OSCE expands access to its technical guidance on the physical security of critical infrastructure

The OSCE Centre in Ashgabat and the OSCE Transnational Threats Department launched the Turkmen version of their Technical Guide on Physical Security Considerations for Protecting Critical Infrastructure from Terrorist Attacks. The launch event was accompanied by a training course on enhancing the physical security of critical infrastructure from terrorist attacks, using the Technical Guide as a training aid.
Developed under the OSCE’s Project PROTECT with support from Germany and the United States of America, the Technical Guide provides practical guidance to policymakers, critical infrastructure owners and operators, and security practitioners on enhancing the protection of critical infrastructure sites from terrorist attacks. The publication consolidates publicly available practices and examples from across the OSCE area and is designed to support stakeholders in developing security measures tailored to their specific risk environment. It was released in November 2025 in the English and Russian. The launch of the Turkmen language version of this Guide, initiated by the OSCE Centre in Ashgabat, is a testament to the Guide's growing value in OSCE participating States.
A representative of the Ministry of Internal Affairs of Turkmenistan presented the country's approach to protecting critical infrastructure, highlighting current practices, the national legislative framework and ongoing efforts to strengthen the security and resilience of critical infrastructure.
The training course brought together government officials responsible for critical infrastructure protection to strengthen their understanding of physical security principles and practices. Participants examined approaches to security system design as well as technical measures including perimeter protection, intrusion detection systems, security lighting, video surveillance, access control and security screening. During the event, participants explored practical ways to apply the Guide’s principles through security assessments, emergency planning, business continuity measures and training exercises.
“The Organization for Security and Co-operation in Europe serves as a vital pillar in global counter-terrorism efforts by actively strengthening the resilience and protection of critical infrastructure across its 57 participating States. Bearing in mind that security is not a task for a single agency or nation, we designed this training programme to build our collective resilience. It is our firm belief that this programme, together with the Guide, will strengthen inter-agency communication and help upgrade security protocols to more effectively protect critical infrastructure from terrorist attacks,” said William Leaf, Head of the OSCE Centre in Ashgabat.
The event featured contributions from international experts and practitioners, as well as the Government of Kazakhstan, another key stakeholder in the OSCE’s Project PROTECT. A representative of the Anti-Terrorism Centre of the Committee of National Security of the Republic of Kazakhstan delivered a presentation on the country's approach to protecting critical infrastructure from terrorist threats.
The event forms part of the OSCE Centre in Ashgabat's project Building Capacity of Law Enforcement and Security Officials of Turkmenistan in Countering Transnational Threats Related to Organized Crime and Terrorism – 2026 and the OSCE's extrabudgetary Project PROTECT, which supports participating States in strengthening national approaches to protecting vulnerable targets from terrorist threats and other hazards.

NATO PA Promotes Investment in Collective Defence, Infrastructure Protection

The NATO Parliamentary Assembly has highlighted legislators’ vital role in ensuring the Atlantic Alliance faces up to pressing security challenges, strengthening collective defence and protecting against hybrid threats.
The Assembly’s Spring Session drew over 230 lawmakers from NATO and partner nations. Discussions on the second day focused on issues ranging from safeguarding critical infrastructure, maintaining military force levels and fast-tracking defence innovation
“The war in Ukraine is driving new thinking about modern warfare,” explained US Congressman Rick Larsen. “Innovating quickly is important but integrating and scaling new technologies is just as essential.
Drawing on Ukraine’s experience of fast-paced wartime innovation, Larsen said NATO must work urgently to overcome years of underinvestment, insufficient and fragmented demand, slow procurement and overly bureaucratic acquisition systems.
“That’s where we come in,” he told fellow parliamentarians. “We control the budgets. We conduct oversight. We can demand answers when promising technologies stall. We can push governments to integrate NATO commitments into national legislation and procurement systems that work.”
A presentation by Greek member Spyridon Kyriakis centred on shaping NATO’s future forces by improved recruitment, retention of experienced military personnel and strengthening the will to fight within Allied societies.
Faced with an aggressive, expansionist Russia on its doorstep, NATO must take steps to meet recruitment targets and ensure personnel stay in uniform longer, particularly those with critical skills such as cyber, intelligence, logistics and special operations.
“We need a sweeping renewed conversation on how we value, support and inspire our forces,” Kyriakis told the Assembly.
New NATO defence plans, bigger budgets and arms acquisition “can only deliver real deterrence if the Alliance has the well-trained, highly motivated men and women needed to operate and sustain them,” he added.
Lawmakers debated the costs and benefits of conscription and emphasised the importance of building on Ukraine’s experience to build public support and societal resilience to shape mobilisation capacity and wartime outcomes.
“As parliamentarians ... we hold the levers of oversight, the power of legislation and the loudest microphones to champion the profound value of military service to our citizens,” Kyriakis concluded.
Ahead of July’s summit of NATO leaders in Ankara, lawmakers highlighted the role of parliaments in ensuring that Allies stick to the goal of spending at least 5% of gross domestic product (GDP) on defence and security.
“There is still much to be done to bring defence spending to 5% of GDP and transfer that money into actual operational deterrence and defence capabilities,” said Dutch Senator Bart Kroon. “Sustaining that level of spending and transformation will require trade-offs and smart policymaking.”
NATO PA speakers underscored the need to protect critical infrastructure, such as undersea and space assets, from the mounting risk of hybrid attacks.
“Allied security is increasingly dependent upon our space systems and undersea infrastructure,” stated US Congressman Mike Turner. “They are core components of our defence posture and our economic resilience; and are under growing pressure from our adversaries.”
Turner and British Member Lord Nigel Dodds made presentations urging better monitoring and attribution of threats to infrastructure, faster repair and replacement options and solutions that allow forces to operate when communications are degraded by adversaries. Cooperation with the private sector is essential.
“Parliaments and we, as parliamentarians, have an important role to play,” said Dodds. “We can help ensure that national legal frameworks are fit for purpose. We can scrutinise whether governments have clear lead authorities and effective coordination structures. We can support dedicated funding for protection, repair, and response; and we can help keep political attention on this issue before a major disruption occurs.”

CoESS calls for exclusion of Private Security Services from EU Inc. Regulation

The Confederation of European Security Services (CoESS) has published a new position paper raising concerns about the European Commission’s proposal for an EU Inc. Regulation. While the proposal aims to simplify cross-border company operations in the EU, CoESS warns that it could unintentionally weaken national security frameworks and create loopholes in the regulation of private security services.
According to CoESS, private security services are already excluded from the EU Services Directive due to their direct link to internal security, Critical Infrastructure Protection, and support for law enforcement and emergency services. The organisation argues that the proposed EU Inc. framework — with rapid digital incorporation, EU-wide company recognition, and limits on additional national requirements — could make it easier for companies to circumvent national licensing and supervision systems. This would create enforcement challenges for national authorities and increase risks related to unlawful competition and weaker oversight.
The paper highlights that private security regulation differs significantly between Member States, reflecting national public security needs and operational realities. CoESS therefore believes that Member States must retain full control over authorising and supervising companies operating in this sensitive sector. The organisation also warns that the proposal could indirectly undermine the exclusion of private security services from the EU Services Directive by facilitating cross-border operations outside national regulatory frameworks.
CoESS is therefore calling on EU policymakers to explicitly exclude private security services from the scope of the future EU Inc. Regulation. The organisation stresses that such an exclusion is necessary to preserve effective enforcement of national security law and maintain robust supervision of services linked to public safety and Critical Infrastructure Protection.

IAEA Director General Visits Gulf Region to Strengthen Nuclear Safety and Cooperation

IAEA Director General Rafael Mariano Grossi visited Kuwait, Qatar, the United Arab Emirates and Saudi Arabia following the recent drone attack on the Barakah Nuclear Power Plant, reinforcing nuclear safety, security and regional cooperation.
During his visit to Kuwait, Mr Grossi met with Foreign Minister Sheikh Jarrah Jaber Al-Ahmad Al-Sabah to discuss regional developments and the IAEA’s support to countries in strengthening nuclear safety, security, emergency preparedness and response.
The discussions also highlighted cooperation in the peaceful uses of nuclear technology, including applications in health, food security and environmental protection.
Mr Grossi also visited the Kuwait Institute for Scientific Research (KISR), where he saw efforts using nuclear science to support environmental protection.
At KISR, he also received updates on joint cooperation, including research being carried out aboad the vessel Al-Mostakshif under the IAEA’s NUTEC Plastics initiative to assess threats to marine ecosystems.
During his visit to the GCC Emergency Management Centre, discussions focused on regional cooperation in emergency preparedness and response, as well as on strengthening coordination mechanisms during nuclear or radiological emergencies.
In Doha, DG Grossi met with Qatar’s Prime Minister and Minister of Foreign Affairs, Sheikh Mohammed bin Abdulrahman bin Jassim Al Thani, to discuss regional developments, including issues related to Iran’s nuclear programme, reaffirm the importance of dialogue, diplomacy and international cooperation.
In Abu Dhabi, Mr Grossi met with United Arab Emirates Foreign Minister Sheikh Abdullah bin Zayed Al Nahyan to discuss nuclear safety in the country and in the region following the 17 May drone strike on the Barakah Nuclear Power Plant.
The discussions also covered the growing role of nuclear energy in supporting energy security and economic development, along with emerging technologies such as advanced reactors and small modular reactors.
In his visit to the Barakah Nuclear Power Plant, he commended the response by the Emirates Nuclear Energy Corporation and Federal Authority for Nuclear Regulation following the drone attack and reaffirmed the IAEA’s support for nuclear safety and security in the UAE and the wider region.
He also met plant personnel and highlighted the importance of preparedness, resilience and transparency in ensuring the safe operation of the facility.
In Saudi Arabia, Mr Grossi met with Energy Minister Prince Abdulaziz bin Salman to discuss the Kingdom’s advancing civilian nuclear programme and the IAEA’s support for its safe, secure and transparent development.
Advancing Cooperation
Throughout the visit, Mr Grossi emphasized the importance of international cooperation, strong safety and security frameworks and the responsible use of nuclear science and technology to support development, energy security, environmental protection and human health.

Ignitis Gamyba Allocates €1.1 Million in Humanitarian Aid for Ukraine’s Critical Infrastructure

From September 2024 to this October, Ignitis Gamyba allocated €1.1 million in humanitarian aid to support the restoration of Ukraine’s war‑damaged energy infrastructure. According to the European Commission, this is the largest logistical operation it has ever coordinated.
In just over a year, 145 lorries loaded with equipment were dispatched from the Vilnius TE‑3 Combined Heat and Power Plant. According to the company’s calculations, a total of 2,681 tonnes of equipment have been allocated for humanitarian aid.
“In this challenging period, as Ukraine experiences continued russian aggression and the destruction of its energy infrastructure, we remain firmly committed to supporting the Ukrainian people. Lithuania’s initiative to relocate a full thermal power plant, with a combined heat and electricity capacity of nearly 1,000 MW, to Ukraine through the EU Civil Protection Mechanism is a powerful example of solidarity and cooperation. A thermal power plant of this size can provide heating for approximately half of Vilnius households. This support is necessary to rebuild the energy sector, which is vital to the daily lives of Ukrainians. I am sincerely grateful to all the countries, companies and institutions involved in this massive project. This operation only became possible through the efforts of all of our partners,” says Minister of Energy Žygimantas Vaičiūnas.
The principal activities of Ignitis Gamyba’s TE‑3 were suspended in 2015 due to high operating costs and an assessment that operation of the power units would not have a significant impact on the stability of the electric power system.
“For more than 30 years, this power plant provided heating for roughly half of Vilnius households. Now it is no longer being used, but the equipment we preserved and kept operational was able to contribute to restoring vital functions in Ukraine,” said Ignitis Group CEO Darius Maikštėnas.
The transfer of equipment was officially confirmed on 15 July 2024, following the signing of a support agreement between Ignitis Gamyba and the electricity distribution network operator in Ukraine. For security reasons, more detailed information about the aid being provided, including the exact names of the equipment as well as the power plants it will be going to, cannot be disclosed.

€113 million in EU funding allocated to strengthen the resilience of Baltic and Polish electricity grids

The European Commission has allocated €113 million in funding from Connecting Europe Facility (CEF) for critical Synchronisation infrastructure protection implemented by the transmission system operators of Lithuania, Estonia, Latvia and Poland. The implementation of wider range of projects aimed at ensuring energy security against potential cyber and physical threats began on February 9 last year, following the successful synchronization of the Baltic States with the Continental European electricity network.
“Having successfully completed the synchronization project, the Baltic States and Poland continue to invest in energy independence and security. We are grateful to the European Commission for supporting our ambition to make the Baltic Sea region a model for strengthening the security and resilience of critical energy infrastructure across Europe. This funding is the result of our consistent efforts and sets a new precedent, as until now the European Union had no dedicated financing for the protection of critical energy infrastructure. By consistently applying the lessons learned from Ukrainian energy specialists, we are expanding the scope of protection for our critical energy infrastructure projects. We plan to apply for further funding for resilience projects and are actively working to ensure that a long-term EU-level instrument for financing critical energy infrastructure protection is established,” – said Žygimantas Vaičiūnas, Minister of Energy of the Republic of Lithuania.
The protection of critical energy infrastructure is being financed on the EU level for the first time. These possibilities have been empowered due to the implementation of the synchronization project by the Baltic States and Poland. Lithuania together with Estonia, Latvia and Poland is targeting the long-term legal and financial instruments for the financing of the critical energy infrastructure within the EU. Currently the legal instruments are under review, it is expected and the efforts are pursued the initiative to be properly aligned also during the negotiations of Multiannual Financial Framework for 2028-2034.
“We launched the resilience programme just over a year ago, and we have already made significant progress in many areas: we have procured and are installing drone neutralization solutions, implemented initial protection measures for substation equipment, designed and prepared to build physical barriers – materials for which were tested at Lithuanian Armed Forces training grounds – and introduced measures to ensure rapid restoration of damaged infrastructure. We continue to raise the level of cybersecurity. By sharing information and insights with partners in the Baltic States and Poland, working with universities and security experts, and learning from Ukraine’s experience, we are constantly looking for ways to supplement and improve existing solutions,” said Litgrid CEO Rokas Masiulis.
The critical infrastructure protection projects implemented by the Baltic and Polish transmission system operators – Litgrid, AST, Elering, and PSE – as part of the Baltic synchronization effort will be financed through the Connecting Europe Facility (CEF).
The projects will receive up to the maximum possible co financing rate of 50% of eligible costs. Funding for projects in Lithuania amounts to €22 million.
Litgrid’s energy infrastructure resilience programme includes strengthening the physical protection of critical facilities, establishing emergency and crisis reserves for transmission network equipment, installing electronic security systems, deploying unmanned aerial vehicle detection and neutralization systems, enhancing perimeter protection, and preparing to operate under critical conditions.
Litgrid is implementing 13 projects under the resilience programme, comprising more than 150 measures deployed across various transmission network facilities. The programme is continuously reviewed based on threat assessments and new technological solutions.
On February 8, 2025, the Baltic States disconnected from the Russia controlled IPS/UPS electricity system, and on February 9 successfully synchronized their electricity systems with the Continental European synchronous area. Synchronization with Continental Europe enables the Baltic States to operate their electricity systems in close cooperation with other Continental European countries, ensuring stable and reliable frequency regulation, thereby strengthening energy independence and enhancing energy security across the region. The Baltic States joined the Continental European network, which serves more than 400 million consumers in 26 countries.

CISA Update Cross-Sector Cybersecurity Performance Goals (CPG 2.0)

CISA has released an updated Cross-Sector Cybersecurity Performance Goals (CPG 2.0) with measurable actions for critical infrastructure owners and operators to achieve a foundational level of cybersecurity.
This update incorporates lessons learned, aligns with the most recent National Institute of Standards and Technology Cybersecurity Framework revisions, and addresses the most common and impactful threats facing critical infrastructure today.
CPG 2.0 includes a new component focused on the essential role of governance in managing cybersecurity. It emphasizes accountability, risk management, and strategic integration of cybersecurity into day-to-day operations, reinforcing the principle that effective governance is the cornerstone of a resilient cyber posture.
CPGs are streamlined and outcome-driven cybersecurity protections for information technology and operational technology environments and provide:
• Clear, foundational practices aligned with real-world threats.
• Straightforward, outcome-oriented language to aid implementation.
• A baseline for guiding investment, benchmarking progress, and reducing risk in measurable ways.
For more information, visit CPG 2.0 and Cross-Sector Cybersecurity Performance Goals | CISA

Germany’s Critical Infrastructure Protection (KRITIS)

By Michael Kolatchev, Principal, Managing Director at Rossnova Solutions (Belgium) & Lina Kolesnikova, Senior Consultant at Rossnova Solutions (Belgium)

Germany is one of the world’s leading economies, depending heavily on resilience and reliability of its CI to maintain national security and economic competitiveness. In response to evolving threats including cyber-attacks, natural disasters, and physical sabotage, the country continues to modernize and expand its regulatory and institutional architecture for CI protection.
German Federal government defines Critical infrastructures (KRITIS) as “organizations or facilities of vital importance to the public sector, the failure or impairment of which would result in lasting supply bottlenecks, significant disruptions to public safety, or other dramatic consequences”. Such sectors include energy, water, information technology, healthcare, transportation, finance, government and administration, media and culture.
Ensuring protection of organisations is a core task for government and business, and a central theme of Germany’s security policy. Resilience of CI increasingly becomes a priority.
KRITIS before CER and NIS2
Necessity of protecting Critical Infrastructure in Germany emerged in 1997 with a creation of a working group within the Federal Ministry of the Interior (BMI). The acronym KRITIS has been used ever since.
The first years of KRITIS protection were characterized by numerous discussions with industries associations, companies and authorities to identify specific sectoral needs. This also led to creation of the first recommendations and guidelines for operators of CI.
A major milestone was reached in 2009 with the adoption of the first National Strategy for the Protection of Critical Infrastructures (KRITIS Strategy). This strategy is still the foundation for overall execution of tasks, and it contributes significantly to their understanding and acceptance.
UP KRITIS
It is estimated that approximately 80% of Germany’s CI is owned and operated by private companies. Effective communication with stakeholders including government bodies, sectoral organizations, the media, and the public is often facilitated through industrial (sectoral) associations. These associations play a key role in public-private partnerships (PPPs) for infrastructure protection.
One of the key milestones in the development of Germany’s critical infrastructure protection strategy was the establishment of UP KRITIS in 2007. UP KRITIS serves as a cooperation and dialogue platform between government authorities and private-sector operators of CI. While the initial focus was on IT security, the platform has since evolved. Today, UP KRITIS includes over 1000 members and addresses a comprehensive range of topics related to CIP, encompassing both physical and cybersecurity, as well as resilience and emergency preparedness across multiple sectors.
Given the central role of IT in nearly all critical processes and its continuous and rapid development, protection of information infrastructures has become a key priority within UP KRITIS. This focus reflects increasing complexity and dynamic nature of cyber threats.
In addition to IT-related issues, UP KRITIS addresses broader dimensions of infrastructure robustness, emphasizing that physical protection and cybersecurity must be designed and implemented as interconnected and mutually reinforcing elements of a comprehensive security strategy.
The platform’s structure facilitates public-private knowledge sharing, enabling integration of business expertise with governmental capabilities in protecting critical information infrastructure. This collaborative approach has notably strengthened cross-company and cross-sector communication, which is now embedded in all UP KRITIS activities.
Evolving regulations
The Federal Republic of Germany’s approach is closely aligned with evolving EU legislation, particularly the CER Directive, NIS2 Directive, and DORA Regulation. National legislation transposing these directives, such as the KRITIS Umbrella Act and the NIS2 Implementation Act establishes obligations for CI operators across physical and cyber domains. This Act regulates resilience and physical security of critical infrastructures, from 2025 onwards.
The Act sets minimum requirements and establishes a catalogue of obligations demanding operators of critical facilities to implement resilience measures. The all-hazards approach applies: every conceivable risk must be considered, from natural disasters to sabotage, terrorist attacks, and human error. Smaller critical infrastructures have the option of voluntarily implementing resilience measures and can rely on industry-specific standards. Potential funding measures are intended to help them improving.
Penalties for violating the law’ provisions are intended to ensure that compliance with security standards is taken seriously and that critical infrastructures remain protected. Amounts have yet to be determined.
Federal ministries are authorized to issue legal regulations to specify resilience measures for the areas within their jurisdiction.
The regulatory landscape is set to evolve further.
CER
The forthcoming National KRITIS Resilience Strategy (2026) will provide a strategic roadmap to strengthen national coordination and sectoral resilience planning.
In contrast to cybersecurity, physical security has historically received less focus, partly due to the complex federal structure of the country, which consists of sixteen federal states (Länder) with differing responsibilities and approaches. With Germany transposing the EU Critical Entities Resilience (CER) Directive into national law by the end of the year, framework for physical resilience of critical entities will enhance.
NIS 2
Germany continues to experience a high volume of ransomware attacks and distributed denial-of-service (DDoS) attacks. In 2024, the cybersecurity industry recorded over 720 such incidents, representing a 67% increase compared to the previous year. Number of attacks targeting SMEs, government and municipal administrations increased sharply. Healthcare, and hospitals in particular, are under attacks. As for most of countries, many cyberattacks in Germany originate from foreign jurisdictions, making attribution and prosecution difficult. Perpetrators increasingly rely on cybercriminal supply chain where capabilities such as malware development, access brokerage, and laundering of ransom payments are outsourced or consumed as services within the new Crime-as-a-Service paradigm.
On July 24, 2024, the Federal Cabinet passed the draft law for the (EU Directive 2022/2555) NIS 2 Implementation and Cybersecurity Strengthening Act, bringing comprehensive modernisation of German IT security law. IT security and security incident reporting requirements are extended to more companies in more economic sectors, like energy, transport, health, or digital infrastructure. It is expected that the number of organizations subject to cybersecurity obligations in Germany will potentially exceed 30,000 entities. This presents considerable administrative and enforcement challenges for the federal level, while cybersecurity at the federal administration itself must strengthen too. The new laws replace the KRITIS regulations in place in Germany since 2014, with more operators implicated and more obligations. Originally scheduled for October 2024, its coming into force is delayed until new Bundestag in 2025.
The Federal Office for Information Security (BSI) receives new supervisory tools to enforce compliance with the new legal obligations. Operators of critical infrastructure facilities are required to register with the Federal Office for Information Security (BSI). Organizations must promptly report significant cybersecurity incidents there. Registered entities must submit a biennial report to the BSI, detailing cybersecurity measures they have implemented. For accountability and continuous improvement, organizations need to undergo certification and external audits, in accordance with defined standards and sector-specific requirements.
Institutional Architecture
Germany’s CI protection is supported by a range of institutions operating at federal and sectoral levels. The Federal Ministry of the Interior (BMI) provides policy leadership and inter-ministerial coordination. The Federal Office for Information Security (BSI) oversees cybersecurity implementation and maintains national situational awareness. Public–private coordination is facilitated through platforms such as UP KRITIS, with strong engagement from sectoral associations.
The inter-ministerial Joint Coordination Task Force for Critical Infrastructure (GEKKIS) serves three key purposes:
• Provide situational reports on protection of critical infrastructure, supporting all federal ministries with a cross-departmental overview of the up-to-date threat landscape.
• Enable communication among ministries, identify common challenges, and develop coordinated responses.
• Convene ad-hoc coordination group for relevant incidents, ensuring rapid and cohesive government action.
This collaborative institutional setup enables Germany aligning with EU standards, and ensuring tailored implementation through cross-sector coordination, federal–state integration, and public–private engagement.
Conclusion
Germany’s approach to CIP follows evolving EU conceptual framework, compliance with EU directives and national implementation. Key elements include:
• Transposition of EU legal instruments into national law, notably:
• The Directive on the Resilience of Critical Entities (CER Directive)
• The Directive on Security of Network and Information Systems (NIS2)
• The Digital Operational Resilience Act (DORA).
• Lessons learned from previous regulatory cycles.
• Adaptation of EU-wide concepts to Germany’s federal system, accounting for sector-specific and state needs.
Most significant conceptual shift is transition from a protection-centric approach to a broader, dynamic focus on resilience, recognising that 100% security cannot be guaranteed. The emphasis increasingly shifts toward ensuring continuity and rapid recovery of services in the face of disruptions.
Key lesson is Germany’s well-structured system of communication, coordination, and collaboration across federal, state (Länder), and local levels. Different stakeholders play clearly defined roles in two-way communication, both government actors and public and private sectors. Mechanisms such as centralized platforms for incident reporting, secure information exchange, and cross-sector coordination, help foster mutual trust and transparency. These structures significantly enhance situational awareness, and enable rapid, coordinated responses to emerging threats.
In the energy sector, operational continuity is central. Installed capacity must match national demand while demanding dynamic power management, with renewable energy in mind, for long-term sustainability. German experience demonstrates integration of existing systems, managed decentralization, and flexible response to demand surges and supply disruptions.
Widespread digitization of CI has exposed systems to new and complex threats, rendering traditional protection methods inadequate. Cybersecurity becomes strategic to CIP. Once a peripheral concern, it has now dedicated legislation, enforcement mechanisms, and technical standards. Rules and oversight structures dedicated to cybersecurity is a response to this reality and a model worth consideration by other countries.
Historically, the focus of CIP has been on large, high-value assets. Supply chains and SMEs now have a greater role. Risk management must extend across entire ecosystems, using unified threat catalogues to support all-hazards risk assessments. If one wants compatibility, consistency, and coordinated responses across sectors and involved operators of different organization types.

Building Ukraine’s Shield: The Bold New Effort to Train Critical Infrastructure Security Professionals

In November 2021, a landmark law on Critical Infrastructure Protection (CIP) was signed by the President of Ukraine—setting in motion a national effort to secure the lifelines of the country’s economy, defense, and daily life. Two years later, in September 2023, the Cabinet of Ministers approved Ukraine’s National Plan for the Protection, Security, and Resilience of Critical Infrastructure, a document that not only laid out an ambitious strategy but also revealed a major vulnerability: a critical shortage of qualified professionals.

The question soon became unavoidable—how and where can Ukraine train the specialists essential to protecting its most vital systems? The National Plan mandated a full feasibility study to explore this issue and develop recommendations for building a sustainable educational and training ecosystem for CIP professionals.

This comprehensive study was the first of its kind in Ukraine and worldwide and took a global approach. It examined not only Ukraine’s own experience but also incorporated lessons and best practices from the European Union, North America, and international organizations such as the United Nations, NATO, OSCE and the World Bank. The study team interviewed over 50 subject matter experts from Ukraine, the EU, and the United States, representing government agencies, industry sectors, and academic institutions.

The Feasibility Study to Affect the Development of Critical Infrastructure Security and Resilience (CISR) Education and Training System in Ukraine was carried out by Ukrainian, Italian, and American experts in critical infrastructure protection, with financial support from the U.S. Department of State. It was also supported by the Directorate of Professional Pre-Higher and Higher Education of the Ministry of Education and Science of Ukraine, the Critical Infrastructure Security Service of the National Security and Defense Council (NSDC), and the Department of Critical Infrastructure Protection of the State Service of Special Communications and Information Protection (SSSCIP).

The study’s main conclusion was that the development of an education and training system for critical infrastructure protection in Ukraine is both possible and necessary. Such a system is needed to prepare leaders, managers, specialists, and trained personnel capable of carrying out a wide range of tasks in the field of CI protection — all in line with Ukrainian legislation and national security goals.

It worth to mention that the results of this Study was officially presented in Lecce, Italy, during the international workshop on “Development of University Programs on Critical Infrastructure Security and Resilience” in March 2024. The event served as a vital platform for Ukrainian participants and international experts to exchange knowledge, share best practices, and explore innovative approaches in the field of Chemical Critical Infrastructure Security and Resilience (CISR) education. The workshop highlighted the importance of academic collaboration in strengthening the resilience of critical sectors and advancing specialized university programs across borders.

Although the study was conducted in 2024, it has already led to several significant outcomes:

1. On June 27, 2024, the Center for Critical Infrastructure Security and Resilience was established at the Department of Civil and Industrial Safety named after Hero of Ukraine O.S. Chub, within the Faculty of Environmental Safety, Engineering, and Technology at Kyiv Aviation University. This center attracted the attention of the Ministry of Infrastructure and Transportation of Ukraine, which has since accepted university students studying CIP for internships at transportation-related CI facilities in Kyiv.

2. The National Institute for Strategic Studies established two working groups focused on developing educational programs in the field of CIP. As a result, a proposal is being prepared for submission to the Ministry of Education of Ukraine to formally introduce new CIP curricula and programs in Ukrainian universities.

3. Compared to the Research on CIP education conducted in 2021, there is clear progress in the development of university-level programs both at the national level (Kyiv) and in several regions (Lviv, Kharkiv, and Cherkasy). This development is supported by the National Qualifications Agency of Ukraine and coordinated by the CIP offices of the NSDC and SSSCIP.

4. Based on the findings of the study, four new professions related to critical infrastructure protection were added to the National Occupational Classifier of Ukraine, including:

* Risk, Threat, and Vulnerability Analyst for Critical Infrastructure – identifies potential threats and vulnerabilities, assesses risks, and develops mitigation recommendations;

*Critical Infrastructure Protection Expert – provides expert assessments of protection methods and ensures resilience against threats;

*Specialist in Critical Infrastructure Protection and Resilience – directly implements protection measures and ensures operational continuity in crisis conditions;

*Head (or other manager) of a Department/Unit for Critical Infrastructure Protection – organizes, coordinates, and oversees security measures, conducts risk assessments, interacts with law enforcement and specialized agencies, and implements policies and standards to ensure CI resilience.
Currently, an interagency working group in Ukraine is developing professional standards for these roles. Whether this initiative will be successful will depend on the outcomes of pilot projects and the real-world performance of certified professionals at critical infrastructure enterprises. It remains to be seen whether additional, more in-depth research and business analysis of the functional responsibilities of CI professionals at enterprises across Ukraine’s 24 critical infrastructure sectors (as defined by a Cabinet of Ministries of Ukraine’s resolution) will be necessary. Based on such analysis, there may be a need to adjust or refine the newly introduced CIP professions, taking into account the 2008 EU Directive and the experience of the 5 CIP SISTERS: United States,Canada, the United Kingdom of the Great Britain, New Zeland and Australia.

In conclusion, the issue of training critical infrastructure protection professionals, especially for sector-specific enterprises, still requires deeper research and strategic planning. Only by thoroughly analyzing the operational needs and critical functions of CI enterprises can Ukraine accurately define the roles and responsibilities of CIP specialists and reflect them in professional standards, paving the way for the development of a qualified and mission-ready workforce.

By Vladlen Basystyi, Technical Advisor at CRDF Global, specializing in cybersecurity and critical infrastructure protection

Critical Infrastructure Protection & Resilience Europe announces Preliminary Conference Programme

The 10th Critical Infrastructure Protection & Resilience Europe, taking place in Brindisi, Italy on 14th-16th October, has announced its Preliminary Conference Programme, with a fantastic line up of international expert speakers sharing their thoughts, experiences and expertise at this premier conference.
Download your guide at www.cipre-expo.com/guide
The second ‘Critical Infrastructure Protection Week in Europe’ will take place in Italy, Brindisi and will see the International Association for CIP Professionals (IACIPP) host the ‘Critical Infrastructure Protection & Resilience Europe’ conference and exhibition and ‘The International Emergency Management Society (TIEMS)’ conference as the two key events as part of the initiative.
Download your preliminary conference guide now
The Preliminary Conference Programme guide provides you with the latest conference agenda, speakers and information to plan your attendance to the premier conference for the critical infrastructure protection, civil contingencies and safer cities professionals.
Download your guide at www.cipre-expo.com/guide
Register online today at: https://www.cipre-expo.com/buy-tickets/
#criticalinfrastructure #criticalinfrastructureprotection #cybersecurity #resilience #emergencymanagement #transport #energy #communications #security #criticalassets #criticalcommunications #firstresponders #nis2 #cerdirective #uas #drones #riskmanagement #riskmitigation
1 2 3 12