Threats from Hostile Rogue States to Critical National Infrastructure.
- Dr. Lucky Ogoo

- Jul 15
- 28 min read
Assessing Risks to National Infrastructure and Enhancing Citizen Preparedness.
Download the full white paper report here
Critical National Infrastructure (CNI) underpins every aspect of modern society. The continuous provision of electricity, water, healthcare, telecommunications, financial services, transport, fuel, food distribution and digital infrastructure enables governments, businesses and citizens to function safely and effectively. These sectors are highly interconnected, with each relying upon the availability and resilience of the others. Consequently, disruption affecting one sector can rapidly cascade across multiple services, creating widespread economic, social and national security consequences.
The strategic environment in which Critical National Infrastructure operates has changed significantly over the past decade. Escalating geopolitical tensions, increasing competition between major powers, regional conflicts and the emergence of revisionist and rogue states have expanded the range of threats facing national infrastructure. Rather than relying solely upon conventional military action, hostile states increasingly employ cyber operations, espionage, sabotage, disinformation campaigns, economic coercion and attacks on supply chains to achieve strategic objectives while remaining below the threshold of open armed conflict. These activities often described as hybrid or grey-zone warfare are specifically designed to exploit vulnerabilities within interconnected societies and undermine public confidence without triggering a traditional military response.
The rapid digital transformation of infrastructure has delivered considerable operational benefits through automation, cloud computing, industrial control systems, remote monitoring and interconnected operational technology. However, these advances have also created new opportunities for adversaries. Infrastructure that was once physically isolated is now increasingly connected to corporate networks and external systems, expanding the potential attack surface. Sophisticated state-sponsored threat actors are capable of exploiting vulnerabilities in software, hardware, third-party suppliers and human behaviour to gain access to critical systems. The convergence of information technology (IT) and operational technology (OT) means that cyber-attacks can now produce direct physical effects, including power outages, transport disruption, interruption of healthcare services and industrial damage.
Recent international incidents demonstrate that attacks on Critical National Infrastructure are no longer hypothetical. Cyber-attacks against Ukraine's electricity grid have shown that hostile actors can deliberately interrupt power supplies to civilian populations during periods of conflict. The Colonial Pipeline ransomware incident illustrated how disruption to a single energy provider could trigger widespread fuel shortages and public panic. The WannaCry ransomware attack significantly disrupted the United Kingdom's National Health Service, highlighting the vulnerability of healthcare systems to malicious cyber activity. Supply chain compromises, such as the SolarWinds incident, demonstrated how trusted software updates can become vectors for espionage and network compromise across thousands of organisations worldwide. Likewise, attacks against satellite communications and other digital infrastructure have illustrated the growing importance of securing emerging technologies that support both civilian and military operations.
The United Kingdom maintains one of the world's most advanced and resilient Critical National Infrastructure ecosystems. Through organisations including the National Cyber Security Centre (NCSC), the National Protective Security Authority (NPSA), government departments, regulators and infrastructure operators, considerable investment has been made in strengthening cyber resilience, protective security, intelligence sharing and emergency response capabilities. Nevertheless, no modern nation is immune from disruption. Increasing dependence upon digital technologies, global supply chains, cloud service providers and international telecommunications networks introduces new systemic risks that require continuous assessment and adaptation.
Protecting Critical National Infrastructure cannot be achieved by government alone. Effective resilience depends upon close collaboration between government agencies, infrastructure operators, technology providers, emergency services, private industry, academia and the wider public. Security must encompass not only technical controls but also organisational governance, workforce training, supply chain assurance, physical security, intelligence-led risk management and effective incident response planning. Public awareness and household preparedness also form an essential component of national resilience, enabling communities to better withstand periods of prolonged disruption.
This white paper examines the evolving threat posed by hostile rogue states to the United Kingdom's Critical National Infrastructure. It explores the principal methods employed by state-sponsored adversaries, including cyber intrusion, sabotage, espionage, influence operations, supply chain compromise and emerging technologies that may be exploited in future conflicts. The paper assesses the potential consequences for individual infrastructure sectors, analyses significant real-world case studies and identifies lessons that can strengthen national resilience.
In addition to examining strategic and technical threats, the paper provides practical recommendations for policymakers, infrastructure operators, businesses and individual citizens. These recommendations include measures to improve cyber resilience, enhance inter-agency cooperation, strengthen supply chain security, develop effective incident response capabilities and encourage sensible household preparedness. While the likelihood of catastrophic nationwide infrastructure failure remains relatively low, the increasing frequency and sophistication of hostile state activity demonstrates that resilience must be viewed as an ongoing national priority rather than a one-time objective.
Ultimately, the security of Critical National Infrastructure is inseparable from the security of the nation itself. By understanding the evolving threat landscape, investing in resilient infrastructure, strengthening public-private partnerships and fostering a culture of preparedness across society, the United Kingdom can continue to deter hostile actors, mitigate the impact of disruption and ensure the continuity of the essential services upon which its citizens, economy and national security depend.
Threat Landscape
The threat landscape facing the United Kingdom's Critical National Infrastructure (CNI) has evolved considerably over the past two decades. Advances in digital technology, increased interconnectivity, global supply chains and geopolitical competition have created an environment in which hostile states can project influence far beyond their borders. Rather than relying exclusively on conventional military force, many adversaries now employ a combination of cyber operations, intelligence activities, economic coercion, influence campaigns and limited acts of sabotage to achieve strategic objectives. Collectively, these activities form part of what is commonly described as hybrid warfare or grey-zone conflict actions deliberately designed to remain below the threshold of open armed conflict while imposing significant political, economic and psychological costs.
Critical National Infrastructure represents an attractive target because disruption to essential services can have disproportionate effects across society. Modern infrastructure sectors are highly interconnected, meaning that failures in one area may rapidly cascade into others. A successful cyber-attack against an electricity distribution network, for example, may affect telecommunications, financial services, healthcare facilities, transport systems and water treatment operations simultaneously. Even relatively short periods of disruption can result in significant economic losses, interruption of essential public services and reduced public confidence in government institutions.
Hostile states generally pursue long-term strategic objectives rather than isolated acts of disruption. In many cases, cyber operations are conducted over months or even years, allowing adversaries to gain persistent access to networks, collect intelligence, understand operational procedures and position themselves for future action. During periods of heightened international tension, these pre-positioned capabilities may enable an adversary to rapidly disrupt essential services, gather sensitive information or support wider military and political objectives.
2.1 Cyber Attacks Against Operational Technology
Operational Technology (OT) systems control the physical processes upon which infrastructure depends. These include electricity generation and distribution, water treatment, railway signalling, oil and gas production, manufacturing processes and numerous other industrial operations. Historically, OT environments were isolated from corporate information technology (IT) networks. However, increased connectivity, remote management and digital transformation have significantly blurred these boundaries.
State-sponsored threat actors increasingly target OT environments because compromise may produce direct physical consequences. Manipulation of industrial processes may interrupt electricity supplies, damage critical equipment, halt manufacturing, disrupt transport networks or compromise the safety of industrial facilities. Even where physical damage is not achieved, the need to isolate systems during incident response can itself result in prolonged operational disruption.
2.2 Malware Targeting Industrial Control Systems
Industrial Control Systems (ICS), including Supervisory Control and Data Acquisition (SCADA) systems and programmable logic controllers (PLCs), manage many of the automated processes within Critical National Infrastructure. Highly specialised malware has demonstrated that cyber-attacks can be designed specifically to interfere with these systems.
Unlike conventional malware that seeks to steal data or encrypt files, ICS-focused malware may manipulate sensors, disable safety systems, alter industrial processes or issue unauthorised commands to physical equipment. Such attacks require considerable technical expertise, extensive reconnaissance and detailed understanding of industrial processes, making them more commonly associated with well-resourced state-sponsored actors than with ordinary cybercriminals.
The increasing convergence of IT and OT environments means that malicious software introduced through seemingly routine corporate systems may ultimately provide a pathway into industrial control networks if appropriate segmentation and security controls are not maintained.
2.3 Ransomware Against Public Services
Although ransomware is commonly associated with financially motivated criminal organisations, several groups are believed to operate with the tacit approval, protection or strategic alignment of hostile states. In some cases, governments may tolerate or indirectly support cybercriminal organisations whose activities serve broader geopolitical objectives.
Hospitals, local authorities, educational institutions and public sector organisations remain frequent targets because they often provide essential services that cannot tolerate prolonged disruption. Successful ransomware attacks may prevent access to patient records, disrupt emergency services, delay medical treatment, interrupt local government operations and undermine public confidence.
Even where ransom payments are not made, recovery from a significant ransomware incident may require weeks or months of system restoration, security improvements and operational recovery.
2.4 Distributed Denial of Service (DDoS) Attacks
Distributed Denial of Service (DDoS) attacks seek to overwhelm online services by generating excessive volumes of network traffic. Although technically less sophisticated than many forms of cyber intrusion, DDoS attacks remain an effective method of disrupting public-facing digital services.
Government websites, financial institutions, telecommunications providers, transport operators and emergency information services may all be targeted during periods of heightened geopolitical tension. While DDoS attacks rarely cause permanent damage, they may significantly impede communication with the public, delay access to essential services and contribute to wider uncertainty during national emergencies.
State-sponsored campaigns frequently combine DDoS attacks with disinformation operations and cyber intrusion to maximise their psychological and operational impact.
2.5 Supply Chain Compromise
Modern infrastructure depends upon extensive international supply chains involving software vendors, hardware manufacturers, managed service providers, cloud service providers and specialist engineering contractors. Consequently, organisations increasingly inherit cyber risk from third parties upon whom they depend.
Supply chain attacks exploit trusted relationships between suppliers and customers. Rather than directly attacking a well-defended target, adversaries compromise a software update, hardware component or service provider that subsequently distributes malicious code to numerous downstream organisations.
Because trusted suppliers often possess privileged access to customer systems, supply chain compromises can bypass many traditional security controls. Such attacks have demonstrated the potential to affect thousands of organisations simultaneously, including government departments, infrastructure operators and private industry.
2.6 Insider Threats
Insider threats remain one of the most challenging risks facing Critical National Infrastructure. Individuals with authorised access to facilities, information or digital systems may intentionally or unintentionally compromise security.
Hostile intelligence services may attempt to recruit employees through financial incentives, ideological influence, coercion or blackmail. Alternatively, trusted personnel may inadvertently expose sensitive information through phishing attacks, poor cyber hygiene or accidental disclosure.
The increasing prevalence of remote working, cloud services and third-party contractors has further expanded the complexity of insider risk management. Effective personnel security, continuous monitoring, security awareness training and robust access controls remain essential components of infrastructure protection.
2.7 Physical Sabotage
While cyber threats receive considerable public attention, physical sabotage continues to represent a significant risk. Electricity substations, telecommunications exchanges, fuel depots, railway infrastructure, water treatment facilities, undersea telecommunications cables and energy pipelines all present potential targets for hostile actors.
Physical attacks need not be sophisticated to generate significant disruption. Damage to a relatively small number of strategically important assets may interrupt services across large geographic areas or require lengthy repair operations. In some circumstances, physical sabotage may be coordinated with cyber-attacks to complicate incident response and prolong disruption.
Infrastructure located in remote areas or beneath the sea presents particular security challenges due to limited physical surveillance and the complexity of repair operations.
2.8 Global Navigation Satellite System (GNSS) and GPS Interference
Modern societies rely extensively upon satellite-based navigation and timing services provided by Global Navigation Satellite Systems (GNSS), including the Global Positioning System (GPS). Beyond navigation, highly accurate timing signals synchronise financial transactions, telecommunications networks, electricity grids and numerous industrial processes.
Hostile states increasingly employ GPS jamming and spoofing technologies to interfere with these services. Jamming blocks legitimate satellite signals, while spoofing transmits false navigation data designed to mislead receivers.
Prolonged GNSS disruption may affect aviation, maritime navigation, emergency services, logistics, telecommunications, precision agriculture and financial systems, demonstrating the broad dependence upon satellite-derived timing and positioning information.
2.9 Satellite Communications Disruption
Space-based infrastructure has become an essential component of national resilience. Satellite communications support military operations, emergency response, broadcasting, maritime communications, aviation and broadband connectivity for remote regions.
Hostile actors may seek to disrupt satellite services through cyber intrusion, electronic warfare, radio frequency interference or attacks against ground stations. Increasing concern also surrounds the security of commercial satellite networks that now provide critical communications capabilities for both government and private industry.
As dependence upon space infrastructure continues to grow, protecting satellite services has become an increasingly important element of national security.
2.10 Espionage
Cyber espionage remains one of the most persistent activities conducted by hostile states. Unlike disruptive attacks, espionage operations frequently seek to remain undetected for extended periods while collecting intelligence from government departments, defence contractors, infrastructure operators, research institutions and technology companies.
Objectives may include the theft of intellectual property, strategic planning documents, defence information, infrastructure diagrams, vulnerability assessments and operational procedures. Such intelligence enables adversaries to improve future cyber operations, support military planning and gain economic advantage.
Persistent espionage campaigns also allow hostile actors to establish long-term access within networks that may later be exploited during periods of political or military crisis.
2.11 Disinformation and Influence Operations
Infrastructure attacks increasingly extend beyond technical systems into the information environment. Hostile states routinely employ coordinated disinformation campaigns to amplify public anxiety, undermine trust in government institutions and exploit social divisions.
False reports concerning power outages, contaminated water supplies, fuel shortages or failures of emergency services may spread rapidly through social media and online platforms. Even where infrastructure remains operational, misinformation can trigger panic buying, public disorder and unnecessary demand on emergency services.
These information operations are often coordinated with cyber incidents to maximise uncertainty and complicate official crisis communication.
2.12 Artificial Intelligence-Enabled Cyber Operations
Artificial intelligence (AI) is rapidly transforming both cyber defence and cyber offence. Hostile actors increasingly exploit AI to automate vulnerability discovery, generate convincing phishing campaigns, produce malicious software, analyse stolen data and identify potential attack pathways at unprecedented speed.
Generative AI can also support sophisticated influence operations by producing realistic text, synthetic audio, manipulated images and deepfake video capable of impersonating trusted individuals or institutions. These capabilities increase the scale, speed and credibility of disinformation campaigns while reducing the resources required to conduct them.
Although AI also provides significant defensive opportunities—including automated threat detection, anomaly analysis and incident response, it is likely that AI-enabled cyber operations will become an increasingly important feature of future hostile state activity.
Strategic Objectives of Hostile States
The methods described throughout this chapter are not ends in themselves but instruments used to achieve broader strategic objectives. Hostile states typically seek to weaken national resilience while avoiding direct military confrontation. Their objectives may include reducing public confidence in government, disrupting emergency services, damaging economic activity, gathering strategic intelligence, influencing political decision-making and diverting national resources during periods of international tension or crisis.
By exploiting the interdependence of modern infrastructure, adversaries can achieve disproportionate effects through relatively limited actions. The challenge for the United Kingdom is therefore not simply to defend individual systems but to strengthen the resilience of the interconnected national infrastructure upon which society depends. Achieving this requires continuous investment in cyber security, protective security, intelligence sharing, supply chain assurance, workforce development, incident response and public preparedness. Only through a comprehensive, whole-of-society approach can the nation reduce the opportunities available to hostile actors and ensure the continued delivery of essential services during periods of disruption.
Chapter 3
National Electricity Grid
The national electricity grid represents the single most critical component of the United Kingdom's Critical National Infrastructure. Virtually every other essential service relies directly or indirectly upon the continuous supply of electrical power. Modern society has become increasingly dependent upon electricity not only for lighting and domestic use but also for communications, healthcare, transport, financial services, manufacturing, food production, emergency response and national defence. As digital technologies become more deeply integrated into daily life, this dependence continues to increase, making the resilience of the electricity sector a matter of national security.
The United Kingdom operates a highly sophisticated electricity system that combines power generation from a diverse range of sources—including gas, nuclear, offshore and onshore wind, solar, hydroelectric and interconnector imports with an extensive transmission and distribution network. This infrastructure is designed with multiple layers of redundancy, continuous monitoring and rigorous engineering standards to ensure reliable operation under a wide range of conditions. National Grid Electricity System Operator (ESO), regional distribution network operators, electricity generators and regulators work closely to maintain system stability and rapidly respond to faults or unexpected changes in demand.
Despite this resilience, the electricity sector remains an attractive target for hostile states. Successful disruption of electricity supplies would produce cascading effects across numerous other infrastructure sectors, multiplying the overall impact far beyond the immediate loss of power. For this reason, electricity infrastructure has become a priority target within many hostile states' cyber strategies and military planning.
Interdependence with Other Critical Sectors
Electricity underpins the operation of almost every element of Critical National Infrastructure. The interconnected nature of modern infrastructure means that even relatively localised outages may have consequences that extend far beyond the affected area.
Mobile telecommunications networks depend upon electricity to power base stations, switching centres and network infrastructure. While backup batteries and emergency generators provide temporary resilience, these systems are generally designed to sustain operations for limited periods. Extended power outages may therefore result in degraded mobile coverage, reduced internet connectivity and disruption to emergency communications.
Financial services are similarly dependent upon reliable electrical power. Banks, payment processors, automated teller machines (ATMs), stock exchanges and online banking platforms all require resilient data centres, telecommunications and electricity. Prolonged outages could prevent electronic payments, interrupt cash withdrawals and significantly reduce commercial activity.
Fuel distribution also relies upon electricity. Modern petrol stations use electrically powered pumps, payment terminals, lighting and fuel monitoring systems. Without electricity, fuel cannot normally be dispensed, even where supplies remain available.
This has implications not only for private transport but also for emergency services, logistics companies and public transport operators.
Road transport systems depend upon electrically powered traffic signals, tunnel ventilation systems, motorway communications and traffic management centres. Significant disruption could increase congestion, delay emergency response vehicles and contribute to road safety risks.
The railway network similarly relies upon electricity for signalling systems, communications, control centres and, in many areas, traction power for electric trains. Although diesel-operated services may continue in some locations, disruption to signalling and operational control would significantly reduce network capacity and safety.
Healthcare services require uninterrupted electrical power to operate medical equipment, diagnostic imaging, operating theatres, life-support systems, pharmaceutical refrigeration and digital patient records. Hospitals maintain emergency generators and fuel reserves to ensure continuity of critical services; however, prolonged outages may create increasing logistical challenges, particularly if fuel deliveries become disrupted.
Food production and distribution also depend heavily upon electricity. Refrigeration throughout warehouses, supermarkets, food processing facilities and domestic homes preserves food safety and reduces waste. Extended loss of power may lead to spoilage of perishable goods, increasing pressure on already disrupted supply chains.
Water treatment and distribution infrastructure relies upon electrically powered pumps, filtration systems, chemical treatment processes and monitoring equipment. Although many facilities possess contingency arrangements, prolonged electricity failures may reduce water pressure, affect wastewater treatment and compromise the continuity of clean water supplies.
The cumulative effect of these interdependencies illustrates why electricity is widely regarded as the foundational infrastructure sector. Failure within the electricity system has the potential to trigger cascading disruption across nearly every aspect of society.
Threats to the Electricity Grid
Hostile states possess a range of capabilities that could be employed against electricity infrastructure. These threats encompass both cyber and physical methods, often designed to complement one another as part of a coordinated campaign.
Cyber Attacks Against Grid Operators
Electricity transmission and distribution operators maintain extensive digital systems that support network management, asset monitoring, demand forecasting and operational control. Although these organisations invest heavily in cyber security, they remain attractive targets for sophisticated state-sponsored threat actors.
Potential objectives include gaining unauthorised access to operational networks, disrupting control systems, manipulating monitoring data, interfering with grid stability or establishing persistent access for future operations.
Cyber espionage campaigns may also seek to collect technical documentation, network architecture, engineering specifications and operational procedures that support subsequent attacks.
Compromise of Industrial Control Systems
Electricity generation and transmission rely upon Industrial Control Systems (ICS), Supervisory Control and Data Acquisition (SCADA) platforms and programmable logic controllers (PLCs) to monitor and manage physical processes.
Successful compromise of these systems may allow an attacker to interfere with circuit breakers, voltage regulation, generation control or protective safety mechanisms. Manipulation of operational technology could result in equipment damage, localised outages or broader instability within the electricity network.
The increasing integration of operational technology with corporate IT systems has expanded the potential pathways through which attackers may reach critical control environments if appropriate segmentation and security controls are not maintained.
Malware and Advanced Persistent Threats
State-sponsored actors frequently employ highly sophisticated malware specifically designed to evade detection, maintain long-term access and support intelligence collection.
Advanced Persistent Threats (APTs) may remain dormant within networks for extended periods while mapping systems, escalating privileges and identifying critical assets. Such access allows hostile actors to position themselves for future disruption during periods of political or military tension.
Unlike conventional cybercriminals, state-sponsored attackers often prioritise strategic intelligence and operational positioning over immediate financial gain.
Insider Threats
Personnel with legitimate access to critical systems represent an additional security concern. Insider threats may arise through malicious intent, coercion by foreign intelligence services, financial incentives or inadvertent human error.
Employees, contractors and third-party maintenance personnel frequently require privileged access to operational environments. Robust personnel security, continuous vetting, behavioural monitoring and strict access controls therefore remain essential components of electricity sector resilience.
Physical Sabotage
Although cyber threats receive significant attention, physical attacks against electricity infrastructure remain a credible concern. Electricity substations, transmission lines, switching stations, transformers and communications facilities may all present attractive targets.
Coordinated physical attacks against multiple substations could significantly increase restoration times, particularly where specialist replacement equipment is required. High-voltage transformers, for example, are complex engineering assets that may require many months to manufacture and install if destroyed.
Physical sabotage may also be coordinated with cyber operations to complicate incident response and maximise disruption.
Potential Consequences of a Prolonged National Outage
The consequences of a prolonged nationwide electricity outage would extend rapidly across every sector of society. Although emergency response arrangements and business continuity plans would reduce some immediate impacts, disruption would intensify as backup resources became depleted.
Within the first few hours, households and businesses would lose lighting, heating, cooling and many forms of communication. Mobile phone networks would begin relying upon battery reserves and standby generators. Internet connectivity would become increasingly unreliable as telecommunications infrastructure exhausted backup power.
Electronic payment systems could become unavailable, preventing debit and credit card transactions. Cash withdrawals from ATMs would be interrupted, leaving many individuals unable to access funds. Retail businesses operating cashless payment systems would experience immediate operational difficulties.
Fuel stations would be unable to dispense petrol or diesel once backup power was exhausted, significantly affecting emergency services, logistics operators and public transport. Traffic signals would cease functioning across affected areas, increasing congestion and the likelihood of road traffic collisions.
Hospitals would transition to emergency generators to maintain critical services. While these systems are regularly tested and designed for resilience, prolonged operation depends upon secure fuel supplies, maintenance capability and reliable logistics. Less critical healthcare services, outpatient clinics and elective procedures would likely be postponed to prioritise emergency care.
Water treatment facilities and pumping stations may experience reduced operational capacity, potentially affecting water pressure and wastewater management. Food retailers would face increasing losses of refrigerated products, while households without alternative refrigeration would experience similar difficulties.
Within several days, disruption to supply chains could result in shortages of essential goods, including food, fuel, medicines and industrial materials.
Manufacturing output would decline, public transport services would be significantly reduced and many businesses would suspend operations.
Public confidence could also be affected. Extended disruption may increase demand upon emergency services, encourage panic buying and create opportunities for misinformation campaigns designed to amplify uncertainty. Effective public communication and transparent government messaging would therefore become as important as technical recovery efforts.
Mitigation and Resilience
The United Kingdom's electricity sector incorporates extensive resilience measures to reduce both the likelihood and impact of major disruption. These include network redundancy, geographically distributed generation, rigorous cyber security standards, continuous monitoring, incident response planning and close cooperation between government agencies and infrastructure operators.
Cyber resilience is strengthened through network segmentation, multi-factor authentication, threat intelligence sharing, vulnerability management, regular penetration testing and continuous monitoring of operational technology environments. Physical security measures include controlled site access, surveillance systems, perimeter protection and close collaboration with law enforcement and national security agencies.
Business continuity planning ensures that essential personnel can respond rapidly to incidents while maintaining coordination between electricity operators, emergency responders, regulators and central government. Regular national exercises test contingency arrangements for large-scale outages and help identify opportunities for continuous improvement.
Longer-term resilience also depends upon investment in modernising infrastructure, diversifying electricity generation, strengthening interconnections, improving supply chain security and enhancing the cyber security of both legacy and emerging technologies. As the transition towards smart grids, renewable generation and distributed energy resources continues, maintaining security by design will become increasingly important.
The national electricity grid is the cornerstone of the United Kingdom's Critical National Infrastructure. Its reliable operation enables the delivery of virtually every essential public service and underpins the country's economic prosperity, national security and social stability. While the sector has benefited from substantial investment in engineering resilience, cyber security and operational excellence, the evolving capabilities of hostile states require continued vigilance and adaptation.
Protecting the electricity grid demands a comprehensive approach that integrates physical security, cyber defence, intelligence sharing, resilient engineering, supply chain assurance and effective emergency planning. By maintaining this whole-of-system approach, the United Kingdom can significantly reduce the likelihood of successful attacks and ensure that essential services remain available even during periods of heightened geopolitical tension or national crisis.
Real-World Case Studies
The evolving threat landscape facing Critical National Infrastructure (CNI) is illustrated by a number of well-documented incidents that have occurred over the past two decades. These events demonstrate that cyber-attacks, ransomware, supply chain compromises and attacks against communications infrastructure are no longer theoretical risks. They also highlight the increasingly blurred distinction between cybercrime, espionage and state-sponsored operations, particularly during periods of heightened geopolitical tension.
Although each incident occurred within a different context, together they provide valuable lessons regarding infrastructure resilience, incident response, business continuity and international cooperation. Importantly, they also demonstrate that attacks against one sector frequently produce cascading effects across other areas of society, reinforcing the need for a whole-of-government and whole-of-society approach to national resilience.
Ukraine Electricity Grid (2015–2016)
The cyber-attacks against Ukraine's electricity distribution networks during December 2015 and December 2016 remain among the most significant publicly documented attacks against operational technology and industrial control systems.
In December 2015, several regional electricity distribution companies experienced coordinated cyber intrusions that resulted in power outages affecting approximately 225,000 consumers. Attackers gained access to corporate networks through phishing emails before moving into operational systems used to control electricity distribution. They remotely disconnected substations, disabled backup power systems and interfered with call centres, making it more difficult for customers to report outages.
A second attack occurred in December 2016 against transmission infrastructure in Kyiv. Unlike the earlier incident, this operation involved more sophisticated malware specifically designed to interact with industrial control systems. Although the outage was relatively limited in duration, the attack demonstrated increasing technical capability and a willingness to target critical infrastructure during ongoing geopolitical conflict.
These incidents fundamentally changed how governments and infrastructure operators viewed cyber security within operational technology environments. They demonstrated that cyber-attacks could produce real-world physical consequences affecting essential services, while also highlighting the importance of network segmentation, incident response planning, manual operating procedures and close cooperation between cyber security specialists and engineering teams.
Lessons Learned
The Ukraine electricity attacks demonstrated that:
Industrial control systems are potential targets during geopolitical conflict.
Cyber intrusions can produce direct physical disruption to essential services.
Phishing and credential theft remain common methods of initial compromise.
Well-rehearsed incident response procedures significantly improve recovery.
Maintaining the ability to operate critical systems manually enhances resilience during cyber incidents.
These events continue to influence infrastructure security planning across Europe and other regions.
Estonia (2007)
In April and May 2007, Estonia experienced one of the first large-scale, nationally coordinated cyber campaigns directed against a highly digital society.
A series of Distributed Denial of Service (DDoS) attacks targeted government departments, ministries, parliament, financial institutions, telecommunications providers, news organisations and other public services. The attacks overwhelmed internet-facing systems with enormous volumes of traffic, reducing the availability of websites and online services for extended periods.
Although the attacks caused relatively little physical damage, they significantly disrupted daily life within one of the world's most digitally connected nations. Online banking services became difficult to access, government websites were temporarily unavailable and media organisations experienced interruptions that affected public communications.
The incident highlighted the vulnerability of highly connected societies to large-scale cyber disruption and demonstrated that attacks designed primarily to reduce service availability could nevertheless have significant political and economic consequences.
Lessons Learned
The Estonia attacks emphasised several important principles:
Digital government services require robust resilience and redundancy.
Distributed Denial of Service attacks can significantly affect public confidence.
National cyber security requires close cooperation between government and private industry.
International collaboration is essential for responding to cross-border cyber incidents.
The experience also influenced NATO's subsequent focus on cyber defence and contributed to the establishment of the NATO Cooperative Cyber Defence Centre of Excellence in Tallinn.
Colonial Pipeline (United States, 2021)
In May 2021, the Colonial Pipeline Company experienced one of the most widely reported ransomware incidents affecting critical infrastructure.
Colonial Pipeline operates one of the largest fuel pipeline systems in the United States, transporting petrol, diesel and aviation fuel across the eastern United States. Following the ransomware attack, the company temporarily suspended pipeline operations as a precaution while assessing the potential impact on operational systems.
Although the malware primarily affected corporate information technology rather than industrial control systems, the decision to halt operations resulted in significant fuel distribution disruption across several states. Temporary shortages occurred at filling stations, prices increased and public concern led to increased consumer purchasing, further amplifying local supply challenges.
The incident demonstrated that cyber-attacks affecting administrative business systems may nevertheless have substantial operational consequences where organisations depend upon integrated digital processes.
Lessons Learned
The Colonial Pipeline incident highlighted that:
Business information technology and operational technology are closely interconnected.
Decisions taken to protect infrastructure during cyber incidents may temporarily affect service delivery.
Public communication plays an important role in preventing unnecessary panic buying.
Business continuity planning is essential for operators of critical infrastructure.
The attack also reinforced the importance of ransomware preparedness, incident response planning and cyber hygiene across essential industries.
NotPetya (2017)
The NotPetya malware outbreak of June 2017 remains one of the most economically damaging cyber incidents ever recorded.
Initially affecting organisations in Ukraine through a compromised software update mechanism, the malware rapidly spread across international networks used by multinational organisations. Although it resembled ransomware, NotPetya was widely assessed as being designed primarily to destroy data rather than facilitate financial extortion.
The malware propagated automatically using multiple techniques, encrypting or destroying systems across numerous sectors including shipping, logistics, manufacturing, pharmaceuticals, professional services and transportation.
Major international companies experienced extensive operational disruption, requiring thousands of computers and servers to be rebuilt. Economic losses worldwide were estimated to total many billions of pounds.
Unlike many cyber incidents, NotPetya demonstrated how attacks directed at one geographic region could rapidly affect organisations around the world through globally connected digital infrastructure.
Lessons Learned
The NotPetya outbreak demonstrated:
Supply chain compromises can affect thousands of organisations simultaneously.
Malware can spread rapidly across trusted business networks.
Robust backup arrangements and network segmentation significantly improve recovery.
International organisations require coordinated cyber resilience regardless of where they operate.
The incident remains a landmark example of how cyber attacks can generate global economic consequences far beyond their original target.
Viasat Satellite Communications (2022)
On the eve of Russia's full-scale invasion of Ukraine in February 2022, a cyber-attack targeted satellite communications infrastructure supporting broadband connectivity across parts of Europe.
The attack affected satellite broadband services provided through Viasat's KA-SAT network by disrupting customer satellite modems. The incident reduced connectivity for thousands of users, including organisations supporting Ukrainian infrastructure, while also affecting customers in several European countries.
The attack demonstrated the strategic importance of satellite communications during modern conflict. Satellite services support military operations, emergency communications, remote communities, energy infrastructure, maritime activities and numerous commercial services. Disruption to these systems therefore has implications extending well beyond traditional telecommunications.
The incident also highlighted the interconnected nature of commercial and governmental infrastructure, illustrating how attacks against privately operated systems may produce wider national security consequences.
Lessons Learned
The Viasat incident reinforced several key principles:
Satellite communications form an increasingly important component of Critical National Infrastructure.
Commercial infrastructure may become strategically significant during geopolitical crises.
Building redundancy across multiple communications technologies improves resilience.
International cooperation is essential for responding to complex cross-border cyber incidents.
The attack accelerated efforts across Europe to strengthen the resilience of satellite communications and diversify communications capabilities.
Cross-Sector Analysis
Although these incidents occurred in different countries and affected different sectors, several common themes emerge.
First, they demonstrate the growing convergence of cyber security and national security. Modern hostile activity increasingly targets civilian infrastructure because disruption to essential services can produce significant political, economic and psychological effects without requiring conventional military action.
Second, they illustrate the interconnected nature of Critical National Infrastructure. An attack affecting electricity, fuel distribution, communications or logistics rarely remains isolated. Instead, disruption frequently cascades into healthcare, financial services, transportation, emergency response and wider economic activity.
Third, the incidents emphasise that resilience is as important as prevention. While no infrastructure can be guaranteed immune from attack, organisations that invest in cyber security, redundancy, incident response planning, staff training and business continuity recover more rapidly and minimise the wider societal impact of disruption.
Finally, these case studies highlight the importance of collaboration. Effective protection of Critical National Infrastructure depends upon close cooperation between government, infrastructure operators, cyber security agencies, law enforcement, international partners and an informed public.
The Ukraine electricity attacks, Estonia's cyber campaign, the Colonial Pipeline ransomware incident, the global NotPetya outbreak and the disruption to Viasat satellite communications collectively demonstrate the diverse methods by which modern infrastructure can be targeted. They also illustrate that cyber incidents are capable of producing real-world consequences affecting energy, communications, finance, transport and public confidence.
Household Emergency Preparedness
National resilience depends not only upon the protection of Critical National Infrastructure by government and industry, but also upon the preparedness of individual households and communities. While the United Kingdom maintains robust emergency planning arrangements and highly resilient public services, severe weather, infrastructure failures, cyber incidents or other emergencies may occasionally result in temporary disruption to essential services.
Preparing for such events should be viewed as a sensible and proportionate precaution rather than a response to an expectation of widespread crisis. Just as households maintain smoke alarms, home insurance and basic first aid supplies, keeping a modest reserve of essential items can reduce inconvenience and help families remain self-sufficient during short-term disruptions.
Most emergencies experienced within the United Kingdom are localised and resolved within hours or days. Nevertheless, incidents affecting electricity, telecommunications, transport, water or fuel distribution may have cascading effects that temporarily reduce access to everyday services. Households that have considered these possibilities in advance are generally better placed to respond calmly and support their families without placing unnecessary demand upon emergency services.
Preparedness also contributes to wider community resilience. When individuals are able to meet their own immediate needs for a limited period, emergency responders can prioritise assistance for those who are most vulnerable or directly affected by an incident.
Principles of Household Preparedness
Effective preparedness is based upon three simple principles:
Be informed by understanding local risks and knowing where to obtain reliable official information during an emergency.
Be prepared by maintaining a modest supply of essential items required for several days.
Have a plan so that all members of the household know what to do if communications, electricity or transport are disrupted.
Preparedness should be practical, affordable and tailored to the circumstances of each household. Factors such as the number of occupants, age, medical needs, mobility, pets and local geography will influence individual requirements.
Importantly, preparedness should not involve excessive stockpiling. Maintaining reasonable quantities of essential supplies is sufficient for most foreseeable short-term disruptions and helps avoid placing unnecessary pressure on retailers or supply chains.
Water
Access to safe drinking water is one of the highest priorities during any emergency.
Households should consider maintaining sufficient drinking water for at least three days, allowing approximately two to three litres per person per day for drinking. Where practical, additional water may be stored for basic hygiene, food preparation and sanitation.
Water should be stored in clean, food-grade containers and replaced periodically in accordance with the manufacturer's recommendations. Commercially bottled water generally provides the simplest and most reliable option for emergency storage.
During water supply interruptions, households should follow advice issued by local water companies or public health authorities regarding the safety of tap water and any precautionary measures such as boil water notices.
Food
A modest supply of long-life food enables households to remain comfortable during temporary disruption.
Suitable foods include canned goods, dried foods, pasta, rice, cereals, long-life milk, powdered milk, crackers, nuts, energy bars and other products that require little or no refrigeration. Where cooking facilities may be unavailable, households should include foods that can be eaten without heating or require only minimal preparation.
Consideration should also be given to dietary requirements, food allergies and the nutritional needs of children, older adults and individuals with medical conditions.
Food stocks should be incorporated into normal household consumption and replaced before expiry to minimise waste.
Receiving Information
Reliable information is essential during emergencies.
Power failures or telecommunications disruption may limit access to television, internet services or mobile communications. For this reason, households should consider keeping a battery-powered or wind-up radio capable of receiving national and local broadcasts.
Radio remains one of the most resilient methods of distributing official information during widespread infrastructure disruption and may continue operating when other communications systems are unavailable.
Where possible, households should also ensure that mobile phones remain charged and that portable power banks are available to extend battery life during prolonged outages.
Official information should always be obtained from government agencies, emergency services, local authorities and recognised broadcasters rather than relying upon unverified information circulated through social media.
Lighting and Power
Electricity interruptions may occur during severe weather, infrastructure failures or maintenance incidents.
Households should keep one or more reliable torches readily available together with sufficient spare batteries. Battery-powered LED torches generally provide efficient and long-lasting illumination.
Portable power banks may be used to recharge mobile phones and other small electronic devices when mains electricity is unavailable. These should be charged periodically to ensure they remain ready for use.
Candles should only be used with appropriate caution due to the risk of fire. Where candles or matches are kept, they should be stored safely, used only when necessary and never left unattended.
First Aid and Medicines
Every household should maintain a well-stocked first aid kit suitable for managing minor injuries until professional medical assistance is available if required.
The kit should contain items appropriate to the household's needs and should be checked regularly to ensure that sterile products and medications remain within their expiry dates.
Individuals who rely upon prescription medicines should ensure that they maintain an appropriate supply in accordance with advice from their healthcare professional. Medical devices, spare batteries for essential equipment and copies of prescriptions may also be valuable during periods of disruption.
Anyone requiring electrically powered medical equipment should consider discussing contingency arrangements with their healthcare provider and electricity supplier where appropriate.
Warmth and Shelter
Power outages during colder weather may reduce heating availability.
Households should keep warm clothing, blankets and suitable bedding readily accessible. Layering clothing is generally more effective than relying upon a single heavy garment and helps retain body heat if indoor temperatures fall.
Where practical, families may choose to remain together in one heated room to conserve warmth should heating systems become temporarily unavailable.
Hygiene and Sanitation
Basic hygiene contributes significantly to health and wellbeing during emergencies.
Households should consider maintaining a modest supply of toiletries, soap, toothpaste, sanitary products, tissues, disposable bags, cleaning materials and other everyday hygiene items.
If water supplies are affected, careful management of available water and adherence to official public health guidance become particularly important.
Essential Household Equipment
A number of inexpensive household items can prove valuable during temporary disruption.
Recommended equipment includes:
A manual can opener for opening canned food without electricity.
Basic household tools for minor repairs.
Waterproof matches or a lighter stored safely.
Reusable water containers.
Spare charging cables for essential electronic devices.
Pen and paper for recording important information if electronic devices are unavailable.
These items require little storage space yet may significantly improve comfort and self-sufficiency during an emergency.
Important Documents
Households should retain copies of important documents in waterproof packaging or other secure storage.
Examples include identification documents, insurance information, emergency contact numbers, details of medical conditions, prescription information and important financial records.
Digital copies stored securely in encrypted cloud storage may provide additional resilience, although paper copies remain useful if internet access is unavailable.
Cash and Financial Preparedness
Electronic payment systems are highly resilient and should continue to be used under normal circumstances.
However, temporary disruption affecting banking or telecommunications may occasionally limit access to electronic payments or cash machines. Maintaining a modest amount of cash at home can provide additional flexibility for purchasing essential goods during short-term outages.
The amount should reflect normal household requirements for a limited period rather than representing a substitute for conventional banking services.
Cash should be stored securely alongside other important household documents.
Pets and Vulnerable Household Members
Emergency planning should account for the needs of every member of the household, including pets.
Owners should ensure that adequate pet food, drinking water, medications and essential supplies are available for several days. Veterinary contact information should also be readily accessible.
Households with infants, older adults or individuals with disabilities should consider additional requirements such as infant formula, nappies, mobility equipment, specialist medical supplies or dietary needs.
Neighbours, relatives and community organisations can also play an important role in supporting vulnerable individuals during emergencies.
Family Emergency Planning
Preparedness extends beyond physical supplies.
Families should discuss how they would communicate if mobile networks became unavailable, identify alternative meeting locations if separated and ensure that everyone understands basic emergency procedures.
Emergency contact numbers should be written down rather than stored solely on mobile phones, and children should know how to seek assistance from trusted adults or emergency services if necessary.
Simple planning undertaken in advance can significantly reduce anxiety and improve decision-making during unexpected events.
Community Resilience
Strong communities recover more effectively from emergencies than isolated individuals.
Knowing neighbours, participating in local community networks and checking on elderly or vulnerable residents during periods of disruption can greatly improve local resilience.
Volunteer organisations, local resilience forums, charities and emergency services all contribute to community preparedness. Individual households therefore form part of a wider network that supports national resilience.
Household preparedness is a practical and proportionate element of national resilience. Preparing for temporary disruption does not imply that major emergencies are expected; rather, it recognises that unforeseen events occasionally occur and that modest preparation can substantially reduce their impact on individuals and families.
Maintaining a small reserve of drinking water, long-life food, basic medical supplies, lighting, communications equipment and other essential household items enables families to remain comfortable and self-sufficient during short-term interruptions to critical services. Combined with a simple household emergency plan and an understanding of where to obtain reliable official information, these measures strengthen both personal resilience and the resilience of the wider community.
Ultimately, resilient communities are built through shared responsibility. Government, infrastructure operators, emergency services, businesses and individual citizens each play a role in ensuring that the United Kingdom remains prepared to respond effectively to future emergencies while maintaining confidence in the systems that support everyday life.
Download the full white paper report here




Comments