Rhys Sharp, Solution Director at Six Degrees talks to us about how businesses can build their resilience to ensure they can maintain operations, respond to disruption and adapt to change.

Business resilience has traditionally been treated as a form of technical insurance. In many organisations, the goal has been simple: recover quickly when something breaks and minimise disruption.

That perspective is still deeply embedded. Research from the Six Degrees Business Resilience Index 2026 shows that nearly three-quarters of technology and security leaders define resilience primarily through a security lens. Yet when presented with a broader definition, 91% said they learned something new about what resilience actually involves.

The reason is clear. Modern organisations face a far wider range of risks than cyber threats alone. Operational disruption, third-party dependencies, supply-chain fragility, regulatory change, economic volatility and increasing technology complexity all shape whether a business can continue to operate effectively.

True resilience is therefore not just about protecting systems. It is about ensuring the organisation can maintain operations, respond to disruption and adapt to change.

The resilience perception gap

Despite growing awareness of broader risks, there remains a disconnect between how resilience is discussed at leadership level and how it is delivered operationally.

Almost all respondents in the Business Resilience Index research (97%) agreed that strong leadership and governance would improve resilience. Yet board-level commitment ranked only tenth among the factors organisations associate with actually delivering it.

This gap often leads organisations to overestimate their readiness. Resilience activities may exist within IT or security teams, but they are rarely embedded into strategic decision-making across the business. As a result, organisations can feel prepared until disruption reveals hidden weaknesses.

Understanding resilience maturity

Resilience is not a fixed state but a spectrum. Most organisations sit somewhere along a maturity curve made up of five stages:

  • At risk – highly vulnerable organisations with fragmented processes, limited planning and largely manual recovery capabilities.
  • Reactive – able to respond to incidents but unable to anticipate them, often experiencing repeated disruptions.
  • Stable – controls exist and major failures are less likely, but resilience is still process-driven rather than embedded into operations.
  • Agile – people, processes and platforms align to support rapid response and organisational flexibility.
  • Strategically resilient – resilience is embedded across governance, operations and innovation, supporting both performance and long-term growth.

Research suggests most organisations sit in the middle of this curve. They can manage disruption when it happens but lack the foresight, integration and adaptability required to move beyond reactive measures.

The five pillars of resilient organisations

Progress along the maturity curve depends on how well organisations integrate five core capabilities across their operations: Continuity, Security, Scalability, Efficiency and Innovation.

When these pillars operate in isolation, resilience efforts often remain limited in impact. When aligned across infrastructure, governance and strategy, they reinforce one another and create a more adaptable operating environment.

Among the five pillars, continuity consistently emerges as the most fragile.

The Business Resilience Index research shows that nearly one in three organisations (28%) are classified as At Risk in this area, while fewer than one in ten (9%) reach the Strategically Resilient level.

Operational data reinforces the challenge. Mean uptime across critical services in the past year was just 73%, meaning businesses experienced downtime more than a quarter of the time, whether planned or unplanned.

Mean Time to Recover (MTTR) also varies significantly between sectors. Technology companies report average recovery times of around 9.7 hours compared with an overall average of 6.7 hours, suggesting that their focus on client uptime could be coming at the expense of enhancing their own.

The findings highlight an important point: continuity cannot simply exist as a disaster recovery plan on a shelf. It must be embedded, tested and coordinated across the entire organisation.

Strengths and gaps across the other pillars

While continuity presents the greatest risk, the other pillars show a mixed picture of progress.

Scalability is relatively strong. More than half of organisations fall into the Agile or Strategically Resilient tiers, reflecting growing adoption of flexible infrastructure and cloud-based services.

Efficiency shows significant potential but limited maturity. Only 7% of organisations reach Strategically Resilient status, although 39% are progressing toward greater automation and smarter decision-making.

Innovation is widely present but rarely embedded. Nearly half of organisations operate at an Agile level, but just 2% integrate innovation deeply enough to achieve strategic resilience.

Security, while widely prioritised, still has room for improvement. Only 5% reach the Strategically Resilient tier, even though most organisations cluster at the Agile stage.

Different sectors, different pressures

Resilience challenges also vary significantly between industries.

Financial services organisations often demonstrate stronger resilience profiles due to strict regulatory oversight, structured governance and consistent investment in operational stability.

Manufacturing organisations, by contrast, tend to sit closer to the middle of the maturity curve. Operational intensity and complex supply chains make resilience harder to embed, resulting in higher numbers of organisations classified as At Risk and fewer reaching Agile levels.

Technology companies face another challenge entirely: managing the complexity of large-scale digital environments while maintaining speed and innovation.

These differences highlight that resilience strategies must be tailored to the operational realities of each sector.

The growing role of automation and AI

Technology priorities are also evolving. The Business Resilience Index research shows that automation and AI are now viewed as the most important drivers of resilience, ranking above traditional incident response, recovery and continuity planning.

These technologies allow organisations to detect issues earlier and respond more quickly by reducing reliance on manual processes that can slow recovery. They also enable more continuous, data-driven operations that help anticipate risks before they escalate.

However, infrastructure limitations can still create bottlenecks. Many organisations report that existing resilience strategies cannot scale quickly enough during sudden demand spikes or operational disruptions. Ensuring platforms and services can adapt rapidly is therefore becoming a central focus of resilience strategies.

Turning resilience into a growth platform

The most resilient organisations approach the challenge differently. Rather than treating resilience purely as a defensive safeguard, they see it as an operational capability that supports growth and adaptability.

In practice, this means embedding resilience into everyday operations and decision-making. High-performing organisations design systems that can sense operational signals and emerging demand, allowing them to identify opportunities as well as risks. Continuity is treated as routine operating hygiene, with systems tested regularly and responsibility shared across the organisation rather than confined to IT teams.

They also build scalability directly into system design through elastic infrastructure, self-service capabilities and automation, enabling the business to respond quickly to change without unnecessary friction. At the same time, efficiency is driven by cost transparency rather than simple cost-cutting, helping leaders invest where resilience clearly delivers value. Finally, innovation is actively protected through governance and resource allocation, ensuring experimentation and future-readiness remain part of the organisation’s long-term strategy.

Together, these practices transform resilience from a reactive safeguard into a strategic platform that enables organisations not only to withstand disruption but also to evolve and grow in response to it.

By Rhys Sharp, Solution Director, Six Degrees.

  • Risk & Resilience

Tim Vessel, Automotive Enterprise Account Executive at Loftware, explores the reasons why collaboration with trusted suppliers helps make the supply chain more agile

The automotive industry is entering one of its most volatile periods in decades. A perfect storm of rising tariffs, persistent global inflation and an oversaturated used vehicle market is driving billions in new costs across the automotive ecosystem, placing unprecedented pressure on OEMs and suppliers alike. Traditional forecasting models, once the foundation of operational planning, are proving increasingly fragile in the face of constant disruption. 

As a result, predictability is no longer the goal. Instead, automotive organisations are shifting their focus toward operational readiness – building supply chains that can adapt quickly, execute consistently and absorb change without compromising compliance or margin. Agility, standardisation and collaboration are becoming as critical as cost control. 

This shift is most visible in how manufacturers engage their supplier ecosystems. By strengthening connectivity and execution across operations – including product identification and packaging – organisations can move from reactive firefighting to proactive readiness.  

From prediction to readiness 

For years, automotive supply chains have relied on long-term forecasting to manage cost, capacity and risk. But today’s operating environment has exposed the limits of this approach. When tariffs shift, input costs rise and demand fluctuates simultaneously, planning for a single “most likely” outcome leaves organisations increasingly exposed. 

Instead, manufacturers and suppliers need the ability to respond quickly to multiple scenarios – adjusting product location, switching suppliers or rerouting components without disrupting downstream operations. Readiness, rather than prediction, is what allows organisations to maintain momentum when conditions change. 

Operational readiness depends on more than contingency plans. It requires consistent execution across every touchpoint in the supply chain, particularly at the points where physical goods move between partners. Product identification and packaging, often overlooked as tactical functions, play a critical role in enabling that consistency at scale. 

Strengthening supplier collaboration and AI-enabled networks 

As automotive supply chains become increasingly distributed, collaboration between OEMs, suppliers and extended partner networks grows more complex. Delays, mislabelling and compliance gaps can quickly escalate, driving up costs and slowing production. Seamless supplier collaboration, enabled by a truly connected network, addresses these challenges by allowing OEMs to share standardised processes and approved labels directly with their Tier 1 suppliers. Without the right network and tools in place, poor product identification processes can stall production, require manual relabelling, increase labour costs and tie up working capital to manage risks. 

Within this connected network, suppliers can leverage AI-enabled packaging and product identification technologies to operate more efficiently. Shared data and standardised processes give manufacturers greater visibility, while suppliers benefit from clearer requirements and faster execution. Aligning suppliers around these consistent standards reduces errors, minimises rework, and streamlines upstream operations, transforming a fragmented network into a coordinated and high-performing ecosystem. Automation ensures labels are applied correctly, regardless of location or producer, accelerating movement through the supply chain and supporting tighter coordination even as sourcing strategies and regional regulations evolve. 

Yet operational efficiency alone isn’t enough. In a recent expert roundtable, William Newman, Automotive Industry Executive Advisor at SAP, noted that AI initiatives often fail when leaders impose productivity targets – 5%, 10%, or 15% gains – without a clear strategy and execution framework. Companies must redesign current work steps while planning for future processes, ensuring AI deployment drives measurable business value. When implemented strategically, AI becomes a catalyst for tangible results across the automotive supply chain, turning collaboration and connected processes into a real competitive advantage. 

Reducing risk in a volatile trade environment 

Trade volatility is reshaping the automotive sector, forcing manufacturers to rethink where and how they produce vehicles and components. 

Without automation, these changes introduce significant risk. Manual updates to product identification or packaging specifications can lead to errors, delays or non-compliance – all of which carry financial and reputational consequences. In the automotive industry, that risk is amplified by the need to prevent counterfeit components entering the supply chain and to ensure long-term traceability across vehicles with lifecycles measured in decades, not months. Automated systems, by contrast, allow organisations to adapt quickly while maintaining accuracy and control. 

When sourcing decisions change, automated product identification and packaging processes ensure that updated requirements are reflected immediately across the supplier network. This reduces the risk of mislabelled goods, border delays or rejected shipments, helping manufacturers protect margins and maintain service levels even as trade conditions fluctuate. 

Scaling efficiently in uncertain times 

Uncertainty is also reshaping how automotive organisations approach growth. Instead of relying on rigid, centralised systems, manufacturers are turning to connected, AI-enabled platforms that make it easier to respond quickly to changing market demands and partner networks. 

These connected platforms lower barriers for suppliers of all sizes, enabling faster onboarding, smoother collaboration across regions and consistent execution without heavy manual oversight. By standardising key processes while maintaining flexibility, manufacturers can adjust production or sourcing strategies on the fly. 

Importantly, this approach allows companies to scale without losing control. As networks expand or contract, leaders retain clear visibility and governance over product identification, packaging and other critical operations – ensuring readiness grows in step with the business, even in volatile or unpredictable markets. 

Building readiness as a strategic advantage 

By treating operational processes like product identification and packaging as strategic enablers rather than back-office functions, automotive OEMs and suppliers can build supply chains that are not only more agile, but more competitive. In an era where disruption is the norm, readiness is what separates those who react from those who lead. 

  • Risk & Resilience

Rami Riashy, transport assurance cyber security principal at NCC Group, discusses the evolving cyber threat to the agriculture sector, and how organisations across supply chains should tackle the rising risks

Modern global trade depends on stable, resilient and secure supply chains. From energy and pharmaceuticals to semiconductors and food, the reliable supply of goods underpins financial markets, social stability and national security. At the centre of these global systems sits agriculture.

Today, agriculture is no longer a low-tech, analogue industry. It is rapidly becoming one of the most technologically advanced sectors. Precision agriculture, cloud-connected equipment and autonomous machinery are transforming how food is grown, harvested, processed and delivered.

Across fields and facilities, technologies such as autonomous tractors, GPS-guided planters, cloud-based fleet management platforms, drone spraying systems, real-time soil telemetry and AI-driven irrigation are now commonplace. These deliver significant gains in efficiency and sustainability, but they must be matched with equally robust approaches to cyber resilience. 

Laying the foundations of digital agriculture 

As agriculture digitises, the sector’s exposure to cyber risk grows. Every link in the agricultural supply chain – from seed genetics and field telemetry to logistics and export documentation – introduces potential vulnerabilities. 

Instead of viewing this as a barrier to innovation, organisations should treat it as a design challenge. The focus should not be simply identifying threats but embedding resilience into the foundations of agricultural systems. 

Cyber security must move from reactive protection to proactive, system-wide design. Priority steps to take include: 

  • Embedding secure-by-design principles in machinery and platforms 
  • Designing systems that are safe and functional, even in degraded or offline conditions 
  • Ensuring security controls are proportionate to real-world operational environments, not just enterprise IT models 

As one of the most immediate points of impact, machinery should be engineered to fail safely, maintain integrity and continue operating even when connectivity is limited or disrupted. 

Designing for real-world agricultural conditions 

Agriculture operates under constraints that require tailored security approaches. Remote locations, long equipment lifecycles and mixed-brand ecosystems make traditional cyber models insufficient. 

Offline-capable security 

Security mechanisms must function without constant connectivity. This means: 

  • Local authentication and authorisation controls 
  • On-device integrity verification
  • Secure fallback modes that maintain safe operations 

Lifecycle conscious engineering 

With machinery often in use for decades, security cannot rely on frequent updates. Instead: 

  • Hardware roots of trust and secure boot should be standard 
  • Cryptographic key management must support long-term use 
  • Systems should be designed to remain trustworthy even if updates are infrequent 

Trust across ecosystems 

Multi-brand environments demand shared security frameworks. A federated trust mode, such as interoperable PKI, allows: 

  • Secure communication between different manufacturers’ systems 
  • Clear accountability without sacrificing competition 
  • Reduced risk of gaps between platforms 

By focusing on these principles, organisations can reduce systemic risk while maintaining operational flexibility. 

Strengthening resilience across the supply chain 

Agricultural cyber risk is not confined to machinery. It spans a broad ecosystem, including cloud platforms, dealer networks and manufacturing systems. 

To ensure that resilience is end to end, some practical steps to take include: 

  • Securing software supply chains, including firmware updates and third-party components 
  • Implementing strict identity and access management across dealer and service networks 
  • Monitoring for anomalies across IT and OT environments 
  • Establishing clear incident response plans that are in line with seasonal operations 

Integrating cyber security with safety 

In agriculture, cyber security is inseparable from physical safety. Compromised systems can directly affect machinery behaviours, operator safety and environmental outcomes. To address these risks, organisations should integrate cyber risk into functional safety assessments, conduct threat modelling that includes malicious and accidental failures, and ensure safety-critical systems are isolated, monitored and resilient. This helps to ensure that even in the event of an attack, systems can default to safe and controlled states. 

Protecting data as a strategic asset 

Agricultural data – from social conditions to yield forecasts – is increasingly valuable, and its integrity underpins decision-making across the supply chain. Protecting this data requires strong validation of data inputs and analytics outputs, safeguards against data manipulation, and clear governance over data ownership, access and usage. 

Compliance with regulation and industry standards 

Regulatory frameworks such as the EU Cyber Resilience Act and NIS2 are elevating expectations across the sector. While requirements may vary globally, the direction of travel is clear: strong cyber security is becoming a baseline for participation in modern supply chains.

A collective responsibility to build resilience 

No single organisation can secure supply chains alone, and responsibility spans OEMs designing secure equipment, suppliers embedding trusted components, platform providers protecting data and infrastructure, farmers and regulators. The strength of the full system depends on its weakest link, meaning collaboration, transparency and shared accountability are all essential. 

The transformation of agriculture into a connected, data-driven ecosystem is both an opportunity and a collection responsibility. While cyber threats are real and evolving, they can be effectively managed through intentional design, coordination action and long-term strategy. 

Cyber security should be treated as a core enabler of resilience, instead of a defensive measure. By embedding security into machinery, data, operation and partnerships, the sector can ensure that innovation continues without the compromise of stability. 

  • Risk & Resilience

UK logistics networks could be operating with too little headroom to withstand mounting pressure on the food system, research from global supply chain and logistics consultancy, SCALA, warns

The report, which is based on a survey of senior supply chain leaders, found that over half (52%) of firms hold less than a quarter (25%) contingency or safety stock, while 71% could increase their UK warehouse capacity by no more than 25%. A further 43% said that no other site could fulfil dispatches if their primary warehouse became unavailable, and only a third (33%) had fully implemented the necessary response strategies, with 52% having partially done so and 14% yet to begin altogether.

While individual businesses have unique requirements that call for tailored supply chain and logistics networks, together, the challenges of limited stock, restricted capacity and a lack of tested alternatives can compound. This leaves logistics networks less able to absorb disruption caused by extreme weather, labour shortages, transport problems or geopolitical events.

The findings come as extreme heat and the decline of ecosystems supplying the UK threaten poor harvests, shortages and higher prices. Farming, retail, food manufacturing and hospitality leaders have already called for a national food resilience plan, warning that secure and affordable food supplies can no longer be taken for granted. This pressure could be further compounded by higher business rates for large logistics properties, encouraging businesses to shift to more efficient rather than resilient supply chains.

Amid this context, SCALA is calling for warehousing and transport to be treated as critical national infrastructure, given their integral role in keeping supermarkets stocked, manufacturers operating and goods moving across the country. The firm is also advising businesses to implement robust contingency plans with alternative sourcing options identified where possible. 

Chris Clowes, executive director at SCALA, said: “Food supply chains are already facing growing pressure from extreme weather, geopolitical instability and rising costs. Our research suggests many businesses are entering the next major disruption severely underprepared, largely due to a focus on efficiency over resilience within logistics networks.

“Businesses should identify the suppliers, facilities and processes that could interrupt supply, establish back-up arrangements, and test how quickly stock, people and vehicles could be redirected. Sainsbury’s recent decision to increase supplies of British-grown vegetables is a great example of this thinking in practise.

“The government must also recognise warehousing and transport as critical national infrastructure, with business rates that support investment in resilient logistics capacity. Any national food resilience plan must consider how food will be stored and moved, as well as how it will be produced.”

SCALA’s report, The Resilience Gap: Assessing the Risks and Readiness of Global Supply Chains, explores the operational weaknesses leaving businesses exposed to disruption and the practical steps they can take to strengthen supply chain resilience.

Read the report here.

  • Risk & Resilience

Pace Technology UK has launched Cold Logic, a new vehicle temperature monitoring platform designed to help pharmaceutical, healthcare and regulated cold chain operators maintain product integrity, improve operational visibility and support regulatory compliance throughout the distribution process

Developed specifically for temperature controlled logistics, Cold Logic combines live temperature monitoring, GPS journey tracking, configurable alerts and automated compliance reporting within a single platform. The solution integrates with vehicle-mounted temperature probes, refrigeration systems, independent data loggers and API-connected devices, allowing operators to enhance existing fleet infrastructure without replacing installed equipment.

Designed to support MHRA Good Distribution Practice (GDP), Cold Logic provides continuous monitoring across every stage of the distribution journey, from collection and trunking through to cross-dock operations and final-mile delivery.

The platform enables operators to identify temperature excursions as they occur, investigate incidents using complete journey data and maintain secure, time-stamped records to support audits, quality reviews and customer assurance. Automated reporting, encrypted data storage, controlled audit trails and role-based access controls help reduce administrative burden while strengthening compliance across regulated transport operations.

Cold Logic is suitable for pharmaceutical manufacturers, wholesale distributors, healthcare logistics providers, hospital pharmacies, NHS supply chains, clinical trial operations and specialist temperature controlled logistics providers transporting refrigerated, frozen and ultra-low temperature products.

Steve Kealey, MD for Pace Technology UK said: “Cold Logic is redefining how the cold chain logistics sector manages temperature data across its fleets.

“As the latest addition to the Pace portfolio, Cold Logic sets a new benchmark for compliant temperature monitoring by combining modern technology with commercial practicality. The result is a seamless, reliable solution that simplifies compliance, enhances operational visibility, and delivers measurable value for cold chain operators.”

As pharmaceutical distribution networks continue to demand greater traceability and operational oversight, Cold Logic provides fleet operators with a practical solution that combines temperature monitoring, compliance reporting and journey visibility within a single platform.

  • Risk & Resilience

Nathan Peacey, Head of Retail and Consumer, and Tamzin Robson, Associate, at Foot Anstey, explore where the UK is falling behind on human rights in the supply chain, and how we can do better

A decade after the Modern Slavery Act 2015 (MSA), the UK’s once-leading framework sits at a crossroads. The Independent Anti‑Slavery Commissioner’s recent report finds that the UK transparency-based model is now viewed as fragmented and operating without meaningful enforcement. Under the current regime, businesses can legally comply by submitting a statement saying they have taken no steps to address modern slavery, and the consequences for failing to publish a statement at all are minimal in practice. 

As a result, the UK is now significantly outpaced by international developments. The report concludes that a full legislative refresh, centred on mandatory, enforceable human rights due diligence (HRDD) and stronger trade enforcement, is essential to protect workers and ensure responsible businesses are not undercut. For supply‑chain‑intensive businesses reliant on stable, resilient and ethically sound sourcing, this gap poses both operational and reputational risks.

The Independent Anti-Slavery Commissioner warns that without reforms aligned to global standards, the UK risks becoming “a dumping ground” for goods made with forced labour once the EU’s import ban takes effect. Leading businesses and investors share this concern. From major UK retailers to international consumer brands, the consensus is that robust, mandatory HRDD is critical to protect workers, safeguard the UK’s credibility and to protect UK supply chains from structural risk and reputational exposure.

Current state of play: Why the UK needs to strengthen its framework

Voluntary transparency is no longer enough. Section 54 of the MSA catalysed reporting, but it does not require companies to prevent harm, and penalties for poor or absent statements are weak. The result has been inconsistent quality and limited impact for exploited workers. In addition, fragmented domestic rules are adding cost and confusion. Sector‑specific legislation such as due‑diligence‑style obligations in NHS procurement and the Great British Energy Act 2025 has created duplication and conflicting expectations for supply chain operators trying to maintain coherent compliance systems across multiple regimes.

The scale and economics of harm are compelling. The UK faces significant recurring costs from modern slavery (estimated at around £60bn annually), while importing approximately £20bn of goods each year at risk of being produced through forced labour. With the EU’s forced‑labour product ban applying from 2027, the UK risks becoming an outlet for blocked goods unless it aligns its own regime. For supply chain leaders, this introduces a clear operational risk: diversion of non-compliant goods into the UK market could disrupt procurement, create customs delays, and expose businesses to unexpected enforcement.

A broad societal consensus supports change too. Survivors, businesses, investors and the public are all calling for mandatory, enforceable standards.

International developments – and how the UK is falling behind

Over the past decade, many of the UK’s major trading partners have moved from voluntary transparency to mandatory human rights due diligence (MHRDD) and enforceable import controls. The EU has led this shift through the Corporate Sustainability Due Diligence Directive (CSDDD), which from 2027 will impose binding HRDD duties and civil liability across global value chains, and the 2024 Forced Labour Regulation, which bans forced-labour-linked products from entering or leaving the EU. France, Germany and Norway have also enacted due diligence laws requiring structured risk assessment, stakeholder engagement, grievance mechanisms and meaningful sanctions.

Beyond Europe, the United States has tightened border enforcement through the Uyghur Forced Labor Prevention Act (UFLPA), which presumes goods from Xinjiang are made with forced labour unless proven otherwise. Canada, South Korea, Brazil, Thailand, Australia and New Zealand are likewise moving toward due-diligence-based regimes and stricter trade controls.

This global shift reflects a clear consensus: voluntary reporting does not prevent harm, and mandatory, enforceable due diligence is now the international norm. Without comparable reforms, the UK risks becoming an outlier, and potentially a “dumping ground” for goods barred from stronger jurisdictions, undermining responsible businesses and its credibility as an ethical trading partner. For supply chain executives, this means misalignment between regulatory regimes will increase operational complexity and create trade-flow friction unless the UK modernises.

What changes to the UK’s Forced Labour and Human Rights Legislative Framework is the Independent Anti-Slavery Commissioner proposing? 

The Independent Anti-Slavery Commissioner’s draft Forced Labour and Human Rights Bill 2026 sets out wide-ranging reforms to bring the UK in line with international best practice. The rules would apply to large organisations with a global turnover of £36 million or more, whether UK-based or overseas but operating in the UK, as well as public undertakings engaged in commercial activity. Financial services providers are expressly included. SMEs fall outside direct regulation but will be affected as part of larger companies’ value chains. 

Key proposals include: 

  • A statutory “failure to prevent” duty

Organisations would be legally liable where they cause, contribute to, or are directly linked to serious human rights harms anywhere in their value chain. This shifts the UK from voluntary transparency to mandatory accountability, mirroring the Bribery Act and aligning with global HRDD laws such as those in France, Germany and the CSDDD. Applying the duty to global operations reduces incentives to offshore exploitation and provides clearer expectations for supply chain oversight at every tier.

  • A “reasonable human rights due diligence” defence

Companies may avoid liability by demonstrating reasonable, proportionate, risk-based due diligence consistent with the UNGPs and OECD Guidelines. This balances firm duties with flexibility, allowing expectations to scale by size, resources and risk, and encouraging continuous improvement rather than tick-box compliance.

  • Strengthened civil enforcement

A new Office for Responsible Business Conduct would be able to issue public censures, compliance, compensation, costs and restoration notices, a penalty notice of up to 5% of global turnover, and exclusions from public procurement. 

These sanctions introduce meaningful commercial consequences, reflecting EU-style enforcement and posing particular implications for public-contract-reliant sectors and for supply chain-heavy industries with complex multi-jurisdictional sourcing models.

Criminal liability for serious abuses

For offences such as slavery, trafficking, GBH or corporate manslaughter, both organisations and consenting/conniving senior officers could face criminal prosecution. This elevates human rights from a compliance issue to a criminal risk, driving greater board-level oversight.

  • A UK-wide forced labour product ban

The Bill would ban the import, export and sale of goods made or transported with forced labour, including presumptive bans for high-risk regions or products and a public risk database. This aligns the UK with EU, US and Canadian regimes and closes a major gap in current law by stopping forced-labour goods at the border rather than merely requiring reporting. For supply‑chain leaders, this would materially alter customs screening, supplier onboarding, and product‑traceability expectations.

  • A mandatory annual Human Rights Statement

In the place of the Modern Slavery Statement, a mandatory annual Human Rights Statement would create enforceable disclosure obligations. Organisations above the threshold would be required to publish a board-approved, evidence-based statement setting out any serious human rights harms for which they may be responsible; an explanation where no such harms are identified; a forward-looking plan for prevention and mitigation; and an assessment of the effectiveness of actions taken. The statement would be uploaded to a central public registry, and failure to comply could result in financial penalties, closing the long-criticised enforcement gap in the MSA. This shifts the current voluntary model into a substantive, outcome‑focused reporting requirement.

Next steps and timescales

The Independent Anti-Slavery Commissioner urges the Government to adopt the Bill in the next King’s Speech. The legislation is designed to come into force two years after enactment, giving organisations time to embed human rights due diligence. Within six months of commencement, the Office for Responsible Business Conduct must be fully operational, and within six months of passage the forced-labour database and enforcement regulations must be established. Guidance on reasonable due diligence and other key concepts must be issued within one year.

What should your business do? 

Given the practical difficulties in achieving full supply‑chain visibility, together with the direction of travel indicated by key trading partners and the Independent Anti-Slavery Commissioner’s recent recommendations, there is value in forward‑looking businesses taking early steps to prepare for potential legislative change.

This should include measures such as mapping value chains beyond Tier 1 and identifying structural risks and visibility gaps, as well as investing in evidence systems for future human rights disclosures such as traceability tools. Reviewing trade compliance is especially vital for high-risk products and regions, and supply chain leaders should also consider strengthening governance structures and ensuring board-level oversight and integration into procurement processes. The value of fostering a culture which encourages employees to speak up should also not be overlooked.

Supply chain leaders who act early will be best positioned to manage risk, assure continuity and maintain competitive advantage.

  • People & Culture
  • Risk & Resilience

Dan Romanelli, SVP at Quoreka, discusses fluctuations in supply chain, how to strengthen the sector again, and the part CTRM systems can play

Global supply chains are being reshaped by the new realities of geopolitics. The combined effects of sanctions, tariffs and regional realignments have up-ended the once-connected network that moved energy, metals, and agricultural products around the world. The result is a trading environment where logistics and risk management are gaining as much visibility as front office processes.

What began as a series of short-term disruptions – from the COVID-19 pandemic to port congestion and sanctions – has evolved into a structural shift in how global trade operates. The Russia-Ukraine conflict exposed how dependent Europe had become on single-route energy corridors, while escalating US-China trade tensions are prompting countries across Asia and the Americas to diversify suppliers and logistics hubs. These changes have redrawn trade routes and altered traditional sourcing models, introducing both resilience challenges and new opportunities for regional players.

For logistics planners and commodity traders alike, the rebalancing of flows is far from straightforward. Europe’s search for alternative gas and metals suppliers, or China’s expanding links with differing economies, illustrate how politics can define supply as much as price or demand. Long-established trade corridors are slowly being augmented to include new, costlier ones that can be harder to predict and maintain. Cargoes are being rerouted, blending standards are shifting, and inventory management has become a far more dynamic process than it was just a few years ago.

At the same time, the return of tariffs and export controls has complicated procurement and pricing. Fluctuating trade policy distorts price discovery and arbitrage, forcing firms to hedge more aggressively and to make faster decisions about storage, transport, and contract exposure. For bulk commodities such as copper, nickel, wheat or corn, the knock-on effects reach from mine and field to port and warehouse. Logistics teams must adapt to changing flows while contending with higher insurance premiums, longer lead times, and increasingly volatile freight markets.

Even efforts to strengthen supply chain security bring trade-offs. Nearshoring and so-called ‘friend-shoring’ are reshaping regional manufacturing and logistics hubs, but they also create inefficiencies that must be managed. More production is being brought closer to home yet input materials often still cross multiple borders. That means greater reliance on real-time data and collaboration between trading, procurement and logistics teams.

CTRM’s expanding role in a fragmented trade environment

This environment has elevated the role of Commodity Trading and Risk Management (CTRM) systems beyond their traditional remit. Once used mainly for pricing, position management, and compliance reporting, CTRM platforms are now at the heart of operational resilience. Modern solutions integrate real-time shipping and warehouse data, cargo tracking and country-level risk analysis, helping firms model disruption and re-route shipments before losses mount.

In practice, that means traders and supply chain operators can run scenario tests to simulate events such as sanctions, port closures, or even extreme weather events. By linking trading positions to freight contracts, credit terms, and insurance exposure, CTRM tools provide a dashboard view of the financial and physical implications of disruption. Firms can compare the cost of alternative routes, quantify potential penalties or missed deliveries, and make faster decisions about reallocating cargoes.

The same systems are also becoming crucial for ESG and regulatory compliance in some areas of the world. New frameworks such as the EU Deforestation Regulation (EUDR), demand traceability from mine or farm through to processing and transport. Integrating those data points within a single CTRM environment allows firms to automate reporting and reduce the risk of non-compliance while maintaining agility.

Ultimately, the convergence of trading, logistics and risk data is changing how global supply chains operate. Instead of treating these as separate functions, leading firms are building integrated decision platforms that merge operational visibility with financial intelligence. This evolution makes CTRM software less a back-office tool and more a real-time command centre for trade.

As commodity flows continue to fragment, success will depend on agility and insight. The ability to integrate new data sources quickly, visualise exposure across suppliers, trade routes and financial positions, will allow action before disruption hits. In this world, data integration is no longer a luxury; it’s the infrastructure that keeps global trade moving.

  • Risk & Resilience

Mark Rutherford, CEO of Alexander Battery Technologies, outlines what the EU Battery Passport means for battery manufacturers supplying into Europe

As the February 2027 enforcement date for the EU Battery Passport approaches, battery manufacturers are adjusting to a higher standard of operational scrutiny that is already influencing customer behaviour across Europe. The regulation requires that in-scope industrial batteries carry a compliant digital record detailing origin, carbon footprint, recycled content and key technical characteristics which means a battery without a defensible data trail cannot be placed on the EU market.

For UK-based manufacturers exporting into Europe, this requirement is feeding directly into supplier questionnaires, qualification audits and commercial discussions well ahead of the deadline. At Alexander Battery Technologies, where we design, develop and manufacture battery pack solutions for OEMs across multiple sectors, the impact is less about interpreting the regulation itself and more about ensuring that our production systems consistently generate the level of evidence customers now expect to see.

Embedding traceability into routine operations

One of the most significant changes is that data capture can no longer be treated as a parallel compliance activity that sits alongside manufacturing; it must be integrated into it. Bills of materials, approved supplier records, serial numbers, firmware versions, test outcomes and process parameters need to sit within a structured framework that allows each finished pack to be traced back through its component batches and build history without having to retrieve and consolidate information from separate systems.

Battery programmes evolve over time as components are substituted, designs are refined and process improvements are introduced and without controlled change management those adjustments can create gaps between approved specifications and what is built on the line. Under a Battery Passport regime, such gaps carry greater commercial risk because the expectation is that documentation and physical product remain aligned throughout the lifecycle of the programme.

For mid-market manufacturers that are not  vertically integrated , the battery pack manufacturer often plays a central role in consolidating upstream materials data, even where the final regulatory responsibility sits with the OEM placing the product on the market. This includes reconciling upstream information on cell chemistry, material origin and lifecycle emissions. That data does not always arrive in a consistent or audit-ready format, so it must be reviewed and validated before it can be relied upon.

The response is disciplined serialisation, structured engineering change control and integrated production records. When those elements are aligned, compliance becomes a natural outcome of controlled, evidence-based manufacturing rather than a separate reporting exercise layered on at the end of the process.

Addressing weak points across the supply chain

Battery supply chains remain globally distributed and technically layered with cells, electronics and mechanical assemblies often sourced from different jurisdictions, alongside battery management firmware that careful version control and documented verification throughout the product lifecycle. The most exposed areas are typically upstream, where raw material data and carbon reporting methodologies are still developing and may not be standardised across suppliers.

Carbon footprint declarations and recycled content claims depend on reliable inputs from cell manufacturers and material processors. Inconsistencies at that level can complicate the creation of a coherent product record further downstream. Manufacturers therefore need systems capable of accommodating and validating that data before it is attached to a compliant Battery Passport.

Software integrity introduces an additional dimension. Modern battery packs incorporate battery management systems and firmware that influence performance, safety and warranty exposure. As a result, version control, update management and documented verification processes are increasingly regarded as integral to overall quality assurance. 

Customers and insurers no longer separate software from hardware in their assessment of risk. Firmware versions, update histories and access controls are examined alongside weld data, torque settings and electrical test results, particularly where batteries are deployed in safety-critical or regulated applications.

The commercial implications are straightforward. Where a performance issue is raised, the outcome depends on whether the manufacturer can evidence exactly what was built, which components were used and what tests were completed at the time. A complete and coherent production record shortens investigations and limits exposure. Where records are inconsistent or dispersed across systems, investigations take longer, commercial relationships can become strained and costs escalate accordingly.

Aligning engineering, procurement and quality functions

Meeting these expectations requires closer alignment between engineering, procurement and quality functions than has historically been the case. Engineering teams focus on performance and validation, procurement on cost and supplier resilience and quality teams on documentation, traceability and regulatory requirements. A Passport-driven environment requires those disciplines to operate from a shared data structure rather than parallel systems.

In practice, this means moving away from informal spreadsheets and local workarounds that may be workable during early development but become difficult to sustain at scale. An integrated framework linking design control, supplier approval, materials management and manufacturing execution allows changes to be reviewed once and reflected consistently across the organisation, reducing the risk of divergent records.

Such integration does not need to slow production when properly implemented. On the contrary, structured systems reduce the time spent compiling information in response to customer queries and support earlier identification of issues before they reach final inspection. End-of-line testing remains an essential safeguard, but it operates within a wider environment of monitored and recorded process control.

As February 2027 approaches, the Battery Passport provides a clear regulatory milestone, yet the broader transition is already well under way. Manufacturers are being asked not only to deliver battery packs that meet technical specification, but to demonstrate, with clarity and consistency, how those products have been designed, sourced and built. For mid-market companies supplying into Europe, embedding that discipline into routine operations is becoming a prerequisite for market access rather than a future compliance exercise.

  • Risk & Resilience

Will Benton, VP of EMEA at LevelBlue, explores the company’s research into the severe issue of cyber resilience within supply chain

Manufacturers today are operating in an environment where digital risk is escalating faster than many organisations can respond. The sector sits at the centre of the global economy, powering industries from energy and healthcare to transportation and consumer goods, which means an operational disruption has implications well beyond individual companies.

Recent research from LevelBlue highlights just how severe the situation has become. The study reveals a sharp rise in cyber threats, driven by advances in artificial intelligence (AI), increasingly complex supply chains and mounting geopolitical tensions. These pressures are exposing vulnerabilities across the UK’s industrial ecosystem, including major automotive manufacturers – like we saw with Jaguar Land Rover in 2025.  

AI as an accelerator for cyber threats

AI promises game-changing efficiency gains across production lines, quality control and workforce productivity. Simultaneously, it is also transforming how attackers operate. Criminal groups are now using AI to scale social-engineering operations, generate highly realistic deepfakes and identify exploitable vulnerabilities at unprecedented speed. 

Manufacturing leaders anticipate these risks rising sharply, many expect a surge in AI-enabled attacks and identity manipulation, yet preparedness lags significantly behind awareness. A major gap has emerged between the rapid adoption of AI technologies and the cybersecurity measures needed to use them safely. According to LevelBlue’s report, while 44% of executives expect AI‑driven attacks and 47% foresee threats like deepfakes or synthetic identities, only about one‑third feel confident in their ability to defend against them.

The consequence is an expanding attack surface that many organisations don’t yet have the structure or tooling to fully manage. AI adoption is happening too fast for regulations, governance or mature cybersecurity controls to keep pace, which expands the attack surface and increases exposure. Many leaders acknowledge these risks yet remain eager to roll out AI solutions, often without putting the necessary safeguards in place. This gap between rapid innovation and adequate protection highlights the pressing need for manufacturers to adopt a more proactive and flexible approach to building resilience.

Software supply chain exposure

Despite years of warnings and high-profile incidents, the software supply chain remains one of the manufacturers’ weakest defence points. Too few organisations have deep visibility across their vendor ecosystem, and only a small portion are making meaningful investments in supply chain security. LevelBlue’s research highlights this: just 31% of Chief Information Security Officers (CISOs) consider the software supply chain their primary security risk, while many continue to downplay concerns such as legacy systems (62%) or limited visibility for security assessments (64%).

The research shows manufacturers regularly underestimate risks such as outdated software, unsecured open-source components and inadequate transparency from third-party suppliers. These weaknesses give attackers an entry point into a company’s systems, allowing them to steal sensitive information, disrupt operations and even pass compromised software on to customers. Strengthening supplier verification, maintaining accurate software bills of materials and performing frequent risk assessments must become baseline practice for manufacturers looking to harden their defences.

Cybersecurity becomes a business priority, but gaps persist

One encouraging shift is that cybersecurity is increasingly being seen as a strategic business issue rather than a technical afterthought. Many manufacturers now align security with business functions, incorporate cybersecurity KPIs at leadership levels, and invest in resilience, earlier in project lifecycles.

LevelBlue’s findings show that 68% of manufacturing executives believe their cybersecurity teams are well aligned with core business functions, and 65% say leadership roles are now directly linked to cybersecurity KPIs. Combined with rising media scrutiny and an increasingly sophisticated threat landscape, these factors are elevating cybersecurity on the corporate agenda, capturing C‑suite attention and driving greater prioritisation across organisations.

This change marks a broader move toward proactive cybersecurity, embedding protection into innovation efforts, enabling calculated risk-taking and fostering better awareness of threats across the workforce. Over half of manufacturers (55%) now set aside cybersecurity funding at the very beginning of new projects, embedding security into initiatives from day one. Additionally, 69% say that adopting an adaptive cybersecurity strategy allows them to take bolder innovation risks, and 70% are actively training employees to recognise social engineering threats. Together, these efforts signal a sector increasingly treating resilience as a core enabler of growth.

But progress continues to be uneven. Less than half of manufacturing organisations describe their cyber culture as fully effective. To reach the next stage of maturity, manufacturers will need stronger governance, deeper employee engagement and security practices that are integrated into the day-to-day functions, rather than just major initiatives. 

What manufacturers should prioritise next 

Manufacturers looking to strengthen their cyber resilience need to shift from simple awareness to concrete action:

  • The next step is strengthening governance so that board-level oversight translates into measurable accountability, clear ownership and consistent risk management across the organisation.
  • At the same time, organisations should work with various departments, particularly with HR, to build a stronger security-minded culture, encouraging safe digital behaviours and making it easy for employees to report suspicious activity. 
  • Another priority is investing more intentionally in protection by implementing layered security measures, adopting advanced detection technologies, and bringing in external expertise where needed to stay ahead of evolving threats.
  • Finally, manufacturers must fortify supply chain resilience by improving transparency across their vendor ecosystem, verifying the security practices of key suppliers and conducting regular assessments of higher-risk third-party systems.

Together, these steps help organisations move toward a more proactive and robust approach to cybersecurity. 

A defining moment for the industry

Manufacturers are at an inflection point. AI-enhanced attacks, deepfakes and increasingly targeted supply chain intrusions are reshaping the security landscape at a pace many organisations are struggling to keep up with. However, the industry is not standing still. With cybersecurity now elevated to the corporate agenda, the next step is building a culture and operating model that treats resilience as foundational to innovation and growth.

By embedding security into business strategy, manufacturers can close the readiness gap, and position themselves to thrive in a future defined by digital risk. 

  • Risk & Resilience

The Founder of KŌSE Advisory has joined the World Economic Forum Expert Network

Koray Kӧse, Founder and Chief Analyst at KŌSE Advisory, has become a member of the World Economic Forum Expert Network.

Kӧse announced the news on LinkedIn this week. His work with organisations like Hope for Justice and Slave-Free Alliance, and the Exiger Executive Forum, has helped put KŌSE Advisory in a position where Kӧse can now contribute his perspectives directly to the World Economic Forum’s policy conversations. 

Kӧse said: “We are entering a period where geopolitics, AI, industrial policy, and supply chain risk can no longer be discussed in isolation, because they are colliding and reshaping how companies compete, how governments act, and how value chains are designed, with consequences measured in trillions and in lives.”

Kӧse’s intent is to contribute actionable, tangible insights to the World Economic Forum Expert Network. These insights will be grounded in data, foresight, and human intelligence. This also includes “understanding that stability and security are the foundation from which prosperity is possible, and that the harder questions about who actually controls the AI supply chain”, he said.

“That means challenging bias and prejudice where it exists, and driving intelligence and security-informed thinking into the policy rooms that need it most.”

  • People & Culture
  • Risk & Resilience

Ivalua finds businesses are caught in a skimpflation sandwich, quietly trading down on quality for consumers while their own suppliers do the same to them

A new report from Ivalua, the enterprise AI platform for procurement, has found that 52% of businesses say cost pressure is driving ‘skimpflation’ in their supply chains – quietly trading down on component or ingredient quality to protect margins. In the UK, this rises to 64% – the highest of any market surveyed.

The report finds businesses are struggling to balance cost, risk and resilience. Constrained by manual processes and limited supplier visibility, the fastest route to saving is skimpflation. This is happening on two fronts: businesses are either reworking product specifications to bring the cost of goods down (59%) or switching to cheaper suppliers or goods outright (36%). The savings, however, rarely reach the consumer. Among businesses that made those changes, just 10% cut their prices, while 43% raised them and 47% left them unchanged. The result is a quiet trade-down where shoppers pay the same, or more, for products and goods made to a lower standard.

The squeeze is showing up elsewhere too, as more than half (53%) of businesses experienced delayed product launches, likely tied to supplier quality issues, poor collaboration or missed warnings of disruptions. And consumers aren’t the only victims of the scourge, as 49% of businesses are seeing skimpflation from their own suppliers.

“Skimpflation is the silent inflation. It never shows up in the headline CPI figure but consumers feel it every time something breaks sooner, wears thinner or runs out faster,” says Alex Saric, Smart Procurement Expert at Ivalua. “But short-term cost and quality decisions can conceal long-term risk. Businesses spend years building brand loyalty, then a single reformulated product or cheaper component undoes it. The firms cutting hardest today aren’t just protecting margins. They’re borrowing against their reputation, and that debt comes due the moment consumers notice the difference.”

Brittle foundations behind the squeeze

Businesses are also rethinking where they buy from as cost pressure, shortages and trade disruption reshape supply chains. Over the past year, organisations have replaced, reduced or exited suppliers across every major region, including Eastern Europe (44%), China (43%), Western Europe/UK (40%) and The Middle East (32%).

Supplier cost inflation (33%) ranks as the biggest trigger for these regional shifts, closely followed by shortages of critical components (32%) and efforts to reduce tariff and trade exposure (30%). The pressure of managing a supply base in constant flux across every major region is forcing businesses to make decisions faster than traditional processes allow.

To address this, 76% of organisations are using or experimenting with AI, with a further 14% planning to adopt it. Among those already using it, 89% say it has been effective at identifying and qualifying new suppliers and sourcing hubs. The catch is that almost half (44%) admit their supply chain data isn’t AI-ready. Until that gap closes, AI won’t fix supply chain problems, it will expose them.

“When businesses can’t see across their supply chain, cost pressure forces their hand. They cut components, switch to cheaper suppliers and hope customers turn a blind eye,” concludes Saric. “AI changes that by giving procurement teams the visibility to find savings and qualify suppliers before quality problems reach the customer. But it only works on clean, connected data. Run it on spreadsheets and scattered systems and it doesn’t surface better decisions – it just makes the wrong ones faster. Get the foundations right and businesses stop having to choose between protecting their margins and protecting their customers.”

  • Risk & Resilience

Fayola-Maria Jack, founder of Resolutiion, asks what businesses can still control when volatility hits

COVID left a permanent mark on global supply chains, from sudden operational shutdowns and force majeure claims, to labour shortages and an almost universal inability to deliver goods and services as expected. 

It was largely a capacity crisis. Businesses scrambled to keep supply chains functioning at all and many assumed it would permanently change how organisations approached resilience. Yet as the Iran conflict began to unfold in March, supply chains were once again forced to absorb new pressures while also dealing with familiar commercial tensions.

COVID vs Iran: What’s changed?

The triggers have changed, but the underlying commercial tensions have not. Cost, control, accountability, and risk transfer have remained at the centre of supplier conflict when conditions deteriorate.  

We are, again, seeing disputes around delayed deliveries, stockpiling, unilateral price increases, cash preservation and disagreements over who absorbs unexpected cost escalation. The psychology is also familiar, uncertainty makes parties more defensive, more transactional, and more focused on protecting margin and liquidity.

However, the impact of the Iran conflict is less a repeat of COVID and more an evolution of it. The pressure points are different: energy volatility, shipping disruption through key trade routes such as the Strait of Hormuz, rising insurance costs, sanctions exposure, cyber risk, and inflationary pressure are feeding directly into supplier pricing and delivery commitments.

Friction around contractual accountability is a major theme. Suppliers are increasingly seeking pricing adjustments, timeline extensions, or invoking force majeure when fuel costs, logistical bottlenecks, or raw material shortages affect delivery or performance. Buyers, meanwhile, are pushing back harder than they did during COVID and there is far less tolerance today for broad “global disruption” arguments. 

It’s also true that preparedness expectations have changed. In 2020, many disruptions were treated as unprecedented and unavoidable. Today, businesses are much more likely to ask whether a supplier should reasonably have anticipated geopolitical instability and built greater resilience into their operations. Resilience planning, alternative sourcing strategies, and geopolitical contingency measures are now commonly shaped as a demand for clearer responses to known risks. 

Visibility is another major difference. COVID exposed how little organisations understood their extended supply chains. Since then, companies have invested heavily in supplier monitoring, analytics and supply chain intelligence. As a result, disputes today are often more evidence based and commercially aggressive. Supplier claims are being scrutinised in far greater detail, particularly around cost pass-throughs, delays, and allocation of scarce inventory.

But, out of all these differences, what’s changed the most is the nature of commercial trust. COVID pushed businesses towards collaboration because everyone was experiencing the same crisis at once. The Iran conflict is much more fragmented and its impact is uneven across sectors, regions, and suppliers. It’s a key change that’s leading to more suspicion and tougher negotiation positions rather than collective problem-solving.

We are also seeing a wider shift from efficiency-focused supply chains towards resilience-focused ones. Businesses are reconsidering supplier concentration risk, geographic dependency, and just-in-time operating models. In many ways, the Iran conflict is accelerating a structural change that began during COVID: geopolitical instability is no longer an exceptional event. It is becoming a permanent commercial condition that businesses must be resilient to.

Why organisations are still caught off guard, despite past global disruptions

After any major disruption, resilience rises quickly up the board agenda. However, after a short period of adaptation, commercial pressure soon returns, pushing many organisations back towards efficiency, cost reduction, and short-term performance optimisation. 

In practice, suppliers are squeezed on pricing, inventory buffers shrink, and lean operating models reappear as quarterly performance pressures resume. True resilience requires long-term investment, cross-functional coordination, and uncomfortable trade-offs. Those are far harder to sustain without the right infrastructure.

There is also a tendency to prepare for the last visible crisis rather than the next emerging one. After COVID, organisations diversified suppliers, increased inventory buffers, nearshored selected operations, invested in visibility tools, and introduced more scenario planning. Those were important improvements. But many companies effectively strengthened resilience in ways that were highly specific to the pandemic and effectively prepared for “another COVID” rather than for a world defined by continuous and varied disruption.

Today’s risks are far more interconnected, with geopolitical, cyber, economic, and operational triggers compounding each other. However, many organisations still assess them in silos, rather than as part of a continuously shifting risk environment.

Advice for supply chain leaders going forward

The next decade is unlikely to be defined by isolated crises. Instead we can expect continuous and diverse events that trigger new instability and for disruption to become part of normal commercial operating conditions. 

Resilience therefore needs to be a leadership capability, not a logistics exercise. Supply chain leaders cannot control world politics or the economy. However, they can control the visibility they have, the quality of decisions made, actions taken under pressure, and the strength of the commercial relationships they foster. Three of the most practical strategies are:

  • Strengthening the supplier ecosystem before the crisis arrives 

Disputes happen frequently. Any organisation that suggests otherwise is simply not paying close enough attention to their delivery ecosystem. This doesn’t necessarily mean a claim, but instead an inability to find a prompt consensus on issues.

The strongest supplier relationships  are built before the crisis arrives, not during it. This means creating shared expectations early, clarifying escalation and resolution pathways, and understanding where friction is most likely to emerge if costs, lead times or delivery assumptions shift. 

  • Prioritising decision quality and speed

Success is determined less by contingency plans and more by the quality of decision-making and actions taken under pressure. When assumptions change, organisations need clear ownership, rapid escalation and the ability to assess commercial impact before delay becomes delivery failure or cost leakage. 

  • Treating commercial trust as operational infrastructure

Supply chains do not fail in isolation. They fail through weak visibility, delayed decisions, and fractured commercial relationships. For organisations to outperform during disruption they must be coordinated; able to surface conflict early, maintain trust under pressure and resolve issues before positions harden.  

Can resilience be a competitive advantage?

Businesses are no longer competing solely on product, price, or scale. They are competing on stability, adaptability, decision speed, and the strength of the relationships that sit behind delivery. Increasingly, resilience and conflict management are becoming measurable competitive advantages rather than simply risk management disciplines. 

In complex commercial environments, this is no longer built through reactive firefighting alone but through visibility, alignment, structured collaboration, and the ability to detect pressure points before they become operational or financial failures. Organisations must deploy the right processes and tools to proactively manage commercial friction, strengthen supplier and customer alignment. This will ensure issues are resolved earlier and businesses will outperform those still relying on fragmented processes and siloed communication.

The conversation is therefore shifting from “How do we survive disruption?” to “How do we outperform through disruption?” And increasingly, the answer lies in the quality, intelligence, and responsiveness of commercial infrastructure.

  • Risk & Resilience

Simon Pamplin, CTO of Certes, warns of the risks of supplier breach and how that can affect you

Many organisations still assume that once their data is handed over to a cloud provider or managed service partner, the risk goes with it. That assumption is not only wrong, it’s also dangerous. Outsourcing IT services does not mean outsourcing accountability. When sensitive information leaves your environment without strong protection, you are effectively placing your reputation, regulatory standing and customer trust in someone else’s hands. When those controls fail, as they often do, it is the data owner who ultimately pays the price.

Regulators have become increasingly clear on this point. Responsibility for protecting data sits squarely with the organisation that owns it, not the supplier processing or moving it on their behalf. Contracts, assurances and compliance statements offer little comfort once data has been exposed.

As a result, supply chain security is no longer an operational detail to be left to technical teams. It is a board level issue that affects risk, compliance, reputation and long term resilience. Senior leaders are now expected to understand where their data travels, who has access to it and how it is protected at every step.

The reality is uncomfortable but unavoidable. Risk cannot be outsourced. Services, platforms and operations can be delegated, but accountability remains firmly with the data owner. The only way to break the link between supplier failure and organisational damage is to ensure that data stays protected wherever it goes.

Why third-party breaches hurt so much

Some of the most damaging recent breaches did not begin inside the organisations that ultimately suffered the consequences. Attackers found their way in through suppliers, shared platforms or service providers that sat outside direct control. Once inside, they were able to access and extract data that belonged to someone else entirely.

Despite this, it was the data owner that faced regulatory investigation, fines, legal action and lasting reputational damage. Customers didn’t blame the supplier; they didn’t even know it existed. They blamed the organisation they trusted with their information. Boards and executives are then left explaining why sensitive data was allowed to travel unprotected through third-party environments.

The false comfort of perimeter security

A common thread in many of these incidents is over-reliance on perimeter based security. Organisations focus heavily on protecting their own networks and identities, while assuming partners will do the same. In reality, attackers rarely respect organisational boundaries. They move through supply chains, exploit weaker links and target data wherever it is most accessible.

Once data leaves your environment, perimeter controls lose their value. If the information itself is not protected, a breach at any point in the chain exposes it. This is why traditional security approaches struggle to contain the fallout from supplier compromises.

Harvest now, decrypt later is already happening

There is an additional risk that many organisations are massively underestimating. Attackers are not only stealing data for immediate use. They are also running harvest now, decrypt later campaigns. Sensitive information is being exfiltrated today, stored, and held until cryptographic advances make it readable.

This is significant because data shared across supply chains retains its importance and value over time. Financial records, personal data, intellectual property and regulated information do not expire quickly. When quantum computing capabilities mature, encryption methods that were once considered strong will no longer offer adequate protection. Data stolen years earlier can suddenly become exposed.

The assumption that quantum threats are a distant concern misses the point. The risk is not when quantum computing arrives. The risk is that the data that will be valuable then is already being collected now. Without quantum-ready, Post-Quantum Cryptography (PQC)-safe security protection in place today, organisations are building a future liability into their supply chains.

Organisations need to be looking at these PQC-safe solutions now that focus on ensuring data remains protected even against future cryptographic breakthroughs. When applied to data in motion, it ensures that information remains unreadable wherever it travels, across internal systems, cloud platforms and third-party environments.

Securing data across the supply chain

The most effective way to reduce supplier risk is to protect the data itself, rather than relying on each partner’s infrastructure. Encryption in transit, strong control of encryption keys and clear policies governing how data flows between systems are critical.

When data is protected end-to-end, a supplier breach does not automatically become a business crisis. Even if attackers gain access to systems, the information they intercept is unusable. This removes much of the incentive for the attack and dramatically reduces the impact if one occurs.

Crucially, this approach works with existing systems. Many organisations rely on legacy platforms that are difficult or costly to replace. Protecting data flows around those systems allows them to remain in use while still meeting modern security and regulatory expectations.

Another benefit of data-centric protection is reduced dependence on supplier assurances. Rather than relying on the assumption that every partner has implemented perfect security, organisations can enforce their own protection standards at the data level. This shifts control back to the data owner and reduces exposure to weaknesses outside their direct oversight.

It also simplifies compliance. When organisations can demonstrate that sensitive data is consistently protected wherever it moves, regulatory conversations become far more straightforward.

Protecting what actually matters

The lesson from repeated third-party breaches is clear. Attackers go where the data is, not where the organisational chart says responsibility should lie. Organisations that focus solely on infrastructure security will continue to be caught out by supplier failures.

Those who take a data focused, quantum-secure approach can change the outcome. Breaches may still occur, but their impact need not define the organisation. When stolen data is unreadable, reputation, trust and regulatory standing are far easier to protect.

The message is simple. You may rely on suppliers, but your data is still your responsibility. Protect it accordingly.

  • Risk & Resilience

Fraser Robinson, CEO of Beacon, digs into three of the biggest challenges facing supply chain this year

For supply chain leaders, ‘business as usual’ means one thing: ever-increasing unpredictability. It only took the first month of the year for a fresh round of Trump tariffs to land against a backdrop of ongoing geopolitical instability worldwide. While previously framed as ‘unprecedented’, this level of volatility has become routine. Month after month, year after year, uncertainty is the job.

While this uncertainty can make it hard to make specific predictions, what are some of the broader trends we can expect to shape the sector in the year ahead? And how can supply chain leaders prepare?

Targets

Supply chain targets are expected to be higher this year. Finance teams are demanding cost reductions, operations need faster delivery times and sales require guaranteed stock availability – often simultaneously. This means supply chain leaders are being asked to do more with less, while also navigating carrier on-time delivery rates that hit historic lows in 2025

Competition is incredibly high and it’s becoming even more commonplace for companies to lose customers and contracts due to late or unreliable deliveries. In particular, heightened volatility has placed greater pressure on supply chain leaders to diversify the range of suppliers they use in order to reduce reliance on a single provider and the risk this carries.

Supply chain leaders therefore need a robust understanding of carrier options, trade routes and market trends to inform how they can achieve hitting these targets. But driving tangible improvements rests on having supply chain data that is independent, unified, standardized and accurate. This allows supply chain leaders to see where money is being left on the table and where the risk lies, like what containers are regularly at risk of demurrage fees, and what business decisions can be made to improve margins and service levels. 

Tariffs

Tariffs have already been a major talking point this year. And whether by Trump (very likely) or other countries, they will be a theme we see much more of in the coming year. McKinsey’s annual survey of global supply chain leaders from December 2025 revealed that the one issue “top-of-mind” was “the potential impact of tariffs on many of the world’s most significant trade flows”, with 82% saying that their supply chains are affected by new tariffs. 

Not only are tariffs impacting trade to and from the US, but other countries and regions are striking their own set of deals to manage the change. And even when deals are struck, tariffs can suddenly change again once a goal has been met or a new dispute arises. 

In this ever-changing landscape, being one step ahead can feel like an uphill battle. But better control and insight into aggregated supply chain data, including carrier performance connected to your freight contracts, can ease this pressure by driving more informed decisions and providing supply chain leaders with confidence in their operation – you know exactly what happened. This confidence enables leaders to make decisions faster and with more clarity over tariffs. It also builds a sense of belief that they can adapt to situations and find solutions to abrupt changes. 

Conversely, if you can’t access insights such as where shipments were at what point, or the various costs of different suppliers compared against their performance history, then maintaining this confidence becomes difficult. You’re making decisions blindfolded, and that’s when tariffs can become even more of a problem. 

Technology

Supply chain leaders face a paradox – the choice of technology platforms on the market is abundant, yet procuring the wrong solution can set operations back years. With lengthy implementation timelines, high costs and integration complexity, the stakes of technology decisions have never been higher. The question isn’t whether to adopt new tech, but how to identify solutions that deliver measurable value without consuming years of implementation effort or disrupting existing operations.

The potential decision paralysis from dealing with these choices is perhaps a factor as to why tech investments are stalling (another finding from the McKinsey survey). For supply chain leaders already managing stretched teams and ongoing system implementations, the risk isn’t just the choice of the wrong platform, but also the opportunity cost of time and resources. A 12-month implementation that pulls key personnel away from daily operations can be more disruptive than the manual processes it’s meant to replace. The question becomes: what technology can integrate without requiring operational upheaval?

Most supply chains weren’t built for the power of AI. Data sits in silos, it is not standardised, technology is not connected, data isn’t kept up to date, and the infrastructure just isn’t there to take advantage of what’s now possible.

Agentic AI and advanced automation promise significant value, but if companies don’t have adequate supply chain technology that effectively unifies data and provides real-time data analytics, then new advancements like AI agents won’t. They need to be incorporated into an already highly functioning system. 

Easing the pressure

Uncertainty and disruption are part and parcel of supply chains. In the year ahead, pressure to hit supply chain targets, navigate fluctuating tariffs and invest in technology that will produce value – not further disruption – will be the key trends facing the sector. What separates leaders who navigate these pressures successfully from those who struggle isn’t necessarily budget size or team capacity. It’s decision-making speed, backed by real-time, unified data.

Can you answer critical questions in minutes rather than days? When tariffs shift, can you immediately assess the impact on in-transit inventory? When targets tighten, can you identify which suppliers or carriers are underperforming? When evaluating new technology, can you distinguish platforms that integrate quickly from those requiring multi-year implementations?

This doesn’t require ripping out existing systems or embarking on transformation projects that consume years. Instead, it requires connecting the data that already exists but currently lives across fragmented carrier portals, forwarder spreadsheets, and email threads. The pressures aren’t going away – but the clarity needed to navigate them is achievable.

  • Risk & Resilience

Why upstream volatility is no longer abstract for design and procurement teams

If you feel like you’re paying more for your electronic components, you’re not imagining it. Thanks to upstream pressures, rising prices for key commodities used across electronics and manufacturing are filtering down into everything from copper-heavy printed circuit boards (PCBs) to metal-backed passives. Here, Chris Withers, sales director at Zel Components, an alternative electronic parts supplier, explains how engineers can respond more quickly to market volatility. 

On the London Metal Exchange (LME), copper reached record territory in early January 2026, pushing above $13,300 per tonne. That’s more than 20% higher than the late 2025 average as stock tightness and strong industrial demand combined.

That matters because copper isn’t just a metal you read about in commodity news. It’s used extensively in printed circuit boards, internal connectors and wiring, as well as across many power and signal paths in electronics. As a result, movements in copper pricing directly influence the cost of the boards and assemblies engineers design and build. 

Precious metals are also impacting pricing dynamics. Gold recently surged above $5,000 per ounce, reaching a series of record highs in the first few weeks of 2026 amid market volatility and safe-haven demand. While gold isn’t in every bill of materials, it’s used in contact plating and specialist components where performance meets reliability.

Likewise, aluminium has traded firmly above $3,000 per tonne on global benchmarks and is forecast to remain well supported given current market dynamics. Even when commodity analysts suggest prices might ease later in the year, the near-term story is volatility, which introduces risk.

When inputs move 

Engineers regularly buy copper foil, laminates and boards priced off copper’s movement. Over 2025 and into 2026, manufacturers of copper-clad laminate — the base material for almost all FR-4 boards — began issuing public price adjustments directly linked to rising raw materials. 

Some supplier notices describe increases of up to 30% across all thicknesses of copper-clad laminate and prepreg, driven by higher copper prices, glass cloth costs and processing expenses. 

This is the kind of upstream movement that doesn’t stay upstream. It filters through every layer of a PCB quotation, especially in multi-layer designs where copper and prepreg content is higher. 

The wider passive component landscape tells a similar story. Industry analysis shows price increases across capacitors, inductors, ferrite beads and related passives. These range from single digit to double-digit percentages for early 2026 deliveries, often citing metals and process cost inflation among the drivers.

 This doesn’t mean you should panic buy every part in your current bill of materials (BOM). However, it does mean that the old “wait-and-see” strategy is getting riskier, particularly if you’re dependent on a single branded source for key sections of your design.

Alternative sourcing

Second sourcing is moving back into focus, not as a cost-cutting exercise but as a form of risk management. Pin-for-pin alternatives, for instance, allow engineering teams to maintain electrical and mechanical compatibility while reducing dependence on individual manufacturers, whose pricing or lead times may be more exposed to raw material volatility.

This approach is particularly effective for widely used regulators, discretes, interface devices and passives, where functional equivalence is well understood and validation cycles are manageable. As volatility increases, having approved alternatives already mapped can significantly reduce disruption when prices shift or allocations appear.

When suppliers combine local stock with extended inventory and effective cross-reference tools, response times improve. During a time of uncertain input costs, that flexibility is as valuable as unit price, provided performance remains consistent.

Prices might ease at some point, but it’s difficult to predict when. Volatility isn’t going away, and when raw material costs feed into electronics pricing, it’s the teams that design and source with flexibility in mind that are better positioned to respond when conditions change. 

  • Risk & Resilience

The appliance company has overhauled its entire UK and Ireland logistics operations

Global home appliance business, Versuni, known for iconic brands including Philips, Saeco, and L’OR Barista, has successfully completed a major overhaul of its UK and Ireland logistics operations, boosting performance, resilience, and readiness for growth. 

The project, managed by global supply chain and logistics consultancy SCALA, saw Versuni transition its UK and Ireland 4PL operations to a new third-party logistics (3PL) provider. The transition was designed to strengthen Versuni’s service capabilities in the UK and Ireland, simplify logistics management, and improve reliability across B2B, ecommerce, and retail channels. The new arrangement offers a seamless, scalable solution well aligned with Versuni’s future growth plans.

With no UK-based supply chain team, Versuni enlisted SCALA to coordinate planning, stakeholder engagement and integration with its SAP systems environment.

The new 4PL solution is based at a shared-user facility in Kettering, where more than 7,000 pallet spaces are reserved for Versuni products. The facility provides a full range of services, including import receipt and checking, retail order picking, direct-to-consumer fulfilment, returns and reverse logistics, and transport coordination with proof-of-delivery management.

Bartosz Gruszczynski, Senior Warehousing & Distribution Manager, Europe, at Versuni, said: “The UK and Ireland are strategically important markets for Versuni and our brands. It was vital that this transition improved service levels without compromising operational continuity.

“Through strong collaboration with SCALA and our new 3PL provider, we achieved a seamless handover. The result is a more robust, reliable logistics approach that gives us the confidence and capacity to grow in the region.”

The project ran from September 2024 to April 2025. Within the first month of go-live, 95% of orders were successfully delivered, demonstrating the smooth transition between providers. 

Phil Reuben, Executive Director at SCALA, added: “This project highlights what can be achieved with clear goals and a collaborative approach to delivery. We’re proud to have supported Versuni and its brands in building a logistics solution that is fit for the future – and already delivering measurable improvements.”

With the project now complete, Versuni has not only streamlined its operations but enhanced the service experience for customers of its much-loved brands. The strengthened UK and Ireland platform ensures greater scalability, visibility, and control, setting the stage for further growth across retail and ecommerce.

  • Risk & Resilience

Expert feedback says retailers are unprepared for Extended Producer Responsibility (EPR) rules around packaging

Josh Pitman, Managing Director at sustainable packaging firm Priory Direct, has warned that retailers are unprepared for Extended Producer Responsibility (EPR) rules around packaging, for which fees went live in October, with the firm fielding hundreds of customer queries. 

EPR fees came into play from 1 October for ‘large’ producers including many affected retailers and Pitman, whose firm supplies planet-friendly packaging to more than 21,000 businesses, says: “The retail sector is simply not prepared for this shift in how their packaging data needs to be reported, and the fees payable based on weight, material and recyclability of packaging. This is particularly true of the ‘majority middle’, or those that fall just over the threshold. 

“We know this because for many weeks, we’ve been dealing with between five and ten queries daily from our customers on our website chat function and directly to account managers. Many of these are basic questions like: does EPR apply to them, what data do they need to share, where do they get this from, and how do they reduce exposure to it? These are all basic but critical details that should have been established months ago, as reporting requirements have been in play since 2023. 

“However, there appears to be a lack of clear, helpful guidance and limited proactive engagement with affected businesses from government, aside from some overly exclusive and expensive events featuring official spokespeople. Knowledge of how to navigate EPR is being firewalled by companies looking to profit from guiding larger clients through the change when, for it to make the most impactful change, the government should be providing clearer, more-open-access guidance on how to use this legislation to actually make a positive improvement to the impact of their business.” 

He adds: “This means it is falling to the private sector to give practical support to retailers, who are seeing headlines like John Lewis revealing a £22 million cost through EPR and are rightly concerned. Without this support, these businesses would struggle to respond to EPR legislation and – what is most crucial – adopt more sustainable packaging choices to limit their exposure to the fees. Otherwise, there is a real risk that business will simply absorb the fees rather than do what EPR is designed to achieve, which is to spur a switch towards more environmentally friendly packaging.” 

Extended Producer Responsibility has changed the way UK organisations responsible for packaging must carry out their recycling responsibilities. For the purposes of EPR, packaging is defined as any material that is used to cover or protect goods that are supplied and that makes handling and delivering goods easier and safer. It includes anything that’s designed to be filled at the point of sale, such as a coffee cup. This definition encapsulates a wide range of businesses including many retailers.  

‘Producers’ are defined as either ‘small’, with annual turnover above between £1 and £2 million and importing or supplying 25 to 50 tonnes of packaging, or ‘large’, with a turnover above £2 million and importing or supplying more than 50 tonnes of packaging. Both small and large producers must report their packaging data, but currently only large producers need to pay fees. These producers will have received their very first invoice – or Notice of Liability (NoL) – this month, October 2025. 

Pitman concludes: “This is a real opportunity for all retailers to minimise their exposure to EPR by switching to more sustainable alternatives. The cost of these alternatives is, in the majority of cases, the same or lower, as well as incurring lower EPR fees, and such steps also help to reduce the overall environmental impact of these retailers. This is a positive move at a time when legislative and consumer pressures on retailers around ESG are growing. With clearer, more practical guidance for those affected, EPR is the carrot that could make a dramatic difference to retailers’ impact on the planet.” 

  • Risk & Resilience

Recent global challenges have elevated the supply chain leader to the executive suite, reflecting a fundamental shift

Over recent years, the chief supply chain officer (CSCO) role has undergone a profound transformation, particularly in sectors where supply chains are mission critical such as consumer goods, industrials, healthcare, and pharmaceuticals. What was once considered a technical or operational function has evolved into a driving force behind enterprise strategy.

This evolution has been accelerated by a series of global disruptions, most notably with the COVID-19 pandemic. Nobody needs to be reminded of the deep vulnerabilities the crisis exposed across supply chains worldwide; practically overnight, a rapid reconfiguration of how supply chain leadership was structured and empowered became critical. Combined with ongoing geopolitical instability, regulatory pressures, and rising stakeholder expectations, the signs are clear: the CSCO is now essential to competitive advantage.

In response, companies are recalibrating how they staff and support their supply chain leadership. Since January 2023, 36% of the world’s largest publicly listed firms have appointed new CSCOs. These changes signal a broader rethinking of what the role entails, and who is best positioned to lead it.

From functional specialist to strategic architect

The growing scope and complexity of the CSCO role is matched by a corresponding rise in enterprise influence. Once focused primarily on cost and efficiency, today’s CSCOs must also navigate a broader landscape that includes sustainability, digital transformation, risk mitigation, and resilience.

Through conversations with seasoned supply chain executives worldwide, it is evident that the CSCO role has been evolving for some time, predating the pandemic, and has accelerated significantly in recent years. Whereas the role previously encompassed a limited set of priorities, it now spans a broader spectrum, including sustainability, digital transformation, and agility.

Within this expanded context, CSCOs are increasingly redefining their role – not as operational enablers or as executional support, but as strategic architects of enterprise value. They now sit on executive committees, report directly to CEOs, and maintain regular access to the board. In other words, boards are now much more open to the transformative power of a CSCO.

Why elevating the CSCO role matters

·       Strategic alignment and faster execution
The CSCO serves as a vital link between business strategy and operational delivery. With many peers on the leadership team coming from commercial backgrounds, the CSCO’s operational acumen offers a crucial balance, ensuring initiatives translate into results.

·       Increased agility in a volatile world
CSCOs are typically first responders when crises strike. Their ability to make rapid decisions—on everything from product line adjustments to supplier realignments—is enhanced when they have a seat at the top table.

·       Talent magnetism

Elevating the CSCO position boosts its attractiveness to emerging leaders. By investing in career paths, leadership development, and visibility, some organisations are turning supply chain functions into high-potential talent pipelines.

The enterprise-centric CSCO

Today’s CSCOs must operate as business leaders first, and functional experts second. While many still come from traditional supply chain backgrounds, companies are increasingly prioritising broader business acumen, seeking candidates with commercial, P&L, or transformation experience. This shift reflects the growing need for CSCOs who can contribute strategically, anticipate regulatory and geopolitical risks, and lead complex, enterprise-wide transformations.

Equally important is the CSCO’s ability to manage a widening network of stakeholders. From peers and boards to regulators and suppliers, today’s supply chain leaders must translate operational complexity into strategic clarity. Their success now depends as much on influencing and communication as on technical mastery, marking a decisive evolution from the function’s historically executional role.

Rethinking succession and talent pipelines

Despite the strategic elevation of the role, there will always be turnover at the top, and many organisations still lack robust succession plans for CSCOs. This is especially concerning given the relatively short average tenure of a little over four years and a high rate of first-time appointments: in 2024, 65% of external CSCO hires in 2024 were step-ups.

To avoid setbacks caused by a gap in the CSCO function, succession planning must be reimagined across three key dimensions:

Future-focused profiles: Companies must define the CSCO role based on future needs.

Tailored development programs: Internal talent development is increasingly crucial.

Detailed, proactive planning: Organisations must develop data-driven, scenario-based succession plans.

The road ahead

The COVID-19 pandemic may have accelerated the shift, but the strategic ascent of the CSCO is not a short-term response – it is a long-term evolution. As companies face continued disruption, increasing complexity, and stakeholder scrutiny, the CSCO is emerging as one of the most consequential roles in the C-suite.

It’s all about flexibility and resilience. Speed of change has massively increased, and the size of those changes is becoming bigger. Organisations that invest in the right leadership, redefine the capabilities required, and reimagine succession planning will be best positioned to not only manage uncertainty, but to turn it into a strategic advantage.

To learn more, please visit www.heidrick.com

  • Risk & Resilience

Richard May, director of product development at virtualDCS, on navigating cyber regulation, assessing risk, and building digital resilience in a cloud-first financial landscape

In 2025, financial services are deeply reliant on digital infrastructures. Cloud services, especially, are reshaping how the sector operates.

The cloud offers both established and challenger companies the ability to improve flexibility, efficiency, and analytics capabilities. When deployed properly, it can deliver integrated security across an organisation, but also introduces new vulnerabilities.

Due to the sensitive nature of financial data, the sector remains a target for cyberattacks. This, combined with strict regulatory oversight, means firms must continuously align with evolving legislation while enhancing service functionality.


Which regulations do financial services need to be aware of?

There are several specific regulatory requirements that financial institutions must follow. These pieces of legislation are designed to ensure customer data is protected from attackers:

Payment card information and PCI-DSS

For businesses that handle payment card information, PCI DSS requirements dictate security and operational requirements for protecting cardholder information during storage, processing, and transmission. In practice, these requirements are 12 mandatory security controls that cover network security, data protection, vulnerability management, access control, monitoring and logging, physical security, testing, and policy enforcement. Failure to comply with the 12 security controls can lead to severe financial penalties and even liability for compensation costs.

GDPR implications

GDPR regulations categorise financial data as sensitive personal data. This refers to bank details, transaction histories, assets, credit scores, and anything else that might concern the overall financial health of an individual. Firms must take measures to prevent unauthorised access or risk facing fines.

Basel III considerations

The third Basel Accord, Basel III, sets the international standards for capital requirements, stress tests, liquidity regulations, and leverage. It is designed to reduce the risks of phenomena such as bank runs and bank failures, as we saw in the 2008 financial crash. Due to this, most of Basel III focuses on financial requirements such as liquidity to ensure banks are more resilient to changes in the international financial markets. However, it still communicates standards in relation to information and communication technology (ICT),‍ cyber incident response and reporting, and‍ third-party risk management (TPRM).

Digital Operational Resilience Act (DORA)

Introduced in January 2025 by the European Union (EU), DORA addresses rising digital dependency in finance. It covers ICT risk management, third-party oversight, operational resilience, incident reporting, and information sharing.

Compliance with these regulations is essential. Beyond avoiding penalties or criminal charges, it strengthens protection against growing cyber threats.

Assessing Vulnerability and Risk in the Financial Services Industry

Risk assessments are critical to business continuity and reducing the impact of cybersecurity breaches. A task of identifying threats and vulnerabilities, and quantifying the consequences of threats if they were to materialise, enables firms to rank services and ensure the most critical systems are protected first.

The Financial Services Information Sharing and Analysis Center (FS-ISAC) identified several key threats to the global financial sector in its latest report, including: 

Supply Chain Incidents

Businesses should remain alert to the competencies and overall security of service providers they utilise. As reliance on external providers is increasingly integral to many core business strategies, firms cannot afford to overlook the cyber maturity of their partners. To mitigate potential security risks, organisations should ensure and verify that all service providers meet robust cyber-security standards.

Fraud

The universality of real-time payments has led to a surge in fraud action in all sectors for which financial channels and services are used. The immediacy of payment has also created a scenario where it is almost impossible to retrieve stolen funds. Online scammers are building complex operations to take advantage of this. Fraud prevention and detection are becoming more and more important to companies in the sector. Increasing friction for payments through two-factor authorisation, along with other strategic obstacles, reduces fraud risks. Without cross-border partnerships tackling this global issue, however, this is set to remain a growing threat for businesses.

Ransomware

Ransomware has long been a cybersecurity threat. Many victims are often opportunistically targeted by hackers, rather than chosen specifically. Incidents of spear phishing are also on the rise – attackers research individuals or organisations to create personalised messages to convince them to click on infected links. Creating barriers to stop or delay ransomware attacks is therefore essential to reduce the threat. Ransomware’s targeting of customer data also means detection and recovery protocols are critical for firms that want to reduce the threat from malicious actors.

Distributed Denial-of-Service

The FS-ISAC revealed that financial services accounted for a third of all distributed denial-of-service (DDoS) attacks in 2023. DDoS attackers bring down an area of a network or application and extort the affected organisation for financial gain. Motivations may also include political statement-making, competitor sabotage, and cyber vandalism, simply to cause chaos and disruption. The increasing use of application programming interfaces (APIs) in the sector means that denial of service can have a devastating effect on financial service businesses. Firms should implement mitigation strategies to protect customer trust and service availability. 

When, Not If: Building Cyber Resilience Through Disaster Recovery

While cybersecurity defences are essential, effective disaster recovery is vital to reduce the impact of incidents and maintain operations.

Speed of recovery has become the main point of difference for organisations attempting to recover from cyber incidents. Prolonged downtime can lead to reputational damage, regulatory penalties, and lost customers. Without effective disaster recovery, continuity efforts are undermined.

Firms should develop a ‘when’, not ‘if’, mindset when it comes to disaster recovery. A comprehensive disaster playbook provides a manual in the event of a cyber incident. This plan must incorporate tools to allow for early detection of malicious action. Your plan for disaster recovery should be printed as a hard copy or saved on an external device (to ensure it remains accessible if your primary system is compromised). It must consider the first steps of: documenting evidence for cyber insurance and law enforcement, identifying and isolating infected systems, and informing relevant stakeholders an attack has taken place. Furthermore, the plan should contain information around communication and key contacts, an agreed chain of command and designated person to lead the ransomware response, and assurance the plan comes under regular review with ‘fire drill’ rehearsals.

Financial institutions face some of the most severe cyber risks in the world. Abiding by regulatory requirements goes some way to protect against threats, but organisations must go further – by proactively assessing threats, incorporating security measures, and preparing for disruptions. Resilience isn’t just about avoiding breaches. It is about ensuring trust, safeguarding sensitive data, and maintaining the ability to deliver reliable services in a digital-first landscape.

Learn more at virtualDCS

  • Cybersecurity in FinTech
  • Risk & Resilience

Fraser Robinson discusses the challenges threatening supply chain planning, why visibility isn’t enough, and what being future-ready means

It’s safe to say it’s been a particularly turbulent time for the global shipping and logistics industry. Disruption is ever more frequent and unpredictable. Geopolitical conflicts, tariffs, major climate events, and economic uncertainty all require constant attention and adaptation.

In just one week, the US and Japan struck a trade deal at the same time as the EU set out plans to match the US’s tariffs of 30% – the latest in a wave of rapid policy changes that continue to reshape global trade. Between October 2023 and October 2024, G20 countries introduced 91 new trade restrictions affecting over $828 billion in goods, more than triple the value seen the year before. These frequent tariff changes, with some being as large as they are too, will impact anything from freight costs to route selection and sourcing strategies.

Regarding sustainability, regulations to limit Scope 3 greenhouse gas emissions and safeguard marine ecosystems can require adapted routes to increase efficiency and avoid protected areas. In April, for example, the International Maritime Organisation approved new net-zero regulations for global emissions, aiming to reach the target by 2050. 

All of this shows how quickly tides can change – and why having real-time visibility over carrier shipping routes, freight rates and logistics is integral to being able to adapt just as fast. But visibility alone isn’t enough. When disruption strikes, teams need to act quickly – and relying on back and forth emails and spreadsheets won’t cut it.

Supply chain managers are in real need of digital tools that not only unify their data, but also enable real-time collaboration and seamless communication with partners across the network. Improving the speed and the accuracy of the decision making process.

The unpredictability of the modern supply chain

Tariffs can bring major changes to shipping trends and patterns. But they’re far from the only source of unpredictability. The climate crisis is triggering more damaging and widescale events that can cause disruption in the blink of an eye. A recent NASA study left researchers “amazed and alarmed” at just how sharply the rise in the frequency, length and severity of extreme weather events like floods and droughts has been in the last two years. So, it’s integral to build and evolve supply chains that are able to withstand these unprecedented changes.

Then you have a range of other factors like port congestion, labour disruption and emerging tech risks, which can all heighten unpredictability. For example, the number of parties involved in a shipment leaves the supply chain susceptible to cyberattacks such as ransomware, where cybercriminals lock down systems until they are paid a ransom.

If just one supplier suddenly can’t make a delivery as their internal systems are frozen, then shipping carriers, ports and warehouses all need to adapt to new schedules and orders to maintain operational efficiency. Not to mention the impact of cashflow from stock outs.

The (massive) need to go digital

Naturally, trying to coordinate across a global network of carriers, suppliers, warehouses and customers can be time consuming and chaotic. Spreadsheets and emails are still widely used in supply chains to organise shipments and communicate – but this creates fragmented processes, a sea of data silos and a lack of real-time coordination. No wonder 86% of operations leaders in a PwC survey said their company needed to invest in better tech to track and measure supply chain risk.

With disruption never far from shore, every partner in a supply chain needs access to the same real-time picture of moving goods. By tracking freight and providing automated alerts for any shipment disruptions or delays that take place, the latest digital platforms can display all relevant logistics data and shipping documents on a live tracking dashboard, and these dashboards are easily shareable via a link to every stakeholder.

Not only does this allow stakeholders to view and spot risk sooner, but it brings together every supply chain partner into one location. In turn, this makes it easier to triage issues and coordinate action plans to maintain the flow of goods. For example, it makes it simple for parties to confirm and share cargo ready dates with suppliers and forwarders, or resolve issues in an embedded chat. And by receiving timely notifications, supply chain professionals can act quicker to mitigate the negative impact of delays and disruptions.

Weathering future storms

The unification of data and communication is not only about firefighting immediate disruption. These capabilities are integral to taking a wider view and forming resilient supply chains that can weather the unpredictable and changeable nature of the industry. We need more advanced methods for measuring metrics like carrier performance and emissions and then using this data to optimise routes and reduce factors like demurrage and detention costs.

Are there ways to understand the frequency and severity of delays by carriers? How about understanding which carriers and forwarders are delivering the quickest, most reliable service? The monitoring of data over time can provide the answer to such questions. Supply chain managers can build ETA accuracy reports, for instance, that compare initial ETAs against ATAs. They can benchmark transit times and accrue objective performance insights that inform decisions about choosing suppliers and routes and ports. It all comes down to having data in one place that can be analysed by AI and provide key, and complex insights.

Of course, there is also an increasing onus on balancing performance with sustainability.

Carbon reports can analyse crucial metrics like distance, vessel and carrier to paint a clear picture of the carbon impact of each shipment. By understanding this impact for different routes and carriers, supply chain managers can make much more informed and sustainable choices when planning their routes. And with consumer and regulatory scrutiny set to intensify, the ability to be transparent through carbon reporting can increase trust and brand reputation.

Disruption is becoming more of a normality in supply chains – it’s something that is predictable. What supply chain professionals can’t predict is what that disruption will look like and where it might come from. As with anything in the modern world, data and communication are crucial to responding quickly to these events as well as implementing changes that improve the overall resilience of supply chains – and choosing sustainable options is generally choosing more reliable ones too.

More turbulence will come, and digital solutions offer the best route for keeping goods and shipments sailing through the storm.

John Santagate, Global Senior Vice President of Robotics at Infios, delves into the challenges tariffs pose.

Successful supply chains have always been measured by how well they deal with complexity. Getting deliveries and returns right requires multiple levels of collaboration, information sharing and strategic decision making to reduce the risks of confusion or delays. In tandem, customer expectations have changed. Expedited deliveries and a smooth returns process are now intrinsically linked to a positive customer experience. Amongst US consumers, cost, transparency of shipping and flexibility and ease of returns, including real-time tracking, are now the leading delivery preferences.  

With seamless buying experiences now standard, pauses in supply chain execution have major consequences for customer loyalty and brand reputation. This is particularly damaging at a time when every pound is crucial. Beyond driving cost efficiencies, enhanced speed and resilience are now equal parts of the supply chain challenge, and retailers must get this process right to succeed.

Even if brands understand that resilience is key, achieving this is another matter entirely. The volume and regularity of significant supply chain disruptions have tested the resilience of even the strongest supply chains. Organisations continually reevaluate the processes they have in place to ensure goods continue to reach customers. 

Global impact of tariffs

Political upheaval, global conflicts and the introduction of trade tariffs have driven six months of unprecedented global supply chain uncertainty. It’s estimated that the economic impact of the tariff disruption alone could reach as high as $1.4 trillion globally. Ongoing tensions have destabilised established supplier relationships and created uncertainty in the cost of products and materials. Beyond costs, businesses face increased uncertainty in product availability and financial planning, adding further obstacles to already complex operations.

2025 was a fundamental milestone in supply chain strategy. Single region sourcing and rigid inventory management are rapidly fading. In its place, diversification in sourcing and real-time adaptability have become more important than ever.

At its base, for retailers, navigating the evolving tariff environment is about maintaining customer satisfaction. Organisations have opted to move manufacturing of products to new markets. Others have used previous pauses in tariff implementations, and regular legal challenges, to try and ‘time’ tariff implementations and activate previously budgeted activity at the optimum period.

Among these changes, a question has emerged – in a world that is now defined by constant tariff uncertainty, where can technology help to establish a new, more resilient approach to supply chain execution?

Does forward buying help?

Forward buying of inventory has become the most common response to tariff-inspired uncertainty, as organisations aim to maintain product levels and meet customer demand. In the short term, some stability has been achieved. Organisations have been able to maintain existing purchasing and pricing strategies and the flow of goods. Over the long term, however, this strategy carries risks. In fast moving industries, like consumer goods, demand can be linked to virality. Trends can die as quickly as they begin, increasing the risk of product redundancy. Falling demand already costs even the smallest retailers as much as £10K per year. Over the long term, tariff uncertainty will continue to disturb the balance between purchasing and investor management and could cause costs to spiral. 

Staying future-ready requires businesses to enhance preparedness. Streamlining operations and building real-time visibility are an important step. As peak season planning picks up, many organisations face uncertainty around how to manage procurement and ordering in a way that minimises waste and inefficiency.

Integration of supply chain technologies, like order management (OMS) and warehouse management (WMS), provide real-time visibility across customer demand, supplier delays, and order status. Live, up-to-date information empowers teams to proactively manage and optimise supply chain operations, reducing bottlenecks and maintaining overall efficiency.

Making technology-powered decisions

The current tariff environment has also reduced the decision-making window. Taking a painstaking approach to sourcing goods and materials was once common practise. The current environment, however, necessitates companies to pivot on short notice. The announcement of any new policy or tariff could inflate costs to an unsustainable level. The ability to effectively source alternative suppliers, in markets with smaller tariff restrictions, or being able to re-route products and amend production timelines, has become a focal point of success.  

This level of decision making requires the practical application of data. Predictive analytics are a powerful tool that organisations can use to understand when costs might rise, or delivery delays could happen. Real-time dashboards mitigate supply chain disruption and provide informed and expedited decision making. Businesses can monitor changing global developments; assess potential risks to their own supply chain processes and act in a greatly reduced timeframe. Traditionally, these planning cycles may have taken place on a quarterly basis. Today, data analytics tools mean pivots can be made in days or hours. The impact of this cannot be overstated, building resilience against disruption alongside a wider competitive advantage. 

It is safe to say that disruption isn’t going away. Whilst tariffs undoubtably pose challenges, the opportunity for organisations to use this period for fundamental business change is clear.  Technology can build stronger supply chain processes and speed up real-time decision making. Not only will this improve responses to tariff-based disruption, but ultimately it will improve the ability for businesses to meet customer expectations, which remains the end goal. 

  • Risk & Resilience

Evan Shelley, Co-Founder and CEO of Truck Parking Club, digs into the issues caused by the truck parking problem.

When people talk about the most pressing issues in the US supply chain, they mostly focus on port congestion, labour shortages, or last-mile delivery challenges. Rarely do they mention truck parking. But as someone who works at the intersection of transportation and real estate, I can tell you that without a doubt: the lack of safe, accessible truck parking is one of the most overlooked threats to supply chain efficiency today.

At Truck Parking Club, we’ve spoken with tens of thousands of truckers and have seen the mounting frustration they experience trying to find legal, reliable parking near their routes.

In fact, on average, truck drivers lose nearly an hour each day searching for a spot to park. That may not sound like a huge issue – until you multiply it by hundreds of thousands of drivers, every day, across the country.

The result: an estimated $7,000 in annual lost income per driver. These delays impact everything from delivery timelines to detention costs and warehouse coordination. In short: they affect the supply chain.

A crisis hidden in plain sight

For every 11 trucks on the road, there’s only one available parking space. This imbalance leads to a ripple effect: drivers park in unsafe or unauthorized areas, are forced to shut down early to secure a spot, or violate hours-of-service rules trying to find parking closer to their destinations. In turn, this leads to supply chain slowdowns, missed delivery windows, and added costs for manufacturers and logistics providers alike.

The truth is, truck parking isn’t just a driver inconvenience – it’s a logistics bottleneck that affects everything downstream. For manufacturers dependent on ‘on-time delivery’, even a small parking-related delay can throw off timelines and impact inventory flow.

Why it matters to supply chain leaders

Manufacturers and supply chain executives might not think about truck parking when evaluating risk and resilience, but they should.

Every inefficiency in freight movement adds cost, and right now, we’re paying the price for decades of underinvestment in infrastructure that supports the flow of goods.

And – you probably guessed it, because it’s obvious: the challenge isn’t going away. With new construction of truck parking spaces costing $100,000–$200,000 per spot and often taking years to develop, there’s no fast fix on the horizon. This means the burden of solving this issue is increasingly falling on the private sector and logistics decision-makers themselves.

What can be done

Innovative solutions are emerging. For example, at Truck Parking Club, we’re addressing the issue by helping landowners and businesses monetize underutilized real estate as truck parking, turning extra space at trucking companies, tow truck companies, truck repair shops, self storage facilities , and other properties into bookable parking spaces that truckers can reserve instantly. This model rapidly increases parking availability without the multi-year construction timelines.

For carriers, logistics companies, and fleet operators, partnering with solutions like ours can yield measurable benefits: more efficient hours driven, reliable scheduling, improved driver retention, and safer working conditions for the drivers you depend on.

A call to action for industry decision-makers

As the supply chain continues to evolve in the wake of e-commerce growth and shifting demand patterns, we can’t afford to ignore foundational infrastructure gaps like truck parking. Leaders in transportation and logistics need to include parking in their budgeting, risk assessments and strategic planning.

That might mean advocating for policy changes, or exploring alternative parking solutions like Truck Parking Club to complement existing facilities. But at a minimum, it means recognizing that your delivery network doesn’t just rely on trucks – it relies on a place for those trucks to stop, rest, and refuel along the way.

Truck parking is no longer a fringe issue. It’s a strategic vulnerability that deserves a seat at the supply chain strategy table. And the sooner we treat it as such, the better equipped we’ll be to build a supply chain that’s not only faster, but stronger, safer, and more reliable for everyone involved.

  • Risk & Resilience

Eelco van der Zande, Managing Director of ReBound Returns, helps navigate the issues caused by tariffs.

Rapid changes in global trade policy are creating serious challenges for businesses operating across borders. With tariffs soaring one day and easing the next, retailers are being forced to rethink how they handle international returns in real time.

Fluctuating import duties imposed by the US have at times exceeded 145%, and retaliatory measures from key trade partners have thrown global supply chains off balance. Even with the most recent truce reducing US tariffs on China to 30%, there’s no guarantee these figures will hold. As of  June, 2025, US trade policy remains fluid, with ongoing negotiations reshaping tariff structures across multiple regions, including Europe and Asia. President Trump has noted that some levies have been suspended- not cancelled – and may rise again within months.

Adding to the uncertainty, twelve US states have filed a lawsuit in the Court of International Trade, seeking to halt to the “Liberation Day” tariffs. A US appeals court has allowed the tariffs to remain in effect while it reviews their legality.

The new risks of cross-border returns

Amongst the ambiguity, international returns are now under intense scrutiny. With each item crossing a border potentially attracting new tariffs, returning products for restocking has become costly. When an item crosses a border twice- first for sale, then for return- and possibly a third time for resale, retailers face multiple layers of duties and fees. A t-shirt sold internationally could now incur fees exceeding its original retail value. This makes it more important than ever to evaluate every return for cost-efficiency and logistical feasibility.

Volatility also makes forward planning difficult. Retailers can’t afford to be reactive; returns systems must be agile, localised, and data-driven to navigate the shifting conditions. Strategic returns management is key to future-proofing reverse logistics against unpredictable tariffs.

Localising and consolidating returns to minimise costs

One of the most effective ways to reduce tariffs exposure is to localise returns processing. Keeping returns in the country where they were purchased allows retailers to avoid costly re-importation. Processing and storing products at local returns centres and re-fulfilling them to new customers in the same region can save on shipping and duties. Repurposing items through alternative channels can also reduce costs.

Consolidating returns into fewer, larger shipments rather than handling them individually can significantly  cut logistics expenses. Using regional return hubs to group items before further processing or redistribution reduces transportation spend and carbon footprint. This local-first approach not only limits fuel consumption and emissions, but also supports a circular economy by keeping goods in-region. As ESG expectations rise, aligning reverse logistics with sustainability goals becomes a competitive differentiator. This optimised, local approach enhances efficiency and makes cross-border returns more sustainable and financially viable at scale.

Faster returns to reduce inventory lag

With tariffs driving up inventory costs, time has become a critical cost factor in returns management. Every day a returned item sits idle or in transit is a day of lost revenue and tied-up capital. Slow processing delays resale and undermines profitability in an already margin-sensitive environment.

Retailers must accelerate returns processing to reduce inventory lag. That means quickly assessing, sorting, and restocking products. Fast triaging, localised warehousing and agile reverse logistics can shave days or even weeks off the cycle, improving inventory turnover and unlocking working capital. In practice, faster processing can significantly increase recovered revenue from returned goods.

Smarter and fewer returns through better data

As tariffs raise the cost of goods, each return, especially the avoidable ones, become more expensive. Retailers that harness return data across their operations can turn unpredictability into strategic insight. This requires integrating data from multiple sources into a unified view, enabling more accurate demand forecasting, better inventory planning, and identification of products that are driving unnecessary returns.

Leading retailers are also using AI-powered platforms to anticipate which items are most likely to be returned and to automatically route them to the most efficient return locations. These systems integrate seamlessly with order and warehouse management tools, reducing cycle time and cost.

Data insights can also reveal deeper patterns, such as size discrepancies, product quality issues, or customer behaviour trends, that are contributing to high return rates. Addressing these issues through refined product descriptions, size guidance, and customer education expectations better can lead to measurable reductions in returns.

Even modest drops in return rates can yield significant savings when margins are tight. Smarter use of data enables faster, more informed decisions, and stronger profitability.  

Seamless returns to build customer loyalty

The increasing complexity of cross-border returns hasn’t slowed rising customer expectations. Shoppers are less forgiving of a clunky or slow returns process, especially when tariffs mean they have paid more or waited longer for their purchase. A seamless experience with fast, easy, and transparent return options is crucial.

Retailers that offer convenient local drop-off points, clear communication, and flexible refund or exchange options are far more likely to retain customers and drive repeat purchases. Quick refunds help preserve brand loyalty, even amid pricing pressures and economic uncertainty.

Retailers that prioritise returns optimisation have seen measurable improvements in customer retention and the frequency of repeat purchases. A great returns experience doesn’t just mitigate risk, it builds trust, strengthens brand reputation, and turns a potential point of friction into a loyalty driver. 

Adapting returns strategies for a shifting tariff landscape

When tariffs can rise or fall overnight, international returns must be treated as a strategic function, not just a back-end process. They directly impact margins, sustainability, and customer loyalty.

Retailers that embrace smarter returns management with localised, streamlined processing, better data insight, and seamless customer experiences will be best positioned to weather ongoing volatility.  To get ahead, retailers should consider conducting a full audit of their current returns operations, identifying gaps in localisation, speed, and tech adoption. Investing in smart logistics infrastructure today can unlock major savings and build long-term resilience.

  • Risk & Resilience

Jorge Aguilar and Andy Prinz, supply chain experts at PA Consulting, discuss shapers vs. stallers.

Volatility isn’t a shock to the system anymore – it is the system. Supply chains are absorbing more disruption than at any point in modern history, yet still expected to deliver flawlessly. Logistics lanes are being re-routed by international conflicts, cyber incidents, climate shocks, and policy shifts. The US tariffs and UK retail cyber-attacks are just some of the latest stand-out examples.

WTW’s recent Global Supply Chain Risk Survey reports that fewer than 8% of leaders believe they have complete control over their supply chain risks, and nearly two thirds continue to experience higher-than-expected supply chain losses. But against this backdrop, customers expect greater performance – instant service, total transparency, and zero excuses.

In this respect, dependable delivery isn’t a nice-to-have. It’s not even a differentiator. It’s the baseline for trust and growth. And in a world where so much is outside of businesses’ control, building systems that can still deliver when nothing else is stable is the new definition of good leadership.

Shapers vs. stallers

PA Consulting’s 2025 Brand Impact Index supports this. It found that the most successful brands – those with stronger growth, loyalty, and pricing power – are actively building the muscle to deliver dependably in the face of new shocks. 

The study of 7,000 consumers and 360 major brands revealed these brands are ‘shapers’. Rather than just investing in front-end experiences, they’re transforming their operational back-end systems, re-engineering networks, and re-thinking supply chain models. These brands prioritise dependable delivery as the top investment area for growth in volatile markets.

At the other end of spectrum are ‘stallers’: brands stuck in reactive cycles, making quick fixes, and clinging to old supply chain assumptions. Notably, stallers are 1.6x less likely to plan for disruption and minimise the impact on customers.

Ask the right questions

So, how do businesses know where they fall? There are a few key questions companies should ask, starting with: is your planning designed to adapt or just explain what already went wrong? Sales and operations planning (S&OP) that can’t respond in real-time is a delay, rather than a decision-making tool. 

More broadly, are you solving for yesterday’s world? If your network is still built on historic cost curves and old demand centres, what risks are you carrying forward without realising it? Do your suppliers extend your resilience or expose your gaps? And finally, is your automation unlocking flexibility, or scaling the wrong process? Technology is only useful if it makes you faster, smarter, or more stable.

These questions aren’t just philosophical; they’re what separate the leaders from the laggards in today’s market. The good news is that those falling behind don’t need to blindly guess the way forward. Rather, shapers are following a proven playbook, leveraging five clear levers to hardwire resilience, agility, and reliability into their supply chains.

Network design 

First, it’s important to engineer multi-location networks that balance cost, service, and risk. The focus needs to be on proximity to demand, redundancy in key nodes, and the flexibility to shift under pressure.

BMW illustrates this well. During COVID-19, BMW redesigned its production footprint to manufacture closer to customers, reducing its exposure and increasing control at a time of global disruption. Its strategy focused on lowering risk in the upstream supply chain while increasing manufacturing in the countries where it sells cars. 

In 2022, Oliver Zipse, BMW’s Chairman, shared that the company was producing over 430,000 cars in the US, 60% of which stayed in the market, alongside retaining a footprint in Central Europe and building up its presence in China. He claimed that this proximity to key markets, as well as flexibly increasing or decreasing production according to customer needs, was key to the company’s production success. This approach highlights that it isn’t about a perfect footprint, but rather having one that adapts when the map changes.

Dynamic planning

The monthly S&OP cycle can’t keep up, with Gartner research indicating that it is becoming ‘obsolete.’ Instead, shapers are treating planning as a continuous discipline, integrating signals, data, and cross-functional coordination to respond in real time. This isn’t about perfect predictions. It’s about responsive, multi-layered planning that sees around corners.

For example, Unilever has advanced its planning capabilities through an ‘always-on’ AI-powered forecasting model. It integrates market intelligence, sustainability constraints, forecast and actual sales data between Unilever and the customer to improve forecasting accuracy. Notably, the initial pilot with Walmart in Mexico increased product availability at point of sale to 98%. This approach has ultimately enabled Unilever to dynamically reallocate supply, adjust demand forecasts, and make financial and environmental trade-offs with speed and precision.

Design-to-value

‘Shapers’ are also surgical with cost, investing where it creates value and cutting where it doesn’t. This may sound simple, but in practice, it means design-to-value models aligned with what customers actually care about.

Just look at Hershey, which unlocked $35 million in hidden capacity using automation. This breakthrough came from applying advanced analytics and AI to its KitKat production network, which consists of six lines. Hershey discovered that simple changes in production scheduling and product mix could dramatically increase throughput, without much investment. 

This kind of design-to-value mindset requires deep operational data, cross-functional visibility, and the discipline to say no to unnecessary complexity.

Supplier collaboration

Beyond this, traditional procurement models are increasingly shown to break under stress. Shapers build supplier ecosystems that share risk, diversify sourcing, and enable upstream visibility.

Procter & Gamble is a good example, as it has focused on supply chain transparency and agility by creating a digital control tower across its vast network of suppliers and partners. This connected infrastructure enables real-time monitoring, rapid risk response, and collaborative problem-solving when disruptions hit. It’s not just about oversight – it’s about coordinated resilience being built into the ecosystem. This stands the business in good stead to assess and respond to new shocks, such as the impact of the US tariffs.     

Digital technology and automation

Finally, digitisation must do more than display data. It needs to enable control, speed, and adaptation. 

Zillow is a case in point, having built an ecosystem that weaves AI and automation into every step of a consumer’s housing journey. It brings together a huge range of products and services under one umbrella through its ‘super app’, which enables renters, buyers, sellers, and real estate professionals to search, tour, finance, negotiate, and close on their housing journeys. 

While not a traditional supply chain, it shows how tech-enabled orchestration can help bring consistency, speed, and reliability out of complexity. For operations leaders, the lesson is that automation matters when it makes the system stronger – not just faster.

Adapt to disruption

Disruption isn’t slowing down. But too many supply chains are still built for a world that no longer exists – optimised for predictability, driven by cost, and dependent on fragile assumptions. For supply chain leaders, the takeaway is simple: in a high-risk environment, the most strategic move isn’t to stabilise, it’s to reshape guided by a clear playbook. 

Dependable delivery isn’t just about the physical movement of goods, but rather building in network flexibility, digital visibility, supplier transparency, dynamic planning, and resilience at every layer of the operation. More than ever, delivering reliably – under pressure, across borders – is what keeps businesses trusted and in motion.

  • Risk & Resilience

SupplyChain Strategy sits down with Ronald Kleijwegt, CEO at Vinturas, to explore the impact of recent tariff changes and geopolitical disruptions on global supply chains.

Donald Trump’s global trade war seems to be in a lull right now. Reciprocal tariffs between the US and China have paused, the US auto industry managed to compel the Trump administration to ease its levies on cars and vehicle components, and a successful trade deal between the UK and US has de-escalated transatlantic tensions somewhat. Friction between the US and EU, as well as with Canada to the north, remain high, however, and if there’s one thing the last four months have taught supply chain leaders, it’s that when it comes to the current US government, it’s unwise to take any amount of stability for granted. 

To take stock — as well as to try and understand what supply chain leaders can do to navigate periods of intense disruption — SupplyChain Strategy sat down with Ronald Kleijwegt, CEO at Vinturas, a Netherlands-based company that develops supply chain network software intended to provide real-time end-to-end visibility for supply chain and logistics teams. While our discussion focused on the impact of recent tariff changes and geopolitical disruptions on supply chains Kleijwegt was keen to highlight the fact that supply chains have always dealt with unpredictability and pain points of one kind or another. Citing examples like the Fukushima earthquake and the Eyjafjallajökull ash cloud, Kleijwegt emphasised the importance of accurate data and technology for resilience to ensure that the supply chains of today survive to become tomorrow’s success stories. 

SupplyChain Strategy: Ronald, could you help us set the stage a bit? I think it’s important to recognise that we’re operating in an increasingly unpredictable environment with a lot of pressures and headwinds. Then there’s always some specific context defining the exact moment we’re having these conversations. For example, in the last couple of days, we’ve seen restructuring in the US–China tariff relationship.

Still, uncertainty remains very high. Things are changing all the time. Could you give us a sense of where things currently stand with the latest tariff developments and what that means for organisations trying to stabilise their supply chains?

Ronald Kleijwegt: “Happy to. First of all, welcome to the world of supply chain! Maybe I’m getting a bit older, but like you said, today it’s about tariffs and trade relations with China. Tomorrow, it might be an earthquake somewhere in the world or another ash cloud grounding flights.

“Although I now run an IT software company, I spent most of my career managing large, complex supply chain operations globally. For example, I was deeply involved during the Fukushima earthquake, which had a massive impact due to sole sourcing of components in Japan. The same happened with the Icelandic ash cloud that shut down airspace.

“Now, we’re dealing with tariff changes in North America. There’s a 90-day grace period, but from a long-term supply chain management perspective, 90 days means very little. You’re still in reactive mode.

“Since COVID, the dynamics of global supply chains have intensified. Crises are no longer isolated—they’re overlapping and constant. To respond effectively, organisations need the right data and information, fast. With that, you can be agile and resilient.”

Ronald Kleijwegt, Vinturas CEO

SupplyChain Strategy: Absolutely. One other point is that these disruptions often bring ripple effects, like new regulatory hurdles or customs red tape. Could you speak to how organisations can deal with that increasing level of administrative complexity?

Ronald Kleijwegt: “It’s a good question, and the answer often depends on how governments choose to respond.

“In North America, for example, tariffs have been increased across the board. In my experience, it’s more effective when governments try to attract companies by offering incentives—like tax breaks or subsidies—not by creating blanket penalties.

“When I worked closely with governments, we had to educate them on how supply chains function. If you want to localise production, you need to lower duties on components and raise them on finished goods. That sounds obvious, but many countries still get it wrong.

“The US is now imposing tariffs across the board—including on components—which can be counterproductive. Then there’s the customs infrastructure. In some countries, like Germany, it’s still quite archaic, and delays in implementation disrupt supply chains even further. Policy decisions might be made at a boardroom level, but the operational side often lags far behind.

“A good example of a country doing things right is Morocco. They’ve successfully built a manufacturing ecosystem where over 65% of sourcing is local. This makes them highly competitive, especially with shipping access to South America and the US East Coast.

“Ultimately, companies can adapt to tariffs and regulatory shifts, but they need stability. You can’t build strategy around constantly shifting policies.

“At the end of the day, companies make decisions based on total landed cost, not just the price of production.

“Adidas, for example, adopted what they called Smart Manufacturing. Fast-moving products were produced closer to demand markets, while slower-moving items remained centralized, even if it meant slightly higher costs. It worked because the overall cost-efficiency improved.

“The problem isn’t just tariffs; it’s the constant change. You can’t build a company or strategy when the rules shift every 90 days.”

SupplyChain Strategy: Do you think we’ve entered a phase where economic policy is more deeply politicised? 

Ronald Kleijwegt: “What we’re seeing in the US right now is pretty unprecedented.

“Historically, trade barriers and subsidies have always existed. Offshoring to China, for instance, was largely driven by subsidies that made manufacturing cheaper. Even the US took advantage of that.

“But politics and trade are now more openly intertwined. Still, even with sanctions—take Russia as an example—trade finds a way. Goods flow through Dubai, Turkey, Kazakhstan, and so on. You can’t stop trade entirely.”

SupplyChain Strategy: What do the next 12 to 18 months look like for supply chain organisations that want to improve visibility and resilience?

Ronald Kleijwegt: “We’re in an ongoing crisis environment—COVID, wars, trade issues. But one positive is that supply chain now has a seat at the boardroom table. That recognition is growing.

“Companies are also realising that visibility alone isn’t enough. They’re shifting from simple dashboards to full-scale network solutions that connect their entire ecosystem. That’s how you get high-quality data, and that’s how you make AI and automation work effectively.

“More companies are coming around. It’s not just about having the latest tech; it’s about transforming how supply chains operate.

“Change is coming. And, for those that embrace it, there’s a big opportunity.”

  • Risk & Resilience