Short course  ·  approx. 35 minutes  ·  no prior knowledge needed

What is national infrastructure?

The water in the tap, the signal on the phone, the payment that clears in two seconds. Thirteen sectors hold the country up — and they hold each other up too.

Audio narrationCourse introduction
UK focus5 modules2 interactive labs10-question check
Start module 01 Skip to knowledge check

01  /  Definitions

Infrastructure, and the part of it that is critical

Infrastructure is the set of physical and digital systems a country runs on: pipes, cables, rails, satellites, servers, treatment works, trading platforms and the people who operate them. Most of it is privately owned. Almost all of it is invisible until it stops.

Audio narrationModule 01

National infrastructure is the portion of that which is nationally significant — the assets and services the UK as a whole depends on. The UK government groups it into thirteen sectors.

Critical national infrastructure (CNI) is a smaller subset again. An asset is critical when losing it would seriously damage the delivery of essential services, cause severe economic or social harm, or cost lives. A handful of things are also treated as critical not because their loss stops a service, but because damaging them endangers the public directly — civil nuclear plants and major chemical sites are the standard examples.

Not everything important is critical. A single village substation matters to that village. The transmission node that feeds a city, the payment system that clears the nation's card transactions, the treatment works that supplies two million homes — those are critical, because their failure is national.

Working distinction used throughout this course
Test 1 — Essentiality

Does the asset deliver, or directly enable, a service the public cannot do without?

Test 2 — Scale of loss

Would losing it cause major detrimental impact nationally, not just locally?

Test 3 — Danger held

Does the asset itself hold a hazard that harms the public if it is attacked or fails?

Government keeps this judgement live through a criticalities process: each sector's lead department works with industry to categorise assets, and only those meeting the threshold are designated critical. Sectors contain thousands of assets. Only a fraction carry the designation, and the list is not published.

02  /  The map

The thirteen sectors

Each sector is overseen by a Lead Government Department responsible for its policy, guidance and industry engagement. Select any sector to see what sits inside it.

Audio narrationModule 02

Select a sector above to read what it covers, who leads it, and what depends on it.

The list is not frozen. In September 2024, Data Infrastructure was formally designated as a CNI sub-sector of Communications, alongside Telecommunications and Internet, Post and Broadcast. This did not make every data centre a designated critical asset; individual assets still need to meet the government's criticality threshold.

03  /  Interactive lab

Nothing fails alone

The reason infrastructure is treated as a security matter, not just an engineering one, is interdependence. Sectors are customers of each other. A single loss propagates outward, and the second-order effects are often worse than the first.

Audio narrationModule 03
Lab 01 — Cascade simulator

Choose a sector to take offline. The model shows what loses service directly, then what loses service because of that. Relationships here are illustrative and simplified for teaching — real dependency mapping is asset-by-asset and much messier.

Origin of failure Direct loss Knock-on loss

No failure selected

Pick a sector above to run the scenario.

Concentration risk

When thousands of organisations rely on the same cloud region, the same managed service provider or the same timing signal, a single failure stops behaving like one customer's problem.

Just-in-time fragility

Lean supply chains hold days of stock, not months. Cascades move faster than replenishment, which is why fuel, food and medicine disruptions escalate within a week.

04  /  Risk

What actually threatens it

UK risk planning splits threats into malicious ones — someone intends the harm — and non-malicious hazards, where nobody does. Both are assessed together, because the infrastructure does not care which kind knocked it over.

Audio narrationModule 04
Cyber attack

Ransomware and destructive intrusion against operators and their suppliers. Assessed in the National Risk Register as moderate likelihood but potentially catastrophic where it hits critical systems.

Hostile state activity

Pre-positioning inside operational networks, sabotage of subsea cables and pipelines, drone incursions over sensitive sites, and interference with satellite navigation and timing.

Terrorism

Attacks on crowded places, transport and energy assets, and on sites whose damage releases a hazard.

Insider risk

Access misused by someone already trusted — the reason personnel security sits alongside physical and cyber security rather than under HR.

95Risks listed in the public National Risk Register, July 2026
204Nationally significant cyber incidents handled by the NCSC in a year — more than double the previous 89
13Sectors within scope of national infrastructure protection

Figures current as at July 2026. The National Risk Register is now reassessed on a rolling basis, so verify before reuse.

05  /  The protective system

Who keeps it standing

There is no single agency for infrastructure. Protection is layered, and each layer does a different job. Read it from the top down — and note where you sit.

Audio narrationModule 05
Technical authorities

NPSA, part of MI5, is the national technical authority for physical and personnel security. The NCSC, part of GCHQ, is the authority for cyber security. UKNACE covers technical security. They set the advice everyone else builds on.

Lead departments

Every sector has a Lead Government Department that owns sector policy, runs the criticalities process with industry, and answers for that sector in a crisis.

Regulators & law

Sector regulators enforce duties on operators. The NIS Regulations 2018 set cyber duties for essential services; the Cyber Security and Resilience Bill, in the Lords as at July 2026, would widen that to managed service providers and data centres, tighten incident reporting and raise penalties.

Local response

The Civil Contingencies Act 2004 places planning duties on responders and organises them into Local Resilience Forums — the multi-agency structures that plan for and manage emergencies in each area.

Whole of society

Current UK policy is explicit that resilience is shared. Businesses, communities and households are treated as part of the system, not bystanders to it — which is the argument for courses like this one existing at all.

Direction of travel, as at mid-2026: continuous rather than periodic risk assessment, published implementation reporting against a Government Resilience Action Plan, investment in flood defence and telecoms security, a national resilience academy training thousands of practitioners a year, and legislation extending cyber duties deeper into supply chains.

Knowledge check

Ten questions

Answer each one. Feedback appears immediately — a wrong answer is fine, read the explanation and move on.

Audio narrationKnowledge check
Score: 0 / 10  ·  not started

Course complete

What you should now be able to do

Audio narrationCourse summary

Next step: look at your own organisation as a node in this map. What does it supply, who supplies it, and how many days could it run if the sector above it stopped?