Critical Infrastructure: Who’s Responsible for Utilities & Banking?

Critical infrastructure forms the backbone of modern society, encompassing systems and assets so vital that their disruption could cripple a nation’s security, economy, public health, or safety. Among the most critical sectors are utilities (electricity, water, gas) and banking (financial services, payment systems). But who exactly is responsible for safeguarding these lifelines? Is it governments, private companies, or a mix of both?

The question has grown more urgent in recent years. Cyberattacks on critical infrastructure have intensified—the FBI’s Internet Crime Complaint Center (IC3) received over 3,600 ransomware complaints in 2025 alone, with losses exceeding $32 million. Meanwhile, shifting government policies and the emergence of new private-sector coalitions are reshaping how utilities and financial services coordinate their defenses.

This article breaks down the complex web of responsibility, exploring key stakeholders, regulatory frameworks, and the evolving challenges in protecting utilities and banking infrastructure.

Table of Contents#

  1. What is Critical Infrastructure?
  2. Key Sectors: Utilities & Banking – Why They Matter
  3. Who is Responsible? A Multi-Stakeholder Approach
  4. Governmental Bodies: Policy, Regulation, and Oversight
  5. Private Sector: Operations, Maintenance, and Resilience
  6. Collaborative Frameworks: Public-Private Partnerships (PPPs)
  7. Challenges in Ensuring Accountability
  8. Conclusion
  9. References

What is Critical Infrastructure?#

The term “critical infrastructure” is defined by the U.S. Department of Homeland Security (DHS) as “systems and assets, whether physical or virtual, so vital to the United States that the incapacity or destruction of such systems and assets would have a debilitating impact on security, national economic security, national public health or safety, or any combination of those matters.” This definition, formalized under Presidential Policy Directive 21 (PPD-21), identifies 16 critical infrastructure sectors, including energy, water, healthcare, transportation, and financial services.

In the EU, the Critical Entities Resilience (CER) Directive (2023) covers 11 sectors, including energy, transport, banking, financial market infrastructure, health, and drinking water.

For this article, we focus on two: utilities (energy, water, and gas) and financial services (banks, payment processors, and financial markets)—the sector officially renamed from “Banking and Finance” to “Financial Services” by PPD-21 in 2013.

Key Sectors: Utilities & Banking – Why They Matter#

Utilities: The Lifeline of Daily Life#

Utilities provide essential services that underpin modern society:

  • Electricity: Powers homes, businesses, hospitals, and critical systems like traffic lights and data centers. A blackout can halt commerce, disrupt healthcare, and compromise public safety.
  • Water: Clean water is vital for drinking, sanitation, and agriculture. Contamination or supply disruptions risk public health crises.
  • Gas: Used for heating, cooking, and industrial processes. Supply interruptions can leave communities without heat in winter or halt manufacturing.

Banking: The Engine of the Economy#

Banking and financial services ensure the flow of money, enabling transactions, investments, and economic stability:

  • Payment Systems: Credit/debit cards, mobile payments, and wire transfers keep businesses and consumers connected. A disruption could freeze salaries, halt retail sales, or delay government benefits.
  • Financial Markets: Stock exchanges, bond markets, and lending institutions drive economic growth. A cyberattack or system failure could trigger market crashes or bank runs.
  • Global Interconnectivity: Banks operate across borders, meaning a disruption in one country can ripple globally (e.g., the 2008 financial crisis).

Who is Responsible? A Multi-Stakeholder Approach#

Responsibility for critical infrastructure is not held by a single entity. Instead, it is a shared duty involving:

  • Governments: Set policies, enforce regulations, and coordinate national security responses.
  • Private Sector: Owns and operates most critical infrastructure (e.g., utility companies, banks) and manages day-to-day resilience.
  • International Organizations: Facilitate cross-border cooperation (e.g., the EU’s European Union Agency for Cybersecurity, ENISA, and the Financial Stability Board, FSB).
  • Local Communities: Play a role in reporting threats (e.g., suspicious activity near power grids) and preparing for disruptions.

Governmental Bodies: Policy, Regulation, and Oversight#

Governments establish legal frameworks to ensure critical infrastructure is protected. Here’s how key agencies operate in major economies:

United States#

  • Cybersecurity and Infrastructure Security Agency (CISA): Part of DHS, CISA serves as the National Coordinator for critical infrastructure security and resilience. It sets guidelines and coordinates with private sector partners. In 2024, National Security Memorandum-22 (NSM-22) updated national policy, directing CISA to develop the 2025 National Infrastructure Risk Management Plan. CISA released updated Cybersecurity Performance Goals 2.0 in December 2025. However, staffing reductions in 2025 have strained public-private coordination.
  • Federal Energy Regulatory Commission (FERC): Regulates electricity and gas utilities, enforcing reliability standards (e.g., mandatory cybersecurity protocols for power grids).
  • Office of the Comptroller of the Currency (OCC): Oversees national banks, ensuring they comply with anti-money laundering (AML) laws and cybersecurity regulations.
  • Federal Reserve (Fed): Manages payment systems (e.g., Fedwire) and monitors financial stability.
  • Department of the Treasury: Serves as the Sector Risk Management Agency (SRMA) for the financial services sector, coordinating with industry through the Financial Services Sector Coordinating Council (FSSCC), established in 2002.

European Union#

  • ENISA: The EU’s cybersecurity agency advises member states on protecting critical sectors. The NIS2 Directive (2022) broadened cybersecurity requirements across essential sectors including energy, banking, digital infrastructure, and health. The Critical Entities Resilience (CER) Directive (2023) requires member states to identify critical entities and carry out risk assessments by 2026.
  • European Banking Authority (EBA): Sets standards for banks, including stress tests and cybersecurity requirements.
  • National Regulators: Countries like Germany (Bundesnetzagentur for energy) or France (Autorité de Contrôle Prudentiel et de Résolution for banking) enforce EU rules locally.

Global Coordination#

Organizations like the International Energy Agency (IEA) and Financial Stability Board (FSB) promote global standards for energy and financial resilience. The FSB has focused specifically on cyber resilience and incident reporting convergence for the financial sector.

Private Sector: Operations, Maintenance, and Resilience#

Most critical infrastructure is privately owned. For utilities and banking, private companies bear primary responsibility for:

Utilities#

  • Day-to-Day Operations: Companies like PG&E (U.S.), National Grid (U.K.), or E.ON (Germany) manage power plants, transmission lines, and water treatment facilities.
  • Cybersecurity: Utilities invest in firewalls, intrusion detection systems, and employee training to defend against ransomware. The 2021 Colonial Pipeline attack—where the DarkSide ransomware group forced a six-day shutdown of the largest U.S. fuel pipeline—exposed how a single compromised password can disrupt national fuel supplies and led to mandatory cybersecurity incident reporting requirements.
  • Resilience Planning: They design systems to withstand natural disasters (e.g., flood-proof power stations) and conduct regular drills to test response to outages.

Banking#

  • Secure Transactions: Banks like JPMorgan Chase and HSBC use encryption, multi-factor authentication, and AI to detect fraud.
  • Business Continuity: They maintain backup systems (e.g., offsite data centers) to ensure services continue during outages.
  • Compliance: Banks must follow regulations like the U.S. Sarbanes-Oxley Act, the EU’s General Data Protection Regulation (GDPR), and the Digital Operational Resilience Act (DORA) (effective January 2025 in the EU) to protect customer data and ensure operational resilience.

Collaborative Frameworks: Public-Private Partnerships (PPPs)#

No single stakeholder can protect critical infrastructure alone. Public-private partnerships (PPPs) bridge gaps between government and industry:

  • Information Sharing: Groups like the Electricity Information Sharing and Analysis Center (E-ISAC) and Financial Services ISAC (FS-ISAC) allow utilities and banks to share threat intelligence (e.g., new malware strains) in real time.
  • Joint Exercises: Governments and companies conduct tabletop drills (e.g., simulating a cyberattack on a power grid) to improve coordination. The EU conducted its first energy sector resilience stress test in 2024.
  • Funding: Governments may provide grants (e.g., the U.S. Infrastructure Investment and Jobs Act) to help utilities upgrade aging infrastructure.
  • Private-Sector Coalitions: In February 2026, major infrastructure operators including JPMorgan Chase, Mastercard, AT&T, and Berkshire Hathaway Energy launched the Alliance for Critical Infrastructure (ACI) to lead cross-sector cybersecurity coordination—a response to reduced federal coordination under the Trump administration.

Challenges in Ensuring Accountability#

Despite shared responsibility, several challenges hinder effective protection:

  • Fragmentation: Many stakeholders (local, national, private) may have overlapping or unclear roles, leading to gaps in oversight. The Trump administration’s 2025 elimination of the Critical Infrastructure Partnership Advisory Council (CIPAC) disrupted a key government-industry coordination channel.
  • Aging Infrastructure: Utilities in developed countries often rely on decades-old systems. The American Society of Civil Engineers gave U.S. energy infrastructure a D+ grade in its 2025 Infrastructure Report Card, and much of the nation’s water pipe network is over 45 years old.
  • Evolving Threats: Cyberattacks (e.g., ransomware, state-sponsored hacks) and climate change (e.g., extreme weather) outpace traditional defense strategies. The World Economic Forum’s Global Cybersecurity Outlook 2026 highlighted the convergence of IT and operational technology (OT) systems as a growing attack surface.
  • Cost: Upgrading infrastructure or implementing cybersecurity measures is expensive, and private companies may prioritize profits over resilience.
  • Cross-Border Risks: Banks and utilities operate globally, but regulations vary by country, complicating coordination during international crises.
  • Shifting Federal Priorities: Proposed budget cuts to CISA and staffing reductions have raised concerns about the federal government’s capacity to support critical infrastructure protection, pushing more responsibility onto the private sector.

Conclusion#

Protecting utilities and banking infrastructure is a collective effort. Governments set the rules, private companies manage operations, and partnerships ensure collaboration. As threats like cyberattacks and climate change grow, this shared responsibility becomes even more critical.

The landscape is evolving rapidly. New EU directives like NIS2 and the CER Directive are raising the bar for critical infrastructure resilience across Europe. In the U.S., private-sector initiatives like the Alliance for Critical Infrastructure are stepping in to fill coordination gaps left by shifting federal priorities. By strengthening regulations, investing in modernization, and fostering public-private trust, we can ensure these lifelines remain secure for future generations.

References#

Legalcamp Team

Welcome to Legalcamp, where our team of dedicated professionals brings clarity to the complexities of the law.

Legal Disclaimer

No content on this website should be considered legal advice, as legal guidance must be tailored to the unique circumstances of each case. You should not act on any information provided by Legalcamp without first consulting a professional attorney who is licensed or authorized to practice in your jurisdiction. Legalcamp assumes no responsibility for any individual who relies on the information found on or received through this site and disclaims all liability regarding such information.

Although we strive to keep the information on this site up-to-date, the owners and contributors of this site make no representations, promises, or guarantees about the accuracy, completeness, or adequacy of the information contained on or linked to from this site.