The next major disruption may begin inside a provider you have never heard of and affect a service you cannot live without.
A cyberattack can begin with a compromised device at a small supplier and end with a hospital cancelling appointments, a factory stopping production or an energy operator losing visibility over part of its network. The affected organisation may have invested heavily in security. It may have passed every internal audit. The disruption still entered through a dependency outside its direct control.
In August 2026, a cyber incident at Boston Scientific disrupted systems used to process and ship customer orders across its global operations. The attack showed how quickly a technical intrusion can reach the physical delivery of medical products.
This increasingly defines cybersecurity. Organisations rely on cloud providers, telecommunications networks, software vendors, payment systems, energy grids and data services. Each connection improves speed, reach and efficiency. It also creates another route through which disruption can travel.
The consequences now extend far beyond the loss of corporate information. Security has therefore become part of a wider struggle over economic stability, national resilience and geopolitical influence.
The organisation controls only part of its environment
Most organisations can describe the systems they own. They know which applications employees use, where they store information and which teams manage access. Their visibility usually becomes less reliable once the map reaches suppliers, subcontractors and shared infrastructure.
A software provider may depend on another company for identity management. A cloud outage may prevent employees from accessing critical applications. A telecommunications failure can disable authentication. An energy interruption may take digital services offline even when every cybersecurity control works as intended.
Supply chains add further layers. Large organisations can impose security requirements on important vendors, request certifications and carry out assessments. Few can inspect every subcontractor behind those vendors or continuously verify the software components they use.
The result is a network of hidden connections. A bank, a logistics company and a public authority may have no direct operational relationship. All three can suffer disruption when a common technology provider fails.
The AWS outage of October 2025 revealed the scale of these shared dependencies. A failure originating in one cloud region disrupted more than a thousand companies, including financial platforms, communication tools and government services. Many affected organisations had no direct involvement with the faulty system that triggered the disruption.
Traditional security programmes struggle with this reality because they grew around assets the organisation could identify and protect. Today, the effective perimeter includes every service required to keep operations running. Most organisations cannot draw that boundary with confidence.
Geopolitical conflict enters through ordinary technology
The World Economic Forum reports that 64% of organisations now account for geopolitically motivated cyberattacks in their risk strategies. These attacks include espionage and attempts to disrupt critical infrastructure. Geopolitical conditions also remain the leading influence on cyber-risk mitigation strategies.
Digital infrastructure has acquired strategic value for governments. Cloud capacity, semiconductor supply, satellite communications, undersea cables, telecommunications equipment and industrial software now form part of international competition. States seek influence over these assets because modern economies depend on them.
Organisations inherit this exposure through ordinary technology decisions. A supplier’s location can affect regulatory access, technical support and vulnerability to sanctions. A data centre can gain strategic importance because of the services it hosts. Software purchased years ago for commercial reasons may become politically sensitive after relations between countries deteriorate.
This exposure became visible during the Middle East conflict in early 2026, when drone strikes affected cloud infrastructure in the United Arab Emirates and Bahrain. Organisations far from the fighting experienced service problems because applications and data depended on infrastructure located inside the conflict zone.
These effects rarely remain inside one department. Procurement teams may need to reconsider suppliers. Legal functions may face new restrictions on data or technology transfers. Operations teams may need alternatives for services that once appeared dependable. Security specialists may detect hostile activity without having enough context to understand its political significance.
Many organisations still separate geopolitical analysis, supplier management and cybersecurity planning. Their operational dependencies have already connected them.
The responsibility extends further than the boardroom.
Resilience depends on whether risk, procurement, security, operations and communications teams can build a shared view of the organisation’s exposure. If each function sees only its own part of the problem, the organisation remains vulnerable at the points between them.
AI changes the economics of attack
Artificial intelligence gives attackers a practical advantage through speed and scale. It reduces the work involved in finding targets, studying organisations and preparing convincing approaches.
Within energy and industrial environments, specialists have also observed attempts to use AI to create scripts, analyse technical protocols and identify vulnerable equipment. The technology can help people with limited expertise complete parts of an attack that once demanded high specialist knowledge.
This development changes the cost of cybercrime
The World Economic Forum found that 87% of respondents regarded AI-related vulnerabilities as the fastest-growing cyber risk during 2025. The figure reflects concern about external attacks and the way organisations deploy AI internally.
Employees may enter confidential information into unapproved tools. Automated systems may receive excessive access to documents and applications. An AI assistant connected to several business systems can create new paths between information that the organisation previously kept separate.
AI therefore changes the security environment from both directions. Attackers gain speed, and organisations introduce new dependencies as they adopt the technology. Security teams must defend existing infrastructure and understand an expanding collection of models, providers, data connections and automated processes.
Industrial operators face an additional constraint. They cannot install patches or change systems casually if an update might interrupt production or destabilise equipment. Attackers can experiment repeatedly. Operators must test each defensive change against its possible physical consequences.
Defenders have to be right 100 percent of the time. Attackers only have to be right once
The wording simplifies a more complicated situation, although it captures the pressure. An organisation may need to maintain thousands of controls across old equipment, modern software and external services. An attacker needs just one weakness that offers useful access.
Critical infrastructure reveals what is at stake
Critical infrastructure shows how deeply digital systems connect society. Energy, healthcare, finance, telecommunications, manufacturing and logistics increasingly depend on shared networks, data flows and external providers.
This connectivity improves coordination. It also allows disruption to spread. An energy failure can interrupt communications. A cloud outage can affect payments and logistics. A compromised supplier can expose several organisations at once.
Recent incidents in the energy sector make this risk tangible. Russian-linked groups have targeted Ukrainian and Polish energy infrastructure. US officials have warned about attempts to breach industrial devices used across energy and manufacturing. British authorities briefed energy executives following reports of an incident that disrupted a small generating facility for several days.
Attribution often remains uncertain. Investigators may identify technical similarities with earlier attacks without proving who ordered the activity. Governments may reach different conclusions from private security researchers. Organisations still need to restore services and communicate with customers during this uncertainty.
Security capacity varies sharply across essential services. Large energy operators can maintain specialist teams and continuous monitoring. Smaller utilities, hospitals, transport providers and local authorities often rely on ageing systems, limited budgets and a handful of specialists.
Their operational role can reach far beyond their size. A regional utility may support a national network, and one specialist supplier may serve hundreds of organisations. When either fails, disruption travels through the connections others depend on.
When compliance reaches its limits
Regulation, standards and supplier assessments can strengthen security. They establish expectations, clarify responsibility and compel organisations to examine weaknesses that might otherwise remain hidden. Their effectiveness still depends on the visibility available to the organisation.
DORA requires European financial entities to identify and manage the technology providers supporting critical operations. It brings greater discipline to third-party risk, resilience testing and incident response. Its implementation also exposes a difficult reality: an organisation may document its principal providers without seeing every subcontractor, shared cloud service or infrastructure dependency beneath them.
A supplier can meet every contractual requirement and remain exposed through another provider. Registers become outdated, technology architectures change and several apparently independent services may rely on the same cloud environment. A certificate confirms that certain controls existed when assessors conducted their review. It cannot prove how the wider ecosystem will behave during disruption.
Compliance can show that controls exist. Only disruption reveals whether the organisation can still function
Compliance creates accountability and improves preparedness. It cannot guarantee continuity. Organisations must test whether critical services can operate when expected conditions fail, including the loss of a major provider. Without that practical examination, extensive documentation may offer assurance on paper and little guidance when operations begin to break down.
Security means keeping the organisation running
Prevention remains essential, though it cannot provide complete assurance across an extensive network of people, technologies and providers. Organisations also need to prepare for controls that fail.
Resilience begins with identifying which services must continue during disruption. It then traces the people, systems and external providers that support them. This work often reveals dependencies that conventional asset inventories miss.
A supposedly redundant system may depend on the same identity provider as the primary service. Several suppliers may host their applications in the same cloud region. A backup may exist without a reliable restoration test. Staff may understand the response procedure but lack authority to make urgent operational decisions.
When ransomware disabled the control system at the water treatment plant in Minot, North Dakota, in March 2026, operators switched to manual processes for about 16 hours. The water supply remained safe because staff could continue operating the facility without the affected system.
Europe’s Critical Entities Resilience framework reflects this broader understanding. It expects critical organisations to assess risk and adopt technical, security and organisational measures that help them prevent, resist, absorb and recover from disruption.
Those activities require cooperation across departmental boundaries. Security teams can identify technical threats. Operations teams understand which processes must continue. Procurement functions know where contractual dependencies sit. Legal and communications teams manage obligations to regulators, customers and the public.
None of these functions can create resilience alone.
During a serious incident, the organisation may need to suspend certain activities to protect essential services. Staff may have to operate manually, accept slower processing or communicate before investigators understand the cause. These decisions require clear authority, though their quality depends on preparation across the organisation.
Organisations must confront their hidden dependencies
A serious resilience assessment should begin with practical questions that cross departmental boundaries:
- Which services must continue during a prolonged digital disruption?
- Which external providers support them?
- Where do separate systems share the same infrastructure?
- How long can operations continue without cloud access, telecommunications, electricity or automated processes?
- Which teams can change priorities and accept temporary risk?
- Has the organisation tested recovery without a major supplier?
- Which dependencies could become sensitive during an international crisis?
- Can suppliers communicate quickly when an incident affects several customers?
These questions expose the difference between an inventory of technology and an understanding of operations. They also show where internal incentives may work against resilience.
Procurement teams often favour efficiency, standardisation and lower costs. Technology teams value integration and speed. Security functions may seek separation, redundancy and tighter control. Each goal has operational value. The organisation must manage the tensions they create together.
Concentration offers a clear example. Moving services to one provider can reduce complexity and improve oversight. It can also create a single point of failure. The appropriate choice depends on the importance of the service, the available alternatives and the organisation’s capacity to operate during an outage.
Human judgement becomes especially important during recovery. Automated tools can detect anomalies and recommend actions. People still decide which services to protect, when to inform customers and how much uncertainty to disclose. Their decisions improve when teams have already tested the difficult scenarios.
Trust turns an ecosystem into a defence
An organisation can strengthen its own systems, but resilience grows through cooperation across the wider ecosystem. Suppliers, regulators, technology providers and public authorities need trusted ways to exchange threat intelligence, report weaknesses and coordinate their response when disruption crosses organisational boundaries.
A practical example of this approach is WeSec – Il Salone della Sicurezza, taking place in Milan in September 2026. Promoted by ABI and organised by ABI Servizi, the event brings together banks, institutions, public authorities, businesses, researchers and technology providers to examine cybersecurity, physical security, fraud, AI, geopolitics and critical infrastructure as connected parts of the same security environment.
Its value lies in the relationships it seeks to build across these communities. Sharing experience before a crisis helps organisations understand common dependencies, develop a shared language and establish the trust needed to coordinate when disruption crosses institutional or sectoral boundaries.
Joint exercises can reveal connections that individual risk assessments miss. Shared standards can give smaller providers practical security measures they can apply. Larger organisations can also support critical partners with expertise, training and clearer incident procedures, strengthening the services on which everyone depends.
This cooperation requires trust. Organisations need confidence that sharing a vulnerability will lead to collective action rather than blame. Regulators and public authorities can support that trust by creating secure channels for information exchange and helping different sectors prepare for disruptions that affect them together.
The next major disruption may still begin inside a provider you have never heard of. When the ecosystem can see its connections and act together, it has a far better chance of containing the disruption before it reaches a service you cannot live without.
Further Reading
- Global Cybersecurity Outlook 2026 | World Economic Forum
- UK says three-quarters of cyberattacks on critical systems are linked to hostile states | Reuters
- Critical Infrastructure Sectors | Cybersecurity and Infrastructure Security Agency
- Digital Operational Resilience Act — Regulation (EU) 2022/2554 | European Union
- Critical infrastructure resilience at EU level | European Commission
- WeSec – Il Salone della Sicurezza | ABI Eventi

Leave a Reply