Critical infrastructure · 10 min read

How should connectivity be planned for CNI and operationally critical sites?

Operationally critical sites require more than a fast circuit. The design must consider physical route independence, carrier and wholesale dependencies, secure handover, monitoring, fault escalation, restoration arrangements, maintenance and evidence that the solution can be supported throughout its life.

Prepared by CROSSLast reviewed 14 August 2026
Direct answer

Connectivity for CNI and other operationally critical sites should begin with the consequence of failure. Define the systems and users affected, required availability and restoration objectives, then design primary and backup paths with evidence of physical and operational independence. Procurement, testing, monitoring and incident management should be specified before the service is ordered.

Clarify the project classification and obligations

“Critical” is often used informally, while Critical National Infrastructure is a formal designation. Confirm the project’s security, regulatory, assurance, access and supplier requirements before determining the technical and commercial solution.

Important: CROSS should not be described as a CNI-approved supplier unless a specific approval or framework appointment can be evidenced. The service is tailored to the project’s own requirements.

Design from the consequence of failure

Identify which operational, safety, security, customer or public-service functions depend on the connection. Set the availability, restoration, maintenance and testing requirements accordingly rather than applying a generic resilience label.

Verify physical and operational diversity

  • Separate external routes and site entrances
  • Underlying wholesale networks and shared nodes
  • Common ducts, chambers, bridges, tunnels and crossings
  • Carrier POP power and environmental dependencies
  • Internal power, containment, racks and active equipment
  • Operational teams, spares and escalation routes

Specify operational assurance

The service plan should define monitoring, alarm ownership, fault detection, carrier escalation, engineering coordination, communication intervals, planned maintenance, incident reporting, root-cause review and periodic resilience testing.

Procure evidence, not labels

Ask carriers to provide route evidence, underlying network details, handover design, support model, planned-maintenance process and measurable service levels. A service described as “resilient” or “diverse” should not be accepted without supporting information.

Define responsibility boundaries

Separate external carrier connectivity from internal LAN, cyber security, OT, SCADA, protection and application responsibilities. CROSS can coordinate the external workstream, while specialist partners retain responsibility for their respective systems.

Frequently asked questions

Common questions

Does every important site count as Critical National Infrastructure?

No. CNI is a formal designation. Other sites may still be operationally critical and require similar resilience or assurance without using the CNI label.

Can CROSS provide 24/7 monitoring?

Monitoring scope, hours, response targets and engineering coverage must be agreed for each service. The website does not assume a 24/7 commitment unless it is contractually established.

Is using two carriers enough for resilience?

No. The underlying routes, wholesale networks, nodes, power, entries and operational dependencies must be verified.

Does CROSS provide cyber or SCADA monitoring?

Not by default. CROSS focuses on connectivity and carrier-service assurance and can coordinate with qualified cyber, OT and SCADA specialists.

Apply this to a live site

Send us the location, existing position and required outcome.

CROSS will identify the most useful next step without requiring you to choose the technology first.

Start the free desktop survey