The Fractured Map

Navigating Travel Risk in a Post-Alliance World

The maps still look the same. Country borders sit where they have for decades. Risk ratings carry the same amber and red flags that compliance teams have relied on for years. But the underlying architecture is coming apart: the web of alliances, agreements, and mutual obligations that gave those ratings meaning. Quietly, and faster than most frameworks are equipped to register.

As of May 2026, the Strait of Hormuz is carrying roughly two percent of its normal shipping volume. Major Gulf airports have been struck by drone debris. Governments issued Do Not Travel advisories for the entire Gulf region in a matter of hours. And the Alliance that underwrote European security for 75 years is now the subject of contingency planning for what happens when it no longer functions.

For every corporate security director whose travel risk framework still rests on country-level threat ratings refreshed quarterly, the gap between the framework and the reality has never been wider.

The Certainties That No Longer Hold

For two decades, corporate travel risk operated on broadly stable geopolitical assumptions. NATO was a reliable deterrent across Europe’s eastern approaches. Gulf states maintained predictable, if fragile, internal stability. Sub-Saharan Africa’s risk picture, while never simple, followed patterns that experienced security advisors could read with reasonable confidence.

Each has now been tested. Some have not held.

NATO’s unity, once treated as a given, is now the subject of active contingency planning. The Greenland crisis in early 2026 exposed a fundamental perception gap within the Alliance, with European leaders openly questioning whether Article 5 could be relied upon if the United States chose not to invoke it. European officials are now advancing plans for what is being described in diplomatic circles as a European NATO, a parallel deterrence architecture that would function even if the US withdraws troops or withholds support. The Ankara Summit scheduled for July 2026 takes place against a backdrop of the most serious transatlantic tensions since the Alliance was founded. For companies moving senior executives through Central and Eastern Europe, or managing assets in states at the Alliance’s margins, the old assumptions around collective security carry less operational weight than they once did.

The Gulf has moved from alignment uncertainty to active conflict. On 28 February 2026, US and Israeli forces launched coordinated strikes against Iran under Operation Epic Fury, killing Supreme Leader Ali Khamenei and targeting nuclear and military infrastructure. Iran retaliated with hundreds of ballistic missiles and thousands of drones directed at US military bases, Israeli territory, and civilian locations across Gulf Arab states. Dubai and Doha airports were struck by drone debris and closed for days. Emirates and Qatar Airways grounded their fleets. Hundreds of thousands of travellers were stranded. The US, UK, India, and the EU issued Do Not Travel advisories covering the entire Gulf region.

A ceasefire has been in place since 8 April, though it has been violated by both sides. As of late May, Iran and the US are converging on a 14-point memorandum, though the Strait of Hormuz remains effectively closed, carrying roughly two percent of its pre-conflict shipping volume. More than 1,500 commercial vessels remain stranded. This is not a Gulf realignment. It is an active regional war with direct, documented consequences for business travel, executive safety, and operational continuity across the region.

Sub-Saharan Africa has seen the sharpest and most sustained ruptures. The succession of coups documented in recent years, across Mali, Burkina Faso, Niger and Gabon, has continued. Guinea-Bissau fell in November 2025. Madagascar followed in October 2025. Nine African countries have now experienced military seizures of power since 2020. French security influence, which underpinned much of the infrastructure available to Western organisations operating in the Sahel, has retracted sharply. The Sahel remains the most lethal theatre of militant Islamist violence in Africa for the fourth consecutive year, accounting for more than half of all militant group-linked fatalities on the continent. The jihadist group JNIM is no longer simply an insurgency. It is now transitioning into a territorial administration across parts of Mali and Burkina Faso.

Why the Standard Country Model Is Failing

Most corporate travel risk frameworks assign each country a risk category (low, medium, high, extreme), updated quarterly or annually, with major incidents occasionally prompting an out-of-cycle revision. Employees travelling to high or extreme-rated destinations trigger enhanced protocols: pre-travel briefings, check-in schedules, confirmed evacuation plans.

As a structural baseline, the approach has genuine merit. Where it falls short is in pace, granularity, and an understanding of how risk actually moves.

The core problem is that countries are too large and too varied to be useful as a single unit of risk. A country-level rating inevitably smooths over wildly different environments within the same border. The business district of Abidjan is not the same risk picture as the country’s interior. Nairobi’s Karen district and the city’s eastern suburbs are not operationally the same place. The Gulf, as rated in January 2026 and as experienced in March 2026, are not the same environment.

Beyond geography, the model struggles with speed. The Iran war moved from embassy advisories to drone strikes on commercial airports in five days. A framework designed to produce outputs quarterly is, by definition, working with yesterday’s picture. In the Gulf in early March 2026, yesterday’s picture and the operational reality had diverged completely.

A third limitation rarely gets discussed: the journey itself. Corporate travel is not a series of isolated national visits. It is a sequence of movements: executives transiting through hub airports, delegations crossing multiple borders in a single itinerary, crisis response teams deploying under time pressure. The closure of Dubai and Doha airports did not affect the UAE and Qatar ratings in isolation. It fractured travel itineraries across the entire region, including for businesses with no direct presence in either country. A country-rated framework cannot account for that. It was not designed to.

Assessing the Journey, Not Just the Destination

The organisations managing travel risk most effectively have stopped trying to improve the traditional model. They have replaced it with something more suited to how their people actually move.

The shift is from static country assessment to live, journey-level risk planning. Rather than asking what a country’s current rating is, the question becomes: what does this specific trip look like, on these dates, via these transit points, for this individual or team? What are the risks at each stage, and how do they combine?

That question requires a different kind of intelligence. It means drawing on near-real-time information: political incident monitoring, civil unrest tracking, airspace status, infrastructure disruption alerts, and public health signals, analysed locally and applied to the specifics of the journey. A route through the Gulf at the start of February 2026 and the same route at the start of March required entirely different assessments. The framework has to reflect that. It cannot be a document produced once and filed.

The most robust frameworks now work across three layers. The first is the broader environment: political stability, the state of bilateral relationships, active conflict indicators, sanctions status, and treaty obligations relevant to the nationalities of the travelling party. The second is operational: the status of airports and ground infrastructure, what trusted transportation is available, how quickly medical evacuation can be achieved, and how reliable communications are across each stage of the journey. The third is specific to the individual: their profile, their perceived affiliation, any elevated threat indicators tied to their sector or public role.

Each layer informs the overall picture of that journey on that date. When the picture crosses a defined threshold, protocols escalate. Not because someone noticed something in a news feed, but because the framework was designed to catch it first.

What This Requires in Practice

Building a framework of this kind is not a matter of upgrading software. It is a genuine operational redesign.

It requires real intelligence capability. Not aggregated alerts from an off-the-shelf platform, but analysts with genuine regional depth: people who understand why a particular set of political conditions matters for a specific itinerary, and how quickly that could change. The accuracy of any live assessment is only as good as the human judgment shaping it. In February 2026, multiple platform-based risk tools still rated Gulf travel as medium risk while government advisories were telling nationals to leave immediately.

It requires pre-built relationships. The ability to act on an elevated risk picture, whether that means rerouting a journey, positioning a close protection resource, or carrying out a controlled extraction, depends entirely on the network being in place before it is needed. Vetted ground partners, trusted transportation providers, established medical evacuation protocols, and reliable local contacts cannot be assembled at speed. Contingency planning of this kind only has value if it exists before the situation demands it.

It requires organisational alignment that extends well beyond the security team. If a live risk assessment can delay or redirect a board director’s travel, the authority to act on that assessment must be agreed in advance, not debated in the moment by people who have never discussed it before.

And it requires intellectual honesty about what the model cannot do. A well-built framework narrows the uncertainty window significantly. It does not close it. Contingency planning for scenarios that seem unlikely today matters as much as the assessment itself.

A Commercial and Talent Consideration

There is a dimension to this that sits outside the security function but belongs in the conversation.

Senior executives and high-value professionals increasingly factor travel risk management into how they assess an employer. The question is no longer simply whether a policy exists. It is whether the organisation demonstrably treats their safety as a strategic priority, with the infrastructure to support that position.

For firms operating in complex environments such as energy, extractives, financial services and professional services, bespoke intelligence-led travel security is a visible signal of operational maturity. It tells clients and talent alike that the organisation understands the environments it works in and has the capability to respond when those environments change.

A Commercial and Talent Consideration

There is a dimension to this that sits outside the security function but belongs in the conversation.

Senior executives and high-value professionals increasingly factor travel risk management into how they assess an employer. The question is no longer simply whether a policy exists. It is whether the organisation demonstrably treats their safety as a strategic priority, with the infrastructure to support that position.

For firms operating in complex environments such as energy, extractives, financial services and professional services, bespoke intelligence-led travel security is a visible signal of operational maturity. It tells clients and talent alike that the organisation understands the environments it works in and has the capability to respond when those environments change.

Building Frameworks Fit for Purpose

The events of 2025 and 2026 have not created the problem this article describes. They have made it visible. The geopolitical architecture underpinning corporate travel risk planning was already under strain. What has changed is the scale and speed of that strain becoming operational reality.

The practical question for any organisation with internationally mobile employees is straightforward: does the current framework reflect the environment as it actually is, or as it was when the framework was built? If the answer involves quarterly country-tier reviews as the primary mechanism, it is worth examining whether that is still proportionate to the duty of care the organisation holds.

Building something more responsive does not require starting from scratch. It requires honest assessment of where the gaps are: in intelligence capability, in pre-positioned relationships, and in the authority structures needed to act quickly. The operating environment will continue to evolve. The value of a well-constructed travel risk framework is that it evolves with it.

Informed. Proportionate. Prepared.
Priavo Security provides bespoke, intelligence-led travel security, close protection, and corporate risk advisory services for principals, executives, and global organisations. To discuss your travel risk framework, contact us at enquiries@priavosecurity.com

Sign up to our security newsletter

* indicates required
   
By entering your details into our website, you consent to our processing of your personal data in accordance with our Privacy Notice, including for HR & marketing purposes.