Full transcript
[00:04.9]
Hello everyone and thank you for joining. My name is James Burr and I’m a Senior Regional Analyst for Europe, the Caucuses and Central Asia. Today I’ll briefly cover the current risk picture surrounding the ongoing Russo Ukrainian conflict focused on Russia’s most recent large scale missile and drone attack on Kyiv.
[00:20.9]
All information in this presentation comes from publicly available reporting. The key takeaway is that these attacks are creating more than just military challenges. They continue to pose risks to personal safety, business continuity, transportation and cybersecurity. Public reporting indicates that Russia recently carried out what has been described as its largest combined missile and drone attack on Kyiv since the full scale invasion began.
[00:47.1]
Using more than 70 missiles, nearly 500 drones, the attack struck civilian areas across the capital and at the time of recording have reportedly killed at least 20 people. It also reflects Moscow’s ongoing strategy of targeting urban areas and critical infrastructure.
[01:03.6]
Although Ukraine continues to intercept many incoming threats, shortages of air defence interceptors are reportedly placing increasing pressure on its defensive capabilities. Now, looking ahead, the main concern is that these large scale attacks from both sides could become more frequent and more disruptive.
[01:22.7]
For organizations with personnel or operations in Kyiv and across Ukraine and Russia, that could mean recurrent air alerts, temporary transport disruptions, utility outages, communications issues and interruptions to normal business activity.
[01:38.0]
But there are also wider regional considerations. Previous large attacks have prompted neighboring countries to increase air patrols and introduce temporary airspace Restrictions which can affect executive travel, logistics and cross border movement.
[01:53.5]
Across central and Eastern Europe, cybersecurity also remains an important consideration. While there is no evidence that this specific attack was accompanied by a coordinated cyber campaign, previous periods of military escalation have coincided with increased activity by Russian state linked and Pro Russian cyber actors.
[02:13.7]
Organizations and sectors such as government, defence, energy, transportation, logistics and telecommunications may face comparatively higher exposure. Now, looking ahead, Moscow is likely to continue using large missile and drone attacks to maintain pressure on Kyiv and other Ukrainian cities even if they do not significantly change the battlefield.
[02:37.6]
This suggests a sustained period of disruption rather than a short lived escalation. So for clients, the practical takeaway is to continue assessing travel to Kyiv carefully and where operations continue. Consider maintaining shelter procedures, reliable personnel accountability measures, redundant communications and contingency plans for short notice disruptions.
[03:03.9]
Organizations elsewhere in Europe may also benefit from monitoring transportation and airspace developments, reviewing sanctions exposure and regularly exercising cyber incident response plans. Overall, this remains a prolonged strategic risk environment rather than any single attack.
[03:22.0]
The greater concern is that repeated large scale strikes by Kyiv and Moscow could make disruption in major cities more routine, increase regional security measures and create wider, indirect impacts for businesses operating across Europe. Thank you for listening.
Full Transcript
[0:05.2]
Good afternoon, everybody. My name is Adam DeLuca. I’m the director of Risk Intelligence here at Everbridge. And welcome to another rapid resilience video. Today I’m joined by Ignacio Brada. He is one of our leading cybersecurity expert here, and he’s the lead security and AI architect and a proud graduate of Michigan State University.
[0:23.5]
It’s good to see you, Ignacio. Good to see you, Ann. Go green. Yeah. Go white. You know, as we all know, the World cup is coming up in a couple weeks, and I think there’s a lot of threats on everybody’s mind, right? There’s travel challenges, language barriers. There’s going to be strains on infrastructure throughout this unique event that’s spawning three different countries and 16 sites.
[0:45.8]
Now, there’s also possibly domestic violent extremism under the, kind of backdrop of the political climate that we’re in here in the United States. But I don’t think a lot of people hear World cup and think cyber security risk and challenge. But we’re here to tell you today that there are real cybersecurity threats out there surrounding an event like this, and we want to talk about it.
[1:05.6]
So, Ignacio, a lot going on in the world right now. Can you just kind of give us a general overview of the cybersecurity threat landscape heading into the tournament? Absolutely, Adam. And it’s an incredible time. I think, in the cybersecurity world. Things, are changing fast.
[1:22.0]
AI is having amazing developments, and at the end of the day, AI is just a tool. So just how it’s helping us on the different side, the bad thing is that it’s helping the bad guys as well. So I’m sure a lot of people here, have heard about how, bad actors are using, the different LLM models to find zero labeling abilities, string exploitability, windows, since a vulnerability is discovered till someone is able to abuse it.
[1:56.7]
And also, it’s creating, you know, a lot of noise out there in the Internet. Scanners are getting smarter, by guys are using this in large amounts, and it’s relatively cheap. Surprisingly right to use these. Anyone can get access to these.
[2:13.4]
While some of the most dangerous, models are used mainly in research, the current models are pretty strong. And I do think that we’re, we’re, you know, heading into these FIFA, World cup with a lot of that in the news. But it’s also important not to forget the classic cybersecurity threats, right?
[2:33.0]
Phishing, QR codes, just sometimes you know, all the. With all the lights in the news, that captures all our attention. But it’s also very, very important to remember, that the traditional way of attacks, are still happening, and we need to be ready for those.
[2:51.3]
Yeah, well, those, types of attacks, those trade craft, are there for a reason, right? Because the social engineering is very successful. And with AI kind of accelerating the landscape, it’s also, broadening, the amount of threat actors out there.
[3:06.5]
Because AI makes these traditional apt groups associated with large nation states. Now individuals and smaller groups can kind of leverage the same technology and get some of the same results. Obviously, we have a developing situation going on in the Middle east with the Iran, Israel, United, States conflict.
[3:25.1]
Is there any heightened threat coming to the World cup based off of that conflict, or is it just business as usual? No, absolutely, Adam, I’m glad you brought that up. And let me start by saying this. Our organizations do not have to be politically active to become a cyber target here. Right?
[3:46.2]
With, a big event like the World cup, being visible, being visually connected, or being part of that, operational indispensable vendor, of the chain here makes you a target. So, it’s really important to think about that.
[4:02.3]
And then on the other side, I think that, you know, with everything going on in the world, and we’ve seen this in the past, right, the different political actors are trying to take advantage of this.
[4:17.6]
It could be creating disruption to create, political unrest. It could be maybe taking advantage of this for cyber espionage. So definitely, there’s a lot of angles there, that people need to be thinking about in order to stay on top of this.
[4:37.3]
I think one of the key things, right, is we need to understand what the core asset. So, for example, if you’re a broadcasting or streaming platform, the trust is really what separates you from the rest. If you’re a ticketing or payment system, you become part of the operation and the transactions there.
[4:55.5]
So, people can have used that or launch a, denial of service attack, to. To affect that. Not even, you know, if we talk about transportation, hospitality, local services, you know, people are working really, really hard with an increased demand.
[5:11.6]
So the door for, for attackers to, you know, sneak in is a little bit bigger than normal. So. So that’s. That’s definitely an area of focus, I think. And especially with all the geopolitical developments that we’re having, you know, nation state, are going to take advantage of that.
[5:29.2]
Yeah, I mean, it’s a good point. That you make. Because a lot of different sectors are involved, not only in the planning and the preparation for this, but, you know, on the operational side. So, you know, supply chain, you have transportation sector, financial sector, healthcare sector, you know, in these cities. And, you know, these threat groups can go after those sectors in a variety of different ways.
[5:48.0]
Like you’re discussing, you know, so you mentioned QR codes, you mentioned some other social engineering, kind of basic level, cybersecurity, hygiene, type issues. What are some of the other tradecraft and tactics that some of these cyber groups might be looking to leverage, during the event?
[6:07.0]
Yeah, I think, you know, definitely causing disruption. So definitely your denial of service attacks, are what, you know, if you look, if you look at some of those expert agencies, you know, Canada on their side, cisa, they have put a lot of, documentation out there talking about some, some of these things.
[6:27.1]
But, you know, ransomware, that’s always, that’s always there. They can, you know, they will definitely try to take, advantage of, the high volume of transactions and people and things happening, to try to try to find the door and be able to, get some financial benefits from it.
[6:44.7]
I would say, you know, for teams, it’s definitely important, you know, keep the user, and Employees, you know, aware of these. On paying, extra attention, I think, understanding, you know, what are the new traffic patterns that, you know, there’s online services might be expecting, increasing monitoring at the WAF layer, making sure that your dos, protections are in place, being able to scale up to handle the demand.
[7:14.5]
I think those are good things to look at. And Adam, let me just call out one more thing as well. Although it’s not a technical control, I think tabletop exercises are super important in these scenarios. Right. You can look at it, you know, at the top, at the top layer.
[7:30.0]
You have, places like Miami and cisa, right. The city of Miami and CISA did an exercise already specifically, for some of the World Cup. And, you know, if they can do it, I think small organizations can do it too. And this really helps you. One, make sure that you know how to react and respond.
[7:48.4]
And then to the coordination part, make sure you’re ready to coordinate. And potentially you could even find gaps, you know, depending what scenario you have, to be able to, to get in front of those before the bad guys do. Yeah, it’s kind of identifying those unacceptable consequences and kind of ranking a rich risk register. Right.
[8:07.9]
Like, of what you can afford and what, what amount of risk that you’re actually comfortable with. And when it comes to some of these cybersecurity threat actors and the impact that they can, you know, whether it’s ransomware, denial of service, or some of those traditional social engineering attacks, you know, they can cause a lot of disruption.
[8:24.7]
You talked about exercising, right, you mentioned a couple other things that businesses can do to mitigate this threat. But are there any other things that businesses and individuals associated with this event that they can do to actually improve their risk posture? Yeah, I think, you know, I think you call out great things, you know, knowing what your crown jewels are.
[8:44.7]
Right. In order to do a good risk metrics there, you need to know where your crown jewels are. What are those assets that cannot fail? What are those processes that need to be running in order for you to keep operating? And then, based on that, you can start making some risk based decisions.
[9:04.6]
Definitely user training, make sure people are aware and then all the technical controls that we talked about before with AI, I think you can also experiment on some new things. So I’ll give you some things that we’ve been looking at.
[9:21.2]
So for example, making sure that, you’re using AI to scan your public facing infrastructure, and going back to the scenarios. LLMs can be very, useful creating some scenarios for you and help you think about things that you haven’t thought about.
[9:37.6]
So if you’re planning on doing a tabletop exercise, make sure you spend some time playing with LLMs. See what scenarios they can come up with and see if they can look at angles that you haven’t really thought about before so that you can start thinking how you can react to some of those.
[9:54.4]
No, that’s a really good point again about, using AI defensively to monitor and even start recovery on some of these incidents that get into your organization. But Ignacio, it was really good to have you here. I just want to have one more question before you go.
[10:09.9]
Who are you rooting for? Yeah, well, I have my jersey right here, with the third star. So I’ll be rooting for Argentina, the last champion, and the United States as well. So hopefully one of those two, get the championship this year. Yeah.
[10:27.3]
Is somebody that comes, from Italian descent. Unfortunately, the, Italians weren’t able to qualify this year, but, we’ll be pulling for the United States States, over here in this household. But Ignacio, it was really great to have you here and get some of your expert, analysis on some of the threats.
[10:43.2]
Approaching the World cup this year from a cybersecurity perspective. You know, please stay tuned to Everbridge. We have the World cup covered from every angle, whether it’s cyber weather, violent extremism, cartel activity in Mexico. We’ll be producing and alerting and monitoring on all threats surrounding the event.
[11:00.2]
If you have any questions or concerns, please contact us. We’re happy to collaborate, Ignacio. Thanks again. Thanks, Adam.
Full transcript
[00:05.1]
Hey, everybody. Good afternoon. My name is Adam DeLuca. I’m the director of Risk Intelligence here at Everbridge. I’m joined by Caitlin Gillespie, our chief of meteorology. How you doing, Caitlyn? Hey, Adam. Thanks so much for having me. I’m doing really well. Excellent. So as everybody knows, the World cup starts here in about two weeks.
[00:23.6]
And it’s on everybody’s mind, not just because it’s a great event and it’s going to provide a lot of entertainment over the summer months where there’s not a lot of sports on, but it also is going to bring a lot of risks and highlight a lot of vulnerabilities for organizations, you know, nationwide.
[00:39.2]
And one of those is, obviously weather, is very topical on everybody’s mind right now. You know, with 16 host cities spread across the United States, Canada and Mexico, it’s kind of an unprecedented event in the way it’s set up logistically. But what are some of the major weather patterns that we typically see during June and July?
[00:57.9]
And kind of what host regions concern you most from a weather perspective? And what can you actually confidently say today, two weeks out? Sure. And I’ll tell you, Adam, I mean, really, June and July are some of the most operationally complex weather months across North America because we’re transitioning into peak summer, heat, thunderstorm activity, tropical moisture, wildfire season.
[01:22.0]
So the challenge for the World cup is the size of the footprint. The weather risk profile looks very different in Dallas than it does Vancouver, Toronto, Mexico City. So starting in the southern United States, especially that southern tier, the primary concern is extreme heat combined with high humidity.
[01:41.4]
Those considerations and conditions can create significant health and operational challenges for spectators, staff, transportation systems, medical and public safety agencies. Also today, June 1, is the kickoff of the Atlantic hurricane season.
[01:59.0]
So even when the Atlantic is on the quieter side, let’s knock on wood for a second, we still have to account for tropical moisture, heavy rainfall, travel disruption, supply chain impacts, and the possibility of short notice homegrown tropical systems near the Gulf or Southeast coast, especially over the next two months, that’s really when we see that style of system.
[02:19.7]
We’re also watching the Eastern Pacific. That basin’s already showing signs of early areas of interest. So moisture from that region can influence parts of Mexico and at times even the Southwestern United States. So even systems that never directly affect a stadium city can still create rainfall, flooding, travel or logistics concerns.
[02:40.8]
So frequent thunderstorms, another major concern. These storms produce lightning, heavy rainfall, local flooding, short notice disruptions. And lightning, of course, really remains one of the leading causes of event interruption because it forces that immediate shelter decision with little notice.
[02:57.4]
Oftentimes, in Mexico, Monterey, we can experience, of course, the summer heat, but Guadalajara and Mexico City, we’re at elevation. Urban heat, lightning, heavy rainfall, and large population concentrations also play that role. So, you know, in moving into Canada, while temperatures may not reach that same extreme levels, the southern United States heat can really be a concern because those, those large outdoor gatherings, and urban environments can increase that heat stress, especially in populations that are less acclimatized, to prolonged heat.
[03:29.8]
So what I can confidently say today is that heat is certainly our highest weather confidence concern and signal heading into the tournament. The exact timing of thunderstorms, tropical systems, or any of those wildfire smoke episodes, those become clear as we move closer towards individual match windows.
[03:47.9]
But for resilience perspective, the cities that concern me the most are not necessarily the hottest cities, but the cities where weather hazards intersect with large populations, transportation networks that are complex, critical infrastructure, and just overall event operations.
[04:04.9]
that’s a lot of interesting points there, Caitlin. And I think, you know, you touched on it a couple weeks out. You know, we can anticipate thunderstorms or things that, you know, we know heat is gonna, gonna be a factor, not just for the people playing it, but the people organizing it and some of these events surrounding it. So if you were advising FIFA today, let’s say, you know, would heat be your number one weather concern?
[04:25.2]
Because you know, we talked about the heat. Obviously, thunderstorms, lightning could cause shelter in place, tropical storms, even wildfires. Right. Like, we didn’t really touch on that. What would you mostly focused on if you’re an organization? No, I love this question. And of course, yes, heat, I think, remains that number one concern because it’s the most widespread, it’s the most persistent, and just the overall, just most complex risk across our tournament.
[04:52.3]
A thunderstorm or tropical system that can affect one city for a limited period of time, it kind of has that expiration time. Right. But he can affect multiple host cities simultaneously and persist for days or weeks. So the challenge for us is really not just a single hot day.
[05:08.0]
It’s the cumulative strain that develops over time. The conversation focuses mainly, of course, on the athletes and match conditions. But from a holistic resilience perspective and standpoint, the concern is much broader. Heat can impact spectators, security personnel, transportation workers, volunteers, the medical teams, and even the broadcasters waiting, in the queues and the venue staff.
[05:31.1]
So while simultaneously increasing the demand on energy systems, transportation networks, healthcare resources, and public safety operations. And especially if our overnight temperatures remain warm, there’s also the less opportunity for people, buildings and infrastructure to recover.
[05:48.8]
Heat really creates that, potential for both resource fatigue and warning fatigue. Medical personnel or public safety agencies and transportation ops, the venue staff and security, they all may be operating under that elevated stress for extended periods, but there’s also the risk of warning fatigue.
[06:07.4]
So where the repeated heat advisories, extreme heat warnings, that can lead people to become less responsive to the message, even as the operational risk certainly remains elevated. And so maintaining that effective communication, preserving that sense of urgency, becomes just as important as monitoring the weather itself.
[06:26.5]
So that said, like you mentioned, heat’s not the only concern. Lightning remains that hazard that’s the most likely to trigger that immediate operational disruption. It can force rapid sheltering. But heat rises to the top for me, and quite literally, scientifically, as the hazard is most likely to affect the broadcast, the broadest range of people, locations and operations at the same, same time.
[06:49.0]
Yeah, you know, I think you touched on the key point. For me, it’s the effect heat can have over a prolonged period of time on infrastructure. Okay, so like the healthcare system is going to be strained. Obviously, heat over a prolonged period of time has a real serious impact on energy and providing, you know, what that looks like to millions and millions of individuals, around the country.
[07:10.9]
So you know, how heat affects infrastructure and the strain it puts on it over a tournament of this length is going to be something that obviously organizations are going to really need to keep an eye on. But if you are an organization, you are supporting the World cup, whether that’s a sponsor, logistics provider, security teams, corporate travelers, what can they do to improve their operating posture and limit some of the safety issues that heat and thunderstorms can have, leading up to the matches?
[07:39.7]
Yes, absolutely. And get to put the emergency manager hat back on. Organizations that perform the best during these major events are not necessarily the ones with the best forecast. They are the ones with the best decision making process tied to the forecast.
[07:55.1]
So a couple of things, you know. Number one, establish weather thresholds and predefined actions well before the tournament begins. Don’t wait for the heat advisory, the lightning threat or that air quality alert to decide what you’re going to do. Identify the conditions that matter, the impacts that they create and the actions that you’re going to take when those thresholds are reached.
[08:16.6]
Second, focus on protecting people. Heat mitigation plans, hydration strategies, cooling areas, your workforce rotation schedule, and your medical surge planning should all be established before match day. So protecting personnel ultimately protects operations.
[08:34.1]
Identify those critical dependencies. I like this point. Because weather rarely creates the biggest disruption directly. The larger disruptions occurs when weather affects a dependency. So transportation, staffing, communications, power supply chains or public safety.
[08:51.4]
So organizations, we should be asking what happens if transportation is delayed? What happens if power reliability is affected? What happens if air quality deteriorates or if a venue or fan zone has to temporarily shelter in place? What happens if our deliveries or staffing or executive movement are disrupted?
[09:09.8]
So understanding these downstream impacts is essential to maintain that continuity aspect, increase our monitoring as our event approaches. Our seasonal outlooks that we discussed in our awesome webinar last month, those provide great strategic awareness. But operational decisions should now start to rely on the shorter range forecast and real time intelligence.
[09:31.1]
So as we move into like that five to seven day, but certainly within that 72 hour window, organizations start to shift from planning mode into that operational readiness, and maintaining that common operating picture. The most resilient organizations are those where security teams, logistics providers, venue operators, emergency managers and the public safety folks.
[09:53.4]
We are all operating from the same picture, with the same information. And so when our stakeholders are sharing information quickly and consistently, they can make those decisions before small disruptions become the large operational problems. At the end of the day, weather intelligence really only creates value when it informs action.
[10:13.4]
So the organization that, that performs the best are the ones that really connect weather information to decisions early enough to stay ahead of a curve. Right. I think you touched on a couple really important mitigation strategies that highlight and kind of separate what successful organizations do and then, what some organizations might get caught off guard.
[10:33.6]
One is scenario planning. You know, we talked about it on the webinar, a month ago, with, with the planners out in Los Angeles talking about how important it is to, to plan for scenarios and exercise with your people so you know how to make those decisions. When something does go wrong, you know, it just shows how important it is that flexibility and then also identifying your unacceptable consequences, you know, due to weather, you know, it is, it can be unpredictable.
[11:00.1]
But, you know, if you’re identifying your unacceptable consequences and your risk regime register, you understand how we can start to prioritize and approach risk and become more resilient. So, you know, I, I do want to say thanks for joining us today, Caitlin. It’s always a pleasure to get to talk to you. Who you got in the tournament? Who are you rooting for?
[11:17.2]
I mean, of course, Team usa. I’m rocking with them. Absolutely. How about you? How about you? Well, you know, I’m not too confident in their, in their chances this year, but I am an American through and through, will be rooting for the United States, win or lose. But just looking for an exciting tournament and some good entertainment and hopefully everybody can stay safe from the weather and all the other risks, that kind of come up due to an event of this size.
[11:41.8]
So Everbridge will continue to report on any and all risks and vulnerabilities associated with the World cup, both forward leaning and strategically as well as tactically during the tournament. So, Caitlin, thanks again for joining us. Talk to you soon. Thank you so much.
Full transcript
[00:05.0]
Hello everyone and thank you for joining. My name is James Burr and I’m a senior regional analyst for Europe, the Caucasus and Central Asia. Today I’ll give a brief overview of the recent the stabbing attack at the Wintertour train station in Switzerland and what these types of security incidents may mean for businesses and travelers near busy transit hubs.
[00:24.2]
All information is brief and is based on publicly available information and official statements available at the time of recording. On May 28th Swiss authorities reported that a man stabbed three people at The Vintator railway station. Officials described the attack as terrorism related and the suspect was arrested shortly afterwards.
[00:44.1]
While investigators currently believe this was a lone act incident, it highlights how crowded open access transit sites remain vulnerable to low complexity attacks. The stabbing caused immediate disruption including police cordons, restricted access and a visible security presence.
[01:01.2]
Even though the casualty count was limited, the operational impact was broader affecting commuters and nearby businesses. For such businesses the main risk following these types of incidents is short notice localised disruption in the near term, elevated police visibility and possible restrictions around impacted stations and nearby transit sites are to be expected.
[01:24.1]
So offices, retail sites, hotels and commuter dependent workforces near transit hubs may face access issues, delayed arrivals and reduce foot traffic after similar events. There is also a duty of care issue.
[01:39.2]
Employees, travelers and customers may feel unsafe or face confusion during fast moving security events. Our Clients are therefore encouraged to review staff communication plans, flexible commuting options and contingency procedures in light of the stabbing attack.
[01:56.0]
Looking ahead, the broader security picture in Switzerland does not appear to have changed significantly. But the attack reinforces a wider regional trend. Busy public transit hubs remain attractive targets because they can create outsized disruption with limited force.
[02:12.3]
Key indicators to watch include evidence of coordination, additional arrests, online calls for violence or follow on attacks at other transport sites. If authorities confirm the case remains isolated then the risk outlook should stabilize.
[02:28.7]
Overall this incident is a reminder to keep transit related contingency planning and employee communications under review especially in dense urban And commuter heavy commercial areas. Thank you.
Full transcript
[00:05.0]
Hello, everyone. Thank you for joining. Today's video focused on 2026 Mayday, otherwise known as International Workers Day. My name is James Burr and I'm a Senior Regional Analyst on Everbridge's Global Insights team. Mayday is expected to bring widespread demonstrations, rallies and public gatherings across multiple regions globally.
[00:23.4]
While many events will remain peaceful and even celebratory, the scale and concentration in major cities mean localized disruptions are highly likely. This year, we're also seeing broader themes shaping participation, particularly cost of living pressures, geopolitical tensions and concerns around labor displacement, including artificial intelligence.
[00:43.6]
Overall, the primary risk is operational rather than security driven, but escalation remains possible in select environments. Starting in Europe and Latin America, these regions present the highest likelihood of disruption. Countries like France, Germany, Spain, Brazil, Brazil and Argentina are expecting large scale mobilizations and coordinated union activity, particularly in capital cities and economic hubs.
[01:08.0]
Elsewhere in the Asia Pacific region, activity is more uneven. Indonesia and the Philippines are expected to see notable demonstrations, while countries like China and Australia are more focused on holiday travel, which may still strain transport systems.
[01:23.7]
Across the Middle east and North Africa, activities mix, with Turkey standing out due to a higher risk of disruption from large planned rallies in Istanbul. Most other countries will see more controlled or symbolic events. Meanwhile, in North America, protests are expected to be widespread across major US and Canadian cities, with generally localized and short term impacts.
[01:45.8]
Finally, in sub Saharan Africa, events are largely formal or state organized, though Nigeria and South Africa may see more active labor mobilization now. From a business perspective, the key risks are operational. Expect transport disruptions, including road closures, public transport delays and restricted access to commercial districts, particularly from late morning through mid afternoon.
[02:08.6]
There is also a risk of localised supply chain delays, especially where protests intersect key logistics corridors or ports. While most events are expected to remain peaceful, isolated clashes, property damage or heightened security measures could create short term disruptions, particularly where counter protests or political tensions are present.
[02:29.8]
Even in low risk markets, holiday travel surges may still impact employee mobility and logistics. So, looking ahead, the overall risk profile for Mayday 2026 remains manageable but highly localized. The most significant disruptions will likely be concentrated in major urban centres, particularly in regions with active labour movements or ongoing economic pressures.
[02:51.6]
For businesses, early planning, such as adjusting travel, monitoring local developments and maintaining operational flexibility will be key to minimizing impact. Escalation risk remains situational, tied to turnout levels, policing posture and the presence of opposing groups.
[03:09.8]
In short, while Mayday is a predictable annual event, this year's broader social, economic and geopolitical context may amplify participation and with it. The potential for disruption. Thank you for listening.
Full transcript
[00:05.4]
And thanks for joining. My name is James Burr and I'm a Senior Regional Analyst for Europe, the Caucuses and Central Asia. As of early April, we're seeing a developing security concern across parts of Europe involving attempted and low level attacks targeting US linked businesses and sites as well as Jewish linked institutions and places of worship.
[00:26.1]
This assessment is based on publicly available reporting, including recent incidents in Belgium, the Netherlands, Norway and the UK as well as the most recent foiled explosive device plot outside a Bank of America office in Paris. While attribution remains unclear, in several cases some attacks have been claimed by a pro Iran group, the so called Islamic Movement of the Companions of the Right.
[00:50.3]
Against the backdrop of heightened tensions linked to the war involving Iran, what we're seeing is not a pattern of high complexity mass casualty attacks, but rather, low complexity symbolic targeting. The Paris plot for example, appears to have involved relatively simple means and potentially decentralized actors, possibly recruited or coordinated through informal channels.
[01:14.3]
Separately, there have been arson and attack plots reported across several European countries. And a recent explosion outside the US Embassy in Oslo reinforces the risk of symbolic targeting of diplomatic or US affiliated sites. Taken together, this suggests a potentially diffuse cross border threat environment where individuals or small cells act with limited sophistication but clear ideological alignment.
[01:41.6]
For businesses, particularly those with visible US Israeli or Jewish affiliations, the risk is less about major acts of violence and more about accessibility and symbolism. Offices in urban centers, especially those with recognizable branding, can be approached through normal foot traffic, making them inherently harder to fully secure.
[02:03.5]
Even unsuccessful or low impact incidents can still lead to operational disruption, including police cordons, restricted access, increased security checks and short notice travel obstacles. There's also a reputational and duty of care dimension as employees may feel heightened concern, particularly at or near businesses or locations where incidents have recently taken place.
[02:29.1]
Looking ahead, we assess that security postures around US Linked and other symbolic sites in Europe will remain elevated in the near term. But the key variable is attribution. If a clearer Iran linked or proxy enabled network is confirmed, threat could become more sustained and geographically widespread.
[02:49.6]
In the meantime, the most likely scenario is a continuation of sporadic low complexity incidents with potential for copycat activity or opportunistic targeting. So for clients, the focus should be on situational awareness, employee movement, planning and engagement, local security guidance, rather than expecting large scale attacks, but also not dismissing the cumulative impact of smaller ones.
[03:17.0]
Thank you for listening.
Full transcript
[00:05.2]
Hello, my name is Zsolt Chepregi. I'm the Regional Analyst for the Middle east and North Africa at Everbridges Global Insights team. Today I will outline the current state and immediate forecast of the U. S. Iran nuclear negotiations that are taking place in Oman as of Friday, February 13th.
[00:22.8]
The most significant new development, is that the US is dispatching the USS Gerald R. Ford aircraft carrier and accompanying warships to join the USS Abraham Lincoln carrier strike group already present in the Middle East. Thereby, it's significantly reinforcing its military leverage over the next stage of diplomacy with Tehran.
[00:43.8]
On the diplomatic calendar. We still do not have a confirmed date for the next round of negotiations, but Ovan remains central. Muscat is not just the venue, it's functioning as a container that both sides accept, keeping the diplomatic channel alive even as military pressure rises around it.
[01:00.9]
The main point to note right now regarding the upcoming talks is that both sides appear to be settling, at least for the time being, on discussing only Iran's nuclear program and what the imposed constraints and verification would look like. Tehran has framed the Muscat talks as a good start, but, also as a process focused strictly on nuclear terms.
[01:22.7]
Not its missiles, not its regional proxies, and definitely not its domestic politics. Iran has also signaled an openness to comprehensive nuclear inspections. That matters because inspections and verification are the foundation for any sustainable nuclear agreement guaranteeing that Iran will not be able to move toward a nuclear weapon from the US Side.
[01:45.2]
However, reporting out of Washington continues to suggest a broader ambition for the talks. Even if the current plane is nuclear, only the US May be interested. And it's also urged by its primary regional partner, Israel, to eventually expand the scope toward ballistic missiles and Iran's regional activities.
[02:05.7]
So what can we forecast? The most likely near term outlook is a month of tense calm as diplomacy continues under intense military pressure. This is in line with US President Donald Trump's stated outlook on the time horizon to achieve a deal.
[02:21.7]
However, there is a real chance of derailment if the scope, question, verification terms or sanctions relief sequencing becomes a hard stop for either side. For businesses operating in or exposed to the Middle east, the key risk channels are sanctions, volatility and any escalation that disrupts travel and logistics.
[02:42.4]
Additional sanctions pressure can create cascading compliance, banking and supply chain effects. And while a military flare up could trigger short notice airspace restrictions, maritime disruption and temporary travel interruptions, cyber risk also tends to rise during periods of heightened US Iran tension.
[03:01.1]
So organizations should maintain elevated monitoring, validate contingency travel and routing plans, and ensure that incident response and third party risk controls are current.







