CISA Launches New Platform to Strengthen Industry Engagement and Collaboration

The Cybersecurity and Infrastructure Security Agency (CISA) launched a new Industry Engagement Platform (IEP) designed to facilitate structured, two-way communication between the agency and companies developing innovative and security technologies. The IEP enables CISA to better understand emerging solutions across the technology ecosystem while giving industry a clear, transparent pathway to engage with the agency.
“With the launch of this new platform, we’re opening the door wider to innovation—giving industry a direct line to share the tools and technologies that can help CISA stay ahead of evolving threats,” said CISA Acting Director Madhu Gottumukkala. “The private sector drives innovation and this collaboration is essential to our national resilience.”
The IEP allows organizations – including industry, non-profits, academia, government partners at all and the research community – with a structured process to request conversations with CISA subject matter experts to describe new technologies and capabilities. These engagements give innovators the opportunity to present solutions that may strengthen our nation’s cyber and infrastructure security.
Through customizable technology profiles, the IEP helps connect organizations to the right CISA experts by capturing areas of expertise and specific topics organizations wish to discuss. Participants may also upload capability overviews for CISA to reference in market research and in understanding emerging technologies across sectors.
While participation in the IEP does not provide preferential consideration for future federal contracts, it serves as a key channel for CISA to gain insight into new capabilities and market trends that support mission needs.
CISA encourages organizations with new, emerging, or advanced technology solutions to visit the Industry Engagement Platform. Current areas of interest include:
- Information technology and security controls
- Data, analytics, storage, and data management
- Communications technologies
- Any emerging technologies that advance CISA’s mission, including post-quantum cryptography and other next-generation capabilities
“Strategic collaboration is essential to strengthening national security and resilience,” Gottumukkala added. “The IEP is one of the ways CISA is aligning innovation with mission needs to advance the defense of our nation’s cyber and critical infrastructure.”

Key international organizations align on AI standards

International standardization bodies have pledged to cooperate on standards for artificial intelligence (AI), aiming to help build an open, sustainable and secure future for all.
The International Electrotechnical Commission (IEC), the International Organization for Standardization (ISO), and the International Telecommunication Union (ITU), at their latest global meeting in Seoul, Republic of Korea, issued a joint commitment to advance the well-being of humanity through AI standards.
The International Summit on AI Standards explores the complex challenges posed by AI and the opportunity to bridge digital divides through effective international standards.
The Seoul Statement enshrines a joint by the three organizations to advance AI standards for the benefit of everyone worldwide.
“Standards are technical tools to uphold the principles we want to live by,” said Seizo Onoe, Director of the Telecommunication Standardization Bureau at ITU. “The vision set out by this joint statement calls for diverse expertise and global commitment to collaboration and consensus – exactly what drives our standards work and exactly the spirit needed to create the future we want.”
A shared vision of AI for humanity
The statement sets out a joint vision and commitments from ITU, ISO and IEC on how technical standards can support the development and deployment of trustworthy AI systems that benefit society, drive innovation, and uphold fundamental rights.
“AI has the potential to bring profound benefits to people and economies across the globe,” said ISO President Sung Hwan Cho. “But to ensure this potential is realized equitably and responsibly, International Standards are essential. This joint statement reflects our commitment to strengthening cooperation across our organizations to deliver relevant, robust and human-centric standards that guide the responsible design and use of AI technologies.”
The summit brought together over 300 participants from 65 countries to share perspectives from government, industry, academia, civil society, the public and private sectors, international organizations and UN agencies.
Reliability and sustainability are crucial for standards to advance the global good. So is respect for human rights.
“The rapid rise of AI confirms a basic truth: technology is always about people,” said IEC President Jo Cops. “As AI becomes central to the global economy, we must urgently establish a guiding framework. This joint commitment underscores the value of international standards as the blueprint for safe, trustworthy, and people-centered AI development.”
Key commitments
The Seoul Statement outlines four key commitments to advance sustainable development and allow everyone to benefit from the AI revolution.
Together, IEC, ISO and ITU have pledged to:
- Actively incorporate socio-technical dimensions in standards development.
- Deepen the understanding of the interplay between international standards and human rights, recognizing both their importance and universality.
- Strengthen an inclusive, dynamic multistakeholder community to develop and apply international standards for the design, deployment, and governance of AI.
- Enhance public-private collaboration on AI capacity building.

Energy resilience in the Netherlands: application of the CER directive and identification of critical entities

The resilience of essential services is a cornerstone for national security and societal stability in the European Union. With this in mind, and as a response to emerging threats and interdependencies between critical infrastructure sectors, the EU introduced in 2022 the Critical Entities Resilience (CER) directive. One of the main points in this directive instructs member states to identify the critical entities that ensure the continuity of essential services across these sectors, including energy. This paper presents the collaboration efforts between the Netherlands Organization for Applied Scientific Research (TNO) and the Dutch Ministry for Climate and Green Growth (KGG) to apply the CER directive to the Dutch energy sector. The project aims to develop a reliable and repeatable method to determine the list of critical entities for each of the selected sectors: natural gas, oil, electricity and district heating.
The proposed method is based first on the definition of the value chains for each subsector followed by the development of a threshold framework that could be used to assess the criticality of processes and entities within the sector. Both pieces of work are then combined in a systematic way to arrive to the final lists of critical entities. The paper starts by presenting the value chains and how they were assembled in Section 2, followed by an explanation of the threshold framework in Section 3. The combination of both approaches and the full method and its application are then outlined in Section 4. The paper  concludes with the main findings and implications of this project in Section 5.
Energy sector value chains
In order to identify the critical entities of the energy sector in the Netherlands, a global overview of each subsector is needed. This overview allows the identification of the critical processes within each energy subsector and the interdependencies between them. This was built in the form of value chains for each subsector. A value chain is defined as the series of steps needed to convert raw energy carrier into a useful resource to consumers and deliver it to said consumers or commercial agents. For example, in the case of oil, this comprises the whole process from crude oil extraction to the delivery of oil products to users. Each value chain is divided into multiple sections that contain a series of processes, subprocesses and assets. A process is defined as each of the activities that enables the previously established value chain. The type of processes can range from engineering, such as production or treatment of an energy carrier, to logistical like transmission and distribution, or commercial, like energy trading, among other types. Each of these processes is carried out by one or multiple entities. An asset is defined as a piece of infrastructure or equipment that enables the previously defined processes. These assets are usually owned and maintained by the entity responsible for said process. The general structure used to build these value chains is shown in Figure 1.
As seen in the figure, these chains provide a clear overview of the main processes involved in each subsector, the main entities responsible for each process and subprocess, and finally, the interrelation and interdependencies between processes. One of the early challenges when defining these values chains is defining their scope. Since the CER directive focuses on entities that enable the value chain in each member state, the limits of the value chain were placed on the processes that happen within the Netherlands. At the edge of these value chains, are the interfaces with neighbouring countries, usually in the form of border connections. The CER directive focuses on the entities that enable the value chain, so final consumers are excluded from the analysis. To further illustrate this with an example, a portion of the oil value chain is shown in Figure 2. This diagram shows the first stages of the value chain, where the oil is produced from different sources or imported into the Dutch system. At each stage, each of the necessary processes is shown, such as onshore and offshore production or crude and oil products storage.
The identification of the processes for each sector was elaborated through a combination of sources. The main one was internal expertise across departments specialising on different energy carriers within TNO. At the same time, during the construction of these value chains, experts from the field, belonging to different entities responsible for each process, were consulted. Aside from this visual representation, a separate spreadsheet mirroring the diagram for each subsector was built. These spreadsheets contain more detailed information on the subsector, including energy volumes, detailed lists of assets and the full list of entities present at each process. The information used to build these overviews was extracted from public sources such as [1], [2] and [3]. This data allowed a better understanding of the weight of each process and subprocess, facilitating the later identification of the critical entities.
All of the processes discussed until now refer to the state of the sectors at the time of writing in 2025. An additional exercise was performed, where an outlook on the state of each subsector was analysed for 2035. In this case, instead of elaborating the whole value chain, only differences with 2025 were illustrated. Examples of this are the expected drop in production of natural gas in the Netherlands [4] or changes in the Dutch refinery market [5]. Additionally, hydrogen was included as a new sector that could play a more significant role in 2035.
Threshold framework
After defining the value chains for each subsector, a clear overview of all the processes and entities is now possible. In order to identify which of these processes are critical, a quantitative framework was established in order to identify the critical processes in a clear, repeatable and uniform way.
For each subsector studied, the CER directive [6] identifies a series of critical entity categories, shown in Table 1. In turn, each of these entities has a series of processes and entities that enable their services. In order to determine if an entity is critical according to the CER, this entity must be essential to enable said process. The question then comes down to what makes an entity essential in the context of a given service. This assessment can be done through a threshold framework. Each service can be assigned one or more thresholds based on a series of criteria. If an entity that provides such service exceeds one or more of these thresholds, it can be then considered critical. The CER directive defines a series of criteria to define these thresholds, shown in Table 2. As seen, all these criteria have a qualitative description and the challenge then becomes the quantification of these thresholds.
The first criterion refers to the number of users that are dependent on an entity that provides one of the services listed in Table 1. To establish a threshold for this parameter two different sources were used: the Dutch risk assessment guideline for integrated national security risk analysis [7] and the values already used by neighboring countries such as Germany, Belgium and Denmark. Each of the subsectors studied have different characteristics and scales they operated within, resulting in different threshold values for each subsector.
To asses interdependencies between CER sectors, first the dependencies between the energy subsectors needs to be determined. Firstly, all of the subsectors are directly dependent on the electricity subsector, powering a significant part of the processes that enable all of the value chains. In the case of natural gas, dependencies were identified in the electricity and heat subsectors, mostly related to natural gas powered boilers and energy stations. In the case of oil, some of the electricity processes, such as emergency diesel power generation were identified. Finally, in the case of heat, no other sector was identified as dependent on it. Furthermore, the CER directive identifies ten other critical sectors, such as transport, government services, wastewater or public health among others. Additionally, member states can add their own sectors to the list, with water management being an important one for the Netherlands. All of these critical sectors can be dependent on the studied energy subsectors. When trying to identify critical entities, it is also important to evaluate whether any of these critical sectors are dependent on them.
An entity can be considered critical if an incident that would affect it would cause a significant disruption to society. In this context, the magnitude of this impact depends on the duration and the severity of the incident. The main source used to assess the weight of a potential disruption duration was [7]. This national guideline defines the severity of an incident based on the duration of it and the number of users affected by it. In the case of electricity, gas and heat this threshold can also be addressed from the angle of security of supply. In the Netherlands, operators are obliged to compensate users economically depending on the duration of the outage. In the case of the oil sector,  a national emergency plan exists, born from the legacy of past oil supply crises [8], where different severity levels are activated based of established thresholds. At the same time, entities have been appointed to permanently maintain established strategic stock levels of crude oil and products at all times to mitigate the impact of potential disruptions.
In addition to the duration of the disruption, in [7] the impact on societal interests are also considered when evaluating the impact of a disruption. In the context of energy, special mention is made to critical off-takers. Regular households are usually covered by the ‘number of users’ criterion, but critical users, such as schools or hospitals, need to be evaluated separately. Entities that directly supply these users can be also considered critical, even if the total number of users does not meet the other thresholds. Additionally, possible severe impacts on the environment can also be considered as severe societal impact. Entities that, in case of failure, would cause environmental disasters, can also be considered critical.
The size and composition of the market that provides the critical service can also play a role in the critical entities determination. A market share threshold can be used to assess this. In the case of a market with a monopoly or oligopoly (either natural or regulated), entities responsible for it are directly critical. In the case of a competitive market, an appropriate value has to be defined as a threshold.
Regarding the threshold of geographic area, two aspects are of importance: the geographic cover of the entity and connections to neighboring countries. In the case of electricity and gas in the Netherlands, the sector is divided into geographic areas that are supplied by given network operators. In most of these cases, the areas contain enough households to reach the number of households threshold previously defined, making most of these operators critical. In the case of the heat networks, they tend to be more localized and cover a smaller number of users, requiring extra analysis when defining the critical operators. In the case of cross border-connections, the Netherlands acts as an energy hub for the electricity, natural gas and oil energy carriers.
The final criterion suggested in the CER is the importance of a given entity for the supply of a critical service. This is the most general criterion described in this section and can be used to appoint as critical entities that play a special role in the supply chain of an energy subsector. This usually concerns entities that, if disrupted, can cause major failures or fallouts in the rest of the value chain without reaching any of the previously defined thresholds.
Using all of the criteria and sources described in this section, a collection of thresholds for every CER service was compiled for each subsector. For the sake of illustration, an extract of this threshold collection is shown in Table 3 for the oil sector in the Netherlands. The exact threshold values have been redacted due to confidentiality reasons. An entity that provides at least one of the essential services and has a large enough presence to exceed the thresholds is considered critical. For this reason, exceeding a single threshold value is enough to appoint that entity critical, even in cases where the service has multiple critical thresholds. Additional tables like Table 3, one for each subsector, can then be used to identify the critical entities present within it.
Identification of critical entities
After describing the value chains for every subsector and compiling the full list of threshold values for every essential service, the final step was to apply all this to build the final list of critical entities. Before this took place, a first version of the value chains and the threshold framework was shared with prominent entities within the electricity, natural gas, oil and district heating subsectors in the Netherlands. The list of organizations to consult was assembled together between TNO and KGG, consisting of both private and public entities and regulators. After collecting all the feedback, a final version of the value chains descriptions and the threshold framework was elaborated. With this work in place, it was now possible to determine the critical entities for each sector. The method used to accomplish this is described in this section.
As explained in Section 2, each subsector was described using a series of processes and subprocesses, with each of them having a list of entities assigned to it. These processes are useful to describe the value chains from a physical point of view, identifying the fundamental steps and the relationship between them. The main limitation of this description is that it does not match one-to-one the essential services described in the CER. This can be overcome by mapping every subprocess in the value chain to its corresponding CER service. This can be done by applying specific sector knowledge to make the connections. An example result is conceptually shown in Figure 3, where it can be seen that an essential CER service can cover one or multiple processes from the value chains. At the same time, there are subprocesses that do not match any of the CER services.
As explained in Section 2, each process of the value chain was assigned the main entities that enable it at a national level.
Thanks to this, once every service has been mapped onto the value chain, it is now possible to link every entity to its corresponding CER service. Combining this insight, with the threshold framework information, it was now possible to link every entity to its corresponding threshold criteria. This is done by using tables such as Table 3, where each service (and now entity) can be assigned a series of threshold criteria and values.
The final step before being able to appoint the critical entities, is to score each entity according to the threshold criteria assigned to it. Again, using the corresponding table for each sector, such as Table 3, every threshold criterion has a parameter assigned to it. This can be for example, number of connections to other countries, total national market share, or specific energy volumes, among others. By researching each sector and entity, it is usually possible, by using publicly available data, to compute these values for each of the previously identified entities.
After completing all of the previous steps, every entity of the value chain is categorized in one of the CER essential services, its threshold criteria identified and how it scores according to this criteria. The final step is to compare the scores of each entity with the maximum threshold values for each criterion, defined in Section 3. If an entity has a single threshold score above the maximum allowed threshold criteria values, it is defined as a critical entity. Applying this process for each sector, service and entity, results in a list with the critical entities requested by the CER directive.
In summary, the method described is structured as follows:
1. Identify every process and subprocess that enable the value chain of the subsector and the relationships between them.
2. For each process and subprocess, identify and collect the main entities responsible for it.
3. Using the criteria defined in the CER, establish a list of threshold values for every critical service also defined in the CER.
4. Map every essential service to its corresponding processes and subprocesses from the value chains defined in step 1.
5. For every essential service, assign it all of the entities previously defined in step 2 that correspond to every (sub)process collected in step 4.
6. Based on the threshold framework developed in step 3, assign the corresponding threshold to every entity, depending on the essential service(s) it is assigned to.
7. Compute every entity’s threshold score for every criteria assigned to it in step 6.
8. Identify what entities have threshold values that exceed the threshold limits defined in step 3.
9. All of the entities that come out from step 7 are assembled into the final list of critical entities.
This method was developed by TNO with advice and support provided by KGG and entities and regulators of each subsector. Once the method was developed and all of the necessary data collected, it was then put into practice in a series of workshops. Each workshop was set to cover one subsector with the goal of reaching the final list with all of its corresponding entities. The parties present in these workshops were the corresponding sector expert groups from TNO, the group responsible for the critical entities appointment at KGG and some key experts from entities within the sectors. Aside from the final list of entities, these workshops also yielded some additional insights. One of them was that, while applying the threshold criteria to entities, in cases where there were multiple of them, one usually dominated. This reduced the number of criteria conflicts and could allow to streamline the threshold framework in a second iteration. Another important insight, is that the list of selected entities can vary significantly depending on the exact threshold values selected. In these cases, additional arguments, such as information from neighboring countries, can be useful to define a more robust threshold value. Finally, it was found that not all CER services are relevant to all countries. For example, only a selection of countries will have entities that will meet the minimum threshold values for fossil fuel production services.
Through this process, TNO provided the ministry with a robust, repeatable method. This method can be applied to any of the discussed energy subsectors and used as a blueprint to identify the critical entities within them. However, the ministry is the responsible body that will ultimately decide which entities will be appointed as critical. As previously mentioned, this method was applied to the current energy landscape in the Netherlands. As future work, it would be interesting to apply this method to different time and geographical scales. The energy sector is expected to change significantly in the coming decades, with new players emerging and old ones fading out. Applying the presented method to the expected sector in ten or twenty years from now could provide useful insights into the evolution of the sector. At the same time, applying it to a European scale could highlight important international dependencies within the continent. Finally, this method does not have to be necessarily limited to the energy sector. It could potentially be applied to other critical sectors that operate in a similar way through value chains and commodity deliveries. Examples of possible sectors could be drinking water management or food production. Finally the current analysis has been performed at a fairly high and abstract level. There could be potential value to be added by including a more quantifiable approach. This could be done through energy network modeling and specific risk scenario analysis.
Conclusion
Through this paper, a methodology was presented and applied for the determination of the Dutch critical entities of the energy subsectors, defined in the EU CER directive. By defining the value chains for each subsector, (natural gas, oil, electricity and district heating), a comprehensive understanding of the main processes and entities present in each of them was established.
After this, a threshold framework was developed to evaluate the criticality of each of these processes and entities. This framework was grounded in the criteria defined also in the CER, including sector dependencies, societal impact and geographic and market shares, among others. The threshold values and categories were tailored for each subsector and service by applying public sources, expert knowledge and consultations to important sector entities.
These two pieces of work were then combined to establish the method applied to appoint the final lists of critical entities. This was done by mapping the processes and entities identified in the value chains to the services and threshold criteria established in the threshold framework. Then, during workshops held between TNO experts, KGG and sector representatives, every entity was classified into its corresponding CER service and their position respect to the established threshold values computed. The application of this method can be used to compile a final list of critical entities for each subsector.
The outcome of this method enables a systematic and robust approach for the determination of the critical entities as defined in the CER directive. This work contributes to a more resilient energy system in the Netherlands, rooted in a repeatable and fact based approach built in collaboration with the subsectors themselves. It also sets the pillars for future updates and refinements and enables the Netherlands to adapt to a changing energy and threat landscape in the coming decades.
By J. Santiago Patterson, J. van Diemen, M.J.J. Scheepers, TNO

Quantum Safe Networks for Critical Infrastructure Protection and Resilience

As the world increasingly relies on interconnected digital systems, the vulnerability of critical infrastructure to cyber threats has become a pressing concern. Traditional cryptographic methods, while effective for securing communications today, are at risk of being compromised by the advent of quantum computing. Quantum-safe networks, which incorporate cryptographic techniques and key distribution methods resistant to quantum algorithms, offer a promising solution to ensuring the long-term security and resilience of critical infrastructure.
Increasingly powerful quantum computers make the threat to current cryptographic systems loom large. The timeline for a cryptographically relevant quantum computer (CRQC) is uncertain, but the cybersecurity migration needed to counter this threat is the largest we’ve ever faced and will take considerable time and effort.
Telecommunication networks, responsible for transporting our data, are a crucial element in this equation. However, there is no one-size-fits-all solution to make a network “quantum-safe”. Quantum safe network is not a technology, but an outcome of different measures that can reduce the risk of a CRQC attack
In the 1990s, Nokia Bell Labs researcher Peter Shor invented a new algorithm for prime factorization, specifically designed to run on quantum computers. Using Shor’s quantum algorithm, a sufficiently powerful quantum computer would be able to crack encryption algorithms that are widely used today.
Recent advancements in quantum computers heighten the threat of a “cryptographically relevant” quantum computer. However, not all cryptographic algorithms are vulnerable to this threat.
Symmetric and asymmetric cryptography
Only asymmetric cryptography (a.k.a. public-key cryptography) can be broken by future quantum computers using Shor’s quantum algorithm. Symmetric cryptography, though vulnerable to Grover’s quantum algorithm for brute force attack, remains safe.
Primitive quantum computers have been available for a while, but they are still far from being able to break today’s asymmetric ciphers.
Although the exact timeline is uncertain, experts envisage a cryptographically relevant quantum computer becoming available within the next decades. Despite this, Harvest Now Decrypt Later (HNDL) possible attacks and increasing investments on quantum computer research, supported by AI, are shifting much closer the risk of CRQC on the cryptography.
To address this threat, a new generation of quantum-safe asymmetric cryptography, called post-quantum cryptography (PQC), is being actively researched and developed. The “post-quantum” designation shows that these new algorithms have—so far—been proven to be un-hackable, even by a quantum computer. The first versions of such PQC algorithms were standardized in August 2024 by NIST.
Symmetric and asymmetric cryptography are typically used for different purposes today (see Figure 1).
Symmetric cryptography is mostly used for the encryption of static connections carrying large volumes of data, owing to the larger computational complexity of asymmetric cryptography. Asymmetric cryptography, on the other hand, is mostly used for authentication and for the exchange of symmetric keys in ephemeral connections between endpoints that are not preconfigured (combining the advantages of symmetric and asymmetric cryptography). Both symmetric and asymmetric cryptography can achieve quantum safety, albeit through distinct methods.
Quantum-safe solutions
Quantum-safe solutions are already commercially available today. Their applicability is uncontrolled/static environments with a small number of endpoints and a large volume of traffic (e.g., transport network links or enterprise connectivity).
Seven different main measures can be put in place to reduce the risk of CRQC attacks. The first five are summarized below:
1. Use Symmetric encryption on the user plane, with secure encryption algorithms like Advanced Encryption Standard (AES). AES encryptors can be used in different layers of telecommunication protocol stack, implementing secure protocols like OTNSec, MACSec, ANYSec, IPSec, TLS etc…
2. A sufficiently large secret key size (256 bits), following the results of the Grover algorithm applied to CRQCs that reduces the complexity of a brute force attack quadratic speedup for searching unsorted databases
3. Key entropy: ensuring sufficient key randomness (entropy) by, e.g., using a physics-based random number generator that never repeats itself. This increases key unpredictability, crucial for countering brute-force and cryptanalytic attacks.
4. Key rotation: periodically refreshing keys limits the volume of data encrypted by a single key, making it harder to hack and limiting the blast radius in the case of successful hacking
5. Sharing the secret key. There are multiple ways to establish a shared secret key in a quantum-safe manner:
• Using pre-shared keys (PSK), relying on a manual provisioning process or automatic centralized symmetric key distribution (Symmetric Key Infrastructures – SKI). The PSK is not necessarily used to encrypt the data itself. Data is often encrypted by another key (the security association key or SAK) that is securely distributed leveraging encryption from a PSK (used as a key encryption key or KEK) over an out-of-band channel.
• Using post-quantum cryptography (PQC)-based Key Encapsulation Mechanisms (KEMs)
• Using Quantum-Key Distribution (QKD), leveraging quantum-physical properties. Two QKD-capable endpoints can establish a common secret key across a dedicated quantum communication channel that is immune to eavesdropping. However, it’s important to note that, for now, QKD is a partial solution that needs to be complemented by other methods.
Quantum Key Distribution: a partial solution
Although sometimes perceived as a complete solution for quantum-safe networking, QKD occupies a specific place in the quantum-safe solution landscape: it is a partial solution for generating a shared secret key for symmetric encryption. QKD also uses an additional classical channel of communication that requires authentication (to ensure information is exchanged with the correct entity on the other side). Authentication on this channel, however, requires using another cryptographic method such as asymmetric cryptography or pre-shared keys.
Terrestrial QKD also still faces some practical limitations impeding its large-scale adoption. It is severely restricted by distance limitations over terrestrial networks (current operation is limited to ~100 km over optical fiber) and requires special-purpose equipment. Furthermore, it is highly susceptible to denial-of-service attacks, as any manipulation of the quantum states of the transmitted photons destroys the ability to exchange a key over the QKD link.
Practical implementation of terrestrial QKD is today limited to short distances: the use of trusted nodes could extend the distance, at the cost of more quantum appliances and security constraints in the trusted node itself. Moreover, it is strongly suggested to implement QKD protection in “crypto-agility” with other quantum safe key distribution techniques like SKI.
Satellite QKD will soon solve the distance limitations, considering that optical attenuation in the fiber is exponential, while optical attenuation in free-space is quadratic: the use of satellites as intermediate trusted nodes can extend the range of the QKD to thousands of kilometers (figure 2).
Quantum-safe asymmetric solutions (PQC), yes but….
PQC will replace current asymmetric cryptography, which is used in more dynamic and uncontrolled environments with many endpoints. Since asymmetric cryptography is more complex than symmetric cryptography, they are often used together for data encryption. This combines the best of both worlds, establishing the secret key with asymmetric algorithms while doing the encryption with symmetric algorithms.
PQC is based on new mathematical algorithms conjectured to be difficult to solve, even with quantum computers. Those new PQC schemes will be used, for example, for exchanging keys in protocols like Transport Layer Security (TLS), and digital signatures used for authentication, code-signing or message digests (with different uses being addressed by different PQC algorithms).
Since 2016, the US National Institute of Standards and Technology (NIST) has been running an open competition and standardization effort for evaluating and selecting PQC algorithms, which do not rely on quantum computing and run on traditional computing platforms. NIST released the first PQC standards in August 2024.
But there are some limitations also in PQC: it is based on mathematics algorithms, and, like RSA, it could be broken by a quantum/supercomputer in the next years.
Then, migration of classical asymmetric cryptography to PQC will take time (NIST has recognized that, historically, it has taken 10 to 20 years to fully implement cryptographic migrations), in the mean-time Harvest Now, Decrypt Later (HNDL) attack is ongoing and CRQC attack asymmetric cryptography could start to be available.
This make PQC a brick of the Quantum Safe solution, but not the only one…
Defense-in-depth: Crypto Redundancy and Crypto Agility
The above considerations are bringing to the last two measures to reduce the risk of CRQC attacks: Crypto Redundancy and Crypto Agility, in general the Defense-in-Dept concept.
A Communication stream is composed of a multi-layer protocol stack. In modern communications, encryption is implemented at application layer, using algorithms like TLS, based on asymmetric, not quantum safe, key agreement.
Even if migration of conventional cryptography to quantum safe PQC is already started or will start soon, best practice would be to protect application layer encryption with encryption on one (or more) network layers: this can strongly reduce the risk of CRQC attack during migration phase to PQC, protecting at the same time against HNDL attack. Moreover, after the migration of application layer encryption to PQC, the network layer encryption can further protect against the risk of future PQC algorithm break: this is what we call crypto redundancy (figure 3).
Crypto-agility is the ability of a system, protocol, or application to easily and safely switch between different cryptographic algorithms or protocols.
It’s an important design principle in cybersecurity because cryptographic algorithms can become obsolete over time due to advances in cryptanalysis, increased computing power or Evolving standards.
In general, crypto-agility is the best answer against the change of threats.
Examples of Crypto-Agility are:
• Network layer quantum safe cryptography protection during the application layer cryptography migration to PQC
• Network layer quantum safe cryptography protection during upgrade to safer PQC algorithm at application layer
• QKD seamless switch to SKI during a denial-of-service attack to the QKD layer (e.g. attack to the fiber to steal quantum material for key decrypting)
Conclusions
The advent of quantum computing poses a significant threat to the security of critical infrastructure, highlighting the urgent need for the adoption of Quantum Safe Networks. The importance of early migration to quantum safe protection cannot be overstated, as it will enable the protection of sensitive information and prevent potential disruptions to critical services.
Network encryption technologies play a crucial role in safeguarding the Post-Quantum Cryptography (PQC) migration at the application layer, ensuring the confidentiality, integrity, and authenticity of data transmitted over critical infrastructure networks. The implementation of a Defense-in-depth approach, incorporating multilayer cryptography (crypto redundancy) and crypto agility, is essential to counter the evolving threat landscape.
The use of multilayer cryptography provides an additional layer of security, ensuring that even if one layer is compromised, the other layers remain intact, protecting the data. This crypto redundancy is vital in mitigating the risks associated with the potential compromise of a single cryptographic algorithm or protocol.
Furthermore, crypto agility is critical in enabling the swift adaptation to changing threats and the seamless integration of new cryptographic protocols and algorithms as they become available. This agility ensures that critical infrastructure networks can respond effectively to emerging threats, minimizing the risk of disruption and ensuring the continued availability of essential services.
The evidence suggests that a proactive approach to quantum safe protection, incorporating a Defense-in-depth strategy with multilayer cryptography and crypto agility, is essential for protecting critical infrastructure from the threats posed by quantum computing. By prioritizing migration to quantum safe networks and adopting a robust and agile cryptographic framework, organizations can ensure the long-term resilience and security of their critical infrastructure, safeguarding the integrity of sensitive information and preventing potential disruptions to vital services.
To take the next step, it is recommended that organizations begin by conducting a thorough risk assessment to identify areas of vulnerability and develop a comprehensive migration plan to quantum safe networks. This plan should include the implementation of network encryption technologies, multilayer cryptography, and crypto agility, as well as ongoing monitoring and evaluation to ensure the continued effectiveness of these measures. By taking a proactive and multi-faceted approach to quantum safe protection, organizations can ensure the security and resilience of their critical infrastructure in the face of emerging quantum threats.
By Giampaolo Panariello, CTO Network Infrastructure Nokia, Italy

2025 CWE Top 25 Most Dangerous Software Weaknesses

The Cybersecurity and Infrastructure Security Agency (CISA), in collaboration with the Homeland Security Systems Engineering and Development Institute (HSSEDI), operated by the MITRE Corporation, has released the 2025 Common Weakness Enumeration (CWE) Top 25 Most Dangerous Software Weaknesses. This annual list identifies the most critical weaknesses adversaries exploit to compromise systems, steal data, or disrupt services.
Prioritizing the weaknesses outlined in the Top 25 is integral to CISA’s Secure by Design and Secure by Demand initiatives, which promote building and procuring secure technology solutions. CISA and MITRE encourage organizations to review this list and use it to inform their respective software security strategies.
The 2025 CWE Top 25:
Supports Vulnerability Reduction: By focusing on the Top 25, organizations can prioritize lifecycle changes, adopt safer architectural decisions, and reduce high-impact vulnerabilities related to injection, access control, and memory safety defects.
Drives Cost Efficiencies: Eliminating weaknesses early reduces downstream remediation; addressing them before deployment is more efficient and cost effective than patching, reconfiguring, or responding to emergency incidents.
Strengthens Customer and Stakeholder Trust: Transparent efforts to identify, mitigate, and monitor weaknesses demonstrate commitment to Secure by Design principles. Organizations that prioritize eliminating recurring weaknesses contribute to a safer software ecosystem.
Promotes Consumer Awareness: The Top 25 empowers consumers to understand underlying causes of common vulnerabilities, supports more informed purchasing decisions, and encourages adoption of products that follow robust security engineering practices.
Recommendations for Stakeholders:
For Developers and Product Teams: Review the 2025 CWE Top 25 to identify high-priority weaknesses and adopt Secure by Design practices in development.
For Security Teams: Incorporate the Top 25 into vulnerability management and application security testing to assess and mitigate critical weaknesses.
For Procurement and Risk Managers: Use the Top 25 as a benchmark when evaluating vendors and apply Secure by Demand guidelines to ensure investment in secure products.
By shining a light on the most dangerous software weaknesses, CISA and MITRE reinforce collective efforts to reduce vulnerabilities at the source, strengthen national cybersecurity, and improve long-term resilience.

CISA Update Cross-Sector Cybersecurity Performance Goals (CPG 2.0)

CISA has released an updated Cross-Sector Cybersecurity Performance Goals (CPG 2.0) with measurable actions for critical infrastructure owners and operators to achieve a foundational level of cybersecurity.
This update incorporates lessons learned, aligns with the most recent National Institute of Standards and Technology Cybersecurity Framework revisions, and addresses the most common and impactful threats facing critical infrastructure today.
CPG 2.0 includes a new component focused on the essential role of governance in managing cybersecurity. It emphasizes accountability, risk management, and strategic integration of cybersecurity into day-to-day operations, reinforcing the principle that effective governance is the cornerstone of a resilient cyber posture.
CPGs are streamlined and outcome-driven cybersecurity protections for information technology and operational technology environments and provide:
• Clear, foundational practices aligned with real-world threats.
• Straightforward, outcome-oriented language to aid implementation.
• A baseline for guiding investment, benchmarking progress, and reducing risk in measurable ways.
For more information, visit CPG 2.0 and Cross-Sector Cybersecurity Performance Goals | CISA

PRC State-Sponsored Actors Use BRICKSTORM Malware Across Public Sector and Information Technology Systems

The Cybersecurity and Infrastructure Security Agency (CISA) is aware of ongoing intrusions by People’s Republic of China (PRC) state-sponsored cyber actors using BRICKSTORM malware for long-term persistence on victim systems. BRICKSTORM is a sophisticated backdoor for VMware vSphere1,2 and Windows environments.3 Victim organizations are primarily in the Government Services and Facilities and Information Technology Sectors. BRICKSTORM enables cyber threat actors to maintain stealthy access and provides capabilities for initiation, persistence, and secure command and control. The malware employs advanced functionality, including multiple layers of encryption (e.g., HTTPS, WebSockets, and nested TLS), DNS-over-HTTPS (DoH) to conceal communications, and a SOCKS proxy to facilitate lateral movement and tunneling within victim networks. BRICKSTORM also incorporates long-term persistence mechanisms, such as a self-monitoring function that automatically reinstalls or restarts the malware if disrupted, ensuring its continued operation.
The initial access vector varies. In one confirmed compromise, PRC state-sponsored cyber actors accessed a web server inside the organization’s demilitarized zone (DMZ), moved laterally to an internal VMware vCenter server, then implanted BRICKSTORM malware. See CISA, the National Security Agency, and Canadian Cyber Security Centre’s (Cyber Centre’s) joint Malware Analysis Report (MAR) BRICKSTORM Backdoor for analysis of the BRICKSTORM sample CISA obtained during an incident response engagement for this victim. The MAR also discusses seven additional BRICKSTORM samples, which exhibit variations in functionality and capabilities, further highlighting the complexity and adaptability of this malware.
After obtaining access to victim systems, PRC state-sponsored cyber actors obtain and use legitimate credentials by performing system backups or capturing Active Directory database information to exfiltrate sensitive information. Cyber actors then target VMware vSphere platforms to steal cloned virtual machine (VM) snapshots for credential extraction and create hidden rogue VMs to evade detection.
CISA recommends that network defenders hunt for existing intrusions and mitigate further compromise by taking the following actions:
• Scan for BRICKSTORM using CISA-created YARA and Sigma rules; see joint MAR BRICKSTORM Backdoor.
• Block unauthorized DNS-over-HTTPS (DoH) providers and external DoH network traffic to reduce unmonitored communications.
• Take inventory of all network edge devices and monitor for any suspicious network connectivity originating from these devices.
• Ensure proper network segmentation that restricts network traffic from the DMZ to the internal network.
See joint MAR BRICKSTORM Backdoor for additional detection resources.

CISA, Australia, and Partners Author Joint Guidance on Securely Integrating Artificial Intelligence in Operational Technology

CISA and the Australian Signals Directorate’s Australian Cyber Security Centre, in collaboration with federal and international partners, have released new cybersecurity guidance: Principles for the Secure Integration of Artificial Intelligence in Operational Technology.
This guidance aims to help critical infrastructure owners and operators integrate artificial intelligence (AI) into operational technology (OT) systems securely, balancing the benefits of AI—such as increased efficiency, enhanced decision-making, and cost savings—with the unique risks it poses to the safety, security, and reliability of OT environments.
The document focuses on machine learning (ML), large language models (LLMs), and AI agents due to their complex security challenges, but is also applicable to systems using traditional statistical modeling and logic-based automation.
Key Principles for Secure AI Integration:
1. Understand AI: Educate personnel on AI risks, impacts, and secure development lifecycles.
2. Assess AI Use in OT: Evaluate business cases, manage OT data security risks, and address immediate and long-term integration challenges.
3. Establish AI Governance: Implement governance frameworks, test AI models continuously, and ensure regulatory compliance.
4. Embed Safety and Security: Maintain oversight, ensure transparency, and integrate AI into incident response plans.
Critical infrastructure owners and operators are encouraged to adopt these principles to maximize AI benefits while mitigating risks. For further details, review the full guidance.

Legal and Regulatory aspects relating to the physical security of the telecommunications infrastructure used for critical communication services

Evidence from around the world indicates that threats to Mobile Network Operators (MNOs) are increasing, including to their physical infrastructure. On the other hand, critical communications are transitioning from legacy networks, primarily operated by governments, to broadband networks, in which key components such as Radio Access Networks are procured from MNOs or dedicated infrastructure providers. The combined effect of these two trends requires critical communications operators to pay special attention to the security of the physical infrastructure that is used for critical communications.
Given the importance of the topic, TCCA’s Legal & Regulatory Working Group (LRWG) developed this white paper, starting with a survey of the legal and operational frameworks in the member countries of the LRWG. As the laws and regulations amend and update dynamically, the survey outcomes that formed the basis of this paper were the position as of 31 January 2025.
The survey identified two potential approaches: impose security obligations through legislation/regulation, or rely on provisions in the contract between the critical communications operator and the MNO/infrastructure provider. The LRWG’s assessment is that while each approach has advantages and disadvantages, a combination of these two, whereby legislation/regulation impose a minimum standard on which contractual terms build additional/advanced obligations, would serve the interests of the critical communication services best. As new legal/regulatory obligations on physical security would require additional investment, in what proportion that cost should be borne by the parties could ideally be set by the legislation/regulation in a proportional manner.
The European Critical Communication System (EUCCS) aims to set up a European-wide mission critical communication network that is based on national critical communications networks. It will require a common standard in physical security across all the participating critical communications networks, which can be ensured by the two-pronged approach stated above.
Though new legal/regulatory obligations on physical security would increase the costs and compliances of MNOs/infrastructure providers that provide services for critical communications, it would also have a salutary effect due to the improved standards of security in the network. It is highly likely that thebconsumers, particularly the business customers, will start demanding greater reassurances on all aspects of security in the network including of the physical infrastructure. From a wider national perspective, governments have started taking steps to ensure security of networks which will be complemented by legislative/regulatory obligations on infrastructure used for critical communications.
This paper is intended to draw the attention of the critical communications community to the importance of the issue of physical security and to generate a wide discourse which, it is hoped, will result in a global standard on a baseline on physical security of infrastructure supporting critical communications.
Background
In 2020 a bomb explosion at a central hub of the critical communications provider of a major developed country left emergency officials cut off from the outside world and public without access to emergency services. This incident demonstrates very strongly and very clearly the criticality of the security of physical infrastructure to the proper functioning of critical communications. Incidents of damage to undersea telecommunication cables connecting Nordic and Baltic states provide further evidence of the need to protect the physical infrastructure.
TCCA’s LRWG has developed this white paper to highlight the importance of the security of physical infrastructure, as the LRWG is of the view that it is a topic to which more attention should be paid. This paper focuses on the physical security of telecommunications infrastructure, in order to facilitate further discussions in the critical communication community which it is hoped will result in a global standard on the baseline of physical security of infrastructure supporting critical communications. There are many other facets to the security of critical communication services including data/cybersecurity, which will be examined in other publications.
Most of the current critical communication networks using such technologies as TETRA, Tetrapol and P25, are owned and operated by the state. As such, their physical security is assured by the state to the extent deemed necessary. However, the ongoing transition from these networks to broadband networks has changed the operating model, as governmental agencies providing critical communication services will rely on MNO networks to some extent, including the Radio Access Network (RAN). In some instances, the critical communications services may procure services directly from infrastructure providers who are not MNOs, similar to the way MNOs procure services from them. The discussion of this paper is equally applicable to such infrastructure providers as it is to MNOs. Thus, the physical security of these network elements is of paramount importance. However, it is debatable whether the measures that MNOs are currently adopting in this regard are sufficiently robust and fit for purpose.
The paper titled ’Considerations for Government Authorities when they are planning to acquire Mission Critical Mobile Broadband Services’1 produced by TCCA’s Critical Communications Broadband Group (CCBG) in 2015 identifies security as of vital importance to mission critical communications solutions.
Security is central to ensuring reliability, availability, stability and general performance of those solutions.
The paper details the need for physical security of all infrastructure and adds that “the level of perimeter security shall reflect the importance of the assets to the service including CCTV, intruder alarms, access locks, temperature control, fire and smoke detection.”
The EC Council Cybersecurity Exchange has issued a paper titled ‘The Role of Physical Security in Maintaining Network Security’ in 20222 which states “Although physical security is absolutely critical to maintaining network security, it is among the most often forgotten aspects of protecting a network.
Physical security is defined as protecting physical access to your network and all network components, such as computers, servers, and routers.”
The paper titled ‘Mobile Telecommunications Security Landscape3’ by GSMA, issued in 2022, identifies physical attack on the network as one of the operational security threats to networks.
Given the mandate of and the expertise within the LRWG, this paper focuses on legal and regulatory measures that are applicable to the physical security of telecommunication infrastructure. The LRWG notes that there are numerous technical and operational measures that are relevant but that remain outside the scope of this paper.
The LRWG also examined European Commission regulations which have provisions relevant to the physical security of telecommunication infrastructure.
The LRWG recommends that legislation on physical security of critical communication infrastructure, defining baseline requirements and rules for cost ceilings/sharing, be adopted as an EU directive. Such a multinational standard will greatly assist the decision-making process of individual countries and establish a common understanding between all relevant parties, including MNOs, Governments and users.
Moreover a European regulation would serve as an inspiration for the global community of critical communication operators.
For the full report download the TCCA White Paper - “Legal and Regulatory aspects relating to the physical security of the telecommunications infrastructure used for critical communication services”
White paper published by TCCA’s Legal and Regulatory Working Group, March 2025

Europe Celebrates the Success of the 2nd CIP Week and 10th Critical Infrastructure Protection & Resilience Europe Conference in Brindisi, Italy

The 2nd Critical Infrastructure Protection (CIP) Week in Europe and the 10th Critical Infrastructure Protection & Resilience Europe (CIPRE) conference concluded successfully in Brindisi, Italy, after three days of high-level discussions, collaboration, and innovation in securing Europe’s critical infrastructure.
Held from 14–16 October 2025, the joint event brought together senior policymakers, industry leaders, security professionals, and researchers from across Europe and beyond to accelerate collective resilience efforts and share strategies to address emerging threats to vital systems and services.

Organised under the theme “Resilience through Innovation & Collaboration,” the programme featured more than 50 international expert speakers focus on hot topic discussions, with live technical demonstrations, an industry exhibition, and policy roundtables focusing on the implementation of the EU Directives on Critical Entities Resilience (CER) and NIS2, cyber-physical risk management, maritime and energy resilience, supply-chain security, and climate adaptation for infrastructure.

The event was hosted by the City of Brindisi with support from CIP Week organisers, the International Association of Critical Infrastructure Protection Professionals (IACIPP) secretariat, and The International Emergency Management Society (TIEMS), in cooperation with European institutions, national agencies, and private-sector stakeholders.

A Milestone for European Critical Infrastructure Resilience
The 10th anniversary of CIPRE marked a decade of progress in building a shared European approach to protecting critical assets in energy, transport, communications, health, and digital sectors. The concurrent 2nd CIP Week in Europe strengthened awareness, training, and policy coordination among Member States.

Key Outcomes
Delegates highlighted several strategic outcomes and next steps for the resilience community:
• Cross-sectoral action: Agreement to accelerate national implementation of the CER and NIS2 Directives and to deepen public-private information sharing.
• Elevation of emerging risks: Recognition of AI/OT convergence, drone and UAS threats, supply-chain vulnerabilities, climate-driven hazards, and hybrid (cyber + physical) attack vectors.
• Operational collaboration: Launch of working groups to develop interoperable approaches for cyber-physical incident response and supply-chain resilience.
• Innovation pipeline: Demonstrations of operationally viable solutions for OT/ICS protection, resilient communications, and maritime safety, identified for follow-up pilots.

Strategic Significance and Future Outlook
As Europe faces intensifying hybrid and cyber threats, climate disruptions, and rapid technological change, the Brindisi conference outcomes serve as a catalyst for next-phase action, including:
• Accelerated rollout of CER- and NIS2-compliant frameworks across Member States;
• Expanded cross-border risk-assessment and resilience-planning partnerships; and
• Increased investment in cyber-physical protection, supply-chain resilience, and infrastructure adaptation.

Conference Chairman John Donlon added, “We are extremely grateful to all the people and organisations who have supported us and shared their knowledge, expertise, and enthusiasm. In particular, we thank the Mayor of Brindisi, Giuseppe Marchionna, and his team for hosting us in this fantastic city. We heard many insightful presentations by distinguished specialists and held great discussions on the pressing issues affecting international infrastructure and information communities. CIPRE remains the best place for the industry to meet, network, and share experiences.”

1 3 4 5 6 7 63