1 · Concept overview
Infrastructure resilience is the proposition that a system can be built to fail gracefully: to lose capacity roughly in proportion to the damage done to it, to keep the loss local rather than let it propagate, and to come back quickly. It is not reliability, which counts how often a system fails. It is not robustness, which asks how much force it takes to break. Resilience is a claim about the shape of the failure and the speed of the recovery, and it is therefore a claim about a distribution that somebody has to have measured.
The field has three limbs and they are in radically different condition. Established The theory of cascading failure in coupled networks is fifteen years old, mathematically elegant, and produces closed-form thresholds. Frontier The empirical event record is thin, dominated by after-action reports written by the operators being assessed, and has only in the last three years acquired an observable independent of them. Established And the restoration literature — where the money, the crews and the misery actually are — optimises restoration in great technical detail without ever measuring it.
Scope boundary. Megaproject Governance owns cost-forecast pathology and the outturn-database tradition; this brief borrows its method and does not restate its findings. Energy Corridors owns the transmission asset itself, including the fact that interconnectors are increasingly sold on resilience grounds. Civilization Resilience Planning owns the tail beyond system failure. This brief owns the middle question: whether “resilience” names a measurable property of a system, and if so, of what.
A sourcing note that governs everything below. Established The research behind this brief ran without web search, against a citation index in which Elsevier and IEEE deposit no abstracts. Roughly half the power-systems literature cited here is therefore verified as a record — title, authors, venue, year, DOI confirmed — with the text unread. Where that is the case this brief cites the paper's existence and subject and prints no number from it. The reading list marks which is which.
2 · Current scientific position
Established Start with what the word is supposed to name. The vocabulary of the field comes from Rinaldi, Peerenboom and Kelly in IEEE Control Systems 21:11 (2001), which set out the classes of interdependency between critical infrastructures and the dimensions along which they should be analysed. Speculative The four-way typology that paper is universally quoted for is not printed in this brief: IEEE deposits no abstract to the citation index, the record lookup returned metadata without even an author list, and the terms could not be confirmed against the primary. Frontier That is a small thing and it is also characteristic. The founding vocabulary of a field that governs trillions of dollars of assets is, in practice, quoted from secondary sources by nearly everyone who uses it. Established The field is now consolidated enough to have a review of record — Tong, Li, Nasirzadeh, Yao and Ji in the International Journal of Critical Infrastructure Protection (2025) — which is usually the moment a field becomes ready to be audited rather than reviewed again.
Established The coupled-network result created the field and is the reason anyone thinks cascade risk is computable. Buldyrev, Parshani, Paul, Stanley and Havlin, in Nature 464:1025 (2010), showed that two networks whose nodes depend on each other do not degrade the way a single network does. Frontier The result as it is universally understood is that interdependent networks undergo an abrupt, first-order percolation transition rather than the continuous one a single random network shows, which makes a coupled pair more fragile than either component alone. Speculative This brief verified the paper's bibliographic record and could not obtain its text or deposited abstract; the finding is real and famous, and the exact wording is not confirmed here, so the claim is stated as the field states it rather than as the paper states it. Established The lineage that follows is substantial and is verified as record: the network-of-networks generalisation (Gao et al., Nature Physics 8:40, 2012), targeted attack (Huang et al., Phys. Rev. E 83:065101, 2011), multiple support-dependence relations (Shao et al., Phys. Rev. E 83:036116, 2011), and — the one that matters most for real infrastructure — Li, Bashan, Buldyrev, Stanley and Havlin in Phys. Rev. Lett. 108:228702 (2012), whose title states the result: the length of the dependency links is critical.
Established The paper most often cited as the foundation of that programme is in fact a demurral from it, and this is the single most important thing to know about the literature. Hines, Cotilla-Sanchez and Blumsack asked, in the title of Chaos 20:033122 (2010), “Do topological models provide good information about electricity infrastructure vulnerability?” The deposited abstract reads, verbatim: “In order to identify the extent to which results from topological graph models are useful for modeling vulnerability in electricity infrastructure, we measure the susceptibility of power networks to random failures and directed attacks using three measures of vulnerability: characteristic path lengths, connectivity loss, and blackout sizes.” Established They tested 40 Eastern US power grid areas. Established Directed attacks caused larger failures than random ones on all three measures. Established And, critically, the topological metrics correlated only mildly with physics-based power-grid models. Frontier The answer to the title question is substantially “not very,” and the paper is nonetheless routinely enrolled as a founding citation for the complex-networks grid-vulnerability programme whose central move it questions. Established The authorship is consistent about this: Paul Hines is also among the twenty-one authors of the PNAS rebuttal to the 100%-renewables reliability claim (Clack et al., PNAS 114:6722, 2017), which turns on the same preference for physical models over convenient abstractions.
Frontier What follows from that is a discipline on how the network-science literature may be used, and this brief applies it throughout. Percolation results on coupled networks are results about coupled networks. They are not, without further argument, results about grids, and the further argument — that graph topology proxies for grid behaviour — has been tested once, at scale, and came back weak. Speculative That does not make the theory wrong. It makes it a theory in search of a validated mapping, which is a different and more interesting position than either its advocates or its dismissers usually grant. Handwave It also means that every published statement of the form “this grid is vulnerable because its degree distribution is heavy-tailed” is carrying an unvalidated inference in the middle of it.
Established The empirical event record is where this brief is thinnest, and the thinness is a finding about the field rather than about this brief. The best-instrumented single event available is Winter Storm Uri, Texas, February 2021. Melaku, Fares and Awal (Sustainability 15:4173, 2023) record the record cold of 14–17 February 2021, average freezing temperatures of 0 to -19 °C with severe levels of -17 to -19 °C in the Texas High Plains, and air-quality indices exceeding the EPA standard in 51.7%, 61.7%, 50.8% and 60% of cases in the Dallas–Fort Worth, Houston–Galveston, Austin and Lubbock regions respectively. Established The datum that matters most for this brief is a count: the event triggered 322 boil-water notices. That is a power failure propagating into a water system, at scale, in a documented event, with a number attached — and it is the single best-verified instance of infrastructure interdependency anywhere in this brief's evidence base.
Established Against that one count, this brief has no verified figure for any other major blackout, and says so rather than reaching for the familiar ones. The North American blackout of August 2003, the Indian blackouts of July 2012, the Argentina–Uruguay event of 2019 and the Iberian event of 2025 are all real, all consequential, and none of their headline quantities — people affected, megawatts lost, hours to restoration — could be verified from a primary source in the research behind this brief. Established No customer-hours figure for any event appears anywhere in this brief's evidence base. Frontier That is not a small housekeeping caveat. Customer-hours is the natural unit of an outage; a field whose central quantity is not routinely retrievable from primary sources, for its most famous events, is a field without an error signal. The literature on the 2003 cascade exists and is verified as record — Chadwick's retrospective at IEEE PECI 2013 asks what a smarter grid would have prevented — but its numbers are not stated here.
Established The most important methodological development in the topic is that outage extent became observable from orbit. Shah, Carvallo, Hsu and Taneja (Environmental Research: Infrastructure and Sustainability 3:025011, 2023) used satellite nighttime lights at census-block-group resolution to reconstruct who lost power during Uri. Established Their results: minority census block groups were 1.5 to 3 times more likely to suffer interruptions than predominantly white ones; income status was positively correlated with the likelihood of interruption; and proximity to critical facilities reduced outage likelihood by approximately 16%. Established Kahl, Tran and Bhaduri, in a 2024 preprint, fit maximum-entropy models to Houston over 11–18 February 2021 and found power-line density the most influential variable at 73.0% contribution, ahead of tree coverage at 7.1% and school proximity at 5.2%, with a mean AUC of 0.758. Frontier The significance is not the equity finding, striking as it is. It is that outage extent is now measurable without the cooperation of the entity being assessed, at fine spatial resolution, from a public data product. Every previous resilience claim was audited, if at all, against numbers supplied by its subject.
Established And then there is the hole. The restoration literature located for this brief is entirely optimisation. Almoghathawi, Barker and Albert give a resilience-driven restoration model for interdependent networks (Reliability Engineering & System Safety, 2019); Almoghathawi extends it to restoration under uncertainty (2025); Fang's doctoral work builds hierarchical simulation and optimisation frameworks for cascading-failure mitigation (2015). Established All three ask what an optimal restoration sequence would be, given an assumed endowment of crews, spares, transport and mutual aid. Established None of them measures how long restoration actually takes. Frontier No empirical time-to-restore distribution — by event class, by damage class, by utility — could be located in anything retrievable for this brief. Speculative A quantity with an elaborate optimisation theory and no measured distribution is a modelling object, not a measurand, and the resource endowment that every one of these models takes as exogenous is the variable that plausibly does most of the work. Frontier Note what this does to the three strategies a system owner can actually buy. Hardening lowers the probability of damage; redundancy preserves capacity after damage; rapid restoration shortens the tail. Established Only the first two have any measured basis at all in this literature, and the third — which is where crews, spares and mutual aid live, and which is what a household actually experiences — is the one with no outturn data whatsoever. Speculative A field that cannot measure its third lever will systematically under-invest in it, and will not know that it has.
3 · Frontier questions
Frontier The live question is whether cascade risk is bounded and computable, and the two branches are both serious. The optimistic branch is that coupled-network percolation gives closed-form critical thresholds, so if real infrastructure falls in the model class, cascade risk has a computable bound. Frontier The pessimistic branch is Hines et al.: if the abstraction that makes the bound computable is the abstraction that makes it wrong, the bound is decorative. Speculative Nobody has adjudicated this, because adjudicating it requires an out-of-sample test — a model calibrated before an event that predicts that event's observed extent, scored against a naive baseline — and until the satellite observable arrived there was no independent extent to score against. Frontier That test is now possible and has not been run. It is the highest-value unrun study in this subject.
Speculative A second frontier question is whether the real cascade channel is geographic rather than topological. The hypothesis is that most actual interdependency is not logical coupling between abstract networks but a substation, a duct bank, a bridge crossing and a fibre route sharing a right of way. Frontier Three pieces of evidence point that way: Li et al.'s finding that dependency-link length is the controlling parameter, since short dependency links are geographic ones; Kahl et al.'s finding that a spatial infrastructure-stock variable dominates vulnerability at 73.0%; and Uri's power-to-water propagation, which was physical and local. Frontier Against it: cyber coupling is genuinely non-local and growing, and the literature on it is expanding fast — Chen and Chen on cyber system failure as a cascade channel (2018), Zhou, Li and Lu's dual-layer cascade model in IEEE Transactions on Smart Grid (2026). Speculative The discriminating test is cheap: run a spatial co-location index head to head against topological centrality on the satellite observable and see which predicts better. Handwave If spatial wins, a large and mathematically sophisticated modelling literature has been aimed at the wrong object for fifteen years.
Speculative Third: resilience and efficiency may not be a trade-off at all. The standard framing is a smooth curve on which redundancy is bought with efficiency, and a planner picks a point. Speculative The coupled-network result suggests something else — that below a coupling threshold, tighter coupling improves both, and above it both collapse together, so there is no curve to sit on, only a cliff to locate. Frontier Against that, real systems have operators, load shedding and islanding, all of which smooth transitions that are sharp in the model; this is the Hines objection generalised. Frontier The adjudicating evidence would be empirical event-size distributions showing bimodality or a gap rather than a smooth heavy tail. Established That is precisely the blackout-size power-law and self-organised-criticality literature associated with Dobson, Carreras and Newman, and it could not be retrieved for this brief at all. Its absence here is declared, not concealed, and it is the most significant single hole in this brief's coverage.
Frontier Fourth: whether N-1 is even the right reliability object. Deterministic N-1 planning guarantees survival of any single contingency. Speculative Large events are not single contingencies; they are correlated common-cause events, which is what Uri was — one temperature field hitting generation, gas supply, water treatment and demand simultaneously. Speculative On this reading the standard is not weakly calibrated, it is measuring a different thing, and compliance with it carries no information about the failure mode that actually occurs. Frontier The defence is that N-1 is a design floor rather than a risk estimate and that probabilistic supplements exist. Speculative Settling it requires showing that historical large events are dominated by common-cause correlation rather than independent coincidence — adjudicable from event catalogues, and not adjudicated here.
Frontier Two developments are consolidating faster than the disputes. Demand-side hardening has become a serious lever: Skiles, Shih, Rhodes and Webber assess building-sector retrofits as a way of mitigating the ERCOT shortfall itself (Energy and Buildings, 2025), which reframes hardening from a network problem into a building-stock problem. Frontier And power–water is now the best-instrumented interdependent pair, with an optimisation literature (Tiong and Vergara, 2023) and, in the 322 boil-water notices, something close to an empirical validation case. Established Both are cases of the same underlying move: the interesting couplings are being found by looking at particular real systems rather than by generalising the abstract model, and the particular systems keep turning out to be coupled through physical proximity and shared services rather than through anything a graph would call an edge.
4 · Technological bottlenecks
Established The binding bottleneck is not mathematical. Nobody has written down what depends on what. Every interdependency study in this brief's evidence base assumes a dependency graph it did not observe. No jurisdiction has published an audited inventory of which substations feed which pumping stations, which fibre routes share which duct banks, which gas compressors need which feeders. Frontier The obstacle is institutional with a security overlay: owners will not share it, and where they would, disclosure is restricted. There is no scientific difficulty in the task whatsoever. Speculative Until it exists, interdependency analysis is a formalism applied to a guess, and no study located here reports how much its conclusions move when the guessed graph is perturbed.
Established The second bottleneck used to be that an outage could not be seen without asking the operator, and it has just been removed. Nighttime-lights outage detection at census-block-group resolution, validated with a reported AUC of 0.758, is the one piece of unambiguously good news in this subject and it arrived in the last three years. Everything downstream of an independent event observable is now possible for the first time.
Frontier The third bottleneck is the one this brief thinks is most binding in practice, and it is embarrassingly cheap to clear: nobody has published the time-to-restore distribution. The data exists. It sits in utility outage-management systems, in mutual-aid dispatch records, in the crew and spares logs of every operator in the developed world. Established What does not exist is a published distribution of restoration times by event class and damage class with the resource endowment as a covariate. Frontier This is the same structural absence that Megaproject Governance spent thirty years filling for construction costs, and the parallel is exact and instructive: that field acquired an error signal at the moment somebody published outturns against forecasts, and every subsequent argument in it — whether reforms work, whether the tails are fat, whether bias is error or incentive — became decidable because the distribution was on the table. Speculative Resilience has no such moment yet. It has an optimisation theory, a vocabulary, an investment case and no outturn distribution.
Frontier The fourth is scientific and is the only genuine unknown here. Percolation theory gives closed forms because it abstracts; physical simulation gives realism because it simulates; nobody has a cascade bound that is both — derived under a physical failure rule (power flow, protection operation, operator action) with stated conditions of validity. Speculative That is the real research frontier, and it is a long way behind the other three, all of which are institutional and none of which requires a discovery.
5 · Research dependencies
Established This brief depends on Energy Corridors, and the dependency has become sharper rather than looser over the last decade. Interconnectors are now routinely justified on resilience grounds rather than on economic dispatch alone; the COBRAcable design paper was presented at a conference called Resilience of Transmission and Distribution Networks. Frontier That justification cannot currently be audited, because resilience benefit has no measurand and because — as FR-VII-14 records — no per-project capital cost, route length or cost-per-GW-km figure could be assembled for any flagship HVDC link. Speculative A benefit nobody can measure, set against a cost nobody has published, is not an appraisal. It is a position.
Established The second dependency is methodological rather than physical, and it runs to Megaproject Governance. Frontier That brief owns the outturn-database tradition: the discipline of collecting what actually happened against what was forecast, publishing the distribution, and letting the distribution settle arguments. Established It also owns the one finding this brief borrows directly — Odeck, Welde and Volden's Norwegian result that external quality assurance “has led to a reduction in cost overruns” but “has not, however, led to improved accuracy” — because it separates an intervention changing an outcome from an intervention changing what is known, and resilience investment is currently claimed to do both while demonstrating neither. Frontier The third dependency runs the other way, to Civilization Resilience Planning, which inherits from here the assumption that infrastructure degrades gracefully — an assumption this brief cannot supply.
Established Two non-brief dependencies are worth naming even though they are not on this map. The first is a public satellite nighttime-lights product maintained as an operational service rather than as a research dataset, because an observable that exists only while a research group is funded is not an audit instrument. Frontier The second is asset geodata: the spatial-versus-topological experiment cannot be run without knowing where the assets physically are, and that is held by the same owners who hold the dependency graph, under the same restrictions. Speculative Neither is a scientific dependency. Both are the kind of thing a jurisdiction could decide to provide in a single budget cycle if it wanted the answer.
6 · Required experiments
Established Experiment one, and the one this brief would run first: publish the time-to-restore distribution. Take one regulator's jurisdiction and one decade. For every outage above a threshold, record time to restore, damage class, event class, and the resource endowment brought to bear — crews mobilised, spares drawn, mutual-aid agreements invoked. Publish the distribution. Frontier The decisive analysis is a variance decomposition: does time-to-restore vary more across events with similar physical damage than physical damage itself varies? Speculative If it does, restoration capacity rather than failure probability is the binding resilience variable, and a large fraction of hardening expenditure is aimed at the wrong term. Established The cost of this study is a data-sharing agreement and an analyst. Nobody has done it.
Frontier Experiment two: score the cascade models out of sample. Take models calibrated before a known event, predict the observed outage extent from the satellite product, and compare the skill score against a naive spatial-persistence baseline. Speculative If cascade models have no out-of-sample skill, the bounded-risk target is not merely unachieved but unapproached, and the field should be told so in a number.
Speculative Experiment three: spatial versus topological, head to head. Build a co-location index from asset geodata and race it against every standard topological centrality measure on the same observable. Frontier Cheap, decisive, and capable of redirecting a large modelling literature in one paper.
Frontier Experiment four is a reporting standard rather than a study, and it is free. Require every interdependency paper to report conclusion stability under plausible perturbation of the assumed dependency graph. Speculative It would immediately reveal how much of the literature is graph-assumption-driven, which is the question nobody in it currently has to answer. Speculative Experiment five tests the equity mechanism: if hardening is regressive because protection follows circuits containing critical facilities while residential circuits are the shed resource, that is a feeder-level claim and feeder-level data can settle it.
Frontier Which one is binding. Experiment one is binding, and it is binding for a reason worth stating explicitly: the other four are all downstream of having an outturn to compare against. Speculative Out-of-sample scoring needs an observed outcome; the spatial-versus-topological race needs an observed outcome; the sensitivity standard needs somebody to care what the conclusions were wrong about. Established An outturn distribution is the thing that makes a field's arguments decidable, and this one does not have it. Handwave The counter-argument — that restoration times are too heterogeneous across event classes to pool usefully — is exactly the argument that was made against pooling construction cost outturns, and it was answered by pooling them and looking.
7 · Engineering requirements
Established The engineering requirements divide cleanly into three strategies with genuinely different economics, and the literature does not compare them. Hardening buys a lower probability of damage per unit of hazard: winterised generation, buried cable, flood walls, freeze-protected pipe. Established Redundancy buys survivable capacity after damage: N-1 margins, second feeds, black-start units, spare transformers. Frontier Rapid restoration buys a shorter tail: crews, spares depots, mutual-aid compacts, pre-staged transport, switching automation. Speculative Their cost curves are unrelated to each other — hardening scales with exposed asset count, redundancy with peak load, restoration with crew-hours and logistics — and no source located for this brief compares their cost-effectiveness on a common outcome. That comparison is the central engineering question in the subject and it is unanswered.
Established Two concrete hardening parameters are worth stating because concrete parameters are rare here. Speculative Williams and colleagues, modelling an abrupt sunlight-reduction scenario, put peak freeze depths above 30 m and the exposed buried-water stock at 5.4 to 8.8 million km of pipes serving over 2 billion people — a quantified burial-depth specification for an extreme case, and one of very few numbers in this subject that an engineer could design against. Frontier And demand-side retrofit is now a supply-side instrument: reducing peak demand in the building stock relieves the same shortfall that generation hardening addresses, at a different point in the system and on a different balance sheet.
Established Frontier Two data classes that any serious restoration engineering requires are absent from this brief's evidence base and should be named: black-start capability inventories and large-transformer lead times. The second is the standard argument for why prevention dominates restoration at the high-consequence end — nothing restores a system that has lost long-lead-time transformers — and this brief cannot supply the lead time that argument depends on. Speculative That argument is probably right at the extreme and it is also the argument most convenient to a hardening budget, which is a reason to want the number rather than the assertion.
8 · Adjacent technologies
Established The closest adjacency is remote sensing, and it is the one that changed the subject. Nighttime-lights radiometry was built for urbanisation and economic-activity research; it turned out to be an outage instrument, and it is now the only externally-observed measurement of a resilience outcome that exists. Frontier Statistical physics supplies the percolation machinery and the coupled-network results; reliability engineering supplies the indices and the N-1 tradition; operations research supplies the restoration optimisation; and cyber-physical security supplies the fastest-growing cascade channel. Established Water engineering deserves separate mention rather than absorption into “infrastructure”: the boil-water notice is the single best-instrumented interdependency outcome available, and it exists because water regulators require a public notification that electricity regulators have no equivalent of. Speculative A field that wants a countable outcome could do worse than to ask why one sector already has one.
Established On this map the subject recurs wherever a system is coupled to another one. Energy Corridors is the load-bearing neighbour and the formal dependency. Frontier Smart Cities matters here in a specific and unflattering way: instrumenting infrastructure adds a cyber dependency layer to systems that previously failed only physically, and the resilience case for sensing has to be net of the fragility that sensing introduces. Established Autonomous Supply Chains owns the logistics substrate that restoration capacity actually runs on — spares, crews, transport — which is exactly the endowment the restoration models take as given. Frontier Circular Infrastructure Systems shares the material-stock question: what is buried, where, and how long it lasts. Speculative And Civilization Resilience Planning takes over at the point where restoration does not happen, which is the failure mode this brief's models are least equipped to describe. Frontier The seam with Megaproject Governance is not adjacency but method: that brief owns the technique this one needs, and the cross-link is worth making in both directions, because a reader who arrives here wanting to know whether resilience spending works is being sent there to see what an answerable version of that question looks like.
9 · Institutional requirements
Established Three of the four bottlenecks in this subject are institutional, and one of them is a disclosure problem with a security overlay. The dependency inventory is the case. It requires no discovery and no invention; it requires asset owners across electricity, water, telecoms and fuel to enumerate, in a shared schema, what depends on what, and to submit that enumeration to audit. Frontier They will not, for three reasons that are all defensible in isolation: it is commercially sensitive, it is a target list, and it would make cross-owner comparison — and therefore blame — possible. Speculative The third reason is the real one, and it is the same mechanism that Nilsson identified in infrastructure appraisal when he found that institutional frameworks prevent meaningful learning from previous projects' implementation experience. An arrangement that prevents learning is not always failing; sometimes it is succeeding at its actual job.
Frontier The restoration distribution is a lighter institutional ask and it is the one worth making. It needs one regulator to require, in the outage reporting operators already file, three additional fields: damage class, resources mobilised, and time to restore by feeder. Established None of that is commercially sensitive in the way a dependency graph is, none of it is a target list, and the reporting infrastructure already exists. Speculative The reason it has not happened is not that anyone has refused; it is that no one has asked, because the field's investment case has never required an outturn to be shown.
Frontier The uncomfortable part, stated plainly. Resilience expenditure is currently justified by model outputs whose out-of-sample skill has never been scored, and it is recovered through regulated rates. Speculative Publishing an outturn distribution would make some of that expenditure look ineffective, and the actors best placed to publish it are the actors whose expenditure it would judge. Handwave That is the same asymmetry that kept construction-cost outturns unpublished for decades, and it broke there when an outside academic group published them anyway. Speculative The institutional lesson is therefore not that regulators should be persuaded but that the first distribution will probably be published by somebody with no stake in the answer, from data obtained under freedom-of-information rules, and that the field should be ready to treat it as authoritative when it appears rather than litigating its provenance.
10 · Ethical & societal considerations
Established Outage incidence is not distributed evenly, and the best evidence on this is more complicated than its citations. Shah and colleagues found minority census block groups 1.5 to 3 times more likely to be interrupted during Uri, and proximity to critical facilities reducing outage likelihood by about 16%. Established They also found income positively correlated with the likelihood of interruption. Frontier Race and income point in opposite directions in the same dataset, and a brief that cites this paper for a simple “the poor lost power” story is misreading it. Speculative The reading the data will support is narrower and sharper: protection appears to follow circuits, and circuits containing critical facilities are protected, which is a defensible engineering rule with an indefensible incidence when the shed resource is residential and the residential population is not randomly distributed.
Frontier Load shedding is rationing, and it is currently designed by circuit topology rather than by any stated principle of fairness. The people who lose supply in a shortfall are selected by which feeder they happen to sit on, a fact of nineteenth- and twentieth-century construction history. Speculative Making that allocation explicit — publishing shed order, and defending it — is technically straightforward and politically unattractive, which is a reliable signature of a decision currently being made by default.
Speculative And the new observable has its own ethics. Satellite outage detection at census-block-group resolution measures households, not utilities. It was built to hold operators to account and it works by watching people's lights. Frontier The accountability gain is real and this brief argues for it. Handwave The corresponding claim — that a public product resolving domestic electricity use to the block-group level is unproblematic because the intent is regulatory — is exactly the claim that surveillance infrastructures have always made about themselves, and it deserves the scrutiny it has not yet had.
11 · Civilizational implications
Established Interdependency is increasing and nobody is measuring the rate. Electricity, water, telecoms and fuel were loosely coupled a century ago and are now tightly coupled in both directions: water treatment needs power, gas compression needs power, power needs gas and needs communications, and every one of those couplings has been added by an optimisation that was locally correct. Frontier Uri is the demonstration — one temperature field, four sectors, 322 boil-water notices. Speculative If the coupled-network intuition is even directionally right, the civilisational consequence is that the efficiency gains of the last fifty years have been partly purchased with an unpriced increase in the abruptness of failure.
Speculative The optimistic case is genuinely available and it costs almost nothing. Nothing in the workback chain for this subject requires an invention. An audited dependency inventory, a published restoration distribution and an out-of-sample scoring convention are three institutional acts, and together they would convert resilience from a rhetorical claim into an auditable one within a decade. Handwave That is a rare shape on this map: a large civilisational gain available from bookkeeping rather than from discovery. Speculative The pessimistic reading of the same fact is that a gain this cheap and this long unclaimed is probably being prevented by something, and the something is that the measurement would embarrass its funders.
Speculative At the far end, the question stops being about grids. Williams and colleagues' sunlight-reduction scenario — freeze depths above 30 m against 5.4 to 8.8 million km of buried water pipe serving over 2 billion people — is a case where hardening, redundancy and restoration all fail simultaneously and for the same reason, because the hazard exceeds the design envelope of the whole stock at once. Handwave Whether that is a resilience problem or a different subject entirely is a real question. This brief's answer is that it is the same subject read at a different scale, and that the honest version of a graceful-failure claim has to state the envelope outside which it does not apply — which almost no resilience claim currently does.
12 · Timelines
These horizons track measurement and disclosure rather than capability. Nothing in the first two rows awaits an invention, which is unusual on this map and is the reason the near horizons are stated with more confidence than the far ones.
- 10 yr: Frontier satellite outage products become a routine regulatory input rather than a research curiosity, and the first empirical time-to-restore distributions are published for at least one national jurisdiction, most likely by an academic group working from mandatory outage reports rather than by an operator. Speculative Cascade models get their first out-of-sample scoring against an observed event; the scores come in worse than their authors expect, and the field discovers that it has been calibrating rather than predicting. Frontier Demand-side hardening becomes a standard line in resilience appraisal, because it is the one lever with a cost curve anybody can compute.
- 25 yr: Speculative an audited cross-sector dependency inventory exists for at least one metropolitan region, and it exists because an event made withholding it untenable rather than because anyone was persuaded. Speculative Resilience investment appraisal acquires an outturn base, and a measurable fraction of past hardening expenditure is retrospectively shown to have had no detectable effect on outage extent or duration. Handwave Expect that finding to be contested on the grounds that the counterfactual is unobservable, which is true, and to be contested most loudly by the parties whose expenditure it judges, which is also predictable.
- 50 yr: Speculative a cascade bound derived under a physical failure rule, with stated conditions of validity, if the seam between percolation abstraction and physical simulation is ever closed. Handwave The alternative is that the seam is not closed and the field settles permanently into simulation without bounds — which is where numerical weather prediction sat for its first several decades, and which is not a disgrace so long as the simulations are scored.
- 100 / 250+ yr: Handwave no basis for forecasting the institutional arrangements, and this brief declines to invent one. Speculative The single durable observation available is that coupling between sectors has increased for as long as there are records, that every increment was locally rational, and that no mechanism currently exists by which a society would decide to decouple deliberately rather than have decoupling forced on it.
13 · Technology tree & dependencies
- Depends on Four things, of which only one exists. An externally-observed measure of outage extent and duration, independent of the operator being assessed: this arrived from orbit in 2023 and is the one link in the chain that solved itself. An audited cross-sector dependency inventory for at least one region, enumerating which substations feed which pumping stations and which fibre routes share which duct banks: this exists nowhere, is blocked institutionally rather than scientifically, and everything downstream is conditioned on it. A published empirical distribution of time-to-restore by event and damage class, with the resource endowment as a covariate: the data sits in operator records and nobody has published it. And, from Energy Corridors, the transmission asset whose resilience benefit this brief has to learn to price. That corridor dependency is load-bearing rather than decorative: interconnectors are now sold on resilience grounds, FR-VII-14 records that no per-project capital cost or cost-per-GW-km figure is publicly assembled for any flagship link, and an unmeasurable benefit set against an unpublished cost is a position rather than an appraisal.
- Enables Every downstream claim in this category that assumes infrastructure degrades gracefully rather than abruptly — which includes most corridor resilience cases, most smart-city sensing cases, and the whole inherited premise of Civilization Resilience Planning, whose recovery arguments start where this brief's models stop. It also enables something narrower and more immediately useful: the auditability of resilience-justified capital expenditure, which is at present justified by model output whose out-of-sample skill has never been scored and recovered through regulated rates. An outturn distribution would make that expenditure assessable for the first time. And one more, easily missed: a scoring convention for cascade models would let the modelling literature tell its own good work from its bad, which no amount of further model development can do on its own.
- Adjacent Statistical physics and percolation theory, which supply the cascade machinery; reliability engineering and the N-1 tradition, which supply the standards actually enforced; operations research, which supplies the restoration optimisation; cyber-physical security, which supplies the one genuinely non-local coupling channel; nighttime-lights remote sensing, which supplies the observable that changed the subject; water-system regulation, which already has a countable interdependency outcome in the boil-water notice; and the outturn-database method developed in Megaproject Governance, which is the single most transferable thing this subject could borrow and has not.
14 · Common misconceptions & speculative claims
Established “Network science shows power grids are vulnerable to targeted attack.” The paper most often invoked is Hines, Cotilla-Sanchez and Blumsack (2010), and it does find directed attacks worse than random on all three of its vulnerability measures. Established It also finds that topological metrics correlate only mildly with physics-based grid models across 40 Eastern US areas, which is the paper's actual conclusion and the reason its title is a question. Frontier The directed-attack result sits inside a paper arguing that the measures producing it are weakly informative. Quote both limbs or neither. Speculative That a demurral has been enrolled as a foundation for the programme it demurs from is not a trivial citation error; it is the mechanism by which a whole literature acquired a validation it was never given.
Frontier “Resilience is a measurable property of a system.” This one is the enthusiasts' overclaim and it needs splitting. Established Resilience is now genuinely measurable ex post, for events that happened, in extent and duration, from orbit, at census-block-group resolution. Frontier It is not demonstrated as an ex ante property of a system. Speculative Any claim that an investment “increased resilience by X%” is a model output unless it comes with an out-of-sample prediction that was scored against an observed event, and no such scoring exists in this subject. Frontier The honest position, and the one this brief holds: measurable after the fact, not yet measurable in advance — which is a real distinction and not a hedge, because it says exactly which studies would close the gap.
Established “Uri showed that the poor lost power.” Shah et al. report both that minority census block groups were 1.5 to 3 times more likely to be interrupted and that income was positively correlated with the likelihood of interruption. Established Race and income diverge in the same dataset. Frontier Quoting one limb is a misrepresentation of the source, and the counter-intuitive limb is the one that gets dropped.
Established “The 2003 blackout affected 50 million people.” Plausibly correct, and not verified here. Established The same applies to the widely quoted load-loss figure for that event, to the 2012 Indian blackouts, to Argentina–Uruguay in 2019 and to Iberia in 2025. Frontier This brief's evidence base contains no verified blackout customer count, no load-loss figure and no customer-hours figure for any event other than the Texas 2021 indicators it does state. Speculative The interesting question is not why this brief lacks them but why they were not straightforwardly retrievable from primary sources for the most-cited events in the field's history. A discipline whose canonical numbers live mainly in secondary citation is a discipline that cannot check itself.
Frontier “Interdependency analysis tells us where the fragilities are.” It tells you where the fragilities are in the dependency graph you supplied. Established No study located for this brief supplies an audited graph, and none reports how far its conclusions move when the assumed graph is perturbed. Speculative Sensitivity to the graph assumption should be a reporting requirement, and the fact that it is not is the strongest available evidence for the sceptical view that the analysis is unfalsifiable as currently practised.
Frontier “Redundancy buys resilience.” The characteristic result of coupled-network theory is an abrupt transition, which implies that added redundancy may buy nothing at all until a threshold and everything at it. Speculative Whether real systems behave that way is contested precisely because of the topological-versus-physical problem above. Frontier “Hardening the grid is the answer” is the adjacent error: the most-quantified vulnerability variable in the best-instrumented event was power-line density, a stock characteristic, and demand-side retrofit has its own literature as a shortfall-mitigation instrument. Established Supply-side hardening is one of at least three levers and no source located here compares their cost-effectiveness. Established “N-1 compliance means the system is reliable” confuses a single-contingency design floor with a risk estimate for correlated common-cause events, which is what every large blackout actually is.
Established “We know how long restoration takes.” We do not, and this is the brief's most important finding. The restoration literature is optimisation, not measurement. Established No empirical time-to-restore distribution could be located in anything retrievable for this brief. Frontier That absence is why resilience has an elaborate theory and no error signal. Speculative Every field on this site that got better got better when somebody published an outturn distribution — which is the entire subject of the sibling brief Megaproject Governance, and the reason this brief points at it so insistently. Handwave The strongest statement of the sceptical position is that “resilience” is a word doing rhetorical work: unfalsifiable, therefore safe to promise, therefore promised. Frontier The strongest statement of the research-programme position is that the sceptic's case rested on unobservability, that unobservability ended in 2023, and that the remaining work is bookkeeping rather than philosophy. Speculative This brief judges the second position stronger and notes that it has been available for three years without anyone acting on it, which is itself evidence for the first.
Established A final misconception about the evidence itself, which this subject should take seriously. The research behind this brief ran against a bibliographic index in which Elsevier and IEEE deposit no abstracts — the two publishers that dominate power-systems engineering. Frontier That means the retrievability of a claim in this field is a function of its publisher, not of its quality, and any machine-assembled synthesis of infrastructure resilience will systematically over-weight what is easy to fetch. Speculative Independent research passes in this same programme caught their own citation tools silently substituting one document for another — returning unrelated papers for correctly addressed identifiers, with no error and no low-confidence signal. Handwave Infrastructure resilience is governed by exactly the kind of assessment report that is assembled that way, and nobody audits those reports' citations.