Natalija Parlov, Gordan Akrap, Josip Esterhajer
Critical infrastructure increasingly depends on digital ecosystems where external providers, artificial intelligence (AI)-based tools, and complex supply chains form the backbone of essential services. This interconnectedness generates cascading risks that surpass the scope of internal controls, exposing sectors, such as energy, water, food, healthcare, and transport to systemic vulnerabilities. Known incidents illustrate that supply chain compromise is not a theoretical possibility but persistent and growing reality. According to the authors’ practical experience in national security and sectoral information security, cybersecurity and resilience-oriented projects, organisations often struggle to recognise context of the threats in their critical services, wideness, and vulnerabilities of own supply chain and/or translate standards and new regulatory requirements into daily operational measures, which is a gap this model seeks to address. The purpose of this paper is to underline why supply chain and AI-related risks represent a systemic challenge for critical infrastructure, demonstrate how existing standards and regulatory frameworks can be synthesised into a coherent governance model and provide organisations with a practical tool that moves towards operational resilience. The chosen methodology rests on comparative analysis of chosen international standards (ISO 28000, ISO 31000, ISO/IEC 27001/27002/27005, ISO/IEC 23894, ISO/IEC 42001, and NIST AI RMF), supported by European Union obligations and recent European Union Agency for Cybersecurity [European Network and Information Security Agency] (ENISA) recommendations. Five-step supply chain security and AI risk governance model contribute structured, practical step-by-step model for strengthening systemic resilience. As an immediate step, operators should insert at least one supply chain-specific clause into their next procurement or renewal contract: a clear timeline and format for incident notification by the supplier.