Insight · Risk & resilience

The 95 risks and the supply chain

The Cabinet Office National Risk Register 2026 lists 95 risks, each with a reasonable worst case attached. That changes the question from how likely is this, to if it were happening now, would we know.

What changed in 2026

The Cabinet Office published the National Risk Register 2026 on 14 July 2026. It now carries 95 risks across nine themes, up from 89. Seven risks were added and one, disruption of Russian gas supplies to Europe, was removed as reliance on those imports fell away.

The additions are: cyber attack or disruption on data infrastructure, digital resilience failure, cyber attack on water infrastructure, cyber attack on police systems, significant disruption of the criminal justice system, threats to democracy from interference, and accidental damage on the National Gas Transmission Network. More than half are cyber or digital. Two risks now sit at the top of the published matrix for both likelihood and impact: pandemic, and water infrastructure failure or loss of drinking water.

The question the register actually asks

Every risk in the register comes with a reasonable worst case scenario attached. That is the important design decision, and it is the one most readers skip past.

A likelihood rating invites a probability argument. A reasonable worst case does not. It hands you a scenario, fully specified, and the only useful response is operational.

If that were running right now, would we know? The only question a reasonable worst case leaves open

That question is harder than it sounds and much cheaper to answer than most resilience work. It does not need a threat intelligence function or a new platform. It needs a named piece of evidence per scenario, an owner, and a date it was last looked at. Where those three exist, the risk is watched. Where they do not, the risk is a blind spot, and no amount of policy documentation changes that.

Why the register is hard for a company to use

  • Almost none of the 95 land on you directly. A cyber attack on water infrastructure does not attack your company. It attacks a utility, which stops a supplier's process, which stops a delivery you were counting on.
  • Ninety five scenarios against a supplier book is not a manual exercise. A hundred suppliers against 95 risks is 9,500 judgements, out of date the week a supplier changes sector or loses its second source.
  • Uniform exposure destroys the signal. Every company in the country is exposed to a pandemic and to loss of drinking water. Saying so about all of your suppliers tells you nothing.
  • What discriminates is the supplier. Whether it holds a live connection into your estate, whether it is your only source, which sector it trades in, how far its goods travel.

The transmission model

Treat a national risk as something that travels down a channel into a supplier and out the other side as a supply failure. There are seven channels, and every risk names the ones it uses: systems and connectivity, power water and telecoms, movement of goods, physical site availability, workforce availability, price and market access, and regulatory action.

This is the whole trick, and it is deliberately dull. A risk with no channel into a supplier is not that supplier's risk. A risk with a strong channel is, whatever the supplier's questionnaire says.

Read the full paper

Nine pages of the argument in full: the seven channel model, five worked supplier profiles with their exposure scores, the three new cyber risks read through a supply chain, an honest account of where the approach stops, and a thirty day path. Give us an email address and the PDF is yours.

We use your address to send you this paper. We do not sell it, and we do not add you to any mailing list unless you tick the box.

Exposure, per supplier

Score each supplier on how strongly it carries each channel, from its own record: criticality, sole source, sector, access type, integration depth, lead time. Match every risk to the strongest channel it can use into that supplier, lifted where the risk names that supplier's sector. Take the worst reachable risk, then let the next four close half of the remaining gap. Five severe risks is worse than one, but not five times worse.

Done properly the spread is wide, which is the point. A standard supplier with no sector, no access and a short lead time sits near 32. A packaging supplier with physical site access reaches 40. An integrated IT vendor and a regional haulier both pass 75, for completely different reasons. A critical sole source food producer reaches 86. The number ranks a book rather than colouring it all red, and every number decomposes into the risk, the channel and the weight, so a supplier manager can argue with it.

Where it belongs: supplier risk and tiering

National exposure is not a separate report, and it should never become one. It belongs inside the risk engine that already runs the supplier book: as a weighted component of the blended supplier score, as a strategy a risk owner can rank the book by, and in the tiers themselves.

  • A risk judged active on a critical supplier makes that supplier tier one while it lasts
  • A risk judged active on any supplier it reaches materially makes it at least tier two
  • High national exposure alone lifts a supplier out of light touch management
  • Standing the risk down reverses all of it, because a tier is a posture, not a label

The same signal should decide which questionnaire goes out. A supplier carrying heavy exposure does not need another controls checklist; it needs the worst case questions. Which site stops first without power or water. How long you can supply with no mains. How you would take our orders with your systems offline. And what would tell you, within hours, that it had started.

The blind spot count

Against each of the 95, record a position: not tracked, watching, active, stood down, with an owner and a named detection source. A risk counts as answered when it has a source, an owner and a review inside six months. Anything older is stale, and stale is not an answer.

A blind spot is a risk that reaches at least one supplier and has no detection source. Count them, rank them, and report that number upward. It is the one figure in this whole exercise that a board can act on.

Where this stops

Supply chain evidence is not endpoint telemetry. Acknowledgement rates, integration heartbeats, lead time steps and delivery failures by region and by platform are the earliest visible signal for several of the 95, and for many others they are not. The value of naming a detection source is that the answer is allowed to be a tool you already own somewhere else. What is not allowed is leaving it blank.

How WAJD Group helps

We build this capability inside the systems you already run, and operate it as a managed service. The supplier risk engine in WAJD Forge holds all 95 risks against a live supplier book, scores what each can reach and down which channel, and counts the blind spots. It runs standalone, with or without the rest of the system.

Monitoring supplier health is one half of the problem, which we cover in continuous third-party risk. The structural half, several suppliers sitting on one sub-tier site, is in two suppliers, one factory. Testing the scenario before it arrives is severe but plausible resilience testing.

Which of the 95 could reach you through a supplier?

Tell us how many suppliers you manage. We will show you what holding the register against them changes.

Start a conversation