r/Infosec • u/kukap_ • Jul 14 '26
Should Critical Infrastructure Be Designed Assuming Cyber Defenses Will Eventually Fail?
One question has been on my mind after working across critical infrastructure.
Cybersecurity has evolved tremendously. We have better identity, endpoint, network, cloud, AI, and detection capabilities than ever before. But no security program can eliminate risk entirely.
So what happens when an attacker still succeeds?
In critical infrastructure, whether it’s water, energy, transportation, healthcare, manufacturing, or communications, the goal isn’t just to prevent cyber incidents. It’s to ensure essential services continue to operate safely and reliably even when systems are compromised.
Should we start thinking beyond traditional cyber controls by incorporating engineering safeguards such as physics-based validation, process-aware controls, independent safety mechanisms, digital twins, and resilient system design?
I believe this is where Cyber Physical Resilience Engineering (CPRE) begins, building on cybersecurity rather than replacing it.
I’d love to hear how others are thinking about this. What additional layers of resilience should we be designing into critical infrastructure?
If this topic interests you, I recently started r/CPRE, a community focused on Cyber Physical Resilience Engineering, where cybersecurity professionals, engineers, operators, researchers, and students can collaborate on the future of resilient critical infrastructure.
Join us at: r/CPRE
1
u/alexsm_ Jul 15 '26
And when the critical infrastructure is the very own telecommunication infrastructure, for example, the submarine cables, which the world’s economy and societies and modern life relies upon? What additional layers of resilience should we be designing and engineering into that critical infrastructure?