Recent conflicts are causing a significant convergence between corporate and national security, with businesses and governments grappling over the responsibility and costs of protecting critical infrastructure. Historically, civilian infrastructure has been a wartime target, but the interconnectedness of the modern world means business assets now hold substantial military value. Facilities designed for cost-efficiency and easy maintenance are deemed by militaries to require enhanced protection, often beyond what companies traditionally provide.
This shift is leading to arguments between companies and governments. For instance, industry groups in Germany are warning that mandatory physical protection standards could lead to financial ruin. Companies argue they need greater clarity from governments on the protections that will be provided and subsidies to help defend privately owned assets that serve a public good. Most governments currently offer minimal incentives for private companies to invest beyond legal resilience requirements.
The 32 NATO member nations last year agreed to dedicate 5% of their economic output to defense and security, with 1.5% allocated to military-adjacent needs, including critical infrastructure protection. This reflects a broadening definition of national defense by governments and NATO allies to encompass civilian assets like subsea cables and power grids. However, this redefinition sparks disputes over funding, liability, and the increasingly blurred line between military and civilian defense responsibilities.
Governments are transitioning from voluntary guidelines to mandatory regulations with financial penalties. The EU has adopted new regulations to reduce vulnerabilities, while the UK is proposing increased penalties for subsea sabotage, and New Zealand is considering fines for critical-infrastructure companies and directors for cybersecurity breaches. These measures highlight the growing intent to force private sector security investments, although they also expose the ongoing challenge of parsing jurisdictions and liability for assets damaged in combat or crossing international waters.
Critical infrastructure such as desalination plants, data centers, subsea cables, energy grids, and logistics hubs are becoming primary military targets. State actors are increasingly targeting civilian systems to cause physical disruption and espionage, moving beyond data theft to remotely manipulate vital functions and cause physical damage. Examples include Iranian hackers targeting US drinking-water systems and suspected Russian hackers manipulating a Norwegian hydroelectric dam, emphasizing the vulnerability of these assets.