What the Updated National Risk Register Means for UK Critical National Infrastructure Operators

The July 2026 update to the UK National Risk Register introduced seven new threat scenarios, including a formal "digital resilience failure" category, and cyber attacks on water infrastructure and police systems. For operators of Critical National Infrastructure, inclusion in the NRR signals that a threat is no longer a planning option but a planning obligation. This article examines what the updated register requires of CNI operators and how a critical event management platform changes their ability to respond when the scenarios it describes become real.

Published on
July 28, 2026

What changed in the July 2026 National Risk Register?

The UK government updated its National Risk Register on 14 July 2026, adding seven new scenarios to the document that defines the threats the country must formally prepare for. Among the additions are a cyber attack on water infrastructure, a cyber attack on police systems, and a category the government has labelled "digital resilience failure", built directly from the lessons of the CrowdStrike outage in July 2024. The register also introduces new AI-related risk scenarios as advanced AI systems become more embedded in public and private sector operations across every CNI sector.

The National Risk Register is not a theoretical exercise. It underpins planning obligations for government departments, local resilience forums, Category 1 responders, and the operators of the sixteen sectors the Cabinet Office classifies as Critical National Infrastructure. When a scenario enters the register, it moves from the category of things an organisation might consider planning for into the category of things it must plan for. The July 2026 update extends that obligation into territory that many organisations have treated as unlikely or as a concern for other sectors.

Why does the register's classification of "digital resilience failure" matter?

The introduction of "digital resilience failure" as a formal NRR category is significant because it elevates a class of event that is neither a traditional cyber attack nor a natural hazard into a first-tier planning scenario. The CrowdStrike outage affected 8.5 million Windows devices in a matter of hours and disrupted airlines, hospitals, broadcasters, and financial services firms simultaneously. At the time, most organisations responded to it as a novel and unforeseeable event. It is now on the National Risk Register.

What this classification requires is not simply an IT recovery plan. A mass simultaneous IT failure affects the tools organisations use to communicate with their own people. It disrupts the channels through which incident commanders issue instructions, through which employees and contractors receive guidance, and through which executives receive situational awareness. An organisation whose incident response workflow runs through email, Teams, or Slack may find that the very event it is responding to has disabled the tools it relies on to respond. Digital resilience failure as a planning scenario demands a communication layer that sits outside the systems at risk.

What do the new cyber scenarios mean for water, energy and policing?

The inclusion of water infrastructure and police systems as specific cyber attack scenarios reflects the intelligence picture that the National Cyber Security Centre has been publishing throughout 2025 and into 2026. Water utilities, energy operators and public safety infrastructure have all appeared in that threat picture, and the updated register formalises what intelligence reporting has been indicating for some time. For CNI operators in those sectors, the NRR update creates a new standard against which their planning will be assessed.

Regulators, insurers, and government auditors will increasingly ask whether an operator has a tested response plan for a cyber scenario, and whether that plan includes the ability to reach all affected staff and contractors when digital systems are compromised. The answer to both questions requires something beyond an IT disaster recovery document. It requires a human communication plan that does not depend on the systems that may be the subject of the attack. The NRR update makes that requirement explicit in a way that internal risk registers and sector guidance have not previously done.

How should CNI operators revise their response plans in light of the update?

The practical requirement of the updated register is that CNI operators treat each new scenario as a planning trigger rather than a theoretical addition to a government document. For the digital resilience failure scenario, that means testing whether an organisation can alert, locate, and communicate with its entire workforce using a channel that operates independently of the affected systems. For the water and policing cyber scenarios, it means verifying that the incident command chain can remain operational when internal networks are unavailable or untrusted.

Operators should also review their multi agency coordination arrangements. The scenarios in the register do not affect single organisations in isolation. A cyber attack on water infrastructure will simultaneously engage the operator, local authorities, emergency services, and central government. An organisation that cannot communicate clearly across that chain in the first hour of an incident will find itself marginalised from the response. The NRR update is, in part, a signal that the government expects CNI operators to be able to demonstrate their coordination capability before an event occurs, not during it.

What does this mean for the staff and volunteer workforces managing these risks?

CNI operators employ large and often geographically dispersed workforces, including control room staff, field engineers, contractors, and volunteers embedded in community response functions. The new NRR scenarios all share a common challenge: they are the scenarios most likely to affect the communication channels these workforces rely on.

An effective response to these scenarios requires an operator to be able to reach every member of its workforce through a channel that is not dependent on the systems under threat. It also requires the ability to confirm receipt, track response, and escalate to individuals who have not acknowledged a message. These are the functions that separate a mass notification capability from an email distribution list, and the NRR update makes the case for that distinction more plainly than any internal risk assessment could.

How does AtlasNXT support CNI operators responding to the updated register?

AtlasNXT provides CNI operators with a critical event management platform that addresses the communication and coordination requirements the updated National Risk Register makes explicit. Its multi-channel notification capability delivers alerts across SMS, voice, app push, and email simultaneously, reaching workforce members regardless of which individual systems are affected. Its two-way communication function allows incident commanders to confirm that messages have been received, identify non-respondents, and escalate in real time without interrupting the wider command operation.

For the specific scenario of digital resilience failure, AtlasNXT operates independently of the standard enterprise IT stack, meaning it remains available when the systems that serve the primary workforce communication function have been disrupted. For the water and policing cyber scenarios, its integration with workforce management and access control data enables rapid population of notification lists that reflect who is on site, on call, or in a contractor role at the moment an incident occurs. For ultimate resilience, the AtlasNXT mobile command centre combined with a Starlink Mini and a PeakDo LinkPower 2 battery provides a full command and control capability even when power and internet access are down. The National Risk Register has named the threats. AtlasNXT provides the response capability.