Last week, restrictions that had been imposed on Anthropic’s Claude Fable 5 model, because its capabilities were judged to pose genuine cyber security concerns should they be used to expose vulnerabilities, were lifted almost overnight following negotiations with the US government. Whether the decision proves right or wrong, what was notable was how fast it happened. A potentially significant change arrived with little more than a day’s notice.
For those trying to lead organisations through this risk environment, this is all too familiar.
We are living through a period in which important shifts arrive quickly, without warning, and often without a clear precedent to fall back on. Tariff announcements, cyber incidents, geopolitical shocks, regulatory reversals and reputational events are landing faster than they ever have. Some pass quickly, others reshape entire industries, and very few can be neatly forecast.
“We are living through a period in which important shifts arrive quickly, without warning, and often without a clear precedent to fall back on.”
As the world becomes more interconnected by the day, the changes are not only rapid, but they also transcend borders and industries. In 2024, a single faulty CrowdStrike software update crashed 8.5 million systems in a matter of hours, the effects of which included flights grounded, hospitals disrupted, retailers taken offline, and banking operations frozen.
Of course, there has always been uncertainty in business. The difference now is that volatility feels chronic rather than acute, whilst its impact spans multiple business functions.
Last year, in our report Uncertainty 2.0, based on conversations with dozens of CEOs, Chairs and Non-Executive Directors, we described a world in which volatility was no longer episodic but structural, and where the ability to anticipate, absorb and adapt to shocks would increasingly define competitive advantage. The message was consistent: resilience was moving up the corporate agenda, and the organisations most likely to thrive would be those that treated uncertainty as one of the central inputs to strategy and not as an interruption to it.
As such, businesses aren’t just changing the way they’re thinking about risk, but also who they need to lead it.
“Of course, there has always been uncertainty in business. The difference now is that volatility feels chronic rather than acute, whilst its impact spans multiple business functions.”
Through our own search work and conversations in the field, we have seen a significant evolution in risk leadership roles. Historically, senior risk positions were often rooted in governance, compliance and assurance. While those responsibilities remain important, the remit has expanded considerably. Functions that once sat separately – including business continuity, crisis management, investigations, fraud, security, operational resilience and threat intelligence – are now being brought together under integrated leadership structures.
This has led to three practical consequences for risk leaders and the businesses they work within.
First, risk leaders are moving higher within organisations. Boards are more directly involved in resilience discussions than at any point in the last decade, and risk leaders are being expected to help shape strategy rather than simply report on threats. In many businesses, they now sit within a small group of executives to ensure the full risk picture across cyber, supply chain, people, regulatory, financial and reputational domains is fed into strategic decisions.
Second, the role is becoming less about owning expertise and more about orchestrating it. The most effective risk leaders we see today do not attempt to be the deepest technical expert in cyber, in supply chain, in tariffs or in reputation. They act as the connective tissue between the specialists. Their value lies in translating between domains, convening the right combination of people at the right moment, and ensuring that the organisation can respond coherently when multiple risks collide.
Third, the capability set required to do this well is genuinely demanding. Boards are looking for leaders who combine enterprise breadth with an understanding of how disruption in one domain impacts others. They want experienced crisis operators – people who have led through real incidents – as much as they want strategic thinkers. They want technology literacy, particularly around AI, cyber and third-party dependencies, without expecting the risk leader to replicate the Chief Digital or Technology Officer. And, perhaps most importantly, they want the confidence, judgement and communication skills to influence at board level under pressure.
Finding leaders who combine all of that is not straightforward. The pool of individuals who have operated successfully across multiple disciplines, in complex organisations, through genuine crises, is relatively shallow. Increasingly, we are seeing organisations recognise how business-critical the strongest of these leaders have become – and how important it can be to retain them.
Which brings us to the question we think every CEO and Chair should be asking in this new environment:
– Is the person leading risk in your organisation today equipped for the environment you are actually operating in – not the one you were operating in five years ago?
– And if they were to leave tomorrow, do you know who would step into that role, and whether they could do it?
Those are not comfortable questions. But in a world where volatility has become chronic, and where risks are now interacting rather than arriving in isolation, they may be among the most important questions the board can ask this year.


