Defending Against an Active Threat to Siemens S7 Series PLCs

The National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), Department of Energy (DOE), and Environmental Protection Agency (EPA)—hereafter referred to as the authoring agencies—are releasing this Cybersecurity Advisory to warn owners and operators of industrial control systems (ICSs) of an active cyber threat to Siemens S7 Series PLCs and provide relevant mitigations to protect and defend them.
The threat actors are conducting reconnaissance and capability development against U.S.-based Siemens PLC installations using AI-generated exploitation scripts disguised as legitimate monitoring tools. The actors leverage Internet scanning services to find Internet-exposed PLCs running outdated software or that are otherwise poorly protected. The U.S. critical infrastructure sectors most targeted by this threat activity include Critical Manufacturing, Energy, Water and Wastewater, Chemical, Food and Agriculture, and Commercial Facilities. This is not a theoretical risk—it is an active threat. Depending on the specific circumstances, exploitation of poorly protected PLCs could lead to disruption of critical industrial processes, safety incidents, downtime or equipment damage, compromise of sensitive data, compliance violations, and cascading impacts across interconnected systems.
The authoring agencies urge all owners and operators of operational technology (OT) systems using Siemens S7 Series and other PLC devices to proactively check their systems:
- are properly protected with all applicable security patches and updates,
- are isolated from the Internet wherever possible,
- have strong access controls, and
- employ security tooling to monitor ICS environments for anomalous or malicious activity.
These mitigations are particularly important for owners and operators who work with third-party service providers or system integrators who may have remote access to PLCs, as the asset owners may not realize that their systems are exposed and at risk.
Technical details
Note: This advisory uses the MITRE ATT&CK® Matrix for ICS1 framework, version 19, and the MITRE ATT&CK Matrix for Enterprise framework, version 19. This advisory also uses MITRE D3FENDTM, version 1.5.0. See Appendix A and Appendix B for tables of the activity mapped to MITRE ATT&CK and MITRE D3FEND tactics, techniques, and countermeasures.
Threat actor targeting
Threat actors are actively targeting the following Siemens PLC models:
- S7-200 Series (all CPU variants)
- S7-300 Series (all CPU variants including 314, 315, 317 models)
- S7-400 Series (all CPU variants)
- S7-1200 Series (CPU 1211C, 1212C, 1214C, 1215C, 1217C variants)
- S7-1500 Series (all CPU variants, including F-series safety controllers)
Threat actors are using AI assistance to generate exploitation scripts using publicly available information on these Siemens S7 Series PLCs for initial access, credential access, denial of service, and other objectives. If these PLCs are exposed to the Internet or insufficiently segmented, then threat actors can exploit various critical and high severity known vulnerabilities in these PLCs.
Note: Using AI to generate exploitation scripts represents an evolution in threat actor capabilities, dramatically reducing the technical expertise and time required to develop working ICS exploitation scripts and malicious tools. In addition, AI enables adversaries to rapidly leverage additional attack vectors and adapt to defensive measures. Threat actors can easily collect public information about vulnerabilities and weaknesses, find exposed and exploitable PLCs, and use AI-generated scripts to act on that information. If PLCs are exposed to the Internet, they are at high risk for exploitation.
Threat actors are leveraging open source industrial automation libraries—specifically snap7.dll/python-snap7—combined with AI-assisted scripting to create custom tools that mimic legitimate OT monitoring solutions. These tools provide read/write access to Siemens S7 Series PLC memory, configuration data, and ladder logic programs via the S7comm protocol.
Threat actor techniques
Threat actors are:
- Using Internet scanning services (e.g., Censys, ZoomEye) to identify Internet-exposed or insufficiently segmented Siemens S7 Series PLCs [T1596.005]
- Rapidly iterating exploit code through AI-assisted development, lowering technical barriers to ICS attacks [T1587.004, T1588.007]
- Taking advantage of insecure credentials to access exposed devices that have unconfigured (default) or minimally configured authentication [T1694]
- Deploying AI-generated Python scripts that incorporate the snap7.dll library from public repositories [T0834] to gain read/write access to the PLC and mimic legitimate tools
- Masquerading malicious scripts as legitimate monitoring tools to evade detection by security teams [T0849]
- Conducting read/write operations on data blocks, potentially for reconnaissance, capability testing, or pre-positioning for effects operations [T0893, T0821]
The authoring agencies assess this activity pattern is likely intended as persistent reconnaissance in targeted sectors and facilities to develop capabilities and prepare to cause operational effects against critical infrastructure. For capability development, actors are testing and refining their exploitation techniques against specific PLC models to improve their ability to compromise the PLCs. To prepare for operational effects, actors are leveraging read access to understand target environments, enabling preparation and positioning for future write operations to cause disruption or other operational impacts.
Potential operational impacts
The U.S. critical infrastructure sectors most targeted by this threat activity include Critical Manufacturing, Energy, Water and Wastewater, Chemical, Food and Agriculture, and Commercial Facilities. Additionally, Siemens S7 Series PLCs are used in other sectors, including the Defense Industrial Base (DIB), and could be targeted there as well. Unauthorized access to PLCs could result in:
- Disruption of critical industrial processes affecting production throughput, product quality, and public services
- Safety incidents affecting personnel through manipulation of safety interlocks, emergency shutdown systems, or process parameters
- Equipment damage and extended operational downtime from process upsets, improper sequencing, or forced equipment operation outside design parameters
- Compromise of sensitive operational data, including proprietary process recipes, control strategies, and facility configurations
- Cascading impacts across interconnected systems affecting supply chains, dependent facilities, and integrated business operations
- Regulatory compliance violations and potential liability from process safety management failures
Mitigation actions
Since threat actors are developing capabilities using AI to compromise PLCs using known vulnerabilities, misconfigurations, and other weaknesses and then may use compromised PLCs to interfere with normal operations, the authoring agencies urge organizations to implement comprehensive defense-in-depth strategies, in addition to Common Vulnerabilities and Exposures (CVE) remediation, to protect and defend their PLCs.
Detection opportunities
Organizations should implement detection strategies and hunt for anomalies that may indicate a compromise, focusing on [D3-PM]:
- Anomalous S7comm behavior: Connections from non-engineering workstations, unusual data block access patterns, or write operations outside change windows
- Reconnaissance indicators: Sequential IP scanning on port 102, repeated connection attempts with varying parameters, or enumeration of CPU properties
- Tool artifacts: Snap7.dll library usage outside approved engineering workstations, Python scripts with S7comm functionality, or unauthorized monitoring software installations
- Temporal anomalies: S7comm activity during off-hours, unexpected connection patterns consistent with automated scripting rather than human operators, or configuration changes without corresponding work orders or change tickets
- Geographic anomalies: Connections originating from unexpected countries or IP ranges not associated with vendors or integrators
Preventative hardening actions
To counter threats to PLCs, the authoring agencies recommend all PLC owners and operators follow the mitigations in joint guidance Primary Mitigations to Reduce Cyber Threats to Operational Technology.

OSCE expands access to its technical guidance on the physical security of critical infrastructure

The OSCE Centre in Ashgabat and the OSCE Transnational Threats Department launched the Turkmen version of their Technical Guide on Physical Security Considerations for Protecting Critical Infrastructure from Terrorist Attacks. The launch event was accompanied by a training course on enhancing the physical security of critical infrastructure from terrorist attacks, using the Technical Guide as a training aid.
Developed under the OSCE’s Project PROTECT with support from Germany and the United States of America, the Technical Guide provides practical guidance to policymakers, critical infrastructure owners and operators, and security practitioners on enhancing the protection of critical infrastructure sites from terrorist attacks. The publication consolidates publicly available practices and examples from across the OSCE area and is designed to support stakeholders in developing security measures tailored to their specific risk environment. It was released in November 2025 in the English and Russian. The launch of the Turkmen language version of this Guide, initiated by the OSCE Centre in Ashgabat, is a testament to the Guide's growing value in OSCE participating States.
A representative of the Ministry of Internal Affairs of Turkmenistan presented the country's approach to protecting critical infrastructure, highlighting current practices, the national legislative framework and ongoing efforts to strengthen the security and resilience of critical infrastructure.
The training course brought together government officials responsible for critical infrastructure protection to strengthen their understanding of physical security principles and practices. Participants examined approaches to security system design as well as technical measures including perimeter protection, intrusion detection systems, security lighting, video surveillance, access control and security screening. During the event, participants explored practical ways to apply the Guide’s principles through security assessments, emergency planning, business continuity measures and training exercises.
“The Organization for Security and Co-operation in Europe serves as a vital pillar in global counter-terrorism efforts by actively strengthening the resilience and protection of critical infrastructure across its 57 participating States. Bearing in mind that security is not a task for a single agency or nation, we designed this training programme to build our collective resilience. It is our firm belief that this programme, together with the Guide, will strengthen inter-agency communication and help upgrade security protocols to more effectively protect critical infrastructure from terrorist attacks,” said William Leaf, Head of the OSCE Centre in Ashgabat.
The event featured contributions from international experts and practitioners, as well as the Government of Kazakhstan, another key stakeholder in the OSCE’s Project PROTECT. A representative of the Anti-Terrorism Centre of the Committee of National Security of the Republic of Kazakhstan delivered a presentation on the country's approach to protecting critical infrastructure from terrorist threats.
The event forms part of the OSCE Centre in Ashgabat's project Building Capacity of Law Enforcement and Security Officials of Turkmenistan in Countering Transnational Threats Related to Organized Crime and Terrorism – 2026 and the OSCE's extrabudgetary Project PROTECT, which supports participating States in strengthening national approaches to protecting vulnerable targets from terrorist threats and other hazards.

INTERPOL report finds AI linked to more than half of cybercrime in Africa

Artificial intelligence is enabling 55 per cent of reported cybercrimes across Africa making attacks faster, more scalable, and increasingly difficult for victims and platforms to detect, according to INTERPOL’s African Cyberthreat Assessment Report 2026.

With more than 1.1 billion mobile subscribers recorded in 2025, Africa’s digital transformation is expanding rapidly.

However, cybercrime legislation is fragmented and AI readiness in law enforcement agencies remains alarmingly low.

The 40-page report draws on survey data from 36 African member countries and highlights a defining shift: cyber-criminality has evolved from isolated incidents into an industrialized, borderless ecosystem.

East Africa emerged as a hub of mobile money fraud and infrastructure-targeted ransomware.

Business email compromise and romance scams targeting both corporate and individual victims were prolific in Central and West Africa.

Southern Africa’s ultra-high connectivity makes it a magnet for global threat actors seeking maximum disruption.

The financial toll of cybercrime in Africa is significant.

Since 2024, cybercrime-related losses have more than doubled, from USD 192 million to USD 484 million, driven primarily by AI-facilitated scams, credential harvesting, and automated social engineering campaigns.

According to the report, in 2025, online scams continued to be the most reported type of cybercrime, with attackers leveraging mobile money platforms, social media and AI to reach their targets.

Notably, 72 per cent of surveyed countries reported the presence of scam centres, with the highest concentration in Southern and West Africa.

AI-enabled cyberthreats
Digital sextortion and online harassment, often facilitated by AI-generated deepfakes and synthetic media, remained pervasive, with some 600,000 sextortion detections recorded by TrendAI, one of several partners working with INTERPOL.

Similarly, the sophistication of Business E-Mail Compromise (BEC) schemes increased dramatically, with AI used to generate highly convincing e-mail correspondence, with Africa-based threat actors targeting victims in Europe and North America using infrastructure located across multiple jurisdictions.

The report reveals that the absence of real-time, inter-agency data sharing between banks, telecoms and law enforcement creates a dangerous blind spot in efforts to combat financial fraud.

This vulnerability is being exploited by criminals who have moved beyond simply stealing existing credentials to creating entirely synthetic identities.

Combining real personal data with fabricated elements, these AI-generated digital personas can bypass even advanced biometric verification systems and have been used to open bank accounts, secure mobile loans and register SIM cards under false names.

Neal Jetton, Director of INTERPOL’s Cybercrime unit said, “Cybercrime has emerged as one of the most significant criminal threats to the region. AI is automating every stage of a cyberattack from reconnaissance and phishing to extortion and evasion.

“However, we see that when countries work together, cybercriminal infrastructure can be identified, disrupted and dismantled.”

Meaningful transnational progress is visible. In 2025, 17 countries enacted or amended cybercrime legislation, including the launch of an online reporting platform in Senegal aimed at enhancing the response to online violations affecting children.

At the same time, regionally coordinated capacity building initiatives continue to strengthen long-term cyber resilience.

Operational cooperation is also delivering noteworthy results.

Four high impact cybercrime operations coordinated by INTERPOL including Operation Serengeti 2.0, Operation Contender 3.0, Operation Sentinel and Operation Red Card 2.0 collectively led to more than 1,500 arrests, the seizure of hundreds of devices and the recovery of over USD 100 million.

In its recommendations, the report calls for standardized digital forensic capabilities, enhanced cross-border cooperation, investment in AI literacy among law enforcement officers and formal-public private partnership to support effective prevention, detection and response.

CISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCs

CISA is currently observing a significant increase in cyber threat actors targeting programmable logic controllers (PLCs) in the Water and Wastewater Systems (WWS) Sector. CISA urges critical infrastructure owners, operators, and integrators to remove publicly exposed PLCs and other operational technology (OT) from the internet as soon as possible. Threat actors targeting exposed PLCs have modified passwords to lock out operators and disconnected the PLCs by changing their IP addresses. This activity has resulted in boil water notices and sustained manual operations.

These threat actors are targeting water entities of all sizes. Even water organizations with mature cybersecurity processes should validate their external connections, as this targeting activity includes cellular modems installed by operators, vendors, or system integrators that may not be documented or included in routine attack surface scans. OT assets exposed to the internet have an increased risk of defacement, configuration changes, operational disruptions, and, in severe cases, physical damage.

CISA recommends organizations implement the following mitigations:

- Disconnect the PLC from the internet. Remote access for operational purposes should go through a VPN or gateway device, not directly to the PLC.
- Enable password protection and change default passwords.
- Allowlist IPs to only allow remote access from known engineering laptops or other critical OT assets.

After disconnecting PLCs from the internet, operators should ensure they have a known clean backup of the PLC image in case they are locked out by a modified password. Note: Owners, operators, and integrators of Rockwell Automation MicroLogix 1400 PLCs should see Rockwell Automation’s IMPORTANT NOTICE: Restoring Access to a MicroLogix™ 1400 Controller When the Password Is Unknown for guidance addressing this activity.

To securely enable remote access to your OT systems, CISA recommends system owners, operators, and integrators see the following resources for guidance:

- CISA: Primary Mitigations to Reduce Cyber Threats to Operational Technology
- United Kingdom's National Cyber Security Center: Secure Connectivity Principles for Operational Technology
- Federal Bureau of Investigation (FBI): Malicious Cyber Actors Targeting Water and Wastewater Sector Internet Facing Programmable Logic Controllers, Causing Operational Disruptions

For additional support, contact the Environmental Protection Agency’s Cybersecurity Technical Assistance Program for the Water Sector.

Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure

The Cybersecurity and Infrastructure Security Agency (CISA), in partnership with the Federal Bureau of Investigation (FBI), National Security Agency (NSA), Environmental Protection Agency (EPA), Department of Energy (DOE), United States Cyber Command – Cyber National Mission Force (CNMF), and Department of the Treasury (Treasury) released an updated joint Cybersecurity Advisory Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure.

This update re-emphasizes the ongoing threat from Iranian-affiliated advanced persistent threat (APT) actors targeting internet-connected operational technology (OT) devices, including programmable logic controllers (PLCs) manufactured by Rockwell Automation/Allen-Bradley, Schneider Electric, Siemens, and potentially other brands/manufacturers. These attacks have resulted in operational disruptions and financial losses across multiple U.S. critical infrastructure sectors, including Government Services and Facilities, Water and Wastewater Systems, and Energy.

What’s New in This Update:

• Expanded Targeting: The advisory now includes observed targeting of Schneider Electric and Siemens PLCs, in addition to Rockwell Automation/Allen-Bradley and potentially other branded/manufacturer devices.
• Updated Technical Details: New information on threat actor tactics, including use of configuration software to exfiltrate device project files, and expanded details on targeted ports and device models.
• Enhanced Mitigations: Additional recommendations for securing cellular modems, implementing isolated architectures, validating project files, and detecting malicious changes in reusable code modules (such as Add-On Instructions/AOIs).
• New Indicators of Compromise (IOCs): Updated tables of internet protocol (IP) addresses and timeframes associated with Iranian-affiliated APT activity.

Iranian-affiliated APT actors continue to adapt their tactics, targeting a wider range of devices and sectors. Proactive review of this advisory and implementation of the recommended mitigations are critical to defending your organization’s OT assets and ensuring operational resilience.

NATO PA Promotes Investment in Collective Defence, Infrastructure Protection

The NATO Parliamentary Assembly has highlighted legislators’ vital role in ensuring the Atlantic Alliance faces up to pressing security challenges, strengthening collective defence and protecting against hybrid threats.
The Assembly’s Spring Session drew over 230 lawmakers from NATO and partner nations. Discussions on the second day focused on issues ranging from safeguarding critical infrastructure, maintaining military force levels and fast-tracking defence innovation
“The war in Ukraine is driving new thinking about modern warfare,” explained US Congressman Rick Larsen. “Innovating quickly is important but integrating and scaling new technologies is just as essential.
Drawing on Ukraine’s experience of fast-paced wartime innovation, Larsen said NATO must work urgently to overcome years of underinvestment, insufficient and fragmented demand, slow procurement and overly bureaucratic acquisition systems.
“That’s where we come in,” he told fellow parliamentarians. “We control the budgets. We conduct oversight. We can demand answers when promising technologies stall. We can push governments to integrate NATO commitments into national legislation and procurement systems that work.”
A presentation by Greek member Spyridon Kyriakis centred on shaping NATO’s future forces by improved recruitment, retention of experienced military personnel and strengthening the will to fight within Allied societies.
Faced with an aggressive, expansionist Russia on its doorstep, NATO must take steps to meet recruitment targets and ensure personnel stay in uniform longer, particularly those with critical skills such as cyber, intelligence, logistics and special operations.
“We need a sweeping renewed conversation on how we value, support and inspire our forces,” Kyriakis told the Assembly.
New NATO defence plans, bigger budgets and arms acquisition “can only deliver real deterrence if the Alliance has the well-trained, highly motivated men and women needed to operate and sustain them,” he added.
Lawmakers debated the costs and benefits of conscription and emphasised the importance of building on Ukraine’s experience to build public support and societal resilience to shape mobilisation capacity and wartime outcomes.
“As parliamentarians ... we hold the levers of oversight, the power of legislation and the loudest microphones to champion the profound value of military service to our citizens,” Kyriakis concluded.
Ahead of July’s summit of NATO leaders in Ankara, lawmakers highlighted the role of parliaments in ensuring that Allies stick to the goal of spending at least 5% of gross domestic product (GDP) on defence and security.
“There is still much to be done to bring defence spending to 5% of GDP and transfer that money into actual operational deterrence and defence capabilities,” said Dutch Senator Bart Kroon. “Sustaining that level of spending and transformation will require trade-offs and smart policymaking.”
NATO PA speakers underscored the need to protect critical infrastructure, such as undersea and space assets, from the mounting risk of hybrid attacks.
“Allied security is increasingly dependent upon our space systems and undersea infrastructure,” stated US Congressman Mike Turner. “They are core components of our defence posture and our economic resilience; and are under growing pressure from our adversaries.”
Turner and British Member Lord Nigel Dodds made presentations urging better monitoring and attribution of threats to infrastructure, faster repair and replacement options and solutions that allow forces to operate when communications are degraded by adversaries. Cooperation with the private sector is essential.
“Parliaments and we, as parliamentarians, have an important role to play,” said Dodds. “We can help ensure that national legal frameworks are fit for purpose. We can scrutinise whether governments have clear lead authorities and effective coordination structures. We can support dedicated funding for protection, repair, and response; and we can help keep political attention on this issue before a major disruption occurs.”

CoESS calls for exclusion of Private Security Services from EU Inc. Regulation

The Confederation of European Security Services (CoESS) has published a new position paper raising concerns about the European Commission’s proposal for an EU Inc. Regulation. While the proposal aims to simplify cross-border company operations in the EU, CoESS warns that it could unintentionally weaken national security frameworks and create loopholes in the regulation of private security services.
According to CoESS, private security services are already excluded from the EU Services Directive due to their direct link to internal security, Critical Infrastructure Protection, and support for law enforcement and emergency services. The organisation argues that the proposed EU Inc. framework — with rapid digital incorporation, EU-wide company recognition, and limits on additional national requirements — could make it easier for companies to circumvent national licensing and supervision systems. This would create enforcement challenges for national authorities and increase risks related to unlawful competition and weaker oversight.
The paper highlights that private security regulation differs significantly between Member States, reflecting national public security needs and operational realities. CoESS therefore believes that Member States must retain full control over authorising and supervising companies operating in this sensitive sector. The organisation also warns that the proposal could indirectly undermine the exclusion of private security services from the EU Services Directive by facilitating cross-border operations outside national regulatory frameworks.
CoESS is therefore calling on EU policymakers to explicitly exclude private security services from the scope of the future EU Inc. Regulation. The organisation stresses that such an exclusion is necessary to preserve effective enforcement of national security law and maintain robust supervision of services linked to public safety and Critical Infrastructure Protection.

NIST SP 1800-41, Responding to and Recovering from a Cyber Attack

The NIST National Cybersecurity Center of Excellence (NCCoE) has released the initial public draft of NIST Special Publication 1800-41, Responding to and Recovering from a Cyber Attack: Cybersecurity for the Manufacturing Sector, which provides guidelines on response and recovery activities in an industrial control system (ICS) environment and recommendations to improve operational resilience. The comment period for this publication is open through July 8, 2026.
Background
As Operational Technology (OT) systems like ICS become more interconnected with IT networks, they are increasingly being targeted by cyber threats, putting factory operations, safety, and property at risk. Organizations operating these systems, such as those in the manufacturing sector, need to have plans and capabilities in place to respond to cyber incidents and restore operations to improve overall resilience.
The NCCoE worked with 11 industry collaborators to develop reference architectures, describe response and recovery scenarios, and demonstrate relevant approaches and capabilities.
This draft publication provides actionable guidelines on responding to and recovering from cyber attacks in manufacturing environments. Discover how to:
- Understand the risks and potential impact of cyber incidents on your operations
- Develop a comprehensive response and recovery plan
- Implement best practices to minimize downtime and restore operations quickly

World Bank Group Supports Resilient Municipal Infrastructure to Modernize Cities in Türkiye

The World Bank Group approved a EUR 191.5 million (US$219.4 million) loan to Türkiye to modernize urban infrastructure and services in the fast-growing cities of Antalya and Konya, addressing a growing demand for public transport, clean water and sanitation, and efficient energy systems, while generating jobs along the way.
The Green and Future Cities Project will be implemented through İller Bankası A.Ş. (ILBANK) with the guarantee of the Republic of Türkiye. Türkiye’s rapid urbanization has intensified demand for efficient and resilient municipal infrastructure. While fast-growing cities are central to the country’s economy, many face constraints in accessing long-term financing for major investments to support people and growing economic activities.
“Türkiye’s cities are key drivers of economic growth and job creation but also face increasing pressures from rapid urbanization and climate change,” said                   J. Humberto Lopez, World Bank Country Director for Türkiye. “This project will help municipalities invest in modern, resilient infrastructure while strengthening their capacity to plan and finance sustainable urban development.”
Planned investments include the expansion and modernization of public transport systems, such as tramlines and low-emission vehicles, as well as upgrades to water supply, wastewater treatment, and sanitation infrastructure. The project will also support measures to enhance energy efficiency and strengthen climate adaptation and resilience. These investments are expected to improve urban mobility, enhance environmental sustainability, and raise the quality of life for residents, while contributing to economic growth and job creation.
The project will also provide technical assistance to ILBANK and participating municipalities to strengthen their capacity in project preparation, financial management, and sustainable urban planning. This will include developing pipelines of bankable, climate-smart investments, strengthen municipal financial and institutional capacity, and enhance long-term resilience to climate and disaster risks.
“By combining financing with technical expertise, this project will help cities develop bankable, climate-smart investments and improve their access to long-term financing,” said Ahmet Kindap, Task Team Leader for of the Project.
The project is also designed to help municipalities strengthen their creditworthiness and lay the groundwork for greater private sector participation over time.
Aligned with Türkiye’s national development priorities, the project will support both mitigation and adaptation efforts. Investments are expected to reduce greenhouse gas emissions, enhance energy efficiency, and strengthen resilience to climate-related risks such as flooding, drought, and extreme heat. By improving infrastructure systems and service delivery, the project will help cities better withstand future shocks while promoting sustainable and inclusive urban growth.
This project preparation benefited from technical assistance and grants from the Global Facility for Disaster Reduction and Recovery (GFDRR)’s Japan-World Bank Program for Mainstreaming Disaster Risk Management in Developing Countries, supported by the Government of Japan.

IACIPP ANNOUNCES 3rd ‘CIP WEEK’ IN EUROPE

The International Association of CIP Professionals (IACIPP) has announced that the 3rd CIP Week in Europe will take place in Brussels from 20–22 October 2026, bringing together critical infrastructure operators, government representatives, security professionals, resilience practitioners, emergency planners and industry experts from across Europe.

Designed as a focal point for collaboration, learning and professional development, CIP Week Europe will provide delegates with opportunities to explore the latest developments in critical infrastructure protection, resilience, risk management and security, while building stronger connections across sectors and national borders.

With organisations across Europe facing new resilience, security and compliance obligations under the CER and NIS2 Directives, the 3rd CIP Week in Europe will bring together experts from government, industry and academia to explore how critical infrastructure operators can strengthen resilience in an increasingly complex risk environment.

At the centre of the programme will be the Critical Infrastructure Protection & Resilience Europe (CIPRE) Conference, which will feature expert speakers, case studies and panel discussions addressing the complex and evolving challenges facing Europe's critical infrastructure. Topics will include physical and cyber security, resilience strategy, emerging threats, public-private cooperation, business continuity and the protection of essential services.

"The implementation of the CER and NIS2 Directives marks one of the most significant developments in European critical infrastructure protection in a generation," said John Donlon, Chairman of the International Association of CIP Professionals. "Organisations are being challenged to think differently about resilience, security, governance and collaboration. CIP Week Europe provides an opportunity for practitioners and decision-makers to come together, share experiences and learn from one another as they navigate this changing landscape."

In addition to the main conference, delegates will have access to a series of specialist workshops delivered by partner organisations, providing practical insights and focused discussion on key areas of resilience and infrastructure protection.

Among the first confirmed partners is the Confederation of European Security Services (CoESS), which will host a workshop examining the growing role of private security in safeguarding critical infrastructure. The session will explore how security providers are supporting resilience and preparedness objectives across Europe, strengthening public-private partnerships and helping organisations anticipate, prevent, respond to and recover from an increasingly complex threat environment. Particular attention will be given to the contribution of private security to the EU’s Preparedness Union agenda, including the protection of critical entities, continuity of essential services and crisis readiness across sectors.

Catherine Piana, Director General of CoESS, said, “The Confederation of European Security Services is delighted to play a bigger role in this year’s CIP Week. As Europe faces an increasingly complex and evolving risk landscape, the private sector has a key part to play in supporting operators and governments in implementing the CER Directive, while also contributing to the objectives of the EU’s Preparedness Union. With more than two million security professionals operating across Europe, our industry represents a significant preparedness and response capability that can support CI operators before, during and after crises. However, unlocking this full potential requires greater recognition of private security as a strategic partner, stronger public-private cooperation, information sharing and a more coherent framework for integrating private security into national and European preparedness planning. Our workshop will demonstrate how the private security sector can make a tangible impact on security, preparedness and resilience planning.”

“CIP Week Europe was created to bring together the diverse community of professionals responsible for protecting and strengthening critical infrastructure,” continued John Donlon of IACIPP. “As the risks facing critical infrastructure continue to evolve, collaboration, knowledge sharing and professional development have never been more important. We are delighted to welcome delegates and partners to Brussels for what promises to be our most comprehensive programme yet.”

The event is expected to attract participants from government agencies, critical infrastructure operators, utilities, transport providers, security organisations, emergency services, consultancies, technology providers and academic institutions.

Further announcements regarding speakers, additional workshop partners and programme details will be released in the coming weeks.

For organisations involved in critical infrastructure protection and resilience, CIP Week Europe offers a unique opportunity to engage with leading experts, share experiences and contribute to the development of a stronger and more resilient Europe.

For further information and registration details, please contact:

International Association of CIP Professionals (IACIPP) at www.cip-association.org

1 2 3 48