Rethinking Critical Infrastructure Protection: From Static Defense to Adaptive Resilience

The End of Predictability
Critical infrastructure is no longer operating in a predictable, linear environment. For decades, the global approach to infrastructure protection was built on a foundational assumption of stability: threats were generally discrete, identifiable, and could be kept at bay through robust perimeter defenses. We built higher walls, thicker firewalls, and more rigid compliance frameworks. Today, however, these systems face overlapping disruptions driven by the convergence of climate pressures, sophisticated cyber-physical threats, and the exponentially increasing interdependencies between sectors.
The events of recent years have shattered the illusion of isolated failures. The global IT outage in mid-2024, triggered by a routine software update from a major cybersecurity vendor, demonstrated with chilling clarity how a single point of failure in the digital supply chain could cascade instantaneously across aviation, healthcare, finance, and logistics worldwide. Similarly, the increasing frequency of extreme weather events intersecting with targeted cyber-attacks on energy grids has shown that risks are no longer isolated. They are connected, dynamic, and often simultaneous.
Traditional protection models were explicitly built to defend against known threats. They focus heavily on prevention, hardening of assets, and reactive response protocols. While these elements remain essential components of a comprehensive security posture, they are no longer sufficient on their own. The current risk landscape requires a fundamental paradigm shift—a transition that allows critical infrastructure to continue functioning even when disruptions inevitably bypass defensive perimeters.
This is where the concept of resilience becomes not just an academic theory, but an operational imperative. Resilience is not merely about stopping disruptions; it is about maintaining core operations despite them. It reflects a strategic shift from static defense toward adaptive performance. Instead of asking exclusively, ‘How can we prevent failure?’, the governing question for modern security leaders must become: ‘How can our systems continue to operate, adapt, and deliver value under extreme stress?’
The Structural Limitations of Traditional Approaches
To understand why a new paradigm is necessary, we must critically examine the limitations of the traditional Critical Infrastructure Protection (CIP) models that still dominate national strategies.
One of the most significant vulnerabilities of traditional approaches is their entrenched reliance on sector-based, siloed thinking. Historically, energy, transport, water, telecommunications, and financial services have been managed, regulated, and secured as separate entities. However, modern infrastructure does not respect these artificial administrative boundaries. A disruption in the power grid immediately cripples telecommunications, which in turn blinds the logistics and transport sectors, leading to supply chain paralysis. This siloed management creates severe coordination gaps and exponentially increases the risk of cascading failures. When security teams only have visibility into their specific sector, they are effectively flying blind to the systemic risks building up in the interconnected web.
Another critical limitation is the over-reliance on static risk assessments. In many organizations, risk assessments are treated as compliance exercises—documents updated annually or bi-annually based on historical data and known scenarios. These static models are structurally incapable of keeping pace with fast-evolving, asymmetric threats. They assume a static baseline that no longer exists. When a novel threat emerges—whether a zero-day exploit or an unprecedented climatic anomaly—static defense mechanisms are often paralyzed by the lack of a pre-defined playbook.
Furthermore, traditional models often equate security with rigidity. The assumption is that the more locked-down a system is, the more secure it is. However, in complex, interdependent networks, rigidity often leads to brittleness. When a rigid system is pushed beyond its design parameters, it does not bend; it breaks catastrophically. To address these systemic vulnerabilities, the global security community must move beyond the illusion of absolute protection and embrace a more practical, dynamic, and adaptive approach.
The Adaptive Resilience Paradigm: A Four-Capability Framework
Transitioning from static defense to adaptive resilience requires more than a change in terminology; it requires a fundamental restructuring of how infrastructure is designed, governed, and operated. A practical and practitioner-focused way to operationalize resilience is through a continuous cycle of four core capabilities: Anticipation, Absorption, Adaptation, and Recovery.
Unlike traditional linear response models (Prevent - Respond - Recover), this framework operates as a continuous, dynamic loop — as illustrated in Figure 1 below.
1. Anticipate: Beyond Threat Intelligence
Anticipation goes beyond traditional threat intelligence. It is the ability to identify emerging risks, systemic vulnerabilities, and potential cascading effects before they materialize into full-scale crises. This requires moving from historical data analysis to strategic foresight. In highly interconnected environments, anticipation means mapping the hidden dependencies between your systems and third-party vendors. It involves continuous horizon scanning, utilizing AI-driven predictive analytics, and understanding the ‘weak signals’ that precede a systemic shock. True anticipation means recognizing that the next major disruption will likely come from a vector you have not explicitly planned for.
2. Absorb: Designing for Graceful Degradation
Absorption is the capacity of a system to withstand a shock without experiencing total systemic collapse. In traditional models, systems are often binary: they are either fully operational or completely offline. An adaptive system is designed for ‘graceful degradation.’ This means that when a cyber-attack or physical disruption occurs, the system can isolate the damaged components and maintain essential, life-safety, or mission-critical functions, even at a reduced capacity. Absorption requires structural redundancy, decentralized architectures, and the deliberate engineering of ‘circuit breakers’ that prevent a localized failure from cascading across the entire network.
3. Adapt: Real-Time Operational Agility
Adaptation is the most critical differentiator between rigid defense and true resilience. Absorption buys the system time; Adaptation is what the system does with that time. It is the ability to modify operations, reallocate resources, and change decision-making structures in real-time as a crisis unfolds. When the operational environment changes drastically, static playbooks become obsolete. Adaptation requires empowered, decentralized leadership where frontline managers have the authority to make rapid decisions without waiting for top-down consensus. It also involves technical agility—such as the ability to dynamically reroute data traffic, switch to alternative energy sources, or utilize backup communication channels seamlessly.
4. Recover: Improving Future Performance
In traditional models, recovery means returning to the pre-crisis baseline—the status quo. In the Adaptive Resilience framework, returning to the baseline is considered a failure of learning. If a system recovers only to its previous state, it remains just as vulnerable to the next disruption. True recovery involves continuous learning and systemic evolution. It means analyzing the root causes of the disruption, identifying the friction points in the response, and integrating those lessons into the system’s architecture and governance. Recovery must result in measurably improved performance and enhanced resilience against future shocks.
Insights from the Gulf: The Microcosm of Interdependency
The necessity of this adaptive approach is nowhere more evident than in high-density, technology-driven environments such as the Gulf region. Cities like Dubai and Abu Dhabi represent the vanguard of integrated urban environments, where the concept of the ‘Smart City’ has been fully realized. In these environments, critical infrastructure—water desalination, district cooling, automated transport, and digital governance—is hyper-connected through the Internet of Things (IoT) and centralized data hubs.
These regions serve as a critical microcosm for the future of global infrastructure. They highlight a crucial reality: resilience cannot be bolted on as an afterthought or activated only during a crisis; it must be built into the DNA of everyday operations. Systems that perform well under stress in these environments are those that are continuously monitored, regularly stress-tested through advanced simulations, and supported by robust, cross-sector governance frameworks.
A key insight from these hyper-connected environments is the critical importance of decision-making speed. In interdependent systems, the window for intervention is drastically compressed. A disruption in a smart grid can escalate into a multi-sector crisis in minutes, not hours. Delayed responses exponentially increase the likelihood of cascading failures. Therefore, real-time coordination, automated information sharing between public and private entities, and joint operational command centers are not optional luxuries—they are baseline requirements for survival.
Moreover, the Gulf region’s experience with large-scale events—such as Expo 2020 Dubai, which brought together 192 nations across a hyper-connected physical and digital platform—provides a powerful case study in operationalized resilience. Security planners were required to protect an environment where cyber threats, physical security, health emergencies, and logistical disruptions could materialize simultaneously and at scale. The approach adopted was not one of absolute prevention, but of continuous anticipation and rapid adaptation. Dedicated cross-agency coordination centers operated around the clock, empowered to make real-time decisions across sector boundaries. The lesson was unambiguous: resilience is a governance model, not merely a technical solution. It demands that human systems—command structures, communication protocols, and leadership cultures—evolve in parallel with the technical infrastructure they are designed to protect. This is a lesson that applies equally to every infrastructure operator, regardless of geography or sector.
Actionable Recommendations for Security Leaders
For professionals, site managers, and policymakers working in critical infrastructure, transitioning to this adaptive model requires deliberate, sustained effort. The following practical actions can significantly strengthen institutional resilience without requiring an immediate, ground-up redesign of existing systems:
1. Map Cross-Sector Interdependencies: Move beyond internal risk assessments. Conduct rigorous mapping of your dependencies on external sectors (power, water, telecom, third-party IT vendors) to understand exactly how external failures will cascade into your operations.
2. Establish Real-Time Coordination Mechanisms: Break down the silos. Create joint communication protocols and shared dashboards between infrastructure operators, government agencies, and emergency responders to drastically reduce the time between detection and response.
3. Integrate Scenario-Based Planning: Abandon static risk matrices. Implement dynamic, scenario-based wargaming that simulates complex, multi-hazard environments (e.g., a simultaneous cyber-attack during an extreme weather event) to test the limits of your absorption and adaptation capabilities.
4. Design for Operational Flexibility: Engineer systems with the capacity for graceful degradation. Ensure that critical functions can be manually overridden or physically isolated from the broader network to maintain partial functionality under extreme stress.
5. Invest in Leadership Readiness: Resilience is ultimately a human endeavor. Train leaders to make high-stakes decisions under conditions of extreme uncertainty and incomplete information. Empower frontline managers to adapt protocols dynamically when rigid playbooks fail.
6. Embed Continuous Learning: Institutionalize the recovery phase. Create formal mechanisms to systematically extract lessons from every disruption, near-miss, and simulation, ensuring these insights are immediately integrated into future architectural and governance planning.
It is important to emphasize that these six actions are not isolated technical upgrades. They represent a coherent governance philosophy. Individually, each action strengthens a specific vulnerability.
Collectively, they create a self-reinforcing cycle of institutional resilience. Organizations that have begun this transition report not only a measurable improvement in their crisis response capabilities, but also greater confidence among leadership in navigating uncertainty. In an era defined by permanent volatility, the ability to adapt is no longer a competitive advantage—it is the baseline requirement for continued operational relevance.
Conclusion: The New Foundation of Governance
The future of critical infrastructure protection will not be defined by who can build the strongest defenses, but by who can sustain operations through the most severe disruptions. The illusion that we can predict and prevent every threat has been definitively shattered by the complex realities of the modern, interconnected world.
Transitioning from static defense to adaptive resilience is no longer a theoretical debate; it is the new foundation for effective infrastructure governance. By embracing a continuous cycle of anticipation, absorption, adaptation, and evolutionary recovery, security leaders can ensure that our most vital systems remain functional, reliable, and capable of supporting society—no matter what shocks the future holds.
Resilience is no longer an option. It is the definitive metric of survival.
About the Author
Prof. Ehab ElHegawy is Professor of Security Sciences and Head of Security Crisis Management at Dubai Police Academy, UAE, with 30 years of operational and academic experience.

The latest issue of Critical Infrastructure Protection & Resilience News has arrived

Please find here your downloadable copy of the Spring 2026 issue of Critical Infrastructure Protection & Resilience News, the official magazine of the International Association of CIP Professionals (IACIPP), for the latest views, features and news, including a Review of the recent Critical Infrastructure Protection & Resilience North America conference, held in Baton Rouge, Louisiana.
Critical Infrastructure Protection & Resilience News in this issue:
- Rethinking Critical Infrastructure Protection: From Static Defense to Adaptive Resilience
- When Cyber Attacks Reach the Physical World: The Growing Insurance Gap in Critical Infrastructure
- Interdependencies - The hidden links between heat, water, and energy
- Why Critical Infrastructure Should Use Drone Vulnerability Risk Assessments Now
- Detection vs. Deterrence: What Actually Stops Intruders
- Algorithmic Amplification Is Now a Critical Infrastructure Risk
- The Unblinking Eye: Advancing Critical Infrastructure Security through GDPR Friendly Iris Recognition
- Review of Critical Infrastructure Protection & Resilience North America
- Agency News
- Industry News
#criticalinfrastructureprotection #criticalinfrastructure #resilience #cybersecurity #emergencymanagement #riskmitigation #portsecurity #homelandsecurity #firstresponder #riskmanagement #ai #artificalintelligence #energysecurity #gridresilience

CISA, NCSC-UK and Partners Release Cybersecurity Advisory on Chinese Government-Linked Covert Networks

CISA and the United Kingdom’s National Cyber Security Centre, in collaboration with other federal and international partners, have released a cybersecurity advisory, Defending Against China-nexus Covert Networks of Compromised Devices, providing network defenders with vital tools and resources to combat the threat posed by Chinese government-linked threat actors’ use of covert networks of compromised devices.
The advisory outlines tactics, techniques, and procedures associated with Chinese government-linked covert networks built from compromised small-office-home-office routers, Internet of Things, and smart devices. It explains how threat actors leveraging these covert networks, including those previously tied to groups such as Volt Typhoon and Flax Typhoon, use large scale botnet infrastructure to obscure attribution and enable reconnaissance, intrusion, command-and-control, and data exfiltration.
The advisory provides tailored defensive guidance for cyber defenders to identify, baseline, and mitigate activity originating from dynamic, deniable covert networks to reduce the risk of organizational compromise.
CISA and partners recommend the following steps to protect against this threat:
• Map and understand network edge devices, developing a clear understanding of organizational assets and what should be connected to them.
• Baseline normal connections, especially to corporate VPNs or other similar devices.
• Maintain log collection and storage solutions to assist with detecting and responding to unauthorized access attempts.
• Implement multifactor authentication for remote connections.
For more information on Chinese government-linked threat actor activity, please visit CISA's China Threat Overview and Advisories page.

Ukraine's experience in critical infrastructure protection is increasingly shaping European thinking on resilience and preparedness

As part of the celebration of the first anniversary of the presentation of the EU Preparedness Union Strategy by the European Union, an EU conference on emergency preparedness, organized by the EU in Emergencies initiative, was held in Brussels (Kingdom of Belgium). The event became a platform for discussing achievements during the year of implementation of the Preparedness Strategy, as well as for exchanging experiences and discussing future challenges.
Vasyl Ananyev, a specialist in the Department of Critical Infrastructure Protection of the State Special Communications Administration, spoke during a session of experts on civil-military cooperation about the role of critical infrastructure protection in ensuring Ukraine's resilience.
“Resilience must be implemented at all levels, and a culture of preparedness should be strengthened in all our societies. The discussion clearly demonstrated that Ukraine’s experience is not only about the resilience of our nation — it is increasingly shaping the European approach to preparedness and resilience,” the State Special Communications Service specialist concluded.
Vasyl Ananyev thanked EU in Emergencies for its continued support for Ukraine and the opportunity to present our country’s experience in protecting critical infrastructure in the face of full-scale war and continuous air strikes on civilian infrastructure.
The two-day conference in Brussels on the occasion of the first anniversary of the EU Preparedness Strategy brought together government representatives, civil protection experts, military, private sector leaders and partners from across Europe. The participants of the event paid special attention to the lessons learned from Russia's military aggression against Ukraine, and also summed up the annual results of the implementation of the Union's Readiness Strategy.
Recall that in March last year, the European Union presented the EU Readiness Strategy, which contains plans for preventing and responding to new threats and challenges in the world.
[source: Vasyl Ananyev, News OKI Defense]

Beyond Compliance: Conceptual and Implementation Cycles in Critical Infrastructure Protection

By Michael Kolatchev, Principal, Rossnova Solutions & Lina Kolesnikova, Senior consultant, Rossnova Solutions, Belgium
Protection of critical infrastructure (CI) is a core national security responsibility that cannot be ensured by any single actor and therefore requires sustained national-level coordination. As a result, it has become a strategic public policy priority in many states. Although CI protection involves multiple public and private stakeholders, international practice confirms the central role of the state in providing strategic direction, ensuring policy coherence, and integrating security considerations, particularly in response to hybrid threats and malicious activities.
Given the systemic and cross-sectoral nature of CI-related risks, the state typically acts as the principal coordinator by establishing governance structures, adopting national strategies, defining mandatory security and resilience requirements, and overseeing their implementation. Effective CI protection enhances resilience, deterrence, and strategic stability by reducing vulnerabilities to disruption and coercion, while avoiding unnecessary centralisation of operational functions.
CI protection cannot be achieved through a single decision or strategy. Resource, expertise, and time constraints, combined with evolving infrastructures, societal needs, and threat landscapes, render one-off approaches insufficient. CI protection should therefore be understood as an iterative and adaptive process rather than a fixed objective. National CI frameworks usually require several years to develop and should allow for periodic updates, for example every three to five years, enabling continuity within a coherent framework.
Such an approach requires continuous coordination, information sharing, and education of stakeholders and society. Static measures, including legislation or information websites alone, are insufficient. Information on requirements and planned changes must remain accessible, current, and actively communicated. Ultimately, effective CI protection depends on the feasibility of objectives and strategies relative to national preparedness and, critically, on people. Responsible behaviour and long-term cultural change among key stakeholders and society are essential to sustainable CI protection.
Cycles in the Development of CIP
Experience across jurisdictions suggests that the development of critical infrastructure protection (CIP) can be structured around two interrelated cycles: a strategic conceptualization cycle and a practical implementation cycle. Their iterative interaction enables continuous adaptation of CIP systems and alignment between strategic objectives and operational outcomes.
The conceptualization cycle covers the formulation, review, and adjustment of CIP strategy. Over time, strategies typically become more refined and aligned with implementation capacities. Maintaining consistency between strategic ambitions and available resources is essential, as persistent misalignment may undermine institutional credibility and stakeholder trust.
A key output of conceptualization is an effective legal and regulatory framework. Legislation should be treated as an integral component of CIP strategy and a tool for its enforcement. The choice of legislative model — umbrella or sector-specific — should reflect institutional maturity and stakeholder compliance capacity. Given the dynamic threat environment, legal frameworks must allow regular adaptation without requiring comprehensive redesign, balancing stability with flexibility.
Conceptualization of the CIP Strategy
The conceptualization of a critical infrastructure protection (CIP) strategy can be understood as an iterative process in which each cycle produces answers to a set of core strategic questions. Where necessary, these answers are formalised through legal and regulatory instruments in order to ensure implementation and accountability. Together, these questions define the key dimensions of CIP strategy development:
• What?
• Who?
• How?
• When?
These dimensions structure strategic decision-making and link policy objectives with governance, operational capabilities, and timelines.
Dimension Key Question Strategic Focus
C.1.1 - What? 
Definition of what constitutes critical infrastructure, including sectors, assets, functions, and services. Identification of protection objectives and priorities, including the balance between protection and resilience. Determination of system boundaries, external dependencies, and relevant threat categories.
C.1.2 - Who?
Allocation of roles and responsibilities among state authorities, regulators, operators, and other stakeholders, including responsibility for strategy development, implementation, coordination, oversight, and effectiveness assessment.
C.1.3 - How?
Selection of protection approaches and instruments, including risk assessment methods, security and resilience measures, operational readiness requirements, coordination mechanisms, and capacity-building. Assessment of the ability of the state and operators to implement these measures.
C.1.4 - When?
Establishment of timelines for strategic decisions, implementation phases, entry into force of requirements, evaluation cycles, and periodic review and adjustment of the strategy and regulatory framework.
Taken together, these dimensions ensure that CIP strategies are not limited to declarative objectives, but are grounded in governance structures, operational feasibility, and temporal discipline — factors that are essential for managing systemic security risks and maintaining strategic stability.
One of the key techniques useful in both formulating the concept and verifying its coherence and feasibility is backward planning and dependency analysis. It starts from the end – imagine, the objective is achieved – and analyses what that future looks like, how that future must function, who does what, etc. Then the analysis goes further backwards finding which necessary components of the future should become available and by when, etc.
Outcomes of Conceptualization and link to Implementation
The outcome of conceptualization is typically formalised in a roadmap defining strategic objectives, timelines, and means. Each conceptualization cycle may encompass multiple implementation cycles aimed at building and sustaining CIP capabilities. This approach enables anticipation of future requirements while ensuring alignment between near-term actions and long-term objectives.
Given evolving threats and constraints, both conceptual and implementation frameworks must adapt over time. Legal and regulatory instruments should therefore support adjustment without undermining legal certainty—an essential requirement in a national security context.
Implementation Cycles
Implementation cycles translate strategic intent into operational reality and provide the feedback necessary for subsequent refinement of the CIP strategy. Multiple implementation cycles may be executed within a single conceptualization cycle, allowing strategic priorities to be pursued through phased, resource-constrained actions.
Each implementation cycle can be structured around four core processes:
• Planning – identification of priority sectors, assets, functions, risks, and acceptable disruption thresholds; development of policies, procedures, response plans, performance indicators, and resource allocation mechanisms.
• Implementation – execution of technical, organisational, and administrative measures, including security enhancements, monitoring, training, redundancy development, exercises, and testing.
• Verification and Evaluation – assessment of effectiveness and compliance through audits, monitoring, testing, exercises, and incident analysis; identification of gaps, deficiencies, and deviations from planned outcomes.
• Improvement and Adaptation – implementation of corrective and preventive actions, adjustment of plans and architectures, scaling of effective solutions, and incorporation of lessons learned into subsequent cycles.
Each implementation cycle is time-bound, reflecting budgetary and resource constraints, while the operation of the protection system itself remains continuous. The use of multiple, iterative cycles enables earlier learning, timely scaling of successful measures, and adjustment of strategy in response to evolving threats.
At the same time, the adaptive capacity of implementation cycles is fundamentally shaped by the objectives, priorities, and boundaries defined during conceptualization. In this sense, conceptualization serves as a strategic constraint and enabler for operational flexibility, directly influencing the effectiveness of CIP as an instrument of national security and resilience.
Wrapping up and drawing from experience
The conceptualization cycle plays a decisive role in defining the objectives, principles, architecture, and core mechanisms of critical infrastructure (CI) protection. Each cycle results in an agreed set of strategic objectives and a corresponding strategy for their achievement, while establishing the parameters that guide subsequent implementation cycles.
Within this process, the definition of objectives — the “what” dimension (C.1.1) — is of central importance. Objectives are rarely fixed at the outset and may be revised multiple times within a single cycle based on analysis across the remaining dimensions: “who” (C.1.2), “how” (C.1.3), and “when” (C.1.4), which reflect governance structures, available instruments, and temporal constraints. As a result, conceptualization typically proceeds through iterative adjustments that align strategic intent with feasibility and capacity.
This iterative logic enhances strategic coherence and realism, reducing the risk of setting objectives that are unattainable or disproportionate to available resources—a common source of failure in national security policy design.
Drawing on international practice, several core recommendations can be identified for the development of CI protection systems:
Conceptualization cycle
• Clearly define the scope of protection, prioritising critical functions and services and accounting for cascading and cross-border dependencies.
• Establish a clear allocation of roles and responsibilities among state authorities, operators, and other stakeholders, supported by central coordination.
• Develop a realistic strategy aligned with national capabilities, resources, and an adaptive legal and regulatory framework.
Implementation cycles
• Apply phased, time-bound implementation with achievable objectives and measurable outcomes.
• Ensure coordination mechanisms capable of operating in both routine and crisis conditions.
• Institutionalise regular testing and exercises as a core element of resilience and readiness.
Cross-cutting principles
• Embed continuous feedback and improvement through the integration of implementation results into governance and strategic review.
• Maintain transparency and predictability of requirements while avoiding excessive or purely formal regulation.
• Prioritise resilient and reliable operation over formal compliance, treating day-to-day system performance as the primary measure of effectiveness.
While international experience provides valuable guidance, its effectiveness depends on careful adaptation to national legal frameworks, institutional arrangements, infrastructure maturity, and resource constraints. In a security context, successful CI protection is achieved not through replication of external models, but through the disciplined translation of international best practices into nationally viable strategies.
Policy Implications and Initial Steps  
As initial steps toward the development of a national concept and legal framework for critical infrastructure (CI) protection, states should adopt a risk-governance–driven approach grounded in an explicit understanding of the evolving threat environment. Priority actions include:
• conducting a systematic inventory of infrastructures, functions, and services based on their criticality, interdependencies, and potential national-level impact under diverse threat scenarios;
• assessing maturity and readiness of key operators and public authorities to manage risks arising from cyber, physical, hybrid, and systemic disruptions;
• defining core principles and strategic priorities for CI protection that reflect national risk tolerance, security objectives, and available capabilities and resources;
• defining (estimating) the pace of continuous CIP build-up as the country and the society can realistically afford, with, for example, 3-or 5-year iterations;
• developing a framework concept and roadmap that enable phased implementation and adaptive responses to changing threat dynamics;
• initiating preparation or adaptation of legal and regulatory instruments designed to support continuous risk assessment, feedback, and periodic revision of requirements.
Together, these steps provide the institutional and analytical foundation for integrating CI protection into broader national security risk governance and resilience planning, while staying realistic and adequate to individual country situation, balancing the “would” with the “could”.

OSCE promotes marine transport security and relevant Convention implementation

The OSCE Programme Office in Astana co-organized a practical seminar on inspection of higher educational institutions and maritime training centres of Kazakhstan in co-operation with the Committee of Railway and Water Transport of the Ministry of Transport and with the support of the Kazakhstan Maritime Academy of the Kazakh-British Technical University. The main goal of the seminar was to strengthen oversight of inspection and accreditation of higher educational institutions and maritime training centres in Kazakhstan, in line with the International Convention on Standards of Training, Certification, and Watchkeeping for Seafarers (STCW).
Maritime safety begins long before a vessel leaves port, it starts in the classroom, where future seafarers are trained to meet international standards. The STCW sets globally accepted minimum standards for the training, certification, and competence of seafarers, ensuring that ships are operated safely worldwide. Before STCW, standards varied widely between countries, creating risks to maritime safety and uneven levels of crew competence. The Convention also plays a key role in protecting the marine environment, as competent seafarers are better equipped to prevent pollution and respond effectively to environmental emergencies.
The seminar focused on the strict STCW requirements governing seafarer training, including curriculum development, teaching methodologies, assessment processes, and institutional facilities. Participants gained a comprehensive understanding of how inspections are conducted, the methodologies used for evaluation, and the specific criteria applied during accreditation.
Through in-depth discussions and practical guidance delivered by an international expert, the seminar helped to identify areas for improvement and support the Ministry’s efforts to modernize and adapt its national framework, where needed. This initiative represents an important step toward modernizing national inspection systems, strengthening compliance with international standards, and enhancing maritime safety and environmental protection.

OSCE and Kazakhstan Strengthen Co-operation on Emergency Management and Disaster Risk Reduction

The Head of the OSCE Programme Office in Astana, Ambassador Alexey Rogov, met with Deputy Minister for Emergency Situations, Batyrbek Abdyshev, at the Ministry's Crisis Management Center to review joint achievements and chart future co-operation in disaster risk reduction and emergency response.
The discussions highlighted the tangible results of the partnership between the OSCE Programme Office in Astana and the Ministry for Emergency Situations. Through the partnership, two critical digital tools have been successfully implemented: the Digital Safety Passport and Interactive Maps sub-systems. These innovations have been integrated into the Ministry's geographic information system (GIS ES), substantially enhancing the country's capacity to forecast and monitor emergency situations.
Deputy Minister Abdyshev congratulated Ambassador Rogov on his recent appointment and expressed appreciation for the Office’s continued support. He emphasized that initiatives on future co-operation are discussed on working and higher levels, and highly relevant to the Ministry’s strategic priorities, particularly noting strong interest in the planned capacity-building seminars on satellite imagery interpretation and the programme to certify Caspian Sea divers according to international standards.
During discussions, the Ministry shared insights into its expanding operational capabilities, including conducting an average of eight drone operations daily – the highest volume among all State agencies, and provided practical examples of their use in rescue and monitoring scenarios as well as the integrated use of Artificial Intelligence. The Ministry’s technical expertise in unmanned aerial systems has positioned it as a resource for other government bodies requiring complex drone-assisted operations.
The sides also addressed emerging security challenges linked to climate change, with the Ministry actively monitoring global patterns in the frequency and intensity of natural disasters.
Ambassador Rogov noted that the partnership demonstrates how international co-operation can deliver practical tools that enhance public safety and strengthen institutional capacity in emergency management. He reaffirmed the OSCE's commitment to supporting Kazakhstan's efforts to further modernize its civil protection systems and build resilience against emerging challenges.
Looking ahead, both sides outlined priority areas for future co-operation in the coming years, including automated monitoring systems for natural hazards, research on glacial and landslide-dammed lakes, seismic hazard assessment, and detailed seismic zoning maps. These priorities will form the basis of a multi-year co-operation framework to be developed in the coming period.
The Office will continue implementation of planned activities, including upcoming capacity-building seminars and technical assistance programmes.
The initiatives, implemented in close co-operation with the Ministry for Emergency Situations, underscore Kazakhstan’s commitment to strengthening its emergency management systems and demonstrates the country's dedication to adopting innovative digital solutions and international good practices in civil protection and disaster risk reduction.

CISA Helps Johnny Secure Operational Technology: New Guidance Addresses Cyber Risks from Legacy Protocols

CISA released the guidance Barriers to Secure OT Communication: Why Johnny Can’t Authenticate. This guidance highlights the known issues with insecure-by-design legacy industrial protocols and seeks to understand why the technology to secure these protocols is not widely adopted. CISA developed this guidance in partnership with operational technology (OT) equipment manufacturers and standard development organizations, by interviewing OT asset owners and operators to understand:
1. What motivates owners and operators to secure communication, and
2. What barriers prevent successful adoption from design through deployment and operations.
Legacy OT protocols lack strong protections against data alteration, device impersonation, and unauthorized access, making critical infrastructure vulnerable to cyber threats. Securing these protocols requires solutions that are practical for current operators as well as cyber experts. Based on the research conducted, CISA provides recommendations for how owners and operators can avoid the negative experiences of their peers, as well as recommendations to OT manufacturers to drive sustainable, more usable capabilities.
For OT Owners and Operators:
• Learn why message signing is the foundation for secure OT communication and when encryption is essential.
• Discover practical strategies for phased adoption of secure protocols to minimize operational risk.
• Identify which OT communications should be prioritized for enhanced security and resilience.
• Explore ways to simplify secure workflows and key management for easier implementation.
For Manufacturers:
• Gain insights from customer research to reduce customer friction and deliver more usable, secure products.
• Explore actionable recommendations to address cost and complexity barriers to secure communication.
• Learn how usability metrics like deployment time and ease of integration can differentiate your solutions and accelerate adoption.
CISA encourages critical infrastructure organizations and OT manufacturers to review and implement the recommendations in this guidance.

Ignitis Gamyba Allocates €1.1 Million in Humanitarian Aid for Ukraine’s Critical Infrastructure

From September 2024 to this October, Ignitis Gamyba allocated €1.1 million in humanitarian aid to support the restoration of Ukraine’s war‑damaged energy infrastructure. According to the European Commission, this is the largest logistical operation it has ever coordinated.
In just over a year, 145 lorries loaded with equipment were dispatched from the Vilnius TE‑3 Combined Heat and Power Plant. According to the company’s calculations, a total of 2,681 tonnes of equipment have been allocated for humanitarian aid.
“In this challenging period, as Ukraine experiences continued russian aggression and the destruction of its energy infrastructure, we remain firmly committed to supporting the Ukrainian people. Lithuania’s initiative to relocate a full thermal power plant, with a combined heat and electricity capacity of nearly 1,000 MW, to Ukraine through the EU Civil Protection Mechanism is a powerful example of solidarity and cooperation. A thermal power plant of this size can provide heating for approximately half of Vilnius households. This support is necessary to rebuild the energy sector, which is vital to the daily lives of Ukrainians. I am sincerely grateful to all the countries, companies and institutions involved in this massive project. This operation only became possible through the efforts of all of our partners,” says Minister of Energy Žygimantas Vaičiūnas.
The principal activities of Ignitis Gamyba’s TE‑3 were suspended in 2015 due to high operating costs and an assessment that operation of the power units would not have a significant impact on the stability of the electric power system.
“For more than 30 years, this power plant provided heating for roughly half of Vilnius households. Now it is no longer being used, but the equipment we preserved and kept operational was able to contribute to restoring vital functions in Ukraine,” said Ignitis Group CEO Darius Maikštėnas.
The transfer of equipment was officially confirmed on 15 July 2024, following the signing of a support agreement between Ignitis Gamyba and the electricity distribution network operator in Ukraine. For security reasons, more detailed information about the aid being provided, including the exact names of the equipment as well as the power plants it will be going to, cannot be disclosed.

Poland Energy Sector Cyber Incident Highlights OT and ICS Security Gaps

In December 2025, a malicious cyber actor(s) targeted and compromised operational technology (OT) and industrial control systems (ICS) in Poland’s Energy Sector—specifically renewable energy plants, a combined heat and power plant, and a manufacturing sector company—in a cyber incident. The malicious cyber activity highlights the need for critical infrastructure entities with vulnerable edge devices to act now to strengthen their cybersecurity posture against cyber threat activities targeting OT and ICS.
A malicious cyber actor(s) gained initial access in this incident through vulnerable internet-facing edge devices, subsequently deploying wiper malware and causing damage to remote terminal units (RTUs). The malicious cyber activity caused loss of view and control between facilities and distribution system operators, destroyed data on human machine interfaces (HMIs), and corrupted system firmware on OT devices. While the affected renewable energy systems continued production, the system operator could not control or monitor them according to their intended design.
CERT Polska’s incident report highlights:
- Vulnerable edge devices remain a prime target for threat actors.
  - As indicated by CISA’s Binding Operational Directive (BOD) 26-02: Mitigating Risk From End-of-Support Edge Devices, end-of-support edge devices pose significant risks.
- OT devices without firmware verification can be permanently damaged.
  - Operators should prioritize updates that allow firmware verification when available; if updates are not immediately feasible, ensure that cyber incident response plans account for inoperative OT devices to mitigate prolonged outages.
- Threat actors leveraged default credentials, a vulnerability not limited to specific vendors, to pivot onto the HMI and RTUs.
  - Operators should immediately change default passwords and establish requirements for integrators or OT suppliers to enforce password changes in the future.
CISA and the Department of Energy’s Office of Cybersecurity, Energy Security, and Emergency Response (DOE CESER) urge OT asset owners and operators to review the following resources for more information about the malicious activity and mitigations:
- CERT Polska’s Energy Sector Incident Report - 29 December 2025.
- CISA’s joint fact sheet with FBI, EPA, and DOE Primary Mitigations to Reduce Cyber Threats to Operational Technology.
- DOE’s Energy Threat Analysis Center’s threat advisories.
1 2 3 4 5 69