Those who own critical information infrastructure – computer systems directly involved in providing essential services – will be expected to detect, respond and recover from cyberattacks.