Critical Service Overlap Vulnerability Regulation
Critical Service Overlap Vulnerability Regulation
Detailed Explanation With Case Laws
1. Introduction
Critical Service Overlap Vulnerability Regulation refers to legal and regulatory arrangements designed to manage situations where two or more essential services depend on the same infrastructure, system, facility, supplier, technology or operational resource.
The basic problem is:
One shared dependency → failure → multiple essential services affected
For example, an electricity control centre may depend on telecommunications. The telecommunications network may itself depend on electricity. Similarly, hospitals, water treatment, transport and emergency services may all depend on reliable electricity.
This creates an overlap vulnerability because one failure can affect several critical services simultaneously.
Modern resilience regulation increasingly recognises these interdependencies. The EU Critical Entities Resilience framework, for example, expressly recognises growing interdependencies between infrastructure and sectors. (UCL Homepages)
2. Meaning of Critical Service Overlap
A critical service overlap exists where different essential services share a common dependency or vulnerability.
Examples include:
Electricity and Telecommunications
Electricity-grid control systems depend on telecommunications, while telecommunications infrastructure often requires electricity.
Electricity and Water
Water treatment and pumping facilities require continuous electricity.
Electricity and Healthcare
Hospitals depend on electricity for medical equipment, lighting, heating, cooling and communications.
Electricity and Transport
Electric railways, airports and transport-control systems depend on electricity and communications.
Therefore, regulation must examine not only individual infrastructure but also relationships between services.
3. Why Overlap Creates Vulnerability
Suppose three hospitals, a water-treatment plant and a telecommunications exchange all depend upon one electricity substation.
If the substation fails:
Substation failure
↓
Electricity interruption
↓
Hospital disruption + water disruption + telecommunications disruption
The impact is therefore much greater than the failure of one electricity asset alone.
This is known as a cascading or systemic risk.
4. Dependency Mapping
Regulators and operators can create dependency maps showing:
essential services;
infrastructure assets;
digital systems;
suppliers;
communication links;
fuel supplies; and
backup arrangements.
A simplified model is:
Electricity Substation
→ Hospital
→ Water Treatment
→ Telecom Exchange
→ Emergency Services
The purpose is to identify common points of failure.
5. Types of Overlap Vulnerability
Physical Overlap
Several services use the same physical location.
Example: electricity and telecommunications equipment located in the same facility.
Digital Overlap
Different services rely on the same software, cloud platform or communication network.
Geographic Overlap
Several critical assets are located in an area exposed to the same flood, wildfire or storm.
Supply-Chain Overlap
Several operators depend on the same manufacturer or contractor.
Energy Dependency
Several essential services depend upon the same electricity network.
6. UK Regulatory Framework
The UK Network and Information Systems Regulations 2018 (NIS Regulations) provide an important legal framework for essential services.
The regulations require Operators of Essential Services to take appropriate and proportionate technical and organisational measures to manage risks to the network and information systems on which their essential services rely. They must also take measures to prevent and minimise the impact of incidents and maintain service continuity. (GOV.UK)
For the energy sector, Ofgem acts as a competent authority for downstream gas and electricity operators in Great Britain. (Ofgem)
7. Supply-Chain and Third-Party Dependencies
Overlap regulation must also consider third parties.
An electricity operator may depend on:
telecommunications providers;
software companies;
equipment manufacturers;
maintenance contractors;
cloud providers; and
fuel suppliers.
A failure affecting one supplier could therefore affect several essential-service operators simultaneously.
UK government guidance specifically requires operators to manage risks to the systems underlying essential services, including supply-chain risks. (GOV.UK)
8. Incident Reporting
Incident reporting is important because regulators need information about systemic weaknesses.
Under the NIS framework, significant incidents affecting the continuity of essential services must be reported to the relevant competent authority. The UK Government states that reportable incidents generally must be notified within 72 hours after identification, according to applicable thresholds and guidance. (GOV.UK)
This information helps regulators identify whether apparently separate incidents are actually connected through a common dependency.
9. Case Law: SSE Generation Ltd v Competition and Markets Authority
An important UK electricity-regulation case is SSE Generation Ltd & Others, R (on the application of) v Competition and Markets Authority [2022] EWHC 865 (Admin).
The case concerned an appeal relating to electricity-network code modifications and Ofgem decisions. The High Court found that the CMA had to partially allow SSE's appeal because Ofgem's modification decision did not comply with relevant regulatory requirements. (GOV.UK)
Relevance
The case illustrates that technical electricity-network decisions must remain within the statutory and regulatory framework.
For overlap-vulnerability regulation, this means that requirements concerning shared infrastructure and resilience should be supported by proper legal authority and regulatory reasoning.
10. Case Law: Peak Gen Top Co Ltd v GEMA
In Peak Gen Top Co Ltd & Others v Gas and Electricity Markets Authority [2018] EWHC 1583 (Admin), electricity generators challenged Ofgem's decisions concerning transmission charging arrangements.
The court considered whether Ofgem had taken account of relevant considerations and whether its decision was lawful. (BAILII)
Relevance
The case demonstrates the importance of relevant evidence and proper regulatory reasoning when an energy regulator makes decisions affecting interconnected electricity-market participants.
This principle is useful when regulators assess the consequences of shared infrastructure.
11. Case Law: British Telecommunications plc v Office of Communications
The telecommunications case British Telecommunications plc v Office of Communications [2011] CAT 5 concerned regulation of BT's network and charges for partial private circuits. The Competition Appeal Tribunal reviewed Ofcom's regulatory determination concerning access to network infrastructure. (Competition Appeal Tribunal)
Relevance
Telecommunications networks are increasingly important dependencies for electricity systems.
The case demonstrates how regulators can impose obligations concerning network access and infrastructure relationships where one operator's network is important to other service providers.
12. Cybersecurity and Overlap
Cybersecurity is particularly important because one digital system may support several critical services.
For example:
Common communication network
→ electricity control
→ water control
→ emergency communications
A cyberattack against the common system could therefore affect several services.
Ofgem's NIS guidance requires energy-sector operators to manage security and resilience risks associated with the network and information systems on which their essential services rely. (Ofgem)
13. Redundancy Requirements
One important regulatory response is redundancy.
Where several critical services depend on one asset, regulators may require:
backup electricity supplies;
alternative communication networks;
duplicate control centres;
geographically separated facilities;
backup generators;
independent data connections; or
alternative suppliers.
The objective is:
Common dependency → alternative dependency → reduced systemic vulnerability.
14. Emergency Planning
Overlap regulation should require operators to plan for simultaneous service disruption.
A normal emergency plan might consider:
What happens if our electricity supply fails?
An overlap framework should ask:
What happens if electricity, telecommunications and water services are affected at the same time?
This distinction is important because traditional sector-by-sector regulation may fail to identify cross-sector cascading effects.
15. Risk Assessment
A useful regulatory assessment can examine:
| Factor | Question |
|---|---|
| Shared asset | Which services depend on the same asset? |
| Dependency | How strongly does each service depend on it? |
| Substitution | Is an alternative available? |
| Duration | How long could disruption continue? |
| Geographic effect | How large an area could be affected? |
| Population | How many users could be affected? |
| Cascading effect | Could one failure cause additional failures? |
| Recovery | How quickly can services be restored? |
The UK NIS framework similarly considers the number of users affected, duration and geographical area when determining the significance of incidents. (GOV.UK)
16. Regulatory Oversight
A strong framework requires cooperation between different regulators.
For example:
Ofgem → Electricity
Ofcom → Telecommunications
Water regulator → Water
Health authorities → Healthcare
Because one vulnerability may cross several sectors, regulators may need to share:
risk information;
incident information;
resilience assessments;
threat intelligence; and
emergency-planning information.
17. Confidentiality
Detailed vulnerability information can itself create security risks.
For example, publishing the exact location of a single backup communication route could make that infrastructure easier to target.
Therefore, legislation may need to balance:
Transparency
with
Security confidentiality.
Operators should nevertheless provide regulators with sufficient information to assess systemic risk.
18. Legal Principles
Critical Service Overlap Vulnerability Regulation should follow several principles:
Clear Responsibility
Each operator should know its obligations.
Proportionality
Protection requirements should reflect the level of systemic risk.
Interdependency Analysis
Regulators should examine cross-sector relationships.
Redundancy
Important shared dependencies should have alternatives where reasonably practicable.
Incident Reporting
Significant failures should be reported promptly.
Information Sharing
Relevant information should be shared between competent authorities.
Continuous Review
Dependency relationships should be reassessed as technology and infrastructure change.
19. Conclusion
Critical Service Overlap Vulnerability Regulation deals with one of the most important problems in modern infrastructure governance: several essential services may depend on the same underlying infrastructure.
The basic model is:
Shared dependency → common vulnerability → failure → cascading disruption → multiple essential services affected.
The UK NIS Regulations provide a useful example because they require essential-service operators to manage security risks, minimise the impact of incidents and maintain continuity. Energy-sector guidance also recognises risks involving underlying systems and supply chains. (GOV.UK)
The cases SSE Generation v CMA, Peak Gen v GEMA, and British Telecommunications v Ofcom demonstrate broader legal principles concerning lawful regulatory decision-making, network regulation and infrastructure relationships. (Ofgem)
For electricity law, the central lesson is that resilience cannot always be regulated sector by sector. Where electricity, telecommunications, water, healthcare and other essential services share infrastructure or digital dependencies, regulators need to examine the combined vulnerability. Effective regulation therefore requires dependency mapping, risk assessment, redundancy, incident reporting, cross-regulator cooperation and continuous resilience planning.

comments