Which capabilities must remain available when normal supply is disrupted?

Evidence reviewed: 15 September 2026

Australia should aim to be a dependable global partner. That ambition requires essential services that can withstand disruption and recover when systems fail.

Sovereign infrastructure is part of that foundation. Its value appears in functioning hospitals, reliable communications, accessible services and businesses that can keep operating.

Global confidence begins with dependable foundations.

The consultancy perspective connects investment decisions to operating reality. Who maintains the system? What happens when a supplier fails? How quickly can service return? These questions make a long-term national ambition concrete.

The problem and the practical response

  • Problem: Ownership alone does not establish continuity of essential services.
  • Response to assess: Define the functions that must remain available and test the capacity to operate, repair and recover them.
  • Problem: Several suppliers can share the same underlying dependency.
  • Response to assess: Map critical dependencies beyond the first contractual supplier.
  • Problem: Domestic production can still rely on imported parts, software or specialist support.
  • Response to assess: Compare local capability with reserves, repair capacity and genuinely diversified supply.
  • Problem: A backup that has never been restored may not provide useful protection.
  • Response to assess: Conduct controlled recovery exercises and measure service restoration.
  • Problem: Large infrastructure investment can displace other public priorities.
  • Response to assess: Assess the cost of each resilience measure against service criticality and plausible disruption losses.

The strategic case

For this report, sovereign capability means the practical ability to maintain or recover essential functions under disruption, with sufficient authority, access, skills and resources. It is an analytical definition, not a claim to replace statutory definitions.

Sovereign infrastructure in Australia should therefore be examined through outcomes. Operational control needs evidence. A domestic address or Australian shareholder alone cannot establish it.

Measure the ability to keep operating.

1. Existing Australian arrangements

Australia already has critical infrastructure resilience institutions. The Critical Infrastructure Security Centre describes an all-hazards approach and risk-management arrangements for relevant entities. Scope and obligations vary; this report is not a compliance determination for any operator. CISC: operating environment.

The policy question is where gaps remain in implementation, coordination and capability. Claims that Australia has done nothing would obscure both existing systems and the need to evaluate their performance.

A useful distinction separates:

  • Ownership: who holds the asset.
  • Control: who can make operational decisions.
  • Access: who can use data, tools and facilities.
  • Capability: who can operate, maintain and repair.
  • Continuity: whether essential functions remain available.
  • Recovery: how quickly and reliably service can be restored.

These characteristics may be distributed across multiple organisations.

2. Map services before assets

Critical infrastructure resilience begins with a service: water delivery, payment processing, communications, medicine distribution or another essential function.

For each service, identify upstream electricity, telecoms, data, logistics, workforce and supplier dependencies. Two cloud providers, for example, may still depend on a common identity service or local communications path.

The analysis should use authorised operator information and protect sensitive details. Public reporting can present aggregate preparedness without publishing exploitable weaknesses.

Economic sovereignty, as used here, concerns the capacity to make and execute essential economic decisions under pressure. It does not imply complete separation from global trade.

3. International approaches

Finland: coordinated security of supply

Finland’s 2026 reform of its security-of-supply arrangements describes cooperation between authorities, organisations and business. Its model connects preparedness to ongoing institutional responsibilities. Finnish Government: security-of-supply reform.

Finland’s national supply agency strategy also emphasises adapting preparedness to changing conditions. NESA strategy 2024-2027.

The transferable lesson is coordination and maintained capability. It is not a case for copying unspecified stockpile volumes or assuming every reserve is cost-effective.

Estonia and Luxembourg: continuity beyond national territory

Estonia’s data embassy uses resources in Luxembourg under Estonian control to support digital continuity. The bilateral agreement was signed in 2017. Estonian Government, e-Estonia: Data Embassy.

This illustrates that trusted international arrangements can form part of sovereignty. The relevance for Australia depends on legal control, recovery design, data requirements and service needs. It is not evidence that overseas hosting is suitable for every workload.

OECD: domestic concentration is still concentration

OECD modelling finds that broad supply-chain relocalisation does not consistently improve resilience. This supports comparing diversification and domestic capability rather than assuming one universal solution. OECD Supply Chain Resilience Review.

4. Options and trade-offs

OptionPotential useMain limit
Domestic productionDifficult-to-substitute essential itemsCost and imported upstream inputs
Strategic inventoriesTemporary disruption to storable goodsShelf life, rotation and replenishment
Diverse suppliers and routesReduce concentrationHidden common dependencies
Repair and maintenance capacityRestore equipment more quicklySkills, tooling and spare-part access
Recoverable data and servicesDigital continuityRestore complexity and operating dependencies
Mutual-assistance agreementsShared surge or recovery capacitySimultaneous demand during widespread shocks

Supply chain resilience needs an explicit time horizon. A stockpile might address weeks of disruption but not a multi-year absence of replacement technology. Domestic capability may take years to develop.

5. What would a sovereign compute assessment examine?

A data sovereignty and compute proposal would need to specify the workloads concerned. Research computing, commercial AI services and essential public records have different needs.

Compare ownership and leasing models, access to hardware, power availability, software portability, operating skills and replacement cycles. Include underutilisation and obsolescence.

AI capability is not equivalent to control over every chip, model or software component. A realistic assessment identifies which dependencies are tolerable, which require alternatives and how continuity is demonstrated.

The path towards more general AI remains uncertain. Essential services need dependable backup and recovery now. Preparing early can create options as technology changes.

6. Financial assessment

Suppose a hypothetical measure costs A$10 million annually and reduces expected annual disruption losses from A$25 million to A$18 million. Its estimated benefit is A$7 million, below its annual cost before other effects.

That does not end the analysis if the service has critical consequences not adequately captured in the loss estimate. It does require those considerations to be stated transparently.

Expected-loss models depend heavily on uncertain probabilities. Assessment should therefore include severe but plausible scenarios and sensitivity tests. Avoid presenting an invented disaster probability as observed fact.

Make the resilience premium visible.

7. Proposed assessment pathway

  • First stage: identify essential services, owners, dependencies and existing obligations.
  • Second stage: define acceptable interruption and recovery outcomes for each service.
  • Third stage: compare local capability, reserves, diversification and recovery options on consistent assumptions.
  • Fourth stage: conduct authorised exercises in controlled environments and document gaps.
  • Fifth stage: evaluate completed improvements and repeat exercises as systems change.

Measures could include time to restore service, the proportion of essential functions successfully recovered, verified inventory coverage, repair lead times and cost per improvement. Inventory counts alone are inadequate if goods have expired or cannot reach the user.

Public institutions and operators would share different responsibilities. Exact powers, procurement terms and information-sharing arrangements need detailed legal and operational design.

8. Failure modes and evidence gaps

Risks include expensive assets without trained operators, incompatible systems, unrecoverable backups and resilience claims that have never been tested.

Multiple sectors can also depend on the same constrained workforce. Building separate reserves without cross-sector coordination may create false confidence.

This report does not contain an operator-level audit, national inventory or engineering design. Those are necessary next inputs for quantifying specific capability gaps and selecting investments.

Recovery must work when it matters.

Direct answers

Must all essential infrastructure be domestically owned? This report does not establish that. Ownership is one consideration among control, access, capability and continuity.

Would a national data centre guarantee data sovereignty? No. Software, legal access, operating skills, power and recovery dependencies also matter.

What is the best first analytical step? Define the essential service and the disruption it must withstand before selecting an asset or technology.

The DivineLab Worx approach: turn setbacks into evidence

Dainu Devis founded DivineLab Worx to bring business strategy, technology and infrastructure into one practical discipline. His founding belief is simple: failures should become evidence for a better system.

The team’s guiding principle is to treat technical failures as hard engineering data. In business and public-service delivery, that also means examining costs, outcomes and people’s experience. A mistake becomes useful only when it is investigated and the lesson changes what happens next.

Record the failure. Find the cause. Test the improvement.

In essential infrastructure, controlled recovery exercises should expose weaknesses before a real disruption does. A failed restore can reveal a missing dependency, an unclear responsibility or an untested procedure.

Record the finding. Assign an owner. Test the correction. Keep sensitive details protected. The objective is a system that can demonstrate recovery under realistic conditions.

Find the weakness. Prove the repair.

This is the discipline DivineLab Worx aims to bring to Australia’s economic transformation. Tighter feedback. Clear accountability. More resilient systems. Our ambition is an Australia whose ability to learn and deliver earns trust around the world.

The long view

Australia’s global contribution can grow from reliability, useful expertise and strong international cooperation. Essential-service continuity supports that ambition at home.

DivineLab Worx’s consultancy perspective starts with the service people depend on. Map its dependencies. Assess the alternatives. Test recovery. Invest where the improvement justifies the cost.

The long-term ambition is an Australia that can support its citizens and contribute confidently to the wider world. Resilience gives that ambition a practical foundation.

Be capable at home. Be valuable to the world.

Dainu Devis

Chief Executive Officer, Sharktech Global

Dainu Devis is the Chief Executive Officer of Sharktech Global, the Australian technology group building products for a world being reshaped and displaced by artificial intelligence. Through its advisory arm, DivineLab Worx, and ventures across critical infrastructure, hospitality and industrial safety, Sharktech backs the operators, builders and businesses that intend to still be standing on the other side of the AI transition. Dainu advises operators, developers, boards and governments on where to build, what to secure, and how to turn strategy into revenue. More about DivineLab Worx and Sharktech Global.