Look at the last few days. Heathrow spent part of last week warning passengers off the roads after flooding closed access to two terminals. A flood warning is in force for Nelson in Lancashire, with alerts out across Merseyside and the North East, arriving straight after weeks dry enough to count as drought, and yellow warnings in place today for flash flooding potential — which is precisely the combination that produces flash flooding, because parched ground sheds water rather than absorbing it. And in the south of France, a tornado tore through the Aude region, damaging more than 300 homes and injuring dozens, while cyclists on the Vuelta were scattering from hail the size of golf balls.
Tornadoes in France sound exotic. Tornadoes in Britain shouldn’t. It’s a long-running pattern, not a one-off: over the decades of records TORRO and the Met Office keep, England has averaged more tornadoes per unit of land area than the United States as a whole, tornado alley included in that national figure. The most recent full year on record bears it out — TORRO logged 26 tornadoes across the British Isles in 2023, on 20 separate days, in line with the Met Office’s long-term average of around 30 reports a year. Most are weak, over almost as soon as they’ve started, and gone from the news cycle within a day. But “weak and forgettable” is still a live example of the category of risk this piece is actually about, which is the weather-related disruption that keeps happening, on a schedule nobody can quite predict but everybody could reasonably expect.
What BCI’s own data says
The Business Continuity Institute has been asking organisations about exactly this in its Horizon Scan survey for well over a decade, and the pattern doesn’t move around nearly as much as you’d think. Adverse or extreme weather has sat in the top five or six threats organisations report being concerned about in most years since 2013, aside from the two years pandemic understandably swallowed everything else on the list. That’s concern. Actual disruption is more striking still. In 2018, adverse weather was the single most common real-world cause of disruption BCI’s respondents reported, ahead of IT outages and running well clear of cyber attacks. In 2025, extreme weather topped the “single biggest cause of disruption” measure for the first time since 2017 — beating cyberattacks into second place.
BCI’s own reports have noticed the gap between how often this happens and how seriously it’s treated as a strategic issue. As far back as the 2013 report, the authors flagged it as “surprising” that climate change, as a longer-term trend, was rated consistently low by the same people who ranked adverse weather as an immediate top-five concern. It took until 2018 for climate change to crack the top ten list of trends organisations were tracking at all. The short-term disruption gets noticed every time it happens. The underlying pattern behind it keeps getting treated as background noise.
Then look at what “operational resilience” has come to mean
Which makes it worth putting BCI’s newest publication next to its own back catalogue. The Operational Resilience Report 2026 runs to 72 pages, and where it does talk about risk, it’s overwhelmingly one kind: cyber attack, data breach, IT and telecom outages, third-party technology suppliers, legacy infrastructure. Weather, climate, flooding and extreme weather don’t feature as risk categories anywhere in it — not once, in any chapter, any chart, or any respondent quote. That’s a fair like-for-like comparison, risk against risk: one category that BCI’s own data says disrupts organisations more often than almost anything else, and one that gets an entire report built around it.
The likelier explanation isn’t that practitioners stopped caring about physical risk. It’s regulatory gravity. An entire sixteen-page chapter of the report is given over to regulation, and one framework dominates it: the EU’s Digital Operational Resilience Act, DORA, named as the framework most organisations in the survey have adopted. DORA exists, in the report’s own words, to impose “structured requirements for ICT risk management,” and its reach comes from “its broad impact across the financial sector.” Once that’s the regulatory lens the report is built around, it’s not surprising that “risk” ends up meaning ICT risk in practice — that’s what DORA asks about, so that’s what gets measured, categorised and written up. Over a third of this year’s respondents work in banking or finance, which is exactly DORA’s jurisdiction, so it was always going to dominate a survey shaped this heavily by that sample.
What’s more interesting is that the skew doesn’t seem to come from what the respondents actually do for a living. Only around six per cent of them work in cyber or information security. The largest single group, by some distance, describes itself simply as business continuity. So the report’s ICT tilt looks less like a reflection of what these practitioners care about, and more like a reflection of which regulator happened to ask the loudest question this year.
Why that’s worth noticing
None of this is an argument against DORA, which does something genuinely useful within its scope. It’s an argument against confusing “what the current regulation asks about” with “what’s actually likely to disrupt you.” Regulatory frameworks are a reasonable proxy for risk, right up until the risk that keeps materialising happens to sit outside whichever framework is fashionable that year. Weather doesn’t check which chapter of the report it’s supposed to appear in before it takes out a control centre, closes an airport terminal, or puts flood water through a supply chain. It has been doing this, on BCI’s own numbers, more reliably than almost anything else organisations report being disrupted by — and it still isn’t getting a paragraph.
It’s a question I’ve been putting to delegates for years, in one form or another: if we know extreme weather is coming, in the sense that it’s plainly a known known and not some freak event, why do organisations remain so consistently unprepared for it? I’ve never had a fully satisfying answer, but I think BCI’s own archive gives away part of it without quite meaning to. Its 2019 Horizon Scan describes adverse weather as a “black swan” — the term for a shock nobody could have reasonably foreseen — in the same paragraph that notes it had disrupted organisations more than five times in the previous twelve months. A genuine black swan is the thing you didn’t see coming. Something that happens five times a year isn’t that. It’s closer to a standing item on the risk register.
If the sector’s own flagship survey can misfile weather as a freak event while its own numbers say otherwise, it’s not hard to see the same thing happening at board level: treated as bad luck rather than as a plannable, budgetable, recurring cost of doing business. Cyber attacks get incident response plans, tabletop exercises and board sign-off, because they’re framed as a certainty worth preparing for. Weather, on the evidence in front of us, has earned exactly the same treatment. It rarely gets it.



