Rethinking resilience: Avoiding the next energy crisis requires a systems approach
Threats to modern grids are no longer siloed – so there's no reason that our approach to energy resilience should be. Image: REUTERS/Pascal Rossignol
- The 2025 Iberian blackout and 2026 European heatwaves each had no single cause; both were reactions rippling through systems managed separately.
- More than half of senior energy professionals say their organizations lack a clearly defined resilience strategy.
- Energy resilience has to be built in by design across public and private actors – not added on after something has already gone wrong.
In April 2025, a blackout swept across mainland Spain and Portugal. Within seconds, transport networks stopped, mobile networks went down and hospitals switched to backup power. A panel investigation by ENTSO-E, an association of European grid operators, later traced the failure to an interacting mix of technical and grid-control factors.
One year on, record-breaking heatwaves across Western Europe pushed electricity demand to new highs in summer 2026, and grid operators issued fresh warnings over supply as the effects cascaded across borders.
Neither 2025’s blackouts or the sustained grid pressure seen this year had any single cause. Each was the result of a chain reaction, a technical fault, a control failure or a climate shock rippling through systems and sectors that used to be managed separately. This is a shift that we must pay attention to.
For most of the past decade, energy companies have treated cyber-attacks, physical sabotage, extreme weather and geopolitical disruption as distinct problems, each with its own team, its own budget and its own risk register. But in increasingly digitalized and interconnected energy systems, that separation is starting to look like the problem itself.
Threats to energy no longer stay in their lane
Subsea gas pipelines and power cables have been deliberately damaged in recent years. Electricity grids have been hit by physical sabotage and cyber-attacks. LNG terminals and tankers face drones and blockades as well as adverse weather. Asia-Pacific grid operators are now designing wind infrastructure to withstand earthquakes; a necessary measure, as renewables are expanding into seismically active markets while governments hesitate to tighten regulation for fear of undermining competitiveness.
Add policy uncertainty, ageing assets and patchy grid monitoring, and what emerges is less a list of separate threats than a single, interconnected exposure of the global energy system. A drought in Ecuador in 2024 caused near-total grid failure, because the country draws three-quarters of its electricity from hydropower. That is a climate story, a supply story and an infrastructure story at once, and none of the three lenses explains it alone.
Survey data backs this up. DNV's 2026 Energy Industry Insights research, based on responses from more than 1,000 senior energy professionals, found that more than half say their organizations lack a clearly defined and regularly updated resilience strategy. Barely a third expect to increase investment in climate resilience over the coming year, even as the physical risks become harder to ignore.
Resilience is now a boardroom question
For years, resilience meant compliance: meeting a safety standard, passing an audit, satisfying a regulator after the fact. That is no longer enough. Governments increasingly treat energy as critical national infrastructure. The EU's Critical Entities Resilience and NIS2 directives now require operators to demonstrate systemic physical and cyber resistance, rather than simply report on incidents once they happen. In the US, the 1950 Defense Production Act has been invoked to treat grid components and supply chains as a national security priority.
That regulatory shift reflects an economic reality. The energy trilemma of security, affordability and sustainability cannot hold if any one leg fails: blackouts and supply shocks push prices up for households and businesses alike, and prevention is consistently cheaper than the alternative. Resilience has moved from a line in a compliance file to a question for the boardroom, and increasingly for finance ministries too.
What a systems-wide approach requires
Closing the gap between recognizing a threat and acting on it means addressing three specific weaknesses.
The first is communication. Industry is often the first to spot an emerging threat, not government, yet the channels for sharing that intelligence with the state remain fragmented in most markets. The second is visibility. Companies routinely map their direct suppliers but rarely see the software, firmware and hardware buried several tiers down their supply chains, which limits strategies such as friendshoring to partial effect at best. The third is legal authority. As DNV notes in its position paper on the subject, US utilities fear drone incursions near substations but often lack the legal mandate to intercept them, an operational risk no internal plan can resolve alone.
Eurelectric, the trade body representing Europe's power sector, has called preparedness for hybrid attacks “a new normal” and is pushing EU member states to back utilities with clearer support. DNV now proposes a four-step framework cycling through risk analysis, investment prioritization, implementation and validation across five dimensions, from physical assets to supply chains. The detail varies between organizations, but the direction does not: resilience has to be built in by design, across public and private actors, rather than added on once something has already gone wrong.
A shared language, coordinated action required
No one company, regulator or country can act on this problem alone, because the risks that create it do not respect those boundaries either. What the sector needs is a shared language for risk: one that lets a utility, a regulator and a government agency describe the same vulnerability the same way and agree who acts on it first.
Asset owners and operators are then responsible for securing their infrastructure, while governments play a critical role in providing wider threat intelligence, protecting critical infrastructure, enabling information sharing, coordinating incident response and creating risk-based regulatory foundations that raise resilience across the entire sector.
DNV’s framework can support both levels of responsibility, from individual assets and portfolios to wider energy systems and regions. Without a coordinated effort such as this, we risk leaving energy systems defended in silos against threats that have long since evolved beyond any single party’s ability to manage alone.
Don't miss any update on this topic
Create a free account and access your personalized content collection with our latest publications and analyses.
License and Republishing
World Economic Forum articles may be republished in accordance with the Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International Public License, and in accordance with our Terms of Use.
The views expressed in this article are those of the author alone and not the World Economic Forum.
Stay up to date:
Energy Infrastructure
Forum Stories newsletter
Bringing you weekly curated insights and analysis on the global issues that matter.


