____________________________________________________________________________________________________ CNI
Security
The UK’ s critical national infrastructure( CNI) is entering a converged threat era- one where cyber, physical and aerial risks are overlapping attack surfaces targeting the same high-value assets. Furthermore, data centres have been formally designated as CNI, elevating both their strategic importance and their exposure to attack.
In this piece, Richard Hilson of PFL Access Management, examines how CNI security has evolved, now there’ s a pressing need to protect distributed, often unmanned, systems across land, air and digital layers.
Historically, organisations responsible for critical assets have approached security in distinct domains, silos maybe. Cybersecurity teams protect networks and data, physical security teams manage access control and perimeter protection and airspace, in most cases, has remained largely ungoverned- until the past decade or so.
But the structure, and manner of threats, has evolved somewhat. According to the UK’ s National Cyber Security Centre,( NCSC) the country is now facing around four nationally significant cyber incidents per week, many linked to hostile state activity. At the same time, geopolitical tensions are increasingly playing out through infrastructure disruption- both physical and digital.
We are living in the converged threat era, and attackers are not constrained by organisational silos any longer, rather they are actively exploiting the gaps between them, and hybrid threats- whether state-backed, or criminal- are combining multiple factors to achieve their objectives.
Hybrid threats in practice
A typical campaign might begin with cyber reconnaissance, identifying vulnerabilities in IT or operational technology( OT) environments. This may be followed by physical surveillance, potentially conducted via drones, to map access points, movement patterns, or security weaknesses. ccemagazine. com 19