When digital systems fail: Understanding the Risk of a Global Digital Pandemic
This side event, hosted by the ITU, the UN Office for Disaster Risk Reduction (UNDRR), and Sciences Po examined the risks posed by large-scale digital disruptions and what can be done to build resilience before the next crisis strikes . A short video illustrated how a major solar storm - comparable to the 1859 Carrington Event - could cascade across power grids, data centres, financial systems, and aviation, with scientists estimating a 2-12% probability of such an event per decade .
Constance de Leusse of Sciences Po presented the joint report or the hosts 'When digital systems fail: An expert report on the risks of our digital world which adopted a scenario-planning methodology to identify cascading interdependencies, noting that a heat wave, for example, could ultimately disrupt healthcare, financial systems, and emergency services . Nigeria's Minister of Communications, Bosun Tijani, shared that a submarine cable cut had already exposed the country's vulnerabilities, affecting banking and government services, and proposed three concrete steps: mapping critical digital dependencies, conducting cross-sector stress tests, and clarifying which institution leads coordination during a crisis .
The UAE's Director General Majed Sultan Al Mesmar described how long-term investment since 2010 - including 22 submarine cables, multiple satellite systems, and regular national resilience drills - enabled critical services to remain operational even during a recent physical attack on its ICT infrastructure . Australia's Ambassador Jessica Hunter highlighted the risks of misunderstanding, escalation, and detection delays during digital crises, and stressed the value of trusted networks such as computer emergency response teams and cross-border diplomatic frameworks .
ITU Deputy Secretary General Tomas Lamanauskas emphasised raising awareness and making preparedness operational through national cybersecurity assessments, strategies, and drills . GSMA's Kimberly Brown underlined the importance of pre-agreed crisis protocols, emergency roaming arrangements, and collaboration across the mobile ecosystem . The EU's Martin Bailey outlined a multi-hazard approach combining cyber shields, AI-driven foresight tools, and open-source platforms, stressing that resilience must be treated as a public good available beyond EU borders . The discussion concluded with broad agreement that digital risk must be systematically integrated into disaster risk management plans, and that continued international cooperation and shared learning are essential .
Overall Purpose
- The discussion aimed to raise awareness about the risks of large-scale digital infrastructure failures - referred to as a "digital pandemic" - and to explore concrete, practical steps that governments, international organisations, and the private sector can take to build resilience before such disruptions occur. The event was anchored by the launch of a joint ITU, UNDRR, and Sciences Po report, 'When digital systems fail: An expert report on the risks of our digital world,' examining plausible scenarios of systemic digital disruption. ---
Major Discussion Points
- The cascading, interconnected nature of digital risks: Speakers emphasised that digital systems do not fail in isolation. A disruption in one sector - such as a heat wave affecting data centres - can rapidly cascade into failures across healthcare, financial services, emergency alerts, and public administration. The video narration illustrated this vividly through the example of a solar storm, which could simultaneously knock out power grids, financial timing systems, and GPS within 18 hours of warning. - The critical importance of preparedness, drills, and stress-testing: Multiple panellists stressed that resilience must be built long before a crisis strikes, not during one. The UAE's Director General described how over 30 national resilience drills enabled critical services - including schools, hospitals, and government systems - to remain operational during a direct attack on its ICT infrastructure. Nigeria's Minister similarly committed to conducting cross-sector stress tests and mapping critical digital dependencies as immediate next steps. Australia's Ambassador and the ITU Deputy Secretary General both reinforced that exercising and testing systems is among the most effective preparedness tools available.
- Coordination and governance as foundational requirements: Panellists consistently identified the absence of clear coordination mechanisms as a major vulnerability. Nigeria's Minister highlighted that energy, aviation, and healthcare planning currently operate in silos, with no clear protocol for who convenes key stakeholders during a crisis or who controls information flow. The UAE pointed to its National Crisis, Emergency, and Disaster Management Authority (NCEMA), established in 2007, as a model for uniting government and private sector under one coordinated framework. The EU's representative similarly described its cyber blueprint and cross-border threat detection systems as governance tools that pre-define command structures. - The transboundary nature of digital disruptions and the role of cyber diplomacy: Ambassador Jessica Hunter underscored that digital disruptions do not respect national borders, creating risks of misunderstanding, escalation, and delayed response across different political jurisdictions. She outlined how trusted networks such as Computer Emergency Response Teams (CERTs), the IWWN, and regional programmes like PACSON help nations share information rapidly and reduce miscommunication. International law and UN norms were cited as foundational frameworks for responsible state behaviour when technical facts become contested. - The need to integrate digital risk into multi-hazard disaster risk management: A recurring theme was that digital risk remains insufficiently embedded in national disaster risk management plans. The EU representative described a "water pandemic" in July 2021 - 400 deaths and EUR 40 billion in damages - where the failure was not in forecasting but in the entire chain of data, decision-making, and action. UNDRR's moderator noted that digital risk has not been systematically integrated into country-level disaster risk frameworks, identifying this as a significant gap requiring urgent attention. The GSMA representative added that compound and sequential events - storms following floods, earthquakes leading to displacement - are already a reality, making cross-sector collaboration and pre-agreed crisis protocols essential. ---
Overall Tone
- The tone of the discussion was urgent yet constructive. The opening segment, including the room's lights being briefly cut and the solar storm video, was deliberately dramatic, designed to convey the seriousness and immediacy of the threat. This created a sense of alarm, reinforced by the audience poll in which the vast majority indicated they did not believe the world is prepared for a digital pandemic. As the panel discussion progressed, the tone shifted towards pragmatic optimism. Each panellist moved from acknowledging the scale of the risk to offering concrete, experience-based solutions - from the UAE's account of surviving a direct infrastructure attack to Nigeria's minister committing to specific action points . The overall atmosphere was collaborative and solutions-oriented, with speakers building on one another's points rather than debating. By the close, the tone was one of shared resolve, with the moderator and panellists agreeing that while much work remains, the tools, frameworks, and partnerships to act already exist.
Expanded Summary: When Digital Systems Fail - Understanding the Risk of a Global Digital Pandemic
#
Opening and Framing
The side event, hosted jointly by the International Telecommunication Union (ITU), the United Nations Office for Disaster Risk Reduction (UNDRR), and Sciences Po Paris, opened with a power cut in the conference room, which moderator Loretta Hieber-Girardet used to illustrate the session's central theme. She asked the audience: "Have we just experienced a global pandemic on digital infrastructure?" She invited those present to imagine the same disruption spreading across Geneva, Switzerland, and all of Europe, and to consider what it would mean if hospitals, emergency services, and transport systems were affected . This device was designed to make the risk viscerally tangible rather than merely theoretical, and it introduced the session's governing metaphor - the "digital pandemic" - in an emotionally resonant way .
Hieber-Girardet then set out the intellectual stakes of the discussion, noting that digital infrastructure underpins every aspect of modern life, from energy systems and financial services to healthcare, emergency alerts, public administration, and humanitarian action . She emphasised that the more interconnected these systems become, the more critical it is to understand how disruption in one sector can spill over across many sectors, societies, and communities . The discussion, she explained, was anchored by a joint report - When Digital Systems Fail and Three Plausible Scenarios of Systemic Disruption - produced through a collaboration between ITU, UNDRR, and Sciences Po, which brought together senior experts to examine how digital disruptions cascade across interconnected systems . The transcript refers to this as "the May report," indicating it was published in May.
---
#
The Solar Storm Scenario: A Credible and Imminent Threat
Before the panel discussion began, a short video was screened to illustrate the scale of potential digital disruption . The video centred on the threat of a major solar storm, drawing on the historical precedent of the 1859 Carrington Event, when a solar storm caused telegraph machines to spark and shock their operators, with some continuing to transmit even after the power was cut . The video noted that a storm of equivalent magnitude narrowly missed Earth in 2012 , and explained that if such an event were to occur today, it would drive geomagnetically induced currents through power grids, causing transformers to fail in a cascade faster than any grid could recover . Replacing a single transformer takes between 12 and 18 months, and no strategic reserve exists .
The cascading consequences would extend far beyond the power grid: data centres would go dark, financial systems would lose the satellite timing signals that sequence every transaction, GPS would fail, and aircraft would be unable to fly - all with only 18 hours of warning . Scientists estimate the probability of a Carrington-level event at up to 12 per cent per decade, making it a real possibility rather than a remote one . The video concluded with a pointed observation: "We know the risks. We know the mechanisms. What we lack is coordinated action." This framing - that the barrier is not knowledge but collective will - set the tone for the entire panel discussion that followed.
---
#
Audience Poll and the Scale of Unpreparedness
Following the video, Hieber-Girardet conducted a brief audience poll, asking how many participants believed the world is actually prepared for a digital pandemic . The poll suggested that very few, if any, participants believed adequate preparation exists, while the majority indicated they did not . This result, combined with the acknowledgement that a major digital disruption is a very real possibility with very real consequences , established a sense of urgency before the panel had spoken.
---
#
Scenario Planning and the Absence of Isolated Risks
Constance de Leusse, Senior Advisor of the Tech and Global Affairs Innovation Hub at Sciences Po in Paris, who was closely involved in producing the joint report, was invited to explain the methodology and key findings of the scenario planning process . Hieber-Girardet framed the discussion by describing one of the report's scenarios - beginning with a severe heat wave and ending with cascading disruption across power, data centres, cloud services, healthcare, payments, and emergency alerts - before inviting de Leusse to elaborate on the methodology.
De Leusse described how the expert group identified that there are no isolated risks in digital systems: a heat wave that disrupts connectivity can cascade to impact the entire chain of modern life, ultimately disrupting healthcare, financial systems, and any system that people depend on daily . This insight led the group to adopt a holistic, systemic approach rather than relying on traditional risk assessments, which tend to treat hazards in isolation . The scenario planning methodology brought experts together - through virtual and in-person meetings in Paris - to work collectively on what a disrupted future might look like and, more importantly, how collaboration could identify solutions and anticipate cascading effects . De Leusse emphasised that scenario planning must be treated as an ongoing effort rather than a one-off exercise, and that the collaborative process itself generated insights that no single expert or institution could have reached alone .
---
#
Nigeria: From Lived Experience to Concrete Action
Nigeria's Minister of Communications, Innovation, and Digital Economy, Bosun Tijani, offered one of the most candid and humanising contributions of the session. He described how his country had already experienced a real-world test of digital fragility when a submarine cable cut left young Nigerians unable to access social media, caused the banking system to stop working, and disrupted a portion of government services . He acknowledged openly that citizens had blamed him personally for the disruption, and that this experience - rather than any policy document - had driven home the importance of resilience . He reflected: "Everything we do as we talk about data transformation and as we move humanity more online, we must also take responsibility to ensure that these systems are resilient." To contextualise why resilience had become personally urgent to him, Tijani described how studies had shown Nigeria needed an additional 90,000 kilometres of fibre optic network, that he had raised $2 billion for this purpose, and that deployment was now underway. This expansion of digital connectivity made the question of resilience all the more pressing for him as a minister actively increasing his country's digital dependence.
Tijani also identified a structural governance failure that he argued is not unique to Nigeria: energy, aviation, and healthcare resilience planning are conducted independently, in silos, with his ministry playing little or no role in major digital projects in other sectors . He noted that when a digital crisis strikes, it touches every part of the economy and society simultaneously, leaving no luxury of time for delayed decision-making . He accepted that sectors would "still likely walk in silos" and that "there's nothing we can do about it" , framing fragmentation as an unavoidable reality to be managed through workaround protocols.
His proposed response was threefold: first, to map critical digital dependencies within Nigeria so that interdependencies are understood and documented before a crisis occurs ; second, to conduct cross-sector stress tests simulating total digital breakdown scenarios, with financial services as a starting example ; and third, to clarify which institution within his ministry is responsible for leading coordination during a crisis . He committed publicly to returning to a future event with a progress report on these three actions .
---
#
The UAE: Resilience Proven Under Real Attack
The UAE's Director General of the Telecommunications and Digital Government Regulatory Authority, Majed Sultan Al Mesmar, provided the most dramatic and consequential disclosure of the session. He revealed that in early March, the UAE had been subjected to a deliberate attack by a neighbouring country on its civilian ICT infrastructure, with data centres, mobile sites, and satellite infrastructure all targeted . Despite this, all critical services - including schools, hospitals, and government systems - remained fully operational . He was emphatic that this outcome was not the result of chance but of long-term, deliberate preparation: "It's not by a chance. We have prepared for this a long time ago." Al Mesmar outlined the principles underpinning the UAE's resilience architecture, which has been developed since the adoption of a national approach in 2010 . The first principle is understanding risks before they become incidents, including cyberattacks, natural disasters, supply chain disruptions, and emerging AI-driven risks, and reviewing them continuously as the threat landscape evolves . As early as 2010, the UAE identified damaged submarine cables as a strategic risk and worked with operators to diversify connectivity and eliminate single points of failure . Today, the UAE connects to the world through 21 to 22 submarine cables entering from two different locations, complemented by 2G-to-5G mobile coverage at 99.8 per cent, two satellite companies providing broadband and mobile services respectively, and the ability to activate all available VoIP services with a single button if all five mobile networks fail . He described this as "the result of long-term investment, not a chance." The second principle is that resilience is a shared responsibility requiring coordination across governments, operators, energy providers, financial institutions, and technology companies . To operationalise this, the UAE established the National Crisis, Emergency, and Disaster Management Authority (NCEMA) in 2007, uniting government and the private sector under one framework for coordinated decisions and rapid information sharing . Al Mesmar stressed that "resilience depends on strong institutions as much as robust technology" , and that the UAE conducts annual table-top drills within the ICT sector and field drills every two years, in addition to national drills involving other entities . The third principle is that resilience must be designed into the architecture itself, with distributed loads, redundancy, and geographical diversity ensuring that services continue seamlessly when one component fails . He concluded: "Resilience is about governance, partnership, continuous learning, and innovation, not only technology." ---
#
Cyber Diplomacy: Managing Risk Across Borders
Australia's Ambassador for Cyber Affairs and Critical Tech, Jessica Hunter, addressed the transboundary dimension of digital disruptions, noting that such events do not stop at national borders . She grounded her remarks in lived national experience, citing Australia's own encounter with a weather crisis that took out the electricity grid for several days, as well as the case of Tonga's 38-day connectivity outage in 2022 following a cable disruption - a real-world illustration of how swiftly digital isolation can become a humanitarian emergency.
She identified three specific risks that emerge in the information vacuum of a crisis. The first is misunderstanding: in the immediate aftermath of a disruption, it is often unclear whether the cause is a physical attack, a cyberattack, or an unintentional event, and this ambiguity creates dangerous potential for miscommunication across different political jurisdictions . The second is escalation, both within domestic agencies and across international borders, as different governments may respond to their own incomplete understanding of events . The third is delay - in detection, problem-solving, and response - which compounds the damage caused by the initial disruption .
Hunter argued that diplomacy, human relationships, and pre-established points of contact are the critical tools for managing these risks . She outlined several practical approaches. At the global level, international law applies in digital crises just as in offline ones, and UN norms on responsible state behaviour provide a framework for clarifying technical facts when they become contested . Trusted global networks - including computer emergency response teams (CERTs), the International Watch and Warning Network (IWWN), and the directory of global mechanisms on cyber - enable rapid information sharing and reduce miscommunication . At the regional level, Australia works with the Asia-Pacific CERT and the Pacific Cyber Security Operations Network (PACSON) to connect nations and build resilience capacity . Through its Southeast Asia Programme, Australia works closely with ASEAN members and Pacific Island partners to test and exercise cross-sectoral crisis scenarios, provide trusted and secure technologies, and conduct crisis preparedness work . She emphasised that public-private partnership is essential because, whilst governments and regulators define what good looks like, most critical systems are owned and managed by industry partners who must be included in scenario testing and crisis preparedness . She concluded that testing, exercising, and preparing represent the best collective effort across government and public-private infrastructure to ensure readiness for the next digital disruption - adding, with a self-correction, that such a disruption is not a matter of if, but when .
---
#
ITU: Raising the Alarm and Making Preparedness Operational
ITU Deputy Secretary General Tomas Lamanauskas was asked how ITU is helping countries move from reacting to digital disruptions to building resilience before crises occur . He began by drawing a parallel to COVID-19, noting that many policymakers currently dismiss catastrophic digital disruption scenarios as science fiction - just as a pandemic was dismissed as implausible only a few years before it happened . He used the probability of a Carrington-level solar event to challenge this complacency: "It's a pretty big chance. And if it burns down your electricity network and kind of mobile networks, can you take that chance?" Lamanauskas described ITU's approach as a structured chain of preparedness activities, modelled on its existing cybersecurity work: national assessments, national cybersecurity strategies, infrastructure building, and cyber drills . He noted that this chain must be triggered by a genuine understanding that preparedness is important, and that ITU's role includes raising awareness as well as providing technical assistance . He highlighted two specific areas of ongoing international work: submarine cable resilience, where an international advisory board was concluding its cycle with a high-level panel and recommendations the following day ; and space sustainability, where ITU is working to address the accumulation of orbital debris as satellite infrastructure becomes increasingly critical . He argued that the next frontier is making people genuinely experience disruption at scale, so that the reality of a digital crisis becomes visceral rather than abstract .
---
#
GSMA: Mobile Networks as Humanitarian Lifelines
Kimberly Brown, Head of Mobile for Humanitarian Innovation at GSMA, highlighted the role of mobile networks as lifelines during humanitarian crises and the importance of pre-agreed mechanisms for maintaining connectivity . She noted that the issues discussed throughout the panel are not only technical but fundamentally about coordination and preparedness . Drawing on GSMA's experience working at the intersection of mobile network operators, governments, humanitarian partners, and regulators , she described how learnings from mobile network operators' resilience practices can be translated into broader digital resilience frameworks .
Brown emphasised that mechanisms such as pre-agreed crisis protocols, business continuity plans, energy and fuel access arrangements, infrastructure sharing, and emergency roaming require significant advance preparation to be effective . She noted that GSMA had recently contributed to an ITU report on emergency roaming, and that instigating emergency roaming in an emergency requires a great deal of work in advance . She also underscored that compound and cascading sequential events - storms following floods, earthquakes leading to displacement - are already a lived reality for humanitarian actors and the mobile ecosystem, making cross-sector collaboration and pre-agreed protocols essential for the restoration of mobile networks and all other vital services .
---
#
The European Union: Multi-Hazard Governance and AI-Driven Foresight
Martin Bailey of the European AI Office at the European Commission outlined the EU's multi-layered approach to digital resilience . On cybersecurity, he described a range of long-established mechanisms: the EU Cyber Shield for cross-border threat detection, the EU Cyber Blueprint for command and information sharing during crises, large-scale cyber exercises conducted by the EU Cyber Agency across member states, and stockpiling of digital as well as medical goods . He also referenced the EU's Preparedness Union Strategy as an all-hazards approach to resilience .
Bailey then described the work of the EU AI Office, which is focused on shifting from fragmented, single-hazard monitoring to integrated foresight, using open and trustworthy AI tools . He cited the July 2021 European flooding disaster - which caused 400 deaths and 40 billion in damages - as a case study in systemic failure . He argued that what went wrong was not the forecasting model but the entire chain: the data, the decision-making, and the action . This observation reinforced the session's broader theme that resilience requires not just technical infrastructure but functional institutional chains for acting on information. Bailey also emphasised the importance of building redundancy into systems, keeping them open source, and moving away from proprietary "black boxes" whose operators may be unknown . He mentioned specific initiatives including projects to make cities ready for any kind of disaster - whether digital or physical - and noted that the EU is engaged in reconstruction modelling work in Ukraine and other affected areas. He described the EU's aim to develop tools and make them available beyond EU borders through trusted partnerships, recognising that the communities least prepared for digital disruptions are often those with the fewest tools at their disposal .
---
#
Convergences, Tensions, and Unresolved Questions
Across the panel, a remarkably high degree of consensus emerged on the fundamental principles of digital resilience. All speakers agreed that digital disruptions cascade across interconnected sectors ; that resilience must be built before a crisis through long-term investment rather than improvised during one ; that drills, exercises, and stress testing are indispensable ; that cross-sector coordination with clear protocols is essential ; and that no single organisation or country can manage a digital crisis alone .
Beneath this surface consensus, however, lay meaningful tensions. Tijani accepted that sectors would "still likely walk in silos" and that "there's nothing we can do about it" , framing fragmentation as an unavoidable reality to be managed through workaround protocols. Al Mesmar, by contrast, presented the UAE's NCEMA as proof that unified cross-sector coordination is structurally achievable , implying that siloed planning is not inevitable. Similarly, Al Mesmar's remarks placed considerable emphasis on technical infrastructure solutions , while Hunter and Bailey also foregrounded governance, diplomacy, and institutional chains as equally essential . An audience member also raised the question of whether broadcasting networks - radio and television - should be more explicitly integrated into resilience frameworks , a challenge that Al Mesmar acknowledged but did not fully resolve, noting that broadcasting services had continued during the UAE attack but pivoting quickly to argue that "mobile is taking over everything" .
---
#
Conclusions and the Path Forward
Hieber-Girardet closed the session by drawing together the key themes and identifying the most significant remaining gap: "Digital risk has not been systematically integrated into a lot of the disaster risk management plans that we see at a country level. So there is a lot of work to be done, a lot of lessons to be learned." This observation served as a corrective to the impressive examples of preparedness presented by the UAE, Australia, and the EU, reminding the audience that these represent the exception rather than the rule. She committed to continuing to work with ITU to disseminate the recommendations of the joint report and to capture and share lessons learned across countries .
The session concluded with broad agreement that the tools, frameworks, and partnerships needed to act already exist, but that translating this consensus into coordinated action at national and international levels remains the central challenge. The joint ITU, UNDRR, and Sciences Po report was identified as a vehicle for raising awareness among ministers and policymakers worldwide , and Tijani's public commitment to return with a progress report on Nigeria's three action points provided a concrete accountability mechanism that gave the discussion a sense of ongoing momentum beyond the session itself.
Digital infrastructure underpins all aspects of modern life, and disruption in one sector cascades across many sectors and societies - Setting the scene on cascading risk
Arg. 1Loretta Hieber-Girardet opens the discussion by emphasising that digital infrastructure is foundational to every aspect of modern life, from energy and healthcare to financial services and humanitarian action. She argues that as systems become more interconnected, a disruption in one sector inevitably spills over into many others, affecting multiple societies and communities simultaneously.
She listed the breadth of systems dependent on digital infrastructure, including energy systems, financial services, healthcare, emergency alerts, public administration, and humanitarian action , and stressed that the more connected these systems become, the more critical it is to understand how disruption in one sector can cascade across many sectors, societies, and communities .
Digital risk has not been systematically integrated into disaster risk management plans at the country level, representing a significant gap that requires urgent attention - Digital risk absent from DRM plans
Arg. 2Loretta Hieber-Girardet concludes the session by noting that while a multi-hazard approach is promoted by UNDRR, digital risk has not been consistently embedded into national disaster risk management frameworks. She identifies this as a critical gap that demands concerted effort and continued collaboration between organisations such as ITU and UNDRR.
She explicitly stated that digital risk has not been systematically integrated into many of the disaster risk management plans seen at the country level, and acknowledged there is a lot of work to be done and lessons to be learned .
The more connected digital systems become, the more important it is to understand interdependencies and how disruption in one sector spills over across many sectors, societies, and communities - Understanding systemic interdependencies
Arg. 3Hieber-Girardet argues that growing digital connectivity amplifies systemic risk, making it essential to map and understand the interdependencies between sectors. Without this understanding, societies remain blind to how a single point of failure can trigger widespread cascading disruption.
She noted that the more connected systems become, the more important it is to understand these interdependencies and that disruption in one sector can spill over across many sectors, many societies, and many communities .
A severe solar storm, like the 1859 Carrington Event, could destroy power grids globally, take down data centres, disable GPS and financial systems, with only 18 hours of warning - Solar storm as existential digital threat
Arg. 1The video narration presents the threat of a major solar storm as a credible and well-documented risk capable of causing catastrophic, cascading failure across global digital infrastructure. It argues that the consequences would be far-reaching, affecting power grids, data centres, financial systems, and aviation, and that humanity would have very little warning time.
The 1859 Carrington Event is cited as a historical precedent, with telegraph machines sparking and shocking operators . A storm of the same magnitude nearly struck Earth again in 2012 . The narration explains that such a storm drives geomagnetically induced currents through power grids, causing transformers to fail in a cascade faster than any grid can recover, with replacing a single transformer taking 12 to 18 months and no strategic reserve in place . It further notes that without power, data centres go dark, financial systems lose satellite timing signals, GPS fails, aircraft cannot fly, and there would be only 18 hours of warning . Scientists estimate the probability of another Carrington-level event at 2 to 12 per cent per decade .
There are no isolated risks; a heat wave disrupting connectivity can ultimately cascade to impact healthcare, financial systems, and all daily dependencies - No risk exists in isolation
Arg. 1Constance de Leusse argues that digital risks are inherently interconnected, meaning that a seemingly localised event such as a heat wave can trigger a chain reaction that disrupts the full spectrum of systems that modern societies depend upon. This insight underscores the need to move beyond siloed risk thinking.
She explained that when a heat wave results in connectivity disruptions, this impacts the entire chain of daily life, ultimately disrupting healthcare, financial systems, and any system people depend on day to day .
Traditional risk assessments are insufficient; a systemic and holistic approach using scenario planning is needed to anticipate cascading effects across interconnected systems - Scenario planning as a methodology
Arg. 2De Leusse contends that conventional risk assessment methods fail to capture the complexity of cascading digital failures, and that a holistic, systemic approach is required. Scenario planning was adopted as the methodology to identify what could fail and how cascading effects might unfold.
She described how the expert group at Sciences Po adopted a scenario planning process and methodology specifically to identify what could fail, anticipate cascading effects, and work collaboratively on solutions .
Scenario planning brings experts together to identify what could fail and how to collaborate on solutions, and must be treated as an ongoing effort rather than a one-off exercise - Ongoing collaborative foresight
Arg. 3De Leusse emphasises that scenario planning is not a single event but a continuous process requiring sustained collaboration among diverse experts. The value lies in the collective identification of future risks and the joint development of solutions.
She noted that experts came together through virtual and in-person meetings in Paris to work on what the future could look like and how to collaborate on solutions, and that the group recognised scenario planning as an ongoing effort .
Nigeria's experience with a subsea cable cut demonstrated how quickly banking, government services, and social connectivity collapsed, revealing the fragility of increasingly online societies - Real-world experience of digital failure
Arg. 1Bosun Tijani draws on Nigeria's direct experience of a subsea cable cut to illustrate how rapidly digital failure can cascade across an entire society. The incident exposed the vulnerability of systems that have migrated online without adequate resilience planning.
He recounted that when Nigeria experienced a subsea cable cut, the banking system stopped working, a portion of government services failed, and citizens who had shifted to online banking could no longer access financial services . He noted that young people were unable to access social media and that this experience made him realise the critical importance of resilience .
on: Whether proactive long-term investment or reactive post-incident learning is the dominant pathway to digital resilience for most countries
Digital disruptions touch every part of the economy and society simultaneously, yet planning for energy, aviation, and healthcare resilience is done independently in silos, which is a challenge not unique to Nigeria - Siloed sectoral planning as a systemic weakness
Arg. 2Tijani identifies the fragmented, sector-by-sector approach to resilience planning as a fundamental weakness that leaves societies unprepared for cross-cutting digital disruptions. He stresses that this siloed approach is a widespread problem, not limited to developing countries.
He observed that energy planning is done independently, aviation resilience is planned separately, and his ministry is not a major part of the large healthcare technology data project in Nigeria . He emphasised that this challenge is not unique to Nigeria but is the case for many countries, including some developed ones .
on: Whether siloed sectoral planning is an inevitable reality to be managed or a structural problem to be overcome through unified governance
Clear protocols must be established in advance to define who coordinates during a crisis, who controls information release, and what triggers coordinated action across sectors - Need for pre-defined coordination protocols
Arg. 3Tijani argues that the absence of pre-defined coordination protocols is a critical vulnerability, as digital crises affect the entire economy and society simultaneously, leaving no time for improvisation. He calls for clarity on decision-making authority, information management, and the triggers for cross-sector coordination.
He stated that at a minimum there needs to be a clear protocol on who gathers key stakeholders during a crisis, who makes the call, who controls information release, and what triggers coordinated action, because when a crisis hits every part of the economy and society, there is no luxury of time to delay decisions .
Cross-sector stress tests should be conducted to simulate total digital breakdown scenarios, for example in financial services, in order to design response protocols before a crisis occurs - Cross-sector stress testing
Arg. 4Tijani proposes that governments should conduct cross-sector stress tests to simulate what a total digital breakdown would mean for critical sectors such as financial services. This would enable the design of response protocols in advance, rather than improvising during an actual crisis.
He expressed his intention to conduct a cross-sector stress test before leaving his ministerial role, using financial services as an example to understand what a total breakdown would mean and to design protocols to manage it better .
Countries should map their critical digital dependencies so that the interdependencies within society are understood and documented before a crisis occurs - Mapping national digital dependencies
Arg. 5Tijani argues that a foundational step towards resilience is mapping the critical digital dependencies within a country, so that decision-makers understand where vulnerabilities lie before a crisis strikes. This mapping provides the informational basis for all subsequent resilience planning.
He identified mapping critical digital dependencies as the first of three concrete actions he planned to take back to Nigeria, stating that knowing and documenting where dependencies exist within society would go a long way towards managing disruptions .
The joint ITU, UNDRR, and Sciences Po report on digital systemic disruption scenarios is a vehicle for raising awareness among ministers and policymakers worldwide about the need to take digital resilience seriously - Report as a global awareness tool
Arg. 6Tijani highlights the joint report as an important instrument for elevating digital resilience on the agendas of ministers and policymakers globally. He argues that every minister should take the report seriously as a prompt to think about resilience and managing digital disruptions.
He described how, since the report was published, he has regularly approached the ITU Deputy Secretary General to discuss promoting the report, and stated that every minister in the world should take it seriously if they are not yet thinking about resilience .
The UAE built resilience over decades by eliminating single points of failure, diversifying submarine cable routes, maintaining multiple network technologies from 2G to 5G, and operating two satellite companies - Long-term investment in redundancy
Arg. 1Al Mesmar presents the UAE's long-term, systematic investment in infrastructure diversity as the foundation of its digital resilience. By eliminating single points of failure across multiple technology layers, the UAE ensured that no single disruption could bring down critical services.
He described how the UAE connects to the world through multiple cable systems, routes, and complementary technologies, with 99.8% coverage from 2G to 5G, 21 to 22 submarine cables entering the country from two different locations, and two satellite companies providing broadband and mobile services respectively . He also noted that even if all five mobile networks were down, services could be maintained through Wi-Fi and VoIP activation .
on: Whether mobile networks should be the primary focus of digital resilience or whether broadcasting networks deserve equal consideration
When the UAE's civilian ICT infrastructure was attacked by a neighbouring country, all critical services including schools, hospitals, and government remained operational because redundancy had been designed into the architecture from the outset - Resilience proven under real attack
Arg. 2Al Mesmar uses the UAE's experience of a real cyberattack on its civilian ICT infrastructure as proof that long-term investment in resilience pays off. The fact that critical services continued operating during the attack validates the UAE's approach of building redundancy and diversity into its systems from the beginning.
He stated that the UAE was attacked by a neighbouring country beginning of March, with data centres, mobile sites, and satellite infrastructure hit, yet none of the critical services including schools, hospitals, and government services went down . He attributed this outcome explicitly to long-term preparation rather than chance .
on: Whether proactive long-term investment or reactive post-incident learning is the dominant pathway to digital resilience for most countries
Digital resilience must be designed into architecture itself, with distributed loads, redundancy, and geographical diversity so that services continue when one component fails - Architecture-level resilience design
Arg. 3Al Mesmar argues that resilience cannot be retrofitted during a crisis but must be embedded into the fundamental design of digital infrastructure. Distributed loads, redundancy, and geographical diversity are the architectural principles that ensure continuity when individual components fail.
He stated that resilience must be designed into the architecture itself, with distributed loads, redundancy, and geographical diversity, and that throughout submarine cable cuts, severe flooding, and the recent attacks, essential digital services remained operational .
The UAE established the National Crisis, Emergency, and Disaster Management Authority in 2007 to unite government and the private sector under one framework for coordinated decisions and rapid information sharing - Unified national coordination authority
Arg. 4Al Mesmar highlights the establishment of NCEMA as a key institutional mechanism that brings together government and private sector actors under a single coordination framework. This unified structure enables rapid, coordinated decision-making during crises rather than fragmented responses.
He described how the UAE established NCEMA in 2007, uniting governments and the private sector under one framework for coordinated decisions and rapid information sharing, and emphasised that resilience depends on strong institutions as much as robust technology .
on: Whether siloed sectoral planning is an inevitable reality to be managed or a structural problem to be overcome through unified governance
The UAE conducted more than 30 national resilience drills with government and critical infrastructure partners, meaning that when a real attack occurred, responders were executing rehearsed procedures rather than guessing - Drills translate to real-world performance
Arg. 5Al Mesmar argues that the value of drills is demonstrated by the UAE's real-world performance during an actual attack, where responders acted on rehearsed procedures rather than improvising. The volume and regularity of drills — over 30 national exercises — directly contributed to the successful maintenance of critical services.
He stated that the UAE has tested its plans through more than 30 national resilience drills with government and critical infrastructure partners, and that when the real attack occurred, responders were not guessing what to do but were doing exactly what they had practised during drills .
In a digital crisis, the first major risk is misunderstanding whether an incident is a physical attack, a cyberattack, or an unintentional disruption, which can lead to dangerous miscommunication across political borders - Risk of misunderstanding in crisis
Arg. 1Ambassador Hunter identifies misunderstanding as the primary risk in the early stages of a digital crisis, when information is incomplete and the nature of the incident is unclear. This ambiguity can trigger dangerous miscommunication not only within domestic agencies but also across international political borders.
She cited Australia's experience of a weather crisis that took out its electricity grid for several days, and the case of Tonga in 2022, which had 38 days without connectivity due to a cable disruption, as examples of situations where the first risk is misunderstanding whether an incident is a physical attack, a cyberattack, or an unintentional disruption . She also noted the risk of escalation across different political borders when governments respond to incomplete information .
on: Whether digital resilience is primarily a technology and infrastructure challenge or primarily a governance, diplomacy, and institutional challenge
International law and UN norms on responsible state behaviour apply in digital crises and provide a framework for clarifying technical facts when they become contested and reducing escalation risk - International law as a stabilising framework
Arg. 2Hunter argues that international law and UN-established norms on responsible state behaviour are directly applicable to digital crises and serve as a stabilising framework when technical facts are disputed. These norms help reduce the risk of escalation by providing agreed standards for state conduct.
She stated that international law applies in a crisis whether it is digital, online, or offline, and that norms set by the United Nations provide clarification around responsible state behaviour, particularly when technical facts become contested and there is risk of miscommunication .
Trusted global networks such as computer emergency response teams, the IWWN, and the PACSON enable rapid information sharing to reduce miscommunication and produce practical outcomes during digital disruptions - Trusted networks for rapid information sharing
Arg. 3Hunter highlights the existence of trusted global and regional networks as practical mechanisms for sharing information rapidly during digital crises, thereby reducing the risk of miscommunication and enabling coordinated responses. These networks are regularly tested and updated to remain effective.
She referenced computer emergency response teams as trusted networks that many nations are part of, the directory of global mechanisms on cyber with regularly tested points of contact, and the IWWN for rapid information sharing . She also mentioned the Asia-Pacific CERT and PACSON as practical regional networks for understanding and addressing resilience requirements .
Australia works with Pacific and ASEAN partners to test and exercise cross-sectoral crisis scenarios, because exercising in advance of a crisis is the most powerful form of preparedness - Regional crisis exercising
Arg. 4Hunter argues that cross-sectoral scenario testing and exercising with regional partners is the most effective form of crisis preparedness, as it builds the relationships and procedures needed before a real disruption occurs. Australia's Southeast Asia Programme exemplifies this approach.
She described Australia's Southeast Asia Programme, which works closely with ASEAN members and Pacific Island partners to test and exercise scenarios in a cross-sectoral manner, noting that a disruption in the energy sector may also flow into the telecommunications sector . She emphasised the power of exercising in a crisis ahead of a crisis .
Public-private partnership is essential because whilst governments and regulators define what good looks like, most critical systems are owned and managed by industry partners who must be included in scenario testing and crisis preparedness - Public-private partnership in cyber diplomacy
Arg. 5Hunter argues that effective digital resilience requires the involvement of industry partners, not just governments and regulators, because the majority of critical systems are privately owned and managed. Excluding industry from scenario testing and crisis preparedness creates a fundamental gap in resilience.
She stated that whilst governments and regulators have a role in determining what good looks like and identifying priority systems of national significance, a lot of these systems are managed and owned by industry partners, and therefore industry must be brought into scenario testing, crisis preparedness, and connectivity networks .
Australia's Southeast Asia Programme provides trusted and secure technologies to partner nations to improve their resilience and reduce the time delay between disruption detection and recovery - Technology provision to regional partners
Arg. 6Hunter highlights Australia's provision of trusted and secure technologies to partner nations as a concrete mechanism for improving regional digital resilience. This directly addresses the risk of time delay in detection and recovery that she identified as a key vulnerability.
She described how Australia undertakes crisis preparedness work and provides trusted and secure technologies to many nations to ensure they are more resilient and able to recover more quickly, linking this back to her earlier point about the risk of delay in detection and resilience .
Raising awareness that seemingly sci-fi scenarios, such as a Carrington-level solar event with a 12% probability per decade, are real risks is the essential first step before operational preparedness can begin - Raising the alarm bell
Arg. 1Lamanauskas argues that many policymakers and the public dismiss catastrophic digital disruption scenarios as science fiction, and that changing this perception is the necessary precondition for any meaningful preparedness action. He draws a parallel with how COVID-19 was once similarly dismissed.
He noted that people might think the solar storm scenario is a sci-fi movie that will never happen, just as many thought the same about COVID-19 a few years before it occurred . He cited the approximately 12% likelihood of a Carrington-level event in the next decade as a significant probability that cannot be ignored, particularly given its potential to destroy electricity and mobile networks .
ITU supports countries through a chain of national cybersecurity assessments, strategy development, infrastructure building, and cyber drills, and the next step is to make people genuinely experience disruption at scale - ITU preparedness chain and experiential drills
Arg. 2Lamanauskas outlines ITU's structured approach to building national cybersecurity preparedness as a sequential chain from assessment through to drills, and argues that the next frontier is creating genuine experiential learning at scale so that the reality of disruption becomes tangible to decision-makers.
He described ITU's product line on cybersecurity, which includes helping countries conduct national assessments, develop national cybersecurity strategies, build infrastructure, and conduct cyber drills . He also referenced the work on submarine cable resilience, noting that cable breakages around the world prompted recognition of the importance of this infrastructure , and mentioned the satellite sustainability initiative addressing space debris .
ITU is working on submarine cable resilience through an international advisory board and high-level panel, and on space sustainability to address satellite debris accumulation, demonstrating the need for coordinated international action on shared infrastructure - ITU international infrastructure initiatives
Arg. 3Lamanauskas highlights ITU's specific initiatives on submarine cable resilience and space sustainability as examples of coordinated international action on shared critical infrastructure. These initiatives demonstrate that international cooperation is essential for managing infrastructure that no single country controls.
He mentioned that ITU would hold the last meeting of its international advisory board on submarine cable resilience the following day, presenting recommendations on what needs to be done . He also noted the satellite sustainability initiative running for two years, addressing the accumulation of space debris as satellite use grows .
Mobile networks serve as lifelines during humanitarian crises, and mechanisms such as pre-agreed crisis protocols, business continuity plans, infrastructure sharing, and emergency roaming require significant advance preparation to be effective - Mobile network resilience mechanisms
Arg. 1Kimberly Brown argues that mobile networks are critical lifelines during humanitarian crises, but that the mechanisms which keep them operational during disruptions — such as emergency roaming and infrastructure sharing — only work if substantial preparatory work has been done in advance. These are not improvised responses but pre-planned arrangements.
She referenced pre-agreed crisis protocols, business continuity plans, energy and fuel access arrangements, and infrastructure sharing as key resilience mechanisms drawn from the experience of mobile network operators . She specifically noted that ITU has produced a report on emergency roaming, and that instigating emergency roaming in an emergency requires a lot of advance work .
The compound and cascading nature of crises is already a lived reality for humanitarian actors, with storms following floods and earthquakes leading to displacement, making collaboration and pre-agreed protocols essential for network restoration - Compound events already a humanitarian reality
Arg. 2Brown argues that the compound and cascading crises discussed theoretically in the digital resilience report are not hypothetical for humanitarian actors — they are already a daily operational reality. This lived experience underscores the urgency of collaboration and pre-agreed protocols for restoring mobile networks and other vital services.
She noted that compound and cascading sequential events are already happening, with storms following floods and earthquakes leading to displacement, and that humanitarian actors and the mobile ecosystem are already responding to these compound and sequential events . She emphasised that collaboration leads to the restoration of mobile networks and all other vital services needed .
The EU is shifting from fragmented, single-hazard monitoring to integrated foresight, using open and trustworthy AI tools to close awareness and preparedness gaps - Integrated multi-hazard foresight
Arg. 1Martin Bailey argues that the EU's AI Office is working to move beyond fragmented, single-hazard approaches to risk monitoring towards a genuinely integrated foresight capability. Open and trustworthy AI tools are central to this shift, and a key objective is closing the uneven distribution of awareness and preparedness across member states and beyond.
He described how the AI Office builds on open, trustworthy AI tools and is working to close gaps arising from the very uneven distribution of awareness, resilience, and preparedness . He cited the July 2021 water pandemic in Europe, which caused 400 deaths and 40 billion euros in damages, as an example where the failure was not in forecasting but in the entire chain of data, decision-making, and action .
on: Whether digital resilience is primarily a technology and infrastructure challenge or primarily a governance, diplomacy, and institutional challenge
The EU's preparedness union strategy takes an all-hazards approach, and the EU cyber blueprint clarifies command structures and information sharing across member states during cross-border digital crises - EU all-hazards governance framework
Arg. 2Bailey outlines the EU's comprehensive governance framework for digital resilience, which combines an all-hazards preparedness strategy with specific cyber crisis management tools. The cyber blueprint in particular addresses the critical question of command and information sharing during cross-border digital incidents.
He described the EU's cyber shield for cross-border threat detection, the EU cyber blueprint for command and information sharing, large-scale cyber exercises conducted by the EU cyber agency, stockpiling of digital goods, and the preparedness union strategy as an all-hazards approach .
The EU develops open-source tools and makes them available beyond EU borders through trusted partnerships, recognising that the communities least prepared are often those with fewest tools at their disposal - EU tools available internationally
Arg. 3Bailey argues that the EU has a responsibility to share its digital resilience tools beyond its own borders, particularly with communities that are least prepared and have the fewest resources. Trusted international partnerships are the vehicle for this technology transfer.
He stated that the EU develops tools and makes them available not just within the EU but aims to share them outside the EU through trusted partnerships, recognising that communities that are unfortunately the least prepared or least able to deal with crises often do not have the tools at their disposal .
Broadcasting networks, including radio and TV, should be considered as part of digital resilience infrastructure alongside mobile networks - Broadcasting as a resilience tool
Arg. 1The audience member raises the question of whether broadcasting networks are utilised as part of the UAE's resilience strategy, implying that radio and TV broadcasting represent an additional layer of communication infrastructure that could contribute to resilience during digital disruptions. The question suggests that broadcasting may have been overlooked or underemphasised in the UAE's resilience framework as presented.
The audience member specifically asked whether the UAE uses all broadcasting networks, clarifying that they were referring to radio and TV broadcasting , prompting Al Mesmar to confirm that broadcasting services also continued during the attack and did not stop .
on: Whether mobile networks should be the primary focus of digital resilience or whether broadcasting networks deserve equal consideration
Session Knowledge Graph
Speakers · Topics · Arguments · Relationships
All panellists converged on the principle that resilience cannot be improvised during a crisis but must be systematically built in advance. Al Mesmar stated explicitly that 'resilience is not built during crisis, but it's built long before the crisis happens' , attributing the UAE's ability to withstand a real attack to preparation that began in 2010 . Tijani reflected that Nigeria's subsea cable cut experience made him realise that 'resilience is extremely important' and that 'everything we do as we talk about data transformation and as we move humanity more online, we must also take responsibility to ensure that these systems are resilient' . Hunter emphasised 'the power of exercising in a crisis ahead of a crisis' . Lamanauskas described ITU's structured preparedness chain and called for making people genuinely experience disruption at scale . Brown noted that mechanisms such as emergency roaming 'require a lot of work in advance' to be effective .
Resilience proven under real attack
Real-world experience of digital failure
Regional crisis exercising
ITU preparedness chain and experiential drills
Mobile network resilience mechanisms
Multiple speakers independently identified drills and exercises as the most critical practical tool for preparedness. Al Mesmar described how the UAE conducted more than 30 national resilience drills, meaning that when a real attack occurred, 'we weren't guessing what to do we were only doing what we have been doing during the drills' . Tijani proposed conducting cross-sector stress tests to simulate total digital breakdown scenarios before leaving his ministerial role . Hunter described Australia's Southeast Asia Programme, which tests and exercises cross-sectoral crisis scenarios with regional partners, emphasising 'the power of exercising in a crisis ahead of a crisis' . Lamanauskas argued that the next stage is to 'make sure how we really make people experience that so that this becomes' real , and described ITU's cyber drill component as part of its national preparedness chain . Hieber-Girardet also affirmed that 'the importance of drills and simulations can't be overestimated' .
Drills translate to real-world performance
Cross-sector stress testing
Regional crisis exercising
ITU preparedness chain and experiential drills
Speakers consistently identified the absence of cross-sector coordination as a critical vulnerability and called for unified governance structures. Tijani identified siloed planning across energy, aviation, and healthcare as a systemic weakness not unique to Nigeria , and called for clear protocols defining who coordinates, who controls information, and what triggers coordinated action . Al Mesmar described how the UAE established NCEMA in 2007 to unite government and the private sector under one framework for coordinated decisions and rapid information sharing . Hunter highlighted the EU cyber blueprint and the need for cross-sectoral exercising where a disruption in energy may flow into telecommunications . Bailey described the EU cyber blueprint for command and information sharing during cross-border digital crises . Hieber-Girardet concluded that digital risk has not been systematically integrated into disaster risk management plans at the country level, identifying this as a critical gap .
Need for pre-defined coordination protocols
Unified national coordination authority
Public-private partnership in cyber diplomacy
EU all-hazards governance framework
Digital risk absent from DRM plans
A strong consensus emerged that digital resilience is inherently a collective endeavour. Al Mesmar stated that 'no organization can manage a digital crisis alone' and that 'governments, operators, energy providers, financial institutions, and technology companies all depend on one another' . Hunter emphasised that whilst governments and regulators define what good looks like, most critical systems are owned and managed by industry partners who must be included in scenario testing and crisis preparedness . Brown highlighted collaboration across mobile network operators, governments, humanitarian partners, and regulators as the foundation of resilience . Bailey described the EU's aim to share its tools beyond EU borders through trusted partnerships, recognising that the least prepared communities often have the fewest tools . Lamanauskas described ITU's international advisory board on submarine cable resilience and satellite sustainability initiatives as examples of coordinated international action on shared infrastructure .
Unified national coordination authority
Public-private partnership in cyber diplomacy
Compound events already a humanitarian reality
EU tools available internationally
ITU international infrastructure initiatives
Several speakers converged on the architectural principle of eliminating single points of failure. Al Mesmar described how the UAE diversified connectivity and eliminated single points of failure as early as 2010 , connecting to the world through multiple cable systems, routes, and complementary technologies from 2G to 5G, with two satellite companies and Wi-Fi VoIP as a further fallback . He stated that 'resilience must be designed into the architecture itself' with 'distributed loads, redundancy and geographical diversity' . Brown referenced pre-agreed crisis protocols, infrastructure sharing, and emergency roaming as mechanisms that keep mobile networks operational during disruptions . Bailey noted that the EU builds redundancy into its systems and keeps them open source, moving away from black boxes .
Long-term investment in redundancy
Architecture-level resilience design
Mobile network resilience mechanisms
EU all-hazards governance framework
Multiple speakers agreed that understanding and mapping interdependencies is foundational to resilience. Hieber-Girardet stressed that 'the more connected these systems become, the more important it is that we understand these interdependencies and understand the disruption in one sector can spill over across many sectors, many societies, and many communities' . De Leusse argued that 'there is no isolated risks' and that a heat wave disrupting connectivity can cascade to impact healthcare, financial systems, and all daily dependencies . Tijani identified mapping critical digital dependencies as the first of three concrete actions he planned to take back to Nigeria, stating that knowing and documenting where dependencies exist would go a long way towards managing disruptions . Brown noted that compound and cascading sequential events are already a lived reality for humanitarian actors, with storms following floods and earthquakes leading to displacement .
Understanding systemic interdependencies
No risk exists in isolation
Mapping national digital dependencies
Compound events already a humanitarian reality
Speakers consistently emphasised the need for international cooperation and trusted information-sharing networks. Hunter described computer emergency response teams, the IWWN, and PACSON as trusted global and regional networks enabling rapid information sharing to reduce miscommunication during digital crises . Lamanauskas highlighted ITU's international advisory board on submarine cable resilience and satellite sustainability initiatives as examples of coordinated international action on shared infrastructure . Bailey described the EU's aim to develop tools and make them available beyond EU borders through trusted partnerships, recognising that the least prepared communities often have the fewest tools . Tijani described promoting the joint ITU, UNDRR, and Sciences Po report as a global awareness tool, stating that 'every minister in the world should actually take this report seriously' .
Trusted networks for rapid information sharing
ITU international infrastructure initiatives
EU tools available internationally
Report as a global awareness tool
Both de Leusse and Lamanauskas argued that conventional thinking about risk is inadequate and that a fundamental shift in perception is required before meaningful action can follow. De Leusse described how the expert group adopted a scenario planning process specifically to identify what could fail and anticipate cascading effects, because traditional risk assessments miss the systemic nature of digital disruptions . Lamanauskas similarly argued that many policymakers dismiss catastrophic digital disruption scenarios as science fiction, drawing a parallel with how COVID-19 was once similarly dismissed, and that changing this perception is the necessary precondition for preparedness . Both speakers saw their respective methodologies — scenario planning and awareness-raising — as the essential first step in a longer preparedness journey. Both Tijani and Al Mesmar identified the fragmentation of sectoral planning as a critical vulnerability, and both pointed to unified coordination structures as the solution, though from very different starting points. Tijani observed that energy, aviation, and healthcare resilience planning is done independently in Nigeria, with no clear protocol for who coordinates during a crisis , and proposed establishing institutional clarity within his ministry . Al Mesmar described how the UAE had already solved this problem by establishing NCEMA in 2007 to unite government and the private sector under one framework for coordinated decisions and rapid information sharing . Their shared diagnosis of the problem — siloed planning — and shared prescription — unified coordination — was striking given the very different levels of preparedness of their respective countries. Both Hunter and Al Mesmar independently emphasised that the value of drills is demonstrated by real-world performance during actual crises. Al Mesmar described how the UAE's more than 30 national resilience drills meant that when a real attack occurred, 'we weren't guessing what to do we were only doing what we have been doing during the drills' [169, 175]. Hunter described Australia's Southeast Asia Programme, which tests and exercises cross-sectoral crisis scenarios with regional partners, emphasising 'the power of exercising in a crisis ahead of a crisis' . Both speakers used concrete real-world examples — the UAE attack and Australia's weather crisis and Tonga's cable disruption — to validate the importance of pre-crisis exercising. Both Brown and de Leusse argued that cascading and compound digital risks are not theoretical constructs but already a lived reality. De Leusse argued from a scenario planning perspective that 'there is no isolated risks' and that a heat wave disrupting connectivity cascades to impact healthcare, financial systems, and all daily dependencies . Brown reinforced this from a humanitarian operations perspective, noting that 'compound and cascading sequential events' are 'already here', with storms following floods and earthquakes leading to displacement, and that humanitarian actors and the mobile ecosystem are 'already responding to these compound and sequential events' . Both speakers used this shared insight to argue for the urgency of collaboration and pre-agreed protocols. Hieber-Girardet, Tijani, and Al Mesmar all drew on concrete real-world experiences of digital failure to make the case for systemic resilience investment. Hieber-Girardet used the room's own temporary power outage as a live demonstration of cascading disruption and cited the breadth of systems dependent on digital infrastructure . Tijani recounted Nigeria's subsea cable cut, which caused banking systems to fail, government services to stop, and citizens to be unable to access financial services . Al Mesmar described the UAE being attacked by a neighbouring country, with data centres, mobile sites, and satellite infrastructure hit, yet critical services remaining operational due to long-term preparation . All three used experiential evidence to argue that digital resilience is not abstract but has immediate, tangible consequences for societies. Both Bailey and de Leusse argued for moving beyond fragmented, single-hazard approaches towards integrated, systemic foresight. De Leusse described how the Sciences Po expert group adopted a scenario planning methodology to identify cascading effects across interconnected systems, treating it as an ongoing collaborative effort . Bailey described how the EU's AI Office is working to shift from 'fragmented, single hazard kind of monitoring to a real integrated foresight' using open and trustworthy AI tools , and cited the July 2021 European water crisis as an example where failure was not in forecasting but in the entire chain of data, decision-making, and action . Both speakers saw integrated, multi-hazard foresight as the necessary evolution from current practice.
It was somewhat unexpected that both a minister from a large developing country and the director general of a highly advanced digital economy would converge on the same diagnosis of inadequate integration of digital risk into national frameworks, albeit from very different positions. Tijani candidly acknowledged that energy, aviation, and healthcare resilience planning is done independently in Nigeria, with his ministry not being a major part of the healthcare technology data project , and that this challenge 'is not unique to Nigeria' but applies to 'many countries, even in some developed countries' . Al Mesmar, representing the UAE's sophisticated resilience architecture, implicitly validated this diagnosis by describing how the UAE had to deliberately build NCEMA in 2007 to overcome exactly this kind of fragmentation . Hieber-Girardet then confirmed from UNDRR's global perspective that 'digital risk has not been systematically integrated into a lot of the disaster risk management plans that we see at a country level' . The consensus across a developing country minister, an advanced economy regulator, and a UN disaster risk reduction official on this gap was notable.
Given that the discussion was ostensibly about digital infrastructure and technology, it was unexpected that speakers from such diverse backgrounds - a national telecommunications regulator, a cyber diplomat, a humanitarian mobile technology specialist, and an EU AI official - all converged on the view that governance, institutions, and human relationships are more important than technology itself. Al Mesmar stated that 'resilience depends on strong institutions as much as robust technology' and that 'resilience is about governance, partnership, continuous learning, and innovation, not only technology' . Hunter emphasised that 'diplomacy comes to the fore and really where the connectivity between humans and relationships and points of contact and exercising and testing our systems really are critical' . Brown highlighted that 'these issues are technical, but they're about coordination, and they're about preparedness' . Bailey described how the July 2021 European water crisis failed not because of inadequate forecasting technology but because of failures in 'the data, the decision-making, the action' . This consensus on the primacy of governance over technology from speakers with deep technical expertise was notably unexpected.
There was an unexpected degree of consensus among technically sophisticated speakers that natural hazards - particularly solar storms and extreme weather - represent as serious a threat to digital infrastructure as deliberate cyberattacks, and that this risk is not adequately appreciated. The video narration presented the Carrington-level solar storm as a credible risk with a 2 to 12 per cent probability per decade . Lamanauskas reinforced this, noting that a 12% likelihood per decade 'is a pretty big chance' and asking 'if it burns down your electricity network and kind of mobile networks, can you take that chance?' . Hunter cited Australia's weather crisis that took out its electricity grid for several days and Tonga's 38 days without connectivity due to a cable disruption as real examples of natural hazard-driven digital disruption . Bailey described the July 2021 European water crisis causing 400 deaths and 40 billion euros in damages as a 'digital pandemic' driven by natural hazard . The consensus that natural hazards are as threatening as cyberattacks - and perhaps less well prepared for - was unexpected in a discussion that might have been expected to focus primarily on cyber threats.
It was somewhat unexpected that both the EU AI Office representative and the UAE telecommunications regulator converged on the importance of transparency and openness in digital systems as a resilience principle. Bailey explicitly stated that the EU builds systems with redundancy, keeps them open source, and wants to 'move away from the black boxes because you never know who's operating the switches' . Al Mesmar described the UAE's approach of maintaining multiple diverse and transparent network layers, with the ability to activate VoIP services with a single button , reflecting a similar philosophy of avoiding dependence on opaque, single-vendor systems. While their contexts differed, both speakers implicitly agreed that proprietary, opaque systems create resilience vulnerabilities.
The discussion revealed a remarkably high level of consensus across all speakers on the fundamental principles of digital resilience. All speakers agreed that: digital disruptions cascade across interconnected sectors and societies ; resilience must be built before a crisis through long-term investment, not improvised during one ; drills, exercises, and stress testing are indispensable ; cross-sector coordination with clear protocols is essential ; no single organisation or country can manage a digital crisis alone ; mapping and understanding interdependencies is foundational ; and international cooperation and information sharing are necessary . There were no significant disagreements among speakers on any substantive point. The discussion was characterised by mutual reinforcement of arguments across very different national and institutional contexts.
Tijani acknowledged that entities will 'still likely walk in silos' and that 'there's nothing we can do about it' , framing siloed planning as an unavoidable reality that requires workaround protocols to manage. He proposed defining triggers for coordination as a pragmatic response . By contrast, Al Mesmar presented the UAE's establishment of NCEMA in 2007 as a deliberate structural solution that unified government and private sector under one coordination framework , implying that siloed planning is not inevitable but can be overcome through institutional design. This represents a fundamental difference in outlook: Tijani accepts fragmentation as a given and seeks to manage it, while Al Mesmar argues it can be structurally eliminated.
Digital disruptions touch every part of the economy and society simultaneously, yet planning for energy, aviation, and healthcare resilience is done independently in silos, which is a challenge not unique to Nigeria - Siloed sectoral planning as a systemic weakness
The UAE established the National Crisis, Emergency, and Disaster Management Authority in 2007 to unite government and the private sector under one framework for coordinated decisions and rapid information sharing - Unified national coordination authority
Al Mesmar placed primary emphasis on technical infrastructure solutions, detailing the UAE's 21-22 submarine cables, 2G-to-5G coverage, satellite diversity, and architectural redundancy as the foundation of resilience . He stated that 'resilience must be designed into the architecture itself' . Hunter, by contrast, foregrounded governance and diplomacy, arguing that the first risks in a crisis are misunderstanding, escalation, and delay , and that international law, UN norms, and trusted human networks are the critical mitigating factors . Bailey similarly emphasised integrated foresight, open-source tools, and multi-hazard governance frameworks . While Al Mesmar did acknowledge that 'resilience depends on strong institutions as much as robust technology' , his detailed evidence was overwhelmingly technical, whereas Hunter and Bailey gave primacy to governance and human coordination.
The UAE built resilience over decades by eliminating single points of failure, diversifying submarine cable routes, maintaining multiple network technologies from 2G to 5G, and operating two satellite companies - Long-term investment in redundancy
In a digital crisis, the first major risk is misunderstanding whether an incident is a physical attack, a cyberattack, or an unintentional disruption, which can lead to dangerous miscommunication across political borders - Risk of misunderstanding in crisis
The EU is shifting from fragmented, single-hazard monitoring to integrated foresight, using open and trustworthy AI tools to close awareness and preparedness gaps - Integrated multi-hazard foresight
Al Mesmar's entire presentation of UAE resilience centred on mobile and internet infrastructure, including 2G-to-5G networks, submarine cables, satellite broadband, and VoIP activation . He explicitly stated that 'mobile is taking over everything' and that 'our lives just go around mobile now' , suggesting mobile is the dominant and sufficient resilience layer. The audience member challenged this framing by asking whether broadcasting networks, specifically radio and TV, were also utilised , implying that broadcasting represents an overlooked or undervalued resilience tool. Al Mesmar confirmed broadcasting services did continue during the attack but had not included them in his resilience framework, revealing a difference in how comprehensively the resilience ecosystem should be defined.
The UAE built resilience over decades by eliminating single points of failure, diversifying submarine cable routes, maintaining multiple network technologies from 2G to 5G, and operating two satellite companies - Long-term investment in redundancy
Broadcasting networks, including radio and TV, should be considered as part of digital resilience infrastructure alongside mobile networks - Broadcasting as a resilience tool
Al Mesmar described the UAE's resilience as the product of a national approach adopted in 2010 and sustained over decades, explicitly stating that 'resilience is not built during crisis, but it's built long before the crisis happens' . The UAE's performance during a real attack was presented as proof of concept for proactive investment . Tijani, by contrast, described how Nigeria's resilience awareness was triggered reactively by experiencing a subsea cable cut , and his proposed actions - mapping dependencies, stress testing, clarifying coordination - are framed as steps yet to be taken . This reflects a real divergence in where different countries currently stand and implicitly in whether reactive learning is an acceptable pathway, with Al Mesmar firmly rejecting it and Tijani describing it as his country's actual experience.
Nigeria's experience with a subsea cable cut demonstrated how quickly banking, government services, and social connectivity collapsed, revealing the fragility of increasingly online societies - Real-world experience of digital failure
When the UAE's civilian ICT infrastructure was attacked by a neighbouring country, all critical services including schools, hospitals, and government remained operational because redundancy had been designed into the architecture from the outset - Resilience proven under real attack
This disagreement was unexpected because the entire panel, including Al Mesmar, had presented a broadly comprehensive view of resilience infrastructure. The audience member's challenge revealed that despite the UAE's extensive resilience framework, broadcasting had been entirely absent from Al Mesmar's presentation, suggesting a potential blind spot in how resilience is conceptualised. Al Mesmar's response - confirming broadcasting continued but then pivoting to argue that 'mobile is taking over everything' - revealed an implicit hierarchy in which broadcasting is considered secondary or supplementary rather than a core resilience layer. This was unexpected given that broadcasting, particularly radio, is often the last-resort communication channel when digital infrastructure fails, which is precisely the scenario being discussed.
It was unexpected that Tijani, as a minister actively working on digital transformation, explicitly stated that entities 'will still likely walk in silos' and that 'there's nothing we can do about it' , effectively accepting structural fragmentation as permanent. This stands in direct contrast to Al Mesmar's presentation of NCEMA as proof that unified cross-sector coordination is achievable . The disagreement is unexpected because both speakers were presenting at the same event promoting resilience, yet arrived at fundamentally different conclusions about whether the siloed status quo can be changed. Tijani's acceptance of silos as inevitable implicitly challenges the feasibility of the coordinated resilience models being promoted by other panellists.
The event was framed around natural and systemic digital risks, with the video narration focusing on solar storms as the paradigmatic threat and the report scenarios centred on heat waves and cascading infrastructure failure . It was therefore unexpected when Al Mesmar revealed that the UAE had recently experienced a deliberate military-style attack on its civilian ICT infrastructure by a neighbouring country , shifting the threat model from natural hazard to geopolitical aggression. Hunter further complicated this by noting that a key risk in any crisis is the inability to distinguish between physical attack, cyberattack, and unintentional disruption . This implicit disagreement about the primary threat type has significant implications for how resilience should be designed and governed, as natural hazard resilience and state-actor attack resilience require different responses.
The discussion was characterised by a high degree of surface-level consensus on the importance of digital resilience, cross-sector coordination, drills and exercises, and public-private partnership. However, beneath this consensus lay meaningful disagreements about: (1) whether siloed sectoral planning is inevitable or structurally solvable ; (2) whether resilience is primarily a technical infrastructure challenge or a governance and diplomacy challenge ; (3) whether mobile networks are sufficient as the primary resilience layer or whether broadcasting deserves equal status ; (4) whether proactive long-term investment or reactive post-incident learning is the realistic pathway for most countries ; and (5) whether the primary threat model is natural hazard, systemic failure, or deliberate state-level attack . The most significant structural disagreement was between Tijani's acceptance of silos as permanent and Al Mesmar's demonstration that unified coordination is achievable , as this goes to the heart of whether the resilience models being promoted are universally applicable or context-dependent.
All speakers agreed that cross-sector coordination is essential for digital resilience, but differed significantly on how to achieve it. Tijani called for pre-defined protocols and clarity on who coordinates , acknowledging that silos are likely to persist . Al Mesmar presented a unified national authority (NCEMA) as the structural solution . Hunter emphasised trusted international networks and diplomacy as the coordination mechanism . Lamanauskas pointed to ITU's chain of national assessments and drills as the pathway . Brown highlighted pre-agreed crisis protocols and emergency roaming arrangements as the practical tools . The shared goal is coordination, but the proposed mechanisms range from institutional unification to diplomatic networks to technical protocols.
Clear protocols must be established in advance to define who coordinates during a crisis, who controls information release, and what triggers coordinated action across sectors - Need for pre-defined coordination protocols The UAE established the National Crisis, Emergency, and Disaster Management Authority in 2007 to unite government and the private sector under one framework for coordinated decisions and rapid information sharing - Unified national coordination authority Australia works with Pacific and ASEAN partners to test and exercise cross-sectoral crisis scenarios, because exercising in advance of a crisis is the most powerful form of preparedness - Regional crisis exercising ITU supports countries through a chain of national cybersecurity assessments, strategy development, infrastructure building, and cyber drills, and the next step is to make people genuinely experience disruption at scale - ITU preparedness chain and experiential drills Mobile networks serve as lifelines during humanitarian crises, and mechanisms such as pre-agreed crisis protocols, business continuity plans, infrastructure sharing, and emergency roaming require significant advance preparation to be effective - Mobile network resilience mechanisms
All four speakers agreed on the value of drills and exercises, but differed on scope, scale, and maturity. Al Mesmar described over 30 completed national resilience drills as a proven model [169, 175]. Hunter advocated for cross-sectoral regional exercises with ASEAN and Pacific partners as the next step . Lamanauskas argued that the next frontier is making people genuinely experience disruption at scale , suggesting current drills are insufficient. Tijani proposed conducting a cross-sector stress test as a future aspiration before leaving office , indicating Nigeria has not yet reached the drill stage. The shared goal is preparedness through simulation, but the speakers are at very different stages of implementation.
The UAE conducted more than 30 national resilience drills with government and critical infrastructure partners, meaning that when a real attack occurred, responders were executing rehearsed procedures rather than guessing - Drills translate to real-world performance Australia works with Pacific and ASEAN partners to test and exercise cross-sectoral crisis scenarios, because exercising in advance of a crisis is the most powerful form of preparedness - Regional crisis exercising ITU supports countries through a chain of national cybersecurity assessments, strategy development, infrastructure building, and cyber drills, and the next step is to make people genuinely experience disruption at scale - ITU preparedness chain and experiential drills Cross-sector stress tests should be conducted to simulate total digital breakdown scenarios, for example in financial services, in order to design response protocols before a crisis occurs - Cross-sector stress testing
De Leusse, Lamanauskas, and Bailey all agreed that traditional, fragmented, single-hazard risk assessment is inadequate and that a more holistic, systemic approach is needed. However, they differed on the methodology. De Leusse advocated for collaborative scenario planning with expert groups . Lamanauskas emphasised raising awareness of low-probability, high-impact events as the precondition for any methodology . Bailey pointed to AI-driven integrated foresight tools and multi-hazard platforms as the technical solution . The shared diagnosis is that current approaches are insufficient, but the proposed remedies differ in their emphasis on human collaboration, awareness-raising, and technological tools respectively.
Traditional risk assessments are insufficient; a systemic and holistic approach using scenario planning is needed to anticipate cascading effects across interconnected systems - Scenario planning as a methodology Raising awareness that seemingly sci-fi scenarios, such as a Carrington-level solar event with a 12% probability per decade, are real risks is the essential first step before operational preparedness can begin - Raising the alarm bell The EU is shifting from fragmented, single-hazard monitoring to integrated foresight, using open and trustworthy AI tools to close awareness and preparedness gaps - Integrated multi-hazard foresight
Hunter, Brown, and Al Mesmar all agreed that public-private partnership is essential for digital resilience, but differed on the nature of that partnership. Hunter emphasised that industry must be brought into scenario testing and crisis preparedness because they own and manage most critical systems . Brown focused on the operational mechanisms — emergency roaming, infrastructure sharing, business continuity plans — that require advance collaboration between mobile operators, governments, and humanitarian partners . Al Mesmar described a formal institutional framework (NCEMA) that unites government and private sector under one coordination structure . The shared goal is public-private collaboration, but the approaches range from informal inclusion in exercises to formal institutional integration.
Public-private partnership is essential because whilst governments and regulators define what good looks like, most critical systems are owned and managed by industry partners who must be included in scenario testing and crisis preparedness - Public-private partnership in cyber diplomacy Mobile networks serve as lifelines during humanitarian crises, and mechanisms such as pre-agreed crisis protocols, business continuity plans, infrastructure sharing, and emergency roaming require significant advance preparation to be effective - Mobile network resilience mechanisms The UAE established the National Crisis, Emergency, and Disaster Management Authority in 2007 to unite government and the private sector under one framework for coordinated decisions and rapid information sharing - Unified national coordination authority
- Digital infrastructure underpins every aspect of modern life, and disruption in one sector cascades rapidly across many others, including healthcare, financial services, emergency alerts, and public administration, making systemic digital risk a critical global concern.
- There are no isolated digital risks; a single event such as a heat wave, a subsea cable cut, or a cyberattack can trigger cascading failures across interconnected systems, as demonstrated by Nigeria's experience with a subsea cable disruption that collapsed banking and government services.
- A severe solar storm comparable to the 1859 Carrington Event, with an estimated probability of up to 12% per decade, could destroy power grids globally, disable data centres, GPS, and financial systems, with only 18 hours of warning, making it a credible and urgent threat rather than a remote one.
- Traditional risk assessments are insufficient; a holistic, systemic approach using scenario planning is necessary to anticipate cascading effects, and this must be treated as an ongoing collaborative effort rather than a one-off exercise.
- Resilience must be designed into digital architecture from the outset, with redundancy, distributed loads, and geographical diversity eliminating single points of failure, as demonstrated by the UAE's ability to maintain all critical services during a real military cyberattack on its civilian ICT infrastructure.
- Siloed sectoral planning for energy, aviation, healthcare, and telecommunications is a systemic weakness common to many countries; clear pre-defined protocols are needed to establish who coordinates during a crisis, who controls information release, and what triggers coordinated action across sectors.
- Drills and exercises are among the most powerful tools for preparedness; the UAE's more than 30 national resilience drills meant that when a real attack occurred, responders executed rehearsed procedures rather than improvising, and similar cross-sectoral exercises are being conducted by Australia with Pacific and ASEAN partners.
- In a digital crisis, the first major risk is misunderstanding whether an incident is a physical attack, a cyberattack, or an unintentional disruption; international law, UN norms on responsible state behaviour, and trusted networks such as CERTs and the IWWN provide frameworks for reducing miscommunication and escalation.
- Digital risk has not been systematically integrated into disaster risk management plans at the country level, representing a significant and urgent gap.
- Public-private partnership is essential because most critical digital systems are owned and managed by industry partners, who must be included in scenario testing, crisis preparedness, and protocol development.
- International cooperation and sharing of tools, best practices, and technologies are critical, particularly for the communities and nations that are least prepared and have the fewest resources at their disposal.
- The joint ITU, UNDRR, and Sciences Po report on digital systemic disruption scenarios serves as a vehicle for raising awareness among ministers and policymakers worldwide, and its recommendations need to be widely disseminated and acted upon.
“Loretta Hieber-Girardet opens the session by staging a live power cut in the room, then asks: 'Have we just experienced a global pandemic on digital infrastructure? Now, imagine if what we're experiencing right now was taking place throughout Geneva, throughout Switzerland, throughout all of Europe.' She then invites the audience to imagine hospitals, emergency services, and transport systems being affected.”
“The video narration states: 'In 2012, a storm of the same magnitude narrowly missed us... Replacing a single transformer takes 12 to 18 months, and there is no strategic reserve... We would have only 18 hours of warning... The probability is estimated at 2 to 12 per cent per decade.' It concludes: 'We know the risks. We know the mechanisms. What we lack is coordinated action.'”
“Bosun Tijani recounts Nigeria's experience with a submarine cable cut: 'Young people in the country that couldn't go on social media were cussing out and saying I'm a useless minister... the banking system wasn't working... people now go into bank branches less... A portion of government services also didn't work.' He then reflects: 'It took that experience to realize that resilience is extremely important.'”
“Bosun Tijani observes: 'When we still plan for energy, it's done independently. When we think of aviation, the planning for aviation and resilience in aviation is done differently... Healthcare, for instance, we have a big technology data project in healthcare in Nigeria, which my ministry is not a major part of. I think this is a challenge and is not unique to Nigeria. It's the case for many countries, even in some developed countries.'”
“Majed Sultan Al Mesmar reveals: 'The UAE has just been went under attack beginning of March by a neighboring country. They attacked our civilian ICT infrastructure... They have hit our data centers, mobile sites, even some of the satellites' infrastructure has been hit. Yet we managed to have all critical services running up. Schools, hospitals, the government services. It's not by a chance.'”
“Majed Sultan Al Mesmar states: 'Resilience is not built during crisis, but it's built long before the crisis happens.' He elaborates: 'Plans on shelf have little value. We have tested them through more than 30 national resilience drills... When we put in the situation of aggression, we weren't guessing what to do. We were only doing what we have been doing during the drills.'”
“Ambassador Jessica Hunter identifies three specific risks that emerge in the information vacuum of a crisis: 'The first risk... is a risk of misunderstanding... is it a physical attack or is it a cyber attack? Or is it just an unintentional activity?... We see risk of escalation... across different political borders... We also see a risk in particular of delay. So that's a risk of delay of detection, which then delays your ability to problem solve.'”
“Thomas Lamanauskas draws a parallel to COVID-19: 'A lot of people would think this is a sci-fi movie. This will never happen. We can wash it and forget it. But probably we thought that same way about COVID, you know, like just six, seven years ago, just felt like it's a sci-fi movie, until it happens.' He then cites the 12% probability: 'It's a pretty big chance. And if it burns down your electricity network and kind of mobile networks, can you take that chance?'”
“Martin Bailey notes: 'We had our own kind of pandemic, the water pandemic in July 2021. We had 400 deaths, 40 billion of damages... What went wrong there was it wasn't just the model or the foresight. It wasn't the forecasting that went wrong. It was the whole chain. It was the data. It was the decision-making. It was the action.'”
“Hieber-Girardet closes by noting: 'Digital risk has not been systematically integrated into a lot of the disaster risk management plans that we see at a country level. So there is a lot of work to be done, a lot of lessons to be learned.'”
How can countries systematically map their critical digital dependencies across sectors?
Minister Tijani identified mapping critical digital dependencies as a concrete next step for Nigeria, implying this is an under-researched and under-implemented area globally. Understanding where dependencies lie is foundational to building resilience, yet most countries lack a comprehensive map of these interdependencies.
What cross-sector stress testing frameworks exist or should be developed to simulate total digital breakdown scenarios?
Minister Tijani expressed a desire to conduct cross-sector stress tests in Nigeria before leaving office, highlighting a gap in preparedness methodology. Research into standardised stress-testing frameworks applicable across different national contexts would be highly valuable.
How should institutional coordination responsibilities be clearly defined within governments to manage digital disruptions effectively?
Minister Tijani noted the lack of clarity around which institution should lead coordination during a digital crisis, even within his own ministry. This is a governance gap that requires further research into best-practice models for institutional design and crisis command structures.
How can the risk of misidentification between physical attacks, cyberattacks, and unintentional disruptions be reduced during a digital crisis?
Ambassador Hunter highlighted that incomplete information during a crisis creates a significant risk of misunderstanding the nature of a disruption. Further research into detection and attribution methodologies, as well as communication protocols, is needed to reduce this risk and prevent unnecessary escalation.
How can cyber diplomacy frameworks and responsible state behaviour norms be strengthened to prevent digital disruptions from escalating across borders?
Ambassador Hunter raised the risk of cross-border escalation stemming from miscommunication during digital crises. Further research into the application of international law and UN norms in digital disruption scenarios, and how these can be operationalised through diplomacy, is needed.
How can trusted international networks such as CERTs and the IWWN be expanded and better utilised to share information rapidly during digital crises?
Ambassador Hunter referenced existing trusted networks but implied they are not yet universally adopted or fully utilised. Research into how these networks can be scaled, made more inclusive, and integrated into national crisis response plans would strengthen global digital resilience.
How can the lessons from the UAE's long-term investment in digital resilience be transferred to other nations, particularly developing countries?
The UAE's experience demonstrated that resilience built over decades through redundancy, diversity, and regular drills can withstand significant attacks. Research into how this model can be adapted and implemented in countries with fewer resources would be of great international value.
What is the appropriate role of broadcasting networks in national digital resilience strategies, and should spectrum allocation for critical services be reconsidered?
An audience member raised the question of whether broadcasting networks are sufficiently integrated into resilience planning. The Director General's response acknowledged the question but did not fully resolve it, leaving open the need for further research into the role of traditional broadcasting as a resilience fallback.
How can ITU's preparedness model used in cybersecurity — including national assessments, strategies, infrastructure building, and drills — be replicated for broader digital resilience beyond cyber threats?
The Deputy Secretary General outlined a chain of preparedness activities used in cybersecurity and suggested this model should be applied more broadly. Research into how this chain can be adapted for other digital disruption scenarios, such as solar storms or submarine cable failures, is needed.
How can large-scale simulations and drills be designed and implemented to make populations and institutions genuinely experience the consequences of a digital disruption?
Both the Deputy Secretary General and the moderator emphasised that drills and simulations are critical but need to be conducted at scale. Further research into the design, scope, and frequency of such exercises, and how to make them realistic enough to drive behavioural change, is essential.
What are the recommendations emerging from the ITU's international advisory board on submarine cable resilience, and how should they be implemented globally?
The Deputy Secretary General mentioned that a high-level panel on submarine cable resilience was concluding its work the following day. The recommendations from this body represent an important area for follow-up research and policy action, particularly given the critical role of submarine cables in global connectivity.
How can space sustainability and the accumulation of orbital debris be managed to protect satellite-based digital infrastructure?
The Deputy Secretary General raised the issue of space debris as an emerging risk to satellite infrastructure. This is an area requiring further technical and policy research, particularly as satellite systems become increasingly central to global connectivity and resilience strategies.
How can pre-agreed crisis protocols, emergency roaming arrangements, and infrastructure sharing agreements be standardised and scaled across mobile network operators globally?
The GSMA representative highlighted that mechanisms such as emergency roaming require significant advance preparation and coordination. Research into how these mechanisms can be standardised, pre-negotiated, and made more widely available — particularly in lower-income countries — would strengthen humanitarian response capabilities.
How can digital risk be systematically integrated into national disaster risk management plans, which currently tend to overlook it?
The moderator noted that digital risk has not been systematically integrated into disaster risk management plans at the country level. This represents a significant research and policy gap, as the absence of digital risk from these frameworks leaves countries unprepared for cascading digital disruptions.
How can the shift from fragmented, single-hazard monitoring to integrated, multi-hazard foresight be achieved using open and trustworthy AI tools?
The EU AI Office representative described efforts to move away from siloed risk monitoring towards integrated foresight, using AI tools. Further research into the methodologies, governance frameworks, and technical architectures needed to achieve this shift at scale — both within and beyond the EU — is warranted.
How can the tools and frameworks developed by the EU for digital and multi-hazard resilience be made accessible to less-prepared communities and countries outside the EU?
The EU representative acknowledged that the communities least able to cope with digital disruptions are often those with the fewest tools at their disposal. Research into mechanisms for international technology transfer, capacity building, and trusted partnerships to address this uneven distribution of resilience is critically needed.
How can the cascading effects of compound and sequential hazard events — such as droughts followed by floods, or storms following floods — be better modelled and anticipated in digital resilience planning?
Both the EU representative and the GSMA representative highlighted that compound and sequential events are already occurring and that resilience planning must account for these chains of disruption. Further research into modelling tools and response frameworks for such scenarios is needed.
What lessons can be drawn from Nigeria's experience with the Swapsea cable cut, and how can similar incidents in other countries inform global best practices for managing submarine cable disruptions?
Minister Tijani described how a submarine cable cut caused widespread disruption to banking and government services in Nigeria. Comparative research across countries that have experienced similar incidents could yield valuable insights into preparedness, response, and recovery best practices.
How can the probability and potential impact of a Carrington-level solar storm be better communicated to policymakers to drive coordinated preparedness action?
The video and the Deputy Secretary General both noted that the probability of a major solar storm is significant but that coordinated action is lacking. Research into risk communication strategies that translate scientific probability estimates into policy urgency is needed to close this gap.
How should the strategic reserve of critical hardware components, such as power grid transformers, be established and maintained to reduce recovery time after a major solar storm or other large-scale digital disruption?
The video highlighted that replacing a single transformer takes 12 to 18 months and that no strategic reserve exists. Research into the feasibility, cost, and governance of establishing such reserves — potentially through international cooperation — is an urgent area for further investigation.
