When Dependencies Become Critical: A Dependency-Centric Perspective on Critical Infrastructure Resilience

Critical Infrastructure Protection (CIP) has traditionally organised resilience around identifiable assets and operators: determine what is critical, assess the risks they face, and strengthen their protection. This logic remains an important foundation of contemporary legislation, regulation and risk management.
The growing emphasis on essential services and functions has broadened this perspective. Their delivery increasingly relies on external platforms, suppliers, technologies and specialised capabilities that may lie beyond the ownership or direct control of the organisations responsible for them.
Contemporary resilience policy already reflects this broader perspective. The EU Critical Entities Resilience (CER) Directive focuses on the continuity of essential services and vital societal functions, while OECD work increasingly addresses resilience at the level of infrastructure systems and their interdependencies.
This article builds on these developments but asks a more specific question: what happens when the systemic significance of a dependency emerges across multiple organisations or sectors and may therefore not be fully visible from any single organisational perspective?
For the purposes of this article, a Critical Dependency is understood as a relationship, resource, service or capability whose disruption compromises the delivery of one or more essential societal functions, irrespective of its formal status within existing CI frameworks. The purpose of the category is not to rename dependencies, but to identify those whose systemic significance becomes visible only when reliance is considered across essential societal functions.
A dependency-centric perspective makes this intermediate level explicit: societal functions define what must be sustained; critical dependencies identify what must remain available; assets, services and capabilities determine how that availability is provided.
When Dependencies Become Systemic
Research on infrastructure interdependencies and systemic criticality has long demonstrated that the consequences of disruption are shaped by the position of assets within wider interconnected systems. A dependency-centric perspective builds on this insight by shifting attention to the relationship between a dependency and the functions that rely upon it.
Dependencies may acquire systemic significance through the structure of reliance around them. Reliance may be concentrated around a common provider or capability, extend across sectors, or connect organisations responsible for essential functions to resources they neither own nor directly control.
Dependency criticality arises not from the characteristics of a resource, service or capability alone, but from what depends upon it.
A service may appear non-critical when considered within a single bilateral relationship, yet acquire systemic significance when multiple essential functions rely upon it. Conversely, even an important dependency may have limited systemic consequences where realistic substitutes or alternative pathways exist.
This creates a problem of perspective. Existing assessments often examine dependencies from the standpoint of an individual organisation, function or essential service. A dependency-centric perspective adds an aggregate view by considering patterns of reliance across multiple functions, operators or sectors. Each individual organisation may reasonably conclude that a dependency is manageable, while the same dependency acquires systemic significance when these relationships are considered collectively. That significance may therefore exceed what is visible to any single participant in the system.
Asset criticality and dependency criticality are related but not identical. The systemic significance of a dependency derives from the functions that collectively rely upon it, rather than from its formal status or characteristics alone. Where that significance exceeds what individual actors can see, a dependency becomes more than an operational relationship: it becomes a distinct resilience concern.
What Makes a Dependency Critical?
The analytical challenge is to distinguish routine operational dependencies from those whose disruption could have wider societal consequences. Two considerations are particularly useful in assessing dependency criticality: how reliance is structured and what consequences disruption could produce.
The first concerns how reliance is organised around a dependency: how many essential functions depend upon it, how concentrated that reliance is, and whether realistic substitutes or alternative pathways exist.
The second concerns the consequences of disruption: the scale and severity of functional loss, and the potential for effects to propagate across infrastructures, sectors or societal functions.
These considerations interact. Concentrated reliance becomes more consequential where substitutes are limited and disruption can propagate across essential functions. No single characteristic is therefore sufficient to establish dependency criticality.
Dependency criticality is also contextual. The same service may be replaceable for one operator but indispensable for another. Its significance may change over time as technologies, markets, suppliers and operating conditions evolve. A capability with several viable substitutes today may become critical following market consolidation, technological integration or vendor lock-in. A routine dependency may also acquire temporary systemic significance during an emergency when alternatives are not immediately available or demand changes sharply.
Capacity adds another dimension to this problem. A dependency may be adequately available to individual essential services under normal conditions yet become constrained when several services require the same resource or capability simultaneously. Criticality may therefore arise not only from the absence of alternatives, but also from whether those alternatives—or the dependency itself—can meet aggregate demand under disruption.
Criticality should therefore not necessarily be understood as a permanent attribute of a dependency. It may instead arise from a particular configuration of reliance, substitutability, capacity and potential consequences. Identifying critical dependencies requires attention to how these patterns may change over time and under different operating conditions.
Taken together, these considerations provide a basis for identifying dependencies that merit systemic attention without treating every external relationship as a matter for critical infrastructure policy.
Reframing Infrastructure Analysis
Building on existing function-based approaches, a dependency-centric perspective makes explicit an additional level of analysis between essential societal functions and the arrangements through which they are sustained.
Each level addresses a different analytical question. Essential societal functions establish what must continue. Critical dependencies identify what must remain available for those functions to continue, while delivery arrangements determine how that availability is provided and protected. Distinguishing these questions matters because they cannot be fully answered at the same analytical level.
Essential societal functions provide a relatively stable point of reference. Infrastructure assets, technologies, suppliers and delivery arrangements may change, while the functions they sustain tend to be more persistent. Defining what must continue also makes it possible to specify required levels of availability, quality, timeliness and tolerable degradation.
Consider water. Infrastructure analysis examines the systems, organisations and dependencies required to maintain supply. At the level of the essential societal function, the requirement is simpler: water must remain available. The former addresses how this is achieved; the latter establishes what must be sustained.
The distinction matters because an organisation can assess the resilience of assets and services within its field of responsibility without necessarily seeing whether the combined delivery arrangements remain sufficient from the perspective of one or several societal functions. Starting from the function does not eliminate asset- or operator-level analysis; it provides a reference against which the adequacy of those arrangements can be considered.
This sequence can also reveal dependencies whose systemic significance remains less visible when assessment is confined to individual organisations or sectors. A service for which each operator has identified a substitute may, for example, have few realistic alternatives at system level if several operators would turn to the same substitute simultaneously during disruption. Substitutability assessed individually may therefore overstate substitutability across a system of essential functions.
Existing capabilities for identifying assets, tracing dependencies, defining service levels and tolerable disruption, and analysing unacceptable consequences remain indispensable. A dependency-centric perspective adds a further analytical question: which dependencies acquire systemic significance because of the societal functions that collectively rely upon them?
Governing Critical Dependencies
Making critical dependencies visible analytically does not necessarily make them governable.
An infrastructure asset generally has an identifiable operator. A dependency may instead connect multiple operators, providers and sectors. Each actor may understand and manage its own relationship, while no single actor sees or is responsible for the aggregate dependence created by those relationships.
This creates a governance problem that bilateral risk management alone may not resolve. A provider may satisfy its obligations to every individual customer, and each operator may have assessed that provider within its own risk framework. Yet collective reliance by several essential functions may create systemic significance that no bilateral assessment captures.
The problem becomes particularly visible where multiple essential services rely on the same digital platform, software ecosystem or specialised provider. Each organisation may have identified and managed its own dependency through contractual arrangements, service-level requirements or contingency measures. Those arrangements, however, do not necessarily reveal whether the provider (or available alternatives) could support simultaneous demand from multiple essential services during a large-scale disruption.
Bilateral assurance may therefore be insufficient where criticality is collective.
The problem is partly one of information rather than individual responsibility. Operators may understand their own dependencies but lack visibility of aggregate reliance. Providers may know their customer base without being positioned or expected to assess the societal significance of every function those customers deliver. Sectoral regulators may see dependencies within their domains while missing concentrations that emerge across sectors. Systemic significance can therefore arise from information that exists in fragments but is not aggregated at the level at which the systemic nature of risk becomes visible.
The governance challenge is not simply to improve coordination, but to make aggregate reliance visible and actionable. This requires visibility beyond direct organisational dependencies, coordination where systemic significance crosses sectoral responsibilities, and continued reassessment as providers, technologies and substitutes change. Most importantly, assurance may need to reflect aggregate reliance rather than bilateral performance alone.
The relevant question is not only whether individual obligations can be met, but whether the dependency as a whole is sufficiently resilient given the combined importance of the essential functions that rely upon it. This does not imply that providers should automatically bear responsibility for all possible societal consequences of downstream dependencies. Imposing such responsibility indiscriminately could itself create disproportionate or commercially unsustainable obligations.
Where, then, should responsibility for resilience reside when the systemic significance of a dependency exceeds its importance to any individual customer?
Formal designation is not necessarily the answer. Treating every systemically significant dependency as critical infrastructure could simply expand existing categories without resolving the underlying governance problem. Different dependencies may require different combinations of information sharing, assurance, contingency planning, coordination or regulatory attention.
Who should perform this aggregating function will vary across governance systems. What matters is that aggregate reliance becomes visible at a level where its systemic significance can be assessed and, where necessary, addressed.
Assets remain essential objects of protection. Critical dependencies should also become explicit objects of resilience governance.
Conclusion
The central issue is not whether critical infrastructure depends on external services, suppliers and capabilities. It is whether their systemic significance becomes visible before disruption reveals it.
A dependency-centric perspective connects what society needs to sustain with what else must remain available for those functions to continue. In doing so, it can reveal aggregate reliance that exceeds what any individual actor can see or manage through bilateral arrangements.
Such a perspective cannot resolve the resulting governance problem by itself. But it can make it visible.
The next step for critical infrastructure resilience may therefore be not simply to map more dependencies, but to recognise when and where they acquire systemic significance across essential societal functions—and to ensure that this significance can be identified, assessed and governed.
By Michael Kolatchev, Principal, Managing Director & Lina Kolesnikova, Senior Consultant at Rossnova Solutions Belgium

Leave a Reply