Skip to main content

Infrastructure resilience was once defined by the physical condition of individual assets and their ability to withstand shocks and recover after disruption.

That definition is no longer enough. Today's infrastructure is an interconnected system in which digital networks, operational technology, cloud platforms, sensors, and AI-enabled controls work together. As those connections deepen, failures rarely stay contained. A disruption in one system can quickly cascade across others.

Resilience can therefore no longer focus solely on protecting individual assets. It requires an integrated systems-based strategy that ensures the continuity of critical services, builds redundancy, enables rapid recovery, and anticipates cascading failures.

In this new reality, cyber and physical resilience should not be treated as separate agendas. Yet governments are responding to them very differently. Deloitte's 2026 Future of Infrastructure Survey (see “About the survey”) shows that cybersecurity is one of the few resilience priorities where risk recognition, investment, and action are closely aligned. At the same time, the findings reveal a growing gap between awareness of extreme weather-related threats and investments in physical resilience.

About the survey

In March 2026, Deloitte’s Center for Government Insights surveyed 985 infrastructure executives across government, private sector, and not-for-profit organizations in 21 countries to understand how leaders are approaching infrastructure investment, delivery, resilience, financing, and artificial intelligence. The report identifies five shifts shaping the future of infrastructure. Taken together, they show how infrastructure is evolving from individual assets to interconnected systems and what this shift means for governments and infrastructure leaders (read the full methodology here).

Cybersecurity is where risk recognition is translating into action

More than half of respondents to Deloitte’s 2026 Global Infrastructure Survey believe that public and critical infrastructure assets need to be strengthened against cyberattacks (figure 1). Digital systems are no longer add-ons to physical assets. Sensors, cloud services, AI tools, and connected systems are central to how infrastructure operates and performs. Against this backdrop, the survey findings reflect a broader recognition that cyber resilience has become fundamental to infrastructure operations.

As these systems become more deeply embedded, cyber resilience should no longer be treated as an afterthought or solely as a way to protect information systems. It is an enabling capability for maintaining operations, supporting informed decision-making, and sustaining essential services during disruption. It needs to be built in from the design phase, not patched on after systems are already operating.1

Although design-phase integration is necessary, it is not sufficient on its own. Infrastructure systems should also be built to continuously sense, share, and act on real-time information across institutional boundaries. The ability to detect what is happening, communicate it quickly, and coordinate a response across organizations is already difficult to achieve, and as infrastructure complexity and interdependencies deepen, that challenge will only grow.

At the same time, as AI accelerates both infrastructure operations and cyberthreats against them, this imperative is becoming more urgent. As a US state chief information security officer notes, “With the rising adoption of AI and agentic AI, the speed at which attacks are occurring is accelerating at a blistering pace.”2

Other research suggests that 94% of leaders identify AI as the most significant driver of cybersecurity change, while 87% identify AI-related vulnerabilities as the fastest-growing cyber risk.3 Together, these findings reinforce the need for a more integrated governance approach that aligns AI assurance more closely with cybersecurity, operational technology, and critical-infrastructure oversight.

What the survey tells us:

  • Globally, 55% of respondents say that public and critical infrastructure need stronger protection from cyberattacks.
  • The cybersecurity urgency varies dramatically across regions. Latin American (78%), Middle East/Africa (66%), and Asia-Pacific (63%) respondents seem to be much more worried than European and North American respondents.

Cybersecurity stands out as one of the few resilience priorities where the path from risk recognition to government action is already visible. Government respondents rank strengthening cybersecurity and incident response as their top critical infrastructure priority over the next three years (figure 2).

What the survey tells us:

  • Globally, 60% of government respondents identify strengthening cybersecurity and incident response as their highest critical infrastructure investment priority.
  • This places cybersecurity as a clear priority, well ahead of other investments in deploying a digital intelligence layer, public-private partnerships, new builds, and extreme weather resilience.
  • We see a regional variance in action with the surveyed Middle East/Africa (69%) and European (64%) government leaders considering cybersecurity as higher priority than in other regions.

Additionally, public and commercial infrastructure leaders are broadly aligned in prioritizing increased cybersecurity investments. Globally, 84% of respondents rate cybersecurity as a leading area for expected increases in government investment, with particularly strong momentum from private-sector respondents (figure 3).

Cyber resilience cannot be built asset by asset or agency by agency. Since disruptions increasingly cascade across interconnected systems and institutional boundaries, governments should adopt an ecosystem resilience approach built on shared capabilities and coordinated governance. This requires a whole-of-government approach in which governments take the lead in providing support to entities outside their jurisdictions. The key principle is to strengthen and protect each node in the ecosystem, especially the ones that lack the resources and know-how to build independent cyber resilience.

Texas illustrates what an ecosystem resilience approach can look like in practice. In 2022, the Texas Department of Information Resources partnered with Angelo State University to establish the first regional security operations center to provide cybersecurity services to local governments. The center, housed on campus and staffed in part with students, provides 24/7 monitoring of servers, systems, and network traffic for local governments, identifying threats in real time.4

In 2025, the state established the Texas Cyber Command to act as the state’s cybersecurity hub to receive cyber incident reports, conduct digital forensics, develop threat intelligence, and support workforce training.5 Together, these efforts extend cyber support beyond state agencies to local governments, public institutions, critical sectors, and the broader cybersecurity workforce.6

But cyber is the exception. Across other resilience domains, particularly physical and extreme weather preparedness, the story is quite different.

Physical resilience faces an implementation gap, not an awareness gap

Physical resilience, especially protection against natural disasters and extreme weather events, is widely acknowledged as the top risk to critical infrastructure (figure 4). Yet investment in extreme weather resilience and disaster preparedness continues to lag (figure 5).

What the survey tells us:

  • 56% of surveyed government leaders globally identify natural disasters and extreme weather events as the greatest threat to infrastructure resilience.
  • Yet, disaster preparedness ranks sixth among near-term infrastructure investment priorities. Only 33% rank building extreme weather-resilient infrastructure as their top investment priority.
  • Latin America is the only region where investment in extreme weather resilience is nearly on par with strengthening cybersecurity (43% versus 45%).

The cost of that implementation gap is becoming increasingly difficult to ignore. Deloitte modeling estimates that average annual direct losses to infrastructure from natural disasters could reach US$460 billion globally by 2050.7 When indirect economic disruption, cascading losses, and ecosystem impacts are included, current annual disaster costs already exceed US$2.3 trillion.8

Several structural factors help explain why investments have not kept pace with risk. Cybersecurity investments are often more targeted, fit within shorter technology-refresh cycles, have clearer organizational ownership, and are reinforced by regulatory requirements and the immediate visibility of cyber incidents. They also align with broader technology modernization efforts.

Extreme weather resilience investments, by contrast, are capital-intensive, asset-specific, and long-term. They also compete with more immediate funding priorities. As a result, many governments continue to underinvest in this area despite recognizing it as a growing threat.

Closing that gap is ultimately a governance challenge as much as an engineering or financial one. Digital capabilities can support that effort by anticipating cascading effects during extreme weather events, making digital resilience an important enabler of physical resilience. For example, Broward County Metropolitan Planning Organization, Florida, is developing a digital twin platform that integrates data from different infrastructure assets to support predictive planning and cross-municipal coordination.9 The platform illustrates how digital capabilities can directly strengthen physical and extreme weather resilience by turning fragmented local data into shared, actionable intelligence.

Whether the threat is a ransomware attack or a coastal storm, the consequences cascade across the same interconnected system. Treating physical and digital resilience as separate agendas is no longer a viable strategy.

Resilience will increasingly depend on connected systems

The survey suggests a clear inflection point in how governments approach infrastructure resilience. Cybersecurity shows what becomes possible when risk recognition translates into investment and action, while extreme weather resilience highlights the harder challenge: turning awareness into investments.

Closing that gap will require more than funding. It will also require governance and appraisal frameworks that recognize the full value of resilience.10

The more fundamental shift is that physical and digital resilience are converging.11 The digital capabilities governments are building to defend against cyberattacks can also make physical infrastructure more adaptable and recoverable during extreme weather events.

The next phase of infrastructure resilience will require an integrated approach—one focused not just on protecting individual assets, but on ensuring critical services continue when disruptions cascade across connected systems.

BY

Miguel Eiras Antunes

Deloitte Portugal

Lea Hurley

United States

Glynis Rodrigues

Deloitte India

Lorraine Mackin

United Kingdom

Tiffany Fishman

Deloitte United States

ENDNOTES

  1. Faris Naffaa, Ayla Hitchcock, and Jasmine Baker, “Secure by design: A CISO’s guide to a practical approach,” Deloitte, 2024.

  2. Meredith Ward and Mike Wyatt, “2026 NASCIO-Deloitte cybersecurity study,” Deloitte Insights, April 27, 2026.

  3. World Economic Forum, “Global Cybersecurity Outlook 2026,” Jan. 12, 2026; Ricardo Villadiego, “How AI protects critical infrastructure from emerging global threats,” World Economic Forum, May 13, 2026.

  4. Texas Department of Information Resources, “An overview of regional security operations centers in Texas,” January 2024; Tom Nurre, “Angelo state opens Regional Security Operations Center,” Angelo State University, Jan. 19, 2023.

  5. Office of the Texas Governor, “Governor Abbott signs Texas Cyber Command into law in San Antonio,” press release, June 2, 2025; Texas Cyber Command, “Homepage,” accessed Aug. 18, 2026.

  6. Sam Park, John O'Leary, Alex Lewek, Sushumna Agarwal, and Mike Wyatt, Whole-of-state cybersecurity: protecting the public information ecosystem, Deloitte Insights, Jan. 30, 2026.

  7. Deloitte Global, “AI for infrastructure resilience,” June 24, 2025.

  8. UNDRR, “Global assessment report (GAR) 2025: Resilience pays: Investing and financing for our future,” 2025.

  9. Broward Metropolitan Planning Organization, “About the MPO,” accessed July 23, 2026; Broward Metropolitan Planning Organization, “Mapping the future of transportation: 2023-2024 annual report,” accessed July 23, 2026; Broward Metropolitan Planning Organization, “Turning opportunity into impact: Annual report 2025-2026,” accessed Aug. 18, 2026.

  10. World Bank, “$4.2 trillion can be saved by investing in more resilient infrastructure, new World Bank report finds,” June 19, 2019; Coalition for Disaster Resilient Infrastructure, “Global infrastructure resilience 2025,” accessed July 23, 2026.

  11. Ecam, “Why cyber and physical security convergence matters,” Feb. 24, 2026.

ACKNOWLEDGMENTS

Editorial (including production and copyediting): Kavita Majumdar, Pubali Dey, Aparna Prusty, and Anu Augustine

Design: Natalie Pfaff and Harry Wedel

Cover image by: Natalie Pfaff and Jim Slatton

Knowledge Services: Rohan Singh

COPYRIGHT