Attacks, accidents and downright lies: what are the new risks the UK is facing?

16 Jul 2026

Jon McLeod and Lana Madkour reflect on the key takeaways from the updated National Risk Register.

1. Interference in the democratic process is now a listed national risk

The addition follows the Government’s response to the independent Rycroft Review, which examined foreign financial interference in the UK’s political and electoral systems. The resulting measures include an annual £100,000 cap on donations from overseas electors, a minimum residency period for returning overseas electors, a moratorium on cryptocurrency donations, and company donations assessed against post-tax profits over the previous five years rather than revenue alone. Candidates will be required to prove that campaign funding received before they formally became candidates came from legitimate sources, and to declare donations above £2,230 received in that period. The measures are being taken forward as proposed amendments to the Representation of the People Bill.

2. Most of the new risks are digital

Cyber attacks on data infrastructure, water infrastructure and police systems have all been added. So has ‘digital resilience failure’, a category built on the lessons of the CrowdStrike IT outage of July 2024, where a rogue software update crippled 8.5 million computers using Microsoft systems around the world. The Cabinet Office attributes the cluster to a rapid increase in the sophistication and proliferation of artificial intelligence. The CrowdStrike precedent is instructive: that incident was not an attack but a faulty update, and the disruption it caused was a function of dependency rather than hostility.

3. AI is named as the risk multiplier by a government also pursuing it for growth

The Government’s statement holds both positions at once, describing AI as offering new ways for criminals to carry out cyber attacks while also offering opportunities for the economy and security.

The AI Security Institute gives that position an evidential base. In April 2026 AISI evaluated a preview of Anthropic’s Claude Mythos model as capable of autonomously attacking small, weakly defended and vulnerable enterprise systems, an assessment that prompted an open letter to business leaders from DSIT. Its evaluation of OpenAI’s GPT-5.5 found it among the strongest models tested on cyber tasks and the second to solve a multi-step cyber-attack simulation end to end. AISI has reported that the length of tasks frontier models can autonomously complete in its cyber suite has been doubling every few months, at a rate that is itself accelerating. The Government’s approach is to measure the capability openly and legislate around it rather than slow the technology: the Cyber Security and Resilience Bill, which reached the Lords in June, brings managed service providers and large data centres into scope and tightens incident reporting, and CYBERUK 2026 saw £90 million committed alongside a voluntary Cyber Resilience Pledge.

The reputational damage and the operational damage now arrive together. Organisations must prepare for both.

4. One risk has been removed

The threat of disruption to Russian gas supplies has come off the Register, reflecting reduced UK reliance. That reduction is the product of a deliberate energy security push since the invasion of Ukraine, and its appearance here is the clearest example of what the Register does when a policy has worked: the entry simply goes. It is worth reading alongside the Armed Forces Minister’s statement in the same release that Russia represents a direct threat to the UK homeland, not only to NATO’s eastern flank. A risk leaving the Register records the success of a specific mitigation, not the disappearance of the underlying adversary, and the seven additions arriving in the same update indicate where the threat has gone instead.

5. Preparedness is being taken to the public

A national resilience campaign will launch later this year, encouraging households to take practical steps against risks including cyber attacks, flooding and severe weather. It builds on the existing GOV.UK Prepare guidance and will include resources for schools and colleges. The Government’s stated aim is to bring the UK into line with European peers, most of which already run comparable campaigns. The Register update was published following another heatwave, in a year when temperatures broke records in May and again in June.

6. Mayors are being brought into the resilience structure

Regional mayors will have a formalised role in responding to local and national emergencies, alongside existing Local Resilience Forums, under proposals now out for consultation. The consultation forms part of a periodic review of the Civil Contingencies Act 2004, which the government considers broadly fit for purpose.

7. The largest home defence exercise in decades is scheduled for 2027

Operation ALBISTON SHADOW will test government preparedness for hybrid attacks against the UK. The scenario will remain classified. Ministers and hundreds of officials are expected to take part, and the exercise will complement NATO’s CMX27. The classified crisis plans known as the War Books are also being updated for the first time since 2004.

Communications considerations

The Register is a planning document, but several of this year’s additions describe risks where the reputational damage and the material damage arrive together, and where the communications response is part of the operational response rather than a consequence of it.

Clients need to integrate this thinking into their resilience planning. Strategic and crisis communications planning must factor in the following considerations:

  • Provenance. The democratic interference measures are largely concerned with establishing where money came from and who controls it. The AI-linked additions raise a version of the same question. As generative tools reduce the cost of producing a convincing output, such as a recording, a corporate identity, a breach notice, or an apparent campaign, verified origin of source material becomes a scarce commodity. Audit trails and reliable proofs of origin are now critical, whether these are describing about information or money.
  • Speed. The CrowdStrike outage illustrated that the damaging interval is often the one in which an organisation cannot yet say what is happening. If AISI’s trend data is accurate and cyber attacks will continue to be carried out at unprecedented speed and scale, organisations will face more pressure to coordinate their response when an attack occurs. Organisations need to invest in crisis preparedness: those that have not tested where the authority to speak sits, outside office hours and with senior people unavailable, do not know how quickly they can respond.
  • Shared vocabulary. The Register is the reference document that regulators, Local Resilience Forums and now regional mayors are working from. Organisations that structure their own scenario planning around it must be using the same terms as the bodies they will need to coordinate with.

Read more about our Crisis Communications services and how we help organisations prepare for today’s evolving risk landscape.