The Corporate Citizen Reimaged: Human Security Matters

By Richard Howitt, Skytop Contributing Author and Host of “Corporate Rapporteur”, SkytopTV Talk Show Series / July 23, 2026

Richard Howitt is member of the Speaker Faculty and Contributing Author at Skytop Strategies and host at SkytopTV. He is Strategic Advisor, lecturer and Board member, specialising in Corporate Responsibility and Sustainability, Business and Human Rights. A former longstanding Member of the European Parliament responsible for the EU’s sustainability reporting rules, Richard was also Spokesperson for the Foreign Affairs Committee of the Parliament, covering conflict prevention, conflict resolution and respect for human rights worldwide. Richard helped lead global efforts as Chief Executive Officer of the predecessor organisation which merged to form today's International Sustainability Standards Board. He was named Top 50 Global Influencer in Environment, Social and Governance, (ESG). Richard is also host of the 'Frankly Speaking' responsible business podcast. 


As European countries increased military spending by $90bn last year and the U.S. administration seeks to replenish $70bn in armaments in relation to the conflict in Iran, defense industries are undergoing an unprecedented period of change.

But as security leaps up the priority list for Governments worldwide, the new age of insecurity is impacting companies across many sectors of the economy, far beyond direct military needs. 

It is estimated that security implications impact up to 70 per cent of the economy, with only a few sectors such as hospitality, healthcare and local services, largely insulated. 

Companies should be asking how are they affected? 

Critical Sectors

The Cybersecurity and Infrastructure Security Agency has named 16 critical industrial sectors which are vital to national security, from chemicals to food production, energy to financial services. 

The thinking is that a successful attack on any of these sectors would have such a devastating effect on national security, economic stability or public health, that it would gain significant military advantage. 

The bouncing bombs of the Second World War's dam busters raid, are bouncing higher and wider. 

An attack on defense industry plant and equipment is allowed under international law, but Articles 52 and 54 of the Geneva conventions limit and, in some cases, prohibit military action against industries meeting civilian needs. 

States engaged in conflict must observe the principle of distinction, ensuring that any harm to civilians does not outweigh anticipated military gains.

But as the 'whole civilisation will die tonight' threat shows, parties to a conflict cannot be relied upon to respect the rules of war. 

Learning Lessons

There will be many in companies outside the defense sector who will find this as too far-fetched and regard defense of their assets to be the prerogative of Government alone. 

However, for some years, private companies involved in critical infrastructure have been cooperating with security services to plan against terrorist attack. 

Airline hijacking, most notably 9/11, the Madrid train bombing and the Charlie Hebdo attack in France, show the necessity of such preparations. 

Meanwhile, the advance of Artificial Intelligence is making the impact of cybersecurity threats ever more potent. According to the IBM Threat Intelligence Report 2026, attacks on company IT systems and by active ransomware groups have both increased by nearly 50 per cent in the past year. 

European Union figures show that states are targeted by only 19 per cent of cyber-attacks, private companies and individuals are the victims in 81 per cent of cases. 

Meanwhile, tech company Clarity reports that 81 per cent of cyber-attacks originating in Iran targeted organisations in the U.S. and Israel, 71 per cent from Russia targeted organisations in European Union countries.

This is a weapon of war. 

Preparing for State Conflict

It is time for companies not simply to connect the dots in planning against terrorist and cyber-attacks, but to begin to do so in relation to potential state conflict. 

For anyone still not convinced, it is important to stress that all such attacks do not have to be controlled by a hostile state, for there to be a concerted threat. 

There has been the rise of what have been termed 'ideological hacktivists', who operate entirely independently, but in full sympathy with the state in which they live or are associated. 

In defense circles, it is now commonplace that adversarial states are engaging in hybrid war, including cyber-attacks, disinformation campaigns, economic and political interference.  

Companies are getting used to significant spending on cyber security - protection which largely works - but need to start to understand their role in human security too. 

The good news is that this doesn't require the creation of huge new private security services but is achieved through detailed cooperation with national authorities and in training and awareness raising amongst employees. 

Scandinavian countries are playing a leading role in working with their business communities in this regard. 

Many of the conversations necessarily take place in private, but companies everywhere need to ensure that they are not missing out. 

Whole of Society

It is in the need for building awareness within the company, which is perhaps less well understood. 

Just as the concept of 'hybrid war' has become commonplace, it is quite possible that a new concept of defense - 'a whole of society approach' - will become increasingly prevalent. 

This describes a range of societal responses to defense needs, including volunteers for homeland security, preparedness for crises amongst the population and plans for recovery after major disruptions. 

It is also argued that building trust and unity in communities, makes them less vulnerable to foreign interference. 

These can be just as much a deterrent to foreign aggressors, as conventional armed forces. 

In this context, business is the ideal partner, for itself and amongst its workforce, because it is nurturing a concept which companies already embrace - that of resilience. 

Business understands the need to prepare for major incidents, for shifts in the market and in the need to develop an adaptive capacity to respond to change. 

It is time to apply those concepts to the security of the company and the safety of those who work for it. 

Malign Forces 

This is not a theoretical challenge. 

Perhaps it does not matter whether events such as the CrowdStrike outage which stalled Microsoft systems worldwide, the energy loss which caused the closure of London Heathrow Airport or the closure of the Straits of Hormuz, were caused by a malign force or not. 

The security of the company and its business are compromised and best solved if the company ensures that plans for business continuity incorporate a security perspective.

And just like cyber security it can work. 

Despite constant attack from Russia in very much conventional as well as hybrid ways, private companies have adapted in Ukraine. The country has increased its export of agricultural products and achieved economic growth in three of the four years since the invasion. Despite power blackouts hitting its population, Ukraine has been able to maintain its energy exports.

If companies can be as creative and resilient when war has already begun, there is an open challenge to all companies to take an active part in ensuring that it never happens at home. 

Next
Next

AI and Boards: It Is Time to Get Practical