Cross-Border Infrastructure Security Governance
Cross-Border Infrastructure Security Governance
1. Introduction
Cross-border infrastructure security governance means the legal and institutional system used to protect infrastructure that connects or affects more than one country. In the energy sector, this includes electricity interconnectors, gas pipelines, LNG terminals, offshore energy infrastructure, transmission networks, undersea cables and hydrogen infrastructure.
The issue has become more important because energy systems are highly interconnected. Damage to infrastructure in one country can affect energy supply, prices and system stability in neighbouring countries. The EU's Critical Entities Resilience (CER) Directive recognises that the increasing interdependence and cross-border nature of critical infrastructure means that protecting individual assets alone is not sufficient. (Eur-Lex)
2. Meaning of Infrastructure Security Governance
Infrastructure security governance involves more than physical protection. It covers:
physical security against sabotage and other malicious acts;
cybersecurity of control and communication systems;
emergency preparedness;
risk assessment;
information sharing;
continuity of essential services;
incident reporting;
cooperation between States and regulators; and
recovery after disruption.
The objective is to ensure that infrastructure can prevent, withstand, respond to, and recover from serious incidents.
3. Cross-Border Energy Infrastructure
Examples include:
Electricity Interconnectors
An electricity cable may connect two national transmission systems. A failure can affect electricity supply in both countries.
Gas Pipelines
International pipelines can transport gas through several jurisdictions. Their disruption can therefore have regional consequences.
Undersea Cables
Electricity and energy-data cables crossing the sea can be particularly difficult to protect because responsibility may involve several jurisdictions.
Hydrogen Infrastructure
As international hydrogen networks develop, similar security issues will arise concerning pipelines, storage facilities and terminals.
The EU has recognised that infrastructure relevant to several Member States may even be physically located in only one country or outside EU territory, such as undersea cables and pipelines. (Eur-Lex)
4. EU Critical Entities Resilience Framework
The CER Directive 2022/2557 provides an important framework for critical infrastructure resilience.
It moves beyond simply identifying infrastructure that must be protected. It focuses on the resilience of critical entities providing essential services.
Energy is specifically included within the framework. Critical entities are expected to take appropriate measures to prevent, protect against, respond to, resist, mitigate and recover from incidents. (Eur-Lex)
This creates a governance structure involving:
EU institutions
↓
Member States
↓
Competent national authorities
↓
Critical entities / infrastructure operators
↓
Energy consumers and markets
5. Physical Security and Cybersecurity
Modern energy infrastructure has two connected security dimensions.
Physical Security
This includes protection against:
sabotage;
deliberate damage;
terrorism;
physical intrusion;
equipment failure; and
natural hazards.
Cybersecurity
Energy networks increasingly depend on digital control systems. A cyberattack against a transmission operator or pipeline control system could therefore have cross-border effects.
The EU has developed the NIS2 framework alongside the CER Directive, creating complementary approaches to physical resilience and cybersecurity. EU policy documents specifically identify the need for coordinated cybersecurity rules for cross-border electricity flows. (Eur-Lex)
6. Cross-Border Risk Assessment
A major governance challenge is deciding which country is responsible when infrastructure serves several countries.
For example:
Country A → electricity interconnector → Country B → wider European grid
If the infrastructure is physically located mainly in Country A but provides essential services to Country B, Country B also has a legitimate security interest.
The CER framework recognises this problem and seeks greater cooperation where disruption has significant cross-border consequences. (Eur-Lex)
Therefore, risk assessment should consider not only national consequences but also regional and cross-border consequences.
7. Energy Security and Infrastructure Governance
Cross-border infrastructure security is closely connected with security of energy supply.
The Balticconnector incident illustrates this connection. In October 2023, the gas pipeline connecting Finland and Estonia was disrupted. EU documents noted that the disruption affected Finland's ability to satisfy the N-1 infrastructure standard and contributed to an increase in Finland's gas-system crisis level. (Eur-Lex)
This demonstrates an important principle:
Infrastructure security → Energy-system resilience → Security of supply
A single infrastructure failure can therefore become a wider regional energy-security problem.
8. Important Case Laws
Poland v Commission, Case T-883/16
This case concerned the OPAL gas pipeline, which connects with the Nord Stream system.
Poland challenged a European Commission decision modifying the exemption regime for the pipeline. The General Court annulled the Commission's decision because the Commission had not adequately examined its effects on Poland's security of gas supply and had failed to properly consider the principle of energy solidarity. (Infocuria)
Relevance
This is highly important for cross-border infrastructure governance because it shows that decisions concerning infrastructure in one Member State may need to consider their effects on neighbouring Member States and the wider EU energy system.
The CJEU subsequently upheld the importance of the energy-solidarity principle in Germany v Poland, Case C-848/19 P, confirming that EU energy measures must be assessed in light of that principle. (curia)
Baltic Cable AB v Energimarknadsinspektionen, Case C-454/18
This case concerned the Baltic Cable electricity interconnector between Sweden and Germany.
The CJEU considered the legal treatment of revenues generated from allocating cross-border interconnection capacity and the regulatory status of the interconnector. (Eur-Lex)
Relevance
The case demonstrates that cross-border infrastructure requires common regulatory principles concerning interconnectors, network operation and cross-border electricity exchanges.
Aquind v ACER, Case C-46/21 P
This case concerned a proposed electricity interconnector between Great Britain and France.
The CJEU examined ACER's regulatory review of the proposed interconnector and emphasised the importance of effective review of complex technical and economic assessments. (Eur-Lex)
Relevance
The case shows that cross-border infrastructure governance requires not only physical security but also clear regulatory authority, transparent decision-making and effective legal review.
9. Major Governance Challenges
Different National Laws
Each country may have different rules concerning infrastructure protection, emergency powers and security standards.
Information Sharing
Security information may be sensitive. Authorities must balance effective cooperation with confidentiality and cybersecurity requirements.
Third-Country Infrastructure
Pipelines or cables may connect EU infrastructure with infrastructure located outside the EU. This creates additional questions concerning jurisdiction and international cooperation.
Private Ownership
Much critical infrastructure is operated by private companies. Governments therefore need effective mechanisms to impose resilience and reporting obligations without unnecessarily interfering with commercial operations.
Foreign Investment
Foreign ownership of critical energy infrastructure can raise additional security and public-order concerns. EU policy proposals have recognised the relationship between cross-border energy projects, foreign investment screening and infrastructure security. (Eur-Lex)
10. Conclusion
Cross-border infrastructure security governance is a multi-level legal system combining energy law, critical-infrastructure law, cybersecurity, national security and international cooperation.
The principal elements are:
risk identification and assessment;
physical protection;
cybersecurity;
emergency preparedness;
cross-border information sharing;
continuity of essential energy services;
cooperation between regulators and governments; and
effective judicial and regulatory oversight.
The cases Poland v Commission (T-883/16), Germany v Poland (C-848/19 P), Baltic Cable (C-454/18), and Aquind (C-46/21 P) demonstrate that cross-border energy infrastructure is not simply a technical matter. It involves questions of energy solidarity, regulatory authority, security of supply, infrastructure access and regional resilience.
For PhD-level energy law, the central issue is how States can protect critical energy infrastructure while creating a coordinated cross-border governance system that recognises the fact that disruption in one jurisdiction can affect the energy security of many others.

comments