Risk Everywhere: how are CEOs and CFOs adapting to the new global risk landscape?
Risk Everywhere: how are CEOs and CFOs adapting to the new global risk landscape?
While they acknowledge the ever-increasing scale and severity of the global risk landscape, business leaders around the world are struggling to create a comprehensive risk management strategy.
In our eleventh global risk landscape annual report we highlight not only how risk is becoming more diversified in a world impacted by everything from geopolitics to artificial intelligence, but how and why business CEOs and CFOs find themselves struggling to cope. We conclude that risk management can no longer be siloed with specialist teams – it must become the domain of every division in the business if leadership hopes to achieve the agility necessary to meet the challenge head-on. This necessitates a step change in business governance, ensuring risk management is built into the core business strategy, rather than left to the last minute.
“The strategic cost of slow action, or even inaction, is no longer just missed business opportunities: organisations’ survival is potentially on the line if they are unable to make timely and proactive risk decisions. Risk aversion, in other words, becomes a risk in itself.
To navigate this unstable new world, businesses must move away from traditional risk management silos and instead embrace a future where risk ownership is shared via a holistic approach. This ensures organisations can get a more joined-up view of what is happening in the risk landscape and how multiple threats interact with different parts of the business, enabling smarter, more coordinated decision-making.”
Alisa Voznaya, Partner and Head of Risk Consulting, BDO UK
The new global risk landscape
As the sources of risk become more diversified and fragmented, traditional risk management models are fast becoming ineffectual. Our report finds that 68% of business leaders agree that the speed at which crises are impacting their organisations is accelerating, up from 54% one year ago.
Still, many of these same CEOs and CFOs admit to feeling paralysed when it comes to identifying risk sources and implementing strategies. 52% told us they struggle to identify the risk signals that truly matter to their organisations. As a result, many organisations are becoming less proactive in their approach to risk – only 9% of business leaders say they are being “very proactive” in 2026, down from 29% in 2023.
While we’ve focused on four key areas of the global risk landscape in 2026 – geopolitics, cyber, fraud and AI – it is the interconnection between these elements that is driving the scale of the threat.
As 83% of CEOs and CFOs tell us they see risks becoming more interconnected and complex, we attempt to discover the common threads between the major risk sources and approach risk holistically. Moving forward, risk management needs to walk the delicate line between crisis and opportunity: the behaviour shift of treating risk not as an existential threat but as a commercial enabler that can be turned into competitive advantage will be vital to helping organisations tackle risk without compromising objectives.
Geopolitics: The risk shaping all others
Encompassing and influencing all other forms of risk, political volatility has gone from an unusual occurrence to an everyday fact of life. We have seen instability in macroeconomic forms such as a global pandemic, conflict and terrorism, but also at the national level: the constant shifting of national leaders bringing about ever-changing policies around financial regulations and tax reforms; the breakdown of international relations leading to increased tariffs, trade embargoes, and restricted flows of talent; cybercrime opening up a new frontier of international warfare and corporate sabotage.
Consequently, businesses find themselves in a situation few would have predicted ten years ago. With supply chains fragmented, regulations becoming increasingly less globalised and no clear consensus on the direction of global travel, leaders find themselves not only managing uncertainty in the short term but planning for it in the long term.
Our report finds worrying discrepancies between the areas of major focus for CEOs, tech leaders and CFOs, highlighting the need for businesses to take a more joined-up approach to planning for and managing large-scale risk, both today and in the future.
“Organisations make better decisions when they stop treating this as a coordination problem and start treating it as a decision model issue. Risk, operations, technology and finance need to come together early, with clear decision rights, common scenarios and an agreed view of the trade-offs involved.”
Ziad Akkaoui, Partner and National Risk Advisory Practice Leader at BDO Canada
Cyber: The number one risk without a clear plan
While businesses are spending more than ever on cybersecurity, hackers are already several steps ahead. Recent high-profile attacks have revealed not only the increasingly advanced tactics behind cybercrime, but the debilitating impacts they can have, even on multi-billion-pound businesses.
Cyber resilience is no longer something organisations can afford to ‘tack on’ at a late stage – it must be hard-wired directly into the strategic vision of every organisation. Cybersecurity can only keep up the pace with cybercrime if it is free to imagine where it needs to be years down the line.
Our report finds some confusion at ground level in the fight against cybercrime. While CEOs and tech leaders are aligned on the present state of affairs, with 35% on both sides agreeing cyber is a top risk today, only 29% of CEOs think it will remain a top risk in five years compared to 41% of tech leaders.
Perhaps this discrepancy is causing indecision: just 52% of business leaders aim to invest in cybersecurity training over the next two years, down from 59% in 2025. Furthermore, as 23% of CEOs confess that their business is underspending on cybersecurity, we are left to wonder: is it finally time for business leaders to give cybersecurity a seat at the table?
“The challenge is that businesses don't always understand the value of having cyber at the outset, or why it should be a strategic enabler rather than a last-minute add-on before go-live. Because if you go live without having built security in, threat actors have the entire product lifecycle to find a way in.”
Rocco Galletto, Partner and Global Cybersecurity Leader at BDO Canada
Fraud: The misunderstood risk under a technology illusion
The advent of AI has given fraudsters incredibly sophisticated tools with the potential to deceive even the most cautious executives. Around the world, newspaper headlines are littered with stories of AI scammers deploying sophisticated tactics, such as ‘deepfaking’ CEOs to lure employees into fraudulent transactions.
The new age of fraud is only just beginning, yet it would appear many business leaders are overlooking the very real potential of this threat: our report finds 93% don’t rank fraud as a top threat, while only 13% say they are actively monitoring and updating their defences specifically for AI-enabled fraud.
It seems as though some business leaders have wrapped fraud under separate categories, such as cyber or AI. This may suggest a widespread belief that fraud refers exclusively to traditional models – or, more worryingly, it could mean many business leaders simply underestimate the scale of the threat. “When you carve out AI, cyber and things like digital asset-related fraud, what you are left with is the more mundane generic-type frauds that are really more like yesterday’s frauds,” says Glenn Pomerantz, Principal & Forensic Leader at BDO USA and Global Forensic Leader. “But while everyone is focused on AI governance, businesses are lagging. The criminals will be moving faster, so you’re going to constantly have to revise and enhance your fraud defences.”
“Our data shows AI fraud mitigation tools will be more commonly used in two years rather than now, likely due to the budget required and the need for proper staff training. These solutions also need to be customised for your business rather than taken off the shelf.”
Glenn Pomerantz, Principal & Forensic Leader at BDO USA and Global Forensic Leader
AI: From hype to practical application, with uneven control
Even in 2026, the conversation around AI remains polarised. On the one side are the sceptics who see AI as a fundamental risk; on the other side are the recklessly ambitious who rush into AI without a clear governance strategy. Somewhere in the middle are those whose appetite is balanced: willing to shoulder the risk without rushing in. Thankfully, this middle territory is becoming more populated. Our report finds that 66% of business leaders see AI as an opportunity (up from 57% in 2025) while only 24% see it as a threat (down from 30% in 2025).
Continuing this sustainable growth in optimism will be down to an organisation’s risk culture. “Organisations need to build a shared understanding of how to manage AI risk at scale,” says Karen Schuler, Principal & Cyber Market Leader at BDO USA and Global Privacy, Data & AI Leader. “Not everybody has to be a data scientist, but it does require a baseline level of AI literacy across leadership teams so they can push that understanding down to their teams.”
Getting to this stage, Karen argues, will mean broadening ownership of AI away from being the exclusive domain of tech teams, into one that crosses through the entire business.
“From my perspective, since AI cuts across functions, it is essentially a stress test for organisational capability, revealing whether governance and controls are truly embedded and consistently applied.”
Karen Schuler, Principal & Cyber Market Leader at BDO USA and Global Privacy, Data & AI Leader
Act, don’t react
Ultimately, our report argues that – as the scale and severity of risk increases – it is no longer a viable strategy to wait and hope for security to return.
The future of effective risk management is in decisive action. Business leaders must act now to identify risk sources and develop robust strategies to counteract them. In many cases, this will require an extensive reshaping of organisations, with updates to policies and governance, in the pursuit of new levels of agility.
The reward for this hard work will be that businesses will find themselves able to not only weather the storm but sail straight through it: discovering competitive advantages as their appetite for risk becomes stronger.
Download the report to read more
Download the report: Risk Everywhere: Extending ownership beyond the risk function