Is The Failure of Risk Management Worth It? 2026 Review | BusinessRiskTV

BusinessRiskTV reviews Douglas W. Hubbard’s The Failure of Risk Management—why heat maps fail and how quantitative risk analysis fixes ERM in 2026.

Enterprise risk management Magazine articles and videos

BusinessRiskTV Book Review: The Failure of Risk Management

BusinessRiskTV Business Risk Management Club recommends this book product as the solution to the problem of poor enterprise risk management application in business.

That recommendation carries weight because the problem is measurable. 65% of UK organisations now believe a serious cyber attack could threaten their survival, yet 1 in 5 have chosen not to report a serious cyber incident to avoid negative consequences. With economic uncertainty cited by 29% of UK trading businesses as their top challenge affecting turnover in September 2026, and 28% reporting decreased turnover, the gap between how businesses think they manage risk and how they actually do is costing real money. Hubbard’s book confronts that gap head-on.‌

What Is The Failure of Risk Management About?

The Failure of Risk Management explains why common risk management techniques are causing bad decision-making and provides a practical framework for adopting accurate, quantitative risk analysis methodology. Renowned risk analysis expert Douglas W. Hubbard argues that many popular risk management methods are “mere placebos which do nothing to reduce risk and improve decisions”. The book is divided into three parts: an introduction to risk analysis, a critique of what is broken, and a practical guide to fixing it.‌‌

Hubbard’s core argument is that qualitative methods like risk matrices and heat maps look sophisticated but are often misleading. He presents a convincing case for probabilistic risk analysis using Monte Carlo simulation as the best approach. The second edition includes updated case studies and expanded guidance on probability modelling, emphasising the efficacy of appropriate risk methodology in practical applications.

Why Should Risk Officers and Business Leaders Read This Book in 2026?

Risk officers and business leaders should read this book in 2026 because the gap between qualitative risk theatre and quantitative risk reality has never been more costly, as current UK business data demonstrates. The UK Government’s own 2026 National Risk Register acknowledges that “the risks the UK faces are more volatile, varied and interconnected than any time in living memory,” listing 95 distinct risks including 87 standalone risks and 8 linked scenarios. Yet the Government Major Projects Report at the end of March 2026 revealed that only 15% of major projects held a Green rating, while 58% were Amber and 18% were Red. These are the very projects where quantitative risk modelling should be standard practice.

Hubbard’s critique is not abstract. The Wood Group was fined almost £13m in March 2026 for failures in financial reporting and systems of controls, with the FCA citing a “poor financial culture”. Carillion’s former finance directors were fined for failing to reflect serious financial troubles in company announcements. These are not failures of risk identification—they are failures of risk quantification and honest communication. Hubbard’s framework directly addresses these systemic weaknesses.

Who Will Benefit Most from Buying and Applying This Book?

Risk officers, compliance teams, project managers, CFOs, board members, and enterprise risk management professionals will benefit most from buying and applying this book. The book targets management consultants and economists primarily, but Hubbard offers important suggestions for war quants and actuaries as well. Specifically:‌

  • Risk officers seeking to move from qualitative heat maps to quantitative modelling will find a step-by-step methodology for calibration and probability estimation
  • Compliance teams facing increasing regulatory scrutiny—the FCA’s actions against Wood Group and Carillion directors show that regulators now expect boards to monitor risk management frameworks effectively
  • Project managers managing complex programmes will benefit from Hubbard’s practical rules for risk registers, including the principle that risks requiring executive notification belong on the register, while those with trivial impacts do not‌
  • CFOs and finance directors grappling with supply chain disruptions—70% of UK businesses have faced greater financial exposure due to supply chain instability, with average annual collection costs rising to over £420,000‌
  • Board members who need to understand why “seeing all risks displayed in an organised, visual format” does not mean they are under control‌

When Should Potential Buyers Buy This Book?

Potential buyers should buy this book immediately if their organisation currently relies on qualitative heat maps, colour-coded risk matrices, or consensus-based risk scoring, because these methods are failing under the weight of 2026’s interconnected risk landscape. The timing is critical for several reasons:

  • Regulatory pressure is intensifying: The UK Corporate Governance Code now asks boards to monitor company risk management and their controls frameworks, yet many boards lack the quantitative tools to do so
  • Cyber risk is existential: 65% of UK organisations say a serious cyber attack could threaten their survival, and AI-driven attacks have more than doubled in frequency over the last 12 months, now affecting 25% of organisations‌
  • Supply chain volatility is structural, not temporary: 28% of UK businesses with 10 or more employees reported concern about international conflict impacting supply chains, while 21% were concerned about shipping disruption‌
  • The cost of inaction is quantifiable: Late payments cost the UK economy £11 billion annually, and 38 businesses close every day due to cashflow problems
    Buy the book before your next risk committee meeting. Buy it before your next board reporting cycle. The organisations that adopt quantitative methods now will be the ones still trading in 2027.

Where in the World Will Your Business Be to Take Advantage of This Book’s Knowledge?

UK-based businesses of all sizes—from SMEs to FTSE-listed corporates—will benefit most from this book’s knowledge, because the UK’s current risk environment provides the most immediate and measurable case for quantitative risk management. The UK is uniquely positioned to apply Hubbard’s framework:

  • UK SMEs are owed an average of £66,770 in late payments, and nearly half of UK companies expect the economy to deteriorate in the next 12 months
  • UK corporates face heightened governance scrutiny following the Carillion and Wood Group enforcement actions, making Hubbard’s methodology for demonstrating risk competence at board level directly applicable
  • UK public sector bodies managing the 95 risks in the National Risk Register need quantitative prioritisation to allocate limited resources effectively, as the Resilience Action Plan acknowledges the need to “assess how resilient the UK is to target interventions and resources”‌
  • UK critical national infrastructure operators in water, power, and communications face risks that Hubbard’s methods were originally designed to address—his approach draws from “nuclear power, exploratory oil, and other areas of business and government” where quantitative risk analysis is already standard practice

What Are the Key Takeaways for Business Decision Makers?

Key takeaways from The Failure of Risk Management that business decision makers can immediately apply include abandoning heat maps for quantitative methods, calibrating probability estimates, and using Monte Carlo simulation to model uncertainty. The most actionable insights are:

  • Heat maps create false confidence: Colour-coded risk matrices oversimplify complex risks, lack granularity, cannot account for risk tolerance, and encourage subjective assessment—yet executives treat them as rigorous analysis‌
  • Quantitative analysis is achievable without a PhD: Hubbard provides practical guidance on probability modelling and empirical inputs, showing that “you don’t need high levels of complexity or a PhD in math to make significantly better-informed risk management decisions”
  • Calibrate your experts: People do not naturally estimate probabilities well, but a little training can significantly improve accuracy—Hubbard provides tests in the appendix for calibrating probability estimations‌
  • Review past models against reality: The best way to know if a model works is to check how past forecasts performed—Hubbard checked over 100 of his own probability forecasts and found events predicted at 30% occurred approximately 30% of the time‌
  • Apply simple risk register rules: If the impact is so trivial you don’t need to tell anyone, it doesn’t belong on the register; if the probability exceeds 1 (it’s expected to happen), it’s not a risk but a project plan item‌
  • Learn from near misses: Treating near misses as successes rather than failures is a critical barrier to organisational learning that Hubbard identifies as a common failure mode‌

How Can You Maximise the Knowledge in This Book for Practical Business Benefit?

To maximise the knowledge in this book for practical business benefit, implement Hubbard’s four key measures: identify deficiencies in your current strategy, adopt a calibrated approach to risk analysis using up-to-date statistical tools, employ accurate quantitative risk analysis and modelling methods, and revisit your models against real outcomes. The practical implementation path is clear:

  • Start with a risk audit: Hubbard advises risk managers to identify deficiencies in their current strategy and fix them, rather than attempting a wholesale replacement of existing systems
  • Convert qualitative to quantitative: Where your risk register uses high/medium/low, convert these to probability estimates—”estimate the probability that the event will happen inside of the timeframe”‌
  • Use existing data before building new models: Where possible, review historical data to see what the real impact of similar events has been, rather than relying on subjective estimates‌
  • Frame risks in financial terms: Quantitative risk assessments assign numerical values to risks, allowing decision-makers to weigh the cost of each risk against its potential impact, enabling more strategic resource allocation
  • Establish feedback loops: Create a culture of purchase reflection where you document experiences, ask what happened and why, price assess reoccurrence likelihood, and identify practical steps to change outcomes‌
  • Join a community of practice: The BusinessRiskTV Business Risk Management Club provides access to exclusive webinars, workshops, and reports from leading risk management experts, with monthly risk intelligence briefings covering geopolitical, economic, and technological trends‌

Is The Failure of Risk Management Value for Money?

The Failure of Risk Management represents exceptional value for money when measured against the cost of poor risk management decisions that it helps prevent. Consider the arithmetic:

  • The book retails at approximately £39, while the average annual cost of collections from late payments alone has risen to £421,800 per business—a 14.5% increase from £368,400 in 2025
  • Cyber incidents cost UK small firms an average of $52,000 (approximately £41,000) per year and cause about 32 hours of disruption, yet average investment in cyber resilience measures stands at only $51,000—almost matching the cost of incidents themselves
  • Late payment costs the UK economy £11 billion annually, and 38 businesses close every day due to cashflow problems
  • The book’s insights, if applied to even one significant risk decision, could save an organisation many multiples of its
    Hubbard’s methodology has earned critical praise from Gartner and Forrester Research, and the second edition includes fresh examples from the 2008 credit crisis, natural disasters, outsourcing failures, and engineering disasters. As Sam L. Savage, Executive Director of ProbabilityManagement.org, wrote: “Some study the theory of risk management. Some actively engage in risk management and find that what works in theory does not always work in practice. Some develop new technologies that will make risk management work better in the future. Doug Hubbard does all three. That’s why this book should be your risk management must-read”.‌

Final Verdict

The Failure of Risk Management is essential reading for any business decision maker who suspects their current risk approach is not delivering genuine insight or protection. In a year where the UK terrorism threat has increased to SEVERE, the National Risk Register lists 95 distinct risks, and 65% of organisations fear cyber attack could threaten their survival, continuing to rely on colour-coded heat maps is not risk management—it is risk theatre. Hubbard provides the practical, proven alternative that business leaders need.‌

BusinessRiskTV Business Risk Management Club recommends this book product as the solution to the problem of poor enterprise risk management application in business.

Get help to protect and grow your business faster with BusinessRiskTV

Find out more about our Business Risk Management Club

Subscribe for free business risk management ideas risk reviews and cost of doing business reduction tips

Connect with BusinessRiskTV for free business risk management tips

Read more business risk management articles and view videos for free

Connect with BusinessRiskTV for free alerts to new business risk management articles and videos 

Your risk heat map is a placebo.

That’s not my line. It’s the uncomfortable conclusion Douglas W. Hubbard forces you to confront in The Failure of Risk Management: Why It’s Broken and How to Fix It.

And in September 2026, the numbers back him up.

65% of UK organisations say a serious cyber attack could threaten their survival. 1 in 5 have chosen not to report a serious cyber incident. ONS-linked business data shows 29% of UK trading businesses cite economic uncertainty as their top challenge affecting turnover. 28% report decreased turnover.

The UK Government’s own National Risk Register lists 95 distinct risks. The Government Major Projects Report at the end of March 2026 showed only 15% of major projects rated Green. 58% Amber. 18% Red.

Wood Group was fined almost £13m in March 2026 for financial reporting and controls failures. Carillion’s former finance directors were fined for failing to reflect serious financial troubles in company announcements.

Yet many boards still stare at red-amber-green heat maps and call it risk management.

Here’s the part most risk committees miss: Hubbard doesn’t just attack heat maps. He shows you what to replace them with. And the replacement does not require a PhD in math.

What to apply immediately:

  • Convert “high / medium / low” into probability estimates. If it’s a risk, ask: what is the probability this happens inside the timeframe?
  • Calibrate your experts. Hubbard checked over 100 of his own probability forecasts. Events predicted at 30% occurred approximately 30% of the time. Most organisations never test their experts this way.
  • Use Monte Carlo simulation to model uncertainty instead of arguing over colour codes.
  • Apply Hubbard’s risk register rule: if the impact is so trivial you don’t need to tell anyone, it doesn’t belong on the register. If the probability exceeds 1, it’s not a risk—it’s a project plan item.
  • Review past models against reality. If your 2024 risk register said “low likelihood” and it happened twice, your model is broken.
  • Treat near misses as data, not as successes. That is one of the biggest barriers to organisational learning Hubbard identifies.

    Wait—there’s more. This is where it gets expensive

    70% of UK businesses have faced greater financial exposure due to supply chain instability. Average annual collection costs have risen to over £420,000. Late payments cost the UK economy £11 billion annually. 38 businesses close every day due to cashflow problems.

    The book costs about £39. One avoided bad risk decision pays for it thousands of times over. That is not a book expense. That is risk management value for money.

    Who benefits most? Risk officers, compliance teams, project managers, CFOs, board members, and enterprise risk management professionals. When should you buy it? Before your next risk committee meeting. Before your next board reporting cycle. Where will it pay off? UK SMEs owed an average of £66,770 in late payments. FTSE corporates under FCA scrutiny. Public sector bodies managing 95 National Risk Register risks. Critical national infrastructure operators in water, power, and communications.

    Read to the end for the one question that exposes a broken risk process:

If your risk register disappeared tomorrow, what decision would actually change?

If the answer is “none”, you don’t have a risk process. You have risk theatre.

BusinessRiskTV Business Risk Management Club recommends this book product as the solution to the problem of poor enterprise risk management application in business.

Want the practical rollout? Email editor@businessrisktv.com with the subject line RiskClub for more information on BusinessRiskTV Business Risk Management Club.

#RiskClub #BusinessRiskTV

Book Under Review

The Failure of Risk Management: Why It’s Broken and How to Fix It by Douglas W. Hubbard

As an Amazon Associate I earn from qualifying purchases

Is The Failure of Risk Management Worth It? 2026 Review | BusinessRiskTV

Author: businessrisktv

Helping you to grow your business faster and protect your assets better. Engaging your business stakeholders in your business products and services. Helping Companies Navigate Uncertainty. Business Risk Management Content Creation Service.

One thought on “Is The Failure of Risk Management Worth It? 2026 Review | BusinessRiskTV”

Leave a Reply