When asked about the greatest threats to corporate IT, most discussions focus on cyberattacks. This is understandable, as these are the incidents that make the headlines. Yet the most underestimated risks today are not necessarily the most widely publicised. They are systemic threats. They may not be spectacular, but they can bring an entire business, or even a country, to a standstill.

In our view, three of them deserve particular attention.

The first is the loss of access to services. This applies to cloud environments, software-as-a-service platforms and infrastructure services, particularly those delivered through the public cloud. In this scenario, a company is not affected by a cyberattack or technical failure. It simply loses access to the environment on which it depends. This can happen overnight as a result of a decision made outside the organisation. For the business, it means that critical processes come to a halt through no fault of its own, with no straightforward path to recovery.

The second is geopolitical pressure and sanctions. In Europe, this risk remains significantly underestimated. Today, it may take only a few days for another trade dispute to emerge, potentially affecting services such as the public cloud. The result could be a dramatic decline in the availability of IT services. In other words, a Polish company’s access to its own systems could be determined by a trade dispute in which the company itself plays no part.

The third is a change in laws and regulations that creates regulatory shock. This type of threat does not cause immediate disruption, but it can force organisations to implement rapid and costly changes. The clearest examples today are the GDPR, the AI Act and NIS2. Each of these regulations also brings positive outcomes, and the point is not to present them as threats. The point is that business risk assessments must treat their impact just as seriously as system failures.

How do these risks compare with the threats that receive the most attention? Comparing three crisis scenarios reveals an interesting pattern. A ransomware attack is the most immediate and realistic risk. It is an everyday threat, not a hypothetical one. A large-scale power outage is extremely rare, but potentially dramatic in its consequences. By contrast, given the current geopolitical environment, being cut off from a foreign cloud service remains the most underestimated risk.

These observations lead to one conclusion. A risk map built solely around loud and visible threats is incomplete. The greatest attention is usually paid to events that have already happened to someone else. The least attention is paid to what may still happen to us, quietly and without warning.

There is another dimension to this issue. Systemic risks rarely produce warning signs that can be detected in advance. No security system can prevent a political decision or a new regulation. The only realistic response is therefore to prepare the organisation for the consequences rather than attempt to avoid the risk altogether.

In practice, it is worth starting with a simple exercise. Add three silent scenarios to the existing risk assessment: loss of access to external services, the consequences of geopolitical tensions and a sudden regulatory change. Then ask one question for each scenario: do we have an action plan if it materialises, or are we simply hoping that it never will?

Systemic risks have one thing in common with insurance. Organisations are reluctant to think about them until they are needed. The difference is that the value of insurance may still be assessed after the damage has occurred. Resilience to systemic threats cannot be built after the fact.