Skip to content

National security and strategic affairs

Risk, threat and uncertainty: three categories that should not be confused

Ali Zuweid

By · Published · 8 min read

Translation published · Arabic original

In July 2026, the UK government added seven risks to its national register, including interference in democratic processes and digital resilience failure. It removed disruption to Russian gas supplies after reducing dependence on them. The significance lies less in the number of entries than in why they changed: risk changes when means of harm or exposure change, even if geography and political antagonisms remain. Announcement of the update

In Iraqi debate, risk, threat and doubt are sometimes used as though they describe the same thing. Yet a decision addressing a public-service failure differs from one confronting deliberate coercion, and both differ from managing inadequate information. The question is not which term sounds more alarming. It is how accurate diagnosis prevents the purchase of a remedy for the wrong problem, and how a state should act when the certainty it would like is unavailable.

Central argument

Risk concerns potential losses and the conditions under which they occur. In the analytical usage adopted here, threat identifies an actor or source of harm, while doubt and uncertainty describe the limits of knowledge. All three may coexist, but conflating them can turn a possibility into a fact or a service problem into an unsupported accusation.

What changes when the categories are separated?

The United Nations Office for Disaster Risk Reduction relates potential losses to the interaction of hazards, exposure, vulnerability and capacity. The presence of a harmful phenomenon alone therefore does not establish the scale of risk: an event far from settlements differs from one affecting a densely populated area with inadequate protection. This definition belongs to disaster risk, but illustrates the value of distinguishing a source of harm from the conditions that turn it into losses. Disaster risk terminology

Consider a hypothetical power interruption at a healthcare facility. A possible consequence is disruption of treatment. A technical failure calls for maintenance and alternatives; evidence of deliberate disruption adds investigation and protection to the technical response. If the cause is not yet known, that gap neither establishes an attack nor justifies dismissing the possibility. Patients can be protected immediately while the explanation remains open to verification.

I use “threat” here in the narrower sense useful for analysing actors, intentions and capabilities, while recognising that some documents also apply it to epidemics and disasters. The aim is not to impose one vocabulary on every institution. It is to define terms within a decision so that one team is not discussing a natural hazard while another hears a security accusation. “Doubt” in the article's title is epistemic: questioning information does not establish that its opposite is true.

The distinction changes the evidence required. Flood-risk assessment draws on water conditions, exposure and preparedness; attributing an incident to an actor requires evidence about conduct and responsibility. Potential losses may be severe even while responsibility remains unknown. Waiting for attribution can delay protection, but turning precaution into a public accusation may create another crisis. Combining protective action with an independent investigation can help avoid both errors.

A register informs decisions; it does not predict events

The UK's 2026 register presents assessments of likelihood and potential impact as the public version of its National Security Risk Assessment. It does not claim that every listed scenario will occur. This distinction matters for Iraqi preparedness: including a severe scenario does not mean knowing when it will happen, and its failure to occur does not prove that preparing for it was wasteful. National Risk Register 2026

A coloured matrix nevertheless does not turn judgment into measurement. The time horizon must be clear: a probability over one month is not directly comparable with one over five years. So must the meaning of impact. Financial loss, deaths and disruption of a vital function cannot be exchanged without a value judgment. If one number hides those differences, it may create an appearance of precision while concealing the actual trade-off.

A useful register should therefore state confidence, data sources and the assumption that could change its assessment. “Medium likelihood” with low confidence is not equivalent to the same description supported by a consistent data series. Updating a simple measurement may be more valuable than prolonged debate about the risk's rank. Officials need to know when an assessment is usable, when more information is needed and who has authority to revise it.

The removal of the Russian gas entry also shows that risk is not an eternal property of another state. Reduced dependence on a particular supplier may lower the impact of disruption even while political conflict continues. The relevant Iraqi inference is to examine exposure itself: where is dependence concentrated, and has an alternative actually reduced its consequences? Announcing diversification is insufficient if supposedly separate alternatives depend on the same route, supplier or financing.

Incomplete data justify neither paralysis nor false confidence

Some decisions can wait for more information; others cannot. The distinction depends on the cost of delay and whether the decision can be reversed. A limited administrative arrangement can be tested and revised, while a long-term financial commitment or a measure affecting rights requires stronger justification and clearer safeguards. This is not a rule against precaution. It matches the scale of a decision to the strength of its evidence and the consequences that cannot easily be undone.

Where probability estimates are poorly grounded, decision-makers can compare alternatives that perform acceptably across several scenarios instead of selecting one forecast and building the entire plan around it. Maintaining a facility and training substitute personnel may help during an ordinary breakdown as well as a wider emergency. Such flexibility has costs, so the protected function, difficulty of replacing it during a crisis and timing of reassessment must be specified.

Scenarios also need boundaries. Combining every catastrophe at maximum severity and assuming they occur simultaneously produces a funding requirement no government can meet. Planning only for the most comfortable scenario makes testing meaningless. A more useful approach selects pressures whose interaction can be explained, then identifies what institutions could absorb and what would exceed their capacity. This examines choices without claiming foreknowledge.

A UN programme covering Iraq, Jordan and Lebanon provides a relevant illustration. A January 2026 account of its December 2025 review connected climate adaptation, health, migration and disaster risk reduction. The account documents cooperation and programme review; it does not itself measure a reduction in Iraqi losses. Its relevance is that different sectors can share sources of exposure and information needs while retaining their own responsibilities. Regional programme review

From a list of concerns to reviewable responsibility

An Iraqi application could begin with a limited register of functions whose interruption causes cascading harm, as discussed in traditional and non-traditional security. It would identify the scenario, responsible institution, information source and review date, then connect each assessment to a funding, maintenance or coordination decision. Collecting dozens of concerns without assigning responsibility produces an extensive document rather than clear preparedness.

The risk register should also be distinguished from an incident register. One estimates what might happen; the other records what occurred and what is known about its causes. After an incident, assumptions—including an institution's assessment of its own readiness—should be revised rather than the narrative adjusted to make every forecast appear correct. This is a subject for discussion in the proposal on disaster risk management and service continuity, whose provisions remain proposals rather than enacted rules.

Distinguishing risk, threat and uncertainty does not remove anxiety, but identifies the work that can reduce it. Risk calls for reducing exposure and loss; a hostile actor calls for evidence-based assessment of conduct and capability; uncertainty calls for information, bounded confidence and decisions that can be corrected. Better-prepared institutions do not promise a future without surprises. They disclose their assumptions and revise their choices when the evidence changes.

Ali Zuweid — Researcher in strategic affairs and national security

Sources

  1. UK Government — National Risk Register update —
  2. UNDRR — Disaster risk terminology
  3. UK Government — National Risk Register 2026 —
  4. UNDRR — Regional dialogue on climate, migration, health and disaster risk —

What are you looking for?

Search content published on the website.