Multiple cyber-attacks against critical infrastructure highlight a need for resilience, operational risk and governance, rather than just technical security.
Critical national infrastructure (CNI) is under attack in the US and UK. In late August, it emerged that a British power plant had been hit and shut down for four days after Iranian adversaries launched an unprecedented cyber-attack.
It came after coordinated attacks targeted dozens of Minnesota water utilities, in an operation thought to be linked to the recent UK incident.
The US Cybersecurity and Infrastructure Security Agency (CISA) had already issued a warning detailing how Iranian actors are targeting water and energy organisations. There are also concerns around cybersecurity across the US aviation sector.
These closely-linked incidents highlight a bigger picture: Cyber-attacks against critical infrastructure are a growing threat and must be viewed through a lens of resilience, operational risk and governance, rather than just technical security.
Attractive Target
There’s no doubt CNI is an attractive target, especially for nation state adversaries looking to inflict maximum damage. With the ability to take down energy infrastructure with real-life consequences, CNI offers attackers “disproportionate leverage”, according to Dominic Carroll, director of portfolio at e2e-assure. “Disrupting a relatively small number of systems can interrupt an essential service,” he points out.
When attacks are successful, the consequences are physical and public. “A water treatment plant taken offline creates visible pressure to restore service within hours, and that gives an attacker a kind of coercive value that no corporate data breach delivers,” Carroll tells IO.
Attacks like these have happened before. Last year’s co-ordinated attacks on Poland’s power grid – targeting wind and solar farms – are evidence that threat actors “understand exactly how to manipulate multiple remote locations simultaneously to destabilise critical power networks”, adds Hybrie de Jager, operations manager Centrii.
Disruptive Campaigns
Recent incidents including Minnesota were motivated by disruption, rather than money. This tends to implicate nation state adversaries.
The latest attacks “highlight a shift towards campaigns that focus on disruption as much as data theft”, according to Tristan Shortland, CTO at Infinity Group. “Attackers are increasingly targeting operational technology and essential services to create business interruption, test resilience and apply geopolitical pressure. The fact that multiple organisations were targeted in a coordinated way also demonstrates a growing willingness by threat actors to pursue scalable attacks against entire sectors.”
CNI is often thought of vulnerable because the sector deals with legacy technology, some of which was never meant to be connected to the internet. These weak controls often open the door for attackers to easily exploit.
Threat actors don’t necessarily need an advanced zero-day exploit if internet-accessible equipment, poorly governed remote access, or weak operational controls provide a simpler route, points out e2e-assure’s Carroll. “They can identify a commonly used technology or exposed communications path and reuse the same approach across multiple operators.”
Beyond CNI
These attacks don’t just matter to CNI organisations themselves. Every organisation depends on critical infrastructure and interconnected supply chains, points out Infinity Group’s Shortland. “An attack on a utility, transport provider or technology partner can quickly ripple through to other sectors, affecting operations, customer service and revenue.”
CNI firms’ suppliers are particularly vulnerable. Every connection “introduces both value and risk”, says Shortland. He believes leaders in CNI firms therefore need visibility “not only of their own security posture but also the resilience of the organisations and technologies they depend on, particularly where those suppliers support critical business processes”.
It comes at a time of a regulatory shift in direction. Things are now moving from voluntary technical guidance towards enforceable operational resilience, clearer accountability, incident reporting and greater scrutiny of supply chains.
In the US, agencies are combining threat intelligence, sector regulation and practical mitigation guidance. In its aviation review, the Government Accountability Office identified gaps in technology, as well as in roles and responsibilities, budget visibility, strategy implementation and performance monitoring, according to Carroll.
The UK Cyber Security and Resilience Bill, now in committee stage, introduces two-stage incident reporting at 24 and 72 hours, wider investigatory powers for regulators and cost recovery to fund oversight. The EU Network and Information Systems Directive 2 goes further in placing liability on management bodies, according to Carroll.
At the same time, the new European Union Aviation Safety Agency’s Part-IS rules have come into place, expanding cybersecurity obligations across the civil aviation sector.
Lessons Learned
Attacks on CNI can be devastating, so it’s integral that organisations can get back on their feet quickly when incidents do occur.
The most important lesson from recent incidents is that resilience matters as much as prevention, says Infinity Group’s Shortland. “Organisations should assume incidents will occur and ensure they can continue operating through them. That includes robust backup and recovery processes, clear incident response plans, regular exercises and an understanding of which systems are truly business critical.”
Jack Nelson, CISO at Ivanti, believes resiliency depends on having visibility into critical assets, trusted operational data and the ability to prioritise and remediate risks before they impact the business. It also requires defence-in-depth when “things inevitably go wrong”.
“In this context, traditional, reactive vulnerability management approaches — where teams are constantly responding to the latest threats and trying to patch everything — won’t cut it,” says Nelson.
Governance Structure
As attacks on CNI continue to take place and the threat from nation state adversaries grows, governance helps provide the structure, accountability and decision-making needed to build resilience before, during and after an incident.
It requires a unified approach. Organisations need to understand and protect their critical assets, maintain visibility across increasingly complex technology landscapes, and have tested plans for keeping essential services running and recovering when disruption occurs, says Rich Giblin, head of public sector and defence at SolarWinds.
Leaders should establish a single governance model spanning cybersecurity, operational technology, engineering, safety, continuity, procurement and executive leadership, says e2e-assure’s Carroll.
Choose a small number of frameworks and map them once, Carroll advises. He says the National Cyber Security Centre’s Cyber Assessment Framework is “the right spine for UK essential services”.
At the same time, IEC 62443 covers industrial control environments, while the National Institute for Security and Technology’s Cyber Security Framework includes the Govern function which “makes accountability an explicit outcome”, he says.
Meanwhile, ISO 27001 and ISO 22301 can help to align information security with business continuity, according to Carroll.
MITRE ATT&CK for industrial control systems can then support threat-informed detection and exercising, and the Cyber Governance Code of Practice “sits above all of them for the board itself”, Carroll adds.
At the same time, boards need to understand the risks posed by CNI. As part of this, it’s important to examine concentration and “potential choke points”, says Carroll. “10 individually well-managed suppliers can still represent one systemic risk if they all depend on the same cloud platform, communications provider or software component.”
Expand Your Knowledge
Podcast: Phishing for Trouble S1, E2: Security of Public Systems and Services
Blog: The NCSC Wants Critical Infrastructure to “Act Now”: What Does That Mean?
Webinar: Simplifying Supply Chain Compliance







