From: PIR Center in collaboration with the Centre russe d’etudes politiques, Genève
Executive Summary
Cybersecurity challenges have become one of the key concerns for the operators across all critical infrastructure (CI) sectors. Rapid progress in offensive cyber capabilities and upsurge of the number of CI cybersecurity incidents demand urgent reaction from operators, regulators and international community. However, all these stakeholders have to face global trends that obviously increase cybersecurity vulnerabilities of CI objects. Those include extensive and ongoing digitalization of PCS and ICS at critical facilities; broad connectivity of CI corporate office and even industrial networks to the Internet, with the advent of IoT and IoE. Internet connectivity goes hand in hand with “mobile revolution”, bringing to CI sectors BYOD and “CI in your pocket” concepts. Finally, extreme complexity of transcontinental ICS, SCADA software and field devices supply chains has become a common issue for most CI sectors.
***
Concerning the regulatory landscape, in most states CNF cybersecurity is just emerging as a separate regulatory framework on a nation-wide level. Key issues include ambiguity in division of regulatory agenda between governmental agencies and gaps and overlaps in the regulators’ functions. In many developing countries, these functions are scattered across many regulators with lack of contact between each other. Next issue is lack of a single sector-specific regulator that often leads to weak feedback from private sector stakeholders. Also, the rigid, though highly elaborated nuclear security paradigm sometimes acts as a barrier to elaboration of a hybrid regulatory framework addressing specific issues of the CNF sector. This is often accompanied with the lack of integration of international guidelines, recommendations and best practices into national CNF cybersecurity regulations.
Leave a Reply