Cross-Sector Dependency Risk Governance Frameworks
Cross-Sector Dependency Risk Governance Frameworks
1. Introduction
Cross-sector dependency risk governance frameworks are legal and regulatory systems used to identify, assess and manage risks created when one critical sector depends on another. Modern infrastructure is highly interconnected. Electricity depends on telecommunications and digital systems, while telecommunications depend on electricity. Transport, banking, water, healthcare and energy can therefore be affected by the failure of another sector.
The main principle is:
Sector dependency → shared risk → coordinated assessment → joint protection → coordinated response.
2. Meaning of Cross-Sector Dependency
A dependency exists when the functioning of one essential service relies on another service or infrastructure.
Examples include:
electricity networks depending on telecommunications;
water systems depending on electricity;
hospitals depending on electricity and digital networks;
transport systems depending on communications;
hydrogen production depending on electricity;
financial institutions depending on telecommunications and data centres.
A failure in one sector can therefore create a cascading failure in another sector.
3. EU Legal Framework
The EU CER Directive 2022/2557 creates a framework for the resilience of critical entities across sectors. It requires Member States to conduct risk assessments and consider dependencies between sectors, including dependencies involving other Member States and third countries. (Eur-Lex)
The NIS2 Directive 2022/2555 provides the complementary cybersecurity framework. It covers sectors such as energy, transport, health, digital infrastructure and other essential services. It also recognises that disruption of an entity can create systemic risks, particularly where the impact crosses borders or affects interdependent sectors. (Eur-Lex)
Thus, modern EU law moves from protecting individual infrastructure towards protecting the interconnected system.
4. Risk Assessment
A cross-sector framework normally begins with risk assessment.
Authorities should identify:
essential services;
critical entities;
dependencies;
possible threats;
consequences of disruption;
alternative sources of supply; and
recovery capabilities.
The assessment should consider both direct and indirect risks.
For example:
Cyberattack on electricity operator → electricity interruption → telecommunications failure → disruption of banking and emergency services.
NIS2 requires risk-management measures covering risk analysis, incident handling, business continuity, crisis management and supply-chain security. (Eur-Lex)
5. Governance and Information Sharing
Effective governance requires cooperation between different regulators and public authorities.
Authorities may need to share information concerning:
cyber threats;
physical threats;
vulnerabilities;
incidents;
supply-chain risks;
emergency plans; and
recovery measures.
NIS2 specifically requires coordination between cybersecurity authorities and authorities responsible for critical-entity resilience. (Eur-Lex)
This prevents each regulator from examining risks only within its own sector.
6. Supply-Chain Dependencies
Modern infrastructure also depends heavily on suppliers.
An electricity operator may rely on:
software providers;
telecommunications companies;
cloud services;
equipment manufacturers;
cybersecurity providers; and
specialist maintenance contractors.
NIS2 requires essential and important entities to consider cybersecurity risks arising from suppliers and service providers. (Eur-Lex)
Therefore, dependency governance extends beyond the organisation itself.
7. Case Law: Tempus Energy v Commission
In Tempus Energy Ltd v European Commission, Case T-793/14, the General Court examined the UK's electricity capacity market.
The Court found that the Commission had not adequately examined the role of demand-side response before approving the scheme.
Relevance
Although this case was not directly about cross-sector dependency, it demonstrates the importance of recognising alternative resources and system relationships when assessing electricity-system resilience.
A governance framework that considers only conventional generation may fail to recognise the contribution of demand response, storage and other interconnected resources.
8. Cross-Border Dependency
Dependencies may extend across national borders.
For example:
Country A electricity grid → Country B telecommunications → Country C financial services.
NIS2 expressly recognises that disruption can create significant systemic risks where effects have a cross-border dimension. (Eur-Lex)
The CER framework similarly requires Member States to consider dependencies involving other Member States and third countries when conducting risk assessments. (Eur-Lex)
This makes cross-border cooperation an essential part of dependency governance.
9. Resilience and Recovery
Governance should not focus only on preventing incidents.
It should also provide for:
emergency response;
backup systems;
alternative suppliers;
redundancy;
disaster recovery;
crisis communication;
restoration of essential services; and
post-incident review.
NIS2 expressly includes business continuity, backup management and disaster recovery among cybersecurity risk-management measures. (Eur-Lex)
10. Conclusion
Cross-sector dependency risk governance frameworks provide a structured method for managing risks created by interconnected critical infrastructure.
Their main elements are:
dependency mapping;
cross-sector risk assessment;
information sharing;
coordinated regulation;
supply-chain security;
business continuity;
crisis management;
cross-border cooperation; and
recovery planning.
The CER Directive 2022/2557 focuses on the wider resilience of critical entities, while NIS2 provides a complementary cybersecurity framework. Both recognise that modern infrastructure cannot be protected effectively by treating sectors as completely independent. (Eur-Lex)
The central principle is that risk governance must consider the dependencies connecting energy, telecommunications, transport, finance, water, healthcare and digital infrastructure, because disruption in one sector can produce cascading consequences across several others.

comments