Critical infrastructures—such as energy grids, transportation systems, healthcare networks, water treatment plants, and financial systems—are increasingly digitized and interconnected. This convergence of operational technology (OT) and information technology (IT) has expanded the attack surface and made purely preventive, perimeter-focused security strategies insufficient. Cyber-resilience has therefore emerged as a complementary and, in many cases, superior paradigm to traditional cybersecurity, emphasizing not only the ability to prevent attacks but also to withstand, adapt to, and rapidly recover from them.This paper develops a theoretical foundation for cyber-resilience in critical infrastructure systems by integrating concepts from complex systems theory, control theory, socio-technical systems, and risk governance. We first distinguish cyber-resilience from traditional cybersecurity and reliability concepts, then propose a conceptual framework built around four core capabilities: anticipate, withstand, recover, and adapt. The paper also introduces a layered model of cyber-resilience that spans technology, processes, organizations, and ecosystems.Using this theoretical lens, we discuss how resilience metrics, control loops, redundancy, diversification, and learning mechanisms can be systematically integrated into critical infrastructure design and governance. Finally, we outline implications for policymakers, system architects, and operators, and propose avenues for future research, including resilience-by-design engineering, cross-sector interdependency modeling, and AI-assisted resilience analytics.