€113 million in EU funding allocated to strengthen the resilience of Baltic and Polish electricity grids

The European Commission has allocated €113 million in funding from Connecting Europe Facility (CEF) for critical Synchronisation infrastructure protection implemented by the transmission system operators of Lithuania, Estonia, Latvia and Poland. The implementation of wider range of projects aimed at ensuring energy security against potential cyber and physical threats began on February 9 last year, following the successful synchronization of the Baltic States with the Continental European electricity network.
“Having successfully completed the synchronization project, the Baltic States and Poland continue to invest in energy independence and security. We are grateful to the European Commission for supporting our ambition to make the Baltic Sea region a model for strengthening the security and resilience of critical energy infrastructure across Europe. This funding is the result of our consistent efforts and sets a new precedent, as until now the European Union had no dedicated financing for the protection of critical energy infrastructure. By consistently applying the lessons learned from Ukrainian energy specialists, we are expanding the scope of protection for our critical energy infrastructure projects. We plan to apply for further funding for resilience projects and are actively working to ensure that a long-term EU-level instrument for financing critical energy infrastructure protection is established,” – said Žygimantas Vaičiūnas, Minister of Energy of the Republic of Lithuania.
The protection of critical energy infrastructure is being financed on the EU level for the first time. These possibilities have been empowered due to the implementation of the synchronization project by the Baltic States and Poland. Lithuania together with Estonia, Latvia and Poland is targeting the long-term legal and financial instruments for the financing of the critical energy infrastructure within the EU. Currently the legal instruments are under review, it is expected and the efforts are pursued the initiative to be properly aligned also during the negotiations of Multiannual Financial Framework for 2028-2034.
“We launched the resilience programme just over a year ago, and we have already made significant progress in many areas: we have procured and are installing drone neutralization solutions, implemented initial protection measures for substation equipment, designed and prepared to build physical barriers – materials for which were tested at Lithuanian Armed Forces training grounds – and introduced measures to ensure rapid restoration of damaged infrastructure. We continue to raise the level of cybersecurity. By sharing information and insights with partners in the Baltic States and Poland, working with universities and security experts, and learning from Ukraine’s experience, we are constantly looking for ways to supplement and improve existing solutions,” said Litgrid CEO Rokas Masiulis.
The critical infrastructure protection projects implemented by the Baltic and Polish transmission system operators – Litgrid, AST, Elering, and PSE – as part of the Baltic synchronization effort will be financed through the Connecting Europe Facility (CEF).
The projects will receive up to the maximum possible co financing rate of 50% of eligible costs. Funding for projects in Lithuania amounts to €22 million.
Litgrid’s energy infrastructure resilience programme includes strengthening the physical protection of critical facilities, establishing emergency and crisis reserves for transmission network equipment, installing electronic security systems, deploying unmanned aerial vehicle detection and neutralization systems, enhancing perimeter protection, and preparing to operate under critical conditions.
Litgrid is implementing 13 projects under the resilience programme, comprising more than 150 measures deployed across various transmission network facilities. The programme is continuously reviewed based on threat assessments and new technological solutions.
On February 8, 2025, the Baltic States disconnected from the Russia controlled IPS/UPS electricity system, and on February 9 successfully synchronized their electricity systems with the Continental European synchronous area. Synchronization with Continental Europe enables the Baltic States to operate their electricity systems in close cooperation with other Continental European countries, ensuring stable and reliable frequency regulation, thereby strengthening energy independence and enhancing energy security across the region. The Baltic States joined the Continental European network, which serves more than 400 million consumers in 26 countries.

Draft NIST Guidelines Rethink Cybersecurity for the AI Era

Artificial intelligence (AI) is impacting many organizations’ activities, and cybersecurity is no exception. For anyone interested in the opportunities and risks at the intersection of cybersecurity and AI, the National Institute of Standards and Technology (NIST) has released a preliminary draft of its Cyber AI Profile.
The publication, whose full title is the Cybersecurity Framework Profile for Artificial Intelligence (NISTIR 8596), offers guidelines for using the NIST Cybersecurity Framework (CSF 2.0) to accelerate the secure adoption of AI. The profile helps organizations think about how to strategically adopt AI while addressing emerging cybersecurity risks that stem from AI’s rapid advance.
“Regardless of where organizations are on their AI journey, they need cybersecurity strategies that acknowledge the realities of AI’s advancement,” said Barbara Cuthill, one of the profile’s authors.
The draft resulted from a yearlong effort on the part of NIST cybersecurity and AI experts. Over that time, more than 6,500 individuals have joined the community of interest to contribute to NIST’s development of the profile. After releasing an initial concept paper in February 2025, conducting a workshop the following April, and hosting a series of community of interest meetings in the summer, NIST is now releasing the preliminary draft of the profile for a 45-day public comment period.
The Cyber AI Profile centers on three focus areas:
- Securing AI systems: identifying cybersecurity challenges when integrating AI into organizational ecosystems and infrastructure
- Conducting AI-enabled cyber defense: identifying opportunities to use AI to enhance cybersecurity, and understanding challenges when leveraging AI to support defensive operations
- Thwarting AI-enabled cyberattacks: building resilience to protect against new AI-enabled threats
“The three focus areas reflect the fact that AI is entering organizations’ awareness in different ways,” Cuthill said. “But ultimately every organization will have to deal with all three.”
The Cyber AI Profile can help organizations use the CSF to crystallize their cybersecurity goals with respect to AI and CSF 2.0. The profile offers insights to help organizations understand, examine and address the cybersecurity concerns related to AI and thoughtfully integrate AI into their cybersecurity strategies.
NIST uses the term “community profile” to describe the application of CSF 2.0 to address shared interests and goals among organizations. The Cyber AI Profile joins other community profiles that NIST has created for the manufacturing, financial and telecommunications communities, among others.
The preliminary draft release is intended to seek feedback from the public to inform an initial public draft, which Cuthill says will further refine the profile and include mapping of additional relevant resources to the CSF. Following the 45-day comment period, NIST plans to develop the initial public draft for release in 2026.
When finalized, the profile will help organizations incorporate AI into their cybersecurity planning by suggesting key actions to prioritize, highlighting special considerations from specific parts of the CSF when considering AI, and providing mappings to other NIST resources, including the AI Risk Management Framework.
Cuthill said the authors hope to continue developing the profile as a tool that will prove useful to the community.
“The Cyber AI Profile is all about enabling organizations to gain confidence on their AI journey,” she said. “We hope it will help them feel equipped to have conversations about how their cybersecurity environment will change with AI and to augment what they are already doing with their cybersecurity programs.”

Lessons from Ukraine: What Critical Infrastructure Protection Professionals Should Learn About Information Warfare

Information Warfare Is Infrastructure Warfare
Critical infrastructure protection has traditionally focused on tangible risks: physical sabotage, natural hazards, equipment failure and, more recently, cyberattacks and protest action. These threats remain central. However, the war in Ukraine has revealed a parallel reality that can no longer be treated as secondary. Information warfare – particularly disinformation – has become a core component of infrastructure targeting.
In Ukraine, attacks on energy, transportation, water, and communications systems were rarely isolated technical events. They were embedded within broader influence campaigns designed to shape how populations, governments, and international audiences perceive those events.
Disinformation did not simply accompany infrastructure attacks: it prepared the ground for them, magnified their effects, and prolonged their impact.
The integration of physical, cyber, and influence operations represents a shift in how critical infrastructure is contested. It challenges existing protection and resilience models, which often assume that technical restoration equates to recovery. Ukraine’s experience shows that even when systems are repaired, trust, confidence and social cohesion may remain damaged – sometimes irreversibly.
The lessons from Ukraine are not limited to armed conflict. The same techniques are increasingly applied during peacetime crises, natural disasters, industrial accidents, and political instability. For critical infrastructure professionals globally, understanding information warfare is now a prerequisite for resilience.
Disinformation as a Preparatory Tool
One of the clearest patterns observed in Ukraine was the use of disinformation well before infrastructure attacks occurred. Russian-aligned media outlets, social media networks, and proxy voices consistently promoted narratives portraying Ukrainian infrastructure as outdated, fragile, corruptly managed, or on the brink of collapse.
These narratives served several strategic purposes:
First, they normalised failure. By repeatedly asserting that infrastructure collapse was inevitable, disinformation lowered public expectations and reduced the perceived shock value of outages. When attacks occurred, they appeared to confirm preexisting beliefs rather than signal deliberate aggression.
Second, these narratives undermined institutional credibility. Infrastructure operators, regulators, and government officials were framed as incompetent or dishonest. This eroded trust before any incident took place, ensuring that official communications would be met with scepticism during crises.
Third, preparatory disinformation shaped attribution. When outages occurred, audiences were already primed to blame mismanagement or systemic decay rather than external attack. This confusion benefited the attacker by obscuring responsibility and complicating international response.
For infrastructure protection professionals, this highlights an often-overlooked warning sign: persistent, coordinated narratives questioning infrastructure reliability may indicate more than public dissatisfaction. They can be early indicators of hostile influence activity aligned with future disruption.
Exploiting the Moment of Crisis
The second phase of information warfare unfolded during active infrastructure disruptions. In Ukraine, disinformation campaigns were activated almost immediately following missile strikes, cyber incidents, or sabotage.
Within minutes, false or misleading claims appeared across multiple platforms, often repeating similar themes:
• Exaggerated estimates of outage scale and duration
• False causes, including fabricated internal failures or accidents
• Claims that authorities were concealing the truth
• Warnings of secondary threats, such as water contamination or fuel shortages
These narratives exploited a universal vulnerability: the information vacuum that emerges during fast-moving incidents. In the early stages of any infrastructure failure, details are incomplete, assessments are ongoing, and officials may hesitate to communicate prematurely. Disinformation thrives in this uncertainty.
In Ukraine, hostile narratives often outpaced official messaging, becoming the first version of events many people encountered. Once established, these narratives proved difficult to dislodge, even after accurate information became available.
The result was not merely confusion, but operational impact. Emergency services faced increased pressure due to panic-driven behaviour. Infrastructure staff were targeted by public anger fuelled by false accusations. Compliance with emergency guidance declined as trust eroded.
This pattern is not unique to Ukraine. Any infrastructure incident – whether caused by natural disaster, accident, or attack – creates similar informational vulnerabilities. The difference lies in whether adversaries are prepared to exploit them.
The Post-Incident Information Battle
Infrastructure protection often defines success as restoration of service. Ukraine’s experience demonstrates that this definition is incomplete. Information warfare continued long after power was restored, trains resumed operation, or communications networks stabilised.
Post-incident disinformation campaigns focused on delegitimising recovery efforts. Common narratives included claims that repairs were superficial, that reported restoration was fabricated, or that funds allocated for recovery were being stolen. In some cases, restored services were portrayed as unsafe or intentionally compromised.
These narratives had cumulative effects. Over time, they fostered a sense of permanent vulnerability and institutional failure. Each subsequent incident, even minor ones, triggered outsized reactions because public confidence had already been degraded.
For societies dependent on complex infrastructure systems, this erosion of trust poses a strategic risk. Public cooperation is essential during outages, conservation measures, evacuations, and recovery efforts. When trust collapses, resilience collapses with it.
Energy Infrastructure: Visibility and Vulnerability
Energy infrastructure emerged as a primary target of integrated attacks in Ukraine, both because of its strategic importance and its visibility. Power outages are immediately felt across society, making them ideal opportunities for influence operations.
Russian disinformation consistently framed energy disruptions as evidence of state failure. At the domestic level, narratives emphasised government incompetence and inevitability of collapse. Internationally, messaging warned that Ukrainian instability threatened regional energy security, aiming to undermine external support.
The combination of physical damage and narrative exploitation transformed grid attacks into broader political and psychological events. Even limited outages were portrayed as existential crises.
Globally, energy infrastructure shares these characteristics. It is highly visible, politically sensitive, and closely tied to public confidence. Whether the cause is hostile action, extreme weather, or technical failure, energy disruptions offer fertile ground for disinformation.
Resilience strategies that focus solely on redundancy and hardening overlook this reality. Narrative management – ensuring credible, timely, and transparent communication – is a critical defensive capability for the energy sector.
Transportation and Logistics: Perception Versus Reality
Transportation and logistics infrastructure played a subtler but equally important role in Ukraine’s information war. Disruptions to rail networks, ports, and supply chains were frequently exaggerated through disinformation to suggest nationwide paralysis.
In practice, many of these disruptions were localised or temporary. However, narratives portraying systemic collapse created disproportionate psychological impact. They undermined confidence in the state’s ability to function and fuelled perceptions of chaos.
This illustrates a key insight: the strategic value of infrastructure disruption lies not only in material impact, but in perceived impact. Disinformation can amplify limited damage into a crisis of legitimacy.
Transportation systems worldwide share similar vulnerabilities. They are complex, interdependent, and largely invisible until something goes wrong. When disruptions occur, public understanding is often limited, making perception easy to manipulate.
Communications Infrastructure and the Information Paradox
Communications infrastructure occupies a unique position in information warfare. It is both a target and a medium.
In Ukraine, attacks on communications networks were accompanied by narratives claiming total isolation, even when partial connectivity remained. These claims intensified fear and hindered coordination, despite technical realities being more nuanced.
At the same time, intact communications networks were used to spread disinformation at scale. Social media platforms, messaging apps, and online forums became battlegrounds where narratives competed in real time.
This paradox underscores a challenge for infrastructure protection: connectivity increases both resilience and vulnerability. Robust communications enable coordination and recovery, but they also accelerate the spread of false information.
Managing this tension requires proactive planning rather than reactive moderation.
AI and the Acceleration of Influence Operations
Ukraine has also demonstrated how artificial intelligence and automation are reshaping information warfare. Disinformation campaigns increasingly rely on AI-assisted tools to generate content, translate messages, and adapt narratives rapidly.
These tools enable influence operations to:
• Respond to incidents in near real time
• Tailor messaging to specific regions or communities
• Test and refine narratives at scale
• Sustain high-volume campaigns with limited human input
For infrastructure operators and authorities, this creates a speed asymmetry. Traditional communication processes, often cautious and hierarchical, struggle to compete with automated disinformation systems optimised for velocity rather than accuracy.
As AI-enabled influence operations proliferate, the gap between incident occurrence and narrative dominance will continue to shrink.
Countering Infrastructure-Focused Disinformation: Lessons from Ukraine and the International Response
While Ukraine’s experience highlights the risks posed by coordinated information warfare, it also offers important insights into how states and institutions can respond. Over the course of the conflict, Ukraine – often with support from international partners – has developed a set of adaptive practices aimed at mitigating the impact of misinformation and disinformation surrounding critical infrastructure.
One of the most important developments has been the deliberate integration of strategic communications into infrastructure resilience and crisis management. Ukrainian authorities increasingly treated public communication as an operational necessity rather than a secondary or reputational concern. During major attacks on the energy system, for example, government officials and grid operators provided frequent, transparent updates on outages, repair timelines, and system stability – even when information was incomplete. This approach reduced uncertainty and limited the space available for hostile narratives to dominate the information environment.
Energy sector coordination has been particularly notable. Ukraine’s transmission system operator and energy ministry worked closely to ensure that technical messaging, public guidance, and security communications were aligned. Consistent terminology and shared situational awareness helped prevent contradictory statements that could be exploited by disinformation actors. Similar coordination was observed between rail operators and government authorities following attacks on transportation infrastructure, ensuring that service disruptions were explained accurately and proportionately.
Ukraine also made extensive use of trusted intermediaries. Municipal authorities, emergency services, and local infrastructure operators were empowered to communicate directly with communities, reinforcing national messaging with localised, context-specific information. This distributed communication model proved more resilient than reliance on a single centralised voice, particularly when adversaries sought to discredit national institutions.
At the international level, Ukraine benefited from intelligence and information sharing with partner governments and multilateral organisations. Early warning of coordinated disinformation campaigns – particularly those linked to major infrastructure attack waves –allowed authorities to anticipate false narratives and prepare counter-messaging in advance. Diplomatic engagement also played a role, with partner governments publicly rebutting false claims aimed at international audiences regarding Ukrainian infrastructure stability and energy security.
Cooperation with technology platforms formed another layer of response. While not eliminating disinformation, collaboration improved the identification and disruption of coordinated inauthentic behaviour, particularly during periods of intense infrastructure disruption. This included rapid takedowns of networks amplifying false claims about nationwide grid collapse or fabricated secondary hazards.
Beyond Ukraine, a broader international response is emerging. Several countries have established dedicated counter–foreign information manipulation units within national security or communications structures, many of which now explicitly include critical infrastructure within their remit. Regional organisations and alliances have expanded information-sharing mechanisms focused on disinformation trends related to energy, transportation, and emergency response, reflecting recognition that influence operations often target multiple states simultaneously.
Importantly, these efforts underscore a growing consensus: countering infrastructure-focused disinformation is not solely the responsibility of media regulators or technology companies. It requires sustained collaboration among infrastructure operators, security agencies, regulators, emergency managers, and communicators. Technical resilience and narrative resilience are increasingly understood as interdependent.
Rethinking Resilience: Practical Implications
Ukraine’s experience points to a fundamental shift in how critical infrastructure resilience must be understood.
First, disinformation should be treated as an all-hazards threat. It can amplify the impact of any disruption, regardless of cause. Risk assessments that ignore the information domain underestimate vulnerability.
Second, crisis communications must be integrated into infrastructure protection planning. Communication is not merely a public relations function; it is an operational capability that influences safety, compliance, and recovery.
Third, cross-sector collaboration is essential. Disinformation campaigns rarely target a single sector in isolation. Energy, transportation, water, communications, and government institutions are often targeted simultaneously. Information sharing across sectors improves situational awareness and response.
Fourth, leadership awareness matters. Executives, operators, and incident commanders must understand how their actions, statements, and silences can be exploited. Training should include information threat scenarios alongside technical exercises.
Finally, coordination with public authorities and international partners enhances resilience. Influence operations often operate across borders, requiring shared understanding and collective response.
Protecting the Invisible Layer
The war in Ukraine has revealed that critical infrastructure has an invisible layer: public trust, institutional credibility, and shared understanding of reality. This layer is neither purely technical nor purely social, yet it underpins the functioning of every infrastructure system.
Information warfare targets this layer directly. By manipulating perception, adversaries can turn infrastructure incidents into strategic crises without increasing physical damage.
For critical infrastructure protection professionals worldwide, the implication is clear. Resilience is not achieved solely through stronger defences or faster repairs. It also depends on the ability to recognise, anticipate, and counter hostile narratives.
Ukraine’s experience offers a stark lesson – but also an opportunity. By learning how information warfare operates in conjunction with infrastructure attacks, societies can strengthen resilience before future crises occur. The alternative is to repair systems repeatedly while the foundations of trust continue to erode.
By Natasia Kalajdziovski, PhD, Senior Fusion Threat Intelligence Analyst, SecAlliance

NIST Launches Centers for AI in Manufacturing and Critical Infrastructure

The U.S. Department of Commerce’s National Institute of Standards and Technology (NIST) has expanded its collaboration with the nonprofit MITRE Corporation as part of its efforts to ensure U.S. leadership in artificial intelligence (AI). Through this award, NIST is investing $20 million to establish two centers to advance the delivery of AI-based technology solutions to strengthen U.S. manufacturing and cybersecurity for critical infrastructure.
“This investment will help accelerate the application of AI in American manufacturing and help drive the American manufacturing renaissance,” said Deputy Secretary of Commerce Paul Dabbar. “We can harness AI to increase the competitiveness of our manufacturers and attract investment in America.”
The award is an important step in implementing NIST’s Strategy for American Technology Leadership in the 21st Century to accelerate the progress of critical and emerging technologies from development to adoption, in close partnership with U.S. industry.
“Our goal is to remove barriers to American AI innovation and accelerate the application of our AI technologies around the world,” said Acting Under Secretary of Commerce for Standards and Technology and Acting NIST Director Craig Burkhardt. “This new agreement with MITRE will focus on enhancing the ability of U.S. companies to make high-value products more efficiently, meet market demands domestically and internationally, and catalyze discovery and commercialization of new technologies and devices.”
The AI Economic Security Center for U.S. Manufacturing Productivity and the AI Economic Security Center to Secure U.S. Critical Infrastructure from Cyberthreats will drive the development and adoption of AI-driven tools, or “agents,” in these two national priority areas. The centers will develop the technology evaluations and advancements that are necessary to effectively protect U.S. dominance in AI innovation, address threats from adversaries’ use of AI, and reduce risks from reliance on insecure AI.
NIST will rely on existing resources to build on its expertise and carry forward recommendations in the White House’s July 2025 America’s AI Action Plan, including Pillar I: Accelerate AI Innovation and Pillar II: Build American AI Infrastructure.
These are important first steps in NIST’s programmatic plan to coordinate innovation-based research efforts for accelerating the development and deployment of critical technologies in areas of national priority. Building on its long history of public-private collaboration, NIST plans to use adaptive and flexible partnerships to develop, pilot and implement new advances to establish U.S. leadership and innovation in critical and emerging technologies such as AI, quantum information science and technology, and biotechnology.
The partnership will leverage MITRE’s long-standing mission to operate federally funded research and development centers. NIST expects the AI centers to enable breakthroughs in applied science and advanced technology and deliver disruptive innovative solutions to tackle the most pressing challenges facing the nation.
This agreement expands NIST’s portfolio of AI-focused programs and builds on the private-public partnerships leveraged by the Center for AI Standards and Innovation (CAISI), which leads evaluations of U.S. and adversary systems and contributes to NIST’s efforts to develop best practices. CAISI has established voluntary agreements with multiple developers of leading-edge or “frontier” AI models to enable collaborative research and voluntary testing of industry models for priority national security capabilities.
In the coming months, NIST plans to announce its award for the AI for Resilient Manufacturing Institute, through the Manufacturing USA program. With up to $70 million in investment over a five-year period from NIST and at least that much in nonfederal funding, the institute will bring together expertise in AI, manufacturing and supply chain networks to promote manufacturing resilience.
Combined, these efforts will enhance NIST’s core research, standards and technology mission to tackle barriers preventing U.S. innovation and leadership in AI.

NSA Releases First in Series of Zero Trust Implementation Guidelines

The National Security Agency (NSA) is releasing the first two products in a series of Zero Trust Implementation Guidelines (ZIGs) to provide practical, actionable recommendations to facilitate the implementation of Zero Trust (ZT).
This series of reports outlines the steps to implement the technologies and processes that support achieving the Target-level ZT Capabilities, Activities, and Expected Outcomes described in the Department of War (DoW) CIO ZT Framework.
The Primer and Discovery Phase are the gateway to ZT implementation, providing guidance and direction to ensure organizations are fully equipped to digest and implement the Phase 1 and Phase 2 ZIGs upon their release.
The Primer outlines the strategy and principles used to develop the ZIGs and provides a holistic approach to maximizing the usage of the series. Notably, the ZIGs are designed to be modular, allowing organizations at different levels of ZT maturity to select and implement the capabilities most relevant to the needs of their environment.
The Discovery Phase is intended to help organizations establish foundational visibility and understand the critical data, applications, assets, and services, as well as access and authorization activity existing within the architecture. The goal of this initial phase is to enable informed prioritization and planning by creating a reliable baseline that supports effective ZT implementation.
System owners, cybersecurity professionals, and stakeholders should review these foundational guidelines to gain a deeper understanding of ZT activities and their organization’s operational landscape in preparation for the release of the Phase 1 and Phase 2 ZIGs.

New report explores use of robotics and unmanned systems in the fight against crime

Europol has published The Unmanned Future(s): The Impact of Robotics and Unmanned Systems on Law Enforcement. The report, produced by the Europol Innovation Lab, provides an in-depth analysis of how unmanned systems could change society, crime and law enforcement, and discusses the challenges and opportunities they present.
The report underscores the rapid advancement and integration of unmanned systems in various sectors, including law enforcement. As these technologies become more sophisticated and widespread, they offer new opportunities for law enforcement operations and operational support. However, they also introduce new security threats – such as misuse by criminal and terrorist groups – and regulatory challenges that law enforcement agencies must address to ensure public safety and maintain trust.
"The integration of unmanned systems into crime is already here, and we have to ask ourselves how criminals and terrorists might use drones and robots some years from now. Just as the internet and smartphones presented significant opportunities as well as challenges, so will this technology. Our new report by Europol’s Innovation Lab explores the future operating environment for European law enforcement agencies and suggests actions needed today in order to effectively combat crime while upholding public trust and fundamental rights tomorrow." said Catherine De Bolle,Europol Executive Director.
One chapter of the report highlights the role of war as a driver for innovation in unmanned systems. Recent conflicts, such as the ongoing Russian war of aggression against Ukraine, have accelerated the development and deployment of advanced unmanned systems. The lessons learnt from these conflicts are invaluable for law enforcement agencies in Europe as they prepare for the future operating environment.
Some of the key topics covered in the report include:
Increasing use of unmanned systems
Unmanned systems are becoming increasingly useful, affordable and widely available, with applications in both public and private sectors. Law enforcement agencies across Europe are scaling up adoption of such systems, including drones and robots, to enhance situational awareness, improve safety and extend operational reach. These systems are employed for a range of tasks, such as monitoring, crime scene mapping, search and rescue operations, and the disposal of explosive ordnance, among others. Converging technologies present a significant opportunity for a breakthrough in the capabilities of unmanned systems.
Technical and regulatory challenges
The report highlights significant technical limitations and regulatory gaps that hinder the effective use of unmanned systems in law enforcement. Issues such as limited autonomy, dependence on industrial suppliers and the lack of clear guidelines for autonomous operations pose substantial challenges.
Security threats
Criminal and terrorist groups are rapidly adopting unmanned systems for illicit activities. The report warns of the potential for these systems to be used for criminal surveillance, smuggling and even attacks. The increasing accessibility and versatility of drones, in particular, present serious security concerns.
Public trust and regulation
Public trust is crucial for the legitimacy of law enforcement capabilities. The report emphasises the need for transparency, accountability and public engagement in the deployment of unmanned systems. Current regulations, while advancing, still have gaps, particularly in addressing non-compliant or criminal use.
Future operating environment
The future of law enforcement will require policing in a three-dimensional space, as unmanned systems operate in the air and on the ground, as well as on and under water. This shift will necessitate new strategies, technologies and training for law enforcement agencies.
Recommendations
The report provides a set of recommendations for European law enforcement agencies, including the development of a strategic direction, the establishment of a competency hub and the integration of unmanned systems into existing information systems. It also calls for investments in training, education and public trust-building initiatives.
The report is available for download on the Europol website and includes detailed insights, case studies and recommendations for law enforcement agencies, policymakers and other stakeholders.

CISA Unveils Enhanced Cross-Sector Cybersecurity Performance Goals

New Benchmarks Empower Organizations to Counter Emerging Threats, Build Cyber Resilience, and Strengthen Governance
the Cybersecurity and Infrastructure Security Agency (CISA) released version 2.0 of its Cross-Sector Cybersecurity Performance Goals (CPGs), offering organizations a more robust framework for integrating cybersecurity into daily operations. The updated CPGs align with the National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF) 2.0, incorporates three years of operational insights, and address emerging threats through data-driven, actionable guidance. These enhancements are designed to promote accountability, improve risk management, and support strategic cybersecurity governance across sectors.
The Cross-Sector CPGs represent a targeted subset of best practices, carefully selected through extensive consultation with industry leaders, government stakeholders, and cybersecurity experts. Designed to meaningfully reduce risks to critical infrastructure and safeguard the American public, these goals offer a practical starting point for small and medium-sized organizations. By focusing on a limited set of high-impact actions, the CPGs help prioritize cybersecurity investments that deliver measurable improvements in resilience and risk reduction.
The updated goals offer expanded and clarified guidance across key cybersecurity domains—including account and device security, data protection, governance, vulnerability management, supply chain risk, and incident response and recovery. Building on the foundation of version 1.0.1, CPG 2.0 introduces several notable improvements:
- Governance Emphasis: A new “Govern” function underscores the critical role of organizational leadership in cybersecurity, regrouping existing goals and introducing two new ones focused on risk management strategy, policy development, and executive accountability.
- Unified Goal Structure: Operational Technology (OT) and Information Technology (IT) goals are now consolidated into universal goals, eliminating silos across IT, Internet of Things (IoT), and OT environments.
- Threat-Responsive Expansion: New goals address emerging threats, third-party risk, zero trust architecture, and incident communication protocols.
- Streamlined Framework: Redundant, unclear, or underutilized goals have been removed to improve clarity and usability.
- Enhanced Documentation: Each goal now includes clearer methodology and supporting materials to reduce guesswork and improve implementation.
“Over the past year, CISA has engaged extensively with hundreds of stakeholders across both the public and private sectors to ensure the updated goals reflect real-world challenges and operational realities,” said Madhu Gottumukkala, Acting CISA Director. “Version 2.0 demonstrates our commitment to listening to and incorporating partner feedback to deliver practical, outcome-driven guidance that organizations can act on. These goals are applicable across all critical infrastructure sectors and offer foundational protection for organizations regardless of their cybersecurity maturity. We encourage all organizations to adopt the new CPGs and continue sharing feedback to help us refine future iterations.”
The Cross-Sector CPGs serve three primary purposes:
- Provide measurable actions that critical infrastructure entities can take to achieve a basic level of cybersecurity.
- Bridge communication gaps between IT/OT technical staff and organizational leadership to align on cybersecurity priorities.
- Support strategic planning by offering clear guidance that informs both near- and long-term cybersecurity investments.
CISA encourages organizations to adopt the voluntary Cross-Sector CPGs. To learn more about the updated Cybersecurity Performance Goals and how they can support your organization’s cybersecurity program, visit Cross-Sector Cybersecurity Performance Goals and Objectives.

CISA Releases Dynamic New Guide for Stadium and Arena Owners to Fortify Operations, Mitigate Vulnerabilities and Elevate Emergency Preparedness

The Cybersecurity and Infrastructure Security Agency (CISA) released the Venue Guide for Mitigating Dependency Disruptions, a new resource designed to strengthen the resilience of public gathering venues. This guide provides stadium and arena owners and operators with baseline strategies to mitigate the consequences of potential disruptions to four critical lifeline sectors—including Energy, Water and Wastewater Systems, Communications, and Transportation.
CISA developed this guide in close collaboration with government and industry experts from the four lifeline sectors as a concise, actionable resource for stadium and arena owners. Tailored for major public gathering events- such as FIFA World Cup 2026, America 250, and 2028 Summer Olympics, the guide draws on lessons learned from recent disruptions at high-profile public gathering sports and entertainment facilities across the United States and internationally. It equips critical infrastructure stakeholders with a clear understanding of threats to lifeline sectors and provides effective strategies to safeguard operations, reduce vulnerabilities, and enhance preparedness.
“Today’s risk environment is rapidly evolving, posing serious threats and disruptions to U.S. critical infrastructure and public gathering venues,” said CISA Acting Director Madhu Gottumukkala. “CISA is committed to working hand-in-hand with our government and industry partners to deliver actionable guidance that helps mitigate these risks. This guide empowers venue owners and operators to proactively assess vulnerabilities tied to dependent lifeline services and integrate those insights into contingency planning—ultimately reducing potential consequences and strengthening operational resilience.”
The Venue Guide for Mitigating Dependency Disruptions aligns with Executive Order 14234 Establishing the White House Task Force on the World Cup 2026, Executive Order 14239 Achieving Efficiency through State and Local Preparedness, and Executive Order 14328 Establishing the White House Task Force on the 2028 Summer Olympics. This guide assists critical infrastructure and public venue owners and operations with:
- Understanding the lifeline sector dependencies and interdependencies that their venues may rely on;
- Assessing security risks and associated key components of a facility evaluation; and
- Focusing on continued information-sharing and relationship-building with key partners such as local services providers, first responders, and CISA Security Advisors.
“Robust partnerships are essential to safeguarding critical infrastructure and public gatherings. By sharing threat intelligence, risk mitigation strategies, and other vital information, we strengthen our collective ability to anticipate and respond to potential disruptions. CISA’s newly released guide empowers venue owners and operators to assess dependencies and implement targeted mitigation strategies,” said CISA Executive Assistant Director for Infrastructure Security Steve Casapulla. “We deeply value the insights and collaboration from our government and industry partners across four lifeline sectors, which were instrumental in shaping this timely and practical resource. CISA urges all organizations that host events to review the guide and take proactive steps to enhance infrastructure security and resilience.”

Mistaking AI vulnerability could lead to large-scale breaches, NCSC warns

NCSC raises alert on “dangerous” misunderstanding of emergent class of vulnerability in generative artificial intelligence (AI) applications.
The National Cyber Security Centre (NCSC) – a part of GCHQ – has shared critical insights cautioning cyber security professionals against comparing prompt injection and more classical application vulnerabilities classed as SQL injection.
A new blog advises that, contrary to first impressions, prompt injection attacks against generative artificial intelligence applications may never be totally mitigated in the way SQL injection attacks can be.
Unlike SQL mitigation techniques, which hinge on enforcing a clear separation between data and instructions, prompt injection exploits the inability of large language models (LLMs) to distinguish between the two.
Without action addressing this misconception, the NCSC warns, websites risk falling victim to data breaches exceeding those seen from SQL injection attacks in the 2010s, impacting UK businesses and citizens into the next decade.
Backing proactive adoption of cyber risk management standards, the NCSC challenges claims that prompt injections can be ‘stopped’.
Instead, it suggests efforts should turn to reducing the risk and impact of prompt injection and driving up resilience across AI supply chains.
As AI technologies become embedded in more UK business operations, the NCSC calls on AI system designers, builders and operators to take control of manageable variables, acknowledging that LLM systems are “inherently confusable” and their risks managed in different ways.

Disaster Assistance High-Risk Series: State and Local Response Capabilities

GAO was asked to review long-standing challenges and emerging issues in federal response efforts for recent disasters, including Hurricanes Helene and Milton, the 2025 Los Angeles wildfires, and the July 2025 Texas floods. In September 2025, GAO issued the first report in a series on disaster response, focusing on the federal response workforce. This second report in the series provides information on federal disaster preparedness and response assistance provided before and during recent disasters, variation in state and local response capabilities, and considerations for potential changes to disaster response roles.
Preparing for and responding to disasters, like hurricanes and wildfires, begins with state and local governments. But, their ability to do so varies widely. The federal government provides extensive support through grants, training, and other assistance.
In light of recent interest in reviewing the federal role in disaster response, federal and state officials told us what they would want policymakers to consider with any potential changes. This includes clear communication, time to prepare, and FEMA's federal coordination role.
This is the second report in a series on disaster response. The first was on the federal response workforce.
State Response Team Assisting after Hurricane Helene
All levels of government have a role in preparing for and responding to disasters, with the Federal Emergency Management Agency (FEMA) leading the federal response. It has been nearly 20 years since the Post-Katrina Emergency Management Reform Act of 2006 required actions—such as the development of a national preparedness system—to address shortcomings in the nation’s disaster response system. Federal, state, and local governments, however, continue to face challenges preparing for and responding to large-scale disasters. Recent disasters, such as Hurricanes Helene and Milton in 2024, the Los Angeles wildfires in early 2025, and the July 2025 flooding in Texas, demonstrate the need for government-wide action to deliver assistance effectively.
The federal government provides extensive support to state and local governments for disaster preparedness and response. For example, FEMA provides preparedness grants, training, and technical support to strengthen state and local emergency management capabilities. FEMA and other federal agencies, such as the U.S. Army Corps of Engineers and the Environmental Protection Agency, also supplement state and local efforts during disaster response (see figure).
U.S. Army Corps of Engineers Debris Removal Efforts After 2025 Los Angeles Wildfires
GAO analyzed selected states’ assessments of their disaster response capabilities and found that capability levels varied widely. Federal, state, and local officials GAO interviewed also emphasized the variation in capabilities at the state and local level—including challenges for rural or less resourced jurisdictions, even if they are within a well-resourced state.
GAO has previously reported on challenges with FEMA and other federal agencies’ disaster assistance and added Improving the Delivery of Disaster Assistance to GAO’s High-Risk list in February 2025 to highlight the recommendations GAO has made to improve federal disaster efforts.
Congress and the President have signaled an interest in reforms to FEMA. For example, the President signed Executive Orders in January and March 2025, respectively, establishing a FEMA Review Council to recommend improvements to FEMA and requiring review and revision of response and preparedness policies. Broader reform of FEMA’s mission, structure, or operations may address long-standing challenges with federal disaster efforts. Given the current levels of federal support and wide variation in state and local response capabilities, officials at the federal and state levels provided the following considerations for policymakers for communicating and implementing any such changes:
- Clear communication and guidance. States raised concerns about the uncertainty of the future of FEMA’s role. For example, state officials said it is challenging to plan in the absence of clear, consistent, and accurate guidance and emphasized the importance of consistent messaging about any changes, including technical assistance and training. GAO’s work following Hurricane Katrina also emphasized the importance of communicating clear roles and responsibilities.
- Time to prepare. Given that state and local governments rely on significant federal disaster support, federal and state officials emphasized the need for adequate time for these entities to prepare for any changes in disaster response roles.
- Catastrophic or widespread disasters. Federal officials underscored that there will always be catastrophic disasters for which even the most well-equipped states would require some level of federal financial or other support.
- Federal-level coordination. FEMA also plays a vital role as the coordinating agency for the federal response to disasters. For example, FEMA has the statutory authority to assign other federal agencies to perform disaster response tasks that those agencies might not otherwise have authority to perform.
GAO analyzed information from interviews conducted with federal agencies involved in disaster response and state and local governments impacted by disasters in recent years. Additionally, GAO analyzed preparedness assessments for the 10 states that received major disaster declarations for these recent disasters. To provide information on preparedness and response assistance, we summarized data on FEMA’s obligations for these disasters and amounts awarded through selected FEMA preparedness grants.
1 2 3 4 5 6 69