Critical Infrastructure Risk Management
Overview
Critical infrastructures are the systems and assets, whether physical or virtual, so vital to the United States that their incapacity or destruction would have a debilitating impact on our nation's security, economy, public health or safety, or any combination of those matters. In the U.S., most critical infrastructure is owned by private companies, and includes pipelines, transmission lines, power plants, hospitals, universities, manufacturers, water treatment facilities, airports, and railroads.
Contacts

Partner and Crowell Global Advisors Senior Director
- Washington, D.C.
- D | +1.202.624.2698
- Washington, D.C. (CGA)
- D | +1 202.624.2500
Insights
Client Alert | 6 min read | 09.11.26
It’s LIVE: The Cyber Resilience Act Reporting Is Mandatory as of Today - 11 September 2026
The wait is over. As of today, manufacturers of connected products (both hardware and software) must comply with the Cyber Resilience Act’s (“CRA”) vulnerability and incident reporting obligations. The CRA’s Single Reporting Platform (“SRP”), operated by the European Union Agency for Cybersecurity (“ENISA”), is now the EU-wide gateway through which those notifications must flow.
Client Alert | 13 min read | 06.12.26
Firm News | 1 min read | 06.11.26
Crowell & Moring Partner Emma Wright Appointed to UK Government's Digital ID Advisory Group
Firm News | 7 min read | 06.04.26
Insights
Critical Infrastructure: Updating the 2013 NIPP and other Risk Mitigation Actions
|05.14.24
Privacy and Cybersecurity Outlook: The 2024 Landscape
- |
12.02.14
Crowell & Moring's Data Law Insights
Professionals
Insights
Client Alert | 6 min read | 09.11.26
It’s LIVE: The Cyber Resilience Act Reporting Is Mandatory as of Today - 11 September 2026
The wait is over. As of today, manufacturers of connected products (both hardware and software) must comply with the Cyber Resilience Act’s (“CRA”) vulnerability and incident reporting obligations. The CRA’s Single Reporting Platform (“SRP”), operated by the European Union Agency for Cybersecurity (“ENISA”), is now the EU-wide gateway through which those notifications must flow.
Client Alert | 13 min read | 06.12.26
Firm News | 1 min read | 06.11.26
Crowell & Moring Partner Emma Wright Appointed to UK Government's Digital ID Advisory Group
Firm News | 7 min read | 06.04.26






