Dispatches → Category
What Changed in Global Risk?
A round-up of the developments most likely to affect corporate travel programmes, and what to do about them. Position as at July 2026; figures current at publication.
James Gribben
19 July 2026 · 8 min read
A traveller does not need to be sent into a war zone to be affected by conflict.
They may be travelling to Singapore, India or East Africa, yet still find their flight cancelled because an airline has changed its route through Middle Eastern airspace. They may arrive safely in Europe but lose half a day to new border procedures. They may be travelling to a supposedly low-risk city when extreme heat, flooding or civil disruption suddenly brings transport and essential services to a halt.
The important change in global risk is not simply that the world has become more dangerous. It is that disruption now spreads further and faster — and that it frequently arrives after the trip has been approved.
We call that the Routine Window: the gap between the moment a journey is assessed and the moment the traveller comes home, during which the conditions the assessment relied upon quietly stop being true. Most of what follows lands inside that window.
Conflict is affecting travel well beyond the battlefield
The 2026 Global Peace Index records the twelfth consecutive year of deteriorating global peacefulness. Ninety-nine countries deteriorated during the preceding year. The number of countries involved in external conflicts has risen from 59 in 2008 to 103. There are now 61 active state-based conflicts, the highest number recorded since the end of the Second World War.
For corporate travel programmes, the immediate concern is usually not direct exposure to fighting. It is the secondary effect on airspace, aviation routes, fuel supplies, borders and communications.
In July 2026, the European Union Aviation Safety Agency continued to advise airlines to consider risks affecting airspace over Israel, Jordan, Oman and Saudi Arabia when making routing decisions. Separate warnings remained in place for Ethiopia and Myanmar.
A destination may therefore remain open while the practical means of reaching it becomes unreliable.
What should organisations do?
Destination risk assessments must examine the complete journey, including transit airports, likely flight paths and realistic alternatives. Organisations should identify travellers who could become stranded if a regional hub closes, and establish in advance who has authority to approve additional accommodation, replacement flights or temporary relocation.
An annual country assessment is no longer enough. Monitoring must continue from the point of booking until the traveller returns.
Navigation itself has become a contested environment
One consequence of conflict has spread further than most travel programmes have noticed.
Satellite navigation interference — jamming, which blocks the signal, and spoofing, which replaces it with a convincing false one — has moved from an occasional regional nuisance to a routine operating condition across a widening band of airspace. EASA has revised its guidance to industry, warning that these events are increasing in both severity and sophistication, and both EASA and the US Federal Aviation Administration have recorded a marked rise since 2022, concentrated around conflict zones and other sensitive areas. Affected regions now include the eastern Mediterranean, the Black Sea, the Baltic, the Middle East, the India–Pakistan border and the Korean peninsula. Industry figures indicate jamming events have risen by around two-thirds since 2023, with spoofing rising considerably faster.
This is not a reason to avoid flying. Aircraft carry redundant navigation systems and crews train for degraded operations. But it is a reason to expect diversions, delays, holding patterns and occasional route changes in and around these regions — and to stop treating a confirmed itinerary as a reliable prediction of where a traveller will actually be.
What should organisations do?
Build the expectation of disruption into planning for journeys through affected airspace: realistic connection times, contingency accommodation, and a traveller who has been told that a diversion is a possibility rather than a catastrophe.
More broadly, do not assume that location data is infallible. Programmes that rely on satellite-based tracking should understand that position information can be degraded or false in precisely the regions where accurate information matters most. Voice contact remains the confirmation. An app that shows a traveller in the right place is not the same as knowing they are there.
Extreme weather is becoming an operational risk
Extreme weather should no longer be treated as an unfortunate act of nature sitting somewhere outside the travel policy.
The World Meteorological Organization has reported an 80 per cent likelihood of El Niño conditions between June and August 2026, with a probability approaching 90 per cent that they will persist to at least November. El Niño can increase the likelihood of heatwaves, drought, heavy rainfall and disrupted weather patterns across several regions.
These events affect far more than personal comfort. They can close airports, disrupt railways, overwhelm local healthcare, interrupt power supplies and make road journeys unsafe. Travellers with existing health conditions may face greater exposure during periods of severe heat or deteriorating air quality.
What should organisations do?
Travel approval should consider seasonal and forecast conditions, not merely the destination's underlying country rating. Programmes should contain clear thresholds for postponing travel, changing accommodation or restricting road movement — decided in advance, not negotiated during a heatwave with a client waiting.
Travellers also need practical instructions. "Take care in hot weather" is not a control measure. Guidance should cover hydration, working hours, transport, medication storage, communications and the signs that a traveller should stop work and seek medical assistance.
Borders are becoming digital
Border administration is changing quickly, and travellers who fail to obtain the correct digital permission may not reach the aircraft at all.
The European Entry/Exit System became fully operational across the Schengen external border on 10 April 2026. It digitally records the entry and departure of non-EU nationals visiting for short stays, capturing facial images, fingerprints and travel-document information in place of passport stamps.
The United Kingdom moved to full enforcement of its Electronic Travel Authorisation requirement on 25 February 2026. Carriers must now verify permission before departure, and the previous discretion to let a passenger board and resolve matters at the border has gone.
Two details catch corporate travellers in particular. An ETA is required for those transiting the UK where they pass through immigration control, not merely for those staying. And dual British nationals are affected: to avoid being treated as ETA-required at check-in, they need a valid British passport or a certificate of entitlement. An expired British passport will not do. Every organisation employing dual nationals has someone whose British passport lapsed years ago because they never needed it.
A further change is expected. ETIAS, the EU's pre-travel authorisation for visa-exempt nationals, is scheduled to begin in the final quarter of 2026, though no date has been confirmed and applications are not yet open.
What should organisations do?
Immigration and entry requirements should be checked when the journey is approved, again when it is booked, and once more shortly before departure. Passport nationality, dual nationality, residence status, transit arrangements and the purpose of travel must all be considered.
The travel function should also clarify responsibility explicitly. Assuming that the traveller, the travel management company and the receiving office have each checked the documentation is a reliable method of discovering that nobody has.
Health risks remain local until someone boards an aircraft
The lesson from recent outbreaks is not that every traveller faces an epidemic. It is that local health events can rapidly acquire regional or international consequences.
In July 2026, the World Health Organization reported continued transmission of Bundibugyo Ebola virus disease in the Democratic Republic of the Congo and Uganda, including an imported case involving a doctor who travelled from the DRC to France.
Most corporate travellers will face far more ordinary medical problems. Yet outbreaks can affect entry procedures, hospital capacity, insurance support, evacuation options and the willingness of airlines or medical providers to operate.
What should organisations do?
Health preparation should be based on the traveller, the activity and the destination. It should cover vaccination advice, access to medication, medical insurance, local healthcare capability and arrangements for clinical advice or evacuation.
Organisations should also know where their people are. A carefully written emergency plan is of limited value when nobody can establish which employees are currently in the affected area.
The traveller is now a portable cyber target
The finance team receives a video call from a director authorising an urgent payment while they are abroad. The voice is right. The face is right. The director never made the call.
Business travellers carry company systems, sensitive correspondence, client information and access credentials through airports, hotels and unfamiliar networks — and they do it while tired, rushed and outside their normal working routines. That combination is precisely what social engineering is designed to exploit.
INTERPOL's 2025–26 assessment of cyber threats across Asia and the South Pacific identified sharp growth in phishing, ransomware, artificial intelligence-enabled scams and industrial-scale social engineering, reporting that cybercrime accounted for more than 30 per cent of recorded crime in many of the countries surveyed.
Criminals rarely need to steal a laptop when they can persuade a tired traveller to surrender credentials through a convincing airline message, a hotel payment request or an urgent instruction apparently from a senior manager.
What should organisations do?
Higher-risk journeys should carry defined cyber controls: clean devices, restricted access to sensitive systems, multifactor authentication, secure communications and checks when equipment returns.
Travellers should be briefed on impersonation, urgent payment requests, false booking messages and the growing quality of synthetic audio and video. Critically, the organisation should establish a verification route that does not depend on the channel being used to make the request — because the entire point of a convincing deepfake is that it sounds convincing.
One more thing worth checking: who else can fail
Most travel risk programmes now depend on a small number of external providers — a tracking application, an assistance company, an insurer, a travel management company.
That is sensible. It also concentrates risk. When a single supplier suffers an outage, a cyber incident or a commercial failure, the safety net stops working for every traveller simultaneously, usually without warning and often at the least convenient moment.
What should organisations do?
Know what happens if the primary provider is unavailable. Test the emergency number rather than assuming it works. Establish a fallback method of locating and contacting travellers that does not depend on the same system. Redundancy is unglamorous, and it is the difference between a degraded response and no response at all.
The practical response
Corporate travel programmes now need to be dynamic rather than document-led.
That means a named owner, reliable traveller information, current destination assessments, genuine pre-travel preparation, monitoring during the journey and a tested method of providing assistance when circumstances change.
It also means confronting the Policy Illusion — the comfortable belief that because a travel policy exists, travel risk is being managed. A document describes intentions. A programme produces decisions, and it produces them at three in the morning when the airport has closed and somebody has to authorise a hotel.
ISO 31030 provides a structured framework for these responsibilities. The first step is to establish what is already in place, where responsibility sits and which gaps could leave travellers or the organisation exposed.
Initiative Training Group helps organisations assess, structure and improve their travel risk management arrangements. Begin with the ITG ISO 31030 Travel Risk Management Assessment and identify where your programme needs attention before the next disruption makes the decision for you.
Written by James Gribben
Role / Title, Initiative Training Group
