When the Lights Go Out: Blackout as a Test of Modern Society's Resilience

8. apríla 2026

A large-scale power outage is no longer a hypothetical scenario. Recent months have brought a series of incidents showing that the stability of Europe's electricity systems is exposed to a combination of threats on a scale we have not previously encountered. The discussion of blackouts is therefore shifting from technical circles into the broader strategic framework of critical infrastructure protection.

The Polish Incident as a Warning for the Entire Region


At the end of December 2025, Poland faced one of the most serious cyberattacks on its energy sector in recent years. According to statements by the Polish Minister for Digital Affairs, it was a targeted attempt to disrupt the functioning of the electricity system with the clear intention of causing a power supply outage. The country managed to prevent a large-scale blackout, but the very nature of the incident significantly shifted the perception of hybrid threats in the Central European area.


Poland is not an isolated case in this regard. It is among the countries most exposed to long-term hybrid pressure, and in the first three quarters of 2025 it recorded approximately 170,000 cyber incidents. However, the attack on the energy grid crossed a new threshold and demonstrated that critical infrastructure can be the target of operations whose consequences affect millions of citizens without a single conventional military action taking place.


Anatomy of a Large-Scale Outage


The term "blackout" is often used in a simplified way in the media. From a professional standpoint, however, it refers to a precisely defined phenomenon: a sudden and unplanned collapse of the electricity system across a wide area, which exceeds the ability of standard protective mechanisms to maintain the balance between generation and consumption. It occurs within seconds, but restoring supply can take hours or even days, because the grid must be restarted gradually, block by block.


The cause is usually a chain reaction of multiple factors — technical, operational, and human. An isolated failure is generally not enough. The problem arises when several weak points coincide within a short time window which, under normal circumstances, would have been caught. This is precisely why blackouts are often described in the professional literature through the "Swiss cheese model": protective layers function properly, but if the holes in them happen to align, the system fails.


This principle was illustrated by the large-scale outage that struck Spain, Portugal, and parts of France in 2025. Approximately 55 million people were left without electricity, internet availability dropped by 80 percent, transport was seriously affected, and economic losses exceeded 1.6 billion euros. A few weeks later, a smaller but equally tangible blackout hit the north of the Czech Republic, where the outage affected one million supply points and lasted up to twelve hours.


The Cascading Effect Across Sectors


A specific characteristic of the energy sector is its position as the fundamental platform on which almost all other sectors of critical infrastructure rely. A power supply outage does not stop at the boundary of a single sector. Within hours, it affects transport, telecommunications, water management, the financial sector, healthcare, and public administration.


Backup power sources in sensitive facilities are designed as a bridging solution, not as a permanent substitute. Mobile networks gradually shut down once the batteries in their base stations are depleted. Water utilities depend on the electric drive of pumping stations. Logistics chains, which today operate on a "just in time" basis, lose their ability to respond after just a few hours. It is precisely this interconnectedness that makes a blackout an event extending far beyond the economic category of a "service outage."


The Combination of Threats Is Expanding



The risks that can lead to a large-scale outage have not only intensified in recent years but have also diversified. In addition to traditional technical causes and extreme weather events, cyber operations, physical sabotage, and hybrid activities in the grey zone between accident and intent have emerged.


At the same time, the European electricity system is under pressure from an ongoing transformation — namely, the integration of renewable sources, changes in the structure of generation, and growing demands for flexibility. This development is well-founded, but it also increases the technical complexity of managing the grid. Analysis of the Spanish blackout indicated that a key role was played by a combination of low system inertia, a shortage of stabilising sources, and limited cross-border interconnection in the region. The cause was not renewable sources themselves, but rather the way the system was prepared for their integration.


To these factors must be added long-underfunded maintenance and postponed investments in transmission and distribution infrastructure, which analysts across Europe have been pointing out. The result is an environment in which the resilience of the energy system is becoming a strategic issue of the highest order.


Slovakia in the European Context


Slovakia is an integral part of the European electricity system, and its energy interconnections with neighbouring countries are among the most developed. This brings fundamental advantages, such as greater stability, the possibility of cross-border assistance, and more efficient use of resources. At the same time, however, it means that events in neighbouring countries have a direct impact on the Slovak system as well.


The state's response is reflected in strategic documents adopted in recent months. The Resilience Strategy for Critical Entities of the Slovak Republic and the National Cybersecurity Strategy for 2026–2030 create a framework for the systematic strengthening of the preparedness of key sectors. Act No. 367/2024 Coll. on Critical Infrastructure introduces specific obligations for critical entities in the areas of risk assessment, continuity planning, and incident response. The year 2026 marks the first year of full practical application of this framework.


"The topic of blackouts has, in recent months, been moving from professional discussions into the strategic sphere. Not because we face an imminent threat of collapse, but because the combination of factors that can cause a large-scale outage has genuinely expanded. The answer is not fear, but systematic preparedness at the level of the state, critical entities, and the professional community that connects them," states Tibor Straka, President of The Critical Infrastructure Association of the Slovak Republic.


Resilience as a Shared Responsibility


Experience from recent incidents in Europe confirms several fundamental conclusions. First, the protection of the energy system is no longer merely a technical task; it is a cross-cutting strategic issue that requires coordination between operators, state authorities, security services, and professional platforms. Second, the boundary between physical and cybersecurity is gradually disappearing; an effective defence must cover both dimensions simultaneously. Third, resilience cannot be built reactively. It requires long-term investment, professional capacity, and the ability to learn from incidents that have occurred elsewhere.


It is in this context that professional platforms connecting actors operating in the field of critical infrastructure play an important role. The Critical Infrastructure Association of the Slovak Republic (AKI SR) provides a space for professional discussion, the sharing of experience, and coordination across sectors. For critical infrastructure entities, it represents a partner capable of translating complex risks into manageable measures — from vulnerability assessments to preparation for scenarios that, until recently, belonged more to the realm of theoretical analysis.


The stability of electricity supply is among the silent prerequisites for the functioning of modern society. Precisely because we usually do not notice it, it is essential to devote systematic and strategic attention to its protection.

21. mája 2026
Until recently, the security of critical infrastructure was associated mainly with the protection of physical facilities, energy sources, or state systems. Today, however, it is increasingly clear that the real vulnerability often lies outside the organisation itself: in its supply chains, technology partners, and external services.
21. mája 2026
Ešte donedávna sa bezpečnosť kritickej infraštruktúry spájala najmä s ochranou fyzických objektov, energetických zdrojov či štátnych systémov. Dnes však čoraz jasnejšie vidíme, že skutočná zraniteľnosť sa často nachádza mimo samotnej organizácie: v jej dodávateľských reťazcoch, technologických partneroch a externých službách.
18. mája 2026
In January 2024, an employee of a financial firm in Hong Kong executed a transfer worth 25 million US dollars. He did so after a video conference with the chief financial officer and colleagues from headquarters that appeared entirely authentic. Yet on the call he was the only real person. The other participants were deepfake replicas generated by generative artificial intelligence on the basis of publicly available recordings. This case, documented by the Hong Kong police, did not announce the arrival of a new threat. It announced that the threat is already here and is operating in production mode.
18. mája 2026
V januári 2024 zamestnanec finančnej spoločnosti v Hongkongu uskutočnil prevod v hodnote 25 miliónov amerických dolárov. Urobil tak po videokonferencii s finančným riaditeľom a kolegami z centrály, ktorá pôsobila úplne autenticky. Na konferencii však bol jediný skutočný človek on sám. Ostatní účastníci boli deepfake repliky vygenerované generatívnou umelou inteligenciou na základe verejne dostupných záznamov. Tento prípad, zdokumentovaný hongkonskou políciou, neoznámil príchod novej hrozby. Oznámil, že hrozba je už tu a funguje v produkčnom režime.
13. mája 2026
The Critical Infrastructure Association of the Slovak Republic is proud to present the success of two of its members, Decent Cybersecurity s. r. o. and FREQUENTIS Solutions & Services s. r. o., which have jointly secured funding for the four-year research and development project COSMOS-SECURE. The project, with total eligible expenditures of EUR 4,144,273.37 and a requested non-repayable financial contribution of EUR 2,981,048.65, focuses on an area that, until recently, belonged mainly to major space agencies: secure voice communication between ground stations, satellites, and spacecraft crews in an era when quantum computers are beginning to challenge the existing foundations of cryptography.
13. mája 2026
Asociácia kritickej infraštruktúry Slovenskej republiky s hrdosťou predstavuje úspech dvoch svojich členov, spoločností Decent Cybersecurity s. r. o. a FREQUENTIS Solutions & Services s. r. o., ktoré spoločne získali financovanie pre štvorročný výskumno-vývojový projekt COSMOS-SECURE. Projekt s celkovými oprávnenými výdavkami vo výške 4 144 273,37 € a požadovanou výškou nenávratného finančného príspevku 2 981 048,65 € sa zameriava na to, čo bolo donedávna doménou veľkých vesmírnych agentúr: bezpečnú hlasovú komunikáciu medzi pozemnými strediskami, satelitmi a posádkami vesmírnych lodí v ére, keď kvantové počítače začínajú spochybňovať existujúce kryptografické základy.
12. mája 2026
The Slovak Republic is in the final phase of a process that is fundamentally changing the approach to the protection of critical infrastructure. In accordance with Act No. 367/2024 Coll. on Critical Infrastructure, the list of entities that will be officially identified as critical for the functioning of the state is to be completed in July 2026. This step represents one of the most important milestones in the implementation of the new regulatory framework, the aim of which is to increase the resilience of key systems to crises, cyber threats and service outages. A new framework of responsibility Inclusion among the critical entities will not be of a merely formal nature. For the organisations concerned, it will mean the introduction of precisely defined obligations in the area of risk management, security measures, incident management and the very continuity of the provision of essential services within the meaning of the Act. For many entities, this represents a fundamental change in the approach to security, which will require systematic preparation even before the actual inclusion in the list. Growing interest of companies in the regulation Already in this period it is evident that potentially affected entities are beginning to intensively follow the development of the legislation and of the implementing rules being prepared. The reason is the need to set up internal processes in good time, so that the transition to the new regime can take place without major operational complications. The growing demanding nature of the requirements is at the same time increasing the demand for expert guidance and methodological support. The role of the Critical Infrastructure Association of the Slovak Republic In this context, the Critical Infrastructure Association of the Slovak Republic (AKI SR) plays a significant role, as it has long been creating a professional platform for cooperation between the state sector, regulators and operators of essential services across all sectors of critical infrastructure, such as for example energy, transport, healthcare or digital infrastructure. As Tibor Straka, President of AKI SR, states: “The process of identifying critical entities is not merely a legislative obligation. It is the moment that determines how resilient the state will be in real crisis situations.” The Association points out in this connection that the period before the final inclusion in the list is the most important one for organisations from the point of view of preparation and adaptation. Room for timely preparation Companies that may be part of the list of critical entities currently have a unique opportunity to prepare for the new obligations systematically and well in advance. In this area, AKI SR provides expert support, methodological guidance and a platform for the sharing of experience between the individual sectors. Cooperation as the foundation of resilience The implementation of the new system for the protection of critical infrastructure will be successful only if it is built on close cooperation between the public and the private sector. In this respect, AKI SR is developing a systematic dialogue with the central bodies of state administration that exercise state administration in the individual segments of critical infrastructure. With many of them, the Association has concluded memoranda of cooperation, which makes possible a more effective interconnection of expert capacities, the exchange of information and coordination in addressing key security topics. In the process, AKI SR thus acts as a natural communication and expert bridge between the regulator and the entities of critical infrastructure, while helping to connect legislative requirements with their practical implementation in the individual sectors. A new stage in the protection of critical systems The finalisation of the list of critical entities in July 2026 represents a fundamental step in the modernisation of the system for strengthening the resilience of critical infrastructure in Slovakia. The new legislative framework sets clearer rules, but at the same time significantly raises the demands placed on the preparedness of the organisations concerned. The outcome of the entire process will depend on how well it is possible to align the regulation with the reality of the operation of critical entities.
12. mája 2026
Slovenská republika sa nachádza v záverečnej fáze procesu, ktorý zásadne mení prístup k ochrane kritickej infraštruktúry. V súlade so zákonom č. 367/2024 Z. z. o kritickej infraštruktúre má byť v júli 2026 dokončený zoznam subjektov, ktoré budú oficiálne identifikované ako kritické pre fungovanie štátu. Tento krok predstavuje jeden z najdôležitejších míľnikov implementácie nového regulačného rámca, ktorý má za cieľ zvýšiť odolnosť kľúčových systémov voči krízam, kybernetickým hrozbám a výpadkom služieb. Nový rámec zodpovednosti Zaradenie medzi kritické subjekty nebude mať len formálny charakter. Pre dotknuté organizácie bude znamenať zavedenie presne definovaných povinností v oblasti riadenia rizík, bezpečnostných opatrení, incident manažmentu a samotnej kontinuity poskytovania základných služieb v zmysle zákona. Pre mnohé subjekty ide o zásadnú zmenu prístupu k bezpečnosti, ktorá si bude vyžadovať systematickú prípravu ešte pred samotným zaradením do zoznamu. Zvyšujúci sa záujem firiem o reguláciu Už v tomto období je zrejmé, že potenciálne dotknuté subjekty začínajú intenzívne sledovať vývoj legislatívy a pripravovaných vykonávacích pravidiel. Dôvodom je potreba včas nastaviť interné procesy tak, aby prechod do nového režimu prebehol bez zásadných prevádzkových komplikácií. Rastúca náročnosť požiadaviek zároveň zvyšuje dopyt po odbornom vedení a metodickej podpore. Úloha Asociácie kritickej infraštruktúry SR V tomto kontexte zohráva významnú rolu Asociácia kritickej infraštruktúry Slovenskej republiky (AKI SR) , ktorá dlhodobo vytvára odbornú platformu pre spoluprácu medzi štátnym sektorom, regulátormi a prevádzkovateľmi základných služieb naprieč všetkými sektormi kritickej infraštruktúry, ako je napríklad energetika, doprava, zdravotníctvo či digitálna infraštruktúra. Ako uvádza prezident AKI SR Tibor Straka: „Proces identifikácie kritických subjektov nie je len legislatívna povinnosť. Je to moment, ktorý určuje, ako odolný bude štát v reálnych krízových situáciách.“ Asociácia v tejto súvislosti upozorňuje, že obdobie pred finálnym zaradením do zoznamu je pre organizácie najdôležitejšie z hľadiska prípravy a adaptácie. Priestor na včasnú prípravu Firmy, ktoré môžu byť súčasťou zoznamu kritických subjektov, majú v súčasnosti jedinečnú príležitosť pripraviť sa na nové povinnosti systematicky a s dostatočným predstihom. AKI SR v tejto oblasti poskytuje odbornú podporu, metodické usmernenia a platformu na zdieľanie skúseností medzi jednotlivými sektormi. Spolupráca ako základ odolnosti Implementácia nového systému ochrany kritickej infraštruktúry bude úspešná len vtedy, ak bude postavená na úzkej spolupráci medzi verejným a súkromným sektorom. V tomto smere AKI SR rozvíja systematický dialóg s ústrednými orgánmi štátnej správy, ktoré vykonávajú štátnu správu na jednotlivých úsekoch kritickej infraštruktúry. S mnohými z nich má asociácia uzatvorené memorandá o spolupráci, čo umožňuje efektívnejšie prepájanie odborných kapacít, výmenu informácií a koordináciu pri riešení kľúčových bezpečnostných tém. AKI SR tak v procese vystupuje ako prirodzený komunikačný a odborný most medzi regulátorom a subjektami kritickej infraštruktúry, pričom pomáha prepájať legislatívne požiadavky s ich praktickou implementáciou v jednotlivých sektoroch. Nová etapa ochrany kritických systémov  Finalizácia zoznamu kritických subjektov v júli 2026 predstavuje zásadný krok v modernizácii systému zvyšovania odolnosti kritickej infraštruktúry na Slovensku. Nový legislatívny rámec nastavuje jasnejšie pravidlá, ale zároveň výrazne zvyšuje nároky na pripravenosť dotknutých organizácií. Výsledok celého procesu bude závisieť od toho, ako dobre sa podarí zosúladiť reguláciu s realitou prevádzky kritických subjektov.
11. mája 2026
In August 2023, something happened on the Polish railways that until then had belonged to the realm of scenarios, not reality. Unknown actors abused the radio system for emergency stopping (radio-stop) and transmitted a signal that brought more than 20 trains to a halt in various regions of the country. The attack required no access to digital systems and no sophisticated malware. A radio transmitter and knowledge of publicly available tones were enough. It was a demonstration of why rail transport ranks among the most complex categories of critical infrastructure. It brings together older analogue and radio technology with contemporary IT and OT systems, and each of these layers has its own vulnerabilities. 
11. mája 2026
V auguste 2023 sa na poľskej železnici udialo niečo, čo dovtedy patrilo do oblasti scenárov, nie reality. Neznámi aktéri zneužili rádiový systém núdzového zastavenia (radio-stop) a vyslali signál, ktorý zastavil viac ako 20 vlakov v rôznych regiónoch krajiny. Útok nepotreboval prístup do digitálnych systémov ani sofistikovaný malvér. Stačil rádiový vysielač a znalosť verejne dostupných tónov. Bola to ukážka, prečo železničná doprava patrí medzi najkomplexnejšie kategórie kritickej infraštruktúry. Spája sa v nej staršia analógová a rádiová technika so súčasnými IT a OT systémami a každá z týchto vrstiev má vlastné zraniteľnosti.