OSCE expands access to its technical guidance on the physical security of critical infrastructure

The OSCE Centre in Ashgabat and the OSCE Transnational Threats Department launched the Turkmen version of their Technical Guide on Physical Security Considerations for Protecting Critical Infrastructure from Terrorist Attacks. The launch event was accompanied by a training course on enhancing the physical security of critical infrastructure from terrorist attacks, using the Technical Guide as a training aid.
Developed under the OSCE’s Project PROTECT with support from Germany and the United States of America, the Technical Guide provides practical guidance to policymakers, critical infrastructure owners and operators, and security practitioners on enhancing the protection of critical infrastructure sites from terrorist attacks. The publication consolidates publicly available practices and examples from across the OSCE area and is designed to support stakeholders in developing security measures tailored to their specific risk environment. It was released in November 2025 in the English and Russian. The launch of the Turkmen language version of this Guide, initiated by the OSCE Centre in Ashgabat, is a testament to the Guide's growing value in OSCE participating States.
A representative of the Ministry of Internal Affairs of Turkmenistan presented the country's approach to protecting critical infrastructure, highlighting current practices, the national legislative framework and ongoing efforts to strengthen the security and resilience of critical infrastructure.
The training course brought together government officials responsible for critical infrastructure protection to strengthen their understanding of physical security principles and practices. Participants examined approaches to security system design as well as technical measures including perimeter protection, intrusion detection systems, security lighting, video surveillance, access control and security screening. During the event, participants explored practical ways to apply the Guide’s principles through security assessments, emergency planning, business continuity measures and training exercises.
“The Organization for Security and Co-operation in Europe serves as a vital pillar in global counter-terrorism efforts by actively strengthening the resilience and protection of critical infrastructure across its 57 participating States. Bearing in mind that security is not a task for a single agency or nation, we designed this training programme to build our collective resilience. It is our firm belief that this programme, together with the Guide, will strengthen inter-agency communication and help upgrade security protocols to more effectively protect critical infrastructure from terrorist attacks,” said William Leaf, Head of the OSCE Centre in Ashgabat.
The event featured contributions from international experts and practitioners, as well as the Government of Kazakhstan, another key stakeholder in the OSCE’s Project PROTECT. A representative of the Anti-Terrorism Centre of the Committee of National Security of the Republic of Kazakhstan delivered a presentation on the country's approach to protecting critical infrastructure from terrorist threats.
The event forms part of the OSCE Centre in Ashgabat's project Building Capacity of Law Enforcement and Security Officials of Turkmenistan in Countering Transnational Threats Related to Organized Crime and Terrorism – 2026 and the OSCE's extrabudgetary Project PROTECT, which supports participating States in strengthening national approaches to protecting vulnerable targets from terrorist threats and other hazards.

NATO PA Promotes Investment in Collective Defence, Infrastructure Protection

The NATO Parliamentary Assembly has highlighted legislators’ vital role in ensuring the Atlantic Alliance faces up to pressing security challenges, strengthening collective defence and protecting against hybrid threats.
The Assembly’s Spring Session drew over 230 lawmakers from NATO and partner nations. Discussions on the second day focused on issues ranging from safeguarding critical infrastructure, maintaining military force levels and fast-tracking defence innovation
“The war in Ukraine is driving new thinking about modern warfare,” explained US Congressman Rick Larsen. “Innovating quickly is important but integrating and scaling new technologies is just as essential.
Drawing on Ukraine’s experience of fast-paced wartime innovation, Larsen said NATO must work urgently to overcome years of underinvestment, insufficient and fragmented demand, slow procurement and overly bureaucratic acquisition systems.
“That’s where we come in,” he told fellow parliamentarians. “We control the budgets. We conduct oversight. We can demand answers when promising technologies stall. We can push governments to integrate NATO commitments into national legislation and procurement systems that work.”
A presentation by Greek member Spyridon Kyriakis centred on shaping NATO’s future forces by improved recruitment, retention of experienced military personnel and strengthening the will to fight within Allied societies.
Faced with an aggressive, expansionist Russia on its doorstep, NATO must take steps to meet recruitment targets and ensure personnel stay in uniform longer, particularly those with critical skills such as cyber, intelligence, logistics and special operations.
“We need a sweeping renewed conversation on how we value, support and inspire our forces,” Kyriakis told the Assembly.
New NATO defence plans, bigger budgets and arms acquisition “can only deliver real deterrence if the Alliance has the well-trained, highly motivated men and women needed to operate and sustain them,” he added.
Lawmakers debated the costs and benefits of conscription and emphasised the importance of building on Ukraine’s experience to build public support and societal resilience to shape mobilisation capacity and wartime outcomes.
“As parliamentarians ... we hold the levers of oversight, the power of legislation and the loudest microphones to champion the profound value of military service to our citizens,” Kyriakis concluded.
Ahead of July’s summit of NATO leaders in Ankara, lawmakers highlighted the role of parliaments in ensuring that Allies stick to the goal of spending at least 5% of gross domestic product (GDP) on defence and security.
“There is still much to be done to bring defence spending to 5% of GDP and transfer that money into actual operational deterrence and defence capabilities,” said Dutch Senator Bart Kroon. “Sustaining that level of spending and transformation will require trade-offs and smart policymaking.”
NATO PA speakers underscored the need to protect critical infrastructure, such as undersea and space assets, from the mounting risk of hybrid attacks.
“Allied security is increasingly dependent upon our space systems and undersea infrastructure,” stated US Congressman Mike Turner. “They are core components of our defence posture and our economic resilience; and are under growing pressure from our adversaries.”
Turner and British Member Lord Nigel Dodds made presentations urging better monitoring and attribution of threats to infrastructure, faster repair and replacement options and solutions that allow forces to operate when communications are degraded by adversaries. Cooperation with the private sector is essential.
“Parliaments and we, as parliamentarians, have an important role to play,” said Dodds. “We can help ensure that national legal frameworks are fit for purpose. We can scrutinise whether governments have clear lead authorities and effective coordination structures. We can support dedicated funding for protection, repair, and response; and we can help keep political attention on this issue before a major disruption occurs.”

CoESS calls for exclusion of Private Security Services from EU Inc. Regulation

The Confederation of European Security Services (CoESS) has published a new position paper raising concerns about the European Commission’s proposal for an EU Inc. Regulation. While the proposal aims to simplify cross-border company operations in the EU, CoESS warns that it could unintentionally weaken national security frameworks and create loopholes in the regulation of private security services.
According to CoESS, private security services are already excluded from the EU Services Directive due to their direct link to internal security, Critical Infrastructure Protection, and support for law enforcement and emergency services. The organisation argues that the proposed EU Inc. framework — with rapid digital incorporation, EU-wide company recognition, and limits on additional national requirements — could make it easier for companies to circumvent national licensing and supervision systems. This would create enforcement challenges for national authorities and increase risks related to unlawful competition and weaker oversight.
The paper highlights that private security regulation differs significantly between Member States, reflecting national public security needs and operational realities. CoESS therefore believes that Member States must retain full control over authorising and supervising companies operating in this sensitive sector. The organisation also warns that the proposal could indirectly undermine the exclusion of private security services from the EU Services Directive by facilitating cross-border operations outside national regulatory frameworks.
CoESS is therefore calling on EU policymakers to explicitly exclude private security services from the scope of the future EU Inc. Regulation. The organisation stresses that such an exclusion is necessary to preserve effective enforcement of national security law and maintain robust supervision of services linked to public safety and Critical Infrastructure Protection.

NIS360: The bigger picture on maturity and criticality of NIS critical sectors

This year’s edition of the ENISA NIS360 report shows improvement in cybersecurity maturity of EU critical sectors while the level of criticality in sectors remains comparatively more stable.
The ENISA NIS360 aims to work as an annual assessment tool supporting national authorities, policymakers and other stakeholders in assessing the cybersecurity maturity and criticality of high criticality sectors under the NIS2 Directive.
ENISA Executive Director, Juhan Lepassaar, said: “The findings of this NIS360 report provide grounds to be optimistic. The implementation of the comprehensive EU cybersecurity regulatory framework, and particularly NIS2, has brought significant improvements. ENISA stands for prioritising cybersecurity and advancing the implementation of EU policies, which are vital now more than ever, to enhance the cyber resilience of our critical infrastructure and societies.”.
The report has a comprehensive approach, where each sector is understood to comprise relevant actors (i.e., national authorities, entities, EU bodies) and applicable rules (EU legislation). In this regard, a sector’s maturity under the NIS360 is determined by: legislation and its effectiveness, companies and their preparedness, authorities and their institutional capacity, and sectoral ecosystem structures and their effectiveness.
The assessment relies on a structured methodology developed and continuously refined by ENISA that takes into account the structural and gradually evolving nature of sectoral cybersecurity maturity and criticality. It also builds on evidence gathered over time from organisations operating within the in-scope sectors, national authorities supervising those organisations, but also EU-level data, to reflect our latest evidence-informed understanding of where each sector stands.
As a result, the NIS360 provides both a comparative overview of sectors and a more detailed analysis per sector to help identify gaps and prioritise resources.
Defining the Risk Zone
NIS360 sector risk zone
A combination and joint interpretation of the criticality and maturity dimensions helps identify areas where mismatches exist between the two and define a risk zone.
The risk zone includes sectors with lower-than-average maturity and criticality that exceeds their maturity. This year’s risk zone includes health, railway, maritime, ICT management service, space, public administrations, drinking and waste water.
Its composition changes over time as overall maturity improves across sectors. This explains why three sectors — railway, drinking water, and waste water — previously at the risk zone boundary, are now within the risk zone. A positive development is that the gas sector has started moving out of the risk zone.
Such shift is driven by improved information sharing, stronger collaboration, and better implementation of risk management measures, leading to higher maturity.
Deep-dive on criticality
While criticality of the sectors is defined by NIS2, the NIS360 assessment ranks the sectors taking into account several elements, such as systemic relevance, exposure, and impact of disruption. As these factors typically change gradually, criticality scores tend to remain relatively stable from year to year.
In this year’s edition, sectors such as banking, electricity, aviation, space, and digital-by-default services (including telecommunications, cloud, and data centres) remain the most critical.
Space has joined this group this year, reflecting its growing role in society and across other sectors, which increases dependency, impact, and time criticality. The railway sector increased in criticality due to its growing role in military logistics, and the heightened cyber threat exposure.
Spotlight on maturity 
Maturity is measured by how effectively and consistently the sector manages cybersecurity risks and capabilities over time, meaning the overall preparedness of the sector. Since the previous edition of this report, cybersecurity maturity across EU critical sectors seems to be steadily improving as organisations respond to the evolving policy requirements and to the cyber threats they face.
Three sectors, including trust services, aviation, and financial market infrastructures (FMIs) moved into the high maturity band. In addition, four sectors strengthened their maturity within the moderate band: gas, road, maritime, and health.
This improvement is often driven by several compounding factors including developments in cybersecurity legislation, increased political attention, but also progress across specific maturity dimensions assessed. Particularly, on cybersecurity legislation, findings of the 2025 ENISA NIS Investments study also suggest that it has acted as a key driver for cybersecurity investment and has encouraged organisations to strengthen their cybersecurity posture.
Despite maturity steadily improving across critical sectors, progress still remains uneven both across and within sectors. A number of factors contribute to these variations including skill shortages, sector-specific characteristics and even organisational size.
Moving forward
In the future, it is anticipated that cybersecurity legislation and organisations’ efforts to strengthen their cybersecurity maturity will continue to prompt cybersecurity investment and drive preparedness, leading to more sectors moving out of the risk zone.

OSCE promotes marine transport security and relevant Convention implementation

The OSCE Programme Office in Astana co-organized a practical seminar on inspection of higher educational institutions and maritime training centres of Kazakhstan in co-operation with the Committee of Railway and Water Transport of the Ministry of Transport and with the support of the Kazakhstan Maritime Academy of the Kazakh-British Technical University. The main goal of the seminar was to strengthen oversight of inspection and accreditation of higher educational institutions and maritime training centres in Kazakhstan, in line with the International Convention on Standards of Training, Certification, and Watchkeeping for Seafarers (STCW).
Maritime safety begins long before a vessel leaves port, it starts in the classroom, where future seafarers are trained to meet international standards. The STCW sets globally accepted minimum standards for the training, certification, and competence of seafarers, ensuring that ships are operated safely worldwide. Before STCW, standards varied widely between countries, creating risks to maritime safety and uneven levels of crew competence. The Convention also plays a key role in protecting the marine environment, as competent seafarers are better equipped to prevent pollution and respond effectively to environmental emergencies.
The seminar focused on the strict STCW requirements governing seafarer training, including curriculum development, teaching methodologies, assessment processes, and institutional facilities. Participants gained a comprehensive understanding of how inspections are conducted, the methodologies used for evaluation, and the specific criteria applied during accreditation.
Through in-depth discussions and practical guidance delivered by an international expert, the seminar helped to identify areas for improvement and support the Ministry’s efforts to modernize and adapt its national framework, where needed. This initiative represents an important step toward modernizing national inspection systems, strengthening compliance with international standards, and enhancing maritime safety and environmental protection.

New report explores use of robotics and unmanned systems in the fight against crime

Europol has published The Unmanned Future(s): The Impact of Robotics and Unmanned Systems on Law Enforcement. The report, produced by the Europol Innovation Lab, provides an in-depth analysis of how unmanned systems could change society, crime and law enforcement, and discusses the challenges and opportunities they present.
The report underscores the rapid advancement and integration of unmanned systems in various sectors, including law enforcement. As these technologies become more sophisticated and widespread, they offer new opportunities for law enforcement operations and operational support. However, they also introduce new security threats – such as misuse by criminal and terrorist groups – and regulatory challenges that law enforcement agencies must address to ensure public safety and maintain trust.
"The integration of unmanned systems into crime is already here, and we have to ask ourselves how criminals and terrorists might use drones and robots some years from now. Just as the internet and smartphones presented significant opportunities as well as challenges, so will this technology. Our new report by Europol’s Innovation Lab explores the future operating environment for European law enforcement agencies and suggests actions needed today in order to effectively combat crime while upholding public trust and fundamental rights tomorrow." said Catherine De Bolle,Europol Executive Director.
One chapter of the report highlights the role of war as a driver for innovation in unmanned systems. Recent conflicts, such as the ongoing Russian war of aggression against Ukraine, have accelerated the development and deployment of advanced unmanned systems. The lessons learnt from these conflicts are invaluable for law enforcement agencies in Europe as they prepare for the future operating environment.
Some of the key topics covered in the report include:
Increasing use of unmanned systems
Unmanned systems are becoming increasingly useful, affordable and widely available, with applications in both public and private sectors. Law enforcement agencies across Europe are scaling up adoption of such systems, including drones and robots, to enhance situational awareness, improve safety and extend operational reach. These systems are employed for a range of tasks, such as monitoring, crime scene mapping, search and rescue operations, and the disposal of explosive ordnance, among others. Converging technologies present a significant opportunity for a breakthrough in the capabilities of unmanned systems.
Technical and regulatory challenges
The report highlights significant technical limitations and regulatory gaps that hinder the effective use of unmanned systems in law enforcement. Issues such as limited autonomy, dependence on industrial suppliers and the lack of clear guidelines for autonomous operations pose substantial challenges.
Security threats
Criminal and terrorist groups are rapidly adopting unmanned systems for illicit activities. The report warns of the potential for these systems to be used for criminal surveillance, smuggling and even attacks. The increasing accessibility and versatility of drones, in particular, present serious security concerns.
Public trust and regulation
Public trust is crucial for the legitimacy of law enforcement capabilities. The report emphasises the need for transparency, accountability and public engagement in the deployment of unmanned systems. Current regulations, while advancing, still have gaps, particularly in addressing non-compliant or criminal use.
Future operating environment
The future of law enforcement will require policing in a three-dimensional space, as unmanned systems operate in the air and on the ground, as well as on and under water. This shift will necessitate new strategies, technologies and training for law enforcement agencies.
Recommendations
The report provides a set of recommendations for European law enforcement agencies, including the development of a strategic direction, the establishment of a competency hub and the integration of unmanned systems into existing information systems. It also calls for investments in training, education and public trust-building initiatives.
The report is available for download on the Europol website and includes detailed insights, case studies and recommendations for law enforcement agencies, policymakers and other stakeholders.

CISA Releases Dynamic New Guide for Stadium and Arena Owners to Fortify Operations, Mitigate Vulnerabilities and Elevate Emergency Preparedness

The Cybersecurity and Infrastructure Security Agency (CISA) released the Venue Guide for Mitigating Dependency Disruptions, a new resource designed to strengthen the resilience of public gathering venues. This guide provides stadium and arena owners and operators with baseline strategies to mitigate the consequences of potential disruptions to four critical lifeline sectors—including Energy, Water and Wastewater Systems, Communications, and Transportation.
CISA developed this guide in close collaboration with government and industry experts from the four lifeline sectors as a concise, actionable resource for stadium and arena owners. Tailored for major public gathering events- such as FIFA World Cup 2026, America 250, and 2028 Summer Olympics, the guide draws on lessons learned from recent disruptions at high-profile public gathering sports and entertainment facilities across the United States and internationally. It equips critical infrastructure stakeholders with a clear understanding of threats to lifeline sectors and provides effective strategies to safeguard operations, reduce vulnerabilities, and enhance preparedness.
“Today’s risk environment is rapidly evolving, posing serious threats and disruptions to U.S. critical infrastructure and public gathering venues,” said CISA Acting Director Madhu Gottumukkala. “CISA is committed to working hand-in-hand with our government and industry partners to deliver actionable guidance that helps mitigate these risks. This guide empowers venue owners and operators to proactively assess vulnerabilities tied to dependent lifeline services and integrate those insights into contingency planning—ultimately reducing potential consequences and strengthening operational resilience.”
The Venue Guide for Mitigating Dependency Disruptions aligns with Executive Order 14234 Establishing the White House Task Force on the World Cup 2026, Executive Order 14239 Achieving Efficiency through State and Local Preparedness, and Executive Order 14328 Establishing the White House Task Force on the 2028 Summer Olympics. This guide assists critical infrastructure and public venue owners and operations with:
- Understanding the lifeline sector dependencies and interdependencies that their venues may rely on;
- Assessing security risks and associated key components of a facility evaluation; and
- Focusing on continued information-sharing and relationship-building with key partners such as local services providers, first responders, and CISA Security Advisors.
“Robust partnerships are essential to safeguarding critical infrastructure and public gatherings. By sharing threat intelligence, risk mitigation strategies, and other vital information, we strengthen our collective ability to anticipate and respond to potential disruptions. CISA’s newly released guide empowers venue owners and operators to assess dependencies and implement targeted mitigation strategies,” said CISA Executive Assistant Director for Infrastructure Security Steve Casapulla. “We deeply value the insights and collaboration from our government and industry partners across four lifeline sectors, which were instrumental in shaping this timely and practical resource. CISA urges all organizations that host events to review the guide and take proactive steps to enhance infrastructure security and resilience.”

Terrorist Watchlist: FBI Should Improve Outreach Efforts to Nonfederal Users

The Threat Screening Center, administered by FBI, is responsible for managing the terrorist watchlist. In recent years, Members of Congress have raised questions about how nonfederal entities use the terrorist watchlist.
GAO was asked to examine the use of the terrorist watchlist by nonfederal law enforcement entities. This report examines (1) nonfederal entities’ reporting of terrorist watchlist encounters to FBI and opportunities for improvement and (2) steps FBI has taken to ensure nonfederal entities’ awareness of watchlist policies through outreach and state-led trainings.
When state and local law enforcement officers encounter people—e.g., in traffic stops—officers check their names against state database systems. The systems will return an alert if a name potentially matches one on the terrorist watchlist, which is managed by the FBI.
In half the interviews with law enforcement agencies, officials said their officers may not always know how to properly respond to these alerts.
We recommended that the FBI develop a communications plan to tell law enforcement agencies about the policies around the terrorist watchlist, and a process to review states' training on the policies.
Nonfederal law enforcement officers query encountered individuals against the terrorist watchlist during routine police interactions, such as traffic stops. After encountering a potentially terrorist watchlisted individual, nonfederal law enforcement officers receive instructions, via the National Crime Information Center (NCIC), to contact the Federal Bureau of Investigation’s (FBI) Threat Screening Center to determine whether the individual is a positive or negative match to the terrorist watchlist.
GAO found that almost half of the law enforcement entities GAO interviewed in four states (12 of 26 entities, including police and sheriff’s departments) reported that officers were not consistently reporting encounters with potentially terrorist watchlisted individuals in instances where it is warranted. Seeking information to understand the extent to which nonfederal law enforcement entities are consistently reporting terrorist watchlist encounters could improve the accuracy of watchlist records.
Nonfederal Law Enforcement Steps When Responding To Terrorist Watchlist Encounters
The Threat Screening Center uses outreach efforts to communicate terrorist watchlisting policies to nonfederal law enforcement entities that use the terrorist watchlist. However, GAO found that FBI has not ensured nonfederal law enforcement entities are aware of terrorist watchlist policies and has not taken steps to develop a communication plan for its outreach efforts. Developing a communication plan with goals and measures as well as periodic assessments of progress would help accomplish this. Additionally, FBI’s Criminal Justice Information Services does not ensure states train NCIC users on terrorist watchlist policies. Without developing a process to review states’ efforts to do so, FBI cannot ensure that state training programs instruct nonfederal law enforcement to properly protect and respond to terrorist watchlist information.
GAO reviewed watchlist policies and training resources for nonfederal entities and collected encounter data for fiscal years 2019 through 2024. GAO interviewed nonfederal law enforcement officials in four states selected based on the number of encounters and other factors. While not generalizable, these interviews provided insights into officials’ awareness of policies and training.
This is the public version of a sensitive report GAO issued in August 2025. Information on encounter data and official FBI instructions on handling watchlist encounters that FBI deemed sensitive has been omitted.
GAO recommends that FBI (1) seek information to understand the extent to which nonfederal law enforcement entities are consistently reporting terrorist watchlist encounters, (2) develop a communication plan to improve its outreach efforts, and (3) develop a process to review state efforts to instruct NCIC users about watchlist policies. FBI concurred with the recommendations.

CISA Update Cross-Sector Cybersecurity Performance Goals (CPG 2.0)

CISA has released an updated Cross-Sector Cybersecurity Performance Goals (CPG 2.0) with measurable actions for critical infrastructure owners and operators to achieve a foundational level of cybersecurity.
This update incorporates lessons learned, aligns with the most recent National Institute of Standards and Technology Cybersecurity Framework revisions, and addresses the most common and impactful threats facing critical infrastructure today.
CPG 2.0 includes a new component focused on the essential role of governance in managing cybersecurity. It emphasizes accountability, risk management, and strategic integration of cybersecurity into day-to-day operations, reinforcing the principle that effective governance is the cornerstone of a resilient cyber posture.
CPGs are streamlined and outcome-driven cybersecurity protections for information technology and operational technology environments and provide:
• Clear, foundational practices aligned with real-world threats.
• Straightforward, outcome-oriented language to aid implementation.
• A baseline for guiding investment, benchmarking progress, and reducing risk in measurable ways.
For more information, visit CPG 2.0 and Cross-Sector Cybersecurity Performance Goals | CISA

UK arrest following aerospace cyber incident

A man has been arrested in the UK by the National Crime Agency as part of an investigation into a cyber incident impacting Collins Aerospace.
The incident, which was reported on 19 September, affected flights at Heathrow and other European airports over the weekend.
NCA officers, supported by the South East ROCU, arrested a man in his forties in West Sussex yesterday evening on suspicion of Computer Misuse Act offences. He has been released on conditional bail.
Deputy Director Paul Foster, head of the NCA’s National Cyber Crime Unit, said:
“Although this arrest is a positive step, the investigation into this incident is in its early stages and remains ongoing.”
“Cybercrime is a persistent global threat that continues to cause significant disruption to the UK. Alongside our partners here and overseas, the NCA is committed to reducing that threat in order to protect the British public.”
1 2 3 11