Legal Governance Of Critical Infrastructure Dependencies .

1. Introduction

Critical infrastructure refers to assets, networks, facilities and systems whose continuous functioning is necessary for essential social and economic activities. Electricity grids, telecommunications, transport systems, water supply, hospitals, financial infrastructure, fuel networks, digital platforms and emergency services are typical examples.

The modern legal problem is no longer simply how to protect an individual critical asset. It is how to govern the dependencies between critical infrastructures. A power grid depends on telecommunications, fuel, digital control systems and water. Telecommunications depend on electricity and physical network infrastructure. Hospitals depend on electricity, water, communications, transport and digital systems. Consequently, disruption in one infrastructure can produce cascading failures in several others.

The EU's Critical Entities Resilience (CER) Directive expressly recognises that increasingly interconnected infrastructure can create cascading effects and requires Member States to consider cross-sectoral and cross-border dependencies in resilience planning. (EUR-Lex)

2. Meaning of Critical Infrastructure Dependencies

A critical infrastructure dependency exists when the operation of one essential infrastructure or service depends upon another.

Four major forms can be identified:

A. Physical dependencies

These arise when one infrastructure requires a physical service from another.

Example:
A water-treatment plant requires electricity. If the electricity supply fails, water treatment may stop.

B. Digital dependencies

Modern infrastructure relies heavily on information and communication technology.

For example:

electricity grids depend on SCADA systems;

hospitals depend on electronic health systems;

banks depend on telecommunications and cloud infrastructure;

transport systems depend on digital signalling and communications.

A cyberattack against a telecommunications provider can therefore affect several apparently unrelated sectors.

C. Geographic dependencies

Several critical services may depend upon infrastructure located at the same geographical location.

For example, electricity cables, telecommunications cables, pipelines and transport routes may occupy the same corridor. A flood, earthquake or deliberate attack can consequently affect several services simultaneously.

D. Organisational and supply-chain dependencies

Infrastructure operators may depend upon:

common suppliers;

specialised equipment manufacturers;

cloud providers;

fuel suppliers;

software vendors;

maintenance contractors;

foreign technology providers.

This creates a legal question concerning third-party and supply-chain risk.

3. From Infrastructure Protection to Infrastructure Resilience

Traditional infrastructure law generally concentrated on protecting particular assets.

The modern approach is broader:

Protection asks how an asset can be prevented from being damaged; resilience asks whether the essential service can continue despite disruption.

This distinction is important because infrastructure cannot always be completely protected.

The EU CER Directive defines resilience as the ability of a critical entity to prevent, protect against, respond to, resist, mitigate, absorb, accommodate and recover from an incident. (EUR-Lex)

The Directive also specifically recognises that protection of individual assets is insufficient because modern infrastructure is increasingly interconnected and cross-border. (EUR-Lex)

4. Legal Objectives of Governance

A comprehensive legal framework for infrastructure dependencies should pursue several objectives.

4.1 Identification of critical dependencies

Governments should require operators to identify:

upstream dependencies;

downstream dependencies;

inter-sectoral dependencies;

digital dependencies;

geographical dependencies;

supply-chain dependencies;

international dependencies.

The EU CER framework requires Member States' risk assessments to consider the extent to which sectors depend upon one another and how disruption in one sector may affect other sectors. (EUR-Lex)

4.2 Risk assessment

Operators should periodically undertake dependency and resilience assessments.

A proper assessment should ask:

What infrastructure does the operator depend upon?

What happens if that infrastructure fails?

How long can essential services continue?

Are alternative suppliers available?

Can services operate manually?

Can the system operate without telecommunications?

What happens if several infrastructures fail simultaneously?

The CER Directive requires critical entities to carry out risk assessments concerning risks capable of disrupting essential services and requires such assessments at least every four years. (EUR-Lex)

4.3 Continuity obligations

Legal systems can require operators to maintain:

backup power;

redundant communications;

emergency generators;

alternative suppliers;

spare equipment;

disaster-recovery systems;

manual operating procedures;

emergency personnel;

geographically diverse infrastructure.

The objective is not merely preventing failure but maintaining essential services during disruption.

5. Cascading Failure as a Legal Risk

One of the most important concepts is cascading failure.

A simplified example is:

Cyberattack → telecommunications failure → electricity-control failure → electricity interruption → water-treatment failure → hospital disruption.

The initial incident may occur in one sector, while the greatest social consequences occur elsewhere.

This creates difficult questions of legal responsibility.

For example:

Is the telecommunications operator responsible for downstream electricity losses?

Is the electricity operator liable for hospital losses?

Should infrastructure operators be required to exchange sensitive information?

Who coordinates an emergency involving several regulators?

Which regulator has primary authority?

Modern resilience legislation increasingly addresses these questions through coordinated governance rather than relying exclusively upon traditional private-law liability.

The EU has expressly identified cascading effects, supply-chain disruption, dependencies, climate risks and unreliable vendors as matters requiring resilience attention. (EUR-Lex)

6. Regulatory Coordination

Critical infrastructure is normally regulated by multiple authorities.

For example:

InfrastructurePossible regulator
ElectricityElectricity regulator
TelecommunicationsCommunications regulator
BankingFinancial regulator
WaterWater regulator
TransportTransport authority
CybersecurityCybersecurity authority
Emergency managementDisaster-management authority

Dependency governance therefore requires inter-regulatory coordination.

The EU CER framework requires governance arrangements identifying the roles and responsibilities of authorities, critical entities and other participants. (EUR-Lex)

The EU's NIS2 framework complements CER by addressing cybersecurity, and the EU expressly requires cooperation between authorities dealing with physical resilience and cybersecurity. (Digital Strategy)

7. Cybersecurity and Physical Infrastructure

The distinction between physical and digital infrastructure is increasingly artificial.

An electricity substation may be physically secure but vulnerable because its control system is connected to an insecure network.

Similarly:

Physical infrastructure + digital infrastructure = integrated critical system.

Therefore, legal governance should combine:

cybersecurity;

physical security;

data protection;

operational resilience;

incident reporting;

supply-chain security.

The EU's CER and NIS2 regimes deliberately operate together so that physical and cyber resilience are addressed in a coordinated manner. (Digital Strategy)

8. Supply-Chain Dependencies

Infrastructure operators frequently rely upon third parties.

Examples include:

transformer manufacturers;

semiconductor suppliers;

cloud providers;

software companies;

satellite operators;

fuel suppliers;

engineering contractors.

A legal framework can therefore require critical operators to conduct supplier-risk assessments.

Contracts may contain:

continuity requirements;

cybersecurity standards;

notification duties;

audit rights;

emergency support obligations;

redundancy requirements;

termination rights;

substitution arrangements.

This is particularly important where a single supplier serves many infrastructure operators.

9. Cross-Border Dependencies

Infrastructure networks frequently cross national borders.

Electricity interconnectors, gas pipelines, telecommunications cables, payment systems and transport networks can create transnational dependencies.

The CER Directive specifically requires consideration of dependencies involving entities and infrastructure located in other Member States and third countries. (EUR-Lex)

This creates several legal problems:

jurisdiction;

information sharing;

emergency powers;

liability;

regulatory cooperation;

national-security concerns.

Cross-border infrastructure therefore requires agreements between governments and regulators as well as private contracts.

10. Protection of Sensitive Information

Dependency mapping creates a significant security dilemma.

Authorities need information about:

network architecture;

vulnerabilities;

suppliers;

backup systems;

control systems;

emergency procedures.

But publishing such information can itself create security risks.

Consequently, legislation normally needs confidentiality mechanisms.

The CER Directive recognises that sensitive information must be exchanged and handled carefully while protecting national-security and commercial interests. (EUR-Lex)

11. Indian Legal Framework

India's legal framework is distributed across several statutes and institutions rather than being contained in one comprehensive "critical infrastructure dependencies" statute.

Information Technology Act, 2000

Section 70A provides for the designation of a national nodal agency for the protection of Critical Information Infrastructure (CII).

Section 70B establishes CERT-In and gives it functions relating to cybersecurity incident response.

The framework is particularly relevant where physical infrastructure increasingly depends upon information systems.

Disaster Management Act, 2005

The Disaster Management Act provides the broader institutional framework for disaster preparedness, response, mitigation and recovery.

Its relevance to infrastructure dependencies arises because disasters can simultaneously affect electricity, communications, transport, water and other essential services.

Sectoral regulation

Infrastructure dependency governance also operates through sector-specific regimes concerning:

electricity;

telecommunications;

banking;

transport;

petroleum and natural gas;

water;

information technology.

Thus, India's legal challenge is not simply creating protection rules but integrating sectoral regulators and infrastructure operators into a common resilience architecture.

12. Important Case Laws

A. PUCL v. Union of India (1997) — Right to Telephone Communication

The Supreme Court of India considered the legal framework governing telephone interception and privacy.

The case is significant for critical infrastructure governance because telecommunications infrastructure is not merely commercial infrastructure; it implicates constitutional rights and public interests.

It demonstrates that governmental control over critical communications infrastructure must operate within legal and constitutional safeguards.

B. Anuradha Bhasin v. Union of India (2020)

The Supreme Court examined restrictions on internet and telecommunications services in Jammu and Kashmir.

The judgment is important for infrastructure law because it recognised the contemporary importance of internet access while examining governmental restrictions under constitutional standards.

It illustrates an important principle for infrastructure governance:

Governmental authority over essential communications infrastructure must be exercised through legally reviewable measures rather than unlimited administrative discretion.

C. Shreya Singhal v. Union of India (2015)

The Supreme Court struck down Section 66A of the Information Technology Act.

Although the case primarily concerned online speech, it is important to critical digital infrastructure because it demonstrates that cybersecurity and digital governance measures must remain consistent with constitutional rights.

It establishes the broader principle that technological regulation cannot operate outside constitutional limitations.

D. Energy Watchdog v. CERC (2017)

The Supreme Court dealt with contractual and regulatory issues involving electricity-generation agreements and change-in-law provisions.

Its significance for infrastructure dependency governance lies in the recognition that electricity infrastructure operates through complex contractual and regulatory arrangements.

Electricity resilience therefore cannot be treated solely as a technical matter; contractual allocation of risks can directly affect the continuity and economics of critical infrastructure.

E. All India Power Engineer Federation v. Sasan Power Ltd. (2017)

The Supreme Court considered issues relating to electricity tariffs and regulatory authority.

The case illustrates the importance of regulatory supervision in ensuring that private contractual arrangements within essential infrastructure sectors remain subject to the statutory electricity-regulation framework.

13. Comparative Case Law

United States — Munn v. Illinois (1877)

The US Supreme Court recognised the principle that certain businesses affected with a public interest may be subject to governmental regulation.

Although the case predates modern critical-infrastructure law, it provides an important theoretical foundation for regulating privately operated infrastructure that performs essential public functions.

United States — Home Building & Loan Association v. Blaisdell (1934)

The Supreme Court considered the government's emergency regulatory authority during the Great Depression.

The case is relevant to infrastructure emergencies because it illustrates the constitutional tension between private rights and governmental emergency powers.

Modern infrastructure legislation must similarly balance:

property rights;

contractual rights;

public safety;

emergency intervention.

14. European Legal Development

The EU represents one of the most developed examples of dependency-based infrastructure regulation.

The CER Directive (EU) 2022/2557 moves beyond the protection of individual infrastructure assets and focuses on the resilience of critical entities providing essential services. (EUR-Lex)

It covers interconnected sectors including:

energy;

transport;

banking;

drinking water;

wastewater;

food;

health;

space;

financial-market infrastructure;

digital infrastructure;

certain public-administration activities. (EUR-Lex)

Member States must also consider cross-sector and cross-border dependencies when conducting risk assessments. (EUR-Lex)

15. UK Approach

The United Kingdom combines sectoral resilience regulation with national-security legislation.

The National Security and Investment Act 2021 permits government scrutiny and intervention in certain acquisitions that may create national-security risks. Sensitive areas include communications, data infrastructure and energy, among others. (GOV.UK)

This is relevant to dependency governance because ownership and control of critical infrastructure can itself create strategic dependency.

For example, acquisition of a strategically important infrastructure supplier may raise questions concerning:

foreign control;

supply security;

technology access;

operational continuity;

national security.

16. Liability for Infrastructure Dependency Failures

A major unresolved legal issue is the allocation of responsibility for cascading failures.

Traditional tort and contract law generally examines relationships between identifiable parties.

Infrastructure failures are different.

A single event may affect:

Operator A → Operator B → Operator C → millions of consumers.

Legal systems therefore need to consider:

contractual liability;

statutory duties;

negligence;

regulatory penalties;

emergency powers;

insurance;

force majeure;

business-continuity obligations.

The law may need to distinguish between failure to prevent an incident and failure to maintain reasonable resilience against foreseeable dependencies.

17. Public-Private Governance

Much critical infrastructure is privately owned or operated.

Consequently, the state cannot govern dependency risks solely through government ownership.

A modern framework requires public-private cooperation involving:

regulators;

infrastructure operators;

emergency agencies;

cybersecurity authorities;

local governments;

suppliers;

law-enforcement agencies.

Legal duties may include mandatory incident reporting, resilience plans, exercises and information sharing.

18. Climate Change and Infrastructure Dependencies

Climate change increases dependency risks.

For example:

Extreme heat → electricity demand increases → grid stress → electricity interruption → water-treatment disruption.

Similarly:

Flood → transport disruption → fuel-delivery disruption → backup-generator shortages → hospital vulnerability.

Consequently, resilience law increasingly needs to incorporate climate-risk assessment.

The EU CER Directive expressly recognises climate change and extreme-weather risks as factors capable of reducing infrastructure capacity and increasing disruption risks. (EUR-Lex)

19. Principles for Future Legal Governance

A mature legal framework should be based upon the following principles:

1. Dependency mapping

Operators should identify their critical upstream and downstream dependencies.

2. System-wide risk assessment

Regulation should consider networks rather than isolated assets.

3. Cascading-failure analysis

Authorities should examine how one disruption can spread across sectors.

4. Redundancy

Critical services should have alternative sources wherever proportionate.

5. Interoperability

Different infrastructure systems should be capable of coordinated emergency operation.

6. Mandatory incident reporting

Significant disruptions should be reported rapidly to competent authorities.

7. Regulatory coordination

Electricity, telecommunications, water, transport and cybersecurity regulators should exchange relevant information.

8. Supply-chain resilience

Critical operators should evaluate strategically important suppliers.

9. Cross-border cooperation

Transnational infrastructure should be governed through coordinated national and international mechanisms.

10. Constitutional and human-rights protection

Emergency infrastructure powers must remain legally constrained and reviewable.

20. Conclusion

Legal governance of critical infrastructure dependencies represents a shift from an asset-centred model of infrastructure protection toward a system-centred model of resilience.

The fundamental legal insight is that critical infrastructure cannot be governed in isolation. Electricity depends on telecommunications; telecommunications depend on electricity; hospitals depend on both; financial services depend on digital and communications networks; and virtually all modern infrastructure depends upon complex global supply chains.

The most significant legal mechanisms are therefore dependency identification, risk assessment, resilience duties, redundancy, incident reporting, cybersecurity, supply-chain regulation, inter-regulatory coordination and cross-border cooperation.

The EU CER Directive provides a particularly clear contemporary model because it expressly requires consideration of cross-sectoral and cross-border dependencies and recognises the possibility of cascading effects. (EUR-Lex) India's framework is more distributed across the IT, disaster-management, electricity, telecommunications and sectoral regulatory regimes, making coordination between institutions particularly important.

Ultimately, the emerging legal principle is that the relevant object of regulation is not merely the critical asset, but the network of dependencies upon which the continuity of essential services depends.

LEAVE A COMMENT