Hosted by the IoCR
14th December 2023
Institute of Directors, London
The IoCR and A Jolly Consulting hosted and sponsored a “Critical National Infrastructure: The challenges of securing Essential Services” event at the Institute of Directors on the 14th of December 2023 bringing together an expert panel, moderated by Wayne Harrop, within the Finance, Communications, Energy, Water, Transport Sectors to explore the current trends and future needs associated with safeguarding Critical National Infrastructure.
Summary of Panel discussion.
This IoCR panel event galvanised interest in cyber physical risks and the panellists agreed a cross functional approach to the cyber threat landscape was essential.
This was apparent from Advanced Persistent Threats (APT Groups), the deteriorating geopolitical challenges and the aggressive engagement of cyber warfare from state actors and affiliated hacking groups. The traditional human factors were considered as still highly relevant, especially with the need for adequate training, education, and awareness across sectors.
Humans were seen as the first line and last line of defence and a “human firewall when trained well. It was noted that there is generally a shortage of cyber professionals with solid IT/OT experience across the essential service providers. Panellists noted the rise of AI as a significant risk tied to a 2025 potential upsurge in generative AI power and evolution.
The remote nature of assets such as international shipping means that cyber spans across international borders and attacks were not always tied to fixed assets, or jurisdictional controls. Key services such as energy were pivotal to driving the smooth delivery of other critical services and without basic inputs other CNI/CII providers might see a domino chain of cascading failure risks.
There was focus on the UK Cyber Assessment Framework and the role of standards applicable to resilient infrastructure.
The following experts formed part the Panel:
30 Guests attended, all experts and responsible for directly managing, overseeing, and supporting the resilient cyber-physical aspects of UK Critical National Infrastructure, regulators, policy makers, parliamentarians, infrastructure governance professionals, and industry thought leaders operating in the CNI space.
The National Cyber Security Centre (NCSC) has signalled that the threat to the nation’s most critical infrastructure is ‘enduring and significant’, amid a rise of state-aligned groups, an increase in aggressive cyber activity, and ongoing geopolitical challenges. The NCSC recorded 2005 cyber related requests for support, up by 64% from last year’s 1226. There were 62 Nationally significant cyber events (compared to 63 last year). Four attacks were among the most sustained, severe, and threatening to the UK.
Operators of Essential Services (OES) must increase the capabilities to manage a serious cyber-attack. Regulatory controls such as NIS(R), UK and NIS 2 European Union, alongside CER Directives are now required across Europe. In the UK the Cyber Assessment Framework (CAF) forms a significant focus for measuring cyber resilience in the UK across 14 elements and tied to Indicators of Good Practice (IGPs).
European Critical Infrastructure (ECI) share common vulnerabilities, challenges and overlapping interdependencies through exposure of Operational Technology and Information Technology mergers, meanwhile generative AI, and insider threats, alongside supply chain risks are expanding threat vectors
extending across all 13 ECI areas, spanning: Energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure services, public administration, space, and production, processing, and distribution of food.
We had the pleasure of Liz Varga, Head of UCL’s Infrastructure Systems Institute, updating all Guests on the work underway to develop the Resilience Infrastructure standard (ISO 22372) at International Standards Organisation levels, in addition CYBOK 1.0 (Cyber Body of Knowledge) offers some useful resources
Subscribe now to keep reading and get access to the full archive.