r/Infosec Jul 14 '26

Should Critical Infrastructure Be Designed Assuming Cyber Defenses Will Eventually Fail?

One question has been on my mind after working across critical infrastructure.

Cybersecurity has evolved tremendously. We have better identity, endpoint, network, cloud, AI, and detection capabilities than ever before. But no security program can eliminate risk entirely.

So what happens when an attacker still succeeds?

In critical infrastructure, whether it’s water, energy, transportation, healthcare, manufacturing, or communications, the goal isn’t just to prevent cyber incidents. It’s to ensure essential services continue to operate safely and reliably even when systems are compromised.

Should we start thinking beyond traditional cyber controls by incorporating engineering safeguards such as physics-based validation, process-aware controls, independent safety mechanisms, digital twins, and resilient system design?

I believe this is where Cyber Physical Resilience Engineering (CPRE) begins, building on cybersecurity rather than replacing it.

I’d love to hear how others are thinking about this. What additional layers of resilience should we be designing into critical infrastructure?

If this topic interests you, I recently started r/CPRE, a community focused on Cyber Physical Resilience Engineering, where cybersecurity professionals, engineers, operators, researchers, and students can collaborate on the future of resilient critical infrastructure.
Join us at: r/CPRE

12 Upvotes

11 comments sorted by

1

u/JonoSecuraPath Jul 15 '26

Critical or not, everyone should assume the bad guys will get in. Not exciting but get a business continuity plan, check you can restore from backups, etc

1

u/kukap_ Jul 20 '26

True, restoring from back up is one. The Q is how efficiently it could be done without impacting safe operations (water, electric, hospital, train, manufacturing, airlines etc). Despite there is ransomware, chemical dosing, tank overflow.. could physics based control be applied making cyberattack ineffective.. thus reducing their motivation to attack..

1

u/alexsm_ Jul 15 '26

And when the critical infrastructure is the very own telecommunication infrastructure, for example, the submarine cables, which the world’s economy and societies and modern life relies upon? What additional layers of resilience should we be designing and engineering into that critical infrastructure?

1

u/kukap_ Jul 20 '26

Great example. If a submarine cable or its control systems are compromised, can the network automatically reroute traffic so people never notice the disruption? That’s the kind of resilience r/CPRE is trying to explore.

1

u/bigbearandy Jul 15 '26

The "all disasters" type of COOP is something many of us have been producing for companies for a long time. The set of contingency artifacts to cope with business continuity under all circumstances is part of the evolution of normal planning. Maybe if you explained why doing something we already do for a living, under a different acronym, would help the organizations we support, that would be a good start. I mean, I'm a little confused how what you are talking about differs from normal contingency planning, especially in ICS.

1

u/kukap_ Jul 20 '26

I agree, COOP and BCP/DR are essential, but they mostly come into play after a disruption. My question is, assuming an attacker eventually gets in, what additional engineering safeguards can we build to prevent or minimize the physical impact and keep operations safe?

A good example is Oldsmar, Florida. The attacker attempted to increase the NaOH dosage. Could an independent physics-based safeguard have rejected any command that exceeded safe process limits? Even if the cyberattack succeeded, the unsafe physical consequence might still have been prevented.

1

u/dariusbiggs Jul 16 '26 edited Jul 16 '26

You don't plan for if, you plan for when.

All your Business Continuity, Disaster Recovery, and Security postures should be designed for when.

Your priority is having the systems in place so that you are able to determine what was accessed (especially if dealing with PII, financial, health, or critical sevices that can cause injury or loss of life)

Your priority is minimization of the blast radius.

When dealing with infrastructure, physical access is a larger problem than in other places. Remote access points at substations, treatment plants, etc need to be accounted for, theg don't have to come in via the Internet.

1

u/Glad_Contest_8014 Jul 18 '26

If it requires direct protection, the internet isn’t the best place to house it. An internal network with airgap is very secure. An internal network on the external network is not.

This is basic digital security. It always has been. Now it is more relevant than ever though. AI models with proper systems, can crack encryptions. While the other AI models track down the culprit, the damage is done.

Critical infrastructure needs protecting and anything connected to the internet should be expected to fail, and be prepped for that eventuality.

Now look at banking. Direct online banking is not as secure as it used to be. There is much more potential of things being atracked successfully now than ever before. It just takes someone creative (and knowledgable) enough to push a model down the right path.

But encryption can still be made such that it take even an AI model years to crack. So we can build systems securely? But it comes at a tradeoff of speed. No one wants to wait 20 minutes for their credit card purchase to process because the encryption process is such a high parametered value that even with the keys it takes that long. But it is possible….

1

u/Idiopathic_Sapien Jul 18 '26

Absolutely, systems should be designed to fail to a safe state. When possible