General Atomics

Building steps towards CNI resilience

Peter Lenk, Technical Lead at Goldilock, sets out the key steps for building a timeline of resilience for the protection of Critical National Infrastructure (CNI).



Image courtesy Goldilock

The threat from cyber-attack landscape facing Critical National Infrastructure (CNI) is evolving at an alarming pace. From utilities to healthcare providers and transport networks, the infrastructure crucial to the smooth running of countries makes an alluring target for state actors and cybercriminals looking to cause chaos and even harm.

Take last summer’s attack on London hospitals. One breach resulted in the postponement of 1,255 planned operations and 3,396 appointments. The reality is that such incidents are no longer contained, as warnings from the UK’s National Cyber Security Centre (NCSC) confirmed that the ‘scale, pace and complexity’ of threats to CNI will only continue to rise. With national resilience in jeopardy, organisations need to build a security infrastructure that considers both response and proactive measures to ensure future security and resilience.

The current state of CNI security

In recent years, experts across the globe have called for more explicit legislation to drive strong cyber resilience measures within CNI organisations. In Europe, for example, the Directive (EU) 2022/2555 of the European Parliament and of the Council of 14th December 2022 was set out to ensure a high common level of cybersecurity was agreed on. Similarly, the Strengthening American Cybersecurity Act of 2022 addressed cybersecurity threats against US critical infrastructure and the federal government.

However, while legislation is a positive step forward, it is clear that CNI organisations require a complete overhaul of their security measures. With 93% of CNI organisations citing an increase in cyberattacks, the traditional and largely outdated measures many organisations rely on are no match for today’s sophisticated cyberattacks.

One of the primary hurdles CNI organisations face is the complexity caused by the existence of OT and IT systems. As a result, entirely different defences are required to ensure maximum protection. Cyber-physical systems, such as power grids and water supply networks, require expert expertise to protect, and the stakes are extremely high. Should bad actors successfully infiltrate these systems, the results could be property damage, physical harm, or even death. So, a framework for greater cyber resilience is crucial.

The three steps towards CNI resilience
To protect systems against increasingly frequent and sophisticated attacks, CNI organisations should adopt a ‘timeline of resilience’ framework to protect all aspects of their organisation. Crucially, this framework focuses on the defence function that typical cybersecurity postures prioritise and balances investment in prevention and recovery capabilities.

The framework can be broken down into three steps: preparation, response, and recovery. Let’s take a look at how organisations can implement them successfully.

Step one: prepare your cyber defences
Preparation should be the first focus for a timeline of resilience framework. Organisations should focus on strengthening their defences by adopting advanced and holistic cyber measures.

This should involve a mix of traditional cyber techniques that many organisations may already have, including encryption and firewalls, alongside physical network segmentation. This allows organisations to segment their networks and isolate and hide critical assets or sensitive data to reduce the attack surface in the event of a breach. Organisations can also choose to keep certain parts of their network offline until they are needed, slowing the attackers’ movements and limiting their reach. After all, anything that is connected to the internet is at risk of attack.

Step two: incident response
The second step in implementing a timeline of resilience framework is the creation of an effective response plan. Often, organisations prioritise only the preparation phase, dedicating resources to building defences that keep bad actors out. But what happens when a breach does occur? Organisations need to approach their cybersecurity with the mindset that a breach will inevitably happen, no matter the safeguards in place. Part of this should be setting out an incident response plan that ensures breaches are quickly detected and arrested to reduce damage.

Organisations should adopt monitoring tools and threat-detection systems that identify breaches in real-time. Part of this can be an effective communication strategy to notify key stakeholders including IT, legal, and management teams, as well as any external partners and regulatory authorities.

Reactive network segmentation plays a vital role in impeding attack propagation and isolating compromised assets and data. Physical network segmentation can occur remotely and without internet access, ensuring leaders have complete control over networks and devices.

Step three: recovery and restoration of services
Perhaps the most overlooked aspect of cyber resilience is a recovery phrase. This step is crucial to reduce the short-term impact of an attack, as well as potential long-term damage.

There are several steps organisations should take to tackle the fall-out of an attack and ensure systems are back up and running with minimal delay. These steps should include data restoration from backups, the reconfiguration of security protocols, and patching breached systems.

Unlike in a typical IT breach, attacks on CNI organisations can directly impact public safety and security, making this even more essential. Trouble shooting and efficient recovery can also be helped along with the use of physical network segmentation. Technology like next-generation physical air-gapping can ensure previously isolated, known safe, network segments are reconnected as soon as possible allowing for the restoration of critical services.

Finally, organisations should factor post-incident analysis into this phase. Organisations can understand how bad actors were able to break through cyber defences and carry out an attack by analysing forensic data and incident logs. These insights can be fed back to the teams responsible for the preparation and response phases of the framework to improve future defence strategies. They can also be shared more widely to help others protect their assets.

A resilient future for CNI
Given the critical role of CNI in national infrastructure, organisations remain prime targets for cyberattacks threatening public safety and national security.

The evolving threat landscape necessitates a proactive approach to cyber resilience. By strategically implementing physical segmentation and other advanced security measures across the three-phase timeline of resilience, CNI organisations can significantly bolster their defences.

This comprehensive approach will enable them to withstand and recover from cyber incidents, ensuring the continued delivery of services in the face of evolving threats.

By prioritising cyber resilience and investing in innovative solutions, CNI leaders can ensure their organisations safeguard their operations and maintain critical services, ensuring the safety and security of nations.

Related

UK Government opens scheme to slash manufacturers’ electricity bills
Jonathan Reynolds
UK Government opens scheme to slash manufacturers’ electricity bills
Applications for the British Industrial Competitiveness Scheme (BICS) are now open to over 10,000 manufacturing businesses.
Aerospace Defence

2 Oct 2026

UK Government proposes airline fee reforms and tougher measures on disruptive passengers
Aircraft landing at Heathrow Airport
UK Government proposes airline fee reforms and tougher measures on disruptive passengers
New aviation proposals would end charges for seating young children with accompanying adults, restrict fees for simple booking errors and strengthen airline cooperation on repeat disruptive passengers.
Aerospace

2 Oct 2026

Doncaster Sheffield Airport takes another step towards reopening with new firefighting fleet
Doncaster Sheffield Airport fire appliance
Doncaster Sheffield Airport takes another step towards reopening with new firefighting fleet
Doncaster Sheffield Airport has ordered three specialist aviation firefighting vehicles as preparations continue for its planned reopening.
UK Government opens scheme to slash manufacturers’ electricity bills
Jonathan Reynolds
UK Government opens scheme to slash manufacturers’ electricity bills
Applications for the British Industrial Competitiveness Scheme (BICS) are now open to over 10,000 manufacturing businesses.
Aerospace Defence

2 Oct 2026

Cohort appoints Richard Mills as Group Strategy Director
Richard Mills
Cohort appoints Richard Mills as Group Strategy Director
Former Boeing executive Richard Mills will lead the growth strategy of Cohort and its seven subsidiaries which specialise in defence and security technology across the UK, Germany, Portugal and Australia.
Seven teams advance in £2bn race to replace British Army Land Rovers
Team LionStrike LMV contenders
Seven teams advance in £2bn race to replace British Army Land Rovers
Seven teams have advanced in the UK Ministry of Defence’s £2 billion Light Mobility Vehicle (LMV) competition, to replace ageing Land Rover and Pinzgauer fleets.
Defence

2 Oct 2026

SatVu’s HotSat-3 launches on SpaceX mission to double thermal satellite capacity
SAtVu HotSat
SatVu’s HotSat-3 launches on SpaceX mission to double thermal satellite capacity
SatVu launches HotSat-3 to double thermal satellite capacity Standfirst SatVu has launched HotSat-3 aboard SpaceX’s Transporter-18 rideshare mission, adding capacity for high-resolution thermal intelligence from space. Publication-ready version SatVu has launched HotSat-3, its latest mid-wave infrared sensing satellite, aboard SpaceX’s Transporter-18 rideshare mission from Vandenberg Space Force Base in California. The British thermal intelligence company said HotSat-3 will double its constellation collection capacity once commissioning is complete. The satellite will operate alongside HotSat-2, enabling SatVu to collect high-resolution thermal imagery day and night, with the ability to revisit any location on Earth every 24 hours. HotSat-3 is SatVu’s third 3.5m resolution mid-wave infrared satellite and forms part of the company’s move towards more persistent thermal intelligence from space. SatVu expands thermal intelligence from space The additional capacity will allow customers to observe the same strategic sites more frequently, building time series data that can show whether an asset is active, how intensely it is operating and how that activity is changing over time. SatVu’s thermal imagery can detect heat signatures from assets and infrastructure including vehicle and vessel engines, generators, gas flares, petrochemical facilities, rail cars, data centres, maritime vessel wakes, power plant cooling effluent plumes and industrial heat sources. The company said this capability is relevant across defence and intelligence, economic intelligence and climate resilience markets. For defence and intelligence users, high-resolution thermal data can provide an independent layer of information for assessing activity at strategic sites and critical infrastructure, including at night or in locations where ground information may be limited or delayed. HotSat-3 to support daily site monitoring Anthony Baker, chief executive and co-founder of SatVu, said: “HotSat-3 is where the constellation optimises what we can deliver for customers. “With two operational satellites, we will have double the capacity: customers can collect twice as much imagery, monitor twice as many sites, or return to the same site more often.” He said repeated observation would allow users to move beyond single snapshots and understand how activity is changing. “Return to a site, day and night, and you can read its operational state by what is hot and what is not, what is on and what is off,” Baker said. “That is the operational heartbeat we are building SatVu to measure: status, intensity and change across the assets and infrastructure that matter to governments, markets and industry.” HotSat-3 will now enter commissioning before the start of commercial operations. SatVu said launches are already secured for HotSat-4 and HotSat-5, supporting further increases in capacity and revisit frequency as the constellation grows.
Member News Space

2 Oct 2026

Orbex’s UK manufacturing assets and IP acquired by Omnidea
Omnidea engineering testing platform
Orbex’s UK manufacturing assets and IP acquired by Omnidea
Portugal's Omnidea has purchased the manufacturing assets and intellectual property (IP) of British rocket manufacturer Orbex UK, which ceased operations in February this year and went into administration.
Member News Space

2 Oct 2026

Filtronic wins SpaceX contract to support Starlink network
ground station
Filtronic wins SpaceX contract to support Starlink network
Sedgefield headquartered Filtronic has won a $68.1 million (£51.52m) order from SpaceX to support its Starlink network, highlighting the growing global demand for UK-developed space technology.
Member News Space

1 Oct 2026

Cohort appoints Richard Mills as Group Strategy Director
Richard Mills
Cohort appoints Richard Mills as Group Strategy Director
Former Boeing executive Richard Mills will lead the growth strategy of Cohort and its seven subsidiaries which specialise in defence and security technology across the UK, Germany, Portugal and Australia.
BAE Systems proves complete counter-drone kill chain in Scotland trials
Container and Sensor
BAE Systems proves complete counter-drone kill chain in Scotland trials
BAE Systems has demonstrated its complete BATS counter-drone chain in Scotland, integrating sensors, electronic warfare and a gun system.
Security

1 Oct 2026

Doncaster Sheffield Airport takes another step towards reopening with new firefighting fleet
Doncaster Sheffield Airport fire appliance
Doncaster Sheffield Airport takes another step towards reopening with new firefighting fleet
Doncaster Sheffield Airport has ordered three specialist aviation firefighting vehicles as preparations continue for its planned reopening.