Global Risks
Critical infrastructure
Cyber & Critical Infrastructure
Also known as cyberattacks / cybersecurity threats
Cyber and critical infrastructure is the modern danger that the grids, hospitals, and banks we depend on now run on software, so a single well-aimed hack can freeze the machinery of daily life. It connects to Civil and Structural Engineering in Technology, because the physical systems being defended, like dams and power stations, must be built and protected as one with their digital controls. It links to Immunology in Health, since a network defends itself much like a body fights infection, spotting intruders and racing to contain them. It also ties to Probability, Risk and Uncertainty in Mathematics, because defenders must weigh rare but catastrophic attacks, and to Biodiversity Loss in Environment, because a monoculture, whether crops or identical software, means one weakness can wipe out everything at once.
Key people
- Manuel AtugGerman computer scientist and computer security specialist
Timeline
- 1996Has had a wide-reaching critical infrastructure protection program in place since 1996.
- 2006Member states are obliged to adopt the 2006 directive into their national statutes.
- 2013The 2013 version of the NIPP has faced criticism for lacking viable risk measures.
- 2020In June 2020, West Virginia passed the Critical Infrastructure Protection Act, which created felony penalties for protests against oil and gas facilities.
Read
- Critical InfrastructureRobert Radvanovsky · 2009Book
- Critical Infrastructure Protection in Homeland SecurityTed G. Lewis · 2006Book
- Critical Infrastructure Protection, Risk Management, and ResilienceKelley A. Pesch-Cronin · 2016Book
- Cyber SecurityMartti Lehto · 2015Book
Listen
- Cyber Focus: Cybersecurity, National Security, and Critical InfrastructureFrank Cilluffo / McCrary InstitutePodcast
- Renewable Energy SmartPodSean McMahonPodcast
- Critical Infrastructure Security CentreAustralian Department of Home Affairs Critical Infrastructure Security Centre (CISC)Podcast
- In Australia’s National Interest - Security of Critical InfrastructurePentagram AdvisoryPodcast
Voices to follow
- Manuel Atug@HonkHase · XGerman computer scientist and computer security specialist
- Stephanie Carvin@stephaniecarvin · XCanadian legal scholar
By the numbers
- 4.7CO₂ per person (t) — global, 2024 (World Bank)
- 31.1Forest area (% land) — global, 2023 (World Bank)
Debates
- Should critical infrastructure be primarily publicly or privately owned?One view: Public ownership ensures services prioritize public good and equity over profit, allowing for better long-term planning and investment. · Another: Private ownership often brings greater efficiency, innovation, and access to capital, leading to more responsive and technologically advanced systems.Open question
- Is it more important to focus on making critical infrastructure highly efficient or highly resilient?One view: Prioritizing efficiency reduces costs and optimizes resource use, delivering services more affordably and quickly under normal conditions. · Another: Prioritizing resilience builds in redundancy and robustness, ensuring services continue even during disruptions like natural disasters or cyberattacks.Open question
- Who bears the primary responsibility for protecting critical infrastructure from cyber threats?One view: Governments should lead protection efforts due to national security implications, resource access, and the ability to set universal standards. · Another: Private sector operators are best positioned to secure their own systems, possessing specific technical expertise and operational control.Open question
Glossary
- Critical InfrastructureSystems and assets essential for a society's functioning, whose disruption would have a severe impact.
- ResilienceThe ability of systems to withstand, adapt to, and recover from disruptions.
- CybersecurityMeasures taken to protect computer systems and networks from digital attacks and unauthorized access.
- InterdependenceThe reliance of one critical infrastructure sector on another for its operation, creating cascading risks.
- Supply ChainThe network of organizations, people, activities, information, and resources involved in moving a product or service from supplier to customer.
- SCADASupervisory Control and Data Acquisition, a control system architecture used for industrial processes like power grids and water treatment.
Careers
Roles this can lead toward
Student research
Published policy papers by One Young India delegates — every delegate leaves published under their own name.
- A Critical Look at India's Digital DivideShreeyans Sharma
- Global Inflation after the Pandemic: Cyclical Pressures, Structural Drivers, and Policy MisstepsGayatri Satish
- Global Emissions and Carbon Offsetting: Examining Conservational Approaches and Regulatory GapsVinayak Raj
- The Decline of Regional Languages in India – Preserving Linguistic Diversity in a Globalized EraSajinkya Sharan Gupta
- Capitalism and Global Inequality: A Unified AnalysisRuveer Vohra
- Untangling The Threads of the TikTok Ban's Impact On Global Trade via Trade, Technology, and DiplomacyAanya Menon
Threads 4
Where this connects to other fields — and why it's worth knowing.
- Civil & Structural Engineering Technology
A lot of the systems running our power grids and banks still hum along on ancient, never-updated code, like a city relying on rusting bridges nobody repaired. Programmers call that 'technical debt,' and just like a crumbling bridge, it stays invisible right up until the day a load it can't handle finally arrives.
- Immunology Health
Your immune system and a company's cybersecurity team are fighting the same unfair war: the attacker only has to get through once, you have to block every time. So both build defenses in layers, and both hit a scary blind spot with something brand-new. A never-seen virus and a never-seen hack are equally dangerous, because neither defender has learned to recognize it yet.
- Probability, Risk & Uncertainty Mathematics
Insurance works because car crashes are independent; yours doesn't cause your neighbor's, so payouts average out. Cyberattacks break that. One computer worm can hit millions of customers on the same day at once. When everyone fails together, the 'safety in numbers' that insurance depends on collapses, which is why cyber is so hard to insure.
- Biodiversity Loss Environment
Plant one type of crop across a whole country and a single pest can wipe out the entire harvest. Software is the same: when everyone runs the identical operating system, one exploit can hack them all at once. That's why variety, in fields or in code, isn't just nice to have, it's actual protection.
