...

Critical incident management for critical infrastructure operators

Author: Agnes Levander
Published: 8 July 2026
Last updated: 13 July 2026
Estimated reading time: ~12 min
CONTENTS

Summary

Critical incident management for critical infrastructure operators is the practical ability to mobilise the right people, skills and equipment when something goes wrong in the field. It happens in two modes, planned readiness and real-time response, and most tools on the market only handle the first. This guide explains why the second mode is where operators most often have a gap.

Ressursstyring for samfunnskritisk

What is critical incident management for infrastructure operators?

Critical incident management for infrastructure operators is the discipline of matching the right person, competence and equipment against every incident, in an operation where field workers are geographically dispersed, authorisations are strictly regulated, and a large share of the work cannot be scheduled in advance. It is not the same as IT incident management, and it is not the same as emergency management. It sits between them: the operational layer that determines what actually happens on site when an incident occurs.

For an operator of critical infrastructure, three things must line up against every incident.

The person and availability. Who is on shift, who is on call, who is tied up on another job, who is free?

The competence. Field operations in critical infrastructure are heavily regulated. Certain tasks may only be carried out by staff with specific certifications or authorisations. Availability alone is not enough. It must be the right person for that specific incident.

The equipment. Specialist vehicles, measurement instruments, spare parts. An available and authorised technician without the right equipment does not solve the incident.

This applies just as much to a water utility, a telecoms operator or a rail maintainer as to an electricity network operator.

Why is incident management harder for critical infrastructure?

Critical incident management is harder for infrastructure operators for three reasons: the geography, the competence dependency, and the unpredictability. Together they explain why tools that work well in office-based operations fall short in field operations, where staff are spread out and part of the work has not even happened yet.

The geography

Field crews are dispersed, often working alone, rarely gathered at a common hub. The person coordinating has no natural line of sight to where everyone is, and therefore cannot plan on what they can see, but only on what gets reported in.

The competence dependency

When an incident requires a specific authorisation, the pool of possible responders shrinks dramatically. The question is not who is free, but which small subset is both free and qualified. The more specialised the incident, the thinner that subset becomes.

The unpredictability

A large share of field operations can be planned: routine inspections, preventive maintenance, the on-call roster. But another share cannot. A burst pipe, a network fault, a weather event, a substation failure. And this unplanned work is often the most time-critical.

What are the two modes of critical incident management?

Incident management operates in two modes, planned readiness and real-time response, and separating them is essential before choosing a tool because they place very different demands on the system.

Planned readiness

In this mode, rosters are built, on-call lists are set, preventive maintenance is scheduled. The work is predictable and there is time to plan. The question is how the week or month adds up. Most tools on the market are built for this mode and they do it well.

Real-time response

In this mode, something has already happened. An incident is a fact, and the plan that looked fine this morning has to be redone in minutes. The question is no longer how the week looks, but who is nearest and available right now, whether that person holds the right authorisation, and where the necessary equipment is. Operators of critical infrastructure live in this mode just as much as in the planned one, and this is where tools and planning most often fall short. When an incident hits, many organisations fall back on phone calls, group chats, and personal knowledge of who tends to be where. That works, until it does not.

Real-time response: Incident management in the moment an incident occurs, when the original plan has to be reworked quickly based on who and what is actually available right now, rather than what was scheduled in advance.

Operativ beredskap

What should an incident management tool actually deliver?

An incident management tool for critical infrastructure should support both planned readiness and real-time response. Concretely, it should deliver six capabilities.

  • Real-time availability. Not just a roster set last week, but a current picture of who is on shift, occupied, free or on call right now.
  • Competence and authorisation matching. The tool should know which certifications each worker holds, so it can find not just an available person, but the right person.
  • Equipment visibility. Where are the specialist vehicles and critical equipment, and what is free to deploy?
  • A shared operational picture. Personnel, competence and equipment in one view for the coordinator, not stitched together from three sources.
  • Mobile support for the field. Those out on the job need to set status and receive assignments where they are, not from a desk.
  • Fast targeted communication. When the situation shifts, the right people need to be reached directly, often as a group assembled by relevance in the moment.

A tool that only delivers the first three is a good rostering system. A tool that also delivers the last three holds up when the plan meets reality.

What are the most common pitfalls?

The most common pitfalls are planning that lives in spreadsheets, out-of-date competence data, unknown equipment locations, and the absence of a real-time picture when an incident occurs.

Planning lives in a spreadsheet, which is a snapshot rather than a live operational picture, and out of date the second anything changes. Competence data is not current, sitting in an HR system or in someone’s head, and cannot be matched quickly when needed. Equipment location is unknown, because the organisation tracks its people well but its assets poorly. And most common of all, the real-time mode is missing altogether. The organisation has invested in rostering but has nothing for the operational minute when an incident hits.

From plan to response

Planned readiness is well served by tools, and a critical infrastructure operator should have a solid system for rosters, on-call and scheduled maintenance. This guide is not arguing against that. But the real-time response mode, incident management in the moment when the original plan has been overtaken by events, is where most critical infrastructure operations have a gap. That gap is where response capability lives or dies.

This is where GSFleet Response fits. Response gives the operations centre and the incident coordinator a real-time view of availability, competence and equipment across the whole operation, so the right resources can be mobilised quickly when an incident occurs. Field crews set status and receive assignments on their phones, the coordinator sees people, skills and equipment in one view, and the right group is reached directly. Response does not replace the rostering system, it complements it. Rostering handles the planned week. Response handles incident management in the unplanned minute.

How to get started with critical incident management

For a critical infrastructure operator looking to strengthen incident management, this is a reasonable order to work in.

  1. Separate your two modes. Map how much of your work is planned and how much is unplanned. That tells you where the biggest need is.
  2. Audit how the operational minute actually works today. When an incident hits, how do you find out who is nearest, authorised and available?
  3. Make sure competence and authorisation data is current and accessible to the coordinator, not locked in an HR system.
  4. Get visibility of your equipment, not just your people.
  5. Evaluate tools against both modes, the planned week and the unplanned minute.
  6. Enable field crews to set status and receive assignments on mobile devices, so the operational picture stays current without phone calls.

Frequently asked questions

What is critical incident management?

It is the practical ability to identify, coordinate and respond to unplanned incidents in the field, matching the right person, competence and equipment to each incident under time pressure.

How is this different from IT incident management?

IT incident management deals with digital incidents in systems and services. Critical incident management for infrastructure operators deals with physical incidents in the field, such as network faults, outages and equipment failures.

Why is incident management harder for critical infrastructure?

Because field crews are geographically dispersed, many tasks require specific authorisations, and a share of the work is unpredictable and cannot be scheduled in advance.

What is real-time response?

Incident management in the moment an incident occurs, when the original plan has to be reworked quickly based on who and what is actually available right now.

About GSFleet

GSFleet helps critical infrastructure operators across the Nordics strengthen their operational incident response. The solution is developed together with customers in sectors including energy, water, district heating and mission-critical communications.

Ready to see it in practice?

Book a demo and we will walk through how Response can strengthen your critical incident management. We show the real-time picture of personnel, competence and equipment, and tailor the demo to how your operation is organised.