Skip to content

Article

Hybrid Threats and Geopolitical Uncertainty

The rapidly evolving hybrid threat landscape and a steady stream of new security regulations are creating major challenges for many organizations. How do you navigate an increasingly unpredictable environment safely and effectively while continuing to support the core business?

In this article, Vaern security expert Niels Trads Pedersen explains the principles behind integrated risk management, and why this approach is particularly relevant today.

Niels Trads Pedersen - Vaern

September 1, 2026 · Niels Trads Pedersen

  • Compliance and Regulation

Integrated Risk Management for a Changing Threat Landscape

When older generations tell their children and grandchildren that they barely recognize the world anymore because everything is changing so quickly, they have a point.

Today’s world is defined by constant change, and long-held assumptions are regularly challenged by events that shift the direction of society. Whether we like it or not, we have to adapt. That applies to decision-makers in both public- and private-sector organizations.

To make the growing hybrid threat landscape and its complexity more manageable, Darize is hosting a security event on January 21, 2026. The event, “Risk Management in the New World Order,” is organized in collaboration with the think tank Ny Verden and Terma.

The central message is clear: More threats and more security regulation require an integrated approach to risk management.

Integrated risk management brings technology, security, compliance, and business needs together in one coordinated governance model.

This enables organizations to respond proactively and reactively to threats and regulatory requirements while keeping business priorities at the center of decision-making and ensuring commercial objectives remain achievable.

Seeing the Bigger Picture

Niels Trads Pedersen is a security advisor at Vaern with extensive experience in security and risk management. He is also one of the speakers at the January 21 security conference. He understands why organizations may struggle to navigate the growing threat landscape and compliance burden.

“New regulations keep coming, and threats are changing from month to month as geopolitical tensions ripple across borders. From a risk and security perspective, the unfortunate result is that everything starts to seem important. And when everything is important, nothing gets prioritized.

“That’s exactly why organizations need a governance model that provides a complete picture, reveals connections across the business, and enables the right action at the right time. That is the core idea behind integrated risk management,” says Niels Trads Pedersen.

Three Principles of Integrated Risk Management

At the security conference, Darize will explore integrated risk management in greater depth, including how to apply it at the strategic, tactical, and operational levels. Here, Niels shares three fundamental principles behind the approach.

“The first is decision intelligence and judgment. The opposite of decision intelligence is giving an organization’s decision-makers a long list of technical details. What are they supposed to do with that information?

“They need security threats translated into business risks. For example, an immediate threat might mean production is down for five days. That is something decision-makers can understand because it’s a risk they can quantify,” Niels says.

“Decision intelligence isn’t about producing more reports. It’s about creating a consolidated view of risk by connecting data, experience, and judgment across disciplines.

“When we consolidate operational and compliance risks—from IT and information security to physical and personnel security—we break down traditional silos. This gives decision-makers the actionable insight they actually need and creates a shared foundation for priorities, accountability, and speed.”

“You cannot effectively protect an organization against threats if it isn’t connected from top to bottom. Integrated risk management is built on coordinated action, a common language, and a clear governance model where everyone knows who owns each risk and how it should be managed.”

A Security Advisor’s Perspective

“You cannot effectively protect an organization against threats if it isn’t connected from top to bottom. Integrated risk management is built on coordinated action, a common language, and a clear governance model where everyone knows who owns each risk and how it should be managed.”

Niels Trads Pedersen

Security Advisor, Vaern

Expect Change

The second principle of integrated risk management is agility and adaptability.

“Agility has become a somewhat overused term, but the underlying idea still matters. Organizations need to be able to change direction when the threat landscape changes—and these days, that happens frequently. If your decision-making processes don’t allow you to adapt to a new reality, you can quickly find yourself stuck in the past,” Niels says.

“Adaptability goes deeper. It means making readiness for change a fundamental organizational capability, including in how resources are allocated.

“Take the Danish Armed Forces as an example. It wouldn’t be a sound strategy to spend the entire budget on capabilities designed solely to address the threats we face today. We can say with a high degree of confidence that the threat landscape will change again before long.

“Ultimately, agility and adaptability are about governing with structure while acting with flexibility. It is the combination of control and flexibility that creates organizational resilience.”

Connected Governance Across the Organization

The final principle of integrated risk management is genuine alignment across departments, organizational levels, and disciplines.

In practice, this means moving away from siloed governance and bringing security and compliance disciplines together within a single governance model.

When organizations move beyond traditional function-based roles—where, for example, the CISO function operates in isolation—and toward a more holistic Chief Security Officer or Chief Resilience Officer structure, they create a connected foundation for decision-making, prioritization, and strategic resilience.

“You cannot effectively protect an organization against threats if it isn’t connected from top to bottom. Integrated risk management is built on coordinated action, a common language, and a clear governance model where everyone knows who owns each risk and how it should be managed,” Niels says.

“When governance, processes, and communication work together, you create alignment and a shared direction.

“The key is to make sure the governance model doesn’t become so rigid that it stifles initiative and progress. The goal is to establish a model that strengthens collaboration and learning. Because when the next wave of threats arrives, you’ll need those shared experiences,” he concludes.