Join our upcoming Summit in London

image

A cyber incident disrupts an energy operator. Power loss affects mobile networks and digital services. Emergency teams struggle to coordinate, while transport delays hold up fuel and repair crews.

This is how cascading crises develop: a disruption that begins in one system spreads through the services that depend on it.

This is the interconnected threat landscape: modern risks move between the systems that provide essential services. Power, communications, digital infrastructure, transport, water and emergency response rely on one another, so they rarely fail or recover in isolation. A resilience plan that addresses only one sector can therefore miss the point at which disruption is most likely to spread.

Critical infrastructure is a network of dependencies

A dependency exists when one service needs another to operate. An interdependency exists when that reliance runs in both directions.

Electricity powers mobile base stations, data centres, water pumps and control rooms. Communications networks allow energy operators to monitor equipment, coordinate field crews and exchange information with emergency services. Digital platforms support logistics, access control and public warnings. Transport networks move staff, equipment and fuel.

These connections make essential services more capable during normal operations, but they can also carry disruption from one system into another. The CISA Infrastructure Dependency Primer encourages planners to identify these relationships rather than assess individual assets in isolation.

A major crisis does not need to damage every part of the network. It may only need to disrupt a connection that several critical functions share.

How cascading crises develop

Consider a plausible sequence. A cyberattack forces an infrastructure operator to restrict or shut down part of its network. A local power disruption follows. Backup systems keep some services running, but their operating time, fuel supply, and maintenance access are limited. Mobile and data networks become congested or unavailable in affected areas.

At that point, control centres receive less reliable information, field teams become harder to dispatch, and partner organisations build different pictures of the same event. Slower decisions give secondary failures more time to develop.

The original hazard is no longer the whole problem. Responders must manage consequences as they move through cyber, physical, and human systems at different speeds. This is what makes cascading crises especially difficult: an organisation may understand its own assets and still be exposed to failures or recovery delays elsewhere.

Why siloed response plans fail

Siloed plans usually fail at the boundaries between organisations and sectors. Common weaknesses include:

  • Conflicting assumptions. A communications provider may expect grid power to return within a certain period, while the energy operator assumes telecommunications will remain available throughout restoration.
  • Backups with shared dependencies. Two systems may appear redundant but still rely on the same fuel supplier, access route, cloud platform, control centre or communications link.
  • Different operational priorities. Each organisation may have a logical restoration order that does not support the services other sectors need first.
  • Fragmented situational awareness. Technical teams, authorities and private operators may each hold part of the picture without a reliable way to combine it.
  • Exercises that are too tidy. A plan tested against one hazard, one outage and one organisation may perform very differently when cyber disruption, power loss and public demand occur together.

No organisation can solve every dependency. It can identify the critical ones, agree on shared assumptions and test what happens when expected support is unavailable.

What cross-sector resilience looks like

Cross-sector resilience does not require one enormous plan. It requires connected plans that recognise where responsibility, information and recovery sequences meet.

That starts with mapping critical functions. Which services must continue? What power, data, people, suppliers and communications do they require? How long can each function operate without them? Who controls restoration?

The answers should inform verified cross-sector contacts, fallback communications, manual procedures, shared escalation thresholds and agreed restoration priorities. Public communication matters too. Delayed or contradictory information can weaken trust as operational demands increase.

Scenario exercises expose assumptions before an emergency does. A useful exercise can remove grid power, telemetry, mobile communications, and a key supplier, then ask: What information remains? Who can act? Which service must return first? What if the outage lasts longer than planned?

The goal is not to predict the exact next crisis. It is to understand how disruption could travel and make better decisions before it does.

Frequently asked questions

What are cascading crises?

Cascading crises occur when disruption in one system triggers or worsens failures in other connected systems. For example, a power outage may affect communications, which then slows coordination and infrastructure restoration.

Why are cyber, energy and communications risks interconnected?

Energy systems use digital controls and communications to operate. Communications and digital services require reliable electricity. A failure or attack in one area can therefore reduce the ability of the others to function or recover.

How can organisations prepare for interconnected risks?

They can map critical dependencies, compare assumptions with partner organisations, establish fallback procedures and run cross-sector exercises that combine multiple disruptions. The emphasis should be on maintaining essential functions and coordinating recovery, not only protecting individual assets.

Putting interconnected resilience into practice

The Resilient and Renewable Society Summit will bring this challenge into a practical, cross-sector setting on 16–17 September 2026 in London. Leaders from academia, NGOs, government, policy and the private sector will examine lessons from recent crises, stress-test future scenarios and develop resilience strategies together.

Day 1 at the Royal Society will focus on what recent crises reveal about natural-disaster preparedness, energy-system disruption, critical infrastructure, security and public trust. Day 2 at Imperial College London will move into workshops and extreme-event exercises, with streams addressing disaster preparedness, energy resilience, and cyber and EMP readiness.

The summit is free to attend, with advance registration required. For anyone responsible for infrastructure, emergency planning or public policy, it offers a chance to examine not only whether an individual plan works, but whether it can withstand the connected pressures that turn isolated incidents into cascading crises.

By: Noya

Create Impact with us:

Join our membership and
contribution programs:

Get involved >>

Participate in our
upcoming events:

Events >>

Schedule a call with
our experts:

Consult >>

Five Crises That Rewrote the Rules of Resilience, and What the Next One Will Demand

On 12 May 2017, hospital staff across England reached for patient records and found locked screens instead. The risk wasn’t new. Neither were many of the vulnerabilities exposed by the crises that followed. We have accumulated years of reports, inquiries, and recommendations on how to protect critical infrastructure. Yet the distance between identifying a risk […]

Learn more

Infrastructure Stress Testing: Grid Forecasting Is Not Enough In This Heat

When temperatures rise, the first concern is usually public health. That is understandable. Extreme heat can put lives at risk, especially for older adults, outdoor workers, medically vulnerable communities, and people without reliable access to cooling. But heat also tests the systems behind daily life. Electric grids face higher cooling demand. Hospitals may see more […]

Learn more

Electric Grid Resilience and the FIFA World Cup: Power Reliability Is a Major Event Security Priority

The FIFA World Cup is not just a global sports event. It is also a major test of the host-city infrastructure. When tens of thousands of fans move through stadiums, airports, transit systems, hotels, fan zones, and city streets, reliable electricity becomes essential to safety and continuity. Power supports much more than stadium lights. It […]

Learn more
image