Skip to content

Understanding the Framework For Managing Business Risk During Political Unrest

Liferaft |    September 29, 2026

Illustration of North America illuminated by interconnected networks, representing the spread and interconnected nature of political violence and instability.

Political and Civil Unrest is on the Rise

ACLED recorded close to 20,000 demonstrations in the United States during 2025, an increase of roughly 77 percent over the previous year and the highest annual total since 2020. Around 97 percent of those events involved no violence and no police intervention, which is the figure security teams tend to overlook when planning. Disruption to a corporate site rarely requires violence. A march routed past a lobby entrance, a blocked loading dock, or a lunchtime demonstration outside a flagship store affects operations regardless of whether anyone breaks a window.

The financial tail matters as well. Insured losses from the 2020 unrest in the United States topped $2 billion, the costliest civil disorder in Property Claim Services records going back to 1950, well beyond the $775 million from the 1992 Los Angeles riots. Analysis published through the World Economic Forum found that roughly one third of those industry losses traced to just three retailers, which shows how concentrated exposure becomes when an organization has many public-facing locations.

Conditions ahead are not easing. Verisk Maplecroft's Civil Unrest Index places seven of the world's largest economies among the countries facing the most disruption over the coming year, with Europe holding five of the ten highest-risk positions and the United States ranking third after recording the sharpest increase in protest size.

 

What Businesses Do to Manage the Risk

Most organizations handle unrest through improvisation. Someone sees a post about a planned march, forwards it to facilities, and a decision gets made a few hours before doors open. That approach works until two sites are affected on the same day, or until an insurer or executive asks what the decision was based on.

A framework replaces that pattern with a repeatable sequence. The structure below follows the logic of ISO 31000, the international standard for risk management, which moves from establishing context through assessment, treatment, and ongoing review. Applied to unrest, it produces four components that a security team can actually staff.

 

Framework for Managing the Risk of Unrest

 

Organization Assessment.

Map what the organization owns and where it is exposed before looking at any external threat. That includes site locations and their proximity to civic buildings, transit hubs, campuses, and traditional protest routes, plus the brands, executives, and policy positions that could draw attention. Organizations that have taken public positions on contested issues, operate in sectors under activist scrutiny, or hold government contracts carry a different baseline than a distribution business nobody talks about.

Risk Assessment. 

Combine that internal picture with external monitoring. Analysts track mobilization calls, event pages, coalition announcements, and local commentary tied to named sites, then judge each against likelihood and potential impact. A call to action circulating among a few dozen accounts a month out sits differently from a permitted march with a confirmed route passing a facility next Tuesday.

Mitigation. 

Match the response to the assessed level. Options range from cheap and reversible, such as adjusting delivery schedules, moving a town hall, or briefing lobby staff, through to costly measures like boarding glass, hiring additional officers, or closing a site for a day. Documented triggers keep those decisions proportionate, since closing a site every time a protest is announced carries its own cost.

Continuous Improvement. 

After each event, record what was predicted, what happened, and what the response cost. Patterns emerge across a year that no single incident reveals, including which monitoring sources give the earliest warning and which sites keep appearing.

 

 

How to Implement the Risk Management Framework

Start with a named owner and a written trigger table. Each threshold should specify who decides, who gets informed, and what action follows, so a Saturday alert does not depend on someone's judgment about whether to wake a director.

Anchor monitoring to specific places and names rather than broad topics. Queries built around facility addresses, neighborhood names, executive names, and brand terms produce reviewable volumes, and threat monitoring and alerting tied to those terms gives analysts something to work from instead of a topic feed. Mapping activity against site locations through situational awareness tooling puts distance and direction into the assessment, which is what separates a demonstration two blocks away from one at the front door.

Bring HR, legal, communications, and facilities into the trigger table before an incident. Decisions about remote work, building access, and public statements sit outside the security function, and the organization's duty of care obligations to employees traveling to or working at an affected site cut across all of them.

Keep the record. Logging assessments and decisions in case  management, and reviewing them through risk trends and analysis over quarters rather than days, is what turns a year of scattered incidents into a defensible program. Liferaft's work on measuring threat escalation velocity covers one method for judging how quickly an emerging situation is building.

 

Dive Deeper

The full framework, including assessment templates, trigger examples, and guidance on structuring the post-event review, is available in our whitepaper on managing business risk during political unrest, in the Liferaft Resource Centre. Teams that want to see how continuous monitoring supports each stage can also book a discovery call.

 

 

FAQs

Why is it important for businesses to prepare for civil and political unrest?

Preparation determines whether a decision gets made hours or minutes ahead of an event. Unrest affects operations well below the threshold of violence, through blocked access, transit disruption, staff unable or unwilling to travel, and pressure on brands drawn into a dispute. Employers also carry legal obligations to their workforce, including the general duty under US occupational safety law to provide a workplace free from recognized hazards, and comparable duty of care obligations elsewhere. Organizations without a documented process end up making improvised calls that are difficult to justify afterward to insurers, regulators, or their own leadership.

 

How does civil unrest risk management compare to natural disaster preparedness?

Both use the same skeleton: assess exposure, monitor for warning signs, prepare graduated responses, and review afterward. The differences are in the signals and the timeline. Weather forecasting is quantitative, publicly available, and relatively reliable over days. Unrest warning signs appear in open sources as organizing activity, calls to action, and commentary, which require analyst judgment about credibility and turnout. Unrest is also targeted in a way that weather is not, since a specific brand, executive, or policy position can put one facility at risk while a neighboring building sees nothing.

 

What role does technology play in managing civil unrest risks?

Technology covers collection and correlation. Continuous monitoring across social platforms, forums, and local sources surfaces mobilization activity that no team could track manually, and geospatial mapping places that activity against an organization's own footprint. Automated clustering and summarization reduce alert volume so analysts can review what matters. Case management preserves the record of what was assessed and decided. Human judgment remains the part that technology does not replace, because credibility assessment, proportionality, and the decision to close a site or move an event all involve tradeoffs that a monitoring platform cannot weigh.