โ† Back to Reports

Compound Cascade Risk Model

When Repairs Fall Behind: Testing Repeated Disruption Across Great Britain's Electricity, Telecommunications and Fuel Systems

A conditional simulation of cross-sector dependencies and shared restoration resources. Functional dependencies dominate; shared resources usually help; the hypothesised multiplying effect was not found.

By Jonathan Kelly ยท

Companion document

Read the executive summary โ†’

A conditional simulation of cross-sector dependencies and shared restoration resources

Distribution note. Conditional scenario analysis. Not a forecast, not an intelligence assessment, and not an estimate of the probability of any attack. Simulated outcomes are reference-scaled service-deficit contrasts, not real-world person-days. Contains no site-level infrastructure detail.


1. What this study asks and where it applies

1.1 The question

Britain's essential services depend on one another. Electricity networks need communications to see faults and direct repairs. Telecommunications need electricity and backup fuel. Fuel distribution needs power, communications and drivers.

This study asks:

If electricity, telecommunications and fuel services were disrupted repeatedly over several weeks, could repairs keep up โ€” or would unrepaired damage build while failures in one service made the others harder to restore?

More formally, the study tests which combinations of incident frequency, repair capacity and cross-sector effects move essential services from recoverable disruption into accumulating damage, and which cross-sector effect matters most.

The model does not estimate whether disruption will occur or who might cause it. It supplies hypothetical incident sequences and tests how the services recover. No probability of war, attack or disruption is calculated.

The hypothesis under test is called the repair-rate trap: incidents arrive faster than they can be repaired, a backlog builds, and failures in supporting services make the repairs slower still. The study tests this proposition; it does not assume it is true.

1.2 Geographical scope โ€” Great Britain, with UK-wide telecoms evidence

The evidence base straddles two territorial regimes and they are not interchangeable.

EvidenceTerritory
Electricity System Restoration StandardGreat Britain
Electricity (Standards of Performance) Regulations 2015Great Britain
Electricity Supply Emergency Code; National Emergency Plan for FuelGreat Britain
Distribution restoration crew figures (ENA mutual aid)Great Britain
Ofcom mobile resilience guidance and backup evidenceUnited Kingdom (telecoms is reserved)

Northern Ireland is separately regulated for electricity โ€” the Electricity (Northern Ireland) Order 1992 and the Utility Regulator, with its own Guaranteed Standards of Service [10, 11]. Conclusions about electricity and fuel restoration, emergency arrangements and mutual aid do not extend to Northern Ireland.

On the synthetic regions. The model uses four anonymised regional archetypes, one of which is labelled "separately governed / isolated" with reduced mutual-aid access. This is a declared stipulated archetype. It is not a model of Northern Ireland and must not be read as one. Northern Ireland's actual arrangements were never parameterised.

2. Why isolated sector assessments miss functional dependencies

Each sector is assessed by the body responsible for it, under the conditions that body is mandated to consider.

DomainExisting assessment or findingCross-sector limitation
Electricity restorationDistribution network operators, under GB standardsCrews already committed to a concurrent telecoms or fuel incident
Telecoms resilienceOfcom guidanceSites whose backup expires because fuel logistics are themselves degraded
Downstream fuelDESNZ resilience planningTanker cycles constrained by comms loss and crew mobility loss
Sustained, multi-sector disruptionNo published cross-sector, capacity-backed restoration standard identifiedCoordination exists, but the reviewed sources do not specify a joint restoration target or shared resource requirement

No institution is failing at its own task. Cross-sector coordination does exist: Ofcom reports joint work between telecommunications and energy bodies to improve incident planning, communications and coordination [7]. What the reviewed sources do not identify is a joint, capacity-backed standard for restoring all three services during sustained disruption below the system-shutdown threshold.

A worked instance from this study's evidence. Ofcom's resilience guidance sets no fixed minimum backup duration for mobile radio sites, framing the expectation as proportionate and risk-based under statutory duties. Separately, the Electricity Supply Emergency Code protects telecommunications only where there is a national need for continued operation, on a criterion narrower than energy or health, with inclusion discretionary rather than automatic. Read together, ordinary mobile sites not individually granted protected status fall back on whatever backup they individually hold [7, 9]. Neither regulator has erred. The exposure lives between them.

3. Four-arm experimental design and the declared-capacity baseline

The study uses a discrete-event simulation of restoration queues across three sectors, four synthetic regional types and six classes of restoration resource. Each primary run covers 90 days, including 60 days of repeated disruption followed by 30 days in which recovery can continue. At the declared reference workload, each generated incident sequence contains roughly 4,900 incidents. Incidents arrive through a stipulated scenario process. The forcing level describes that process as a ratio to the study's declared reference workload; it is not an observed incident rate, an attack probability or a measured national threshold.

3.1 The design

Two cross-sector mechanisms are separated:

  • Functional dependency โ€” one sector's failure degrades another's repair process (comms loss slowing dispatch, power loss disabling equipment, fuel loss constraining movement).
  • Cross-sector contention โ€” sectors compete for the same restoration resources.

A 2ร—2 factorial isolates them. All four arms consume the identical pre-generated incident realisation.

ArmFunctional dependencyCross-sector contentionWithin-sector contention
A โ€” declared-capacity additive baselineOffOffOn
B โ€” dependency onlyOnOffOn
C โ€” contention onlyOffOnOn
D โ€” fully coupledOnOnOn

Functional effect = Y_B โˆ’ Y_A ยท Contention effect = Y_C โˆ’ Y_A Interaction = Y_D โˆ’ Y_B โˆ’ Y_C + Y_A

Within-sector contention is active in every arm, including the baseline. Competition between regions inside a sector is part of the real restoration environment and belongs in the baseline. Switching it off would have let a well-evidenced regional effect masquerade as evidence for the weakly evidenced cross-sector one.

Total physical capacity is identical across all four arms. Dedicated pools partition the shared pool; they never replicate it.

3.2 The declared-capacity additive baseline

Terminology matters here and an earlier formulation is withdrawn. This baseline was originally described as "regulator-derived", on the premise that published restoration standards encode assumed capacity. That premise does not survive the evidence audit (ยง8). The capacity assumptions are the analyst's declared choices, and four of the six are reference-only.

The baseline is arm A of the same experiment, not a separately assembled estimate. Assembling regulator figures and comparing them to a simulation would have compared objects differing in structure, incidents, thresholds and coupling simultaneously โ€” and coupling would not have been identifiable.

4. Evidence classification and limitations

Every capacity carries an explicit evidential category.

CategoryMeaningCount
OBSERVEDExternally documented physical quantity1 of 6
DERIVEDCalculated from observed inputs through a disclosed conversion1 of 6
REFERENCE-ONLYIntroduced to define a scenario, with no claim about actual capacity4 of 6

Two-thirds of the model's resource capacities carry no claim about Great Britain at all. Results over them are reported as functions of a capacity multiplier, never as statements that capacity is or is not sufficient.

4.1 Measurement limitations that bind the conclusions

The service-deficit measure is reference-scaled. Its absolute level is not interpretable; only differences between arms are, because all four share the transformation identically. These are not real-world person-days.

The transformation is not sign-safe. Testing across four normalisation scales showed interaction signs stable โ€” but the transform inverted the sign for one sector relative to the underlying physical measures. No transformed interaction sign is reported here without its physical counterpart.

The transformation compresses at high forcing. Between forcing 0.50 and 1.50, measured service-deficit contrasts collapsed toward zero while raw impairment rose about 90-fold and resource queue-days about 122-fold. The apparent convergence is a measurement ceiling, not physical convergence. Effect sizes at high forcing understate the mechanism.

Regimes are near-deterministic away from boundaries. At the reference workload every realisation sat far from the classification threshold, so regime outcomes are effectively fixed by the arm. Near boundaries they become genuinely probabilistic. Conditional on fixed parameters this model produces classifications, not probability distributions; recovering probabilities would require a declared distribution over structural uncertainty, which does not exist here.

4.2 Source checks

Mobile-site backup percentages are now verified at source. Ofcom's February 2025 technical report estimates that around 20% of all UK mast sites have at least one hour of backup and around 5% have at least six hours [8]. The figures describe UK mobile sites, not Great Britain electricity assets. They do not establish the backup duration of every remaining site, so this study does not infer that 80% have less than one hour. Ofcom's estimate that around two-thirds could make an emergency call for up to one hour is a modelled coverage result using premises as a proxy for people; it depends on emergency roaming between networks and does not establish that two-thirds of individual sites remain operational.

Backhaul is addressed in the current guidance. Ofcom's June 2026 guidance explicitly discusses mobile aggregation and backhaul, and expects proportionate measures to reduce relevant single points of failure [7]. It does not establish a universal minimum battery duration for mobile sites or supply a quantified backhaul-restoration parameter for this model.

A widely quoted count of utility telemetry lines. Traced to source, it covers gas and electricity companies combined, undated, with no sectoral split, in a vendor information document. Withdrawn. The dependency of distribution operators on telecommunications for coordinating resources is separately and qualitatively evidenced, and that is what the study relies on.

Evidence-control note. The Ofcom primary documents were retrieved and inspected in the document-review environment after evidence register v1.4 was frozen. The project execution environment continued to return HTTP 403, so that retrieval could not be reproduced there. Evidence register v1.5 records the source upgrade and access limitation through a versioned amendment; the earlier register was not silently changed.

5. Main results, including the adverse finding

Confirmatory ensemble, 200 realisations, on a seed base reserved and untouched until after the code and its invariants were frozen. All eleven implementation checks and nine amendment invariants pass.

5.1 Functional dependency dominates

Reference-scaled service-deficit contrasts:

SectorFunctionalContentionTransformed interactionPhysical interaction: primary outcomes
Electricity+1.85 bnโ‰ˆ 0โˆ’26.5 mNegative; slightly offsetting
Telecoms+1.92 bnโ‰ˆ 0โ‰ˆ 0Negative; slightly offsetting
Fuel+2.17 bnโˆ’833 m+586 mNegative; transformed sign is misleading

The functional effect dominates in electricity and telecommunications, where the contention effect is close to zero. In fuel, the functional effect is about 2.6 times larger in magnitude than the sizeable beneficial effect of sharing resources. The effects have opposite signs: functional dependency increases the fuel deficit, while sharing reduces it; they do not add together as harms. Physical interaction directions are shown separately because the primary physical measures use different sector-specific units; they are not interchangeable with the reference-scaled figures. The fuel row makes the transformed sign reversal visible in the results table itself.

5.2 The adverse finding: synergistic amplification is not supported

The study precommitted, before the model existed, to expecting a positive interaction โ€” dependency and contention compounding.

Because the transform is not sign-safe, the interaction was recomputed on untransformed, sector-specific physical measures, in native units, never combined:

  • Primary service outcomes โ€” unserved workload and raw impairment, per sector โ€” show interaction magnitudes at or below 22% of the functional effect, and sub-additive in sign. The two mechanisms slightly offset.
  • Secondary operational diagnostics โ€” queue-days, task counts, throughput โ€” agree in direction. These are related projections of the same processes, not independent confirmations.

Note the sign reversal. In fuel the transformed interaction is positive while every physical fuel measure is negative. The transformed sign is an artefact, and reporting it alone would have inverted the finding.

One measure dissented, and resolved to compensation. Generator refuelling successfully delivered showed a positive interaction. Closing the full accounting identity โ€” activated demand = served + deferred + remainder, balancing exactly across all four arms โ€” showed the positive term in served coinciding with reductions in unmet generator demand and in electricity and telecoms impairment. More support delivered; nothing supported got worse. That is compensation inside a weakly interacting system, not harm. Its absolute magnitude is under 5% of activated generator demand.

The strong form of the repair-rate trap is not supported. Functional dependencies cause substantial harm, while resource sharing is usually neutral or beneficial; the two mechanisms do not multiply the harm in the principal physical outcomes. The complete identity remains Y_D โˆ’ Y_A = (Y_B โˆ’ Y_A) + (Y_C โˆ’ Y_A) + interaction.

6. The absorption boundary and the conditional 3.8ร— ratio

An earlier design treated the reference workload as sitting on the absorption boundary. It does not โ€” the uncoupled baseline was already past it, comfortably. That interpretation is withdrawn; the reference workload is a declared normalisation, nothing more.

The boundary was instead located empirically, defined explicitly as the 50% crossing at which the uncoupled baseline stops absorbing:

MeasureValue
Uncoupled absorption boundary0.244 of reference workload (95% band 0.201โ€“0.294)
Cross-sector binding onsetโ‰ˆ 0.935
Ratioโ‰ˆ 3.8ร—, conditional range 3.2โ€“4.7ร—

Shared cross-sector resources begin to bind at roughly four times the workload at which half of the separate-restoration runs first fail to absorb all incoming disruption.

The stated range reflects uncertainty in the absorption boundary only. The binding onset is treated as fixed and was estimated less precisely. It is a conditional range, not a confidence interval.

7. Why pooling usually helps, and when joint constraints bind

Pooling is not automatically harmful โ€” it is usually beneficial. Shared capacity moves to where demand is. Across three allocation settings for sharing resources between regions within the same sector, outcomes improved as pooling increased while total capacity stayed identical. This regional-allocation result is separate from the comparison of resource sharing between different sectors.

Contention binding and contention harming are different things. A shared pool can be fully committed while still delivering better outcomes than separate pools would have. Only the four-arm comparison distinguishes them, and the regime label alone does not.

A crossover exists for cross-sector sharing. In electricity, the effect of sharing resources between sectors changes sign close to the reference workload: pooling helps below that point, while competition dominates above it. In fuel it never crosses within the range examined. This does not contradict the beneficial within-sector regional pooling described above: the two comparisons concern different resource-allocation mechanisms. The crossover location, not the existence of sharing, is the operationally relevant quantity.

When joint constraints bind. Escaping the contention-dominated regime required relaxing both relevant pools. Relaxing the tanker-driver pool alone was never sufficient at any value tested. The boundary is a curve in two dimensions, not a threshold on either pool separately โ€” an earlier apparent feature at the reference value proved to be an artefact of coarse sampling.

8. Compensation, restoration obligations, and the sub-threshold governance gap

Three distinct instruments, frequently conflated, examined at source.

Customer compensation is in force. The Electricity (Standards of Performance) Regulations 2015 create an obligation to compensate where supply is not restored within a relevant period. They are not an individually enforceable duty to restore, and not a statement of assumed restoration capacity. The 2024 amendment shortened the interval between successive payments, not any restoration deadline [1, 2].

Exemptions are conditional, and for large incidents the most relevant are closed. The exemptions covering third-party acts, inability to obtain access and exceptional circumstances apply only where restoration action was not reasonably practicable โ€” and for interruptions affecting 5,000 or more customers those three are specifically unavailable. Deliberate interference does not automatically exempt. Other provisions may apply where their conditions are met.

A system-restoration capability standard exists. Following total or partial shutdown of the Great Britain electricity system, the system operator must be capable of restoring 60% of transmission demand in all regions within 24 hours and 100% of national demand within five days. The capability deadline is 31 December 2026 โ€” a capability deadline that had not arrived at the time of this analysis [3, 4]. Related generator resilience obligations โ€” including 72-hour resilience for critical control, monitoring and protection tools, and dedicated resilient control communications โ€” are already in force. Ofgem approved Grid Code modification GC0148 on 18 August 2023; the relevant critical-tools obligations had a separate compliance period and applied from September 2024 [5, 6]. Approval of the modification, commencement of a particular obligation and the 2026 system-wide capability deadline are three different dates.

The gap, stated precisely

The modelled campaign falls outside the shutdown-triggered system-restoration standard and has no identified cross-sector, capacity-backed restoration-time requirement. Applicable customer-compensation protections may nevertheless remain in force.

Restoration planning is not absent. Both regimes are real and one is substantial. They are scoped to different events than sustained disruption below the shutdown threshold โ€” one to individual customer outcomes, the other to system shutdown. The uncovered middle is not an oversight by either.

A scope caution on the resilient architecture. Resilient communications and 72-hour provisions apply to designated generators and restoration service providers. They do not extend to ordinary mobile sites, distribution field crews or temporary mobile generation. But they are physical infrastructure that already exists โ€” protection during sub-threshold disruption depends on whether a given asset is connected to that architecture, not on whether a formal restoration scenario has been declared.

9. What cannot be established about actual Great Britain resource capacity

The two pools that would locate Great Britain relative to the boundary in ยง7 are not publicly quantified.

  • Qualified tanker drivers available to both retail fuel delivery and generator refuelling. Named as a response tool; no capacity figure published. National driver counts describe a labour market, not a pool available to two claimants in the same period.
  • Mobile generation deployable across sectors. No government-held or government-contracted pool with stated capacity located. Commercial hire fleets exist and are substantial, but a hire fleet is not automatically an interoperable, deployable emergency pool.

No publicly defensible quantitative estimate of the cross-sector available pool was identified within the declared search scope.

This is a finding about the evidence. It is not evidence that the pools are inadequate, and it is not a claim of resource shortage. The organisations responsible may hold these figures. What is established is that the position cannot be determined from public information, and therefore that whether Great Britain sits near the boundary is currently unknowable to outside analysis.

10. Practical implications, reproducibility and withdrawn claims

10.1 Implications

Prioritise the dependency channel. The dominant mechanism is sectors degrading each other's ability to repair, not competing for resources. Measures that keep restoration functions working during another sector's failure address the larger effect by a wide margin.

Do not fragment shared resources as a precaution. Sharing within a sector improved outcomes across the regional-allocation settings tested. Sharing between sectors can also help, but its effect can change with the level of disruption. The operational question is where that crossover sits for a given pool.

Two numbers would change what can be known. The genuinely shared driver pool and the deployable generation pool. Neither requires disclosing anything site-level. Publishing them would let independent analysis locate Great Britain relative to a boundary that currently cannot be located at all.

Attend to the scope gap, not to an absence of planning. The question for policy is whether a cross-sector, capacity-backed restoration expectation should exist for sustained disruption below the shutdown threshold โ€” not whether restoration planning exists, because it does.

10.2 Reproducibility

Frozen and hashed: the incident manifest, the capacity configuration, the regime thresholds and the precommitted priors โ€” the last recorded before any simulation code existed. Eleven implementation checks and nine invariants, including a runtime test that no random number is generated during simulation, and a construction test that the baseline cannot produce the contention-dominated regime. A previous held-out set exposed an implementation defect. That set was retired to diagnostic status rather than reused for confirmation. Confirmation then ran on a fresh, reserved seed base; nine of nine sign conclusions reproduced.

10.3 Claims withdrawn during the work

Recorded because the corrections were substantive, not cosmetic.

WithdrawnReason
The reference workload is the absorption boundaryThe uncoupled baseline was already well past it
Interaction is positive in fuelPositive transformed, negative on every physical measure
Regulator-derived additive baselineCompensation thresholds do not encode restoration capacity
There is no statutory duty to restoreToo broad โ€” wider system duties and a separate restoration framework exist
Exemptions may be disapplied under deliberate attackWrong in direction โ€” for large incidents the most relevant are specifically unavailable
A campaign is covered by neither regimeOverstated โ€” customer compensation may remain in force
43,000 electricity distribution telemetry linesCombined gas and electricity, undated, no split
~80% of mobile sites hold under an hour of backupNo source establishes reporting completeness
A threshold feature at the reference capacityArtefact of coarse sampling
Regime probabilities from this ensembleRequires a declared uncertainty distribution that does not exist

10.4 A recurring error, and the rule adopted against it

The same structural mistake occurred four times: a combined quantity treated as though it described a narrower, operationally coherent population โ€” aggregating across non-substitutable resource classes three times, and once across two utility sectors in a cited figure.

Rule adopted. Before any quantity is used, state its population across five axes โ€” sector, asset class, geography, date, unit โ€” and confirm the quantity describes that population and no wider one. A combined count may not be narrowed by assertion. Where a split is not published, the quantity is unverified for the narrower use, however well sourced it is for the wider one.


Central conclusion

Under declared Great Britain-focused scenarios, functional dependencies produce larger service consequences than cross-sector resource contention, while shared resources generally improve resilience until specific joint constraints bind. The hypothesised harmful synergistic amplification is not supported by the principal physical outcomes examined. Whether real-world resource pools approach the relevant boundary cannot be established from available public evidence.

What this study does not claim

It does not estimate the probability of war or of any attack. It does not attribute any past incident. It does not claim that Great Britain has insufficient restoration capacity, that customer protections are absent, that statutory exemptions apply automatically, or that restoration planning does not exist. It does not report simulated deficits as real-world person-days. It does not extend electricity or fuel conclusions to Northern Ireland. It publishes no site-level infrastructure detail.

11. Primary sources and references

The following official sources support the legal, regulatory and territorial statements in this study. Model outputs, scenario assumptions and unavailable commercial capacity figures are not represented as externally verified facts.

  1. UK legislation, The Electricity (Standards of Performance) Regulations 2015, SI 2015/699, especially regulations 5, 6, 7 and 9.
  2. UK legislation, The Electricity (Standards of Performance) (Amendment) Regulations 2024, SI 2024/984.
  3. UK Government, Introducing a new Electricity System Restoration Standard: policy statement, 1 April 2021.
  4. Ofgem, Suite of code modifications in relation to the Electricity System Restoration Standard, 5 February 2024.
  5. Ofgem, Authority decision on modification GC0148: Implementation of EU Emergency and Restoration Code Phase II, 18 August 2023.
  6. National Energy System Operator, GC0148: Second Final Modification Report, 5 June 2023; see the discussion of 72-hour critical-tools resilience and the separate compliance period for clauses CC.7.10 and ECC.7.10.
  7. Ofcom, Network and Service Resilience Guidance for Communications Providers, 16 June 2026.
  8. Ofcom, Mobile RAN Power Resilience: Technical Report and CFI Update, 10 February 2025.
  9. Department for Energy Security and Net Zero, Electricity Supply Emergency Code, revised April 2026; especially the protected-site eligibility and approval provisions.
  10. UK legislation, The Electricity (Northern Ireland) Order 1992, SI 1992/231 (N.I. 1).
  11. Northern Ireland legislation, The Electricity (Standards of Performance) Regulations (Northern Ireland) 1993, SR 1993/448; see also the Utility Regulator's Electricity Guaranteed Standards of Service review, which describes the separate Northern Ireland regime and its statutory basis.
  12. UK legislation, Communications Act 2003, section 105A, and The Electronic Communications (Security Measures) Regulations 2022, SI 2022/933.

Weekly UK Fuel Briefing

Every Tuesday: UK reserve status, price movements, and supply-risk signals โ€” in one concise email.

Read by UK fleet operators, procurement teams, and energy analysts.