Germany’s Critical Infrastructure Protection (KRITIS)

By Michael Kolatchev, Principal, Managing Director at Rossnova Solutions (Belgium) & Lina Kolesnikova, Senior Consultant at Rossnova Solutions (Belgium)

Germany is one of the world’s leading economies, depending heavily on resilience and reliability of its CI to maintain national security and economic competitiveness. In response to evolving threats including cyber-attacks, natural disasters, and physical sabotage, the country continues to modernize and expand its regulatory and institutional architecture for CI protection.
German Federal government defines Critical infrastructures (KRITIS) as “organizations or facilities of vital importance to the public sector, the failure or impairment of which would result in lasting supply bottlenecks, significant disruptions to public safety, or other dramatic consequences”. Such sectors include energy, water, information technology, healthcare, transportation, finance, government and administration, media and culture.
Ensuring protection of organisations is a core task for government and business, and a central theme of Germany’s security policy. Resilience of CI increasingly becomes a priority.
KRITIS before CER and NIS2
Necessity of protecting Critical Infrastructure in Germany emerged in 1997 with a creation of a working group within the Federal Ministry of the Interior (BMI). The acronym KRITIS has been used ever since.
The first years of KRITIS protection were characterized by numerous discussions with industries associations, companies and authorities to identify specific sectoral needs. This also led to creation of the first recommendations and guidelines for operators of CI.
A major milestone was reached in 2009 with the adoption of the first National Strategy for the Protection of Critical Infrastructures (KRITIS Strategy). This strategy is still the foundation for overall execution of tasks, and it contributes significantly to their understanding and acceptance.
UP KRITIS
It is estimated that approximately 80% of Germany’s CI is owned and operated by private companies. Effective communication with stakeholders including government bodies, sectoral organizations, the media, and the public is often facilitated through industrial (sectoral) associations. These associations play a key role in public-private partnerships (PPPs) for infrastructure protection.
One of the key milestones in the development of Germany’s critical infrastructure protection strategy was the establishment of UP KRITIS in 2007. UP KRITIS serves as a cooperation and dialogue platform between government authorities and private-sector operators of CI. While the initial focus was on IT security, the platform has since evolved. Today, UP KRITIS includes over 1000 members and addresses a comprehensive range of topics related to CIP, encompassing both physical and cybersecurity, as well as resilience and emergency preparedness across multiple sectors.
Given the central role of IT in nearly all critical processes and its continuous and rapid development, protection of information infrastructures has become a key priority within UP KRITIS. This focus reflects increasing complexity and dynamic nature of cyber threats.
In addition to IT-related issues, UP KRITIS addresses broader dimensions of infrastructure robustness, emphasizing that physical protection and cybersecurity must be designed and implemented as interconnected and mutually reinforcing elements of a comprehensive security strategy.
The platform’s structure facilitates public-private knowledge sharing, enabling integration of business expertise with governmental capabilities in protecting critical information infrastructure. This collaborative approach has notably strengthened cross-company and cross-sector communication, which is now embedded in all UP KRITIS activities.
Evolving regulations
The Federal Republic of Germany’s approach is closely aligned with evolving EU legislation, particularly the CER Directive, NIS2 Directive, and DORA Regulation. National legislation transposing these directives, such as the KRITIS Umbrella Act and the NIS2 Implementation Act establishes obligations for CI operators across physical and cyber domains. This Act regulates resilience and physical security of critical infrastructures, from 2025 onwards.
The Act sets minimum requirements and establishes a catalogue of obligations demanding operators of critical facilities to implement resilience measures. The all-hazards approach applies: every conceivable risk must be considered, from natural disasters to sabotage, terrorist attacks, and human error. Smaller critical infrastructures have the option of voluntarily implementing resilience measures and can rely on industry-specific standards. Potential funding measures are intended to help them improving.
Penalties for violating the law’ provisions are intended to ensure that compliance with security standards is taken seriously and that critical infrastructures remain protected. Amounts have yet to be determined.
Federal ministries are authorized to issue legal regulations to specify resilience measures for the areas within their jurisdiction.
The regulatory landscape is set to evolve further.
CER
The forthcoming National KRITIS Resilience Strategy (2026) will provide a strategic roadmap to strengthen national coordination and sectoral resilience planning.
In contrast to cybersecurity, physical security has historically received less focus, partly due to the complex federal structure of the country, which consists of sixteen federal states (Länder) with differing responsibilities and approaches. With Germany transposing the EU Critical Entities Resilience (CER) Directive into national law by the end of the year, framework for physical resilience of critical entities will enhance.
NIS 2
Germany continues to experience a high volume of ransomware attacks and distributed denial-of-service (DDoS) attacks. In 2024, the cybersecurity industry recorded over 720 such incidents, representing a 67% increase compared to the previous year. Number of attacks targeting SMEs, government and municipal administrations increased sharply. Healthcare, and hospitals in particular, are under attacks. As for most of countries, many cyberattacks in Germany originate from foreign jurisdictions, making attribution and prosecution difficult. Perpetrators increasingly rely on cybercriminal supply chain where capabilities such as malware development, access brokerage, and laundering of ransom payments are outsourced or consumed as services within the new Crime-as-a-Service paradigm.
On July 24, 2024, the Federal Cabinet passed the draft law for the (EU Directive 2022/2555) NIS 2 Implementation and Cybersecurity Strengthening Act, bringing comprehensive modernisation of German IT security law. IT security and security incident reporting requirements are extended to more companies in more economic sectors, like energy, transport, health, or digital infrastructure. It is expected that the number of organizations subject to cybersecurity obligations in Germany will potentially exceed 30,000 entities. This presents considerable administrative and enforcement challenges for the federal level, while cybersecurity at the federal administration itself must strengthen too. The new laws replace the KRITIS regulations in place in Germany since 2014, with more operators implicated and more obligations. Originally scheduled for October 2024, its coming into force is delayed until new Bundestag in 2025.
The Federal Office for Information Security (BSI) receives new supervisory tools to enforce compliance with the new legal obligations. Operators of critical infrastructure facilities are required to register with the Federal Office for Information Security (BSI). Organizations must promptly report significant cybersecurity incidents there. Registered entities must submit a biennial report to the BSI, detailing cybersecurity measures they have implemented. For accountability and continuous improvement, organizations need to undergo certification and external audits, in accordance with defined standards and sector-specific requirements.
Institutional Architecture
Germany’s CI protection is supported by a range of institutions operating at federal and sectoral levels. The Federal Ministry of the Interior (BMI) provides policy leadership and inter-ministerial coordination. The Federal Office for Information Security (BSI) oversees cybersecurity implementation and maintains national situational awareness. Public–private coordination is facilitated through platforms such as UP KRITIS, with strong engagement from sectoral associations.
The inter-ministerial Joint Coordination Task Force for Critical Infrastructure (GEKKIS) serves three key purposes:
• Provide situational reports on protection of critical infrastructure, supporting all federal ministries with a cross-departmental overview of the up-to-date threat landscape.
• Enable communication among ministries, identify common challenges, and develop coordinated responses.
• Convene ad-hoc coordination group for relevant incidents, ensuring rapid and cohesive government action.
This collaborative institutional setup enables Germany aligning with EU standards, and ensuring tailored implementation through cross-sector coordination, federal–state integration, and public–private engagement.
Conclusion
Germany’s approach to CIP follows evolving EU conceptual framework, compliance with EU directives and national implementation. Key elements include:
• Transposition of EU legal instruments into national law, notably:
• The Directive on the Resilience of Critical Entities (CER Directive)
• The Directive on Security of Network and Information Systems (NIS2)
• The Digital Operational Resilience Act (DORA).
• Lessons learned from previous regulatory cycles.
• Adaptation of EU-wide concepts to Germany’s federal system, accounting for sector-specific and state needs.
Most significant conceptual shift is transition from a protection-centric approach to a broader, dynamic focus on resilience, recognising that 100% security cannot be guaranteed. The emphasis increasingly shifts toward ensuring continuity and rapid recovery of services in the face of disruptions.
Key lesson is Germany’s well-structured system of communication, coordination, and collaboration across federal, state (Länder), and local levels. Different stakeholders play clearly defined roles in two-way communication, both government actors and public and private sectors. Mechanisms such as centralized platforms for incident reporting, secure information exchange, and cross-sector coordination, help foster mutual trust and transparency. These structures significantly enhance situational awareness, and enable rapid, coordinated responses to emerging threats.
In the energy sector, operational continuity is central. Installed capacity must match national demand while demanding dynamic power management, with renewable energy in mind, for long-term sustainability. German experience demonstrates integration of existing systems, managed decentralization, and flexible response to demand surges and supply disruptions.
Widespread digitization of CI has exposed systems to new and complex threats, rendering traditional protection methods inadequate. Cybersecurity becomes strategic to CIP. Once a peripheral concern, it has now dedicated legislation, enforcement mechanisms, and technical standards. Rules and oversight structures dedicated to cybersecurity is a response to this reality and a model worth consideration by other countries.
Historically, the focus of CIP has been on large, high-value assets. Supply chains and SMEs now have a greater role. Risk management must extend across entire ecosystems, using unified threat catalogues to support all-hazards risk assessments. If one wants compatibility, consistency, and coordinated responses across sectors and involved operators of different organization types.

The latest issue of Critical Infrastructure Protection & Resilience News (Autumn 2025) has arrived

Your latest issue of Critical Infrastructure Protection & Resilience News has arrived
Please find here your downloadable copy of the Autumn 2025 issue of Critical Infrastructure Protection & Resilience News, the official magazine of the International Association of CIP Professionals (IACIPP), for the latest views, features and news, including a Review of the recent Critical Infrastructure Protection & Resilience Europe conference, which took place in Brindisi, Italy as part of CIP Week in Europe.
Critical Infrastructure Protection & Resilience News in this issue:
- Germany’s Critical Infrastructure Protection (KRITIS)
- About civil protection forces interoperability and citizen crisis real time communication
- Quantum Safe Networks for Critical Infrastructure Protection and Resilience
- Protecting Critical Infrastructure In Nigeria’s Border Communities: Counting The Giant Strides Of The NSCDC
- Energy resilience in the Netherlands: application of the CER directive and identification of critical entities
- Securing the Digital Backbone: How Nokia is Building Resilient, Autonomous Critical Networks
- Review of Critical Infrastructure Protection & Resilience Europe
- The PRESERVE project
- Helping OT Organizations to Establish Defensible Architecture and More Resilient Operations
- Agency News
- Industry News
#criticalinfrastructureprotection #criticalinfrastructure #resilience #cybersecurity #emergencymanagement #riskmitigation #portsecurity #homelandsecurity #firstresponder #riskmanagement #ai #artificalintelligence #energysecurity #gridresilience

Legal and Regulatory aspects relating to the physical security of the telecommunications infrastructure used for critical communication services

Evidence from around the world indicates that threats to Mobile Network Operators (MNOs) are increasing, including to their physical infrastructure. On the other hand, critical communications are transitioning from legacy networks, primarily operated by governments, to broadband networks, in which key components such as Radio Access Networks are procured from MNOs or dedicated infrastructure providers. The combined effect of these two trends requires critical communications operators to pay special attention to the security of the physical infrastructure that is used for critical communications.
Given the importance of the topic, TCCA’s Legal & Regulatory Working Group (LRWG) developed this white paper, starting with a survey of the legal and operational frameworks in the member countries of the LRWG. As the laws and regulations amend and update dynamically, the survey outcomes that formed the basis of this paper were the position as of 31 January 2025.
The survey identified two potential approaches: impose security obligations through legislation/regulation, or rely on provisions in the contract between the critical communications operator and the MNO/infrastructure provider. The LRWG’s assessment is that while each approach has advantages and disadvantages, a combination of these two, whereby legislation/regulation impose a minimum standard on which contractual terms build additional/advanced obligations, would serve the interests of the critical communication services best. As new legal/regulatory obligations on physical security would require additional investment, in what proportion that cost should be borne by the parties could ideally be set by the legislation/regulation in a proportional manner.
The European Critical Communication System (EUCCS) aims to set up a European-wide mission critical communication network that is based on national critical communications networks. It will require a common standard in physical security across all the participating critical communications networks, which can be ensured by the two-pronged approach stated above.
Though new legal/regulatory obligations on physical security would increase the costs and compliances of MNOs/infrastructure providers that provide services for critical communications, it would also have a salutary effect due to the improved standards of security in the network. It is highly likely that thebconsumers, particularly the business customers, will start demanding greater reassurances on all aspects of security in the network including of the physical infrastructure. From a wider national perspective, governments have started taking steps to ensure security of networks which will be complemented by legislative/regulatory obligations on infrastructure used for critical communications.
This paper is intended to draw the attention of the critical communications community to the importance of the issue of physical security and to generate a wide discourse which, it is hoped, will result in a global standard on a baseline on physical security of infrastructure supporting critical communications.
Background
In 2020 a bomb explosion at a central hub of the critical communications provider of a major developed country left emergency officials cut off from the outside world and public without access to emergency services. This incident demonstrates very strongly and very clearly the criticality of the security of physical infrastructure to the proper functioning of critical communications. Incidents of damage to undersea telecommunication cables connecting Nordic and Baltic states provide further evidence of the need to protect the physical infrastructure.
TCCA’s LRWG has developed this white paper to highlight the importance of the security of physical infrastructure, as the LRWG is of the view that it is a topic to which more attention should be paid. This paper focuses on the physical security of telecommunications infrastructure, in order to facilitate further discussions in the critical communication community which it is hoped will result in a global standard on the baseline of physical security of infrastructure supporting critical communications. There are many other facets to the security of critical communication services including data/cybersecurity, which will be examined in other publications.
Most of the current critical communication networks using such technologies as TETRA, Tetrapol and P25, are owned and operated by the state. As such, their physical security is assured by the state to the extent deemed necessary. However, the ongoing transition from these networks to broadband networks has changed the operating model, as governmental agencies providing critical communication services will rely on MNO networks to some extent, including the Radio Access Network (RAN). In some instances, the critical communications services may procure services directly from infrastructure providers who are not MNOs, similar to the way MNOs procure services from them. The discussion of this paper is equally applicable to such infrastructure providers as it is to MNOs. Thus, the physical security of these network elements is of paramount importance. However, it is debatable whether the measures that MNOs are currently adopting in this regard are sufficiently robust and fit for purpose.
The paper titled ’Considerations for Government Authorities when they are planning to acquire Mission Critical Mobile Broadband Services’1 produced by TCCA’s Critical Communications Broadband Group (CCBG) in 2015 identifies security as of vital importance to mission critical communications solutions.
Security is central to ensuring reliability, availability, stability and general performance of those solutions.
The paper details the need for physical security of all infrastructure and adds that “the level of perimeter security shall reflect the importance of the assets to the service including CCTV, intruder alarms, access locks, temperature control, fire and smoke detection.”
The EC Council Cybersecurity Exchange has issued a paper titled ‘The Role of Physical Security in Maintaining Network Security’ in 20222 which states “Although physical security is absolutely critical to maintaining network security, it is among the most often forgotten aspects of protecting a network.
Physical security is defined as protecting physical access to your network and all network components, such as computers, servers, and routers.”
The paper titled ‘Mobile Telecommunications Security Landscape3’ by GSMA, issued in 2022, identifies physical attack on the network as one of the operational security threats to networks.
Given the mandate of and the expertise within the LRWG, this paper focuses on legal and regulatory measures that are applicable to the physical security of telecommunication infrastructure. The LRWG notes that there are numerous technical and operational measures that are relevant but that remain outside the scope of this paper.
The LRWG also examined European Commission regulations which have provisions relevant to the physical security of telecommunication infrastructure.
The LRWG recommends that legislation on physical security of critical communication infrastructure, defining baseline requirements and rules for cost ceilings/sharing, be adopted as an EU directive. Such a multinational standard will greatly assist the decision-making process of individual countries and establish a common understanding between all relevant parties, including MNOs, Governments and users.
Moreover a European regulation would serve as an inspiration for the global community of critical communication operators.
For the full report download the TCCA White Paper - “Legal and Regulatory aspects relating to the physical security of the telecommunications infrastructure used for critical communication services”
White paper published by TCCA’s Legal and Regulatory Working Group, March 2025

Europe Celebrates the Success of the 2nd CIP Week and 10th Critical Infrastructure Protection & Resilience Europe Conference in Brindisi, Italy

The 2nd Critical Infrastructure Protection (CIP) Week in Europe and the 10th Critical Infrastructure Protection & Resilience Europe (CIPRE) conference concluded successfully in Brindisi, Italy, after three days of high-level discussions, collaboration, and innovation in securing Europe’s critical infrastructure.
Held from 14–16 October 2025, the joint event brought together senior policymakers, industry leaders, security professionals, and researchers from across Europe and beyond to accelerate collective resilience efforts and share strategies to address emerging threats to vital systems and services.

Organised under the theme “Resilience through Innovation & Collaboration,” the programme featured more than 50 international expert speakers focus on hot topic discussions, with live technical demonstrations, an industry exhibition, and policy roundtables focusing on the implementation of the EU Directives on Critical Entities Resilience (CER) and NIS2, cyber-physical risk management, maritime and energy resilience, supply-chain security, and climate adaptation for infrastructure.

The event was hosted by the City of Brindisi with support from CIP Week organisers, the International Association of Critical Infrastructure Protection Professionals (IACIPP) secretariat, and The International Emergency Management Society (TIEMS), in cooperation with European institutions, national agencies, and private-sector stakeholders.

A Milestone for European Critical Infrastructure Resilience
The 10th anniversary of CIPRE marked a decade of progress in building a shared European approach to protecting critical assets in energy, transport, communications, health, and digital sectors. The concurrent 2nd CIP Week in Europe strengthened awareness, training, and policy coordination among Member States.

Key Outcomes
Delegates highlighted several strategic outcomes and next steps for the resilience community:
• Cross-sectoral action: Agreement to accelerate national implementation of the CER and NIS2 Directives and to deepen public-private information sharing.
• Elevation of emerging risks: Recognition of AI/OT convergence, drone and UAS threats, supply-chain vulnerabilities, climate-driven hazards, and hybrid (cyber + physical) attack vectors.
• Operational collaboration: Launch of working groups to develop interoperable approaches for cyber-physical incident response and supply-chain resilience.
• Innovation pipeline: Demonstrations of operationally viable solutions for OT/ICS protection, resilient communications, and maritime safety, identified for follow-up pilots.

Strategic Significance and Future Outlook
As Europe faces intensifying hybrid and cyber threats, climate disruptions, and rapid technological change, the Brindisi conference outcomes serve as a catalyst for next-phase action, including:
• Accelerated rollout of CER- and NIS2-compliant frameworks across Member States;
• Expanded cross-border risk-assessment and resilience-planning partnerships; and
• Increased investment in cyber-physical protection, supply-chain resilience, and infrastructure adaptation.

Conference Chairman John Donlon added, “We are extremely grateful to all the people and organisations who have supported us and shared their knowledge, expertise, and enthusiasm. In particular, we thank the Mayor of Brindisi, Giuseppe Marchionna, and his team for hosting us in this fantastic city. We heard many insightful presentations by distinguished specialists and held great discussions on the pressing issues affecting international infrastructure and information communities. CIPRE remains the best place for the industry to meet, network, and share experiences.”

Critical Infrastructure Security Doesn’t Have Time for False Alarms as the Airspace Gets Busier with Drones

Drones have emerged as the tool of choice for bad actors at critical infrastructure sites. The confusion and damage caused by drone activity is very real, and awareness is growing, thanks to a spate of serious recent incidents that have drawn attention to the threat. Reports in December of unknown drone activity in New Jersey  sparked headlines around the world, and drone incidents also paused air traffic in two states, at an Air Force base in Ohio  and an airport in New York . These, unfortunately, are not isolated incidents.
At Sweden’s Stockholm Arlanda Airport , UAS sightings forced the suspension of air traffic, disrupting operations and endangering travelers. In Nashville, a man reportedly attempted to weaponize a drone with explosives  to collapse the U.S. power grid. It’s clear that drones are no longer a toy and are not restricted to causing annoyances such as disrupting air travel. They present a tangible risk to CI sites and reinforce the necessity for operators to be thoroughly prepared. And along with the uptick in drone sightings, a high volume of false alarms has proven a strain to security infrastructure and response teams.
The issue of false alarms is highlighted by an FBI report into drone sightings in December 2024 , concluding that many had been false alarms, with helicopters, hobbyist drones and even stars mistaken for drone threats. The FBI wrote, “Having closely examined the technical data and tips from concerned citizens, we assess that the sightings to date include a combination of lawful commercial drones, hobbyist drones, and law enforcement drones, as well as manned fixed-wing aircraft, helicopters, and stars mistakenly reported as drones. We have not identified anything anomalous and do not assess the activity to date to present a national security or public safety risk over the civilian airspace in New Jersey or other states in the northeast.”
At the same time, aviation and drone flights are growing rapidly, with the FAA dealing with 45,000 flights per day, and a million drones now registered in the U.S. The skies are a busy place, and traditional ‘2D’ security systems at critical infrastructure sites are struggling to keep up.
Recent Executive Orders, such as ‘Restoring American Airspace Sovereignty’  have highlighted the urgency of dealing with this issue, with the President’s Executive Order noting that, “Critical infrastructure, including military bases, is subject to frequent — and often unidentified — UAS incursions.  Immediate action is needed to ensure American sovereignty over its skies and that its airspace remains safe and secure.”
However, all too often, security teams are expected to deal with these new threats on top of their existing tasks, with teams simply asked to ‘look up’ rather than being augmented with specialist officers with the skills to deal with drone threats. That means already-stretched teams are stretched even further.
As demands for airspace monitoring, deconfliction, and threat management rapidly intensify, technology is becoming the essential bridge between strained security resources and evolving operational needs. Advanced sensor systems are now capable of discerning a broad range of airborne objects—not just aircraft—enabling more accurate identification and prioritization. This capability is vital in reducing false alarms and alleviating the burden on overstretched teams. Traditional perimeter intrusion detection systems (PIDS), while useful, often struggle to differentiate between drones posing real threats to critical infrastructure and benign objects like birds, debris, or weather phenomena. Emerging technologies offer a path forward, enhancing situational awareness and supporting more effective, efficient airspace security.
Cameras and radio frequency (RF) sensors have long played a valuable role in monitoring and securing critical infrastructure—from substations to dams—by providing early detection and situational awareness. However, as airborne threats grow in scale and sophistication, these traditional tools face challenges in reliability, often generating false alarms that burden security teams. Relying solely on optical or RF sensors, or ground-based guards focused on 2D perimeters, is no longer sufficient for addressing the complex dynamics of modern airspace threats. Closing this capability gap requires new technologies purpose-built for the evolving landscape.
The Good, Bad, and Ugly: The Airspace is Getting Busier
Drones are filling the skies at an unprecedented pace, driven by surging adoption in agriculture, infrastructure, and the rapid rise of commercial delivery fleets. Commercial delivery drones are expected to grow at 42.7% CAGR per year from 2025 to 2032, for example .
The FAA has registered 420,825 commercial drones and 383,007 recreational drones in the U.S., with drones used to inspect infrastructure sites sharing the skies with everything from electric vertical takeoff and landing vehicles (eVTOLs) and hobbyist UAVs. Hobbyist drone pilots may operate with good intentions, but their presence near airports, for example, can unintentionally disrupt critical airspace operations. With the FAA recording over 100 drone sightings near U.S. airports each month, the agency is focusing education efforts on recreational users to reduce these incidents and help ensure the safety and reliability of the national airspace system.
Critical infrastructure sites also face the possibility of drones being used for malicious purposes, ranging from espionage to direct attacks. To take one example, Greenpeace flew a Superman-shaped drone  into a nuclear plant in 2018 to show its vulnerability. In such situations, radar sensors can play an important role in providing time-stamped and geo-located evidence for later prosecutions.
Drones can also be a powerful tool for espionage, being able to land unobserved in remote locations, even if there is human security on the ground. From that position, they can probe wireless networks for vulnerabilities. Many locations that have previously been considered ‘secure’, because the idea of a cheap drone with cyber capabilities was science fiction 10 years ago, are now no longer ironclad.
And it is not just remote sites that are vulnerable. Any building that houses computer systems, be that a regional bank or a datacenter hosting cloud-based resources, could potentially be vulnerable to UAV attacks. With many of the services the world relies on, from email to food delivery to internet banking, hosted in server farms, there is vulnerability to small UAVs landing on the roof to tap into networks and breach security systems, or unleashing software to steal trade secrets or simply attack and damage resources.
There are many possible motivations for attackers to target CI locations, from criminal enterprises aiming to steal intellectual property, to state-sponsored espionage and terrorism, to those who seek to cause chaos for its own sake. For such attackers, drones are particularly attractive. They are low-cost, easily and legally accessible, and easy to modify to use as weapons.
In some cases, drones are purpose-built for offensive operations. One illustrative example is the Kalashnikov KUB-UAV, a loitering munition unveiled in 2019. Roughly the size of a coffee table, the drone can fly at speeds up to 80 mph for 30 minutes while carrying a six-pound payload—typically explosives—up to 40 miles. Described by its manufacturer as offering “hidden launch, high accuracy, noiselessness, and ease of handling,” it reflects the increasing sophistication of drone-based weapon systems.
In addition to individual drones, swarming tactics—in which dozens or even hundreds of smaller drones operate in coordination—represent another growing area of concern. These swarms could overwhelm traditional defenses and sensors through sheer volume and maneuverability. A RAND Corporation report  identifies drone swarms as a “current and growing threat,” particularly due to their potential to be used against complex and distributed infrastructure.
What Constitutes a “False Alarm” and Why
In the context of drones operating in shared airspace—whether the pilot is clueless, careless, or criminal—the term “false alarm” is often misunderstood. Many assume that if a detected drone isn’t a direct threat, it must be a false alarm. But that’s not the case.
A robust perimeter intrusion detection system—especially one that covers both ground and air domains—is expected to detect and identify all drones in its vicinity. That includes hobbyist drones, commercial platforms, and potential threats. The goal isn’t to ignore non-threatening drones, but to accurately classify and assess them.
This is why advanced detection, tracking, and classification technology is essential. With the growing diversity of drone makes, models, sizes, and flight behaviors, the ability to distinguish between benign and potentially malicious drones has become increasingly complex—and increasingly critical. Effective classification enables informed decision-making, reduces unnecessary escalations, and ensures that security teams can focus their attention where it matters most.
Why False Alarms Create a Vulnerability for CI Security Teams
True false alarms create vulnerabilities for CI security teams, ranging from wasted man-hours to increased operational costs. The most serious of these problems is incident fatigue: if false alarms sound constantly, there is a risk that operators will begin to think, ‘Nothing to worry about, it’s just another false alarm.’ This can lead to delayed response times and, more critically, a gradual desensitization among operators. When genuine threats do arise, the urgency to act may be diminished—resulting in missed opportunities to intervene and exposing the organization to significant financial and reputational risk.
Rising Attention from Authorities Signals a New Era of Airspace Security
As the operational implications of drone activity become clearer, federal agencies and national security leaders are responding with increased urgency. The FAA, for example, has been testing drone detection systems at airports for several years, and is now expanding these efforts to off-airport locations in New Mexico, North Dakota, and Mississippi. These trials involve hundreds of drones—both commercial and recreational—operating in real-world scenarios, highlighting a shift toward scalable, field-tested solutions for airspace awareness.
This growing investment in detection capabilities reflects mounting concern at the highest levels of government. Former FBI Director Christopher Wray, speaking before a U.S. Senate panel, called the drone threat “steadily escalating,” noting it had intensified following the publicity surrounding the attempted assassination of Venezuelan President Maduro using explosive-laden drones.
Meanwhile, former CISA Assistant Director Brian Harrell offered a blunt assessment as early as 2019: “This is not an emerging threat. This was emerging five years ago. This is here. It is now… The overhead threat for attack is absolutely real today.”
For operators of critical infrastructure, these signals point toward a clear trajectory: drone detection is no longer optional. In the wake of high-profile airport incidents and increasing visibility into the potential for airspace misuse, regulatory expectations are rising, and CI sites should prepare for a future where drone detection and classification are standard components of perimeter security.
Is Your Site More Susceptible to False Alarms? 
While airports have received much of the public and regulatory attention around drone-related false alarms—largely due to high-profile incidents and the obvious risks associated with dense air traffic—they are far from the only critical infrastructure sites affected. In fact, what makes a site vulnerable to false alarms is not just traffic volume, it is proximity to “drone-like” airborne objects, such as birds, balloons, or weather phenomena.
Utilities, energy producers, oil and gas facilities, and nuclear plants have all reported concerns:
• Nuclear Facilities: The U.S. Nuclear Regulatory Commission has acknowledged the potential threats drones pose to nuclear power plants, emphasizing the need for vigilance and reporting of unauthorized drone sightings.
• Energy Infrastructure: In July 2020, a modified drone was discovered near a Pennsylvania power substation , equipped in a manner suggesting an intent to disrupt operations. This incident marked the first known attempt to target U.S. energy infrastructure using a drone.
• Oil and Gas Platforms: Norway’s Petroleum Safety Authority  has urged increased vigilance after unidentified drones were observed near offshore oil and gas installations, warning of potential risks to safety and operations.
These examples demonstrate that the threat—and the potential for false alarms—extends well beyond airports, especially as the skies become increasingly crowded with commercial, recreational, and potentially hostile drones. Addressing this challenge requires precision detection technologies capable of distinguishing real threats from harmless objects across a wide range of environments and operational contexts.
Addressing the Limitations of Conventional PIDS in the Drone Era
How can critical infrastructure sites respond to the growing challenge of drones? Traditional security systems—designed for ground-level threats—are increasingly outmatched in the face of airborne risks. Most rely on thermal sensors, RF detectors, and human patrols, which are not only vulnerable to false alarms but can also miss or misclassify fast-moving, low-signature aerial objects. Cameras, for instance, often struggle to distinguish between drones and similarly sized objects like birds or debris.
Addressing this modern threat landscape requires a layered approach, combining detection, tracking, and classification with high-performance technology layers that support future-state mitigation. In this framework, advanced drone detection radar systems play a central role—bringing the precision and persistence needed to identify, classify, and respond to airborne intrusions in real time. Unlike conventional radar designed for ground-based movement, modern airspace-focused radar systems are built for high transmit and receive density, allowing them to continuously and precisely interrogate the entire field of view—even in cluttered or obstructed environments.
This enhanced radar capability provides far more than just detection. By analyzing size, speed, altitude, and flight behavior in real time, and when combined with optical and classification capabilities, radar helps operators distinguish between benign activity and true threats—minimizing false alarms and enhancing situational awareness. Crucially, radar performs reliably day or night, in all weather conditions, and does not depend on visible signatures or RF emissions. This makes it especially effective against so-called ‘dark drones’—unmanned systems designed to evade detection by flying silently and without emitting RF signals. These drones are increasingly favored by criminal actors for their ability to bypass traditional surveillance tools such as cameras, RF sensors, and optical systems.
Modern radar systems can track multiple airborne targets at once and leverage micro-Doppler capabilities to detect subtle flight behaviors—such as drones flying in tight formation, loitering in place, or slowly approaching with potential payloads. Additionally, today’s advanced drone detection radar is more compact, affordable, and easily deployable than ever before. Facilities like airports, substations, and water treatment plants can install multiple radar units to create overlapping coverage zones, even in complex layouts.
Other technologies play a valuable supporting role alongside radar, depending on the specific needs and layout of a given site. Optical sensors, such as pan-tilt-zoom (PTZ) cameras, are especially effective complements to radar, providing visual confirmation and enabling continuous monitoring once a target is detected. Additional sensors—such as thermal imaging systems and RF detection technologies for identifying drones that emit radio signals—can further strengthen the detection stack. When RF signals are catalogued and analyzed, they can also add meaningful value by helping to triangulate or trace the location of a drone’s pilot, offering an additional layer of operational intelligence. Together, these tools provide layered coverage and enhance overall situational awareness.
To move beyond the limitations of conventional perimeter systems, critical infrastructure sites must adopt purpose-built technologies for today’s airspace threats. Advanced radar designed specifically for drone detection is foundational to this shift, offering the precision, speed, and data richness required to manage a modern threat environment.
This level of precision becomes even more important in jurisdictions where mitigation is legal, as safely intercepting or neutralizing a drone demands real-time data on its size, velocity, flight path, and behavior. Only high-performance radar offers the responsiveness and fidelity necessary to inform proportionate, accurate, and legally defensible mitigation tactics.
Reducing False Alarms is Foundational for Modern Critical Infrastructure Protection and Resilience
For critical infrastructure security operators, the urgency to address false alarms—across personnel, systems, and overall security strategy—has never been greater. Every false positive consumes time, depletes resources, and reduces the impact of active site security efforts. It’s no longer enough to ask whether your PIDS is functioning—it’s time to ask whether it’s keeping up with the reality of today’s threats.
The threat has taken to the skies. Drones have rapidly evolved from hobbyist gadgets into instruments of espionage, disruption, and potential destruction. Site operators, policymakers, and security stakeholders must adapt to this new operational environment—one that demands new rules, new technologies, and new urgency.
A layered perimeter intrusion detection system, anchored with advanced radar that detects, tracks and classifies drones with precision delivers the situational awareness required to cut through the noise, drastically reduce false alarms, and free operators to focus on real threats. In doing so, they not only enhance site security, but also help protect the essential systems our modern world depends on. The path forward is clear: to defend what matters most, we must rise above outdated approaches—and start protecting the airspace as vigorously as we do the ground.
By Curtis Walters, Echodyne VP Sales, Government and Critical Infrastructure

UK arrest following aerospace cyber incident

A man has been arrested in the UK by the National Crime Agency as part of an investigation into a cyber incident impacting Collins Aerospace.
The incident, which was reported on 19 September, affected flights at Heathrow and other European airports over the weekend.
NCA officers, supported by the South East ROCU, arrested a man in his forties in West Sussex yesterday evening on suspicion of Computer Misuse Act offences. He has been released on conditional bail.
Deputy Director Paul Foster, head of the NCA’s National Cyber Crime Unit, said:
“Although this arrest is a positive step, the investigation into this incident is in its early stages and remains ongoing.”
“Cybercrime is a persistent global threat that continues to cause significant disruption to the UK. Alongside our partners here and overseas, the NCA is committed to reducing that threat in order to protect the British public.”

Unidentified Drone Incursions Temporarily Shut Down Copenhagen and Oslo Airports

Authorities in Denmark and Norway are investigating a series of unauthorized drone sightings that forced the temporary closure of airspace over two major international airports—Copenhagen's Kastrup Airport and Oslo's Gardermoen Airport, and are being treated as serious threats to national and regional security.
In Copenhagen, multiple drones were detected near the airport perimeter, leading to a near four-hour shutdown that disrupted over 50 flights and affected approximately 20,000 passengers. Danish police say the drones demonstrated flight behavior consistent with advanced operation, and officials have described the incursion as one of the most significant threats to Denmark’s critical infrastructure in recent memory.
Shortly after the Copenhagen incident, Oslo’s main airport reported similar drone activity, prompting Norwegian authorities to temporarily close airspace. Though the disruption lasted just under three hours, it led to delays and diversions and raised concerns about a coordinated effort.
While Danish and Norwegian officials are cooperating closely, no definitive link between the two incidents has been established. Authorities in both countries are analyzing radar data, visual reports, and drone signatures as part of a joint investigation. Danish leadership has confirmed the threat level to critical infrastructure remains elevated.
Security experts across Europe have expressed growing alarm over the vulnerability of critical national infrastructure and entities to drone-related threats. Discussions are now underway among Nordic and EU partners regarding the implementation of a regional drone defense strategy.

CISA Releases Advisory on Lessons Learned from an Incident Response Engagement

CISA released a cybersecurity advisory detailing lessons learned from an incident response engagement following the detection of potential malicious activity identified through security alerts generated by the agency’s endpoint detection and response tool.
This advisory, CISA Shares Lessons Learned from an Incident Response Engagement, highlights takeaways that illuminate the urgent need for timely patching, comprehensive incident response planning, and proactive threat monitoring to mitigate risks from similar vulnerabilities.
The advisory also outlines the tactics, techniques, and procedures (TTPs) employed by cyber threat actors, including exploitation of GeoServer Vulnerability CVE-2024-36401 for initial access. By understanding these TTPs, organizations can enhance their defenses against similar threats.
CISA recommends organizations take the following actions:
- Prioritize Patch Management: Expedite patching of critical vulnerabilities, particularly those listed in CISA’s Known Exploited Vulnerabilities catalog, with a focus on public-facing systems.
- Strengthen Incident Response Plans: Regularly update, test, and maintain incident response plans, ensuring they include procedures for engaging third-party responders and deploying security tools without delay.
- Enhance Threat Monitoring: Implement centralized, out-of-band logging and ensure security operations centers continuously monitor and investigate abnormal network activity to detect and respond to malicious activity effectively.
CISA urges organizations to apply these lessons learned to bolster their security posture, improve preparedness, and reduce the risk of future compromises. For additional details, review the full cybersecurity advisory.

Building Ukraine’s Shield: The Bold New Effort to Train Critical Infrastructure Security Professionals

In November 2021, a landmark law on Critical Infrastructure Protection (CIP) was signed by the President of Ukraine—setting in motion a national effort to secure the lifelines of the country’s economy, defense, and daily life. Two years later, in September 2023, the Cabinet of Ministers approved Ukraine’s National Plan for the Protection, Security, and Resilience of Critical Infrastructure, a document that not only laid out an ambitious strategy but also revealed a major vulnerability: a critical shortage of qualified professionals.

The question soon became unavoidable—how and where can Ukraine train the specialists essential to protecting its most vital systems? The National Plan mandated a full feasibility study to explore this issue and develop recommendations for building a sustainable educational and training ecosystem for CIP professionals.

This comprehensive study was the first of its kind in Ukraine and worldwide and took a global approach. It examined not only Ukraine’s own experience but also incorporated lessons and best practices from the European Union, North America, and international organizations such as the United Nations, NATO, OSCE and the World Bank. The study team interviewed over 50 subject matter experts from Ukraine, the EU, and the United States, representing government agencies, industry sectors, and academic institutions.

The Feasibility Study to Affect the Development of Critical Infrastructure Security and Resilience (CISR) Education and Training System in Ukraine was carried out by Ukrainian, Italian, and American experts in critical infrastructure protection, with financial support from the U.S. Department of State. It was also supported by the Directorate of Professional Pre-Higher and Higher Education of the Ministry of Education and Science of Ukraine, the Critical Infrastructure Security Service of the National Security and Defense Council (NSDC), and the Department of Critical Infrastructure Protection of the State Service of Special Communications and Information Protection (SSSCIP).

The study’s main conclusion was that the development of an education and training system for critical infrastructure protection in Ukraine is both possible and necessary. Such a system is needed to prepare leaders, managers, specialists, and trained personnel capable of carrying out a wide range of tasks in the field of CI protection — all in line with Ukrainian legislation and national security goals.

It worth to mention that the results of this Study was officially presented in Lecce, Italy, during the international workshop on “Development of University Programs on Critical Infrastructure Security and Resilience” in March 2024. The event served as a vital platform for Ukrainian participants and international experts to exchange knowledge, share best practices, and explore innovative approaches in the field of Chemical Critical Infrastructure Security and Resilience (CISR) education. The workshop highlighted the importance of academic collaboration in strengthening the resilience of critical sectors and advancing specialized university programs across borders.

Although the study was conducted in 2024, it has already led to several significant outcomes:

1. On June 27, 2024, the Center for Critical Infrastructure Security and Resilience was established at the Department of Civil and Industrial Safety named after Hero of Ukraine O.S. Chub, within the Faculty of Environmental Safety, Engineering, and Technology at Kyiv Aviation University. This center attracted the attention of the Ministry of Infrastructure and Transportation of Ukraine, which has since accepted university students studying CIP for internships at transportation-related CI facilities in Kyiv.

2. The National Institute for Strategic Studies established two working groups focused on developing educational programs in the field of CIP. As a result, a proposal is being prepared for submission to the Ministry of Education of Ukraine to formally introduce new CIP curricula and programs in Ukrainian universities.

3. Compared to the Research on CIP education conducted in 2021, there is clear progress in the development of university-level programs both at the national level (Kyiv) and in several regions (Lviv, Kharkiv, and Cherkasy). This development is supported by the National Qualifications Agency of Ukraine and coordinated by the CIP offices of the NSDC and SSSCIP.

4. Based on the findings of the study, four new professions related to critical infrastructure protection were added to the National Occupational Classifier of Ukraine, including:

* Risk, Threat, and Vulnerability Analyst for Critical Infrastructure – identifies potential threats and vulnerabilities, assesses risks, and develops mitigation recommendations;

*Critical Infrastructure Protection Expert – provides expert assessments of protection methods and ensures resilience against threats;

*Specialist in Critical Infrastructure Protection and Resilience – directly implements protection measures and ensures operational continuity in crisis conditions;

*Head (or other manager) of a Department/Unit for Critical Infrastructure Protection – organizes, coordinates, and oversees security measures, conducts risk assessments, interacts with law enforcement and specialized agencies, and implements policies and standards to ensure CI resilience.
Currently, an interagency working group in Ukraine is developing professional standards for these roles. Whether this initiative will be successful will depend on the outcomes of pilot projects and the real-world performance of certified professionals at critical infrastructure enterprises. It remains to be seen whether additional, more in-depth research and business analysis of the functional responsibilities of CI professionals at enterprises across Ukraine’s 24 critical infrastructure sectors (as defined by a Cabinet of Ministries of Ukraine’s resolution) will be necessary. Based on such analysis, there may be a need to adjust or refine the newly introduced CIP professions, taking into account the 2008 EU Directive and the experience of the 5 CIP SISTERS: United States,Canada, the United Kingdom of the Great Britain, New Zeland and Australia.

In conclusion, the issue of training critical infrastructure protection professionals, especially for sector-specific enterprises, still requires deeper research and strategic planning. Only by thoroughly analyzing the operational needs and critical functions of CI enterprises can Ukraine accurately define the roles and responsibilities of CIP specialists and reflect them in professional standards, paving the way for the development of a qualified and mission-ready workforce.

By Vladlen Basystyi, Technical Advisor at CRDF Global, specializing in cybersecurity and critical infrastructure protection

Commission Communication to strengthen the resilience of critical entities across the EU adopted

On 11 September 2025, a Commission Communication to strengthen the resilience of critical entities across the EU was adopted. It provides non-binding guidance to EU countries to identify their critical entities and a risk assessment reporting template.

Directive (EU) 2022/2557 on the resilience of critical entities1 (‘the Directive’) aims to ensure that services essential for the maintenance of vital societal functions or economic activities are provided in an unobstructed manner in the internal market. The Directive enhances the resilience of the critical entities providing such services and creates an overarching framework of resilience of critical entities in respect of all hazards (natural and man-made, accidental or intentional).
To achieve a high level of resilience, Member States have obligations under the Directive. The Commission was mandated to develop recommendations, non-binding guidelines and a voluntary common reporting template to support them in fulfilling some of these obligations. Specifically, this Communication gives effect to Article 5(5) of the Directive regarding the development of a template for the provision of certain information to the Commission, to Article 6(6) of the Directive regarding the development of recommendations and guidelines to support Member States in identifying critical entities, and to Article 7(3) of the Directive regarding the adoption of guidelines to facilitate the application of the criteria for determining the significance of a disruptive effect, taking into account the information that Member States must submit in accordance with Article 7(2) of the Directive.
Before the adoption of this Communication, in accordance with the aforementioned provisions, Member States were consulted in a workshop that took place on 3-4 October 2024 and the Critical Entities Resilience Group (CERG) was consulted on 12 February 2025. Further bilateral consultations of CERG delegates took place in writing in March 2025 and an updated version was shared with the CERG on 7 April 2025.
The present Communication is not legally binding and does not affect the interpretation of EU law by the Court of Justice of the European Union.
The voluntary common reporting template for Member States to provide certain information related to the risk assessment to the Commission, as provided for in Article 5(5) of the Directive, is set out in the Annex.
Although this reporting template is voluntary in nature, Member States are encouraged to use it when providing information pursuant to Article 5(4) of the Directive.
Further details can be found in the 'Commission Guidelines and reporting template developed pursuant to Articles 5(5), 6(6) and 7(3) of Directive (EU) 2022/2557 on the resilience of critical entities'.
1 4 5 6 7 8 69