When infrastructure becomes a societal dependency

When infrastructure becomes a societal dependency
For decades, critical infrastructure was relatively easy to picture.
Power grids. Ports. Railways. Airports. Telecommunications. Water systems.
Large physical assets that societies could not function without, and which therefore required particular protection. That picture is becoming inadequate.
What makes an organisation critical today is increasingly not what it owns, but what depends on it. A relatively small technology supplier may be essential to an energy system. A commercial satellite operator may support both civilian and military functions. A software platform can become a point of failure for physical infrastructure it never comes close to owning.
Criticality, in other words, is moving from infrastructure to dependency. And that changes more than our understanding of security. It changes the relationship between business, government and society.
Geopolitics has entered the operating model
Several developments have converged. The first is geopolitical. Energy systems, telecommunications networks, ports, railways and undersea cables are no longer simply economic infrastructure. They are part of the security environment.
The distinction between civilian and military infrastructure has become particularly difficult to maintain. NATO estimates that around 90 per cent of military transport for large operations is provided by civilian assets from the commercial sector, while more than 70 per cent of satellite communications used for defence purposes come from commercial providers.
The second development is the changing nature of conflict itself. Cyberattacks, sabotage, GPS interference, disinformation and economic coercion can disrupt essential societal functions without crossing the traditional threshold of war. NATO has explicitly stated that hybrid operations against Allies could reach the level of an armed attack and potentially lead to Article 5 being invoked.
But there is a third development that may prove even more consequential: the extraordinary density of dependencies created by modern economies. A port is no longer simply quays, cranes and warehouses. It depends on electricity, communications, software, satellite navigation, payment systems, logistics platforms, fuel and specialised suppliers. The same is true almost everywhere. Modern infrastructure has become a system of systems.
The company behind the company
This changes how we should think about criticality.
The traditional question has been: Is this organisation part of critical infrastructure?
A more useful question today may be: Which essential societal functions depend on this organisation – and what happens if it stops functioning?
This is a different analytical lens. Consider an electricity network. The network itself is obviously critical. But so may be the cloud environment supporting parts of its operations, the cybersecurity provider monitoring its systems, the manufacturer producing a difficult-to-replace transformer, or the small specialist company with the competence and access required to restore an industrial control system. Size tells us remarkably little. An organisation with 80 employees can conceivably represent a more serious systemic vulnerability than one with 8,000 if it occupies an irreplaceable position in an essential chain.
This logic is increasingly visible in European regulation. The EU’s Critical Entities Resilience Directive does not simply focus on individual assets. It requires critical entities to consider natural and man-made risks, hybrid and other antagonistic threats, and – importantly – dependencies between sectors and entities. Recent EU guidance goes further by emphasising systemic interdependencies and supply-chain dependencies.
The conceptual movement matters. We are moving from a sector logic to an ecosystem logic. Criticality can therefore be understood through four questions: How dependent are others on this function? How severe would its disappearance be? How easily can it be replaced? And how long would recovery take?
Not a formula, perhaps. But a different way of seeing the organisation.
From continuity to societal resilience
Once an organisation becomes part of such an ecosystem, its leadership task also changes. Business continuity traditionally asks how an organisation can continue operating through disruption. The emerging question is larger: can the organisation continue performing the function society depends on when the surrounding system itself is under pressure?
That difference is subtle, but profound. It brings issues once delegated to technical or operational functions into the executive and boardroom: redundancy, supply-chain exposure, access to critical competencies, relationships with authorities, crisis decision-making and the ability to operate for extended periods under conditions that cannot be predicted precisely.
Efficiency and resilience also begin to pull in different directions. For three decades, much corporate thinking has rewarded specialisation, outsourcing, global supply chains, lean operations and just-in-time delivery. None of these principles has suddenly become irrelevant. But geopolitical uncertainty introduces another set of considerations: redundancy, strategic autonomy, security of supply and preparedness. The organisation is no longer optimising only for normal conditions.
When we at SJ&K advise organisations operating in and around critical societal functions, this shift is increasingly visible. Questions that initially appear operational quickly become questions of governance, responsibility and organisational judgement. Who decides when normal procedures are no longer adequate? Which dependencies deserve executive attention? And how much inefficiency are we willing to accept in normal times in order to remain functional in abnormal ones?
These are not primarily security questions. They are leadership questions created by a new security environment.
The communication paradox
There is another consequence, and it is easily underestimated. Critical organisations have to communicate in several different logics at once.
Under normal conditions, they need to demonstrate reliability, competence and efficiency. Under pressure, they need to demonstrate preparedness and the ability to maintain essential functions. Yet from a security perspective, there are vulnerabilities, capacities and contingency arrangements that they should precisely not make transparent. This produces a peculiar paradox: The critical organisation must demonstrate resilience without demonstrating its vulnerabilities.
We have encountered versions of this tension in our work around organisations such as DanPilot and NAVIAIR. Their everyday functions are highly specialised, but the larger significance of those functions only becomes apparent when one asks what else depends on them. That changes the communication task.
Communication can no longer be understood simply as reputation management around an operational organisation. It becomes part of the organisation’s resilience architecture: coordination with authorities and stakeholders, employee preparedness, crisis communication, information integrity and the ability to maintain legitimacy when information is incomplete or deliberately manipulated. Again, the boundary between disciplines begins to disappear. Security becomes communication. Communication becomes preparedness. Preparedness becomes leadership.
The securitisation of business
This may be part of a larger development. National security is moving into domains of corporate life that, until recently, had little reason to understand themselves in security-political terms.
Cloud providers. Shipping companies. Data centres. Satellite operators. Port terminals. Manufacturers of specialised electrical equipment. Technology companies with privileged access to operational systems. Some own recognisably critical infrastructure. Others become critical because of where they sit in a chain of dependencies. This is why the emerging landscape cannot be understood simply by adding more industries to an official list of critical sectors.
The deeper change is that security is becoming a condition of doing business in an interdependent society.
For leadership, this creates an unfamiliar form of responsibility. A company may remain privately owned, commercially governed and competitively exposed while simultaneously carrying obligations that arise from its role in the functioning of society.
When we advise on strategy and communication in this landscape, one distinction is becoming particularly useful. For years, companies have discussed their licence to operate: the legitimacy and acceptance required to conduct their business in society.
Critical organisations face something more. A duty to operate.
Society does not merely expect them to behave responsibly. It expects them to keep functioning when other parts of society are under pressure. That is a fundamentally different expectation. And as dependencies continue to multiply, it may apply to far more organisations than those we currently call critical infrastructure.