
Field Notes
APAC's Geopolitical Risk Mispricing: Why Corporate Risk Registers Are Running a Region-Wide Blind Spot
TL;DR
G4S's 2025 World Security Report found APAC company executives face the world's highest risk of targeted violence. That finding does not appear in most APAC risk registers, which still score the region below the Middle East and Eastern Europe.
G4S's 2025 World Security Report, drawn from interviews with corporate security officers across 31 countries, found executives in APAC at greater risk of violence than those in any other region.[^1] The Aon Global Risk Management Survey 2026 found APAC risk leaders consistently rank cyber attack or data breach as their top current and future risk, while geopolitical risk surged ten places in APAC future risk rankings compared with Aon's previous survey. What we infer: attention is arriving, but it is arriving as a forecast rather than as a control, which is a different thing from being unaware.[^2] Most corporate risk registers treat APAC as a growth region with manageable, well-understood risk. The gap between that perception and what the data shows is wider here than in any other geography.

Why the Standard APAC Risk Register Misprices the Region
The IIA 2026 APAC Risk in Focus report found most organisations in the region run some of the most complex and globally integrated supply chains in the world, yet only 11 percent of APAC respondents have evaluated risk financing solutions for supply chain disruption.[^2] The gap is not negligence but a structural mismatch between what gets measured and what is actually moving.
- The G4S executive violence finding. APAC executives face a higher risk of violence than peers in any other region.[^1] Most corporate security protocols in APAC are calibrated to a risk level that sits below what that evidence supports.
- The Aon operational underweighting finding. APAC risk professionals are measuring geopolitical risk as a ranking rather than tracking it through the operational consequence chain, the sequence that runs from policy signal to supply chain impact to capital exposure. What we infer: a risk that moves ten places in a survey and nowhere in the control environment has been noticed, not managed.[^2]
- The Taiwan binary error. Most risk registers treat a Taiwan scenario as a catastrophic, low-probability event. The more operationally relevant risk in 2026 is the ongoing campaign of coercive signalling, military exercises, and cyber operations that affects investment confidence and supply chain continuity before any kinetic threshold is crossed. That gradient of escalating pressure is not what most APAC risk entries describe.

The Five Structural Drivers That Corporate Monitoring Misses
Each of these drivers is visible in open-source data and requires no classified access to track. What they require is a monitoring framework designed to detect them, not one calibrated around the conventional APAC growth narrative.
- ASEAN supply chain concentration. Companies shifting production from China into Vietnam, Indonesia, Thailand, and India have moved their concentration risk, not reduced it. Vietnam carries its own political dependencies, labour regulatory risks, and proximity to South China Sea flashpoints. A company that has not remapped geopolitical exposure onto its new supplier base has moved from one blind spot to another.
- India-China LAC corridor. The Line of Actual Control remains an active flashpoint with periodic escalations. For companies with supply chains, infrastructure exposure, or counterparties in Ladakh, the northeast Indian corridor, or the tri-junction zones, this is a named operational risk that sits entirely outside most corporate geopolitical monitoring frameworks.
- North Korean cyber-enabled financial crime. US Department of Justice prosecutions concluded in November 2025 covered fraudulent employment schemes that reached more than 136 US victim companies, generated over $2.2 million for the North Korean regime, and compromised the identities of more than 18 US persons.[^3] The exposure is not geographically limited to the Korean Peninsula. Any company with proprietary technology, cryptocurrency treasury exposure, or defence-adjacent operations carries this risk regardless of its APAC footprint.
- Jurisdictional divergence. APAC is not a single regulatory environment. It is sixteen countries with rapidly diverging frameworks on data privacy, AI governance, sanctions compliance, and export control implementation. Singapore, India, Japan, South Korea, and the Philippines each interpret the US-China technology competition differently, and each is legislating accordingly. A company operating across all five is managing five distinct and shifting compliance requirements simultaneously.
- City-level executive threat variation. The risk profile for Jakarta, Manila, and Ho Chi Minh City is not merely different in degree. It is different in nature. The Philippines carries kidnap-for-ransom exposure at senior executive level. Jakarta carries risks linked to infrastructure and extractive industry disputes. A generic APAC executive security briefing does not address this distinction. A city-specific, sector-specific, and visit-specific threat assessment does.[^1]

What Geostrategic APAC Coverage Requires from Risk Functions
The capability gap is not about intelligence access: the data exists across G4S, Aon, the IIA, and multiple regulatory bodies. The gap is in monitoring structure: what gets tracked, at what frequency, and whether the output connects to the functions making operational decisions.
- Active South China Sea incident monitoring. Not academic commentary updated quarterly. Incident-level tracking of PLA naval activity, Taiwan Strait crossing events, and coercive signalling cadence, with a defined threshold for escalation reporting to logistics and procurement functions.
- Country-level political risk tracking for the top five operational markets. Each track calibrated to the company's sector and counterparty profile, not regional averages. The risk picture for a defence-adjacent technology company in Seoul is materially different from the same company's exposure in Singapore or Manila.
- Executive pre-travel briefings at city and sector specificity. The G4S data requires a response. Calibrating pre-travel briefings to the actual documented threat level by destination and executive profile is the minimum the evidence now supports.
- Consequence chain mapping for Taiwan escalation. A scenario assessment that extends past any immediate kinetic event to second-order effects on chip supply, electronics component availability, financial market volatility in regional currencies, and contract force majeure implications. This can be modelled before an event occurs. Most organisations have not done it.
Fortius Intel note: The G4S and Aon findings are consistent with what Fortius Intel observes across client risk registers: APAC carries a risk score that reflects its investment case, not its threat environment. The data to correct that score is publicly available. The gap is not one of intelligence access. It is one of monitoring design.
Methodology: Analysis draws on G4S World Security Report 2025, Aon Global Risk Management Survey 2026, IIA 2026 APAC Risk in Focus report, Fenergo APAC Compliance Report March 2026, and US Department of Justice findings on North Korean IT infiltration cited by Google Threat Intelligence and The Guardian February 2026. All cited sources are publicly available.
Footnotes
About the author
Shekhar Attri, Co-Founder & CTO. An Indian Army Special Forces veteran with 21 years of service and a gallantry medal, Shekhar's corporate security advisory work spans Singapore, India, the Philippines, and the UAE, alongside PhD research on machine intelligence under incomplete information.