2025 CWE Top 25 Most Dangerous Software Weaknesses

The Cybersecurity and Infrastructure Security Agency (CISA), in collaboration with the Homeland Security Systems Engineering and Development Institute (HSSEDI), operated by the MITRE Corporation, has released the 2025 Common Weakness Enumeration (CWE) Top 25 Most Dangerous Software Weaknesses. This annual list identifies the most critical weaknesses adversaries exploit to compromise systems, steal data, or disrupt services.
Prioritizing the weaknesses outlined in the Top 25 is integral to CISA’s Secure by Design and Secure by Demand initiatives, which promote building and procuring secure technology solutions. CISA and MITRE encourage organizations to review this list and use it to inform their respective software security strategies.
The 2025 CWE Top 25:
Supports Vulnerability Reduction: By focusing on the Top 25, organizations can prioritize lifecycle changes, adopt safer architectural decisions, and reduce high-impact vulnerabilities related to injection, access control, and memory safety defects.
Drives Cost Efficiencies: Eliminating weaknesses early reduces downstream remediation; addressing them before deployment is more efficient and cost effective than patching, reconfiguring, or responding to emergency incidents.
Strengthens Customer and Stakeholder Trust: Transparent efforts to identify, mitigate, and monitor weaknesses demonstrate commitment to Secure by Design principles. Organizations that prioritize eliminating recurring weaknesses contribute to a safer software ecosystem.
Promotes Consumer Awareness: The Top 25 empowers consumers to understand underlying causes of common vulnerabilities, supports more informed purchasing decisions, and encourages adoption of products that follow robust security engineering practices.
Recommendations for Stakeholders:
For Developers and Product Teams: Review the 2025 CWE Top 25 to identify high-priority weaknesses and adopt Secure by Design practices in development.
For Security Teams: Incorporate the Top 25 into vulnerability management and application security testing to assess and mitigate critical weaknesses.
For Procurement and Risk Managers: Use the Top 25 as a benchmark when evaluating vendors and apply Secure by Demand guidelines to ensure investment in secure products.
By shining a light on the most dangerous software weaknesses, CISA and MITRE reinforce collective efforts to reduce vulnerabilities at the source, strengthen national cybersecurity, and improve long-term resilience.

CISA Update Cross-Sector Cybersecurity Performance Goals (CPG 2.0)

CISA has released an updated Cross-Sector Cybersecurity Performance Goals (CPG 2.0) with measurable actions for critical infrastructure owners and operators to achieve a foundational level of cybersecurity.
This update incorporates lessons learned, aligns with the most recent National Institute of Standards and Technology Cybersecurity Framework revisions, and addresses the most common and impactful threats facing critical infrastructure today.
CPG 2.0 includes a new component focused on the essential role of governance in managing cybersecurity. It emphasizes accountability, risk management, and strategic integration of cybersecurity into day-to-day operations, reinforcing the principle that effective governance is the cornerstone of a resilient cyber posture.
CPGs are streamlined and outcome-driven cybersecurity protections for information technology and operational technology environments and provide:
• Clear, foundational practices aligned with real-world threats.
• Straightforward, outcome-oriented language to aid implementation.
• A baseline for guiding investment, benchmarking progress, and reducing risk in measurable ways.
For more information, visit CPG 2.0 and Cross-Sector Cybersecurity Performance Goals | CISA

PRC State-Sponsored Actors Use BRICKSTORM Malware Across Public Sector and Information Technology Systems

The Cybersecurity and Infrastructure Security Agency (CISA) is aware of ongoing intrusions by People’s Republic of China (PRC) state-sponsored cyber actors using BRICKSTORM malware for long-term persistence on victim systems. BRICKSTORM is a sophisticated backdoor for VMware vSphere1,2 and Windows environments.3 Victim organizations are primarily in the Government Services and Facilities and Information Technology Sectors. BRICKSTORM enables cyber threat actors to maintain stealthy access and provides capabilities for initiation, persistence, and secure command and control. The malware employs advanced functionality, including multiple layers of encryption (e.g., HTTPS, WebSockets, and nested TLS), DNS-over-HTTPS (DoH) to conceal communications, and a SOCKS proxy to facilitate lateral movement and tunneling within victim networks. BRICKSTORM also incorporates long-term persistence mechanisms, such as a self-monitoring function that automatically reinstalls or restarts the malware if disrupted, ensuring its continued operation.
The initial access vector varies. In one confirmed compromise, PRC state-sponsored cyber actors accessed a web server inside the organization’s demilitarized zone (DMZ), moved laterally to an internal VMware vCenter server, then implanted BRICKSTORM malware. See CISA, the National Security Agency, and Canadian Cyber Security Centre’s (Cyber Centre’s) joint Malware Analysis Report (MAR) BRICKSTORM Backdoor for analysis of the BRICKSTORM sample CISA obtained during an incident response engagement for this victim. The MAR also discusses seven additional BRICKSTORM samples, which exhibit variations in functionality and capabilities, further highlighting the complexity and adaptability of this malware.
After obtaining access to victim systems, PRC state-sponsored cyber actors obtain and use legitimate credentials by performing system backups or capturing Active Directory database information to exfiltrate sensitive information. Cyber actors then target VMware vSphere platforms to steal cloned virtual machine (VM) snapshots for credential extraction and create hidden rogue VMs to evade detection.
CISA recommends that network defenders hunt for existing intrusions and mitigate further compromise by taking the following actions:
• Scan for BRICKSTORM using CISA-created YARA and Sigma rules; see joint MAR BRICKSTORM Backdoor.
• Block unauthorized DNS-over-HTTPS (DoH) providers and external DoH network traffic to reduce unmonitored communications.
• Take inventory of all network edge devices and monitor for any suspicious network connectivity originating from these devices.
• Ensure proper network segmentation that restricts network traffic from the DMZ to the internal network.
See joint MAR BRICKSTORM Backdoor for additional detection resources.

CISA, Australia, and Partners Author Joint Guidance on Securely Integrating Artificial Intelligence in Operational Technology

CISA and the Australian Signals Directorate’s Australian Cyber Security Centre, in collaboration with federal and international partners, have released new cybersecurity guidance: Principles for the Secure Integration of Artificial Intelligence in Operational Technology.
This guidance aims to help critical infrastructure owners and operators integrate artificial intelligence (AI) into operational technology (OT) systems securely, balancing the benefits of AI—such as increased efficiency, enhanced decision-making, and cost savings—with the unique risks it poses to the safety, security, and reliability of OT environments.
The document focuses on machine learning (ML), large language models (LLMs), and AI agents due to their complex security challenges, but is also applicable to systems using traditional statistical modeling and logic-based automation.
Key Principles for Secure AI Integration:
1. Understand AI: Educate personnel on AI risks, impacts, and secure development lifecycles.
2. Assess AI Use in OT: Evaluate business cases, manage OT data security risks, and address immediate and long-term integration challenges.
3. Establish AI Governance: Implement governance frameworks, test AI models continuously, and ensure regulatory compliance.
4. Embed Safety and Security: Maintain oversight, ensure transparency, and integrate AI into incident response plans.
Critical infrastructure owners and operators are encouraged to adopt these principles to maximize AI benefits while mitigating risks. For further details, review the full guidance.

Quantum Safe Networks for Critical Infrastructure Protection and Resilience

By Giampaolo Panariello, CTO Network Infrastructure Nokia, Italy

As the world increasingly relies on interconnected digital systems, the vulnerability of critical infrastructure to cyber threats has become a pressing concern. Traditional cryptographic methods, while effective for securing communications today, are at risk of being compromised by the advent of quantum computing. Quantum-safe networks, which incorporate cryptographic techniques and key distribution methods resistant to quantum algorithms, offer a promising solution to ensuring the long-term security and resilience of critical infrastructure.
Increasingly powerful quantum computers make the threat to current cryptographic systems loom large. The timeline for a cryptographically relevant quantum computer (CRQC) is uncertain, but the cybersecurity migration needed to counter this threat is the largest we’ve ever faced and will take considerable time and effort.
Telecommunication networks, responsible for transporting our data, are a crucial element in this equation. However, there is no one-size-fits-all solution to make a network “quantum-safe”. Quantum safe network is not a technology, but an outcome of different measures that can reduce the risk of a CRQC attack
In the 1990s, Nokia Bell Labs researcher Peter Shor invented a new algorithm for prime factorization, specifically designed to run on quantum computers. Using Shor’s quantum algorithm, a sufficiently powerful quantum computer would be able to crack encryption algorithms that are widely used today.
Recent advancements in quantum computers heighten the threat of a “cryptographically relevant” quantum computer. However, not all cryptographic algorithms are vulnerable to this threat.
Symmetric and asymmetric cryptography
Only asymmetric cryptography (a.k.a. public-key cryptography) can be broken by future quantum computers using Shor’s quantum algorithm. Symmetric cryptography, though vulnerable to Grover’s quantum algorithm for brute force attack, remains safe.
Primitive quantum computers have been available for a while, but they are still far from being able to break today’s asymmetric ciphers.
Although the exact timeline is uncertain, experts envisage a cryptographically relevant quantum computer becoming available within the next decades. Despite this, Harvest Now Decrypt Later (HNDL) possible attacks and increasing investments on quantum computer research, supported by AI, are shifting much closer the risk of CRQC on the cryptography.
To address this threat, a new generation of quantum-safe asymmetric cryptography, called post-quantum cryptography (PQC), is being actively researched and developed. The “post-quantum” designation shows that these new algorithms have—so far—been proven to be un-hackable, even by a quantum computer. The first versions of such PQC algorithms were standardized in August 2024 by NIST.
Symmetric and asymmetric cryptography are typically used for different purposes today (see Figure 1).
Symmetric cryptography is mostly used for the encryption of static connections carrying large volumes of data, owing to the larger computational complexity of asymmetric cryptography. Asymmetric cryptography, on the other hand, is mostly used for authentication and for the exchange of symmetric keys in ephemeral connections between endpoints that are not preconfigured (combining the advantages of symmetric and asymmetric cryptography). Both symmetric and asymmetric cryptography can achieve quantum safety, albeit through distinct methods.
Quantum-safe solutions
Quantum-safe solutions are already commercially available today. Their applicability is uncontrolled/static environments with a small number of endpoints and a large volume of traffic (e.g., transport network links or enterprise connectivity).
Seven different main measures can be put in place to reduce the risk of CRQC attacks. The first five are summarized below:
1. Use Symmetric encryption on the user plane, with secure encryption algorithms like Advanced Encryption Standard (AES). AES encryptors can be used in different layers of telecommunication protocol stack, implementing secure protocols like OTNSec, MACSec, ANYSec, IPSec, TLS etc…
2. A sufficiently large secret key size (256 bits), following the results of the Grover algorithm applied to CRQCs that reduces the complexity of a brute force attack quadratic speedup for searching unsorted databases
3. Key entropy: ensuring sufficient key randomness (entropy) by, e.g., using a physics-based random number generator that never repeats itself. This increases key unpredictability, crucial for countering brute-force and cryptanalytic attacks.
4. Key rotation: periodically refreshing keys limits the volume of data encrypted by a single key, making it harder to hack and limiting the blast radius in the case of successful hacking
5. Sharing the secret key. There are multiple ways to establish a shared secret key in a quantum-safe manner:
• Using pre-shared keys (PSK), relying on a manual provisioning process or automatic centralized symmetric key distribution (Symmetric Key Infrastructures – SKI). The PSK is not necessarily used to encrypt the data itself. Data is often encrypted by another key (the security association key or SAK) that is securely distributed leveraging encryption from a PSK (used as a key encryption key or KEK) over an out-of-band channel.
• Using post-quantum cryptography (PQC)-based Key Encapsulation Mechanisms (KEMs)
• Using Quantum-Key Distribution (QKD), leveraging quantum-physical properties. Two QKD-capable endpoints can establish a common secret key across a dedicated quantum communication channel that is immune to eavesdropping. However, it’s important to note that, for now, QKD is a partial solution that needs to be complemented by other methods.
Quantum Key Distribution: a partial solution
Although sometimes perceived as a complete solution for quantum-safe networking, QKD occupies a specific place in the quantum-safe solution landscape: it is a partial solution for generating a shared secret key for symmetric encryption. QKD also uses an additional classical channel of communication that requires authentication (to ensure information is exchanged with the correct entity on the other side). Authentication on this channel, however, requires using another cryptographic method such as asymmetric cryptography or pre-shared keys.
Terrestrial QKD also still faces some practical limitations impeding its large-scale adoption. It is severely restricted by distance limitations over terrestrial networks (current operation is limited to ~100 km over optical fiber) and requires special-purpose equipment. Furthermore, it is highly susceptible to denial-of-service attacks, as any manipulation of the quantum states of the transmitted photons destroys the ability to exchange a key over the QKD link.
Practical implementation of terrestrial QKD is today limited to short distances: the use of trusted nodes could extend the distance, at the cost of more quantum appliances and security constraints in the trusted node itself. Moreover, it is strongly suggested to implement QKD protection in “crypto-agility” with other quantum safe key distribution techniques like SKI.
Satellite QKD will soon solve the distance limitations, considering that optical attenuation in the fiber is exponential, while optical attenuation in free-space is quadratic: the use of satellites as intermediate trusted nodes can extend the range of the QKD to thousands of kilometers (figure 2).
Quantum-safe asymmetric solutions (PQC), yes but….
PQC will replace current asymmetric cryptography, which is used in more dynamic and uncontrolled environments with many endpoints. Since asymmetric cryptography is more complex than symmetric cryptography, they are often used together for data encryption. This combines the best of both worlds, establishing the secret key with asymmetric algorithms while doing the encryption with symmetric algorithms.
PQC is based on new mathematical algorithms conjectured to be difficult to solve, even with quantum computers. Those new PQC schemes will be used, for example, for exchanging keys in protocols like Transport Layer Security (TLS), and digital signatures used for authentication, code-signing or message digests (with different uses being addressed by different PQC algorithms).
Since 2016, the US National Institute of Standards and Technology (NIST) has been running an open competition and standardization effort for evaluating and selecting PQC algorithms, which do not rely on quantum computing and run on traditional computing platforms. NIST released the first PQC standards in August 2024.
But there are some limitations also in PQC: it is based on mathematics algorithms, and, like RSA, it could be broken by a quantum/supercomputer in the next years.
Then, migration of classical asymmetric cryptography to PQC will take time (NIST has recognized that, historically, it has taken 10 to 20 years to fully implement cryptographic migrations), in the mean-time Harvest Now, Decrypt Later (HNDL) attack is ongoing and CRQC attack asymmetric cryptography could start to be available.
This make PQC a brick of the Quantum Safe solution, but not the only one…
Defense-in-depth: Crypto Redundancy and Crypto Agility
The above considerations are bringing to the last two measures to reduce the risk of CRQC attacks: Crypto Redundancy and Crypto Agility, in general the Defense-in-Dept concept.
A Communication stream is composed of a multi-layer protocol stack. In modern communications, encryption is implemented at application layer, using algorithms like TLS, based on asymmetric, not quantum safe, key agreement.
Even if migration of conventional cryptography to quantum safe PQC is already started or will start soon, best practice would be to protect application layer encryption with encryption on one (or more) network layers: this can strongly reduce the risk of CRQC attack during migration phase to PQC, protecting at the same time against HNDL attack. Moreover, after the migration of application layer encryption to PQC, the network layer encryption can further protect against the risk of future PQC algorithm break: this is what we call crypto redundancy (figure 3).
Crypto-agility is the ability of a system, protocol, or application to easily and safely switch between different cryptographic algorithms or protocols.
It’s an important design principle in cybersecurity because cryptographic algorithms can become obsolete over time due to advances in cryptanalysis, increased computing power or Evolving standards.
In general, crypto-agility is the best answer against the change of threats.
Examples of Crypto-Agility are:
• Network layer quantum safe cryptography protection during the application layer cryptography migration to PQC
• Network layer quantum safe cryptography protection during upgrade to safer PQC algorithm at application layer
• QKD seamless switch to SKI during a denial-of-service attack to the QKD layer (e.g. attack to the fiber to steal quantum material for key decrypting)
Conclusions
The advent of quantum computing poses a significant threat to the security of critical infrastructure, highlighting the urgent need for the adoption of Quantum Safe Networks. The importance of early migration to quantum safe protection cannot be overstated, as it will enable the protection of sensitive information and prevent potential disruptions to critical services.
Network encryption technologies play a crucial role in safeguarding the Post-Quantum Cryptography (PQC) migration at the application layer, ensuring the confidentiality, integrity, and authenticity of data transmitted over critical infrastructure networks. The implementation of a Defense-in-depth approach, incorporating multilayer cryptography (crypto redundancy) and crypto agility, is essential to counter the evolving threat landscape.
The use of multilayer cryptography provides an additional layer of security, ensuring that even if one layer is compromised, the other layers remain intact, protecting the data. This crypto redundancy is vital in mitigating the risks associated with the potential compromise of a single cryptographic algorithm or protocol.
Furthermore, crypto agility is critical in enabling the swift adaptation to changing threats and the seamless integration of new cryptographic protocols and algorithms as they become available. This agility ensures that critical infrastructure networks can respond effectively to emerging threats, minimizing the risk of disruption and ensuring the continued availability of essential services.
The evidence suggests that a proactive approach to quantum safe protection, incorporating a Defense-in-depth strategy with multilayer cryptography and crypto agility, is essential for protecting critical infrastructure from the threats posed by quantum computing. By prioritizing migration to quantum safe networks and adopting a robust and agile cryptographic framework, organizations can ensure the long-term resilience and security of their critical infrastructure, safeguarding the integrity of sensitive information and preventing potential disruptions to vital services.
To take the next step, it is recommended that organizations begin by conducting a thorough risk assessment to identify areas of vulnerability and develop a comprehensive migration plan to quantum safe networks. This plan should include the implementation of network encryption technologies, multilayer cryptography, and crypto agility, as well as ongoing monitoring and evaluation to ensure the continued effectiveness of these measures. By taking a proactive and multi-faceted approach to quantum safe protection, organizations can ensure the security and resilience of their critical infrastructure in the face of emerging quantum threats.

Germany’s Critical Infrastructure Protection (KRITIS)

By Michael Kolatchev, Principal, Managing Director at Rossnova Solutions (Belgium) & Lina Kolesnikova, Senior Consultant at Rossnova Solutions (Belgium)

Germany is one of the world’s leading economies, depending heavily on resilience and reliability of its CI to maintain national security and economic competitiveness. In response to evolving threats including cyber-attacks, natural disasters, and physical sabotage, the country continues to modernize and expand its regulatory and institutional architecture for CI protection.
German Federal government defines Critical infrastructures (KRITIS) as “organizations or facilities of vital importance to the public sector, the failure or impairment of which would result in lasting supply bottlenecks, significant disruptions to public safety, or other dramatic consequences”. Such sectors include energy, water, information technology, healthcare, transportation, finance, government and administration, media and culture.
Ensuring protection of organisations is a core task for government and business, and a central theme of Germany’s security policy. Resilience of CI increasingly becomes a priority.
KRITIS before CER and NIS2
Necessity of protecting Critical Infrastructure in Germany emerged in 1997 with a creation of a working group within the Federal Ministry of the Interior (BMI). The acronym KRITIS has been used ever since.
The first years of KRITIS protection were characterized by numerous discussions with industries associations, companies and authorities to identify specific sectoral needs. This also led to creation of the first recommendations and guidelines for operators of CI.
A major milestone was reached in 2009 with the adoption of the first National Strategy for the Protection of Critical Infrastructures (KRITIS Strategy). This strategy is still the foundation for overall execution of tasks, and it contributes significantly to their understanding and acceptance.
UP KRITIS
It is estimated that approximately 80% of Germany’s CI is owned and operated by private companies. Effective communication with stakeholders including government bodies, sectoral organizations, the media, and the public is often facilitated through industrial (sectoral) associations. These associations play a key role in public-private partnerships (PPPs) for infrastructure protection.
One of the key milestones in the development of Germany’s critical infrastructure protection strategy was the establishment of UP KRITIS in 2007. UP KRITIS serves as a cooperation and dialogue platform between government authorities and private-sector operators of CI. While the initial focus was on IT security, the platform has since evolved. Today, UP KRITIS includes over 1000 members and addresses a comprehensive range of topics related to CIP, encompassing both physical and cybersecurity, as well as resilience and emergency preparedness across multiple sectors.
Given the central role of IT in nearly all critical processes and its continuous and rapid development, protection of information infrastructures has become a key priority within UP KRITIS. This focus reflects increasing complexity and dynamic nature of cyber threats.
In addition to IT-related issues, UP KRITIS addresses broader dimensions of infrastructure robustness, emphasizing that physical protection and cybersecurity must be designed and implemented as interconnected and mutually reinforcing elements of a comprehensive security strategy.
The platform’s structure facilitates public-private knowledge sharing, enabling integration of business expertise with governmental capabilities in protecting critical information infrastructure. This collaborative approach has notably strengthened cross-company and cross-sector communication, which is now embedded in all UP KRITIS activities.
Evolving regulations
The Federal Republic of Germany’s approach is closely aligned with evolving EU legislation, particularly the CER Directive, NIS2 Directive, and DORA Regulation. National legislation transposing these directives, such as the KRITIS Umbrella Act and the NIS2 Implementation Act establishes obligations for CI operators across physical and cyber domains. This Act regulates resilience and physical security of critical infrastructures, from 2025 onwards.
The Act sets minimum requirements and establishes a catalogue of obligations demanding operators of critical facilities to implement resilience measures. The all-hazards approach applies: every conceivable risk must be considered, from natural disasters to sabotage, terrorist attacks, and human error. Smaller critical infrastructures have the option of voluntarily implementing resilience measures and can rely on industry-specific standards. Potential funding measures are intended to help them improving.
Penalties for violating the law’ provisions are intended to ensure that compliance with security standards is taken seriously and that critical infrastructures remain protected. Amounts have yet to be determined.
Federal ministries are authorized to issue legal regulations to specify resilience measures for the areas within their jurisdiction.
The regulatory landscape is set to evolve further.
CER
The forthcoming National KRITIS Resilience Strategy (2026) will provide a strategic roadmap to strengthen national coordination and sectoral resilience planning.
In contrast to cybersecurity, physical security has historically received less focus, partly due to the complex federal structure of the country, which consists of sixteen federal states (Länder) with differing responsibilities and approaches. With Germany transposing the EU Critical Entities Resilience (CER) Directive into national law by the end of the year, framework for physical resilience of critical entities will enhance.
NIS 2
Germany continues to experience a high volume of ransomware attacks and distributed denial-of-service (DDoS) attacks. In 2024, the cybersecurity industry recorded over 720 such incidents, representing a 67% increase compared to the previous year. Number of attacks targeting SMEs, government and municipal administrations increased sharply. Healthcare, and hospitals in particular, are under attacks. As for most of countries, many cyberattacks in Germany originate from foreign jurisdictions, making attribution and prosecution difficult. Perpetrators increasingly rely on cybercriminal supply chain where capabilities such as malware development, access brokerage, and laundering of ransom payments are outsourced or consumed as services within the new Crime-as-a-Service paradigm.
On July 24, 2024, the Federal Cabinet passed the draft law for the (EU Directive 2022/2555) NIS 2 Implementation and Cybersecurity Strengthening Act, bringing comprehensive modernisation of German IT security law. IT security and security incident reporting requirements are extended to more companies in more economic sectors, like energy, transport, health, or digital infrastructure. It is expected that the number of organizations subject to cybersecurity obligations in Germany will potentially exceed 30,000 entities. This presents considerable administrative and enforcement challenges for the federal level, while cybersecurity at the federal administration itself must strengthen too. The new laws replace the KRITIS regulations in place in Germany since 2014, with more operators implicated and more obligations. Originally scheduled for October 2024, its coming into force is delayed until new Bundestag in 2025.
The Federal Office for Information Security (BSI) receives new supervisory tools to enforce compliance with the new legal obligations. Operators of critical infrastructure facilities are required to register with the Federal Office for Information Security (BSI). Organizations must promptly report significant cybersecurity incidents there. Registered entities must submit a biennial report to the BSI, detailing cybersecurity measures they have implemented. For accountability and continuous improvement, organizations need to undergo certification and external audits, in accordance with defined standards and sector-specific requirements.
Institutional Architecture
Germany’s CI protection is supported by a range of institutions operating at federal and sectoral levels. The Federal Ministry of the Interior (BMI) provides policy leadership and inter-ministerial coordination. The Federal Office for Information Security (BSI) oversees cybersecurity implementation and maintains national situational awareness. Public–private coordination is facilitated through platforms such as UP KRITIS, with strong engagement from sectoral associations.
The inter-ministerial Joint Coordination Task Force for Critical Infrastructure (GEKKIS) serves three key purposes:
• Provide situational reports on protection of critical infrastructure, supporting all federal ministries with a cross-departmental overview of the up-to-date threat landscape.
• Enable communication among ministries, identify common challenges, and develop coordinated responses.
• Convene ad-hoc coordination group for relevant incidents, ensuring rapid and cohesive government action.
This collaborative institutional setup enables Germany aligning with EU standards, and ensuring tailored implementation through cross-sector coordination, federal–state integration, and public–private engagement.
Conclusion
Germany’s approach to CIP follows evolving EU conceptual framework, compliance with EU directives and national implementation. Key elements include:
• Transposition of EU legal instruments into national law, notably:
• The Directive on the Resilience of Critical Entities (CER Directive)
• The Directive on Security of Network and Information Systems (NIS2)
• The Digital Operational Resilience Act (DORA).
• Lessons learned from previous regulatory cycles.
• Adaptation of EU-wide concepts to Germany’s federal system, accounting for sector-specific and state needs.
Most significant conceptual shift is transition from a protection-centric approach to a broader, dynamic focus on resilience, recognising that 100% security cannot be guaranteed. The emphasis increasingly shifts toward ensuring continuity and rapid recovery of services in the face of disruptions.
Key lesson is Germany’s well-structured system of communication, coordination, and collaboration across federal, state (Länder), and local levels. Different stakeholders play clearly defined roles in two-way communication, both government actors and public and private sectors. Mechanisms such as centralized platforms for incident reporting, secure information exchange, and cross-sector coordination, help foster mutual trust and transparency. These structures significantly enhance situational awareness, and enable rapid, coordinated responses to emerging threats.
In the energy sector, operational continuity is central. Installed capacity must match national demand while demanding dynamic power management, with renewable energy in mind, for long-term sustainability. German experience demonstrates integration of existing systems, managed decentralization, and flexible response to demand surges and supply disruptions.
Widespread digitization of CI has exposed systems to new and complex threats, rendering traditional protection methods inadequate. Cybersecurity becomes strategic to CIP. Once a peripheral concern, it has now dedicated legislation, enforcement mechanisms, and technical standards. Rules and oversight structures dedicated to cybersecurity is a response to this reality and a model worth consideration by other countries.
Historically, the focus of CIP has been on large, high-value assets. Supply chains and SMEs now have a greater role. Risk management must extend across entire ecosystems, using unified threat catalogues to support all-hazards risk assessments. If one wants compatibility, consistency, and coordinated responses across sectors and involved operators of different organization types.

UK arrest following aerospace cyber incident

A man has been arrested in the UK by the National Crime Agency as part of an investigation into a cyber incident impacting Collins Aerospace.
The incident, which was reported on 19 September, affected flights at Heathrow and other European airports over the weekend.
NCA officers, supported by the South East ROCU, arrested a man in his forties in West Sussex yesterday evening on suspicion of Computer Misuse Act offences. He has been released on conditional bail.
Deputy Director Paul Foster, head of the NCA’s National Cyber Crime Unit, said:
“Although this arrest is a positive step, the investigation into this incident is in its early stages and remains ongoing.”
“Cybercrime is a persistent global threat that continues to cause significant disruption to the UK. Alongside our partners here and overseas, the NCA is committed to reducing that threat in order to protect the British public.”

Unidentified Drone Incursions Temporarily Shut Down Copenhagen and Oslo Airports

Authorities in Denmark and Norway are investigating a series of unauthorized drone sightings that forced the temporary closure of airspace over two major international airports—Copenhagen's Kastrup Airport and Oslo's Gardermoen Airport, and are being treated as serious threats to national and regional security.
In Copenhagen, multiple drones were detected near the airport perimeter, leading to a near four-hour shutdown that disrupted over 50 flights and affected approximately 20,000 passengers. Danish police say the drones demonstrated flight behavior consistent with advanced operation, and officials have described the incursion as one of the most significant threats to Denmark’s critical infrastructure in recent memory.
Shortly after the Copenhagen incident, Oslo’s main airport reported similar drone activity, prompting Norwegian authorities to temporarily close airspace. Though the disruption lasted just under three hours, it led to delays and diversions and raised concerns about a coordinated effort.
While Danish and Norwegian officials are cooperating closely, no definitive link between the two incidents has been established. Authorities in both countries are analyzing radar data, visual reports, and drone signatures as part of a joint investigation. Danish leadership has confirmed the threat level to critical infrastructure remains elevated.
Security experts across Europe have expressed growing alarm over the vulnerability of critical national infrastructure and entities to drone-related threats. Discussions are now underway among Nordic and EU partners regarding the implementation of a regional drone defense strategy.

CISA Releases Advisory on Lessons Learned from an Incident Response Engagement

CISA released a cybersecurity advisory detailing lessons learned from an incident response engagement following the detection of potential malicious activity identified through security alerts generated by the agency’s endpoint detection and response tool.
This advisory, CISA Shares Lessons Learned from an Incident Response Engagement, highlights takeaways that illuminate the urgent need for timely patching, comprehensive incident response planning, and proactive threat monitoring to mitigate risks from similar vulnerabilities.
The advisory also outlines the tactics, techniques, and procedures (TTPs) employed by cyber threat actors, including exploitation of GeoServer Vulnerability CVE-2024-36401 for initial access. By understanding these TTPs, organizations can enhance their defenses against similar threats.
CISA recommends organizations take the following actions:
- Prioritize Patch Management: Expedite patching of critical vulnerabilities, particularly those listed in CISA’s Known Exploited Vulnerabilities catalog, with a focus on public-facing systems.
- Strengthen Incident Response Plans: Regularly update, test, and maintain incident response plans, ensuring they include procedures for engaging third-party responders and deploying security tools without delay.
- Enhance Threat Monitoring: Implement centralized, out-of-band logging and ensure security operations centers continuously monitor and investigate abnormal network activity to detect and respond to malicious activity effectively.
CISA urges organizations to apply these lessons learned to bolster their security posture, improve preparedness, and reduce the risk of future compromises. For additional details, review the full cybersecurity advisory.

Building Ukraine’s Shield: The Bold New Effort to Train Critical Infrastructure Security Professionals

In November 2021, a landmark law on Critical Infrastructure Protection (CIP) was signed by the President of Ukraine—setting in motion a national effort to secure the lifelines of the country’s economy, defense, and daily life. Two years later, in September 2023, the Cabinet of Ministers approved Ukraine’s National Plan for the Protection, Security, and Resilience of Critical Infrastructure, a document that not only laid out an ambitious strategy but also revealed a major vulnerability: a critical shortage of qualified professionals.

The question soon became unavoidable—how and where can Ukraine train the specialists essential to protecting its most vital systems? The National Plan mandated a full feasibility study to explore this issue and develop recommendations for building a sustainable educational and training ecosystem for CIP professionals.

This comprehensive study was the first of its kind in Ukraine and worldwide and took a global approach. It examined not only Ukraine’s own experience but also incorporated lessons and best practices from the European Union, North America, and international organizations such as the United Nations, NATO, OSCE and the World Bank. The study team interviewed over 50 subject matter experts from Ukraine, the EU, and the United States, representing government agencies, industry sectors, and academic institutions.

The Feasibility Study to Affect the Development of Critical Infrastructure Security and Resilience (CISR) Education and Training System in Ukraine was carried out by Ukrainian, Italian, and American experts in critical infrastructure protection, with financial support from the U.S. Department of State. It was also supported by the Directorate of Professional Pre-Higher and Higher Education of the Ministry of Education and Science of Ukraine, the Critical Infrastructure Security Service of the National Security and Defense Council (NSDC), and the Department of Critical Infrastructure Protection of the State Service of Special Communications and Information Protection (SSSCIP).

The study’s main conclusion was that the development of an education and training system for critical infrastructure protection in Ukraine is both possible and necessary. Such a system is needed to prepare leaders, managers, specialists, and trained personnel capable of carrying out a wide range of tasks in the field of CI protection — all in line with Ukrainian legislation and national security goals.

It worth to mention that the results of this Study was officially presented in Lecce, Italy, during the international workshop on “Development of University Programs on Critical Infrastructure Security and Resilience” in March 2024. The event served as a vital platform for Ukrainian participants and international experts to exchange knowledge, share best practices, and explore innovative approaches in the field of Chemical Critical Infrastructure Security and Resilience (CISR) education. The workshop highlighted the importance of academic collaboration in strengthening the resilience of critical sectors and advancing specialized university programs across borders.

Although the study was conducted in 2024, it has already led to several significant outcomes:

1. On June 27, 2024, the Center for Critical Infrastructure Security and Resilience was established at the Department of Civil and Industrial Safety named after Hero of Ukraine O.S. Chub, within the Faculty of Environmental Safety, Engineering, and Technology at Kyiv Aviation University. This center attracted the attention of the Ministry of Infrastructure and Transportation of Ukraine, which has since accepted university students studying CIP for internships at transportation-related CI facilities in Kyiv.

2. The National Institute for Strategic Studies established two working groups focused on developing educational programs in the field of CIP. As a result, a proposal is being prepared for submission to the Ministry of Education of Ukraine to formally introduce new CIP curricula and programs in Ukrainian universities.

3. Compared to the Research on CIP education conducted in 2021, there is clear progress in the development of university-level programs both at the national level (Kyiv) and in several regions (Lviv, Kharkiv, and Cherkasy). This development is supported by the National Qualifications Agency of Ukraine and coordinated by the CIP offices of the NSDC and SSSCIP.

4. Based on the findings of the study, four new professions related to critical infrastructure protection were added to the National Occupational Classifier of Ukraine, including:

* Risk, Threat, and Vulnerability Analyst for Critical Infrastructure – identifies potential threats and vulnerabilities, assesses risks, and develops mitigation recommendations;

*Critical Infrastructure Protection Expert – provides expert assessments of protection methods and ensures resilience against threats;

*Specialist in Critical Infrastructure Protection and Resilience – directly implements protection measures and ensures operational continuity in crisis conditions;

*Head (or other manager) of a Department/Unit for Critical Infrastructure Protection – organizes, coordinates, and oversees security measures, conducts risk assessments, interacts with law enforcement and specialized agencies, and implements policies and standards to ensure CI resilience.
Currently, an interagency working group in Ukraine is developing professional standards for these roles. Whether this initiative will be successful will depend on the outcomes of pilot projects and the real-world performance of certified professionals at critical infrastructure enterprises. It remains to be seen whether additional, more in-depth research and business analysis of the functional responsibilities of CI professionals at enterprises across Ukraine’s 24 critical infrastructure sectors (as defined by a Cabinet of Ministries of Ukraine’s resolution) will be necessary. Based on such analysis, there may be a need to adjust or refine the newly introduced CIP professions, taking into account the 2008 EU Directive and the experience of the 5 CIP SISTERS: United States,Canada, the United Kingdom of the Great Britain, New Zeland and Australia.

In conclusion, the issue of training critical infrastructure protection professionals, especially for sector-specific enterprises, still requires deeper research and strategic planning. Only by thoroughly analyzing the operational needs and critical functions of CI enterprises can Ukraine accurately define the roles and responsibilities of CIP specialists and reflect them in professional standards, paving the way for the development of a qualified and mission-ready workforce.

By Vladlen Basystyi, Technical Advisor at CRDF Global, specializing in cybersecurity and critical infrastructure protection

1 2 3 4 5 6 59