A cyber incident disrupts an energy operator. Power loss affects mobile networks and digital services. Emergency teams struggle to coordinate, while transport delays hold up fuel and repair crews.
This is how cascading crises develop: a disruption that begins in one system spreads through the services that depend on it.
This is the interconnected threat landscape: modern risks move between the systems that provide essential services. Power, communications, digital infrastructure, transport, water and emergency response rely on one another, so they rarely fail or recover in isolation. A resilience plan that addresses only one sector can therefore miss the point at which disruption is most likely to spread.
A dependency exists when one service needs another to operate. An interdependency exists when that reliance runs in both directions.
Electricity powers mobile base stations, data centres, water pumps and control rooms. Communications networks allow energy operators to monitor equipment, coordinate field crews and exchange information with emergency services. Digital platforms support logistics, access control and public warnings. Transport networks move staff, equipment and fuel.
These connections make essential services more capable during normal operations, but they can also carry disruption from one system into another. The CISA Infrastructure Dependency Primer encourages planners to identify these relationships rather than assess individual assets in isolation.
A major crisis does not need to damage every part of the network. It may only need to disrupt a connection that several critical functions share.
Consider a plausible sequence. A cyberattack forces an infrastructure operator to restrict or shut down part of its network. A local power disruption follows. Backup systems keep some services running, but their operating time, fuel supply, and maintenance access are limited. Mobile and data networks become congested or unavailable in affected areas.
At that point, control centres receive less reliable information, field teams become harder to dispatch, and partner organisations build different pictures of the same event. Slower decisions give secondary failures more time to develop.
The original hazard is no longer the whole problem. Responders must manage consequences as they move through cyber, physical, and human systems at different speeds. This is what makes cascading crises especially difficult: an organisation may understand its own assets and still be exposed to failures or recovery delays elsewhere.
Siloed plans usually fail at the boundaries between organisations and sectors. Common weaknesses include:
No organisation can solve every dependency. It can identify the critical ones, agree on shared assumptions and test what happens when expected support is unavailable.
Cross-sector resilience does not require one enormous plan. It requires connected plans that recognise where responsibility, information and recovery sequences meet.
That starts with mapping critical functions. Which services must continue? What power, data, people, suppliers and communications do they require? How long can each function operate without them? Who controls restoration?
The answers should inform verified cross-sector contacts, fallback communications, manual procedures, shared escalation thresholds and agreed restoration priorities. Public communication matters too. Delayed or contradictory information can weaken trust as operational demands increase.
Scenario exercises expose assumptions before an emergency does. A useful exercise can remove grid power, telemetry, mobile communications, and a key supplier, then ask: What information remains? Who can act? Which service must return first? What if the outage lasts longer than planned?
The goal is not to predict the exact next crisis. It is to understand how disruption could travel and make better decisions before it does.
What are cascading crises?
Cascading crises occur when disruption in one system triggers or worsens failures in other connected systems. For example, a power outage may affect communications, which then slows coordination and infrastructure restoration.
Why are cyber, energy and communications risks interconnected?
Energy systems use digital controls and communications to operate. Communications and digital services require reliable electricity. A failure or attack in one area can therefore reduce the ability of the others to function or recover.
How can organisations prepare for interconnected risks?
They can map critical dependencies, compare assumptions with partner organisations, establish fallback procedures and run cross-sector exercises that combine multiple disruptions. The emphasis should be on maintaining essential functions and coordinating recovery, not only protecting individual assets.
The Resilient and Renewable Society Summit will bring this challenge into a practical, cross-sector setting on 16–17 September 2026 in London. Leaders from academia, NGOs, government, policy and the private sector will examine lessons from recent crises, stress-test future scenarios and develop resilience strategies together.
Day 1 at the Royal Society will focus on what recent crises reveal about natural-disaster preparedness, energy-system disruption, critical infrastructure, security and public trust. Day 2 at Imperial College London will move into workshops and extreme-event exercises, with streams addressing disaster preparedness, energy resilience, and cyber and EMP readiness.
The summit is free to attend, with advance registration required. For anyone responsible for infrastructure, emergency planning or public policy, it offers a chance to examine not only whether an individual plan works, but whether it can withstand the connected pressures that turn isolated incidents into cascading crises.
By: Noya
Join our membership and
contribution programs:
Participate in our
upcoming events:
Schedule a call with
our experts:
On 12 May 2017, hospital staff across England reached for patient records and found locked screens instead. The risk wasn’t new. Neither were many of the vulnerabilities exposed by the crises that followed. We have accumulated years of reports, inquiries, and recommendations on how to protect critical infrastructure. Yet the distance between identifying a risk […]
When temperatures rise, the first concern is usually public health. That is understandable. Extreme heat can put lives at risk, especially for older adults, outdoor workers, medically vulnerable communities, and people without reliable access to cooling. But heat also tests the systems behind daily life. Electric grids face higher cooling demand. Hospitals may see more […]
The FIFA World Cup is not just a global sports event. It is also a major test of the host-city infrastructure. When tens of thousands of fans move through stadiums, airports, transit systems, hotels, fan zones, and city streets, reliable electricity becomes essential to safety and continuity. Power supports much more than stadium lights. It […]