top of page
Search

Four years in - has your board actually prepared for this, or just talked about it?

Aug 28
9 min read

On 25 August, CIA Director John Ratcliffe made an unannounced trip to Moscow. According to the Wall Street Journal, CNN, Politico and RFE/RL, the message was blunt: Russia should not test NATO's Article 5 by targeting Estonia, Latvia or Lithuania - not with a drone, not with a cyberattack, not with a limited land incursion. The US intelligence assessment behind the visit reportedly concludes that Putin, within the next few years, may try to probe NATO's willingness to defend every inch of allied territory, as Estonia's foreign minister put it afterwards.


That is not a declaration of war. But it is a signal that one of the world's most well-informed intelligence services now rates the probability of a direct confrontation between Russia and a NATO member as high enough to justify an emergency trip to the Kremlin.


It is also worth being precise about the history here, because it is not flattering. The last time a CIA director made this kind of unannounced trip to Moscow was in November 2021, when then-Director William Burns flew in to warn Putin directly against invading Ukraine, laying out in detail what US intelligence knew about his plans. We all know how closely that warning was heeded. Three months later, Russian tanks crossed the border. That does not mean history simply repeats itself, and no one is suggesting a repeat of 2022 against a NATO member. But it does mean the real question this week is not whether Washington delivered a clear warning. It is how much weight that warning actually carries in Moscow this time - and boards would be naive to assume the answer is “more than last time.”


Here is the uncomfortable part for Nordic boardrooms: this is not new information dressed up as a fresh crisis. The war in Ukraine has now run for four years. Drone incursions into Polish and Romanian airspace, GRU-linked devices found at Leipzig airport, Russian electronic warfare redirecting drones over Latvia, repeated sabotage and cyber operations against the Baltics - none of this is new. What is new is that boards no longer have the excuse of surprise. The question four years in is not “could this happen.” It is “why haven't we finished preparing for it.”



The status check nobody wants to run

The honest answer, based on what the data is telling us this year, is that preparedness has not kept pace with the risk.


Deloitte's Spring 2026 European CFO Survey, covering more than 1,100 CFOs across 12 countries, found that pessimism about company prospects has nearly doubled since autumn 2025 - and geopolitical concern is now higher than at any point since the war began in 2022. WTW's 2026 Political Risk Survey found that three out of four respondents had experienced an insurable loss directly linked to political or geopolitical risk this year, one of the highest shares in the survey's nine-year history. And the EU Institute for Security Studies' 2026 risk assessment puts a hybrid attack on critical infrastructure at the very top of Europe's threat picture - not a hypothetical, but the most likely near-term scenario, alongside a Russia-favourable ceasefire that would embolden further pressure on NATO's eastern and northern flank.


Eurasia Group's 2026 outlook is even more direct about who is exposed: Eastern Europe and the Nordics are named specifically as the regions most exposed to Russian escalation, with the most dangerous front in Europe shifting from the trenches in Ukraine to a hybrid war fought directly against NATO members.


That includes you. Not as a bystander watching a war next door, but as a participant in a security environment that is already testing critical infrastructure, cyber defences and supply chains across the Nordics.


Denmark and Sweden aren't on the sidelines - we are the gate

In conversations with Nordic peers over the past weeks, one contrast keeps coming up: Danish executives tend to take this threat personally, Swedish executives more often frame it as somebody else's problem. That is not a coincidence. Denmark was occupied for five years in the Second World War, and that memory still shapes how seriously Danish institutions take an early warning. Sweden's identity, by contrast, was built on more than two centuries of non-alignment, and it only joined NATO in 2024, the last Nordic country to do so. That history is worth naming, because it can quietly bias risk perception in the boardroom - and on the numbers, the neutrality instinct is the one that no longer fits the map.


The Baltic Sea has exactly one way out to the open ocean: the Danish Straits, comprising the Øresund, the Great Belt and the Little Belt. Every ship in or out of the Baltic - Russian, Nordic, or anyone else's - has to pass through Danish-controlled waters. Sweden's Gotland, sitting almost in the geographic centre of the Baltic Sea, gives NATO a decisive position over regional air and sea movement and directly counters Russia's ability to seal off the eastern Baltic. With Finland's accession in 2023 and Sweden's in 2024, every state bordering the Baltic except Russia is now a NATO member, and the sea is routinely described by analysts as a “NATO lake” - with the Danish Straits as its alliance-controlled exit gate.


That is not a comfortable position to be in. It means Denmark and Sweden are not simply two more exposed NATO members among many; they hold the geography that determines whether Russia's Baltic Fleet is a regional nuisance or has open access to the Atlantic. Russia's fleet is already assessed to hold a large stockpile of naval mines, and mining the Danish Straits or interfering with Gotland-based surveillance would be a far more achievable way to pressure NATO than any direct attack on the Baltic states. The Nord Stream sabotage and the ongoing shadow-fleet tension in Danish waters are early, low-intensity previews of exactly that kind of pressure. For a Danish or Swedish company, this geography is not background information. It is the specific reason your infrastructure, ports and undersea cables carry a materially higher risk profile than a comparable company in, say, Germany or the Netherlands - and it is precisely the kind of fact a genuinely neutral-minded boardroom risks underweighting.


Three risk levels most boards still haven't priced in


1. Supply chains are no longer just an “Eastern Europe exposure” line item


Four years ago, supply chain risk from the war meant energy prices and a handful of Ukraine-linked suppliers. Today it means asking what happens to Baltic Sea shipping lanes, Polish and German logistics corridors, and insurance premiums if a NATO member becomes the target of a “limited” attack. This is no longer a regional sourcing question. It is a question of whether your supply chain can function at all during a regional security crisis - and whether leadership has actually modelled that, or is simply hoping it stays theoretical.


2. Hybrid and cyber risk is not waiting for a formal war to be declared

The drone and GRU-linked incidents in Germany, Poland and Romania show that Russian hybrid activity does not wait for a formal escalation. It is happening now, against civilian infrastructure, in countries far more similar to the Nordics than Ukraine is. NIS2 already makes board-level accountability for this a legal requirement, not a best practice. The real question is whether your incident response plan is built for routine IT disruption, or for a scenario where a state actor is deliberately testing your resilience.


3. Economic fragmentation moves faster than the front line does

Sanctions, export controls and the slow decoupling of Western and Russian-aligned economies are already reshaping trade flows across Europe, well ahead of any further military escalation. An open confrontation between Russia and a NATO member would accelerate that fragmentation sharply. The companies without a scenario ready will spend the next crisis reacting instead of deciding.


Minimum Viable Company: the absolute floor, not an aspiration

Most boards still treat resilience as a technology conversation - recovery-time objectives, backup architecture, which systems come back online first. That is IT's job, and it matters. But it is not the same question as the one the board actually owns: if everything else fell away tomorrow, what is the absolute minimum this company must keep doing to survive, and who decided that - the board, or a vendor's default configuration?


That is the Minimum Viable Company question. Given how fast the security situation in Europe is moving, this is no longer a strategic nice-to-have for next year's board retreat. It is the floor of what a responsible board must have activated now, before the next escalation makes the decision for you.


At minimum, that means the board - not IT, not a single executive - has explicitly decided:

-      Which functions, products or systems are truly non-negotiable to keep the company alive, and which can be paused without existential damage.

-      The order in which capabilities get restored if several fail at once, so restoration priority isn't improvised in the middle of a crisis.

-      Who has the authority to declare an MVC state and activate contingency measures, and how fast that authority can be exercised without waiting for a full board meeting.

-      The minimum staffing, minimum data access and minimum supplier relationships needed to keep the non-negotiable core running, independent of any single supplier's own continuity promises.

-      How this decision gets tested through an actual tabletop exercise, not just written down and filed - a plan nobody has rehearsed is an assumption, not a plan.


If your board cannot answer these questions today, in specific and documented terms, you do not currently have a Minimum Viable Company decision. You have a hope that IT's disaster recovery plan will somehow cover it. Given the pace of escalation across Europe this year, that gap is no longer a theoretical governance weakness. It is an active exposure.


This is not just an LCG framework - it is where regulators are already heading

It is worth being clear that this is not a provocative idea invented for this blog. NATO's seven Baseline Requirements for national resilience, agreed at the 2016 Warsaw Summit and strengthened in 2021, explicitly state that Allied militaries depend on civilian and commercial infrastructure - energy, transport, communications, food and water - to function at all, and that this dependency has to be planned for in peacetime, not discovered during a crisis. The EU's Preparedness Union Strategy and its Critical Entities Resilience Directive push the same logic one level further into the private sector, requiring resilience strategies and risk assessments from critical companies across ten sectors, as the operational counterpart to NIS2's cyber requirements.


Denmark is now moving in the same direction. The new Ministry for Societal Security and Preparedness published its National Risk Picture in 2025 and is building what it calls a “totalberedskab” - a whole-of-society preparedness model - with Confederation of Danish Industry (DI) explicitly pushing for standby contracts, capacity agreements and joint exercises between authorities and companies, not just individual disaster recovery plans filed away and forgotten.


Sweden offers the clearest look at what this looks like once it matures. Since 2015, following Russia's annexation of Crimea, Sweden has steadily rebuilt its total defence model. In early 2026, MSB (Sweden's civil defence agency, now part of MCF) sent a preparedness brochure with concrete planning, exercise and continuity guidance directly to 130,000 Swedish companies, alongside a free course on business continuity planning. That is not an aspiration. It is a government treating private-sector Minimum Viable Company thinking as infrastructure, at national scale. Danish and Nordic boards that still treat this as an internal IT exercise are, on this measure, already behind where regulators expect them to be.


The questions your board should be asking management now

-      Have we mapped our exposure to the Baltics, Poland and Northern European supply corridors - or are we still assuming “that's far away”?

-      Is our cyber resilience built to withstand a state actor, or only ordinary criminal activity?

-      Can every board member personally account for their NIS2 obligations if an incident hits tomorrow?

-      Have we, as a board, actually decided what our Minimum Viable Company is, in line with what NATO and the EU already expect of critical businesses, or are we relying on a vendor's default recovery plan?

-      Do we have an actual scenario for what happens to our business if Russia and a NATO member enter open confrontation - or will we find out in real time, like everyone else?

-      Is geopolitical risk a standing item on the board agenda, or something we react to once the crisis is already underway?


The uncomfortable conclusion

What makes this week different is not that Russia has become more unpredictable. It is that one of the world's best-informed intelligence services has judged the risk serious enough to act on it, publicly and directly. Four years into this war, the boards that treat this as new information are the ones who have quietly failed to do the work already.

At Leadership Capital Group, we work with exactly this kind of decision readiness - moving boards from knowing a risk exists to having actually decided how they will act on it, before a crisis forces the decision for them. Our workbooks on geopolitical risk, cyber security and NIS2 Director Readiness are built for precisely this moment: helping boards and leadership teams ask the right questions, and settle their Minimum Viable Company, while there is still time to act.


Let's have that conversation, before someone else makes the decision for you.


Leadership Capital Group - Independent Decision Readiness advisory

CVR 13565783 - Slotsgade 12, 3480 Fredensborg, Denmark - +45 40 73 90 20 - kontakt@leadershipcapitalgroup.dk - www.leadershipcapitalgroup.dk

 
 
 

Comments


bottom of page
★★★★★
“...moves the conversation beyond governance as process and towards the question that really matters: are we ready to decide? The right evidence. The right challenge. Clear ownership.”
Garry Veale
Board Chair, UK software company owned by BlackRock — one of the world's largest and leading private equity firms — and a director for many years across UK and US technology businesses