Skip to content
WINNIIO
← Insights

Seven design requirements for national resilience — knowledge as the second infrastructure, fallback autonomy, governed dual-use conversion, federated sovereignty and contested-reality operations. Nation-agnostic, with Sweden as the worked example.

The Resilience Musts of a Nation

By Nicolas Waern, CEO — WINNIIO AB Published: August 2026 · ORCID 0000-0001-7970-2707 · CC BY 4.0


A note on method before anything else. This paper is nation-agnostic. Sweden appears only as a worked example, and every Swedish passage is labelled as one. Where I use a scenario, it is labelled a scenario. Where I use a composite firm, it is labelled a composite. Where a number would help but I cannot source it, the gap is marked in the text instead of papered over. A resilience paper that fakes its own evidence has already failed at its own subject.

1. Start with a day when nothing was attacked

On 28 April 2025 the Iberian peninsula lost roughly 15 gigawatts of generation in about five seconds (Red Eléctrica; ENTSO-E, 2025). Trains stopped. Payments stopped. Telephony degraded within hours. Nothing had been bombed. The hardware was intact the entire time.

That day is the cheapest resilience lesson any planner will ever get, because nobody had to die for it. A modern nation can be stopped without a single strike on a single asset. The things that stopped Iberia were not objects. They were relationships between objects — frequency, timing, authentication, coordination — and the knowledge of how to bring a continent-scale machine back when those relationships fail.

And here is the verdict this paper asks you to test: most national resilience planning audits objects. Outcomes are decided by whether the knowledge and the connections that make objects usable survive contact. NATO Article 3 obliges every ally to "maintain and develop their individual and collective capacity to resist armed attack" (North Atlantic Treaty, 1949). Every ally reads that as stockpiles, redundant grids, hardened sites. Almost nobody reads it as an obligation to audit where the knowledge of operating all of it actually lives. It lives, overwhelmingly, in heads. Heads retire. Heads get sick. Heads can be coerced, recruited, or killed. But heads never appear on an asset register.

2. The thesis: resilience is not acquired. It is relocated.

You do not buy resilience. There is no procurement line that delivers it, no platform that installs it. What a nation can actually do is relocate its operating reality — out of individual heads, out of single sites, out of foreign clouds — into artifacts the nation owns, can reach, and can act from when the normal channels are gone. Michael Polanyi said it in one sentence sixty years ago: "we know more than we can tell" (Polanyi, 1966, p. 4). A nation's real capability is exactly the part its institutions cannot tell. Relocating that part into owned, structured, reachable form is the whole game. Everything else in this paper is mechanism.

Why now? Because the exception has become the operating mode. The United States logged 27 separate billion-dollar weather and climate disasters in 2024, against a long-run average of about nine per year; the interval between such events has compressed from one every 82 days in the 1980s to roughly one every 12 days (NOAA NCEI, 2024). Munich Re put 2024 global losses at about $318 billion, roughly $140 billion of it insured, 93 percent weather-related (Munich Re, 2025). A system designed for one such event per season, repaired at leisure, is being asked to absorb one every twelve days. Degraded operation is no longer an exception state. It is the state the architecture must hold by default.

And the second reason is slower and quieter than any storm: the people are leaving. The average American welder is about 55 years old (American Welding Society). Deloitte and The Manufacturing Institute project 3.8 million manufacturing jobs to fill in the US by 2033, of which 1.9 million may go unfilled (Deloitte & The Manufacturing Institute, 2024). The WHO projects a global shortfall of roughly 10 million health workers by 2030 (WHO). Every one of those retirements is a small, silent transfer of national capability into the grave of undocumented experience. Nothing breaks on the day the veteran leaves. That is the trap. The margin erodes without an alarm attached to it.

Can this be fixed during the crisis, when the need is finally obvious? No. Externalized knowledge, rehearsed fallbacks, governed conversions — all of it is the product of learning that accumulates for months and years before the disruption. You cannot build this capability in a crisis. You build it before the crisis, which means building it now.

The rest of this paper states seven requirements. They are design requirements, not aspirations, and they are industry-agnostic and nation-agnostic. Sweden appears as the worked example because it is the nation I know from the inside — a country that joined NATO in March 2024 and rebuilt its total-defence doctrine in Government Bill Prop. 2024/25:34 — and because its gaps are typical, not unusual.

Too long a list? Read the seven headings and the closing procurement clauses. Then come back for the mechanisms.

3. The seven musts

Must 1 — Knowledge must be audited as infrastructure

Every resilience domain has two dimensions. The asset dimension: machines, sites, stockpiles, networks. And the knowledge dimension: the tacit, head-held understanding of how to operate, restart, adapt and repair the assets. Defence planning inventories the first dimension to the bolt. The second dimension — equally load-bearing — appears in no inventory anywhere. It is the invisible second defence infrastructure.

[FIGURE NEEDED — verify: two-axis diagram, asset dimension × knowledge dimension, with example capabilities placed by how well each dimension is secured]

A factory whose equipment survives but whose key people are gone is as dead as a bombed factory. Worse, actually — the bombed factory gets a reconstruction budget, because the damage is visible. The knowledge-dead factory gets nothing, because on every register it still exists.

And the adversary has already understood this. Targeting the two or three individuals who hold unrecoverable process knowledge is cheaper than targeting the plant, and the target list can be assembled from a supply-chain map, a company registration and a LinkedIn search. Coercion, recruitment, removal. Externalizing the knowledge is attack-surface reduction in the most literal sense: it converts an unrecoverable loss into a recoverable one.

The audit itself needs no technology at all. Which processes are held by a single person? Which planning functions are one-person systems? What could not be reconstructed from documentation if the holder disappeared tonight? The whole instrument compresses into one question a ministry can put to every critical supplier: if your three most critical people are unavailable tomorrow, how long before you can produce again? Any supplier that cannot answer has told you the answer.

Can a nation recruit its way out instead? No. Absorptive capacity is the reason (Cohen & Levinthal, 1990): an organization that never codified its knowledge has nothing for a replacement to plug into. The new hire arrives, and the thing she was hired to absorb does not exist in absorbable form. Knowledge conversion — tacit to explicit, explicit back to shared practice — is a discipline with a forty-year literature behind it (Nonaka & Takeuchi, 1995). It is not applied because it has never been anyone's line item.

Worked example — Sweden. Prop. 2024/25:34 rebuilds total defence across every sector: energy, food, transport, health, industry. Read it with the two-dimension lens and the pattern is immediate — it hardens the asset dimension throughout, and the knowledge dimension is absent as a category. Sweden is not unusual in this. I have not found any nation whose defence doctrine treats knowledge as auditable infrastructure. [SIFFRA SAKNAS — verifiera: nationell statistik över andel certifierade industrispecialister nära pensionsålder i Sverige]

The requirement: mandate the knowledge audit — holders per process, degree of externalization, reconstruction time — as a condition of every resilience grant and every critical-supplier contract, before any technology is funded.

Must 2 — Critical production must have a fallback to autonomy

Here is the distinction most digitalization programmes miss: digital is not the same as externalized. An organization can be fully digital while its operating reality is still carried — by a person, a veteran cohort, a vendor — instead of held in an artifact the organization owns.

Worked example — a composite firm. Take a mid-sized steel fabricator somewhere in Sweden. It is a composite, drawn from real engagements in Swedish manufacturing, and it stands here as an archetype, not a case report. Production planning lives in one planner and one spreadsheet only that planner can truly operate. The certified welders hold the tolerances in their hands and ears. The firm is a second-tier supplier to defence contractors, which makes it part of the national defence capability whether anyone ever told it so. If the planner leaves, if he is sick, if he quits — the plan leaves with him. The spreadsheet stays. The spreadsheet was never the knowledge.

This is what a digital twin is actually for. The twin is not the 3D model on the trade-show screen and it is not another cloud dashboard. It is the externalization of head-held knowledge into a structured, persistent, on-premises record that survives any individual's departure — anchored to the exact place where the work happens, because the knowledge is where the work is. The concept has a proper lineage (Grieves, 2014) and a proper taxonomy separating models, shadows and twins (Kritzinger et al., 2018). Use the lineage. Ignore the trade-show version.

And externalization is the precondition for the fallback that matters most in a mobilization scenario: fallback to autonomy. The chain is strict. Knowledge is externalized. Externalized knowledge becomes encoded specifications. Machines and skill models execute from those specifications when the people are pulled away. A mobilization order does not reach an encoded specification. It keeps producing. But no machine can fall back onto knowledge that was never externalized. Skip the first link and the whole robotics budget buys you nothing on the day it was bought for.

One trap inside the fallback: a skill model that only runs in a vendor's cloud has not removed the person-dependency. It has moved the dependency abroad and added a subscription. Rented knowledge is not resilient knowledge. The fallback must execute on hardware the firm owns, on the site where production happens, under the partition conditions of Must 6.

The requirement: for every production capability designated critical, the nation must be able to answer — what fraction of this process is encoded in owned, executable, locally-runnable form, and has the fallback ever actually run?

Must 3 — Dual-use assets must be reprogrammable, and the conversion governed in advance

Every nation is surrounded by peacetime machines that are hardware-capable of crisis work. A parcel drone can carry insulin — the hardware is the same. An agricultural robot can clear debris. A district-heating optimizer can ration. So why does almost none of this capacity convert when the crisis comes?

Because conversion fails on three layers, and none of them is hardware. Take the drone as an illustration — an illustration, not an incident report. First, its operating-environment model is calibrated to the wrong geography; a machine that flies logistics corridors knows nothing about the hospital's approach paths. In Europe the base layers to fix this exist as public geodata under the INSPIRE directive (2007/2/EC) — the work is integration, not collection. Second, the authorization and triage logic for crisis tasking was never built; who may redirect the fleet, under whose liability, against which priority list? Third, the regulatory pathway was never prepared; emergency extensions under frameworks like EASA's U-Space (Opinion 01/2021) must be negotiated in peacetime and represented inside the asset's own operating model, so that the machine itself knows which regulatory state it is flying under. Crisis conversion is a knowledge and governance problem. It is solved beforehand or not at all.

Beneath the governance sits a harder ownership test: reprogrammability equals open format, plus local control, plus the legal right to change. An asset whose operating logic sits in a proprietary blob, alterable only with vendor authorization from another jurisdiction, is a peacetime asset. It does not matter what the brochure says about dual use.

The standards for doing this without inventing anything already exist. The Asset Administration Shell (IEC 63278-1) makes an asset's digital representation portable and machine-actionable across toolchains; ISO 23247 frames manufacturing twins; RAMI 4.0 (DIN SPEC 91345, 2015) gives the reference architecture. And the same lifecycle data that satisfies a resilience mandate satisfies the EU Digital Product Passport under ESPR (EU) 2024/1781 — a nation that mandates open asset representations pays once and collects twice, with the Critical Raw Materials Act (EU) 2024/1252 adding a third reason to know what your industrial base contains.

Two extensions follow almost for free. A federated capability registry: every firm registers what it can do — material, process, tolerance class — never the proprietary geometry, so the state can task capacity in a crisis without any firm surrendering its IP. And pooled additive manufacturing as a strategic spare-part reserve: no single small firm justifies a metal printer, but a consortium pooling spare-part demand across a shared parts ontology does, and the economics flip entirely once unplanned downtime is priced honestly — reactive maintenance runs at three to nine times the cost of planned intervention (Mobley, 2002). When import chains are cut, distributed printing capacity is the difference between a waiting list and a workaround.

Must 4 — The national capability must be federated: a sum of sovereign nodes, not a central database

Ashby settled the theory in 1956: only variety can absorb variety (Ashby, 1956). A distributed, adaptive, cheap threat cannot be met by scaling up a centralized defence, because the centralized defence inherits centralization's fragility — one budget, one bottleneck, one target. A distributed threat requires a distributed response that matches its variety, cost and tempo.

And the empirical record on the centralized alternative is consistent. Every attempt I have watched to build the one national platform, the one rigid taxonomy, the one database all actors must feed dies the same death — not at the technology stage, at the governance stage, because sovereign entities will not surrender their operating data to a central point regardless of technical merit. They are right not to. At Volvo they had about 100 data scientists all responsible for different parts of the truck. The problem was that they never understood that they were working with a truck. Centralizing the data would not have fixed that. A shared artifact describing the truck would have.

So the design inverts. Every nation, every municipality, every company, every person will have their own AI models, their own agents and their own data — their own context is the most important thing. The national capability is the sum of those sovereign nodes, connected at deliberately minimal seams. Specify the fewest points where two systems must agree; everything behind each seam stays sovereign. The seam, not any single stack, is what a nation actually signs.

Three mechanisms make federation hold. First, boundary objects (Star & Griesemer, 1989): one structured artifact that a welder, a plant manager, a defence planner and a regulator can each read in their own terms — build one structure many communities read, never one report per audience. Second, commons governance compiled into software: Ostrom showed how commons survive without central owners — monitored contribution, graduated sanctions, nested decision layers (Ostrom, 1990) — and those rules can be enforced by the infrastructure itself instead of by exhortation. Third, incentives that grow the mesh without a central planner: individuals deployed roughly 900,000 radio hotspots for the Helium network by 2022 under token incentives with a falsification-resistant proof of contribution (Helium Foundation) — proof that citizen-built infrastructure scales when the reward mechanism is honest, and its governance troubles are part of the same lesson.

But do not romanticize voluntary federation either. When Hurricane Helene took down 48.7 percent of cell sites in the affected area, roaming between competing operators had to be mandated by the regulator (FCC, DOC-406055A1, 2024). Voluntary interoperability fails under load. The seams must be negotiated, contracted and rehearsed in peacetime — which is Must 7's business.

The oldest proof that federation works predates every digital platform: Kalundborg's industrial symbiosis, where firms exchange energy and material streams across a whole industrial district, grew over decades through bilateral agreements between sovereign neighbours — no master plan, no central database, and it has outlived every centralized integration fashion since (Ehrenfeld & Gertler, 1997).

A federated capability has one more property planners undervalue: it gives the adversary nothing central worth taking.

Must 5 — The person must be a sovereign data node

Every civic-sensing and population-resilience programme dies on the same rock: surveillance. Citizens will not feed a state database with their sound, movement and health, and they are right to refuse. The architecture that survives contact with a free society is the inverted one — the person is a node, not a source. Personal data should never be shared. Ever. The experts, the models and the queries travel to the data. The data stays.

This is buildable today, at three architectural levels, none of them a policy promise. Inference runs at the edge, on the citizen's own device — the computer-science case for edge was settled years ago (Satyanarayanan, 2017). Only derived detection objects leave the node, never raw streams; a feature-extraction step is, in practice, a privacy filter. And whatever aggregate learning the network needs can be done under differential privacy, with mathematically bounded leakage (Dwork & Roth, 2014). Identity itself can stay sovereign under the W3C Decentralized Identifiers standard (DIDs v1.0, 2022). Architecture decided at this level is a constitutional commitment about what the system is permitted to know. Write the constitution in the architecture, and no future administration can quietly amend it.

What does a sovereign node contribute to national resilience? Sensing, first. Ukraine demonstrated that fused civilian smartphone reports can track airborne threats across a country — a population as a distributed sensor grid, contributing structured observations without surrendering private life. The schema is the whole trick: a node emits equipment class, compressed signature, time and recommended action — explicitly never identity, never location beyond what the observation requires, never raw audio. Design the include/exclude schema first and publish it, and the surveillance objection is answered before it is raised. This is the digital successor of the volunteer defence tradition every resilient nation already has.

And beyond sensing: the same sovereignty applies to the citizen's own continuity. Health records, competence records, the externalized knowledge of Must 1 — all of it belongs on nodes the person controls, reachable by the person under partition, shareable by consent and by computation rather than by copy. A nation of sovereign nodes is not harder to defend than a nation with a central register. It is dramatically easier, because there is no register to take.

Must 6 — Everything must operate in contested reality

Assume an adversary. Not as a slogan — as a design input for every layer. Four contests are already live.

The time base. GPS is the hidden clock of modern infrastructure; 5G alone needs timing on the order of 240 nanoseconds, GNSS-sourced (NIST TN 2189). In May 2024 the Gannon storm — the first G5 geomagnetic storm in more than two decades (NOAA SWPC, 2024) — degraded high-accuracy GNSS positioning down to about latitude 49°N for 15 to 20 hours (Yang et al., 2025). A single natural event attacked timing and grid simultaneously, and everything north of 49°N sat inside the band. Worked example — Sweden: the entire country lies north of that line. The requirement writes itself: holdover clocks and non-GNSS time distribution for critical infrastructure, tested against the jamming and spoofing an actual adversary adds on top of what the sun does for free.

The legal layer. The US CLOUD Act (Pub. L. 115-141, 2018) empowers US authorities to compel US providers to produce data in their possession regardless of where it is stored. Read that twice. The contract, the region label and the encryption marketing are irrelevant; jurisdiction follows the provider, not the datacenter. For a nation's aggregated industrial and defence-adjacent data, hosting with a foreign provider is a structural exposure that no clause can fence off. Physical custody is the only sovereignty mechanism that holds under conflict. The software may be open source and internationally shared — the data is sovereign.

Reachability under partition. The cloud-versus-local debate is the wrong axis; a cloud region and a local server are both single places. The right axis is whether the people who need the operating picture can still reach it when the network fragments and the power fails. So make it a test — a single, binary, falsifiable acceptance criterion: does the readable model of this operation survive simultaneous loss of network and power at the node? "There is a cloud backup" fails the test, because the path is what failed. So does the subtler chokepoint: an attack on authentication can leave the data intact on servers the attack never touched, while nobody who needs it can log in for hours. Reachability means the whole chain, credentials included. Ukraine is the field evidence on both sides: attacks destroyed large parts of the grid — the ITU documented damage reaching roughly 65 percent of it — yet national roaming across competing operators stood up in about a week, because capability was dispersed and the seams existed (ITU, 2023). And the Kyivstar wiper of December 2023, which took roughly 24 million subscribers dark (CERT-UA, 2023), proved that no operator, however large and professional, is a sanctuary. Winter storm Uri showed the cascade version: roughly 10 million people lost power and 49 percent of Texans lost water, gas failing electricity failing everything downstream (Busby et al., 2021). Power is not one utility among several. It is the substrate the others silently assume — and the network that would report the failure fails with it.

The archive. Everything a nation externalizes under Musts 1 and 2 becomes a target with a long shelf life. An adversary recording encrypted traffic today decrypts it the day quantum hardware allows — harvest now, decrypt later. A fifty-year secret encrypted with a ten-year lock is not a secret; it is a scheduled disclosure. The response ships today: NIST finalized the post-quantum standards FIPS 203, 204 and 205 in August 2024. The requirement is post-quantum encryption from the first byte on every long-lived archive — health data, grid topologies, industrial knowledge — plus crypto-agility so the next migration is a configuration change, not a decade. Retrofitting an archive that has already been exfiltrated protects nothing.

One quieter contest belongs here too: the reference state. The oldest sensor on any factory floor is the operator's ear, trained on years of normal. An attack on a physical control system succeeds most easily where nobody can say what normal is. Baselining normal — acoustically, thermally, operationally — into the owned record is cyber defence, whatever budget line it sits on.

Must 7 — No simulation may become history

Everything above leans on models, twins, scenarios and rehearsals. Which creates the discipline problem this must exists for: no simulation may ever harden into history. A scenario drafted for an exercise gets quoted in a briefing, the label falls off, and two documents later the nation is planning against an event that never happened. I have watched synthetic numbers outlive their own watermarks. The rule must be mechanical, not cultural: every figure carries provenance; every synthetic dataset is watermarked in the data, not the caption; every scenario is labelled a scenario at every appearance, not just the first.

Simulation always works or doesn't work based on emulation. You have to emulate reality first — the actual current state, holes and all — before any simulated future deserves belief. And this is also the argument for simulation, done honestly: planning on historical statistics fits a smooth curve to a fixed past, and the frequency data in Section 2 says the past has stopped being a projection of anything. A nation that can only extrapolate yesterday is defenceless against the first genuinely new Tuesday. The whole point is that you can try things out in a virtual copy of reality before you do something in reality — run the disruption in the sandbox, let the sandbox absorb the failures, and let the learning accumulate where it costs nothing.

But only if the rehearsal is real. A failover path that has never been exercised is a hypothesis, not a capability. So the policy form is an exercise calendar, not a document: an annual partition exercise for every critical service — cut the network and the power for real, at the node, and observe what the operators can still reach and still decide. Publish the pass/fail. The test from Must 6 is binary precisely so that it cannot be narrated around.

Two disclosure rules complete the discipline. Every claim in a resilience programme ships with its evidence tier — deployed, demonstrated, or speculative — and a falsification condition; an unfalsifiable resilience claim is marketing. And every AI or optimization result ships with its benchmark, its baseline and its weighting method, because aggregates hide exactly the failures worth fixing: a system optimizing against a flattering average will confidently repair the wrong thing. Demand attempt-weighted metrics in national KPIs and the confident wrongness becomes visible.

The argument earns trust by marking its seams. So does the nation.

4. The methodology layer: one grammar, many instances

Do the seven musts need a single vendor, a single platform, a national programme office? No. They need a shared grammar — an open, vendor-neutral method for moving operating reality into owned artifacts, applied instance by instance, sector by sector. Mine is SMILE, published open with a citable record (v6.4.3, DOI: 10.5281/zenodo.21757691; concept DOI: 10.5281/zenodo.20175405). It is free to implement and it obeys its own rule: if a better grammar exists, swap it in. A methodology that demands loyalty has already violated Must 4.

[FIGURE NEEDED — verify: the relocation chain as one diagram — head-held knowledge → elicited record → encoded specification → autonomous execution under partition — with the seven musts mapped onto its stages]

Three instances, honestly labelled.

Manufacturing. The composite fabricator of Must 2 is where the grammar was ground down to practice. Scan the geometry first — the 3D scan gives operators a spatial vocabulary and defuses the surveillance suspicion before a single question is asked — then anchor the elicited judgment to the exact station where it applies. Start deliberately under-ambitious: a digital shadow before any twin (Kritzinger et al., 2018), observation before intervention, read-only integration over the incumbent spreadsheet so its owner becomes a participant instead of a casualty. And the finding that matters most for programme officers: no technology solves this. Facilitation does. Fund hardware without funding facilitation and you will fund a very expensive way of producing nothing.

The person. Life Atlas applies the same relocation to a human life. I call it life care rather than healthcare, because health systems model episodes and a person is a continuous system. The record is edge-native and sovereign in exactly the Must 5 sense: the person's data stays on hardware the person controls, experts and models travel to it, every inference is explainable and grounded in retrieval rather than generation. The mechanistic simulation layer — today an engine called M4, best in its class — is architecturally swappable, because no resilient design depends on a single engine, including the best one. Five beta users today. I write the real number because Must 7 applies to me first.

Networks and optimization. In a dense-urban Open RAN deployment with a major Asian operator, I have applied the same discipline to quantum optimization of radio-network combinatorics. The problems genuinely fit the quantum formulation. And the honest result so far: classical optimization won on wall-clock time and cost, on a mobility layer that was synthetic and watermarked as synthetic. Quantum enters production the day it beats the classical incumbent on the same instance — wall-clock, cost, reproducibility, disclosed. I co-chair a quantum working group within the Digital Twin Consortium, and this benchmark-gated stance is the position I argue there. A nation buying "quantum readiness" without mandatory benchmark disclosure is buying Must 7 violations in bulk.

One grammar. Sovereign instances. Minimal seams. That is what a national capability looks like when nobody owns the middle.

5. Sovereignty is architecture, not policy

Policies are promises about behaviour. Architecture is a constraint on what behaviour is possible. Under pressure — legal pressure, kinetic pressure, commercial pressure — promises renegotiate and constraints do not. The CLOUD Act does not care what your data-protection policy says; it cares where jurisdiction sits (Pub. L. 115-141, 2018). A geomagnetic storm does not read your timing SLA (NOAA SWPC, 2024). A mobilization order does not exempt your one irreplaceable planner. Every must in this paper is the same sentence wearing different clothes: put the capability where no signature, no outage and no adversary can revoke it.

For the programme officer who needs this on one page, the musts compress into six clauses any procurement can carry tomorrow:

1. Edge-native execution — critical functions run on-site, cloud optional, never load-bearing. 2. The partition test as acceptance test — simultaneous loss of network and power at the node, passed before payment, repeated annually. 3. Post-quantum encryption at the archive, from the first byte (NIST FIPS 203/204/205, 2024). 4. Open, portable asset representations (IEC 63278-1) — conformance demonstrated, not asserted. 5. Data egress in open formats within the recovery time objective — the exit is part of the product. 6. Benchmark, baseline and weighting disclosed for every AI and optimization claim.

Six sentences. Any nation can sign them this year. And the audit of Must 1 costs an interview protocol and an org chart before it costs a single crown, euro or dollar.

Because the summary of the whole paper fits in four short sentences. The physical assets will mostly survive. The knowledge is leaving on a schedule already visible in the retirement statistics. Relocating it into artifacts the nation owns is achievable with standards, methods and hardware that exist today. And you cannot build this capability in a crisis — you build it before the crisis, which means building it now.

The methodology is open. The DOI is public. Take it, implement it without asking me — and where I am wrong, prove it. That would help too.

Sincerely, Nicolas Waern


References

  • North Atlantic Treaty (1949), Article 3.
  • Sweden's accession to NATO, March 2024 (public record).
  • Regeringens proposition 2024/25:34, Totalförsvaret 2025–2030 (Sweden; worked example only).
  • Clarifying Lawful Overseas Use of Data (CLOUD) Act, Pub. L. 115-141 (2018).
  • NIST, FIPS 203 / 204 / 205, post-quantum cryptography standards (August 2024).
  • NIST Technical Note 2189 — timing requirements for 5G (~240 ns).
  • NOAA NCEI, Billion-Dollar Weather and Climate Disasters (2024 data: 27 events; long-run average ~9; interval compression 82 → 12 days).
  • Munich Re (2025), natural catastrophe figures for 2024 (~$318B total, ~$140B insured, 93% weather-related).
  • Red Eléctrica / ENTSO-E (2025), preliminary reporting on the Iberian outage of 28 April 2025 (~15 GW in ~5 s).
  • NOAA SWPC (2024), May 2024 (Gannon) G5 geomagnetic storm.
  • Yang et al. (2025), GNSS high-accuracy degradation to ~49°N for 15–20 h during the Gannon storm.
  • Busby, J. et al. (2021), "Cascading risks: Understanding the 2021 winter blackout in Texas," Energy Research & Social Science (~10M without power; 49% of Texans without water).
  • ITU (2023), assessment of Ukraine's connectivity and energy infrastructure under attack (~65% grid damage; national roaming in ~1 week).
  • CERT-UA (2023), Kyivstar incident, December 2023 (~24M subscribers affected).
  • FCC, DOC-406055A1 (2024), Hurricane Helene communications status (48.7% of cell sites down; mandated roaming).
  • Polanyi, M. (1966), The Tacit Dimension, p. 4.
  • Nonaka, I. & Takeuchi, H. (1995), The Knowledge-Creating Company.
  • Cohen, W. & Levinthal, D. (1990), "Absorptive Capacity: A New Perspective on Learning and Innovation," Administrative Science Quarterly.
  • Star, S. L. & Griesemer, J. (1989), "Institutional Ecology, 'Translations' and Boundary Objects," Social Studies of Science.
  • Ashby, W. R. (1956), An Introduction to Cybernetics (law of requisite variety).
  • Ostrom, E. (1990), Governing the Commons.
  • Ehrenfeld, J. & Gertler, N. (1997), "Industrial Ecology in Practice: The Evolution of Interdependence at Kalundborg," Journal of Industrial Ecology.
  • Grieves, M. (2014), digital twin concept white paper.
  • Kritzinger, W. et al. (2018), "Digital Twin in manufacturing: a categorical literature review and classification," IFAC-PapersOnLine.
  • Mobley, R. K. (2002), An Introduction to Predictive Maintenance (reactive maintenance at 3–9× the cost of planned).
  • Dwork, C. & Roth, A. (2014), The Algorithmic Foundations of Differential Privacy.
  • Satyanarayanan, M. (2017), "The Emergence of Edge Computing," IEEE Computer.
  • W3C (2022), Decentralized Identifiers (DIDs) v1.0.
  • Helium Foundation (2022), network scale (~900,000 hotspots).
  • American Welding Society, workforce statistics (average welder age ~55).
  • Deloitte & The Manufacturing Institute (2024), US manufacturing talent outlook (3.8M jobs by 2033; 1.9M potentially unfilled).
  • WHO, projections of global health workforce shortfall (~10M by 2030).
  • IEC 63278-1 (Asset Administration Shell); ISO 23247 (digital twin framework for manufacturing); DIN SPEC 91345 (RAMI 4.0, 2015).
  • Regulation (EU) 2024/1781 (Ecodesign for Sustainable Products / Digital Product Passport); Regulation (EU) 2024/1252 (Critical Raw Materials Act); EASA Opinion 01/2021 (U-Space); Directive 2007/2/EC (INSPIRE).
  • Waern, N., SMILE Methodology, v6.4.3, DOI: 10.5281/zenodo.21757691 (concept DOI: 10.5281/zenodo.20175405). ORCID 0000-0001-7970-2707.

Where this goes next

Want this applied to your organisation?

One call is enough to know if we're a fit.

Book a call
Digital twin specialists

Nobody brings the full stack of digital twin competence — organizational, global, change management, technology strategy, and a NASA JPL-derived method — the way we do. We bring the best people together for a company faster than anyone else, and we implement it with them.

The decisions are being made either way. The only variable is whether you find out afterwards.

Scoping workshop from €4,500, credited in full against the project. See how scoping works