Detection vs. Deterrence: What Actually Stops Intruders

Across critical infrastructure sectors such as energy, transportation, water, utilities, and other facilities, physical security threats are increasing in frequency and complexity. Assets are more distributed, sites are often remote or unstaffed, and essential operations cannot afford disruptions. Meanwhile, many organizations continue to rely on security frameworks focused primarily on detection rather than prevention.
The common approach is familiar: detect an intrusion, verify the threat, and initiate a response. Cameras, alarms, analytics, and monitoring centers form the backbone of this model, providing visibility into events as they unfold. In many cases, these systems are well-integrated and operationally necessary. However, detection-led security is inherently reactive. It assumes an intrusion attempt will occur and focuses on managing the outcome rather than reducing the likelihood of the event. In environments where response times vary and sites span large geographic areas, even rapid detection is unlikely to prevent loss, damage, or disruption.
This raises a broader strategic question for global infrastructure leaders: Is it enough to recognize when a breach occurs, or should the primary goal be preventing the attempt altogether?
The Structural Imbalance Between Detection and Deterrence 
Detection and deterrence are not competing concepts, but in practice, they are often treated disproportionately. As industry threats evolve and expectations for resilience rise, that imbalance is becoming harder to ignore.
Most physical security strategies are built around detection. According to the Physical Security Market 2025-2030 report, video surveillance systems dominated the global market, accounting for more than 50.5% (Grand View Research). This includes systems that detect activity once it has begun and trigger a response, such as cameras, motion sensors, alarms, and monitoring centers — tools that provide visibility into events as they occur.
• Detection systems answer necessary questions: What is happening? What happened? What response is required? They provide situational awareness to support incident verification and create a record for investigation, compliance, insurance, or operational review. In well-designed environments, they can be integrated into response protocols that guide how teams react once a threat is identified.
• Deterrence systems, by contrast, focus on influencing behavior before an intrusion attempt occurs. These include visible barriers, controlled access points, lighting, active perimeter security, signage, and environmental design that signal a higher level of risk, effort, and consequence to potential intruders.
The critical infrastructure industry continues to prioritize detection over deterrence. The global video surveillance market is projected to grow from $95.1 billion (USD) in 2026 to 261.65 billion (USD) by 2034 (Fortune Business Insights). The issue is not that detection is unnecessary. It is that a detection-first approach can create a security gap when visibility and response are emphasized more heavily than perimeter-based prevention strategies.
The Reality of Infrastructure Intrusions
To develop effective security strategies, it is necessary to understand how most violations take place in practice. While high-profile incidents may be sophisticated or targeted, most security breaches across critical infrastructure are less complex.
Many crimes are opportunistic, driven by theft, vandalism, trespassing, or easy access rather than coordinated attacks. The continued rise in material theft, such as copper, components, and equipment, reflects this pattern. These incidents typically occur where assets are visible, access is predictable, and resistance is low. In this context, intruders tend to follow a straightforward logic: they weigh effort against reward and choose the path of least resistance. Therefore, sites with inconsistent perimeter control, limited deterrents, or predictable operating patterns are more likely to be targeted.
For infrastructure operators, the consequences often extend far beyond the value of the stolen material or damaged asset. A single intrusion can create emergency repairs, downtime, safety concerns, crew diversion, insurance involvement, regulatory scrutiny, and operational disruption. For electric utilities, water providers, transportation operators, and other critical infrastructure organizations, the incident itself is often only the beginning of the cost.
When applied to security design, systems that primarily detect activity after entry can still leave infrastructure exposed. When the environment signals low resistance, the likelihood of an attempt remains high — even if detection capabilities are strong.
Where Detection-First Systems Fall Short
Detection systems identify events effectively, but once someone initiates an intrusion that triggers the system, the damage may already be done, and an unavoidable gap remains. Because these systems depend heavily on post-alarm intervention, monitoring teams — even those with AI — must assess alerts, filter out false alarms, and determine the appropriate response. In the United States alone, 94-98% of police alarm calls are false alarms, costing the public about $1.5 billion per year in police time (U.S. Department of Justice). Over time, delayed escalation or false calls can lead to a lack of response, especially in highly distributed areas.
The operational and financial impacts extend beyond the incident itself. A single breach can cause downtime, safety issues, and regulatory scrutiny, diverting resources and straining teams. From a financial perspective, downstream expenses such as replacements, insurance, and productivity losses tend to rapidly surpass prevention costs.
For many infrastructure sites, the issue is not whether detection works. The issue is whether detection happens early enough, and whether the response can arrive quickly enough, to prevent meaningful loss or damage.
How Deterrence Influences Behavior
A prevention-focused approach shifts the point at which security is activated. It moves the risk outward to the perimeter, where decisions are made and potential threats can be deterred from escalating.
At its core, deterrence operates on perception. Visible security measures create clearly defined boundaries and alter how a potential intruder evaluates risk versus reward. When effort increases and uncertainty rises, the likelihood of an attempt decreases. Essentially, security begins as a psychological barrier before any physical action is taken; it begins in the decision-making process. This premise also aligns with principles in criminology. Individuals seeking opportunity tend to favor environments with lower resistance and higher predictability. When those conditions change, behavior changes with them. In most cases, the outcome is not confrontation but displacement; intruders will move on to less-protected sites.
For critical infrastructure, many assets are located in remote or minimally staffed environments where response times are inherently constrained. In these settings, visible deterrence and clear boundary enforcement must be foundational measures. Physical barriers and well-defined perimeters heighten avoidance instincts and reinforce a simple message: access is controlled, and intrusion carries consequences. When security is designed with human behavior in mind, it reduces the likelihood that unlawful activity progresses in the first place.
The Case for a Layered Security Approach
Detection and deterrence should work together, not compete; relying on only one creates gaps. A more effective approach is organized, multi-layered, and aligned with how intrusions occur and how human behavior responds.
This model organizes security into three functional layers at critical infrastructure sites:
• Outer layer: Deter. Establish visible boundaries through barriers, active perimeter deterrence, lighting, signage, and controlled access gates to discourage intrusion attempts before they begin.
• Middle layer: Delay. Introduce intrusion sensors, lighting, audible alerts, secondary barriers, and other physical obstacles that slow or complicate movement, increasing the time and effort required to proceed.
• Inner layer: Detect and Respond. Use cameras and real-time monitoring systems to identify activity and initiate an appropriate response in the event of a confirmed breach.
In this framework, detection remains essential, but it is no longer the first or only line of defense. Its role is to reinforce a system designed to prevent intrusion, not simply manage it after the fact. For infrastructure operators, the objective is to align these layers with asset value, operational scale, and acceptable risk levels. A well-designed multi-layer approach minimizes perimeter exposure while enhancing response effectiveness and supporting continuity across critical systems.
Operational Considerations for Infrastructure Leaders
For industry leaders, the shift from detection toward layered deterrence is strategic. It requires moving from a reactive posture to proactive risk mitigation, with the objective of reducing exposure before incidents happen. This shift also changes how security effectiveness is evaluated. The focus moves beyond response capability to include prevention, visibility, and resilience across the entire operating environment.
A few questions can help assess whether your current strategies are aligned:
• Are we primarily reacting to incidents, or preventing them?
• How visible and defined is our security posture at the perimeter?
• Would a potential intruder view this site as difficult, risky, and time-consuming to enter?
How does our anticipated response time compare to the speed of a typical intrusion?
Are cameras and alarms being used as part of a layered strategy, or are they carrying most of the burden?
What is the full cost of an incident beyond replacement material or repair expense?
• Can the current model scale across distributed assets without creating unnecessary operational complexity?
At the same time, practical constraints remain. Security decisions must balance cost, coverage across distributed assets, and the ability to maintain and scale systems over time. The most effective strategies integrate these considerations without introducing unnecessary complexity or operational burden.
Selecting a partner that can manage all aspects of compliance, risk management, and connectivity for multi-site operations within a layered security strategy can reduce the need to juggle multiple vendors.
The Evolving Threat Landscape and Industry Expectations
The responsibilities assigned to critical infrastructure operators are expanding. Security is no longer evaluated solely on the ability to detect and report incidents, but on the ability to maintain continuity under increasing pressure. Regulatory scrutiny is intensifying, public safety expectations are rising, and insurance and liability considerations are becoming more closely tied to how risk is managed — not just how it is documented.
In response, there is a broader shift toward proactive risk mitigation. Resilience frameworks emphasize reducing exposure and ensuring operational stability rather than relying solely on post-incident reporting. Therefore, a perimeter-first, layered approach is a strategic foundation for addressing risk at the boundary, reducing the likelihood of intrusion, and limiting the need for downstream response. This shift also reflects a closer integration between physical security and operational resilience. Protection strategies are no longer isolated functions; they are part of a connected effort to safeguard uptime, reliability, public safety, and trust across critical systems.
As these expectations evolve, so must the standard for what constitutes effective security. Monitoring alone cannot secure critical infrastructure. The outdated sequence of detect, verify, and respond is no longer sufficient on its own. A more comprehensive model prioritizes deterrence and delay immediately, with detection and response as needed. As a result, success depends not only on how incidents are handled, but more importantly, on how often they can be avoided entirely.
Redefining Effective Security in CIP
Detection answers an important question: “What happened?” Yet deterrence addresses a more consequential one: “How do we reduce the likelihood that it happens in the first place?”
The most effective security strategies recognize this distinction. They prioritize preventing incidents where possible, while maintaining the ability to detect, verify, and respond when necessary. For infrastructure leaders, this requires a shift in how success is defined.
Success should not be measured only by how efficiently incidents are managed after they occur. It should also be measured by how effectively a security posture discourages attempts, delays escalation, reduces preventable losses, and supports operational continuity.
Detection will always matter. But detection alone is not prevention.
As threats evolve and expectations for resilience increase, the strongest critical infrastructure security strategies will be those that move risk outward, strengthen the perimeter, and combine deterrence, delay, detection, and response into a coordinated model designed to prevent more incidents from happening in the first place.
Jonathan Ratledge leads AMAROK’s Critical Infrastructure and Government strategy, helping utilities, public agencies, and infrastructure operators strengthen perimeter security across high-value sites.

Crisis Communications Network Europe Joins CIP Week Europe 2026

The International Association of CIP Professionals (IACIPP) has announced that the Crisis Communications Network Europe (CCNE) has become the latest supporting organisation for the 3rd CIP Week Europe, taking place in Brussels from 20th–22nd October 2026.
Following the recent launch of CIP Week Europe 2026, IACIPP continues to expand the event's programme through partnerships with leading organisations representing the diverse disciplines that contribute to the protection and resilience of Europe's critical infrastructure.
Bringing together critical infrastructure operators, government representatives, security professionals, resilience practitioners, emergency planners and industry experts from across Europe, CIP Week Europe provides a platform for collaboration, knowledge sharing and professional development at a time when organisations are implementing new resilience and security obligations under the CER and NIS2 Directives.
At the heart of the programme will be the Critical Infrastructure Protection & Resilience Europe (CIPRE) Conference, featuring expert speakers, case studies and panel discussions covering physical and cyber security, resilience strategy, emerging threats, public-private cooperation, business continuity and the protection of essential services.
In addition to the main conference, delegates will have access to a series of specialist workshops delivered by supporting organisations, providing practical guidance and expert insight into key aspects of critical infrastructure resilience.
As one of the latest confirmed supporting organisations, Crisis Communications Network Europe (CCNE) will deliver a specialist workshop "From Incident to Communication: Crisis Communications for Critical Infrastructure", examining how communications support the response to incidents affecting critical infrastructure, from tactical communications in the field to strategic engagement with stakeholders, authorities, and the public.
The workshop will explore realistic scenario, participants will examine challenges, exchange experiences, and explore practical methodologies, best practices, and lessons learned. The session is intended for anyone responsible for, or interested in, crisis communications and resilience, and aims to provide practical insights that can be applied across a wide range of organisations and sectors.
John Donlon, Chairman of the International Association of CIP Professionals, welcomed the partnership.
"Protecting critical infrastructure is about much more than physical security and cyber resilience. Effective communication during a crisis is fundamental to maintaining public confidence, supporting operational response and enabling organisations to recover more quickly. We are delighted to welcome Crisis Communications Network Europe as a supporting organisation for CIP Week Europe 2026. Their expertise adds an important dimension to the programme and reflects the multidisciplinary approach needed to strengthen resilience across Europe's critical infrastructure."
Robbert Meulemeester, Coordinator of the Crisis Communications Network Europe (CCNE), said "The CCNE is delighted to be supporting and be part of CIP Week Europe. Crisis communications has a key part to play in managing an incident, helping organisations communicate clearly, maintain public confidence and support informed decision-making during times of uncertainty. As the risks facing critical infrastructure continue to evolve, effective communication must be recognised as a core component of organisational resilience, alongside security, business continuity and emergency management. Our workshop will provide delegates with practical insights into developing crisis communication strategies that strengthen preparedness, support response and contribute to faster recovery when incidents occur."
"CIP Week Europe was created to bring together the diverse community of professionals responsible for protecting and strengthening critical infrastructure," continued John Donlon. "Every new supporting organisation brings additional expertise and practical experience that benefits delegates. As the risks facing critical infrastructure continue to evolve, collaboration, knowledge sharing and professional development have never been more important."
The event is expected to attract participants from government agencies, critical infrastructure operators, utilities, transport providers, security organisations, emergency services, consultancies, technology providers and academic institutions.
Further announcements regarding speakers, additional workshop partners and programme details will be released in the coming weeks.
For organisations involved in critical infrastructure protection and resilience, CIP Week Europe offers a unique opportunity to engage with leading experts, share experiences and contribute to the development of a stronger and more resilient Europe.

Why Critical Infrastructure Should Use Drone Vulnerability Risk Assessments Now

Drone incursions over critical infrastructure sites are no longer hypothetical—they are operationally relevant and escalating. Unauthorized incursions over the Salem and Hope Creek Generating Systems and River Bend Nuclear Power Plant highlight the issue, with reports suggesting some drones were up to five feet in diameter and capable of flying at more than 100mph. This is well beyond the profile of hobbyist systems.
The exposure is not limited to energy assets. The Federal Aviation Administration (FAA) now logs 100 UAS sightings per month near airports. For operators of sites such as airports, prisons, ports, utilities, data centers, oil and gas facilities, it’s already clear that dealing with the emerging drone threat is an urgent priority, but the question is how to address it in a defensible and measurable way.
Despite this, many operators delay action, waiting for regulatory clarity or standardized counter-UAS frameworks. This is a mistake. Inaction does not reduce risk; it compounds it.
Drone Vulnerability Risk Assessments (DVRAs) offer an immediate and practical path forward for critical infrastructure site operators. They enable operators to quantify exposure, identify detection and response gaps, and elevate the drone threat from a theoretical concern to a defined operational risk that can be communicated, prioritized, and acted on at the executive level.
Why DVRAs Matter
Conducting a DVRA provides a clear operational advantage by shifting organizations from reactive response to proactive risk management. Ideally implemented during the design phase and equally valuable in retrofit environments, a DVRA enables operators to identify vulnerabilities, evaluate threat scenarios, and integrate mitigation strategies before drone activity impacts service continuity, safety, or operations. This approach allows organizations to act deliberately, rather than under pressure, ensuring that counter-UAS measures are aligned with both mission requirements and site-specific risk profiles. A DVRA allows an organization to quantify their exposure in concrete terms, creating a defensible basis for budget allocation and prioritization of high-risk sites.
The assessment also translates emerging drone threats from a technical issue understood by specialists into something that leaders can evaluate. Detection of investment should be framed as a resilience and continuity measure, moving organizations from passive awareness to defensible, risk informed action. Early investment is critical, and a DVRA enables more disciplined capital allocation, avoiding higher costs and inefficiencies of reactive response.
What a DVRA Actually Delivers
DVRAs are not simple site walk-throughs; they provide a multi-layered analysis that translates drone-related technical challenges into actionable risk management. A DVRA evaluates the specific threat profile of a site, including likely drone capabilities, attack vectors, potential consequences, and high-impact security gaps.
This analysis enables operators to prioritize sensor placement and account for environmental factors such as radio frequency interference, ensuring detection systems are appropriately selected and deployed. Radar plays a critical role, particularly in addressing “dark drones” that cannot be detected through RF-based methods.
While some operators may wait for full counter-drone authorization, targeted detection remains an effective first layer of defense and supports soft mitigation strategies. A DVRA supports this approach by mapping risk across distributed assets and identifying the highest-consequence vulnerabilities requiring immediate attention.
The Scale of the Problem
The number of drones already in U.S. skies is staggering. The FAA has registered 420,825 commercial drones and 383,007 recreational drones in the U.S., ranging from hobbyist UAVs through to larger electric vertical takeoff and landing vehicles (eVTOLs). Threats range from hobbyists who may not mean to cause harm but do so accidentally (such as drones sighted over wildfires, which can cause a real threat to firefighting aircraft), through to those used for espionage and sabotage.
Drones present a unique threat to critical infrastructure. They can enter sites unnoticed, land undetected, and bypass traditional human security measures. As a result, locations once considered secure against ground-based threats are no longer assured in an era where modern drone technology has become a real and accessible risk.
Drones also pose very real threats to critical infrastructure. The scientific paper Advances And Challenges in Drone Detection and Classification Techniques, published by Purdue University researchers and researchers from Satbayev University, found:
“Due to the fact that unmanned aerial vehicles are capable of carrying explosives as well as biological and chemical weapons, drone attacks fall under the first category of possible threats. These explosives might be used to attack a variety of targets, such as specific individuals, public institutions, business organizations, and even whole nations.
Smuggling is the second-leading threat category for drone use. For border patrols and jail staff, drone drug smuggling has grown to be a serious issue. Sometimes weapons or other illegal items are smuggled beyond the reach of ground-based security. Border locations have a wide range of weather; therefore, smuggling drones need to be able to operate in adverse weather conditions.
Drones with strong cameras may also be used to spy on people, businesses, and governmental institutions from a distance. Despite privacy claims, this worry might be a drone hazard, such as a privacy invasion or espionage.
Accidentally or purposefully launching a remote-controlled drone near an aircraft or in its flight path might threaten the safety of the crew and passengers and might damage property.”
The Drone Threat Is Here Now-An Ideal Time for DVRA
These threats are not abstract, futuristic concepts. Analysis of drone incidents in 2023 found that 38% relate to drones breaching borders, and 28% involved drones delivering illegal items and drugs into prisons. Another 18% involved drones flying too close to airport runways.
The sightings of drones in New York, Pennsylvania and New Jersey spread over 17 days, and led to the FAA issuing ‘special security’ flight bans over parts of New York and New Jersey to protect critical infrastructure. The saturated attack had significant impacts, including preventing a medical helicopter from transporting a car crash victim due to a drone sighting near Raritan Community College.
Beyond coordinated incursions, drones are now a leading source of disruption in the aviation sector. UAS incidents have become the primary cause of non-weather-related flight delays, with 749 flights disrupted across the United States between January and September 2025 alone.
Internationally, the patterns are similar. At Sweden’s Stockholm Arlanda Airport, sightings of UAS forced full suspension of air traffic for two-and-a-half hours, with fears that the incursion could be linked to heightened geopolitical tensions following Sweden’s accession from NATO. In the United States the risk profile continues to expand. Recently, a United Airlines pilot reported colliding with a drone at 3,000 feet above San Diego, California. And in Nashville, a man with extremist beliefs who wanted to collapse the U.S. power grid attempted to weaponize a drone with explosives.
Correctional facilities face parallel escalation. The number of incidents has jumped from just 23 in 2018 to almost 500 in 2024, driven by evolving drone technology and greater detection awareness. There are reasons for optimism. At a state prison in Ionia, Michigan, a drone-delivered contraband drop was intercepted, leading to the identification and arrest of three individuals. This was one of the earliest documented cases where operators were apprehended in direct response to a drone smuggling event.
The Limits of Legislation
One key issue is that it’s still unclear how legislation will change to allow site owners to respond to drone threats. At present, drones enjoy protected status as ‘aircraft’, making it a federal felony to disable, damage or destroy them, under FAA rules. The Cybersecurity and Infrastructure Security Agency’s (CISA) ‘Be Air Aware’ guide, published late in 2025, raises awareness around the threat of drones both at infrastructure sites and at public gatherings, and highlights detection, rather than mitigation. The CISA guide advises, “If you witness a UAS operation that appears dangerous or is being used to commit a crime, report it immediately to local law enforcement first responders.”
The SAFER Skies Act, enacted as part of the FY2026 National Defense Authorization Act in December 2025, expands U.S. counter-drone authority by allowing qualified state, local, tribal, and territorial agencies- not just federal agencies - to detect, track, identify, and mitigate drones that pose credible threats to people at major public events, and critical infrastructure including correctional facilities. It also establishes federal training, certification, approved technology standards, reporting requirements, and funding pathways to help local agencies respond more quickly and lawfully to growing drone risks.
With infrastructure operators still constrained by regulatory and legal limitations, many continue to delay investment in drone detection capabilities.
Reactive Spending After an Incident Costs More
Investing in drone defense early—through a DVRA and a structured approach to threat mitigation—is often the most cost-effective long-term strategy. Reactive spending after an incident is typically more expensive, particularly when factoring in the direct and indirect costs of operational disruption.
The 2018 Gatwick Airport incident provides a clear example. Reports of drone activity led to a full airport shutdown, with estimated economic losses of £50 million. Emergency response measures added further cost, including the rapid deployment of military-grade tracking equipment. In the aftermath, Gatwick implemented counter-drone technology at an estimated cost of £4 million.
While the post-incident investment was necessary, the scale of disruption and financial impact underscores the value of earlier, proactive measures.
Making the Final Case Against Waiting
Critical infrastructure security can no longer stop at the fence line. It must extend into the low-altitude airspace above the site, where commercially available drones can create real consequences for operations, safety, continuity, and sensitive data.
Conflicts in Ukraine, the Middle East, and other contested environments have demonstrated how inexpensive, commercially available, and rapidly modified drones can produce outsized effects. Those tactics will not remain confined to conflict zones. They are already informing criminal activity, extremist planning, and unauthorized incursions near sensitive facilities.
For infrastructure operators, the case for waiting is collapsing. Regulatory uncertainty may limit mitigation options today, but it does not prevent organizations from understanding their exposure, deploying detection, and building a defensible response plan.
A DVRA is the practical first step. It gives operators a clear view of their vulnerabilities, their highest-consequence gaps, and the investments needed to reduce risk before an incident forces action under pressure.
This ties back much more cleanly to the introduction: drone threats are urgent; waiting is not a strategy, and DVRAs are the most practical path forward now.
By Kara Quesada, Senior Director of Marketing at Echodyne and William Edwards, Director of C-UAS Training – ENSCO

NATO PA Promotes Investment in Collective Defence, Infrastructure Protection

The NATO Parliamentary Assembly has highlighted legislators’ vital role in ensuring the Atlantic Alliance faces up to pressing security challenges, strengthening collective defence and protecting against hybrid threats.
The Assembly’s Spring Session drew over 230 lawmakers from NATO and partner nations. Discussions on the second day focused on issues ranging from safeguarding critical infrastructure, maintaining military force levels and fast-tracking defence innovation
“The war in Ukraine is driving new thinking about modern warfare,” explained US Congressman Rick Larsen. “Innovating quickly is important but integrating and scaling new technologies is just as essential.
Drawing on Ukraine’s experience of fast-paced wartime innovation, Larsen said NATO must work urgently to overcome years of underinvestment, insufficient and fragmented demand, slow procurement and overly bureaucratic acquisition systems.
“That’s where we come in,” he told fellow parliamentarians. “We control the budgets. We conduct oversight. We can demand answers when promising technologies stall. We can push governments to integrate NATO commitments into national legislation and procurement systems that work.”
A presentation by Greek member Spyridon Kyriakis centred on shaping NATO’s future forces by improved recruitment, retention of experienced military personnel and strengthening the will to fight within Allied societies.
Faced with an aggressive, expansionist Russia on its doorstep, NATO must take steps to meet recruitment targets and ensure personnel stay in uniform longer, particularly those with critical skills such as cyber, intelligence, logistics and special operations.
“We need a sweeping renewed conversation on how we value, support and inspire our forces,” Kyriakis told the Assembly.
New NATO defence plans, bigger budgets and arms acquisition “can only deliver real deterrence if the Alliance has the well-trained, highly motivated men and women needed to operate and sustain them,” he added.
Lawmakers debated the costs and benefits of conscription and emphasised the importance of building on Ukraine’s experience to build public support and societal resilience to shape mobilisation capacity and wartime outcomes.
“As parliamentarians ... we hold the levers of oversight, the power of legislation and the loudest microphones to champion the profound value of military service to our citizens,” Kyriakis concluded.
Ahead of July’s summit of NATO leaders in Ankara, lawmakers highlighted the role of parliaments in ensuring that Allies stick to the goal of spending at least 5% of gross domestic product (GDP) on defence and security.
“There is still much to be done to bring defence spending to 5% of GDP and transfer that money into actual operational deterrence and defence capabilities,” said Dutch Senator Bart Kroon. “Sustaining that level of spending and transformation will require trade-offs and smart policymaking.”
NATO PA speakers underscored the need to protect critical infrastructure, such as undersea and space assets, from the mounting risk of hybrid attacks.
“Allied security is increasingly dependent upon our space systems and undersea infrastructure,” stated US Congressman Mike Turner. “They are core components of our defence posture and our economic resilience; and are under growing pressure from our adversaries.”
Turner and British Member Lord Nigel Dodds made presentations urging better monitoring and attribution of threats to infrastructure, faster repair and replacement options and solutions that allow forces to operate when communications are degraded by adversaries. Cooperation with the private sector is essential.
“Parliaments and we, as parliamentarians, have an important role to play,” said Dodds. “We can help ensure that national legal frameworks are fit for purpose. We can scrutinise whether governments have clear lead authorities and effective coordination structures. We can support dedicated funding for protection, repair, and response; and we can help keep political attention on this issue before a major disruption occurs.”

CoESS calls for exclusion of Private Security Services from EU Inc. Regulation

The Confederation of European Security Services (CoESS) has published a new position paper raising concerns about the European Commission’s proposal for an EU Inc. Regulation. While the proposal aims to simplify cross-border company operations in the EU, CoESS warns that it could unintentionally weaken national security frameworks and create loopholes in the regulation of private security services.
According to CoESS, private security services are already excluded from the EU Services Directive due to their direct link to internal security, Critical Infrastructure Protection, and support for law enforcement and emergency services. The organisation argues that the proposed EU Inc. framework — with rapid digital incorporation, EU-wide company recognition, and limits on additional national requirements — could make it easier for companies to circumvent national licensing and supervision systems. This would create enforcement challenges for national authorities and increase risks related to unlawful competition and weaker oversight.
The paper highlights that private security regulation differs significantly between Member States, reflecting national public security needs and operational realities. CoESS therefore believes that Member States must retain full control over authorising and supervising companies operating in this sensitive sector. The organisation also warns that the proposal could indirectly undermine the exclusion of private security services from the EU Services Directive by facilitating cross-border operations outside national regulatory frameworks.
CoESS is therefore calling on EU policymakers to explicitly exclude private security services from the scope of the future EU Inc. Regulation. The organisation stresses that such an exclusion is necessary to preserve effective enforcement of national security law and maintain robust supervision of services linked to public safety and Critical Infrastructure Protection.

NIST SP 1800-41, Responding to and Recovering from a Cyber Attack

The NIST National Cybersecurity Center of Excellence (NCCoE) has released the initial public draft of NIST Special Publication 1800-41, Responding to and Recovering from a Cyber Attack: Cybersecurity for the Manufacturing Sector, which provides guidelines on response and recovery activities in an industrial control system (ICS) environment and recommendations to improve operational resilience. The comment period for this publication is open through July 8, 2026.
Background
As Operational Technology (OT) systems like ICS become more interconnected with IT networks, they are increasingly being targeted by cyber threats, putting factory operations, safety, and property at risk. Organizations operating these systems, such as those in the manufacturing sector, need to have plans and capabilities in place to respond to cyber incidents and restore operations to improve overall resilience.
The NCCoE worked with 11 industry collaborators to develop reference architectures, describe response and recovery scenarios, and demonstrate relevant approaches and capabilities.
This draft publication provides actionable guidelines on responding to and recovering from cyber attacks in manufacturing environments. Discover how to:
- Understand the risks and potential impact of cyber incidents on your operations
- Develop a comprehensive response and recovery plan
- Implement best practices to minimize downtime and restore operations quickly

World Bank Group Supports Resilient Municipal Infrastructure to Modernize Cities in Türkiye

The World Bank Group approved a EUR 191.5 million (US$219.4 million) loan to Türkiye to modernize urban infrastructure and services in the fast-growing cities of Antalya and Konya, addressing a growing demand for public transport, clean water and sanitation, and efficient energy systems, while generating jobs along the way.
The Green and Future Cities Project will be implemented through İller Bankası A.Ş. (ILBANK) with the guarantee of the Republic of Türkiye. Türkiye’s rapid urbanization has intensified demand for efficient and resilient municipal infrastructure. While fast-growing cities are central to the country’s economy, many face constraints in accessing long-term financing for major investments to support people and growing economic activities.
“Türkiye’s cities are key drivers of economic growth and job creation but also face increasing pressures from rapid urbanization and climate change,” said                   J. Humberto Lopez, World Bank Country Director for Türkiye. “This project will help municipalities invest in modern, resilient infrastructure while strengthening their capacity to plan and finance sustainable urban development.”
Planned investments include the expansion and modernization of public transport systems, such as tramlines and low-emission vehicles, as well as upgrades to water supply, wastewater treatment, and sanitation infrastructure. The project will also support measures to enhance energy efficiency and strengthen climate adaptation and resilience. These investments are expected to improve urban mobility, enhance environmental sustainability, and raise the quality of life for residents, while contributing to economic growth and job creation.
The project will also provide technical assistance to ILBANK and participating municipalities to strengthen their capacity in project preparation, financial management, and sustainable urban planning. This will include developing pipelines of bankable, climate-smart investments, strengthen municipal financial and institutional capacity, and enhance long-term resilience to climate and disaster risks.
“By combining financing with technical expertise, this project will help cities develop bankable, climate-smart investments and improve their access to long-term financing,” said Ahmet Kindap, Task Team Leader for of the Project.
The project is also designed to help municipalities strengthen their creditworthiness and lay the groundwork for greater private sector participation over time.
Aligned with Türkiye’s national development priorities, the project will support both mitigation and adaptation efforts. Investments are expected to reduce greenhouse gas emissions, enhance energy efficiency, and strengthen resilience to climate-related risks such as flooding, drought, and extreme heat. By improving infrastructure systems and service delivery, the project will help cities better withstand future shocks while promoting sustainable and inclusive urban growth.
This project preparation benefited from technical assistance and grants from the Global Facility for Disaster Reduction and Recovery (GFDRR)’s Japan-World Bank Program for Mainstreaming Disaster Risk Management in Developing Countries, supported by the Government of Japan.

IACIPP ANNOUNCES 3rd ‘CIP WEEK’ IN EUROPE

The International Association of CIP Professionals (IACIPP) has announced that the 3rd CIP Week in Europe will take place in Brussels from 20–22 October 2026, bringing together critical infrastructure operators, government representatives, security professionals, resilience practitioners, emergency planners and industry experts from across Europe.

Designed as a focal point for collaboration, learning and professional development, CIP Week Europe will provide delegates with opportunities to explore the latest developments in critical infrastructure protection, resilience, risk management and security, while building stronger connections across sectors and national borders.

With organisations across Europe facing new resilience, security and compliance obligations under the CER and NIS2 Directives, the 3rd CIP Week in Europe will bring together experts from government, industry and academia to explore how critical infrastructure operators can strengthen resilience in an increasingly complex risk environment.

At the centre of the programme will be the Critical Infrastructure Protection & Resilience Europe (CIPRE) Conference, which will feature expert speakers, case studies and panel discussions addressing the complex and evolving challenges facing Europe's critical infrastructure. Topics will include physical and cyber security, resilience strategy, emerging threats, public-private cooperation, business continuity and the protection of essential services.

"The implementation of the CER and NIS2 Directives marks one of the most significant developments in European critical infrastructure protection in a generation," said John Donlon, Chairman of the International Association of CIP Professionals. "Organisations are being challenged to think differently about resilience, security, governance and collaboration. CIP Week Europe provides an opportunity for practitioners and decision-makers to come together, share experiences and learn from one another as they navigate this changing landscape."

In addition to the main conference, delegates will have access to a series of specialist workshops delivered by partner organisations, providing practical insights and focused discussion on key areas of resilience and infrastructure protection.

Among the first confirmed partners is the Confederation of European Security Services (CoESS), which will host a workshop examining the growing role of private security in safeguarding critical infrastructure. The session will explore how security providers are supporting resilience and preparedness objectives across Europe, strengthening public-private partnerships and helping organisations anticipate, prevent, respond to and recover from an increasingly complex threat environment. Particular attention will be given to the contribution of private security to the EU’s Preparedness Union agenda, including the protection of critical entities, continuity of essential services and crisis readiness across sectors.

Catherine Piana, Director General of CoESS, said, “The Confederation of European Security Services is delighted to play a bigger role in this year’s CIP Week. As Europe faces an increasingly complex and evolving risk landscape, the private sector has a key part to play in supporting operators and governments in implementing the CER Directive, while also contributing to the objectives of the EU’s Preparedness Union. With more than two million security professionals operating across Europe, our industry represents a significant preparedness and response capability that can support CI operators before, during and after crises. However, unlocking this full potential requires greater recognition of private security as a strategic partner, stronger public-private cooperation, information sharing and a more coherent framework for integrating private security into national and European preparedness planning. Our workshop will demonstrate how the private security sector can make a tangible impact on security, preparedness and resilience planning.”

“CIP Week Europe was created to bring together the diverse community of professionals responsible for protecting and strengthening critical infrastructure,” continued John Donlon of IACIPP. “As the risks facing critical infrastructure continue to evolve, collaboration, knowledge sharing and professional development have never been more important. We are delighted to welcome delegates and partners to Brussels for what promises to be our most comprehensive programme yet.”

The event is expected to attract participants from government agencies, critical infrastructure operators, utilities, transport providers, security organisations, emergency services, consultancies, technology providers and academic institutions.

Further announcements regarding speakers, additional workshop partners and programme details will be released in the coming weeks.

For organisations involved in critical infrastructure protection and resilience, CIP Week Europe offers a unique opportunity to engage with leading experts, share experiences and contribute to the development of a stronger and more resilient Europe.

For further information and registration details, please contact:

International Association of CIP Professionals (IACIPP) at www.cip-association.org

IAEA Director General Visits Gulf Region to Strengthen Nuclear Safety and Cooperation

IAEA Director General Rafael Mariano Grossi visited Kuwait, Qatar, the United Arab Emirates and Saudi Arabia following the recent drone attack on the Barakah Nuclear Power Plant, reinforcing nuclear safety, security and regional cooperation.
During his visit to Kuwait, Mr Grossi met with Foreign Minister Sheikh Jarrah Jaber Al-Ahmad Al-Sabah to discuss regional developments and the IAEA’s support to countries in strengthening nuclear safety, security, emergency preparedness and response.
The discussions also highlighted cooperation in the peaceful uses of nuclear technology, including applications in health, food security and environmental protection.
Mr Grossi also visited the Kuwait Institute for Scientific Research (KISR), where he saw efforts using nuclear science to support environmental protection.
At KISR, he also received updates on joint cooperation, including research being carried out aboad the vessel Al-Mostakshif under the IAEA’s NUTEC Plastics initiative to assess threats to marine ecosystems.
During his visit to the GCC Emergency Management Centre, discussions focused on regional cooperation in emergency preparedness and response, as well as on strengthening coordination mechanisms during nuclear or radiological emergencies.
In Doha, DG Grossi met with Qatar’s Prime Minister and Minister of Foreign Affairs, Sheikh Mohammed bin Abdulrahman bin Jassim Al Thani, to discuss regional developments, including issues related to Iran’s nuclear programme, reaffirm the importance of dialogue, diplomacy and international cooperation.
In Abu Dhabi, Mr Grossi met with United Arab Emirates Foreign Minister Sheikh Abdullah bin Zayed Al Nahyan to discuss nuclear safety in the country and in the region following the 17 May drone strike on the Barakah Nuclear Power Plant.
The discussions also covered the growing role of nuclear energy in supporting energy security and economic development, along with emerging technologies such as advanced reactors and small modular reactors.
In his visit to the Barakah Nuclear Power Plant, he commended the response by the Emirates Nuclear Energy Corporation and Federal Authority for Nuclear Regulation following the drone attack and reaffirmed the IAEA’s support for nuclear safety and security in the UAE and the wider region.
He also met plant personnel and highlighted the importance of preparedness, resilience and transparency in ensuring the safe operation of the facility.
In Saudi Arabia, Mr Grossi met with Energy Minister Prince Abdulaziz bin Salman to discuss the Kingdom’s advancing civilian nuclear programme and the IAEA’s support for its safe, secure and transparent development.
Advancing Cooperation
Throughout the visit, Mr Grossi emphasized the importance of international cooperation, strong safety and security frameworks and the responsible use of nuclear science and technology to support development, energy security, environmental protection and human health.

JRC identifies key opportunities for critical raw material recovery

Waste from different sources, including batteries, vehicles and electrical equipment, has great potential for the recovery and recycling of critical raw materials, a new JRC report shows.
Critical raw materials are essential elements of key technologies, from electric vehicles and wind turbines, to drones and smartphones. Currently, the EU is highly dependent on third countries for their supply. As the demand for such technologies is expected to surge, this will put immense pressure on securing access to critical raw materials.
By improving waste collection and processing, the EU can recover strategic raw materials domestically. The production of secondary strategic and critical raw materials, as well as extending the lifetime of products, can reduce dependency on third countries and support the transition to a more circular economy.
A new JRC report identifies a list of products, components and waste streams that could have a significant circularity potential for critical and strategic raw materials, such as permanent magnets from wind turbines, cobalt and lithium in electric vehicle batteries, and aluminium parts in vehicles.
The list, a step forward under the Critical Raw Materials Act, will help EU countries prioritise key waste streams for recoverability and help identify gaps in current waste treatment systems. It also highlights challenges and opportunities for a more circular and strategically independent raw materials’ value chain.
From waste to resource
The analysis highlights current gaps in treatment of waste from specific products. For example, small electrical and electronic equipment account for significant losses of strategic and critical raw materials: 46% of the total strategic and critical raw materials in these products is lost in collection. Yet, common household items, such as hard disk drives and cables could have a significant recovery potential, if well-collected and treated.
Moreover, the report shows that critical raw materials used in electric vehicle batteries and wind turbines - the very technologies which power the shift to cleaner energy - are often not sufficiently recovered, leading to a major loss of critical raw materials when these products reach the end of their life.
Similarly, permanent magnets used in wind turbines tend to get lost in bulk steel and aluminium waste flows, rather than being recovered separately, despite their strategic importance. Losses are projected to jump from 1.9 thousand tonnes per year in 2022 to around 45 thousand tonnes per year in 2030, when the first large wave of turbines reaches their end-of-life.
Towards a more circular economy 
The Critical Raw Materials Act requires EU countries to develop national circularity programmes that target specific waste streams. This report supports the Implementing Act of Article 26 of the Critical Raw Materials Act, and helps governments put in place effective programmes by making it easier to spot gaps in existing legislation, processes and data, and to harness circularity potential.
By keeping critical and strategic materials within the continent, the EU can improve the circular economy and EU competitiveness, while reducing exposure to supply disruptions.
1 2 3 4 69