← Back to NOVRISK.
08 — Risk landscape

The six risks we help you anticipate.

Crises spread from one domain to another. Plans, though, are often built risk by risk. We map what connects them — interdependencies between activities, knock-on effects from one site to another, trade-offs liable to come into tension — then we test that systemic reading through our exercises.

The regulatory framework
How we read them

Three steps, before the decision.

These risks combine. Our work is to bring them back to a scale where an organization can decide.

01

Interdependencies

Each risk is tied to the activities it threatens and to the dependencies that spread it. The resulting map is what makes priorities visible.

02

Basin scale

Living areas, economic areas, risk basins: we work at the scale where the effects actually occur, the one shared by neighbouring sites and organizations.

03

The test of the exercise

The exercise puts that reading to the test. Decisions are made under time pressure, with the people who will make them on the day.

Navigating a changing world

Six risks, and what connects them.

For each one: what it covers, what it changes for an organization, and a dated figure.

01

Geopolitical instability

Armed conflicts, shifting alliances and strategic uncertainty are redrawing the global balance of power. For an organization, that translates into concrete decisions: where to produce, with which suppliers, under which sanctions regime, and with what exposure for teams abroad.

World military spending reached USD 2,887 billion in 2025, an eleventh consecutive year of growth. Europe accounts for USD 864 billion of that, up 14% year on year.

SIPRI, Trends in World Military Expenditure, 2025 — April 2026
Risks & resilience
02

Technological disruption

Cyberattacks on critical infrastructure are growing more sophisticated, and artificial intelligence is changing decision-support tools. The same innovations reshape both the threats and the means of responding to them.

France's national cybersecurity agency handled 3,586 security events in 2025, including 1,366 incidents, and was notified of 128 ransomware compromises. The most targeted sectors were education and research (34%), central and local government (24%) and healthcare (10%).

ANSSI, Panorama de la cybermenace 2025 — 11 March 2026
Business continuity
03

Economic destabilization

Financial crises, supply disruptions and market volatility weaken the resilience of organizations and states. A single supplier failing is enough to break an entire chain.

68,564 corporate insolvencies were recorded in France in 2025, 15.5% above the average of the ten years preceding the health crisis. Over the twelve months to June 2026, the total reached 70,803.

Banque de France, Corporate insolvencies — February and August 2026
Business continuity
04

Emerging societal challenges

Disinformation, social unrest, terrorism and hybrid threats are reshaping how we interact with the world. A documented rumour travels faster than a denial, and reputation is decided in the first few hours.

VIGINUM identified four foreign digital interference operations targeting the French municipal elections of March 2026, including a campaign using more than a hundred “.fr” domain names impersonating news outlets.

SGDSN / VIGINUM — 11 June 2026
Crisis preparedness & management
05

Climate disruption

Natural disasters, resource scarcity and ecological change are forcing a rethink of risk management models.

Natural events cost French insurers EUR 5.2 billion in 2025, EUR 2.2 billion of it from hail alone. Over 2020-2023, actual costs already exceed the trajectory projected to 2050 by 18%.

France Assureurs — March 2026
Risks & resilience
06

Public health challenges

Health crises, pandemics and breaks in the care chain test organizations' continuity and their duty to protect their people.

Adopted on 20 May 2025 by the World Health Assembly, the WHO Pandemic Agreement is still under negotiation on its annex and binds no state as yet.

World Health Organization — May 2026
Exercises & simulations
The framework

What regulation already requires.

Three texts now shape resilience obligations for organizations. We build them into our diagnoses and our exercises.

Directive (EU) 2022/2555

NIS 2

More than 25,000 French entities will be covered, across 17 sectors, against a few hundred under the previous regime. French transposition is still going through parliament: the European Commission referred France to the Court of Justice of the European Union in July 2026 over the delay.

Regulation (EU) 2022/2554

DORA

In force since 17 January 2025 for the financial sector and its IT service providers. It covers ICT risk management, incident reporting, resilience testing and control of third-party dependencies.

International standard

ISO 22301

Security and resilience: business continuity management systems, requirements. The 2019 edition, supplemented in 2024 by an amendment bringing climate change into the scope of the management system.

Status of these texts verified in September 2026.