Model G20 2027 at FLAME University — registrations now open

Global Risks

Critical infrastructure

Cyber & Critical Infrastructure

Also known as cyberattacks / cybersecurity threats

Cyber and critical infrastructure is the modern danger that the grids, hospitals, and banks we depend on now run on software, so a single well-aimed hack can freeze the machinery of daily life. It connects to Civil and Structural Engineering in Technology, because the physical systems being defended, like dams and power stations, must be built and protected as one with their digital controls. It links to Immunology in Health, since a network defends itself much like a body fights infection, spotting intruders and racing to contain them. It also ties to Probability, Risk and Uncertainty in Mathematics, because defenders must weigh rare but catastrophic attacks, and to Biodiversity Loss in Environment, because a monoculture, whether crops or identical software, means one weakness can wipe out everything at once.

Key people

  • Manuel AtugGerman computer scientist and computer security specialist

Timeline

  • 1996Has had a wide-reaching critical infrastructure protection program in place since 1996.
  • 2006Member states are obliged to adopt the 2006 directive into their national statutes.
  • 2013The 2013 version of the NIPP has faced criticism for lacking viable risk measures.
  • 2020In June 2020, West Virginia passed the Critical Infrastructure Protection Act, which created felony penalties for protests against oil and gas facilities.

Read

  • Critical InfrastructureRobert Radvanovsky · 2009Book
  • Critical Infrastructure Protection in Homeland SecurityTed G. Lewis · 2006Book
  • Critical Infrastructure Protection, Risk Management, and ResilienceKelley A. Pesch-Cronin · 2016Book
  • Cyber SecurityMartti Lehto · 2015Book

Listen

  • Cyber Focus: Cybersecurity, National Security, and Critical InfrastructureFrank Cilluffo / McCrary InstitutePodcast
  • Renewable Energy SmartPodSean McMahonPodcast
  • Critical Infrastructure Security CentreAustralian Department of Home Affairs Critical Infrastructure Security Centre (CISC)Podcast
  • In Australia’s National Interest - Security of Critical InfrastructurePentagram AdvisoryPodcast

Voices to follow

  • Manuel Atug@HonkHase · XGerman computer scientist and computer security specialist
  • Stephanie Carvin@stephaniecarvin · XCanadian legal scholar

By the numbers

  • 4.7CO₂ per person (t) — global, 2024 (World Bank)
  • 31.1Forest area (% land) — global, 2023 (World Bank)

Debates

  • Should critical infrastructure be primarily publicly or privately owned?One view: Public ownership ensures services prioritize public good and equity over profit, allowing for better long-term planning and investment. · Another: Private ownership often brings greater efficiency, innovation, and access to capital, leading to more responsive and technologically advanced systems.Open question
  • Is it more important to focus on making critical infrastructure highly efficient or highly resilient?One view: Prioritizing efficiency reduces costs and optimizes resource use, delivering services more affordably and quickly under normal conditions. · Another: Prioritizing resilience builds in redundancy and robustness, ensuring services continue even during disruptions like natural disasters or cyberattacks.Open question
  • Who bears the primary responsibility for protecting critical infrastructure from cyber threats?One view: Governments should lead protection efforts due to national security implications, resource access, and the ability to set universal standards. · Another: Private sector operators are best positioned to secure their own systems, possessing specific technical expertise and operational control.Open question

Glossary

  • Critical InfrastructureSystems and assets essential for a society's functioning, whose disruption would have a severe impact.
  • ResilienceThe ability of systems to withstand, adapt to, and recover from disruptions.
  • CybersecurityMeasures taken to protect computer systems and networks from digital attacks and unauthorized access.
  • InterdependenceThe reliance of one critical infrastructure sector on another for its operation, creating cascading risks.
  • Supply ChainThe network of organizations, people, activities, information, and resources involved in moving a product or service from supplier to customer.
  • SCADASupervisory Control and Data Acquisition, a control system architecture used for industrial processes like power grids and water treatment.

Careers

Roles this can lead toward

Cybersecurity AnalystUrban PlannerEmergency ManagerPolicy AnalystCivil EngineerRisk ManagerSupply Chain ManagerEnvironmental Engineer

Student research

Published policy papers by One Young India delegates — every delegate leaves published under their own name.

Threads 4

Where this connects to other fields — and why it's worth knowing.

  • Civil & Structural Engineering Technology

    A lot of the systems running our power grids and banks still hum along on ancient, never-updated code, like a city relying on rusting bridges nobody repaired. Programmers call that 'technical debt,' and just like a crumbling bridge, it stays invisible right up until the day a load it can't handle finally arrives.

  • Immunology Health

    Your immune system and a company's cybersecurity team are fighting the same unfair war: the attacker only has to get through once, you have to block every time. So both build defenses in layers, and both hit a scary blind spot with something brand-new. A never-seen virus and a never-seen hack are equally dangerous, because neither defender has learned to recognize it yet.

  • Probability, Risk & Uncertainty Mathematics

    Insurance works because car crashes are independent; yours doesn't cause your neighbor's, so payouts average out. Cyberattacks break that. One computer worm can hit millions of customers on the same day at once. When everyone fails together, the 'safety in numbers' that insurance depends on collapses, which is why cyber is so hard to insure.

  • Biodiversity Loss Environment

    Plant one type of crop across a whole country and a single pest can wipe out the entire harvest. Software is the same: when everyone runs the identical operating system, one exploit can hack them all at once. That's why variety, in fields or in code, isn't just nice to have, it's actual protection.

← Explore the living map