- Supply chain and AI are of concern in current international trading climate.
- Nation state attacks changing risk managers’ approaches.
- Greater reliance on AI.
Research from Riskonnect’s 2025 New Generation of Risk Report has discovered 62% of security leaders believe cybersecurity threats may increase if the US implements stricter trade policies over the long term. Experts warn that such policies may lead to cyberattacks from foreign governments and federal funding for cybersecurity may be reduced, leaving organisations more vulnerable.
According to the report, other risks associated with a long-term restrictive trade environment include increased domestic labour costs, higher production and indirect costs, and serious interruptions to and shortages in the supply chain.
Riskonnect surveyed more than 200 risk, compliance, and resilience professionals around the world, finding the political risk has risen into the top three corporate threats, up from fifth in 2024.
This comes as no surprise, as nation-state-led attacks are becoming more frequent. In March 2025, the US added 80 companies, including subsidiaries of China’s major cloud computing provider, Inspur Group, to its export blacklist, with an aim to prevent China from acquiring advanced computing technology for military applications.
At the time, Jeffrey Kessler, Under Secretary of Commerce for Industry and Security, said, “The US Department of Commerce’s Bureau of Industry and Security (BIS) is sending a clear, resounding message that the Trump administration will work tirelessly to safeguard our national security by preventing US technologies and goods from being misused for high performance computing, hyper-sonic missiles, military aircraft training, and UAVs that threaten our national security.”
Ongoing tensions may have a significant impact on organisations going forward, with 97% of risk leaders saying political risks are affecting their businesses. 40% categorised the impact as ‘severe.’
The report found that 37% of companies have slowed or stopped hiring employees, 23% have experienced delays to expansion plans, 28% have seen delays to key technology investments, and 27% have re-shored operations or diversified their supply chains due to political instability in their region.
“We’re in a new generation of risk – one where cyber, geopolitical, technology, political risk, and other factors are rapidly converging and reshaping the landscape. The impact on markets and operations is unfolding faster than many organisations can keep up,” said Jim Wetekamp, CEO, Riskonnect.
“Riskonnect’s research shows that while organisations are making progress in some areas, today’s unpredictable business environment demands more than stronger defences. It requires organisations to build resilience as a core strategic capability.”
Businesses are shifting to proactive, tech-driven, and strategic risk management
A key finding from the report shows 85% of those surveyed have a plan for business continuity in case of IT outages or cyber incidents. However, just 8% are capable of assessing the risks of their key partners and their suppliers, highlighting a number of vulnerabilities present in the digital supply chain.
According to the report, two-thirds of companies began 2025 with plans to manage geopolitical risks and volatility, an increase from 19% in 2024, reflecting a shift from reactive to proactive risk management.
Risk leaders are also relying on AI more. In 2024, 62% of companies surveyed said they were using or planned to use AI to help manage risk. In 2025, this has leaped to 70%, with the majority focusing on forecasting, risk assessments, scenario planning, creating risk registers, and identifying new risks.
More companies are now recognising risk management as a key cog in their overall strategies, with 60% of organisations using a chief risk officer (CRO) in the C-suite, ensuring the business is protected in the board.
Worst-case scenarios are a daily consideration for businesses, with 61% of risk leaders saying they have modelled their worst-case scenario, compared to just 44% in 2024 and 37% in 2023.
Gen AI oversight still present
Despite tech-driven risk management strategies on the rise, governance around AI remains very weak. Just 42% of companies have policies in place to manage and control AI use by employees, while 72% admitted to not having a policy in place for the use of generative AI by suppliers and partners.
Three quarters of respondents have no plan for addressing gen AI risks and threats, like AI-powered fraud attacks. Only 15% have budgets set up to mitigate potential risks associated with AI, whereas 23% have policies that are against the use of foreign AI models. While AI adoption increases, this lack of oversight leaves many organisations at severe risk of operational, compliance, and security issues.
On a brighter note, there seems to be a rise in training or briefing companies about AI risks, with 32% formally training staff, up from 19% in 2024 and 17% in 2023 respectively.
Andrea Brody, CMO at Riskonnect, added, “Many organisations aren’t currently built to keep pace with the speed of AI’s evolution. AI demands strong governance. The is a moment for risk professionals to lead the charge on AI oversight and show their value as strategic enablers.”
(Image source: “Wolfsburg – Volkswagen Plant (Postcard)” by roger4336 is licensed under CC BY-SA 2.0.)
Want to experience the full spectrum of enterprise technology innovation? Join TechEx in Amsterdam, California, and London. Covering AI, Big Data, Cyber Security, IoT, Digital Transformation, Intelligent Automation, Edge Computing, and Data Centres, TechEx brings together global leaders to share real-world use cases and in-depth insights. Click here for more information.
TechHQ is powered by TechForge Media. Explore other upcoming enterprise technology events and webinars here.

