Menu
Wed, 19 August 2026

Beyond prevention: cyber resilience in critical infrastructure

Credit: Unsplash

Marcus Samphire, Market Director – Security and Critical Infrastructure

Marcus Samphire, Market Director – Security and Critical Infrastructure | AtkinsRéalis

5 min read Partner content

A cyber attack doesn't have to succeed to cause disruption. As infrastructure becomes more connected, resilience is increasingly defined by how organisations respond, recover and continue operating under pressure

The conversation around cyber security in critical infrastructure often focuses on preventing attacks, and for infrastructure operators responsible for energy, water, transport and other essential services, that remains an important priority.

However, the challenge has broadened significantly, as the growing convergence of information technology (IT) and operational technology (OT) reshapes what cyber risk means in practice. Operators are connecting smarter digital systems with ageing infrastructure that was never designed for today's threat landscape, with the result that as well as greater efficiency, better visibility and improved performance, new vulnerabilities and new forms of risk exposure are entering the picture.

In this changing environment, cyber resilience is increasingly becoming the practical application of cyber security: for operators of critical national infrastructure, the question is no longer only whether an attack can be prevented, but whether essential services can continue to operate safely if systems are compromised, suppliers are disrupted or key operational technologies must be isolated. The ability to maintain services, recover quickly and make effective decisions under pressure has become central.

The growing importance of resilience reflects the reality of the threat landscape. The UK's National Cyber Security Centre (NCSC) handled 204 nationally significant cyber incidents in the year to August 2025, compared with 89 the previous year. Of those, 18 were categorised as highly significant incidents, representing a 50% increase and the third consecutive annual rise.

Resilience as a system challenge

Historically, organisations could focus primarily on protecting their own assets and systems; today, risks increasingly emerge at the points where systems, organisations and supply chains connect.

Critical infrastructure can also no longer be viewed as a collection of discrete assets protected behind a perimeter. It increasingly operates as a connected system made up of operational technology, field devices, cloud platforms, remote access capabilities, data flows and complex supplier ecosystems. Across sectors including energy, water, transport, aviation and telecoms, resilience depends not just on securing individual assets but on understanding how assets, systems and organisations interact.

This is particularly important in the context of critical national infrastructure. Traditional measures of resilience - regulation, standards and guidance - provide a critical baseline and help organisations to establish priorities, improve consistency and strengthen security. The direction of travel is also becoming clearer from a policy perspective. The UK's Cyber Security and Resilience Bill is expected to strengthen requirements on operators of essential services and certain critical suppliers, extending expectations around incident reporting, risk management and resilience assurance.

However, compliance alone cannot keep pace with a threat landscape that is evolving so rapidly. In an environment shaped by geopolitical tension, supply chain dependency, rapidly evolving digital tools and increasingly capable hostile actors, resilience can no longer be judged solely by whether an organisation has satisfied a compliance requirement. Instead, infrastructure operators must truly understand and continually monitor the threat landscape.

An example is the Volt Typhoon threat actor that compromised multiple US critical infrastructure organisations across sectors including communications, energy, transportation and water. Investigators found evidence that the group had maintained access within some victim environments for as long as five years. The lesson for infrastructure operators is that cyber threats are not always singular events. Adversaries may establish persistent footholds long before disruption occurs, reinforcing the need for continuous monitoring, threat hunting, detection and a clear understanding of how services will continue operating, how decisions will be made under pressure and how recovery will be managed.

Organisations that may see themselves primarily as utilities providers or infrastructure operators are increasingly part of a broader system that supports economic activity, public services and national capability, while governments and organisations are only as strong as the cyber resilience of their suppliers.

Leaders in such organisations can build operational resilience before a cyber incident occurs, by understanding how critical services depend on technology, suppliers, people, physical assets and data, and where failures could create operational or safety consequences. They should be asking challenging questions, both to themselves and their supply chains. What happens if a threat actor gains access to our network? What if a key supplier is compromised? What if we can no longer trust the integrity of our operational data? How would we continue operating in a degraded state for days or weeks while recovery takes place?

Asking the right questions

As organisations increasingly depend on technology partners and software providers to deliver their services, they need to place a greater emphasis on cyber requirements during supplier procurement, assurance and contract management, rather than treating cyber security as a technical issue to be addressed after delivery. This focus on third-party assurance is likely to become even more important as the Cyber Security and Resilience Bill broadens scrutiny of critical suppliers and recognises that national resilience depends not only on operators themselves, but also on the organisations and technologies they rely upon.

Transparency and visibility are key here – many organisations have a strong understanding of their own estate’s strengths and weaknesses but less visibility of the dependencies that sit several tiers down their supply chain. The question they should be asking themselves is no longer "are my systems secure?" but "do I understand all of the systems and suppliers my operations depend on?".

Investment in technology and compliance remains essential, but clearly, resilience is equally dependent on governance, decision-making, operational preparedness and organisational culture. The strongest organisations are building resilience into every aspect of their operations and their supply chains, with a focus on understanding their dependencies, continually testing their preparedness, strengthening detection and response capabilities, and developing confidence in their ability to recover from disruption.

As our critical infrastructure and the technologies it depends on continues to evolve, behavioural and supply chain resilience will provide the foundation for organisations to adapt and modernise with confidence, while maintaining the trust, reliability and continuity that society expects.

Categories

Technology