When Macro Risk Reaches the Operating Model

On Christmas Day 2024, the tanker Eagle S – suspected of belonging to Russia’s sanctions-evading shadow fleet – dragged its anchor nearly 90 kilometres across the Baltic seabed and severed the Estlink 2 power interconnector between Finland and Estonia. The cable stayed offline for more than seven months, cost up to €60 million to repair, and a Finnish court later dismissed the case against the crew entirely. No boardroom risk register had a line item for “sanctioned tanker severs our power interconnector.

That is exactly the point: macro and geopolitical risk does not wait for the register to catch up before it reaches the operating model.


The 30-second take

The lesson from Estlink 2, and from the wider 2026 risk landscape, is not that geopolitical risk belongs on a heatmap. It is whether an organisation can trace a macro signal – a shipping lane, a trade restriction, a third-party outage – into planning, pricing, supplier decisions, stress testing and board appetite before it becomes a customer, capital or service failure.

Maturity is proved by the decision trail, not the framework.


Insurers are already pricing this. Are you?

Allianz’s 2026 Risk Barometer – based on responses from over 3,700 risk experts in 106 countries – found cyber incidents topped the global risk ranking for the fifth year running, with AI the fastest-rising peril at #2 and business interruption, including supply chain disruption, at #3.

Trade restrictions have tripled in the past year to affect an estimated US$2.7 trillion of merchandise, roughly 20% of global imports, yet just 3% of respondents describe their supply chains as “very resilient.” Respondents named global supply chain paralysis from a geopolitical conflict involving multiple major economies as the most plausible “black swan” scenario facing their business in the next five years.

That is not an abstract heatmap entry – it is what underwriters are already pricing into your renewal.

When the cable actually gets cut

Estlink 2 shows what happens when the scenario stops being hypothetical. A single vessel, allegedly linked to a sanctioned network, created a seven-month operational and financial hit to two countries’ energy systems – not through a cyberattack or a software bug, but through a physical, geopolitically-motivated act nobody had modelled as “our” risk.

The subsequent court dismissal is its own lesson: even once the facts are established, legal accountability for macro-driven disruption is far from guaranteed. Organisations that treat resilience purely as a compliance artefact, rather than a live decision-making capability, will find the same gap between “we knew about the risk” and “we could show what we did about it.

Regulators are moving from frameworks to evidence

The direction of travel among prudential regulators reinforces this. The Bank of England’s Prudential Regulation Authority published its March 2026 policy statement on operational incident and third-party reporting, building on operational resilience rules that became fully binding on UK firms in March 2025.

The focus has shifted from “do you have a policy” to “can you report the incident accurately, on time, and show your important business services stayed within impact tolerance.

A framework on the intranet no longer satisfies that bar – only evidence of a working decision trail does.

Ask your organisation

  • If a supplier, cable, port or data centre tied to a geopolitically exposed region failed tomorrow, could we name the business decision it would force within 24 hours?
  • Who owns the translation of a macro signal – a sanctions list update, a shipping disruption, a trade restriction – into a pricing, appetite, or supplier decision?
  • Could we produce evidence, not just a policy document, that a past macro or geopolitical signal actually changed a business decision?
  • Where do we sit against Allianz’s finding that only 3% of organisations see their supply chains as “very resilient” – and what would move us into that 3%?
  • If a regulator asked us to report an operational incident within hours rather than weeks, could our current processes meet that bar?
  • When did our board last stress-test appetite against a named geopolitical scenario, rather than a generic “cyber incident” heatmap entry?

Where to start

Macro risk is not a new category to add to the register. It is a test of whether your existing risk management actually changes decisions when the world outside your walls shifts.

Try our practical board readiness snapshot to pressure-test whether your organisation’s decision trail would hold up under the same scrutiny as Estlink 2’s.


More from the Reading Room

AI Agent Security: What the RubyGems and Hugging Face Incidents Reveal

Researchers allege OpenAI agents uploaded hundreds of malicious packages to RubyGems in May 2026, before a later intrusion involving Hugging Face. The incidents show why AI agent security requires stronger containment, monitoring and accountable governance.

When Fraud Syndicates Exploit Loan Processes: What Australia’s $600 Million Scam Reveals About Control Failures

NSW police allege a criminal syndicate defrauded banks of up to $600 million using false loan applications and insider help from accountants and money mules. This case uncovers how multi-party collusion exploits gaps in loan processes, demanding tighter fraud controls and cross-agency scrutiny.

APRA and ASIC put frontier AI, cyber and resilience on the board agenda

APRA and ASIC’s September 2026 superannuation roundtable summary shows why AI, cyber and supplier disruption should be tested as one compound event. Businesses need rehearsed authority to contain harm, operate through disruption and approve recovery.

APRA’s ING action is a blunt reminder: liquidity breaches are not just an internal issue

APRA’s 3 September 2026 action against ING Australia showed how a reported liquidity ratio near 160 per cent could conceal a materially lower position. Every business should govern critical metrics as controlled products with reproducible calculations, named ownership and escalation for uncertainty.