#criticalinfrastructuresecurity
Good start to the week: @katjabego.bsky.social's 'Deep Connections' has arrived... #criticalinfrastructuresecurity
September 21, 2026 at 7:33 AM
“German politicians are making serious accusations against the Alternative for Germany (AfD) party. They allege the party is studying the country's critical infrastructure — in the interests of the Kremlin,“ using parliamentary inquiries to gather detailed information on IT, transport, water etc.
Is Germany's far-right populist AfD spying for Russia? – DW – 10/26/2025
German politicians are making serious accusations against the Alternative for Germany (AfD) party. They allege the party is studying the country's critical infrastructure — in the interests of the Kre...
www.dw.com
October 26, 2025 at 10:16 AM
December 16, 2024 at 7:33 PM
UK: the fragility of national industrial self-sufficiency & sovereign capability was highlighted last autumn by the National Preparedness Commission. This risk was explored... #industrialresilience #criticalinfrastructuresecurity nationalpreparednesscommission.uk/publications...
March 15, 2026 at 11:26 AM
UK: Subsea resilience & crisis preparedness... #criticalinfrastructuresecurity #societalresilience
It has been published: the Joint Committee on the National Security Strategy's report on undersea cables.

It was a privilege to be involved in the inquiry and see some of my suggestions picked up by the committee.

publications.parliament.uk/pa/jt5901/jt...
September 19, 2025 at 8:20 AM
CUI: Waterworth, scale & three oceanic corridors. Great analysis from @ravirockks.bsky.social... #criticalinfrastructuresecurity
March 1, 2025 at 10:31 AM
Finland-Sweden: "This project will promote the security & security of supply of the whole of Finland..." Funding to finally open the Tornio-Haparanda connection, enabling cross-border rail movement across the #BothnianArc... #criticalinfrastructuresecurity #societalresilience yle.fi/a/74-20195051
Suomesta voi matkustaa junalla muualle Eurooppaan ehkä jo keväällä – valtiolta 1,9 miljoonan lisärahoitus
Suomen ja Ruotsin välisen rataliikenteen käynnistymiseen tulee 1,9 miljoonan vuosittainen rahoitus valtiolta. Alueen kuntien aktiivisuudella oli ministerin mukaan merkitystä.
yle.fi
November 22, 2025 at 11:43 AM
Interesting language being used here: 'retaliation doctrine'. This is the original question exchange from 3rd December 2024... #criticalinfrastructuresecurity www.theyworkforyou.com/lords/?id=20...
December 21, 2024 at 10:28 AM
Sweden: "Rail networks, ports, & dual-use transport corridors are indispensable for commercial viability & military mobility alike..." #criticalinfrastructuresecurity #militarymobility #eastofnarvik h/t @kostianv.bsky.social www.thearcticinstitute.org/swedens-fort...
Sweden's Forthcoming Arctic Strategy: A Preview
Three sets of policy categories will feature prominently in Sweden’s yet to be realised (2026) Arctic strategy.
www.thearcticinstitute.org
April 4, 2026 at 6:32 AM
For those of you attending & interested in #criticalinfrastructuresecurity, you can hear Ravi's presentation "The tangled web: Critical software and critical infrastructure law" on Wednesday 18th in Think Tank 3
Melbourne Room 1 at 10.50...
Thrilled to bits to be returning to the largest cyber event in the Southern Hemisphere, put on by the wonderful AISA team!

Looking forward to presenting on my research at #cybercon2023!

If you're in Melbourne and want to talk cyber then, lemme know!
October 11, 2023 at 6:59 AM
Frequency realignment: final hours of preparations for tomorrows disconnection by Estonia, Latvia & Lithuania from the Russian power grid & Sunday's full synchronization with mainland Europe... #criticalinfrastructuresecurity
February 7, 2025 at 7:28 AM
A primary focus on 4 components of UK CNI (Communications, Energy, Government & Finance) is interesting: firmly positioning this within the criticalities framing & recognising the substantive upstream dependencies these components embody for the other 9 CNI sectors... #criticalinfrastructuresecurity
October 13, 2023 at 4:57 AM
This leads on the #criticalinfrastructuresecurity context, but it does mention #ProjectCabot & ASW capabilities. It doesn't set these within the broader strategic context of #AtlanticBastion & the #GIUKGap. No klaxon on this occasion... www.ft.com/content/ec7d...
Battle for the seabed: defence groups take aim at underwater security
Disruption to gas pipelines and telecoms cables have focused policymakers’ minds on protecting submarine assets
www.ft.com
August 26, 2025 at 6:31 AM
UK: Joint Committee on the National Security Strategy (JCNSS) opens new enquiry to examine threats to undersea cables... #criticalinfrastructuresecurity #nationalresilience committees.parliament.uk/committee/11...
January 28, 2025 at 5:50 AM
Global Surge in Military Grade Spyware Puts Personal Smartphones at Risk #CommercialSpyware #CriticalInfrastructureSecurity
Global Surge in Military Grade Spyware Puts Personal Smartphones at Risk
  Global cybersecurity discourse is emerging with a growing surveillance threat under the surface as the UK's top cyber authority issues a stark assessment of the unchecked proliferation of commercial spyware capabilities. Initially restricted to tightly regulated law enforcement use, advanced intrusion tools are now widely used across more than 100 countries, able to remotely compromise smartphones, bypass encrypted communications, and covertly activate device sensors.  NSO Group and an increasingly opaque ecosystem of competitors are driving this rapid expansion, signaling the shift from targeted investigative use to a wider landscape of state-aligned digital intrusion, a shift in which state-aligned cyberattacks are becoming increasingly commonplace.  In spite of their increasing accessibility and operational stealth, enterprises and operators of critical national infrastructure are not adequately prepared for the scale and sophistication of these threats. There is an evolving threat landscape supporting it, which is supported by the increasing sophistication of modern spyware frameworks, which leverage "zero-click" exploitation chains to gain unauthorized access without requiring the user's involvement.  NSO Group's Pegasus platform and Paragon's Graphite platform function as highly advanced intrusion suites. They exploit latent vulnerabilities within mobile operating systems to extract sensitive communications, media, geolocation information, and other artifacts through forensic minimalism.  The commercial dynamics underpinning this ecosystem demonstrate the magnitude of the challenge as well as its persistence. As part of the United States entity list, the Israeli developer NSO Group, widely associated with high-end surveillance tooling, was listed in 2021 for its supply of technologies to foreign governments. These technologies were then utilized to target a wide range of individuals, including government officials, journalists, business leaders, academicians, and diplomats.  In defending its claims that such capabilities serve legitimate anti-terrorism and law enforcement purposes, the company asserts that it lacks direct visibility into operational use, while retaining the right to terminate client relationships in instances of verified misuse.  In spite of the rapid expansion of the vendor landscape, NSO Group represents only one node within it. According to industry observers, including Casey, the sector is extremely profitable and is undergoing rapid growth. There are currently dozens of firms offering comparable capabilities in this market.  According to estimates, more than 100 countries have procured mobile spyware, an increase over earlier assessments, which indicated deployment across more than 80 national jurisdictions. Along with offering a cost-effective shortcut to the development of capabilities that would otherwise require years of development, commercial intrusion platforms offer a fast and easy means for states lacking indigenous cyber expertise. In addition, the National Cyber Security Centre noted previously that, despite the fact that these tools are intended for law enforcement purposes, there is credible evidence that they have been used on a widespread basis against journalists, human rights defenders, political dissidents, and foreign officials with thousands of individuals being targeted annually.  Several leaked toolkits, including DarkSword, demonstrate the dispersal of capabilities once restricted to state intelligence agencies into less controlled environments, making it possible for state-aligned and criminal actors to launch attacks by utilizing vectors as inconspicuous as compromised web sessions on unpatched iOS devices. In addition to theoretical risk models, operational exploits are being actively employed against targets who often assume device-level security as the basis of their attack.  A notable increase in the victim profile is that it includes corporate executives, financial professionals, and organizations dealing with valuable information, as well as journalists and political dissidents. It was highlighted by Richard Horne, the director of the UK's National Cyber Security Centre, that there still remains a significant gap in industry readiness.  Many enterprises underestimate the capability and operational maturity of these surveillance capabilities. Essentially, this shift illustrates the democratization of offensive cyber tools, where sophisticated surveillance, once monopolized by a few intelligence agencies, is now available to a broader range of state actors lacking native cyber expertise.  As a result, these capabilities are increasingly available economically and they are unintentionally disseminated, which fundamentally alters the threat equation. Through the transition from tightly controlled assets to commercially traded products, advanced surveillance tools become increasingly difficult to contain as they are propagated through illicit channels, including corrupt procurement practices, insider exfiltration, and secondary resale markets.  In the wake of this leakage, non-state actors, including organized criminal networks, have acquired capabilities that were previously available only to sovereign intelligence operations. The proliferation of state-linked campaigns, including those attributed to China and focused on large-scale data exfiltration, illustrates the use of such tools not only for immediate intelligence gain, but also to establish strategic prepositioning for future geopolitical conflicts.  Traditional device-based safeguards and consumer privacy controls are only marginally effective against adversaries equipped with exploit chains developed specifically to circumvent them. International efforts to regulate and oversee exports are gaining momentum, but operational reality suggests that containment may already lag behind proliferation, which enables a significant expansion of attack surfaces across both civilian and enterprise digital environments.  The convergence of commercial availability, technical sophistication and weak oversight has led to the normalization of capabilities that were once considered exceptional. These developments illustrate a structural shift in the cyber threat environment.  In conjunction with the widespread adoption of such tools, and their continual evolution and leakage, there is an ongoing need for public and private sectors to assess their security assumptions at a fundamental level. There is no longer a limited need to defend against isolated intrusions for enterprises, critical infrastructure operators, and individual users, but rather to navigate a complex ecosystem where highly advanced surveillance techniques are frequently accessible and increasingly resemble legitimate activity.  In the absence of strengthened international coordination, enforceable controls, and a corresponding increase in defensive maturity, a continued erosion of digital trust is likely, resulting in compromise becoming not an anomaly, but an expected condition of operating within a hyperconnected environment.
dlvr.it
May 5, 2026 at 3:36 AM
Europe Targets Chinese and Iranian Entities in Response to Cyber Threats #AdvancedPersistentThreats #CriticalInfrastructureSecurity
Europe Targets Chinese and Iranian Entities in Response to Cyber Threats
  Council of the European Union, in response to the escalation of state-linked cyber intrusions, has tightened its defensive posture by imposing targeted sanctions on a cluster of entities and individuals allegedly engaged in sophisticated digital attacks against European interests in a measured yet unmistakably firm manner.  According to the Council, on behalf of the bloc's member states, this decision represents a broader strategic shift within the European Union, where cyber threats are increasingly treated as instruments of geopolitical pressure capable of compromising critical infrastructure, public trust, and economic stability rather than isolated technical disruptions.  It was announced earlier this week that sanctions would extend beyond corporate entities and include senior leadership figures, indicating a desire to hold not only organizations, but also their decision-makers accountable for orchestrating or enabling malicious cyber activity.  China's Integrity Technology Group and Anxun Information Technology Co., a company formerly known as iSoon, were among those names, along with Iranian entity Emennet Pasargad, who are believed to have participated directly in attacks against essential services and government networks.  The inclusion of executives such as Wu Haibo and Chen Cheng further underscores the EU's evolving approach to cyber operations, one in which the traditional veil of denial is pierced.  The European Union attempts to reset deterrence in cyberspace by formally assigning responsibility and imposing economic and legal constraints, where attribution is a challenging task, accountability is often elusive, and the consequences of inaction continue to increase with each successive breach by establishing a new standard of deterrence.  European authorities have also focused attention on Anxun Information Technology Co., commonly referred to as I-Soon. The company appears to be closely connected to Chinese domestic security apparatuses, particularly the Ministry of Public Security. Despite its formal positioning as a commercial company, Huawei has long been associated with cyber operations aligned with Beijing's strategic intelligence objectives, blurring the line between state-directed activity and outsourced service.  As a result of this dual-purpose posture, Western governments have paid sustained attention to the situation; following sanctions imposed by the United Kingdom in March 2025, the Department of Justice unveiled charges against multiple I-Soon personnel for participating in coordinated intrusion campaigns.  In confirming these concerns, the European Union has made the claim that I-Soon operated as an offensive cyber services provider, systematically attacking critical infrastructure sectors and governmental systems both within member states and abroad.  As alleged by investigators, its activities extend beyond unauthorized access to include sensitive data exfiltration and monetization, introducing persistent risks to the diplomatic and security frameworks supporting the Common Foreign and Security Policy as a result of institutionalizing the hacker-for-hire model. It is also important to note that the Council has designated key corporate figures, including Wu Haibo and Chen Cheng, who are senior managers and legal representatives within the company's structure. This reinforces the EU's intention to attribute accountability at both the individual and organization level. There have also been actions taken against Emennet Pasargad, an Iranian threat actor known by various aliases, such as Cotton Sandstorm, Marnanbridge, and Haywire Kitten and widely considered to be linked with the Cyber-Electronic Command of the Islamic Revolutionary Guard Corps.  A wide range of disruptive and influence-driven cyber activities have been associated with the group, ranging from interference operations in connection with the 2020 presidential election to intrusion attempts related to the Summer Olympics in 2024.  In accordance with European assessments, cyberattacks against Sweden's digital infrastructure, including the compromise of the national SMS distribution service, were also attributed to the group, indicating a pattern of operations intended not only to infiltrate systems but also to undermine public trust and operational resilience. Furthermore, additional technical assessments further demonstrate the extent and persistence of Emennet Pasargad's activities. As indicated by Microsoft's analysis previously, the group-tracked as "Neptunium"-is suspected of compromising the personal information of over 200,000 Charlie Hebdo subscribers.  According to many observers, the intrusion was a retaliatory act in response to the publication's controversial content targeting Ali Khamenei, illustrating the trend of politically motivated cyber operations being increasingly integrated with information exposure and intimidation methods. The Council of the European Union identifies the group as conducting hybrid operations, including the unauthorized control of digital advertising billboards during the 2024 Summer Olympics for propaganda purposes, as well as a compromise of a Swedish SMS distribution service. Interestingly, the latter incident is consistent with an earlier documented campaign that utilized mass messaging to incite retaliatory sentiments within the Swedish community, a tactic that has later been referenced by the Federal Bureau of Investigation in its threat advisories.  Additionally, the Council's documentation illustrates earlier interference activities targeting the 2020 United States presidential elections, during which stolen voter data was used to deliver coercive communications using false political identities, demonstrating a deliberate campaign to undermine the trust of voters.  Indictments have been issued in the United States against individuals such as Seyyed Mohammad Hosein Musa Kazemi and Sajjad Kashian as a result of enforcement actions. Financial sanctions have been imposed by the Treasury Department in an attempt to disrupt the group's operations funding. In spite of these measures, the actor has remained active, and subsequent attribution has linked it to ransomware campaigns believed to be affiliated with the Islamic Revolutionary Guard Corps. There are parallel findings regarding Integrity Technology Group that reinforce the transnational nature of these threats. Investigators discovered that the company's infrastructure and tooling were used by the Flax Typhoon threat group as a means of gaining access to tens of thousands of devices throughout the European continent, as well as facilitating espionage-focused activities targeting Taiwanese entities.  In addition, coordinated sanctions between the United Kingdom and the United States indicate a growing alignment of international responses targeted at reducing the ability of state-linked cyber activities to sustain their operations. In combination, these coordinated efforts indicate a maturing enforcement posture in which cyber operations are not viewed merely as technical incidents but rather as matters of strategic significance that require sustained, multilateral responses.  As part of the ongoing process of improving the European Union's cyber sanctions framework, the EU will emphasize attribution, intelligence sharing, and alignment with international partners in order to ensure that punitive measures are effectively translated into tangible operational disruptions. It becomes increasingly important for organizations operating both within and outside of Europe to strengthen their resilience against advanced persistent threats, in particular those that utilize supply chain access, managed service providers, and covert infrastructure.  It has been noted that the convergence of espionage, cybercrime, and influence operations calls for a more integrated defense model that includes technical controls, threat intelligence, and regulatory compliance.  Having said that, the effectiveness of sanctions will ultimately depend on the consistency with which they are enforced, on the timely attribution of the perpetrators and on the ability of both public and private sectors to anticipate and mitigate the evolving threat environment.
dlvr.it
March 19, 2026 at 2:47 AM
US: "The United States is at risk of losing the ongoing irregular world war, falling behind in the resilience race that will be key to winning it..." #totaldefence #criticalinfrastructuresecurity
In order to protect critical national infrastructure from hybrid attacks, the US should emulate the whole-of-society approach pioneered by Sweden, Finland and the Baltic States.

The US needs a total defence strategy | Alexander Noyes and @jasoncmoyer.com

engelsbergideas.com/notebook/the...
The US needs a total defence strategy
In order to protect critical national infrastructure from hybrid attacks, the United States should emulate the whole-of-society approach pioneered by Sweden, Finland and the Baltic States.
engelsbergideas.com
August 25, 2026 at 4:36 AM
Iranian Hackers Shut Down UK Power Plant in Historic Cyberattack

#IranCyberattacks #CriticalInfrastructureSecurity #VantaWire #TechNews

🔗 https://www.vantawire.com/iranian-hackers-shut-down-uk-power-plant-in-historic-cyberat/
August 24, 2026 at 8:30 PM
Siemens S7 PLCs Face Emerging Threat From AI-Generated Exploit Scripts #AIGeneratedExploits #CriticalInfrastructureSecurity #CyberAttacks
Siemens S7 PLCs Face Emerging Threat From AI-Generated Exploit Scripts
A cyber threat targeting critical infrastructure has been reported by the U.S. government utilizing AI-generated exploit scripts aimed at Siemens programmable logic controllers (PLCs) of the S7 Series. Reconnaissance and exploit development are among the activities, with malicious scripts masquerading as legitimate monitoring tools used to monitor PLC installations in the country.  The NSA, CISA, FBI, Department of Energy, and Environmental Protection Agency have jointly issued an advisory stating that threat actors are utilizing internet scanning platforms including Censys and ZoomEye to locate PLCs that are directly exposed to the Internet, run outdated software, or are protected by weak security controls. Siemens S7 PLCs are a key focus for the activity, however it appears to involve more than one vendor of PLCs.  A number of critical infrastructure sectors have been affected by the activities, including manufacturing, energy, water and wastewater, chemicals, food, and agriculture, and commercial facilities. The agencies have not identified any known threat actors or groups associated with the campaign. A compromised PLC could have a number of consequences, ranging from disruptions of industrial operations and equipment damage to safety incidents and data exposure, as well as broader impact on interconnected systems as a whole.  The owners and operators of operational technology environments are therefore advised to examine the exposure of PLCs, to implement available security updates, to restrict internet access, to strengthen authentication and access controls, and to monitor industrial networks for suspicious activity. In light of a broader series of cyberattacks targeting U.S. critical infrastructure, particularly water and wastewater facilities, this latest warning is significant.  There has been a significant increase in scrutiny of industrial control systems following recent incidents affecting utilities in several states. Many of these systems remain based on outdated technology and inadequate cybersecurity protection. Federal agencies have previously warned of Iranian-linked activity aimed at operational technology (OT) environments. There had been earlier warnings regarding attacks against internet-connected devices that manage critical infrastructure, with water and wastewater systems being identified as a major concern. However, the August warning adds a new dimension to the threat by describing how artificial intelligence is being used in reconnaissance and exploit development.  Using public information on Siemens S7 PLCs, vulnerabilities can be identified, exposed devices located, and scripts can be developed that can interact with vulnerable systems. Since they direct physical processes, such as machinery, industrial equipment, and automated operations, they are particularly sensitive targets. As the FBI has warned, systems with exposure to the internet or inadequate segmentation from other networks are at increased risk of exploitation.  The vulnerability of devices with default or weak authentication mechanisms increases the importance of limiting external access and securing remote connections. There has been an observation of activity involving multiple Siemens S7 product lines, including S7-200, S7-300, S7-400, S7-1200, and S7-1500. This range includes both standard CPU variants as well as F-series safety controllers, as found in the S7-1500 series.  A Python-based script, which is designed to interface with Siemens PLCs, is also used as part of the activity, using open-source industrial automation libraries such as python-snap7. S7comm protocol allows access to PLC memory, configuration information, and ladder logic through tooling that can resemble legitimate monitoring utilities. A comprehensive inventory of Siemens S7 PLC deployments has been recommended, along with a critical security update installation and verification that PLCs cannot be directly accessed from the internet. A number of additional measures have been recommended to detect suspicious activity, including stronger access controls, network segmentation, multifactor authentication for remote access, as well as continuous monitoring.  Using Artificial Intelligence (AI), attack tools are becoming easier to develop and adapt, thus increasing the security risks associated with industrial control systems. In order to reduce the risks of disruption across critical infrastructure, it remains critical to secure exposed PLCs, strengthen access controls, and maintain effective network segmentation.
dlvr.it
August 22, 2026 at 4:00 PM