October 1, 2026 · Professional Development, Research · 7 min read
A useful continuity statistics page should not pretend that one percentage predicts whether a company will survive a crisis. The strongest current evidence instead shows which disruptions risk professionals are most concerned about, how those risks interact and where organisations perceive their resilience to be weak.

Source: Allianz Risk Barometer 2026
Cyber incidents ranked first globally in the Allianz Risk Barometer for the fifth consecutive year, selected by 42% of respondents. Allianz reports that cyber was also the top-ranked concern across company sizes and across every major region covered by the survey, including Africa and the Middle East.
Source: Allianz Commercial, Cyber incidents, 2026
Business interruption, including supply-chain disruption, ranked third globally in 2026 and was selected by 29% of respondents. Allianz notes that business interruption had ranked either first or second in every edition of the Risk Barometer for the previous 15 years before moving to third in 2026.
Source: Allianz Commercial, Business interruption, 2026
42%
32%
29%
26%
21%
Percentages are respondent selections, not mutually exclusive shares and not event probabilities.
In a separate Allianz Risk Barometer question on supply-chain resilience, only 3% of 970 respondents described their supply chains as “very resilient” to disruptions caused by geopolitical conflict, changing trade patterns or critical-infrastructure failures.
That figure should be interpreted narrowly. It does not mean 97% of global supply chains will fail. It shows that very few respondents were willing to place their supply chains in the highest resilience category against the specified disruption types.
A critical input may have several named suppliers but still depend on one country, port, cloud platform or upstream manufacturer.
An organisation may restore its own operations before a critical vendor, logistics route or infrastructure provider recovers.
Third-party technology can create business interruption even when the organisation’s own network remains available.
Trade restrictions, conflict, sanctions and transport disruption can affect availability without damaging any company-owned asset.
AI was selected by 32% of Allianz respondents and rose from tenth place in the previous year’s ranking to second in 2026. The report groups concerns including implementation problems, liability and misinformation/disinformation.
The continuity angle is operational dependency. As organisations embed AI into core workflows, they need to know which services can continue if a model, provider, integration or data pipeline is unavailable or unreliable.
Changes in legislation and regulation ranked fourth globally at 26%. A regulatory event may not look like a traditional crisis, but new tariffs, sanctions, data restrictions, safety requirements or operating rules can make a previously viable process impossible or non-compliant.
Natural catastrophes ranked fifth globally, selected by 21% of respondents. Allianz reported that insured natural-catastrophe losses for 2025 were expected to reach approximately US$107 billion, citing Swiss Re, with economic losses above US$200 billion.
Source: Allianz Commercial, Natural catastrophes, 2026
Those are global loss estimates, not a forecast of what one organisation will lose. For continuity planning, the practical question is which facilities, infrastructure, people, transport routes and suppliers are exposed to weather and catastrophe risk, and whether the recovery strategy is independent of the same hazard.
The World Economic Forum’s Global Risks Report 2026 found geoeconomic confrontation was the most frequently selected top risk for 2026 in its Global Risks Perception Survey, chosen by 18% of respondents, followed by state-based armed conflict at 14%.
Source: World Economic Forum, Global Risks Report 2026
These are global risk-perception results, not business-interruption rates. They matter because geopolitical disruption can transmit into operations through trade restrictions, energy, logistics, currencies, suppliers, cyber activity and workforce mobility.
| Evidence | Planning question | Useful exercise |
|---|---|---|
| Cyber: 42% | Can critical services operate if core systems or shared files are unavailable? | Ransomware plus communications outage |
| AI: 32% | Which critical decisions or workflows now depend on an AI model or vendor? | AI service failure or unsafe output scenario |
| Business interruption: 29% | Which dependencies would stop delivery even if the organisation itself remains intact? | Multi-supplier and logistics disruption |
| Regulatory change: 26% | What if a market, supplier or operating process becomes restricted? | Sudden sanctions, tariff or compliance change |
| Natural catastrophes: 21% | Are primary and backup facilities exposed to the same hazard? | Regional flood, storm, heat or infrastructure outage |
IT disaster recovery is important, but Ready.gov explicitly positions technology recovery alongside business continuity rather than as a substitute for it. Recovery strategies need to cover people, facilities, suppliers, communications and decision-making as well as systems and data.
As of 2026, ISO 22301:2019 remains the published international standard for business continuity management systems, with its 2024 climate-action amendment. ISO is developing a third edition, but the committee draft is not yet the published replacement. Organisations should therefore distinguish the current standard from the revision work underway.
A risk survey becomes operationally useful when it changes what the organisation rehearses. The Allianz results point to combinations rather than isolated events: a cyber incident that interrupts operations, an AI dependency that fails during a customer-service surge, a regulatory change that removes a supplier, or a natural catastrophe that also affects transport and telecommunications.
| 2026 risk signal | Useful continuity scenario | Capability to test |
|---|---|---|
| Cyber incidents | Ransomware removes access to core systems and shared files | Manual operations, data restoration, decision authority, communications |
| AI risk | Critical AI service becomes unavailable or produces unsafe output | Human override, manual fallback, vendor dependency, quality controls |
| Business interruption | Major supplier and transport route fail together | Alternate sourcing, inventory priorities, customer commitments |
| Regulatory change | New rule immediately restricts a product, country or data transfer | Legal escalation, alternate process, customer communication |
| Natural catastrophe | Regional event affects office, staff transport, utilities and backup site | Geographic redundancy and remote operating capability |
External risk rankings tell you what other organisations are worried about. They do not tell you whether your own organisation can recover. Pair them with internal evidence.
How many critical services have been tested against a realistic scenario in the last 12 months?
During tests, how often did actual recovery meet the agreed RTO and RPO?
How many critical suppliers and technology services have a validated fallback?
How many exercise or incident findings remain open beyond their agreed due date?
Which critical services can continue at a minimum acceptable level without their primary system?
Can deputies activate continuity arrangements if primary leaders are unavailable?
MATSH’s Crisis Management and Business Continuity Course connects business impact analysis, recovery planning, crisis leadership, communications and scenario exercises so the plan is usable under pressure.
We run all our courses as private programmes for organisations across the GCC and Africa.
Request In-House →