On 28 April 2025, the power grids of Spain and Portugal collapsed within seconds, one of the clearest demonstrations yet of how vulnerable critical infrastructure has become. The final investigation report by European grid operator association ENTSO-E, published in March 2026, points to a combination of oscillations, gaps in voltage control, and differences in grid management practices between operators. The bill was steep: Spain spent 711 million euros reinforcing its grid, while Portugal invested an additional 400 million euros, partly in battery storage. The incident turned out to be no isolated accident, but a warning sign.
In late December 2025, Poland came close to a nationwide blackout, by its own account. Prime Minister Donald Tusk and ministers Krzysztof Gawkowski and Miłosz Motyka confirmed in January 2026 that Russia-linked actors first tried to disrupt power plants and the national grid, and when that failed, shifted their attack to smaller, decentralized sources such as wind farms, solar installations, and combined heat and power plants. Poland managed to prevent a blackout, but the incident showed how targeted such attacks have become.
The Netherlands has (so far) not experienced a power outage or cyberattack of that scale, but the same kind of vulnerability is showing up here in a slower, less visible way. The summer of 2026 was one of the driest ever recorded, with a national precipitation deficit that had already exceeded 250 millimeters by July, comparable to the record year 2018. Drought is more than an agricultural or drinking-water problem: heat limits the operation of movable bridges, higher water levels reduce clearance under fixed bridges, and drying clay soil accelerates the subsidence of building foundations. The Knowledge Centre for Foundation Problems (KCAF) reports a doubling in damage reports, and estimates that between 487,000 and 537,000 properties already face elevated risk.
At the same time, maintenance backlogs on bridges, tunnels, and locks keep growing. The Netherlands Court of Audit puts the maintenance backlog at Rijkswaterstaat and ProRail, the national road and rail infrastructure agencies, at 54.5 billion euros. In January 2026 the government qualified that figure as a structural gap between required and available budget through 2038, while acknowledging the growing pressure on the safety of these structures. Drought, ageing infrastructure, and budget constraints are not doomsday scenarios. They are things that actually happened this year.
The signal: critical infrastructure under pressure everywhere at once
These three examples, Spain, Poland, and the Netherlands, illustrate what the ESPAS Horizon Scanning project (the joint early-warning initiative of the European Commission and the European Parliament) identifies as one of the most impactful signals of change for 2026: “eroding security (infra)structures”, the erosion of security and infrastructure systems that until recently seemed self-evident. The ESPAS report (Issue 10, March 2026) points, alongside climate stress and sabotage, to the United States’ retreating role within NATO and to dependence on commercial actors such as Starlink for space technology. Sweden turned back to cash as a safety net last year, precisely for this reason.
Think tank Ember calculated in September 2025 that 55 percent of the European electricity system has limited capacity to import power from neighbouring countries during a disruption. Spain, Ireland, and Finland are the most exposed. Cross-border interconnections have already prevented at least three major blackouts in the EU over the past five years, and kept the grids of Ukraine and Moldova running during Russian aggression. Those same interconnections are, for exactly that reason, an attractive target: in the Baltic Sea alone, nine sabotage incidents involving undersea cables have been recorded since 2022.
Critical infrastructure: from resilience to recoverability
For critical infrastructure, the obvious response to this kind of signal is more resilience: stronger cables, higher dikes, tighter security. ESPAS points to a different, less obvious shift. Alongside resilience, there is now growing attention for reversibility, designed failure, managed retreat from high-risk zones, and re-wilding infrastructure assets by reintegrating natural processes.
This fits a broader shift in the academic literature on critical infrastructure, from “robust design” (building a system so it cannot break) to “resilience design” (building a system so it recovers quickly once it does), as summarized in a systematic literature review in the journal Infrastructures. Managed retreat, once seen mainly as evidence of failed policy, is described in a recent study in Earth’s Future as an increasingly serious component of European climate adaptation policy. For a Dutch water authority this is not an entirely new idea, think of the Room for the River programme, but the question is whether the same principle can also be applied to power grids, digital infrastructure, and transport structures.
What does this mean for Dutch organizations?
For municipalities, water authorities, grid operators, and healthcare institutions that manage critical infrastructure, this signal arrives at an uncomfortable moment. Since 15 August 2026, the Cybersecurity Act, the Dutch implementation of the European NIS2 directive, has been in force, expanding the number of organizations with mandatory cyber-resilience requirements from roughly a thousand to about eight thousand. At the same time, the Critical Entities Resilience Act took effect, requiring organizations to map risks to their own essential services. In its Critical Infrastructure Threat Landscape of July 2025, the Dutch National Coordinator for Security and Counterterrorism (NCTV) identifies four types of threats: failure of critical processes themselves, deliberate sabotage, natural disasters, and underlying political, economic, and technological developments. At EU level, the European Commission’s Preparedness Union Strategy (March 2025) forms the overarching framework, with minimum preparedness requirements for hospitals, schools, transport, and telecoms, among others.
Most of these frameworks are still primarily aimed at resilience: keeping the system standing. The question ESPAS raises is sharper. If resilience alone is no longer enough, which systems are we willing to deliberately let fail, reorganize, or retreat from, so that the rest keeps functioning? For a grid operator, that might mean deliberately disconnecting part of the network to protect the core. For Rijkswaterstaat, it might mean that not every structure gets the same maintenance priority, but that a deliberate choice is made about which connections get restored first when something goes wrong. That is a fundamentally different planning question than “how do we prevent this from going wrong”, and it calls for scenarios in which failure itself is factored in, not just prevented.
From signal to scenario
ESPAS works out this signal using a “Futures Wheel”: one signal that, step by step, leads to further consequences. For “eroding security (infra)structures”, the report points to a growing sovereignty discourse, a lack of cross-border solutions, budget shortfalls, and the question of who bears which responsibility. That is the same method used in scenario planning and Three Horizons thinking: don’t stop at the first-order effect, but keep asking about the second and third ring of consequences.
An early-warning system only helps here if the signals are also linked to such scenarios, as we described earlier in our posts on what early-warning systems in 2026 have in common and why early warning without a scenario is just noise. Drought, maintenance backlogs, and sabotage are three signals that look unrelated on their own. Put side by side, they form a pattern: infrastructure under pressure from multiple directions at once, while existing policy frameworks are still mostly built around a single threat at a time.
In closing
ESPAS ends the signal with a provocative question: what if the EU stopped treating infrastructure networks in isolation, and instead designed them holistically so they can be quickly reconfigured? For a Dutch organization, the translation is more concrete. Which part of its own critical infrastructure, digital, physical, or organizational, is being protected today at all costs, when it might be smarter to plan for the moment it fails anyway?
Sources
- ESPAS, Horizon Scanning: Emerging issues for EU policymaking, Issue 10, March 2026.
- ENTSO-E Expert Panel, Final Report on the Grid Incident in Spain and Portugal on 28 April 2025, March 2026.
- Euromaidan Press and the Polish government, on the cyberattack on the Polish power grid, December 2025 / January 2026.
- Ember, “55% of Europe’s power system risks blackouts without improved grid interconnection”, September 2025.
- Dutch Union of Regional Water Authorities and Weeronline, on the drought of summer 2026 (Dutch-language sources).
- FunderingskaartNederland.nl and the Knowledge Centre for Foundation Problems (KCAF), on foundation damage caused by the 2026 drought (Dutch-language source).
- Dutch government, response to parliamentary questions on “Rijkswaterstaat and ProRail raise alarm: maintenance backlog exceeds 50 billion”, 20 January 2026 (Dutch-language source).
- European Commission, Preparedness Union Strategy, 26 March 2025.
- Dutch National Coordinator for Security and Counterterrorism (NCTV), Critical Infrastructure Threat Landscape, 23 July 2025 (Dutch-language source).
- Dutch National Cyber Security Centre (NCSC), Cybersecurity Act (NIS2), in force since 15 August 2026 (Dutch-language source).
- Wolff, C. et al., “Insights From Managed Retreat Projects in Europe”, Earth’s Future, 2026.
- “The Resilience of Critical Infrastructure Systems: A Systematic Literature Review of Measurement Frameworks”, Infrastructures, 2022.




