Preview • August 2026
Beyond the Checklist: Rethinking Critical Infrastructure Resilience in a Networked World
Why lengthening a risk register does not make a networked system of systems any safer
Tony Ridley, MSc, CSyP, FSyI, SRMCP. Originally published 19 August 2026.
Boards and executives responsible for critical infrastructure tend to treat the risk register as a proxy for safety. The longer the list of identified hazards, the safer the organisation is assumed to be. This piece examines why that assumption fails once an asset sits inside a networked system of systems, where power, water, transport and telecommunications are interdependent rather than isolated. It looks at why malevolent human actors cannot be modelled the same way as natural hazards, why granular, asset-by-asset analysis can obscure risk rather than reveal it, and why failure in one node of a network rarely stays contained to that node. It also examines a persistent capability gap in the security and risk profession itself, and why standardised checklists and universal standards, while useful as an entry point, cannot on their own support genuine risk-informed decision-making for systems of national significance. The piece sets out the analytical sequence that leadership needs to work through in full, and the questions every leader responsible for a critical system or asset should be able to answer about how failure would actually propagate through their organisation and its dependencies.
This is a member article. The full piece is available to members. Become a member to read it in full.