World Bank Group Supports Resilient Municipal Infrastructure to Modernize Cities in Türkiye

The World Bank Group approved a EUR 191.5 million (US$219.4 million) loan to Türkiye to modernize urban infrastructure and services in the fast-growing cities of Antalya and Konya, addressing a growing demand for public transport, clean water and sanitation, and efficient energy systems, while generating jobs along the way.
The Green and Future Cities Project will be implemented through İller Bankası A.Ş. (ILBANK) with the guarantee of the Republic of Türkiye. Türkiye’s rapid urbanization has intensified demand for efficient and resilient municipal infrastructure. While fast-growing cities are central to the country’s economy, many face constraints in accessing long-term financing for major investments to support people and growing economic activities.
“Türkiye’s cities are key drivers of economic growth and job creation but also face increasing pressures from rapid urbanization and climate change,” said                   J. Humberto Lopez, World Bank Country Director for Türkiye. “This project will help municipalities invest in modern, resilient infrastructure while strengthening their capacity to plan and finance sustainable urban development.”
Planned investments include the expansion and modernization of public transport systems, such as tramlines and low-emission vehicles, as well as upgrades to water supply, wastewater treatment, and sanitation infrastructure. The project will also support measures to enhance energy efficiency and strengthen climate adaptation and resilience. These investments are expected to improve urban mobility, enhance environmental sustainability, and raise the quality of life for residents, while contributing to economic growth and job creation.
The project will also provide technical assistance to ILBANK and participating municipalities to strengthen their capacity in project preparation, financial management, and sustainable urban planning. This will include developing pipelines of bankable, climate-smart investments, strengthen municipal financial and institutional capacity, and enhance long-term resilience to climate and disaster risks.
“By combining financing with technical expertise, this project will help cities develop bankable, climate-smart investments and improve their access to long-term financing,” said Ahmet Kindap, Task Team Leader for of the Project.
The project is also designed to help municipalities strengthen their creditworthiness and lay the groundwork for greater private sector participation over time.
Aligned with Türkiye’s national development priorities, the project will support both mitigation and adaptation efforts. Investments are expected to reduce greenhouse gas emissions, enhance energy efficiency, and strengthen resilience to climate-related risks such as flooding, drought, and extreme heat. By improving infrastructure systems and service delivery, the project will help cities better withstand future shocks while promoting sustainable and inclusive urban growth.
This project preparation benefited from technical assistance and grants from the Global Facility for Disaster Reduction and Recovery (GFDRR)’s Japan-World Bank Program for Mainstreaming Disaster Risk Management in Developing Countries, supported by the Government of Japan.

IACIPP ANNOUNCES 3rd ‘CIP WEEK’ IN EUROPE

The International Association of CIP Professionals (IACIPP) has announced that the 3rd CIP Week in Europe will take place in Brussels from 20–22 October 2026, bringing together critical infrastructure operators, government representatives, security professionals, resilience practitioners, emergency planners and industry experts from across Europe.

Designed as a focal point for collaboration, learning and professional development, CIP Week Europe will provide delegates with opportunities to explore the latest developments in critical infrastructure protection, resilience, risk management and security, while building stronger connections across sectors and national borders.

With organisations across Europe facing new resilience, security and compliance obligations under the CER and NIS2 Directives, the 3rd CIP Week in Europe will bring together experts from government, industry and academia to explore how critical infrastructure operators can strengthen resilience in an increasingly complex risk environment.

At the centre of the programme will be the Critical Infrastructure Protection & Resilience Europe (CIPRE) Conference, which will feature expert speakers, case studies and panel discussions addressing the complex and evolving challenges facing Europe's critical infrastructure. Topics will include physical and cyber security, resilience strategy, emerging threats, public-private cooperation, business continuity and the protection of essential services.

"The implementation of the CER and NIS2 Directives marks one of the most significant developments in European critical infrastructure protection in a generation," said John Donlon, Chairman of the International Association of CIP Professionals. "Organisations are being challenged to think differently about resilience, security, governance and collaboration. CIP Week Europe provides an opportunity for practitioners and decision-makers to come together, share experiences and learn from one another as they navigate this changing landscape."

In addition to the main conference, delegates will have access to a series of specialist workshops delivered by partner organisations, providing practical insights and focused discussion on key areas of resilience and infrastructure protection.

Among the first confirmed partners is the Confederation of European Security Services (CoESS), which will host a workshop examining the growing role of private security in safeguarding critical infrastructure. The session will explore how security providers are supporting resilience and preparedness objectives across Europe, strengthening public-private partnerships and helping organisations anticipate, prevent, respond to and recover from an increasingly complex threat environment. Particular attention will be given to the contribution of private security to the EU’s Preparedness Union agenda, including the protection of critical entities, continuity of essential services and crisis readiness across sectors.

Catherine Piana, Director General of CoESS, said, “The Confederation of European Security Services is delighted to play a bigger role in this year’s CIP Week. As Europe faces an increasingly complex and evolving risk landscape, the private sector has a key part to play in supporting operators and governments in implementing the CER Directive, while also contributing to the objectives of the EU’s Preparedness Union. With more than two million security professionals operating across Europe, our industry represents a significant preparedness and response capability that can support CI operators before, during and after crises. However, unlocking this full potential requires greater recognition of private security as a strategic partner, stronger public-private cooperation, information sharing and a more coherent framework for integrating private security into national and European preparedness planning. Our workshop will demonstrate how the private security sector can make a tangible impact on security, preparedness and resilience planning.”

“CIP Week Europe was created to bring together the diverse community of professionals responsible for protecting and strengthening critical infrastructure,” continued John Donlon of IACIPP. “As the risks facing critical infrastructure continue to evolve, collaboration, knowledge sharing and professional development have never been more important. We are delighted to welcome delegates and partners to Brussels for what promises to be our most comprehensive programme yet.”

The event is expected to attract participants from government agencies, critical infrastructure operators, utilities, transport providers, security organisations, emergency services, consultancies, technology providers and academic institutions.

Further announcements regarding speakers, additional workshop partners and programme details will be released in the coming weeks.

For organisations involved in critical infrastructure protection and resilience, CIP Week Europe offers a unique opportunity to engage with leading experts, share experiences and contribute to the development of a stronger and more resilient Europe.

For further information and registration details, please contact:

International Association of CIP Professionals (IACIPP) at www.cip-association.org

IAEA Director General Visits Gulf Region to Strengthen Nuclear Safety and Cooperation

IAEA Director General Rafael Mariano Grossi visited Kuwait, Qatar, the United Arab Emirates and Saudi Arabia following the recent drone attack on the Barakah Nuclear Power Plant, reinforcing nuclear safety, security and regional cooperation.
During his visit to Kuwait, Mr Grossi met with Foreign Minister Sheikh Jarrah Jaber Al-Ahmad Al-Sabah to discuss regional developments and the IAEA’s support to countries in strengthening nuclear safety, security, emergency preparedness and response.
The discussions also highlighted cooperation in the peaceful uses of nuclear technology, including applications in health, food security and environmental protection.
Mr Grossi also visited the Kuwait Institute for Scientific Research (KISR), where he saw efforts using nuclear science to support environmental protection.
At KISR, he also received updates on joint cooperation, including research being carried out aboad the vessel Al-Mostakshif under the IAEA’s NUTEC Plastics initiative to assess threats to marine ecosystems.
During his visit to the GCC Emergency Management Centre, discussions focused on regional cooperation in emergency preparedness and response, as well as on strengthening coordination mechanisms during nuclear or radiological emergencies.
In Doha, DG Grossi met with Qatar’s Prime Minister and Minister of Foreign Affairs, Sheikh Mohammed bin Abdulrahman bin Jassim Al Thani, to discuss regional developments, including issues related to Iran’s nuclear programme, reaffirm the importance of dialogue, diplomacy and international cooperation.
In Abu Dhabi, Mr Grossi met with United Arab Emirates Foreign Minister Sheikh Abdullah bin Zayed Al Nahyan to discuss nuclear safety in the country and in the region following the 17 May drone strike on the Barakah Nuclear Power Plant.
The discussions also covered the growing role of nuclear energy in supporting energy security and economic development, along with emerging technologies such as advanced reactors and small modular reactors.
In his visit to the Barakah Nuclear Power Plant, he commended the response by the Emirates Nuclear Energy Corporation and Federal Authority for Nuclear Regulation following the drone attack and reaffirmed the IAEA’s support for nuclear safety and security in the UAE and the wider region.
He also met plant personnel and highlighted the importance of preparedness, resilience and transparency in ensuring the safe operation of the facility.
In Saudi Arabia, Mr Grossi met with Energy Minister Prince Abdulaziz bin Salman to discuss the Kingdom’s advancing civilian nuclear programme and the IAEA’s support for its safe, secure and transparent development.
Advancing Cooperation
Throughout the visit, Mr Grossi emphasized the importance of international cooperation, strong safety and security frameworks and the responsible use of nuclear science and technology to support development, energy security, environmental protection and human health.

JRC identifies key opportunities for critical raw material recovery

Waste from different sources, including batteries, vehicles and electrical equipment, has great potential for the recovery and recycling of critical raw materials, a new JRC report shows.
Critical raw materials are essential elements of key technologies, from electric vehicles and wind turbines, to drones and smartphones. Currently, the EU is highly dependent on third countries for their supply. As the demand for such technologies is expected to surge, this will put immense pressure on securing access to critical raw materials.
By improving waste collection and processing, the EU can recover strategic raw materials domestically. The production of secondary strategic and critical raw materials, as well as extending the lifetime of products, can reduce dependency on third countries and support the transition to a more circular economy.
A new JRC report identifies a list of products, components and waste streams that could have a significant circularity potential for critical and strategic raw materials, such as permanent magnets from wind turbines, cobalt and lithium in electric vehicle batteries, and aluminium parts in vehicles.
The list, a step forward under the Critical Raw Materials Act, will help EU countries prioritise key waste streams for recoverability and help identify gaps in current waste treatment systems. It also highlights challenges and opportunities for a more circular and strategically independent raw materials’ value chain.
From waste to resource
The analysis highlights current gaps in treatment of waste from specific products. For example, small electrical and electronic equipment account for significant losses of strategic and critical raw materials: 46% of the total strategic and critical raw materials in these products is lost in collection. Yet, common household items, such as hard disk drives and cables could have a significant recovery potential, if well-collected and treated.
Moreover, the report shows that critical raw materials used in electric vehicle batteries and wind turbines - the very technologies which power the shift to cleaner energy - are often not sufficiently recovered, leading to a major loss of critical raw materials when these products reach the end of their life.
Similarly, permanent magnets used in wind turbines tend to get lost in bulk steel and aluminium waste flows, rather than being recovered separately, despite their strategic importance. Losses are projected to jump from 1.9 thousand tonnes per year in 2022 to around 45 thousand tonnes per year in 2030, when the first large wave of turbines reaches their end-of-life.
Towards a more circular economy 
The Critical Raw Materials Act requires EU countries to develop national circularity programmes that target specific waste streams. This report supports the Implementing Act of Article 26 of the Critical Raw Materials Act, and helps governments put in place effective programmes by making it easier to spot gaps in existing legislation, processes and data, and to harness circularity potential.
By keeping critical and strategic materials within the continent, the EU can improve the circular economy and EU competitiveness, while reducing exposure to supply disruptions.

CISA Announces Revised Town Hall Schedule to Engage with Stakeholders on Cyber Incident Reporting for Critical Infrastructure

The Cybersecurity and Infrastructure Security Agency (CISA) today announced a revised schedule for a series of virtual town hall meetings to gather stakeholder input on the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) rulemaking. Scheduled to begin June 15, these town hall meetings replace the town hall meetings previously scheduled for March and April 2026, but which CISA was not able to hold due to the recent Democrat shutdown of the Department of Homeland Security (DHS).
CISA remains committed to affording stakeholders the opportunity to provide additional input on the CIRCIA rulemaking through a town hall series before the rule is finalized. The revised schedule is available in the Federal Register. Interested stakeholders may register for the town hall meetings at www.cisa.gov/circia. Any changes or updates to the town halls will be available on www.cisa.gov/circia.
“CISA is working to maximize the impact of CIRCIA to significantly improve our Nation’s cybersecurity posture. At the same time, CISA values the interest and concern our stakeholders have that CIRCIA will be implemented with minimal unnecessary burden to entities in critical infrastructure sectors,” said CISA Acting Director Nick Andersen. “CISA appreciates our stakeholder’s patience with waiting for our rescheduled town hall meetings to provide their critical input as we finalize this rule. As an agency built on collaboration and coordination, CISA is committed to hearing from the American people, critical infrastructure owners and operators, and other community members.”
CIRCIA is a U.S. law that will help the government quickly respond to cyber threats and share information to protect critical infrastructure. Once the final rule is implemented, covered organizations will be required to report certain cyber incidents to CISA within 72 hours and ransom payments within 24 hours.
CISA has received numerous requests for additional engagement on the CIRCIA rulemaking process and greatly values its stakeholders’ interest in shaping a final rule that maximizes CIRCIA’s impact on our Nation’s cybersecurity posture while minimizing unnecessary burden. Given the broad stakeholder community that CIRCIA may potentially impact, CISA will conduct a series of town hall meetings to solicit input on the Notice of Proposed Rulemaking (NPRM). CISA selected this approach to gather additional engagement on the CIRCIA NPRM to provide access to CISA across the broad range of entities within the critical infrastructure sectors.
CISA issued the CIRCIA NPRM in April 2024. To inform the CIRCIA NPRM, CISA hosted in-person public listening sessions across the country, conducted virtual sector-specific sessions, and engaged with Sector Risk Management Agencies (SRMAs) and other federal partners—all aimed at gathering meaningful input from a broad range of stakeholders. The NPRM was open for a 90-day public comment period.

NIS360: The bigger picture on maturity and criticality of NIS critical sectors

This year’s edition of the ENISA NIS360 report shows improvement in cybersecurity maturity of EU critical sectors while the level of criticality in sectors remains comparatively more stable.
The ENISA NIS360 aims to work as an annual assessment tool supporting national authorities, policymakers and other stakeholders in assessing the cybersecurity maturity and criticality of high criticality sectors under the NIS2 Directive.
ENISA Executive Director, Juhan Lepassaar, said: “The findings of this NIS360 report provide grounds to be optimistic. The implementation of the comprehensive EU cybersecurity regulatory framework, and particularly NIS2, has brought significant improvements. ENISA stands for prioritising cybersecurity and advancing the implementation of EU policies, which are vital now more than ever, to enhance the cyber resilience of our critical infrastructure and societies.”.
The report has a comprehensive approach, where each sector is understood to comprise relevant actors (i.e., national authorities, entities, EU bodies) and applicable rules (EU legislation). In this regard, a sector’s maturity under the NIS360 is determined by: legislation and its effectiveness, companies and their preparedness, authorities and their institutional capacity, and sectoral ecosystem structures and their effectiveness.
The assessment relies on a structured methodology developed and continuously refined by ENISA that takes into account the structural and gradually evolving nature of sectoral cybersecurity maturity and criticality. It also builds on evidence gathered over time from organisations operating within the in-scope sectors, national authorities supervising those organisations, but also EU-level data, to reflect our latest evidence-informed understanding of where each sector stands.
As a result, the NIS360 provides both a comparative overview of sectors and a more detailed analysis per sector to help identify gaps and prioritise resources.
Defining the Risk Zone
NIS360 sector risk zone
A combination and joint interpretation of the criticality and maturity dimensions helps identify areas where mismatches exist between the two and define a risk zone.
The risk zone includes sectors with lower-than-average maturity and criticality that exceeds their maturity. This year’s risk zone includes health, railway, maritime, ICT management service, space, public administrations, drinking and waste water.
Its composition changes over time as overall maturity improves across sectors. This explains why three sectors — railway, drinking water, and waste water — previously at the risk zone boundary, are now within the risk zone. A positive development is that the gas sector has started moving out of the risk zone.
Such shift is driven by improved information sharing, stronger collaboration, and better implementation of risk management measures, leading to higher maturity.
Deep-dive on criticality
While criticality of the sectors is defined by NIS2, the NIS360 assessment ranks the sectors taking into account several elements, such as systemic relevance, exposure, and impact of disruption. As these factors typically change gradually, criticality scores tend to remain relatively stable from year to year.
In this year’s edition, sectors such as banking, electricity, aviation, space, and digital-by-default services (including telecommunications, cloud, and data centres) remain the most critical.
Space has joined this group this year, reflecting its growing role in society and across other sectors, which increases dependency, impact, and time criticality. The railway sector increased in criticality due to its growing role in military logistics, and the heightened cyber threat exposure.
Spotlight on maturity 
Maturity is measured by how effectively and consistently the sector manages cybersecurity risks and capabilities over time, meaning the overall preparedness of the sector. Since the previous edition of this report, cybersecurity maturity across EU critical sectors seems to be steadily improving as organisations respond to the evolving policy requirements and to the cyber threats they face.
Three sectors, including trust services, aviation, and financial market infrastructures (FMIs) moved into the high maturity band. In addition, four sectors strengthened their maturity within the moderate band: gas, road, maritime, and health.
This improvement is often driven by several compounding factors including developments in cybersecurity legislation, increased political attention, but also progress across specific maturity dimensions assessed. Particularly, on cybersecurity legislation, findings of the 2025 ENISA NIS Investments study also suggest that it has acted as a key driver for cybersecurity investment and has encouraged organisations to strengthen their cybersecurity posture.
Despite maturity steadily improving across critical sectors, progress still remains uneven both across and within sectors. A number of factors contribute to these variations including skill shortages, sector-specific characteristics and even organisational size.
Moving forward
In the future, it is anticipated that cybersecurity legislation and organisations’ efforts to strengthen their cybersecurity maturity will continue to prompt cybersecurity investment and drive preparedness, leading to more sectors moving out of the risk zone.

Euro-Mediterranean partners advance cooperation on civil protection and disaster risk management

Representatives from across the Euro-Mediterranean region gathered this week for the Union for the Mediterranean (UfM) Civil Protection Meeting to advance regional cooperation on disaster risk management and support the implementation of the 2030 UfM Action Plan on Civil Protection and Disaster Risk Management.
The meeting brought together representatives from UfM Member States, the European Commission’s Directorate-General for European Civil Protection and Humanitarian Aid Operations (DG ECHO), the Prevention, Preparedness and Response to Natural and Man-made Disasters in the Mediterranean programme (PPRD Med), the International Federation of Red Cross and Red Crescent Societies (IFRC), and the United Nations Office for Disaster Risk Reduction (UNDRR). Discussions focused on strengthening regional collaboration on prevention, preparedness, response and recovery in the face of increasingly complex and interconnected risks across the Mediterranean region.
Advancing a shared vision for regional resilience
Participants reviewed recent progress under the UfM Civil Protection and Disaster Risk Management mandate and discussed priorities for strengthening regional cooperation through the UfM Regional Dialogue Platform.
The meeting highlighted key elements of the 2030 UfM Action Plan, including:
- Strengthening public awareness and volunteer engagement
- Enhancing preparedness through capacity development
- Supporting regional disaster assistance and cooperation
- Strengthening national and regional institutions
- Promoting monitoring, evaluation and learning
Discussions emphasized the importance of creating a common culture of risk awareness and resilience, while supporting closer cooperation among governments, civil society, technical institutions, and regional partners.
Strengthening preparedness and knowledge exchange
Participants shared experiences and initiatives aimed at strengthening preparedness and operational readiness across the Mediterranean region.
Discussions highlighted the importance of investing in prevention and preparedness, particularly as countries across the region face increasingly complex and interconnected risks, including wildfires, floods, earthquakes, and climate-related hazards.
Key areas of discussion included:
- Lessons from the 3rd Euro-Mediterranean High-Level Workshop on Fire Risks
- Volunteering and community engagement in disaster risk management
- Early warning systems and information sharing
- Capacity development and training opportunities
- Regional platforms for cooperation and knowledge exchange
Participants also explored opportunities to strengthen collaboration among civil protection authorities and regional partners, while advancing practical approaches to preparedness, information sharing, and mutual support across the Mediterranean.
Building momentum for regional action
UNDRR presented the Stop Disaster Game initiative (an educational tool that helps users better understand disaster risks and resilience-building measures) as an example of innovative approaches to strengthen disaster risk awareness and preparedness.
Participants further discussed opportunities to leverage regional platforms and initiatives, including UfM Med Green Week, to promote collaboration and strengthen engagement on disaster risk reduction and climate resilience.
Looking ahead
The meeting concluded with a shared commitment to continue advancing the implementation of the 2030 UfM Action Plan and strengthening cooperation among Euro-Mediterranean partners.
As countries across the region face increasing risks from wildfires, floods, earthquakes, droughts and other climate-related hazards, continued efforts to strengthen cooperation, preparedness, and operational coordination will help lay the foundations for a more resilient and interconnected Mediterranean.

When Cyber Attacks Reach the Physical World: The Growing Insurance Gap in Critical Infrastructure

Modern life depends on systems we rarely see. Power stations keep the lights on. Pipelines carry fuel across long distances. Chemical plants manage fast and complex reactions. Transport networks move people and goods every day.
Behind all of this sits Operational Technology (OT). These are the control systems, sensors and safety tools that keep physical processes running safely.
For many years, these systems were built with one aim: to keep operations stable. Cyber security was not a priority. Most OT systems were isolated, used proprietary technology, and were run by engineers rather than IT teams.
That world has changed.
Industrial systems are now connected to corporate networks, cloud platforms, remote access tools and supply chains. This has improved efficiency, but it has also created a new kind of risk: cyber attacks that affect the physical world.
When this happens, the impact is very different from a typical IT breach. Instead of lost data or downtime, the result can be damaged equipment, fires, explosions, pollution or long outages.
These events are still rare. But when they happen, the consequences can be severe.
The Nature of OT Cyber Risk
OT systems operate under the laws of physics.
They are designed to keep things like pressure, temperature and flow within safe limits. If those limits are exceeded, equipment can fail, sometimes in dramatic ways. That is why safety systems are built into industrial sites.
Cyber attacks can interfere with these safeguards. Any programmable safeguard designed for an intended function, can be re-programmed to behave in an unintended way.
Attackers might change sensor readings so operators think everything is normal. They might alter controls to change how machines behave. They could disable alarms or safety shutdown systems. In some cases, they may lock operators out of the system altogether.
In many cases, small changes can have big effects. Adjusting a valve, motor speed or sensor reading can push a system outside safe limits. Once that happens, problems can spread quickly.
What matters most is this: once a system crosses a safety boundary, physics takes over. Equipment will behave according to physical forces, not human intent.
How Attacks Reach Physical Systems
Most cyber-physical incidents do not start in the control room.
They often begin with standard IT breaches. A phishing email, stolen login details, weak remote access or a third-party connection can give attackers a foothold. From there, they move through the network until they reach systems linked to industrial processes.
This pattern has been seen before.
A well-known example is the 2014 attack on a German steel mill. Reports suggest attackers entered through the corporate network using phishing. They then moved into the plant’s control systems.
The disruption meant the plant could not safely shut down a blast furnace. This led to serious physical damage.
The lesson is clear: an IT issue can become a physical incident once attackers cross into OT systems.
Not all attacks are highly advanced.
In Australia, a former contractor used radio signals to control sewage pumps, releasing waste into public areas. In Poland, a teenager reportedly used a simple device to interfere with tram systems.
These cases show that even basic weaknesses—like poor access controls or exposed systems—can lead to real-world damage.
Near Misses and Hidden Risks
Some of the most important warnings come from incidents where disaster was narrowly avoided.
The Triton malware attack in Saudi Arabia is a key example. The attackers targeted a system designed to prevent serious accidents, such as uncontrolled material release or unsafe conditions leading to fire/explosion.
A fault in the malware caused the plant to shut down before any damage occurred. No explosion happened.
But the message was clear. Attackers had reached the last line of defence.
From a risk point of view, a near miss is still a serious warning. It may reflect strong safety design—or simple luck.
Rare Events, Severe Consequences
Confirmed cases of cyber attacks causing physical damage are still uncommon.
Over several decades, only a small number of such incidents have been publicly reported.
However, this can give a false sense of security.
Many events are never disclosed due to commercial or regulatory concerns. In addition, OT systems often lack detailed monitoring, so incidents may go undetected or misattributed as a systems malfunction.
At the same time, industrial sites deal with high energy processes and hazardous materials. If something goes wrong, losses can escalate quickly.
A single major event could cost billions, including repairs, lost production, environmental clean-up and legal claims.
The Insurance Challenge
While awareness of OT cyber risk is growing, insurance has struggled to keep up.
Traditional policies were not designed for cyber-physical events. As a result, coverage often falls between two areas.
Property insurance usually covers physical damage, but many policies now exclude cyber-related causes.
Cyber insurance tends to focus on data breaches and IT disruption. It often excludes physical damage.
This creates a gap. If a cyber attack causes physical damage, it may not be covered by either policy.
For operators of critical infrastructure, this is a serious issue.
A single incident could lead to large losses that exceed cyber policy limits, while property insurers may reject the claim due to cyber exclusions. The risk owner pays the entire loss out of pocket.
When Cyber Stops the Physical World
Even without physical damage, cyber incidents can still have major effects.
The 2021 ransomware attack on Colonial Pipeline is a good example. The attack mainly affected IT systems, but the company shut down operations as a precaution.
Fuel supplies were disrupted across large parts of the United States.
This and hundreds of ransomware incidents each year shows how closely digital systems are linked to physical operations.
More broadly, many manufacturers have found that IT failures can stop production entirely. In modern industry, the link between IT and OT is often economic as much as technical.
Why Insurers Find OT Risk Difficult
There are several reasons why this risk is hard to assess.
First, there is limited data. There are not many well-documented cases to analyse.
Second, every industrial site is different. Processes, equipment and safety systems vary widely, including the rigor of their engineering, making standard models difficult.
Third, this risk sits across several fields: cyber security, engineering, safety and finance. Each uses its own language and approach.
This can make it hard for insurers and operators to fully understand each other.
Closing the Gap
Addressing this issue will require closer collaboration.
One approach is to use more quantitative risk models (in this context, risk is $$). Instead of relying only on checklists or broad assessments, these models estimate the financial impact of specific cyber scenarios.
This helps organisations understand where to invest in security. It also helps insurers assess potential losses more clearly.
An Honest Way Forward
The truth is, this is still an evolving area.
Cyber-physical incidents are rare, and data is limited. No single group—operators, insurers or security experts—has all the answers.
What is clear is that cyber risk is no longer just digital. As systems become more connected, attacks will increasingly affect the physical world.
Dealing with this challenge will require engineers, cyber specialists, insurers and policymakers to work more closely together.
The aim is not only to prevent attacks, but also to understand and manage the financial impact when they happen.
Only by bridging the gap between cyber security, engineering and insurance can critical infrastructure remain resilient in a connected world.
By Neil Arklie, Cyber Insurance Expert, DeNexus
DeNexus has combed through 40 years of cybersecurity incidents and have discovered only ~8 that have led to physical property damage due to malicious actors (e.g., Stuxnet). Consider there are thousands facilities globally and hundreds of ransomware driven incidents annually, but on a tiny fraction in 40 years have actually gone beyond downtime, to incur physical damage (e.g., equipment damage, explosion, fire, flooding). Meanwhile, property insurance policies exclude damage triggered by cyber events, and cyber insurance policies exclude property damage. There is a gap where cyber-induced physical damage is not a covered peril for the majority of industry.

Next-generation geospatial models to support coastal risk insurance and risk mitigation

Coastal risks such as storm surges, erosion and the impacts of rising sea levels are escalating, impacting millions of homes and high-value assets. At the same time, the combination of this potential high impact with unpredictability is leaving some areas uninsurable. With the support of ESA's Business Applications and Space Solutions (BASS), UK-based Ocean Ledger has developed as a solution a next-generation coastal surge model to improve accuracy, transparency, and nuance for insurance risk exposure management.
Digital Elevation Models (DEMs) are essential for understanding and managing coastal risks. Existing models are however often static, may rely on outdated bathymetric or shoreline elevation data or are too coarse to capture localised coastal dynamics, which limits their value for risk assessment and operational decision-making.
Ocean Ledger is addressing the gaps in coastal risk data used in DEMs by integrating multiple sources of satellite Earth observation data, delivering a market-ready geospatial service that provides high-value insights for the insurance and climate resilience sectors, while supporting broader economic and societal protection against climate-driven hazards.
“The specific problem being addressed by Ocean Ledger is the absence of frequently updated, spatially granular and environmentally realistic elevation models which are suitable for integration into risk and insurance models,” explained Ocean Ledger CEO Paige Roepers.
In contrast to existing models, Ocean Ledger takes an observation-driven approach, effectively creating a digital twin of the coastline by using standardised satellite-derived topography workflows for shoreline elevation, shoreline position, vegetation and bathymetry. Their hazard model can be used in comparison to other models and to inform risk reduction strategies for those that own and operate assets.
“Through our project with ESA’s Business Applications and Space Solutions (BASS) team, we have been improving our DEMs, making them more accurate with the latest coastline elevation data and historical trend analysis. This allows us to make better predictions and offer more up-to-date insights than others,” says Ms Roepers. “With that, we can provide more transparency to make confident decisions around risk selection and pricing in highly exposed areas.”
Reflecting on the value of taking part in an ESA BASS programme, Ms Roepers added: “Working with ESA BASS has been a catalyst for us, significantly accelerating both our technological road map and commercial traction. The funding has allowed us to transition from high-level research and development to actionable market entry.”
“Having the ESA brand and funding behind us has been an invaluable asset and has helped us achieve the letters of support we needed to carry out pilots. We are looking forward to hopefully start a Demonstration Project with ESA BASS soon, to continue our journey with ESA and to deliver those pilots that will then take us closer to commercial contracts across Europe and the US.”
ESA BASS Applications and Partnerships Officer Ana Raposo said: “It has been wonderful to support Ocean Ledger and see the opportunities they have been able to secure within the ESA BASS Kick-start framework. I look forward to seeing how their journey continues and they go on to capitalise on the springboard for success they have now built.”

Supply Chain Compromises Impact Nx Console and GitHub Repositories

CISA is prioritizing the response to multiple emerging software supply chain intrusion campaigns targeting developer ecosystems Continuous Integration/Continuous Development (CI/CD) pipelines. These recent incidents, including the GitHub compromise via a malicious Nx Console Visual Studio Code (VS Code) extension and the “Megalodon” supply chain intrusion campaign, demonstrate how cyber threat actors are abusing tools and processes that support enterprise, cloud, and DevOps environments—specifically CI/CD pipelines, code extensions and workflows.
Threat actors leveraged a prior compromise of Nx developer systems to compromise a GitHub employee’s device through a poisoned third-party VS Code extension, resulting in unauthorized access and exfiltration of internal GitHub repositories. The malicious extension version (18.95.0) was distributed through VS Code’s automatic update mechanism, meaning systems with Nx Console previously installed may have received the malicious build without developers taking any manual installation action. GitHub released a security advisory on this activity, and CVE-2026-48027 has been assigned to the malicious version of Nx Console and added to CISA’s Known Exploited Vulnerabilities (KEV) Catalog.
Additionally, in a campaign known as “Megalodon,” a cyber threat actor injected malicious GitHub Action workflows to harvest CI/CD secrets, cloud credentials, and tokens, impacting both development and deployment pipelines in public GitHub repositories.
CISA urges organizations to implement the following recommendations to detect and remediate a potential compromise:
- Monitor and audit workflow files and contributor activity for suspicious pull requests and direct commits, particularly those authored by automated accounts.
- Revert unauthorized changes, especially from automated accounts, e.g., build-bot, auto-ci, ci-bot, pipeline-bot and especially those made after May 18, 2026.
If your organization discovers a compromise resulting from previously compromised GitHub or Nx Console software, CISA recommends the following steps:
- Conduct a forensics review of CI/CD logs, cloud audit trails, and affected developer machines.
- Rotate/revoke all secrets including: all credentials, tokens, and secrets accessible to CI/CD pipelines, including API keys, cloud provider credentials (Amazon Web Services, Google Cloud Platform, Microsoft Azure), SSH keys, Docker/npm/PyPI/Vault/Terraform/Kubernetes tokens, GitHub/GitLab/Bitbucket tokens, and developer or pipeline secrets.
- Notify proper stakeholders if necessary.
CISA recommends the following best practices for using package repos:
- Wait at least three hours before pulling a new package. This gives the software community time to identify suspicious or malicious packages before they are widely downloaded.
- Pin software to specific trusted versions. Pinning software prevents pulling a malicious or unscreened package during the build process.
- Only pull packages from known and trusted sources. Relying on known and trusted sources reduces the likelihood of downloading a package that has been maliciously forked.
1 2 3 4 69