On Christmas Day 2024, the tanker Eagle S – suspected of belonging to Russia’s sanctions-evading shadow fleet – dragged its anchor nearly 90 kilometres across the Baltic seabed and severed the Estlink 2 power interconnector between Finland and Estonia. The cable stayed offline for more than seven months, cost up to €60 million to repair, and a Finnish court later dismissed the case against the crew entirely. No boardroom risk register had a line item for “sanctioned tanker severs our power interconnector.”
That is exactly the point: macro and geopolitical risk does not wait for the register to catch up before it reaches the operating model.
The 30-second take
The lesson from Estlink 2, and from the wider 2026 risk landscape, is not that geopolitical risk belongs on a heatmap. It is whether an organisation can trace a macro signal – a shipping lane, a trade restriction, a third-party outage – into planning, pricing, supplier decisions, stress testing and board appetite before it becomes a customer, capital or service failure.
Maturity is proved by the decision trail, not the framework.
Insurers are already pricing this. Are you?
Allianz’s 2026 Risk Barometer – based on responses from over 3,700 risk experts in 106 countries – found cyber incidents topped the global risk ranking for the fifth year running, with AI the fastest-rising peril at #2 and business interruption, including supply chain disruption, at #3.
Trade restrictions have tripled in the past year to affect an estimated US$2.7 trillion of merchandise, roughly 20% of global imports, yet just 3% of respondents describe their supply chains as “very resilient.” Respondents named global supply chain paralysis from a geopolitical conflict involving multiple major economies as the most plausible “black swan” scenario facing their business in the next five years.
That is not an abstract heatmap entry – it is what underwriters are already pricing into your renewal.
When the cable actually gets cut
Estlink 2 shows what happens when the scenario stops being hypothetical. A single vessel, allegedly linked to a sanctioned network, created a seven-month operational and financial hit to two countries’ energy systems – not through a cyberattack or a software bug, but through a physical, geopolitically-motivated act nobody had modelled as “our” risk.
The subsequent court dismissal is its own lesson: even once the facts are established, legal accountability for macro-driven disruption is far from guaranteed. Organisations that treat resilience purely as a compliance artefact, rather than a live decision-making capability, will find the same gap between “we knew about the risk” and “we could show what we did about it.“
Regulators are moving from frameworks to evidence
The direction of travel among prudential regulators reinforces this. The Bank of England’s Prudential Regulation Authority published its March 2026 policy statement on operational incident and third-party reporting, building on operational resilience rules that became fully binding on UK firms in March 2025.
The focus has shifted from “do you have a policy” to “can you report the incident accurately, on time, and show your important business services stayed within impact tolerance.”
A framework on the intranet no longer satisfies that bar – only evidence of a working decision trail does.
Ask your organisation
- If a supplier, cable, port or data centre tied to a geopolitically exposed region failed tomorrow, could we name the business decision it would force within 24 hours?
- Who owns the translation of a macro signal – a sanctions list update, a shipping disruption, a trade restriction – into a pricing, appetite, or supplier decision?
- Could we produce evidence, not just a policy document, that a past macro or geopolitical signal actually changed a business decision?
- Where do we sit against Allianz’s finding that only 3% of organisations see their supply chains as “very resilient” – and what would move us into that 3%?
- If a regulator asked us to report an operational incident within hours rather than weeks, could our current processes meet that bar?
- When did our board last stress-test appetite against a named geopolitical scenario, rather than a generic “cyber incident” heatmap entry?
Where to start
Macro risk is not a new category to add to the register. It is a test of whether your existing risk management actually changes decisions when the world outside your walls shifts.
Try our practical board readiness snapshot to pressure-test whether your organisation’s decision trail would hold up under the same scrutiny as Estlink 2’s.

