Infrastructure resilience was once defined by the physical condition of individual assets and their ability to withstand shocks and recover after disruption.
That definition is no longer enough. Today's infrastructure is an interconnected system in which digital networks, operational technology, cloud platforms, sensors, and AI-enabled controls work together. As those connections deepen, failures rarely stay contained. A disruption in one system can quickly cascade across others.
Resilience can therefore no longer focus solely on protecting individual assets. It requires an integrated systems-based strategy that ensures the continuity of critical services, builds redundancy, enables rapid recovery, and anticipates cascading failures.
In this new reality, cyber and physical resilience should not be treated as separate agendas. Yet governments are responding to them very differently. Deloitte's 2026 Future of Infrastructure Survey (see “About the survey”) shows that cybersecurity is one of the few resilience priorities where risk recognition, investment, and action are closely aligned. At the same time, the findings reveal a growing gap between awareness of extreme weather-related threats and investments in physical resilience.
In March 2026, Deloitte’s Center for Government Insights surveyed 985 infrastructure executives across government, private sector, and not-for-profit organizations in 21 countries to understand how leaders are approaching infrastructure investment, delivery, resilience, financing, and artificial intelligence. The report identifies five shifts shaping the future of infrastructure. Taken together, they show how infrastructure is evolving from individual assets to interconnected systems and what this shift means for governments and infrastructure leaders (read the full methodology here).
More than half of respondents to Deloitte’s 2026 Global Infrastructure Survey believe that public and critical infrastructure assets need to be strengthened against cyberattacks (figure 1). Digital systems are no longer add-ons to physical assets. Sensors, cloud services, AI tools, and connected systems are central to how infrastructure operates and performs. Against this backdrop, the survey findings reflect a broader recognition that cyber resilience has become fundamental to infrastructure operations.
As these systems become more deeply embedded, cyber resilience should no longer be treated as an afterthought or solely as a way to protect information systems. It is an enabling capability for maintaining operations, supporting informed decision-making, and sustaining essential services during disruption. It needs to be built in from the design phase, not patched on after systems are already operating.1
Although design-phase integration is necessary, it is not sufficient on its own. Infrastructure systems should also be built to continuously sense, share, and act on real-time information across institutional boundaries. The ability to detect what is happening, communicate it quickly, and coordinate a response across organizations is already difficult to achieve, and as infrastructure complexity and interdependencies deepen, that challenge will only grow.
At the same time, as AI accelerates both infrastructure operations and cyberthreats against them, this imperative is becoming more urgent. As a US state chief information security officer notes, “With the rising adoption of AI and agentic AI, the speed at which attacks are occurring is accelerating at a blistering pace.”2
Other research suggests that 94% of leaders identify AI as the most significant driver of cybersecurity change, while 87% identify AI-related vulnerabilities as the fastest-growing cyber risk.3 Together, these findings reinforce the need for a more integrated governance approach that aligns AI assurance more closely with cybersecurity, operational technology, and critical-infrastructure oversight.
Cybersecurity stands out as one of the few resilience priorities where the path from risk recognition to government action is already visible. Government respondents rank strengthening cybersecurity and incident response as their top critical infrastructure priority over the next three years (figure 2).
Additionally, public and commercial infrastructure leaders are broadly aligned in prioritizing increased cybersecurity investments. Globally, 84% of respondents rate cybersecurity as a leading area for expected increases in government investment, with particularly strong momentum from private-sector respondents (figure 3).
Cyber resilience cannot be built asset by asset or agency by agency. Since disruptions increasingly cascade across interconnected systems and institutional boundaries, governments should adopt an ecosystem resilience approach built on shared capabilities and coordinated governance. This requires a whole-of-government approach in which governments take the lead in providing support to entities outside their jurisdictions. The key principle is to strengthen and protect each node in the ecosystem, especially the ones that lack the resources and know-how to build independent cyber resilience.
Texas illustrates what an ecosystem resilience approach can look like in practice. In 2022, the Texas Department of Information Resources partnered with Angelo State University to establish the first regional security operations center to provide cybersecurity services to local governments. The center, housed on campus and staffed in part with students, provides 24/7 monitoring of servers, systems, and network traffic for local governments, identifying threats in real time.4
In 2025, the state established the Texas Cyber Command to act as the state’s cybersecurity hub to receive cyber incident reports, conduct digital forensics, develop threat intelligence, and support workforce training.5 Together, these efforts extend cyber support beyond state agencies to local governments, public institutions, critical sectors, and the broader cybersecurity workforce.6
But cyber is the exception. Across other resilience domains, particularly physical and extreme weather preparedness, the story is quite different.
Physical resilience, especially protection against natural disasters and extreme weather events, is widely acknowledged as the top risk to critical infrastructure (figure 4). Yet investment in extreme weather resilience and disaster preparedness continues to lag (figure 5).
The cost of that implementation gap is becoming increasingly difficult to ignore. Deloitte modeling estimates that average annual direct losses to infrastructure from natural disasters could reach US$460 billion globally by 2050.7 When indirect economic disruption, cascading losses, and ecosystem impacts are included, current annual disaster costs already exceed US$2.3 trillion.8
Several structural factors help explain why investments have not kept pace with risk. Cybersecurity investments are often more targeted, fit within shorter technology-refresh cycles, have clearer organizational ownership, and are reinforced by regulatory requirements and the immediate visibility of cyber incidents. They also align with broader technology modernization efforts.
Extreme weather resilience investments, by contrast, are capital-intensive, asset-specific, and long-term. They also compete with more immediate funding priorities. As a result, many governments continue to underinvest in this area despite recognizing it as a growing threat.
Closing that gap is ultimately a governance challenge as much as an engineering or financial one. Digital capabilities can support that effort by anticipating cascading effects during extreme weather events, making digital resilience an important enabler of physical resilience. For example, Broward County Metropolitan Planning Organization, Florida, is developing a digital twin platform that integrates data from different infrastructure assets to support predictive planning and cross-municipal coordination.9 The platform illustrates how digital capabilities can directly strengthen physical and extreme weather resilience by turning fragmented local data into shared, actionable intelligence.
Whether the threat is a ransomware attack or a coastal storm, the consequences cascade across the same interconnected system. Treating physical and digital resilience as separate agendas is no longer a viable strategy.
The survey suggests a clear inflection point in how governments approach infrastructure resilience. Cybersecurity shows what becomes possible when risk recognition translates into investment and action, while extreme weather resilience highlights the harder challenge: turning awareness into investments.
Closing that gap will require more than funding. It will also require governance and appraisal frameworks that recognize the full value of resilience.10
The more fundamental shift is that physical and digital resilience are converging.11 The digital capabilities governments are building to defend against cyberattacks can also make physical infrastructure more adaptable and recoverable during extreme weather events.
The next phase of infrastructure resilience will require an integrated approach—one focused not just on protecting individual assets, but on ensuring critical services continue when disruptions cascade across connected systems.