
The adoption of Directive 2557/2022 has brought about a fundamental paradigm shift in the perception of critical infrastructure security, with attention shifting from critical infrastructure protection (CIP) to critical entity resilience (CER). While the CIP model focused primarily on critical infrastructure prevention and physical protection, the CER concept now emphasizes organizations' ability to adapt, recover, and maintain their key functions, thereby significantly reducing the risk of incidents and small-scale disasters. At the same time, there is a change in the approach to designating critical entities. Critical entities are no longer entities that own critical infrastructure elements, but entities that provide essential services. However, identifying these essential services is a fundamental challenge to the comprehensive implementation of the CER Directive in national critical infrastructure systems. Member States lack specific quantified criteria for identifying essential services. Based on these facts, the aim of the article is to propose criteria for identifying essential services, on the basis of which critical entities can be designated. The definition of these criteria is based on a methodology for categorizing and prioritizing objects necessary for restoring electricity supplies after a blackout, sectoral criteria for determining critical infrastructure elements, and an assessment of the synergistic effect in the event of an essential services failure. At the end of the article, a practical example of the procedure for identifying essential services and designating critical entities in the Czech Republic's Transport sector is presented.
Today’s subsea telecommunications cables are a critical backbone of the global digital economy, essential to national security and the functioning of modern societies. Despite their contemporary prominence, many of the challenges that media and governments highlight regarding their security and resilience are hardly new. This article argues that both industry and government concerns regarding subsea cables are deeply rooted in recurring problems, even if the resulting actions to remedy them are different. Through an analysis of three core interdependent issues - physical damage, system redundancy, and charting - the article examines both continuities and discontinuities in how industry and governments have understood and managed risks to submarine cable systems from the nineteenth century to the present, demonstrating how an appreciation of past experiences can - and should - inform industry practice and contemporary policy- and decision-making. It concludes that sustained public–private collaboration is essential for protecting subsea cable infrastructure in an era of renewed geopolitical tension, while also acknowledging that, as in the past, such cooperation will itself become increasingly politicised as questions of authority, responsibility, and strategic control intensify. The article contributes to the literature by incorporating historical data on the geopolitical dimensions of damage, redundancy and charting that has received limited attention in discussions on subsea cable resilience. This approach demonstrates that historical understanding can constitute a practical resilience capability in itself, yielding insights with important implications for contemporary subsea cable policy.
Cyberattacks on the health sector can have far-reaching consequences. In addition to data loss, such attacks can disrupt patient care, erode trust, and even lead to poorer health. The purpose of this study is to characterize cyberattacks targeting healthcare facilities compared with other critical infrastructure sectors and to examine regional differences between the EU and the US, with the aim of strengthening education, preparedness, and security strategies. We conducted a cross-sectional analysis of the European Repository of Cyber Incidents (EuRepoC). The effects of and reactions to cyberattacks on healthcare facilities with these on other critical infrastructure sectors worldwide and the cyberattacks on the health sector between Europe (EU Member States) and the US from January 2023 to December 2025 (three years) were compared. With about 74% of health sector incidents stored in the repository, the health sectors in the EU and the US are worldwide the most frequently observed to be targeted by cyberattacks. In healthcare, these attacks are mostly carried out by non-state actors, exploiting public-facing applications and valid credentials. Compared to other sectors, these incidents cause greater functional disruption and impact more sensitive data. Disclosure times are notably longer in the US. As a conclusion in addition to technical measures, for healthcare cybersecurity an “all-hazard” approach should be adopted. A culture of security in practice, regular drills, and early sharing of cyber threat intelligence may be beneficial. This could make it possible to close security gaps more quickly and prevent cascading effects of cyberattacks in the healthcare sector.
The convergence of Information Technology (IT) and Operational Technology (OT) has created an economic paradox where traditional cybersecurity investments often conflict with the operational mandates of industrial environments. Despite the escalating threat landscape, the link between cybersecurity maturity and firm-level economic performance remains theoretically opaque. Drawing on the Resource-Based View (RBV), this study employs fuzzy-set Qualitative Comparative Analysis (fsQCA) to examine how configurations of dynamic capabilities - Anticipate, Resist, Recover, and Evolve - drive Return on Assets (ROA) in a sample of 130 Spanish critical infrastructure operators. We operationalize cybersecurity maturity through the Cyber Resilience Improvement Indicators (CII) framework, evaluating how specific configurations of its core goals, Anticipate, Resist, Recover, and Evolve, drive Return on Assets (ROA). Crucially, the findings reveal a major theoretical paradigm shift: resilience is empirically proven to be more economically valuable than preventative resistance. The results challenge the linear defense in depth orthodoxy, identifying two equifinal pathways to economic success. The first, termed the Agile Responder, demonstrates that firms can achieve high performance with low technical resistance if they possess superior recovery and adaptive capabilities, validating a safe to fail paradigm. The second, the Stable Planner, reveals that legacy operators can remain economically viable by substituting modernization with intense anticipation and continuity planning. Ultimately, this research empirically isolates Recovery as the keystone capability for asset heavy industries, providing a strategic roadmap for Chief Information Security Officers (CISOs) to optimize resource allocation in the face of the patching paradox.
Critical infrastructures in rural Alaska function as interdependent socio-technical lifelines; disruptions in one system, such as transportation or communications, can cascade across others. These interdependencies are shaped not only by technical connections but also by how actors understand responsibilities, constraints, and coordination pathways. In remote communities, resilience planning requires cross-agency coordination, yet stakeholder groups may recognize and prioritize different connections. This study examines how perceived interdependencies vary across stakeholder groups and what becomes visible when perspectives are combined. To do so, we analyzed 96 semi-structured interviews with community members (n=61), infrastructure providers (n=13), and state-level regulators (n=22). Using qualitative coding, we identified directed interdependencies and constructed stakeholder-specific networks. We compared network structure for regulators and providers and synthesized a map combining all stakeholder perspectives. This study advances infrastructure interdependency research by translating interview-derived interdependencies into stakeholder-specific networks and systematically comparing their structures while preserving the qualitative context of the relationships in rural Alaska. Results show distinct, role-based maps. Providers described a broad set of systems but a less interconnected structure, consistent with an operational focus. Regulators emphasized a tightly connected network, reflecting responsibilities for coordination and resource allocation. Healthcare services were frequently described as dependent on other systems, while power generation was described as enabling other services. Bridge (connector) systems diverged, with aviation being central for regulators, whereas providers emphasized ground transportation and water distribution. By showing how stakeholder roles shape perceived interdependencies, the findings reveal often overlooked coordination gaps and identify bridge systems for resilience planning in remote communities.
Critical transportation infrastructures are vulnerable not only to physical disruptions but also to the chaotic behavioral responses they trigger. While Defender-Attacker-Defender (DAD) models are standard for assessing network resilience, most existing frameworks assume that network users possess perfect rationality and complete information during the post-disaster stage. This "idealized" assumption ignores the limited situational awareness and panic-induced perception uncertainty distinct to extreme events, potentially leading to a dangerous overestimation of system resilience. To bridge this gap, a novel Tri-level Defender-Attacker-User Equilibrium (DAU) framework that endogenously integrates travel time reliability with panic-induced perception errors is proposed.Unlike passive adaptation models, our framework captures the full lifecycle of resilience: (1) Strategic Pre-positioning (Defender) to fortify critical links under budget constraints; (2) Worst-Case Disruption (Attacker) targeting structural vulnerabilities; and (3) Bounded Rational Response (Users), modeled via a Panic-Adaptive Stochastic User Equilibrium (PSUE) where perception variance is a function of disruption severity. A Hybrid Nested Genetic Algorithm (HNGA) is developed to solve this highly complex, discrete tri-level optimization problem. Case studies on the Sioux Falls network reveal a counter-intuitive "Strategic Diversion" mechanism: optimal defense implies forcing attackers toward links where panic-induced perception uncertainty is controllable, rather than merely hardening the busiest roads. Our results indicate that neglecting the "Panic Multiplier Effect" can overestimate resilience by up to 27.6%. These findings suggest that for critical infrastructure protection, investing in information dissemination systems to correct situational awareness delivers equivalent operational effectiveness compared with physical reinforcement.
LEO satellite communications are transforming smart ships and Maritime Autonomous Surface Ships (MASS) into always-connected cyber-physical systems, expanding the cyber-attack surface of shipboard operational technology (OT). Conventional VPN-based remote access provides insufficient session-level control and traceability for these environments.This paper proposes a Secure Remote Access (SRA) architecture based on Zero Trust principles integrated with the IEC 62443 Zone and Conduit model. Design requirements are derived from IMO MSC.428(98), IACS UR E26/E27, IEC 62443, and NIST Zero Trust Architecture.Full-scale experiments on a crude oil tanker using Starlink LEO satellite communications (downlink 94.7 ± 12.3 Mbps; RTT 38.2 ± 6.1 ms) executed ten functional and four adversarial scenarios against two OT systems. The SRA architecture achieved 100% blocking of unauthorized access attempts and 80–100% automated blocking across adversarial scenarios, with the residual 20% (a single privilege-escalation case) attributable to policy configuration incompleteness and subsequently resolved to 100% after policy refinement. Mean Time to Detect was 8.4 ± 5.1 s (n = 20), a 99.6% reduction from the VPN baseline (37.2 ± 14.8 min, p < 0.001); Mean Time to Respond was 1.3 ± 1.1 min, a 94.4% reduction (baseline: 22.5 ± 8.3 min, p < 0.001). SRA mediation added 2.5 s session-establishment latency and 2.6% throughput cost. Regulatory mapping confirms structural satisfaction of IACS UR E26/E27 and IEC 62443 core requirements. These gains are relative to a manually-monitored VPN baseline, not IDS/SIEM best practice; the contribution is integrating and validating established Zero Trust principles for maritime OT.
Industrial control systems (ICS) are increasingly vulnerable to sophisticated cyber-physical attacks, yet existing anomaly detection methods struggle to capture complex spatial correlations among sensors and efficiently process long industrial time-series. To address these limitations, this paper proposes an Improved Spatio-Temporal Feature Fusion-based Anomaly Detection (ISTFAD) method and integrate it with an industrial digital twin system. ISTFAD first constructs a similarity graph by integrating cosine similarity, dynamic time warping, and KL divergence, then employs a multi-dimensional graph attention mechanism to model spatial dependencies across multiple latent subspaces. For temporal modeling, a frequency-domain self-attention mechanism based on fast Fourier transform captures global temporal dependencies with reduced computational complexity. An adaptive thresholding method using the generalized Pareto distribution dynamically adjusts anomaly thresholds, improving sensitivity to extreme anomalies. Extensive experiments on three public datasets (SWaT, WADI, and GP) demonstrate that ISTFAD achieves F1-scores of 0.966, 0.951, and 0.894, respectively, achieving the best overall performance among 14 compared baseline methods. Furthermore, validation on a real-world digital twin cyber range for energy enterprise attack-defense exercises confirms its practical effectiveness, achieving an average F1-score of 0.970. The proposed method provides a robust and efficient solution for anomaly detection in industrial digital twin environments.
Vulnerability management is an essential part of modern cybersecurity, as well as a cornerstone of the IEC 62443 standard. However, vulnerability management of Operational Technology (OT) systems is less than trivial due to factors such as legacy systems, a wide range of suppliers and stakeholders, and business continuity requirements. To investigate how asset owners of power plants and substations in smart grids can consider existing security measures when prioritizing vulnerabilities, we based our proposal on de facto standards and frameworks, e.g. the Purdue reference model, IEC 62443 and the Common Vulnerability Scoring System (CVSS). Through a systematic content analysis, our main contribution is the mapping suggestion between the security levels of IEC 62443-3-3 system requirements to the values of the Environmental metrics of the CVSS v3.x framework. The mapping proposal was applied to a Programmable Logic Controller (PLC) as a proof of concept due to its criticality in smart grid systems, and also to a set of Windows-based Operator Stations (OS). The proposed approach is scalable in the sense that similar assets can be assessed together, and the procedure is intended to be applicable to asset types across Purdue levels, although this paper evaluates only selected examples. The proof of concept with a PLC and Windows-based Operator Stations illustrates how considering existing security measures can change the Environmental score, thus the prioritization.
Critical information infrastructure relies on continuous network monitoring, but high-traffic intrusion detection systems must operate under large flow volumes and unknown deployment conditions. NetFlow-based detectors trained on one dataset are often ineffective on another because of cross-dataset domain shift, while applying costly Stage-2 inspection to all flows is impractical. We propose RiskGate-IDS, a budget-aware two-stage risk-gating framework for NetFlow intrusion detection in high-traffic critical information infrastructure under domain shift. RiskGate-IDS uses a lightweight source-trained Tiny-Gate to generate flow-level risk evidence, a small labeled target calibration set to train a target-aware RiskGate ranker, and a BudgetBank mechanism to adaptively allocate Stage-2 budget across time-ordered micro-batches. The selected high-risk flows are further verified by XGBoost and neural MLP Stage-2 detectors.Direct cross-dataset transfer produced poor results; for example, Cross-Gate-only achieved zero attack recall from NF-UNSW-NB15-v3 to NF-CICIDS2018-v3. With only 0.1% labeled target calibration and a 30% Stage-2 budget, RiskGate-IDS achieved an attack recall of 0.904896 ± 0.000018 and an F1-score of 0.949298 ± 0.000018. In streaming-like evaluation, BudgetBank improved micro-batch recall from 0.549752 to 0.904788 compared with fixed per-batch Top-B selection. The optimized Spark local-mode implementation achieved 1.59 million flows/s. With RiskGate + Stage-2 MLP, end-to-end recall was maintained at 0.904788, while false positives were reduced from 551 to 277. These results show that target-calibrated risk ranking and adaptive budget escalation can improve deployment reliability for high-traffic NetFlow intrusion detection.
Low-cost commercial drones have made adversarial sUAS a persistent threat in environments where terrain, vegetation, and urban structures degrade sensor performance in ways that controlled evaluations rarely capture. This survey benchmarks five primary sensing modalities, namely EO/IR, radar, LiDAR, acoustic, and RF, alongside the widely deployed Radar+EO/IR fusion baseline, drawing on 33 studies from 2015 to 2025. Unlike prior reviews, it treats deployment feasibility and system-level constraints including SWaP, integration burden, and maintenance as first-order evaluation criteria rather than secondary considerations, reflecting the operational reality that sensor selection cannot be separated from the context in which a system must be sustained. Each modality is assessed across detection range, probability of detection, false alarm rate, robustness to clutter, latency, and SWaP/cost under cluttered or NLOS conditions. No unimodal sensor performs reliably across all degraded settings: EO/IR degrades under occlusion and poor illumination, radar struggles with low-RCS targets and multipath, acoustic range is severely limited by ambient noise, RF detection fails against autonomous platforms operating without active transmissions, and LiDAR remains environmentally sensitive and resource-intensive. Radar+EO/IR fusion offers the most operationally mature balance of range and confirmation capability, but degrades under simultaneous occlusion and multipath. The review finds that the gap between nominal and field performance is a central unresolved challenge in counter-sUAS sensing, driven in part by inconsistent evaluation practices and insufficient attention to deployment constraints. Closing it will require standardized benchmarking under realistic clutter conditions and fusion architectures that treat sensor degradation as a design assumption rather than an edge case.
The digitalization trend has increased the importance of communication networks for power system monitoring and control, highlighting the need for studying their interactions in the context of the Cyber-Physical Power System (CPPS). One of the common methods to study a CPPS is utilizing the testbeds, integrating proper models of components for conducting a variety of experiments. The most common type of a CPPS testbed is the co-simulation platform, i.e., a software-based. This is due to its unique features, such as low cost, experiments reproducibility, and equipment safety. However, the main issue in co-simulation testbeds is proper synchronization among various software providing the desirable accuracy and speed. In this paper, a new synchronization method is proposed based on the novel concept of Critical Future Event Prediction (CFEP). The key features of the proposed method are the practical trade-off between the accuracy and speed, accurate power grid data acquisition and evaluation, independent investigation of events initiated from the cyber and physical environments, integrating the control schemes requiring additional data for decision-making, and simultaneous evaluation of several control schemes with different time scales. Various experiments are conducted on the developed testbed, including an agent-based backup protection scheme for distance relays, spoofing cyber-attacks, and SCADA/EMS operation. The proposed testbed has been also deployed in a real-world industrial environment, enabling the simulation of practical cyber-physical scenarios for a large-scale power grid. The results show the correctness, efficiency, and applicability of the proposed method in different types of CPPS studies and scenarios.
The adoption rate of technological advancement in Industrial Control System (ICS) has been increased in the last decade. However, they are still prone to cyber-attacks that make them less reliable. Usually a two way mechanism is used to protect ICS against the cyber-attacks. One is to protect them at the network level and the second is to provide protection at the physical level. A lot of studies have been reported in the literature to protect these systems at the network level as compare to the physical level. When a cyber-attack launch on these systems then it creates an anomalous behavior in the physical processes of these systems. In control engineering, detecting these anomalous behaviors is important for maintaining system integrity and operational efficiency. There exist various techniques to detect these anomalous behaviors that includes signature, specification, and behavior-based techniques. We have proposed an invariant mining approach for anomaly detection in an industrial control system. The suggested method combines specification- and behavior-based approaches using Association Rule Mining (ARM). This technique exploits the normal behavior of the plant to generate invariants which later serve as monitors to detect process anomaly. The entire study was conducted on a Water and Distribution testbed. This clearly demonstrates the practical applicability and performance of the proposed approach in a realistic industrial setting.
As global dependence on electricity increases, alongside rising threats from natural disasters and hostile actors such as military, intelligence, criminal, and terrorist entities, the risk of large-scale, prolonged power outages is intensifying. This paper addresses a gap in the literature by (1) reviewing the main concepts of major power outages, (2) identifying numerous cases, and (3) extracting their typical societal and cross-sectoral consequences. Findings on similarities and differences from 28 analysed cases confirm that major and prolonged electric power outages are likely to cause serious, both predictable and unpredictable, societal and cross-sectoral consequences, such as human casualties, significant financial losses, and disruption, delay, or cessation of activities in the following sectors: information and telecommunications, transport, water, food, finance, health, security, public administration, industrial production, leisure activities, and many other areas (households, public lighting, electric locks, elevators, crematoria). The Achilles' heel in such scenarios is the availability and quality of electric power generators and related fuel supplies during periods of drastic demand by many critical societal actors.
Major cities/states around the world face escalating risks from cascading disruptions due to complex interdependencies among their critical infrastructure/industrial sectors. Traditional resilience assessments based on the input-output model, often limited to national or provincial levels, lack spatial explicitness to capture asymmetric regional vulnerabilities. This study bridges the gap by integrating multi-regional input-output tables with the dynamic inoperability input-output model, creating a spatially explicit framework to quantify resilience in high-density urban systems. Using Singapore's 2011 Pulau Bukom oil refinery fire as a case study, multi-regional analyses are conducted and results are compared with national (single region) analyses, revealing regional interdependencies together with differential recovery trajectories and unequal economic losses across regions that cannot be uncovered by the national model. Inventory dynamics are also incorporated into the model to demonstrate how much losses can be reduced by having inventory buffers to delay disruption propagation across sectors/regions. Slow and rapid recovery scenarios are also compared to study how much prolonged disruptions can amplify total losses compared to rapid interventions, emphasizing the critical role of adaptive recovery strategies. The framework serves as a cost-effective tool for studying region-specific disruptions/shocks and how multi-regional interdependencies shape systemic fragility, allowing decision makers to prioritize different regions in their recovery plans or to develop spatially targeted redundancies and coordinated preparedness plans. By transcending aggregated national models, the multi-regional model underscores the value of regional granularity in resilience studies for incorporating risk reduction in economic/urban planning and other policy decisions.