. They are the ones whose governance was built to notice disruption early, regardless of where it started, and to ask the right questions before disruption turns into crisis.

Why this keeps catching organisations off guard

It is worth pausing on why this particular category of risk is so consistently underestimated, because the reasons are more organisational than they are about the region itself.

The first reason is distance, which feels like protection even when it isn’t. A risk that originates somewhere an organisation has no physical presence reads, instinctively, as somebody else’s problem. Boards are generally good at scrutinising the risks sitting directly in front of them: financial controls, safeguarding, data protection, regulatory compliance. They are far less consistent about risks that arrive secondhand, through a supplier’s supplier or a funder’s own funding source, because those risks don’t have a natural owner inside the organisation. Nobody’s job description says “monitor Red Sea shipping insurance premiums,” so nobody does, until the delay is already sitting in a warehouse somewhere.

The second reason is recency bias. If the last three years passed without a serious disruption from this direction, it is easy, quietly, to start treating that as evidence the exposure doesn’t really exist, rather than evidence that it simply hasn’t been tested recently. Risk registers tend to reflect what has already gone wrong far more readily than what hasn’t gone wrong yet. That is a reasonable way to prioritise finite attention, but it leaves genuine gaps in categories that happen to be dormant at the time the register was last reviewed.

The third reason is that this risk rarely turns up as a single dramatic event. It shows up as a two-week delay here, a slightly higher invoice there, a donor going quiet for a month, a slightly odd phishing attempt that gets reported and forgotten. Individually, none of those looks like a geopolitical risk materialising. Collectively, over a period of sustained regional tension, they very often are. Governance structures that are built to catch single large incidents can be surprisingly poor at noticing a pattern made up of small, deniable-looking events, unless someone is deliberately looking for the pattern.

Where the exposure actually sits

Supply chains carry it first, and usually most quietly. Freight does not need to originate in an affected region to be affected by what is happening there. A shipping route that runs near a conflict zone attracts rising insurance premiums, carriers that reroute around it, and lead times that stretch, and none of that shows up as a single alarming number on anyone’s dashboard. It shows up as a delivery that arrives a little later than usual, then a little later again, until someone finally asks why. Organisations that depend on specific consumables, components, or equipment with long or fragile supply chains are the most exposed, and clinical and safety-critical supply chains sit near the top of that list. If a business continuity plan assumes shipping timelines that were accurate two or three years ago, it is worth confirming whether they are still accurate now, well before a delay lands on something that genuinely cannot wait.

Funding relationships move on a different clock than day-to-day operations do. Charities and NGOs with international donors, grant funders, or delivery partners operating in or near an affected region often feel the effect first as a delay rather than an outright loss. A grant due for renewal gets quietly deferred while a funder reassesses its own regional commitments. A partner organisation goes quiet for a few weeks because its own operations are consumed by something more immediate and closer to home for them. None of this necessarily means the money disappears permanently, but a board that has never mapped what proportion of its funding carries this kind of exposure tends to find out about the problem later than it should, usually once a gap has already opened in the budget rather than while there was still time to plan around it.

Cyber activity rises in ways that rarely stay confined to one side of a conflict. State-linked and opportunistic threat actors both tend to get busier during periods of heightened regional tension, and healthcare, local government, and infrastructure targets get caught up in that activity even when they have no connection whatsoever to the conflict driving it. Attackers use periods of distraction and stretched resources opportunistically, and an organisation dealing with a genuinely unrelated crisis elsewhere in its operations is, unhelpfully, also a slightly softer target during that same window. This is one of the more measurable effects of regional instability and also one of the easier ones to prepare for in advance. An incident response plan that has not been tested recently is a known gap rather than a mysterious one, and a period of heightened regional tension is as reasonable a prompt as any to finally close it.

Vendor and third-party risk is where most organisations have the least visibility of all. A vendor risk register that scores suppliers on financial stability, data handling, and delivery history is doing genuinely useful work, but it is usually missing a column for geographic and geopolitical exposure, largely because until recently that exposure felt theoretical enough to leave out. It stops feeling theoretical the moment a critical supplier turns out to be two or three steps removed from a disrupted region, and the organisation learns about it from a missed delivery rather than from its own risk assessment having flagged it months earlier.

Staff wellbeing and duty of care sit alongside all of the above, and tend to get less structured attention than they deserve. Any organisation with employees who travel to the region for work, have family there, or are otherwise personally affected has a duty-of-care question worth answering deliberately rather than assuming away. That does not always mean specific action is required. Sometimes the honest, considered answer is that no additional measures are needed right now. But that should be a conclusion someone actually reached and documented, not a gap nobody got around to closing because it felt awkward to raise.

What this actually asks of governance

The right response to all of this is not a crisis plan written in a hurry. It is the same discipline that good governance already claims to have everywhere else, applied to a category of risk that has historically been easy to leave off the list simply because it felt distant.

A risk register earns its keep when geopolitical exposure has its own line and its own named owner, rather than being folded into a broad “external factors” category that nobody in particular is accountable for. A business continuity plan is only as good as the scenarios it has actually been tested against, and a supply chain shock originating from regional instability is a scenario worth adding deliberately if it is not already there in a meaningful form. Third-party risk assessments become considerably more useful the moment geographic and geopolitical exposure becomes a scored factor in its own right, rather than an afterthought raised only once something has already gone wrong. And a board that gives volatile periods a standing few minutes on its regular agenda, rather than waiting for a crisis to justify an emergency briefing, tends to catch problems while they are still small enough to manage calmly, with options still available, instead of large enough to force a reactive scramble.

None of this requires predicting how a conflict on the other side of the world will unfold, and it should not require anyone on a board or leadership team to develop views on the politics of the region in order to govern their own organisation well. It requires a governance framework built to notice second-order effects quickly, wherever they originate, applied with the same seriousness given to the risks that already sit close to home. Most organisations already have that discipline for financial risk, for safeguarding, for data protection. The gap is rarely a lack of capability. It is usually just a category that never quite made it onto the register, because for a long stretch of relatively calm years, it never needed to.

That is really the only prediction this piece is making: not about the region, and not about how long any particular period of tension will last, but about the reliability of the pattern itself. Periods like this recur. Organisations that treat that recurrence as a governance question, rather than a news story to watch from a distance, are consistently the ones who come through the other side having lost the least time, the least money, and the least sleep.

If it has been a while since your risk register, business continuity plan, or vendor assessments were tested against a scenario like this one, that is usually the first sign it is worth doing, not a reason to assume everything is already covered. We help organisations run that kind of review properly, without turning it into a bigger exercise than it needs to be. If you would like a second opinion on where your own exposure actually sits, we are glad to talk it through.