Abstract

This note analyses cascading failures across critical infrastructure sectors, drawing on six documented cases: the Iberian (2025), Texan (2021), Italian and North American (2003) power outages, the systematic exploitation of interdependencies against Ukraine (2017–2024), and the attack on Change Healthcare (2024). It establishes that these cascades share a common substrate: the digital layer through which failures cross sectoral boundaries. From these cases, it derives a ten-criterion evaluation grid to assess whether a given instrument (regulatory framework or exercise) takes cross-sector propagation as its object. The analysis relies exclusively on public documentation. Bilingual note (French and English), with executive summaries in both languages.

Executive summary (PDF)

Changelog v1 → v2

Version 2 (August 2026). This version incorporates the comments of three reviewers. Main changes: a treatment of the supply chain provisions (NIS2 Articles 21 and 22, DORA Articles 31 to 44) added to section 4.2; the M.E.Doc case, previously absent from that section, projected onto the regulatory frameworks; the ten evaluation criteria made operational, each now carrying a test and a case; and the register of the note stated explicitly, its criteria being prescriptive at the level of exercise and plan design.

How to cite

Roux, N. (2026). The Digital Substrate of Cascading Failures: Cross-Sector Propagation in European Critical Infrastructure. Independent policy note.
Zenodo DOI: https://doi.org/10.5281/zenodo.21285147