error
Subscriptions are not available for this site while you are logged into your current account.
close
Skip to main content

      Summary

      The CER Regulations signal a broader shift in how resilience is viewed across Europe, placing it alongside safety, security, and sustainability as a core consideration for the management of critical infrastructure.

      Organisations that move beyond compliance and embed resilience within strategy, planning, and investment decision-making will be better positioned to navigate an increasingly complex risk landscape.


      Background to changing risk environment

      Ireland's critical infrastructure networks are operating in an increasingly complex risk environment. Climate change is altering Ireland’s risk profile, increasing exposure to hazards.

      At the same time, digitalisation is creating new dependencies across essential services, while growing geopolitical uncertainty is highlighting the vulnerability of interconnected infrastructure systems. Disruptions that were once considered isolated events can now have cascading consequences across multiple sectors, affecting businesses, communities, and public services.

      Recent years have demonstrated the importance of resilience in maintaining the services that underpin everyday life. Electricity, water, transport, communications, healthcare, and public administration systems are becoming increasingly interconnected, meaning that disruption in one sector can quickly affect others.

      As a result, governments across Europe are placing greater emphasis on resilience, preparedness, and continuity of service rather than solely focusing on the protection of physical assets.


      Case study: Storm Éowyn and critical infrastructure interdependencies

      On 24 January 2025, Storm Éowyn brought record-breaking wind gusts of over 184 km/h, the highest ever recorded in Ireland. The storm provided a clear example of how disruption in one critical infrastructure sector can cascade across others.

      As highlighted in the Review of Storm Éowyn report, severe weather impacts to electricity, communications, water, and transport infrastructure disrupted essential services and affected communities across the country. The event highlighted the interconnected nature of critical infrastructure and the wider societal consequences that can arise when multiple infrastructure systems are disrupted simultaneously.

      The illustrative example below shows how cascading impacts can unfold during an extreme wind event such as Storm Éowyn.


      Hazard Extreme wind event - Storm Éowyn (January 2025)  Record-breaking wind gusts of over 184 km/h caused widespread damage to infrastructure and falling trees.  Direct Impact Loss of power supply  Following extensive damage to the electricity network, 103 transmission faults occurred across 39 transmission circuits, primarily in the West and Northwest. These included faults on one 220 kV line and one 400 kV line.  Cascading Impacts Water and wastewater services  286 water treatment plants and 293 wastewater treatment plants were affected due to power outages.  Communications  More than 6,000 telecommunications poles and 1,500 km of network were damaged, while prolonged power outages reduced network availability by depleting backup batteries.  Health services  Hospitals relied on backup generators while some health facilities experienced water and communications disruptions.  Community and economic impacts 768,000 customers (approximately 30% of electricity users) lost power. Outpatient services and other healthcare operations were disrupted. Over 130,000 customers experienced water supply disruptions. Emergency Hubs were established to support affected communities. Approximately 2.05 million mobile users and 281,000 fixed-network users experienced connectivity issues. Almost 34,000 Humanitarian Assistance Scheme claims were awarded (€8.2 million provided).

      The Critical Entities Resilience Framework

      For infrastructure owners, operators, planners, and investors, the CER Regulations are more than a compliance exercise. They signal a growing expectation that resilience will be embedded across infrastructure planning, asset management, climate adaptation, business continuity, operational resilience, and investment decision-making.
      Barry O'Dwyer
      Barry O'Dwyer

      Climate Change Lead

      KPMG in Ireland


      Against this backdrop, the European Union introduced the Critical Entities Resilience (CER) Directive (EU 2022/2557) to strengthen the resilience of organisations that provide essential services.

      The Directive was transposed into Irish law through the European Union (Resilience of Critical Entities) Regulations 2024, establishing a framework to ensure that providers of critical services can anticipate, withstand, respond to, and recover from disruptive events.

      The Regulations adopt an all-hazards approach, requiring organisations to consider a broad range of threats including natural hazards, cyber incidents, technological failures, supply chain disruptions, and malicious attacks.

      Ireland is advancing implementation of the Critical Entities Resilience (CER) Regulations through an enhanced national resilience framework that includes the National Risk Assessment (NRA), the National Strategy on the Resilience of Critical Entities, and sector-specific resilience planning.

      Together, this framework represents a significant shift from traditional infrastructure protection towards resilience-led planning and continuity of essential services.

      The CER framework encourages organisations to move beyond asset protection and take a service-based approach to resilience, considering how risks, dependencies, and interconnections could affect the continuity of critical services.

      As organisations prepare for implementation, the CER framework provides an opportunity to strengthen resilience across the critical services upon which Ireland's economy and society depend.


      Key timelines

      The implementation of the CER framework is progressing through a series of milestones that will shape how resilience is governed across Ireland's critical infrastructure sectors.

      • 17 October 2024

        European Union (Resilience of Critical Entities) Regulations 2024 came into effect.

      • 2026

         Ireland’s 2023 National Risk Assessment updated to align with CER requirements, strengthening the assessment of essential services, sectoral risks, and cross-sector dependencies.

      • 2026

        Publication of Ireland's National Strategy on the Resilience of Critical Entities 2026-2029, establishing governance arrangements and implementation priorities.

      • By July 2026

        Competent Authorities assess organisations within scope and identify Critical Entities.

      • Following designation

        Critical Entities are given time to undertake risk assessments, implement resilience measures and establish reporting arrangements.

      • 2027 onwards

        Ongoing compliance monitoring, incident reporting and resilience planning become embedded across critical sectors.


      Who is in scope?

      The CER Regulations apply to organisations that provide services essential to the functioning of society and the economy. Sectors within scope include:

      • Energy
      • Transport
      • Banking
      • Financial market infrastructure
      • Health
      • Drinking water
      • Wastewater
      • Digital infrastructure
      • Public administration
      • Food production, processing, and distribution
      • Space infrastructure

      Organisations may be designated as Critical Entities where disruption to their services could have a significant impact on public safety, public health, economic activity, the environment or societal well-being.


      Key obligations for Critical Entities

      The National Risk Assessment (NRA) provides the national risk baseline for the CER framework and informs the identification of Critical Entities. Once designated, Critical Entities must consider relevant national risks alongside their own threats, vulnerabilities, dependencies, and interdependencies to understand how disruption could affect the delivery of essential services and to inform proportionate resilience measures.

      Building on this foundation, Critical Entities must implement a range of risk management and resilience measures aimed at maintaining the continuity of essential services.

      The CER Regulations require asset owners and operators to revise risk assessment methodologies, incorporating plausible scenarios and cross-sector interdependencies. These assessments must be translated into targeted resilience plans and investment programmes. Effective plans should be sequenced across short, medium, and long-term time horizons so that resilience benefits are delivered progressively over time.
      Ciarán Rabbitt

      Director, Infrastructure and Government

      KPMG in Ireland


      Key obligations include:


      Overview

      Critical Entities must undertake an all-hazards risk assessment that considers national and sector-specific risks, critical service dependencies, interdependencies, vulnerabilities, and future threats. As part of this process, organisations should consider their ability to maintain essential services under severe but plausible scenarios, including compound events and failures affecting critical suppliers or interconnected infrastructure.

      Challenge

      Many organisations already conduct risk assessments, but CER requires a shift towards assessing service resilience, supply-chain dependencies and interdependencies across critical sectors. Organisations must also consider how climate change acts as a threat multiplier that increases the likelihood, severity, and interconnectedness of a range of nationally significant risks. 

      Overview

      Critical Entities must implement appropriate and proportionate technical, security and organisational measures to strengthen their ability to prevent, withstand, respond to and recover from disruptive incidents. In practice, this will require organisations to translate risk assessment findings into targeted resilience plans and investment programmes, encompassing governance, business continuity, crisis management, emergency response, supply-chain resilience, and recovery planning.

      Challenge

      The biggest challenge may not be identifying resilience measures but determining which investments will materially improve resilience while balancing competing operational and capital priorities. Implementation timeframes may vary considerably across different measures, driving the need for multi-year investment plans that deliver resilience improvements over time.

      Overview

      Critical Entities must ensure resilience measures are proportionate to the scale, complexity and risk profile of the organisation. Relevant plans, procedures and measures should be regularly reviewed, tested, and updated to reflect evolving threats, operational changes, emerging vulnerabilities and lessons learned from incidents and exercises.

      Challenge

      Many organisations already have business continuity arrangements. However, CER raises expectations around board-level ownership, regular testing, and demonstrable resilience outcomes. Decision-makers will need to consider any additional risks identified, ensuring the ongoing governance and management of these risks as part of a holistic risk management framework.

      Overview

      Critical Entities must implement incident management and reporting arrangements that enable the timely identification, escalation and notification of disruptions that materially impact or could impact the continuity of essential services.

      Challenge

      The operational challenge will be establishing processes that allow organisations to determine rapidly whether an incident meets the reporting threshold, compile reliable information, and notify the relevant Competent Authority, while simultaneously managing operational disruption and stakeholder communications.

      Overview

      Critical Entities must maintain regulatory compliance through proactive engagement with Competent Authorities, timely remediation of identified gaps, and the effective implementation of actions arising from audits, inspections and supervisory reviews.

      Challenge

      The challenge is likely to move from designing resilience measures to proving they are effective and embedded throughout the organisation.


      What does this mean for infrastructure owners and operators?

      Collectively, these obligations signal a shift from traditional compliance, safety, and business continuity activities towards a more holistic approach to resilience management.

      Organisations will need to work closely with other Critical Entities, public authorities, and sector stakeholders to understand cross-sector dependencies and interdependencies, shared vulnerabilities, and interconnected risks.

      Ultimately, the challenge is not simply achieving compliance, but embedding resilience into strategic planning, operational decision-making, and investment programmes.


      Key steps to prepare

      Although many organisations are awaiting confirmation of whether they will be formally designated as Critical Entities, there are several practical actions that can be taken now to strengthen readiness.

      • Determine applicability

        Assess whether your organisation or services are likely to fall within scope of the CER Regulations.

      • Review existing arrangements

        Evaluate current risk, business continuity and resilience frameworks against CER requirements.

      • Embed resilience into risk management

        Review existing risk, business continuity and emergency management arrangements to ensure they address the broad range of threats covered by CER.

      • Integrate climate resilience

        Consider future climate risks within asset management, infrastructure planning and investment decisions as part of a multi-year resilience improvement plan.

      • Strengthen governance

        Establish clear ownership, accountability and oversight for organisational resilience.


      How KPMG can help

      KPMG supports infrastructure owners, operators, investors, and public-sector organisations in preparing for and responding to the requirements of the CER Regulations.

      Drawing on expertise in infrastructure, climate adaptation, risk management, governance, operational resilience, investment planning, and business case development, we support organisations with CER readiness reviews, risk assessments, resilience planning, scenario analysis, and governance frameworks.

      We help clients identify critical vulnerabilities and dependencies, prioritise resilience investments, strengthen preparedness, and embed resilience considerations into strategic planning and operational decision-making.

      This supports regulatory compliance while enhancing the reliability and continuity of essential services in an increasingly uncertain risk environment.

      Our experience shows that as organisations progress from risk identification to resilience implementation, several common strategic enablers are emerging: 

      • Resilient design standards

        Establishing resilient design standards for new and existing assets to strengthen resilience outcomes across the asset lifecycle.

      • Data-driven prioritisation

        Using data-driven approaches to prioritise resilience investments and direct resources towards the areas of greatest need.

      • Risk-based governance

        Adopting risk-based governance models that target resource allocation towards the highest-risk assets, locations and services.

      • Legislative and regulatory support

        Strengthening legislative and regulatory frameworks that support the implementation of resilience measures and resilience outcomes.

      Russell Smyth

      Partner, Head of Sustainable Futures and Corporate Finance

      KPMG in Ireland

      Dr Barry O'Dwyer

      Climate Change Lead

      KPMG in Ireland

      Ciarán Rabbitt

      Director

      KPMG in Ireland

      Rodney Doyle

      Managing Director

      KPMG in Ireland


      Discover more in Infrastructure

      Something went wrong

      Oops!! Something went wrong, please try again

      Infrastructure Advisory

      Working together to solve infrastructure, sustainability and planning challenges
      USA highway transportation infrastructure at sunset. American freeway road with fast driving cars