inklap

Supply Chain Security and AI Risk Governance Model for Critical Infrastructure under NIS2, CER, and CRA

Natalija Parlov, Gordan Akrap, Josip Esterhajer · Applied Cybersecurity & Internet Governance · 2025

Critical infrastructure increasingly depends on digital ecosystems where external providers, artificial intelligence (AI)-based tools, and complex supply chains form the backbone of essential services. This interconnectedness generates cascading risks that surpass the scope of internal controls, exposing sectors, such as energy, water, food, healthcare, and transport to systemic vulnerabilities. Known incidents illustrate that supply chain compromise is not a theoretical possibility but persistent and growing reality. According to the authors’ practical experience in national security and sectoral information security, cybersecurity and resilience-oriented projects, organisations often struggle to recognise context of the threats in their critical services, wideness, and vulnerabilities of own supply chain and/or translate standards and new regulatory requirements into daily operational measures, which is a gap this model seeks to address. The purpose of this paper is to underline why supply chain and AI-related risks represent a systemic challenge for critical infrastructure, demonstrate how existing standards and regulatory frameworks can be synthesised into a coherent governance

📖 افتح في inklap 🔗 DOI 📮 اطلب بحثاً