Critical infrastructure failure often carries immediate, disastrous consequences. But while the initial loss may be easily understood, failures of this kind can also trigger long-term impacts on organisations that they may not be able to control effectively, and which may not be fully visible.

For most organisations resilience planning has begun from a traditional place: what could happen to our critical assets and if the worst does happen what shall we do about it? Those questions are important, with assets, threats and recovery times remaining central considerations. But as our cities, infrastructure and businesses become more interconnected, the conversation about what happens after a crisis strikes becomes ever more complex.

The failure is visible. The dependency is not.

The collapse of the Francis Scott Key Bridge in Baltimore in March 2024 illustrates the point. The immediate cost was human: members of a maintenance crew lost their lives which was a tragedy that rightly drove the initial public response.

Wider infrastructure lessons came later, and the consequences did not stop at the bridge. The Port of Baltimore was effectively cut off. Supply chains were disrupted, exports were affected and freight was rerouted, affecting manufacturers and logistics providers far beyond Maryland.

The bridge was the obvious point of failure, but the disruption extended to manufacturing schedules, export routes, insurance positions and the movement of critical goods that depended on that crossing remaining open. That is the bit that is often missed: the failure may be visible, but the dependency is often hidden.

When disruption moves sideways

The wider threat landscape is also undergoing another shift. Infrastructure has increasingly become a practical point at which an adversary can apply pressure, without necessarily declaring conflict or attacking a company head-on. Disruption to a port, power supply, cable route or indeed a software provider can have a direct and swift commercial impact, often two suppliers upstream. Recent events have shown how easily disruption can travel through these dependencies. The trigger may vary, but operational and commercial consequences can move through an interconnected system much faster, and with more impact than many expect.

 Examples of this include the July 2024 CrowdStrike outage, which demonstrated how a trusted software dependency can become an operating problem within hours. Attacks on shipping in the Red Sea turned a maritime security issue into a supply chain and cost issue for companies around the world. Data centre grid constraints exhibit a similar vulnerability, where something as basic as a power connection can influence growth plans and valuations.  None of these sit neatly inside our traditional risk categories or models, which is precisely why they can be overlooked and not noticed until the consequences of disruption are being felt.

The upstream visibility problem

Organisations know the first-tier suppliers, their main sites and the principal supply routes they are dependent on. The obvious threats and risks are also generally well known. They are often much less certain about the upstream dependencies, transport nodes, critical commodities and shared infrastructure that would actually determine how a disruption plays out.

The automotive sector has a clear illustration. The March 2021 fire at Renesas Electronics’ Naka semiconductor plant in Japan exposed how one incident can reverberate across an entire industry.Automakers knew their immediate parts suppliers, but the real constraint sat deeper upstream: a specialist clean-room facility producing microcontroller chips used across the sector. Toyota, Nissan, Honda and others had to assess production impacts not because their own plants had failed, but because capacity in a shared upstream node could not be replaced quickly.

 Most organisations know their own assets reasonably well. They are much less clear on the systems those assets depend on. A logistics hub may look like a property and operations issue, but its resilience depends on electricity, fuel, telecoms, software platforms, transport networks, customs systems and third-party suppliers. The same is true of factories and commercial real estate, where the real dependency often sits outside the physical perimeter.

These are the trade-offs organisations have made in pursuit of efficiency. Cloud adoption, outsourcing, just-in-time supply chains and smart infrastructure have created value, but also critical dependencies that now lie outside of direct control.

Old risk categories, new infrastructure

Part of the difficulty is structural. Organisations are still arranged around internal categories and functions: physical security, cyber, business continuity, supply chain, geopolitical risk and operational resilience. The infrastructure those functions are trying to protect does not necessarily sit wholly within these domains. Cloud platforms, data centres, telecoms networks and energy systems cut across sectors, jurisdictions and operating models.

The line between commercial, strategic and civil-military infrastructure is also less clear than many organisations might assume. A port, data centre, cable route or energy asset may be commercially owned, but still matter strategically in a crisis because of what it carries, who depends on it, or which public and national-security functions it enables

Traditional risk assessment still tends to imply that disruption can be contained. In practice, that is rarely how modern infrastructure works. Systems are more connected, more concentrated and more dependent on common providers and these are not being captured in traditional risk models.

Different industries, the same vulnerability

The pattern is already visible in industries where even minor infrastructure failures can have disproportionate consequences. Food, pharmaceuticals and healthcare supply chains share this vulnerability. This could be a refrigerated port failure, fuel availability, specialist packaging, customs platform outage or a labour issue at a critical logistics node. A weak point in the cold chain might be very mundane, such as too few powered reefer points at the port or containers sitting too long waiting for someone to move them. If the cargo is vaccines, biologics or insulin, a small temperature issue can write off an entire shipment. This is usually where the real exposure sits: not in the trigger event, but in the way consequences move through systems people assumed would be available.

The AI build-out provides an up to date example of how strategic dependencies are shifting. Data centres were once discussed mainly as a technical or real-estate asset. Today, compute, power and data storage have become strategic capacity. In some markets, facilities hosting cloud or AI workloads will be viewed in terms of what they enable, not simply by who owns them.

Power availability may become the limiting factor: grid capacity may not be available when the asset is ready, transformers and high-voltage equipment can have long lead times and water resources may come under pressure. None of these issues is contained inside the data centre’s physical perimeter, but each can impact on the commercial and operational performance of the asset.

The boardroom question

Executives can usually describe their major risks. What is much more difficult is describing the dependencies that would turn those risks into loss: unaudited suppliers, routes with no alternative, software providers buried in the operating model, or the grid connection that cannot be accelerated.

That is why the practical question is not just what could fail? It is what fails next? Which dependency comes under pressure, who else is affected, how quickly does the disruption move and when does it become a commercial problem?

Most organisations already have business continuity plans, crisis management frameworks, dashboardsand risk registers. The gap is usually a clearer view of where dependencies concentrate, how disruption would move through the operating model, and which controls would actually reduce consequence under pressure.

That view needs to be built into decisions rather than retrofitted after the event. In practical terms what should an organisation focus on?

  • Map dependencies, not just assets: Look beyond what you own to what you rely on, including the suppliers, routes, platforms, utilities and inputs that would determine how a disruption actually unfolds.
  • Concentrate on consequence, not just likelihood: Identify where a small, upstream weakness could escalate into significant commercial impact and prioritise the controls that reduce it.
  • Treat critical dependencies as part of the operating model: A port, grid connection, cloud platform, logistics node or critical commodity your business depends on belongs in the plan, not in the background.
  • Make resilience more practical, not more elaborate: The goal is not more process. It is an accurate account of what you depend on, and what happens when it fails.

None of this is about predicting every failure. It is about knowing what fails next and being clear about the dependencies that will decide how far, and how fast, the consequences travel.

The failure is always visible. The dependency rarely is.

Control Risks helps owners, investors and operators find the dependencies that decide how a crisis plays out, before it does. If you want to talk about critical infrastructure failure, and what happens next, get in touch.

For more insights around Built Infrastructure and Risk Management Services, sign up for our quarterly newsletter.

Get in touch

Can our experts help you?