Geopolitical Cyber Risk: What CISOs Need to See Before the Risk Register Falls Behind

The Internet Doesn’t Care About Your Threat Model, But Geopolitics Just Rewrote It Anyway 

A treaty gets signed between two countries. Nobody in your security team reads about it. Nobody adds it to the risk register. Yet within months, the networks carrying data between those countries begin forming more direct connections.

No firewall changed. No vulnerability disappeared. The structure underneath the internet simply adjusted to a new expectation of risk. 

Now change the conditions. Sanctions. A diplomatic crisis. A border skirmish. Network operators begin reconsidering who they depend on, which traffic they accept, and how much instability they are willing to carry. They do not always wait for a government order. Sometimes companies move first because they can already see the risk approaching. 

This is not theory. Researchers analyzed routing relationships across more than 70,000 internet networks, 173 countries, and 96 months. They found that a treaty was associated with a 58.5% increase in direct interconnection agreements between networks across the countries involved. 

That is not a rounding error. That is the internet reorganizing around power politics without a single CISO in the room. 

Here’s the uncomfortable part: your risk register probably doesn’t have a line item for “geopolitical relationship between Country A and Country B.” 

But perhaps it should. 

Because that relationship may already be shaping which networks carry your data, which suppliers remain dependable, which regions are becoming harder to support, and how quickly the business could recover if one of those dependencies disappeared. 

The Threat Model Is Missing Something

The World Economic Forum Just Confirmed What CISOs Suspected

The Global Cybersecurity Outlook 2026 surveyed more than 800 security leaders across 92 countries. It found that 64% of organizations now factor geopolitically motivated cyberattacks, including espionage and critical infrastructure disruption, into their overall risk strategy. 

That’s not a niche concern anymore. That’s a majority. 

And it’s not paranoia. Politically motivated cyber activity rarely stays contained within governments. It spills into telecommunications providers, cloud platforms, suppliers, transportation systems, financial infrastructure, and businesses that were never the primary target. 

Those organizations do not need to be part of the conflict. Their position inside the digital ecosystem is enough. 

A company may be targeted because of the customers it serves, the technology it operates, the research it holds, the infrastructure it supports, or the access it can provide to someone more strategically valuable. 

Sometimes you are the target. Sometimes you are the route. 

Confidence Is Falling Exactly When It Should Be Rising

The same WEF report found that 31% of respondents lacked confidence in their country’s ability to respond to a major cyber incident affecting critical infrastructure. Last year, that number was 26%. 

Confidence is going down while geopolitical instability is going up. That gap is where surprises live. 

And the gap isn’t evenly spread. Confidence in critical infrastructure protection sits at 84% in the Middle East and North Africa. In Latin America and the Caribbean, it’s 13%. If your organization operates across regions, your actual exposure varies wildly depending on which government, which infrastructure, and which alliance sits behind each office you have. 

Sanctions Leave a Blind Spot 

The Internet Gets an Exception 

Here’s a detail almost nobody in security factors into their thinking. Internet interconnection is routinely exempted from sanctions regimes. The US Treasury has explicitly authorized peering with sanctioned telecom providers in Cuba, Iran, and Sudan since 2009. The EU clarified in 2022 that sanctions on Russia do not apply to the telecommunications infrastructure keeping communications running.

Why does this matter for you? Because it means the usual tools, tariffs, sanctions, and contract enforcement, do not fully reach the layer where your data actually moves. Almost 99.5% of interconnection agreements between networks are handshake deals with no formal contract at all. There is no clear legal backstop. The protection the business is used to relying on elsewhere may not exist here. 

The Real Risk Isn’t the Sanction, It’s the Retaliation

When China placed tariffs on Australia after a diplomatic dispute in 2020, the story didn’t end with trade numbers. Cyberattacks against Australian targets spiked immediately after, and by 2024, twenty members of an Australian parliamentary group focused on China had been directly targeted.

This is the pattern security leaders need to internalize: geopolitical tension doesn’t stay in the news cycle. It shows up as attack traffic, weeks or months later, often aimed at organizations that had nothing to do with the original dispute. 

Shadow AI Opens Another Front 

Urgency Moves Faster Than Governance

Geopolitical pressure changes how people work. A regional team needs a translation immediately. Procurement wants a supplier document summarized. Security needs to review unfamiliar material. Operations is trying to keep moving while normal support channels are unstable. 

So someone opens an AI tool nobody approved. 

The obvious risk is data leakage. The less obvious one is that the organization has just created another external dependency without checking where the service processes data, which infrastructure supports it, which jurisdictions affect it, or whether access could disappear when conditions change. 

One urgent task becomes a repeated shortcut. The shortcut becomes a workflow. Then leadership discovers that sensitive work depends on a tool with no contract, no accountable owner, no continuity plan, and no clear record of where the information went. 

Shadow AI belongs in the geopolitical-risk conversation because instability does not only change external threats. It also creates internal pressure to adopt services faster than the organization can assess them. 

That is how a tool nobody approved becomes part of a risk nobody mapped. 

So What Should CISOs Do? 

Nobody Owns the Whole Picture 

Geopolitical risk sits in a strange no-man’s-land inside most companies. Legal watches sanctions. Finance watches currency and commercial exposure. Procurement watches suppliers. Operations watches service delivery. Threat intelligence teams watch nation-state activity. 

Yet nobody may own the question that connects all of them: What happens to the business if political conditions change the security, availability, or trustworthiness of a dependency we rely on?

The WEF data suggests that large organizations are beginning to close this gap. Among organizations with more than 100,000 employees, 70% increased their focus on nation-state threat intelligence, compared with 30% of smaller organizations. Large organizations were also more likely to deepen engagement with government agencies and information-sharing groups, at 49% compared with 26%. 

Translation: the biggest players are already treating geopolitics as a core input to security decisions. Many others are still treating it as background noise. 

Turning Uncertainty Into a Decision 

The organizations doing this well are not guessing. They are mapping exposure the same way they would map any other risk: which vendors operate in which countries, which conflicts or political relationships affect them, and which of those conditions could change fast enough to matter. 

CISOs do not need to predict every geopolitical development. They need a repeatable way to decide whether it changes the organization’s risk. Ask three questions before the risk register falls behind: 

  • What changed?
    Did targeting increase, sanctions affect a provider, or a region become less stable? 
  • What does it touch?
    Which services, vendors, data flows, users, and recovery processes depend on it?
  • What decision changes?
    Does the organization need tighter monitoring, faster remediation, stronger access controls, an alternative provider, tested recovery, or board escalation? 

That is the practical translation CISOs need to make. A vague warning gives leadership something to worry about. A clear exposure gives leadership something to decide. 

Resilient Companies See More 

Highly resilient organizations do not rely on controls alone. They involve security earlier, map more of the ecosystem around them, and test what happens when a dependency fails. Among highly resilient organizations, 70% involve security in procurement, 59% assess supplier security maturity, 48% map their ecosystem in detail, and 44% run incident or recovery exercises with partners. 

Same threats. Same world. Completely different visibility.

That visibility does not remove geopolitical risk. It gives the business enough time to act before a supplier, region, network, or hidden AI dependency makes the decision for it. 

Conclusion: The Risk Register Is Already Late

Global conflict, nation-state activity, sanctions, and regional instability will keep changing the conditions around your organization, often before any system fails and before any alert gives the security team a reason to look. 

The CISO cannot control those conditions. The job is to recognize when they have changed the organization’s exposure, identify which suppliers, regions, data flows, and unapproved tools now carry more risk, and turn that change into a decision leadership can defend. 

Could the organization show the board, today, which dependencies would become critical if geopolitical conditions shifted tomorrow? 

Geopolitical cyber risk is not simply another category to add to the register. It changes the likelihood, impact, urgency, and ownership of risks already there.

The risk register may already be late. The decision does not have to be.

For Further Reading

This blog post is based on insights and analysis from: