Written by
Dr Rebecca HoilePublished on
September 15, 2026

For years, organisations have demonstrated risk preparedness through risk registers, business continuity plans and crisis management plans. These remain important but having them is no longer enough. The risk environment is moving too quickly, becoming too interconnected and changing too unpredictably for organisations to assume that risks will emerge in the way they were documented, or that disruption will follow the scenarios anticipated in a plan.
A risk register is increasingly a snapshot of what we understood at a particular point in time, while a plan provides a foundation for response rather than a script for what happens next. What increasingly determines resilience is an organisation’s ability to recognise change early, understand what matters, adapt its response and continue protecting its critical people, assets, information and operations.
Risk awareness is becoming as important as risk documentation.
The risk environment has changed
Traditional risk management has been built around a relatively stable cycle: identify risks, assess likelihood and consequence, document controls, develop plans and periodically review them. That approach remains necessary, but the environment surrounding it has changed.
Cyber threats, geopolitical conflict, artificial intelligence, supply chain disruption, regulatory change, economic volatility and extreme weather are increasingly interconnected. Events occurring thousands of kilometres from Australia can affect Australian organisations within hours through energy prices, financial markets, shipping routes, suppliers, technology platforms and stakeholder confidence.
Risks can also change character as they develop. A cyber incident can quickly become an operational, privacy, regulatory and reputational issue. A geopolitical event can become a supply chain, financial or workforce issue. A technology outage can become a safety or customer issue.
Modern risks rarely remain within the categories assigned to them.
Operational risk can quickly become strategic risk
One of the consequences of this changing environment is that the traditional boundary between operational and strategic risk is becoming less distinct.
Many of the events capable of materially affecting an organisation's strategy now begin as operational disruptions. A cyber incident may initially affect a system or business process, but prolonged disruption can affect customers, regulatory obligations, revenue and reputation. A supplier failure can interrupt operations before exposing a much larger strategic dependency. An energy or telecommunications outage can quickly challenge an organisation's ability to deliver critical services.
Conversely, strategic developments such as geopolitical conflict, regulatory change, artificial intelligence or economic volatility increasingly translate into immediate operational consequences.
This matters because organisations often manage these risks through different processes, owners and reporting cycles. Strategic risks may receive board-level attention, while operational risks are managed within business functions. In a more connected environment, however, the significance of a risk can change faster than those governance arrangements recognise.
The capability to identify when an operational issue is developing strategic consequences is therefore becoming an important part of risk awareness.
Organisations need visibility across these traditional boundaries so that emerging risks can be recognised, escalated and acted upon before their consequences compound.
A small operational disruption can become a strategic problem surprisingly quickly.
Risk registers are becoming snapshots
Risk registers remain valuable because they establish known exposures, controls, ownership and accountability. But they represent what an organisation understands about its risk environment at a particular point in time.
The environment continues to change between reviews. A vulnerability becomes actively exploited, geopolitical tension becomes supply chain disruption, a weather forecast becomes a continuity issue, or a supplier failure exposes previously unrecognised dependencies.
This means organisations need to complement periodic risk assessments with more continuous risk awareness. Threat intelligence, horizon scanning, cyber monitoring, supplier intelligence, regulatory developments and frontline reporting can provide early indications that exposure is changing.
Individually, these signals may appear insignificant. Together, they may indicate that the organisation needs to prepare, escalate or act.
Early awareness creates options. Late awareness removes them.
Having a plan is not the same as being prepared
The same principle applies to crisis management and business continuity. A detailed plan cannot anticipate every scenario, particularly when the next disruption may involve several interconnected events or circumstances the organisation has never experienced.
Plans may also rely on assumptions about technology, suppliers, people, communications and dependencies that do not hold when they are needed.
The value of a good plan is therefore not its ability to prescribe every action. Its value is in establishing the foundations for an effective response: clear responsibilities, escalation pathways, decision-making authority, critical priorities and an agreed structure for managing disruption.
From that foundation, organisations need the capability and confidence to adapt as circumstances change.
Resilience is demonstrated through adaptation, not adherence to a script.
Flexibility is becoming a core risk capability
Resilience is rarely tested when everything happens according to plan. It is tested when assumptions fail: a critical supplier becomes unavailable, communications are disrupted, key personnel cannot be reached, information is incomplete, recovery takes longer than expected or several risks materialise at the same time.
Organisations that understand their critical assets and dependencies, maintain awareness of their changing environment and empower people to make decisions are better positioned to adapt when this occurs.
This does not mean less governance. It means governance that is designed to operate under uncertainty and allows an organisation to change direction when the situation requires it.
Exercising for uncertainty
This changing risk environment also requires a different approach to exercising. The purpose should not simply be to test whether people can follow a crisis or business continuity plan, but to develop the skills and confidence of the people expected to use it.
A good plan provides the framework. It establishes roles, responsibilities, escalation pathways, priorities and decision-making structures. Importantly, it also identifies the capabilities that need to exist across the response team. It should guide people through a disruption, rather than attempt to prescribe every action they will need to take.
Exercises turn that framework into organisational capability. Each time teams practise situational assessment, communication, coordination, prioritisation, escalation and decision-making under uncertainty, those skills become more familiar and more readily applied.
The more the capabilities within the plan are exercised, the more confident and capable the team behind the plan becomes.
Over time, this builds teams that are less dependent on the document itself. They understand its intent, know what needs to be protected and are more comfortable adapting their response when information is incomplete, assumptions fail or circumstances change.
This is ultimately where exercising strengthens resilience. The plan provides the structure, but repeated practice develops the people and capability needed to respond when the disruption does not follow the plan.
From risk management to risk readiness
At Sention, we see the changing risk environment requiring a shift from documenting risk towards maintaining readiness. Risk registers and plans remain important foundations, but their value depends on an organisation’s ability to recognise changing exposure and translate that awareness into action.
Risk readiness means understanding how operational, cyber, geopolitical, financial and supply chain risks interact, recognising when assumptions or dependencies are changing, and having people capable of adapting the response. It is less about anticipating every scenario and more about being prepared for conditions to develop differently from those expected.
Resilience is ultimately demonstrated through this capability - the ability to remain aware, make informed decisions and adapt while continuing to protect critical people, assets and operations.
The objective is not to predict every disruption, but to be ready when risk does not follow the plan.