Securing Critical National Infrastructure

Bridging the operability gap 

15th September 2026 • Online

In an increasingly hostile attack environment, CNI operators need a practical blueprint for 'good enough'

 

Tough times for the world's most targeted sector 

According to a March 2026 Research Report into the state of UK CNI: 

•    93% of CNI organisations experienced a cyber attack in the past 12 months
•    Regulation is now the #1 motivator for maturing cyber security programmes
•    Al-related cyber risk has entered the top five cyber challenges for the first time
•    Cloud environments are now the most common attack entry point
•    Legacy OT and outdated systems drive a significant proportion of successful breaches

And it's not simply attacks. The top impacts came in the form of IT outages (50%), operational disruption (34%), and revenue / data loss (31%). 
The good news- and in a sense the bad news too- is that attack sophistication is not the issue The top attack vectors are still phishing/BEC, DDoS, and straightforward malware infiltration, with Cloud a key attack vector. 

The causes too are familiar: poor patching hygiene {34%), poor monitoring (35%), lack of skilled personnel {38%). And, of course, in a sector that build infrastructure to last decades, "legacy" technology doesn't mean obsolete computers, it means physical plant that cannot simply be replaced like an out of date iPad. 

The foundational failing is still visibility: only 29% have centralised asset visibility. And it's hard to defend what you cannot see. 

The sector is also making the same mistakes with Al as with previous technology revolutions - adopt first, secure later. (Though it is not alone in this).

Finally, regulation has become the dominant force shaping cybersecurity investment in CNI, with 35% of organisations now citing it as the primary driver of cyber maturity-a sharp year-on-year increase. Adoption of key frameworks such as CAF and NIS2 is rising, but remains uneven, with only 46% reporting compliance with CAF and just 29% with NIS2. But only 35% of organisations believe regulation is delivering security in practice. 

So what does all this imply for CISOs and their vendors? 

It means that CNI doesn't need more tools or fancier tools unless those tools deliver real visibility, real resilience and the ability to deploy them at scale in the real-world in which CNI operates. 

It means that there is budget for regulatory and Al-driven initiatives but that these need to be more focused on delivering actual security and resilience and not just compliance or fancy dashboards. 

And it means CNI operators need partners. They need help from their peers. And they need a trusted space to find them. That's why we are running the e-Crime & Cybersecurity Manufacturing Summit. 

 

The e-Crime & Cybersecurity CNI Summit will take place on line and will look at how cybersecurity teams are tackling these challenges. Join our real-life case studies and in-depth technical sessions and help make manufacturing secure. 

 

The themes of this summit are:

Achieving visibility across ecosystems 
From exposed initial access points such as warehouse management systems to complex machine control software, simply understanding your device and application landscape is a huge challenge. Can you help with asset tracking and endpoint visibility? And what about anomaly detection after that? 

Transitioning OT to the Cloud? 
OT traditionally was localized in particular sites and air-gapped from IT systems. But connectivity with broader corporate networks and the need to manage technology more centrally (especially during COVID) has seen companies looking at managed services in the Cloud for OT. Is this a way forward? Or does the Cloud just create more problems? 

Defending against the latest ransomware variants 
Ransomware is effective precisely because it can exploit whatever weaknesses exist in your security architecture and processes. The threat and the actors are constantly evolving and that evolution is forcing the hands of government and causing havoc in the insurance market. What can CISOs do to better defend against ransomware? 

OT and the regulations 
DORA, NIS2 and other regulations put more responsibility for resilience on firms deemed important or critical. Many have focused on IT networks but the regulations include all resilience and so OT environments matter. What does this new emphasis from mean practically for OT security? 

Why zero trust, isolation and segmentation are key 
There has been a shift in recent attacks away form the theft of data- now threat actors are concerned with interrupting all operation activity. It is now critical that business functions are separated, and that internet access to OT networks is limited. Can security teams still keep up with sophisticated foes? Should they upgrade their capabilities? 

Pen testing for OT/ SCADA 
Testing is key to identifying and fixing vulnerabilities before they're exploited. Regulations like NERC CIP require utilities to assess and mitigate risk. Testing checks OT security controls are functioning properly shows regulators an organization's commitment to security. But what what kind of testing works best? How frequent should it be? Who should do it? 

Making the best use of threat intelligence 
In a preemptive security model, timing is everything - success depends on detecting and neutralizing threats before they become active incidents. To do this, security operations can't just rely on internal telemetry (e.g., endpoint or network logs). They need external, real-time context about emerging threats - where do they get it? 

Security Posture Management 
Traditional vulnerability scanners don't handle cloud native architectures well. Today's cloud environments spin up thousands of ephemeral assets without a traditional OS, without an IP address for long. So how do you adapt to that dynamic, APl-driven reality? How can traditional tools connect the dots - not just generate tickets? 

Improving continuous attack surface discovery 
You need to know what attackers can see and what they can actually attack - and you need it on a continuous basis, not in some static inventory. Ideally you also need assets ranked by risk priority and put into the current threat and vulnerability context. Is this feasible and is it cost effective? 

The power of automation 
There's too much manual intervention in security. SOAR pulls data from SIEMs, EDRs, firewalls, cloud APls, ticketing systems threat intelligence feeds, and even email servers and coordinates actions across tools via APls and prebuilt integrations and intelligent playbooks. Well, that's the theory. How does it work in the real world? 

Adversary simulation and behavioural analysis 
Automated adversary simulation Identifies telemetry blind spots. They provide prioritized remediation guidance and control effectiveness metrics. They track progress trends and validate security ROls as well as providing board and audit reporting. How well do they work in practice? 

Dealing with regulations 
CISOs now must build a single coherent security program that simultaneously satisfies divergent regulatory demands; they must interpret vague legal standards into technical architectures, and they risk non-compliance if auditors, regulators, or courts interpret differently later; they face unrealistic expectations around incident reporting; and they face personal liability. Can RegTech help? 

  • Achieving visibility across ecosystems

    • From exposed initial access points such as warehouse management systems to complex machine control software, simply understanding your device and application landscape is a huge challenge. 
    • Can you help with asset tracking and endpoint visibility? 
    • And what about anomaly detection after that? 
  • Transitioning OT to the Cloud?

    • OT traditionally was localized in particular sites and air-gapped from IT systems.
    • But connectivity with broader corporate networks and the need to manage technology more centrally (especially during COVID) has seen companies looking at managed services in the Cloud for OT.
    • Is this a way forward?
  • Defending against the latest ransomware variants

    • Ransomware is effective precisely because it can exploit whatever weaknesses exist in your security architecture and processes
    • The threat and the actors are constantly evolving, and that evolution is forcing the hand of the government and causing havoc in the insurance market
    • What can CISOs do to better defend against ransomware?
  • OT and the regulations

    • DORA, NIS2 and other regulations put more responsibility for resilience on firms deemed important or critical.
    • Many have focused on IT networks but the regulations include all resilience and so OT environments matter. 
    • What does this new emphasis from regulators mean practically for OT security?
  • Why zero trust, isolation and segmentation are key

    • There has been a shift in recent attacks away from the theft of data – now threat actors are concerned with interrupting all operation activity.
    • It is now critical that business functions are separated, and that internet access to OT networks is limited.
    • Can security teams keep up with sophisticated foes? 
  • Pen testing for OT / SCADA

    • Testing is key to identifying and fixing vulnerabilities before they're exploited. 
    • Regulations like NERC CIP require utilities to assess and mitigate risk. 
    • Testing checks OT security controls are functioning properly and shows regulators an organization's commitment to security. Can you help?
  • Making the best use of threat intelligence

    • In a pre-emptive security model, timing is everything — success depends on detecting and neutralizing threats before they become active incidents.
    • To do this, security operations can't just rely on internal telemetry (e.g., endpoint or network logs).
    • They need external, real-time context about emerging threats — where do they get it?
  • Security Posture Management

    • Traditional vulnerability scanners don’t handle cloud native architectures well.
    • Today’s cloud environments spin up thousands of ephemeral assets without a traditional OS, without an IP address for long.
    • So how do you adapt to that dynamic, API-driven reality? How can traditional tools connect the dots – not just generate tickets?
  • Improving continuous attack surface discovery

    • You need to know what attackers can see and what they can actually attack – and you need it on a continuous basis, not in some static inventory.
    • Ideally you also need assets ranked by risk priority and put into the current threat and vulnerability context.
    • Is this feasible and is it cost effective?
  • The power of automation

    • There’s too much manual intervention in security. SOAR pulls data from SIEMs, EDRs, firewalls, cloud APIs, ticketing systems, threat intelligence feeds, and even email servers.
    • It also coordinates actions across tools via APIs and prebuilt integrations and intelligent playbooks.
    • Well, that’s the theory. How does it work in the real world?
  • Adversary simulation and behavioural analysis

    • Automated adversary simulation identifies telemetry blind spots.
    • They provide prioritized remediation guidance and control effectiveness metrics. They track progress trends and validate security ROIs as well as providing board and audit reporting.
    • How well do they work in practice?
  • Dealing with regulations

    • CISOs now must build a single coherent security program that simultaneously satisfies divergent regulatory demands.
    • They must interpret vague legal standards into technical architectures, and they risk non-compliance if auditors, regulators, or courts interpret those differently later.
    • They face unrealistic expectations around incident reporting and they face personal liability. Can RegTech help?

Who attends

Job titles

PCI Manager
Senior Internal Auditor
Payments Design Authority
OT Security Analyst
CIO
Chief Information Security Officer
Information Security Engineering Principal - Head of Technical IS Assurance & GRC Platforms
GRC Manager
Programme Manager
Director of Financial Operations
Cyber Security Analyst
OT Technical Director
InfoSec Manager - Digital Investigations & Forensics
Principle InfoSec Architect
Global PCI Analyst
Head of Security Architecture
Lead Security & Compliance
Information Security Officer
Security Assurance Analyst
Head of Information Security
IT Compliance Manager
IPR Manager - Data and Technology
Group CISO
Principle Security Engineer
Senior Project Manager
I.T. Security Manager
Security Eng
Security Programme Manager
Security Training and Awareness Manager
Head of Client Onboarding
Lead Enterprise Security Architect
Information Security Specialist
Information Security Operational Analyst
Information Security Manager
Senior Information Security Officer
Group Chief Information Security Officer
Head of Detection and Response
Cyber Intelligence Specialist
Operational Audit Manager
Group CISO - Interim
Information Security Analyst
Global Head of Security Architecture
MD
Head of Cyber Security
Group Information Security Manager
Divisional Information Security Officer
IT
Information Security Analyst
Cyber Security Manager - ‪Penetration Testing
Senior Security Engineering Manager
Director of Information Security
Business Professional
Cyber Security Manager
Head of Technology & Payments
Chief Risk Officer
Information Security Risk & Assurance Specialist
Cyber Security Analyst
Cybersecurity Architect
Manager, GMS Europe
Cyber Compliance Analyst
Senior Cyber Security Consultant
Senior Security Product Manager
Product Manager
Finance Project Manager
Compliance and Security Analyst
Data Protection Administrator
SOC Analyst
Group Head of Security Engineering and Product Security
Vice President Cyber Security
IS Security Support Engineer
Payments Strategy Associate
Cyber Security Consultant
Head of Information Security Assurance
Head of Information Security
Director of Information Security
Senior Security Manager
Senior Information Security Manager
Data Protection/Cyber Security Manager
IT Security Manager
Payment Security Manager
Compliance and Audit Manager
Card Systems Specialist
Information Security Consultant
Senior GRC Operations Analyst
Information Security Manager
Cyber Security Risk and Compliance
Payment Operations and Assurance Manager
Security Operations Lead
Information Security Manager
Cyber Intelligence Specialist
Lead Cyber Authority
IT Security Manager
Digital Safety Compliance Analyst
Information Security Manager
IT Compliance Manager
SOC Manager
Group Application Security Manager
Head of Data Protection and Privacy
Cyber Security - OT Security Product Manager
Information Security Risk & Assurance Specialist
Cyber Security Change Manager
Head of IT Compliance
Information Security Analyst
Information security Manager
IT Risk and Compliance Analyst
Head of Group Management Services Europe
Cybersecurity Security
Cybersecurity Manager
Cyber Security Operations Lead
Team Lead, Card Systems UK and Ireland
PCI DSS Compliance Lead
Senior Cyber Security Analyst
Payments Acceptance Manager
Project Manager
Cyber Governance Consultant
Head of Security Risk, Assurance & Compliance
Assistant Manager Internal Audit
Assistant Manager Internal Audit
Group Data Protection Officer
Senior Manager Information Security
Head of Cyber Regulation and Policy
Domain Architect-Payments
Head of Cyber Development and Assurance
Cyber Compliance Analyst
Group Data Protection Administrator
CISO
Head of Data Engineering & Data Platform
Payments Compliance Product Owner
Senior Manager-Cyber Security
Director of Security Strategy and Governance, Risk & Compliance
IPR Analyst
Senior Infrastructure Security Architect
Information Security Manager
Director of IT
Payment solution designer
Cloud Security Threat & Vulnerability Specialist
Internal Audit Manager
Editor
Head of Global Cyber Security
Cyber Security Analyst
Cyber risk and compliance analyst
IS/IT Audit Manager
UK Security Operations Manager
Product Manager (Compliance Frameworks)
Platform Security Manager
Global PCI Lead
Cyber Security Architect
Digital Safety Compliance Manager
Cyber Security Manager
Global Head of Cyber Governance, Risk and Control
Lead Security Architect
Security Compliance Manager
Head of Information Security Services
Cyber Security Manager
Director, Security Operations
Information Security Risk and Assurance Specialist
Associate Director
Cybersecurity
Head of Security and Compliance
Head of DevOps
CISO
Principal Cloud Security Engineer
Chief Information Security Officer
Cyber Risk & Assurance Manager
Head of Security Data Science
Information Security Manager
Project Manager - Cyber Security
Head of Information Security
Cyber Security Analyst
Identity and Security Analyst
Security Consultant
Solution Architect - PCI

Companies

EasyJet
Formula 1
Vodafone
BT
Pennon Group
Ocado
Which?
Brambles Industries
Hutchison 3G UK Ltd t/as Three UK
Tata Communications
Sky
IMG Media Limited
Wejo
Which?
Virgin Media O2
Trainline
Heathrow
Pearson
BP
Sky
BBC
Network Rail
Toyota PLC
Vodafone
Post Office
BP
Sky
Virgin Media O2
EasyJet
A.P. Moller - Maersk
South Western Railway
British Car Auctions (BCA)
Hutchison Whampoa (Europe) Limited
Manchester Airports Group (MAG)
National Highways
Hutchison 3G UK Ltd t/as Three UK
Sky
Informa
Pearson
BBC
The Walt Disney Company
Hutchison Whampoa (Europe) Limited
National Grid
BT
Wessex Water plc
Valero Energy Corporation
Virgin Media
Sky
SSEN Transmission
RATP Dev
Virgin Media O2
BP
Pearson
Sky
BBC
Cadent Gas
National Grid
Constellation Automotive Group
DPD (UK)
BP
Informa
Transport for Greater Manchester (TfGM)
Associated British Ports
Network Rail
Rail Delivery Group
Informa
Transport for London (TfL)
International Airlines Group (IAG)
BT
Sky
BBC
OVO Group
British Airways
Tesco Mobile
Contact Centre Panel
Communisis
Hutchison 3G UK Ltd t/as Three UK
Aston Martin Lagonda Limited
OVO Group
Virgin Media O2
Sky
Ocado
Reward Gateway
Hutchison 3G UK Ltd t/as Three UK
Rail Delivery Group
DHL
North Sea Transition Authority
Vodafone
South Western Railway
Sky
BT
British Car Auctions (BCA)
Toyota PLC
Manchester Airports Group (MAG)
Transport for London (TfL)
Trainline
BBC
Post Office
Scottish Water
UK Power Networks
Trainline
Hutchison Whampoa (Europe) Limited
Pearson
ETEL (European Tyre Enterprise Ltd)
Sky
Virgin Media O2
BP
Vodafone
Hutchison 3G UK Ltd t/as Three UK
TieTa
WPP Group
Giffgaff
Avanti West Coast
M&C Saatchi Ltd
Formula 1
The AA
OVO Group
Cadent Gas
Sky
Arriva Group
Associated British Ports
Delinian Limited
Alesther
Springer Nature
Ocado
Delinian Limited
Telia Company
M&C Saatchi Ltd
Sky
Hutchison Whampoa (Europe) Limited
British Airways
Valero Energy Corporation
Virgin Media O2
BT
FedEx
Transport for Greater Manchester (TfGM)
ETEL (European Tyre Enterprise Ltd)
Constellation Automotive Group
Hutchison Whampoa (Europe) Limited
Financial Times (FT)
Communisis
Pearson
A.P. Moller - Maersk
Vodafone
Heathrow
British Airways
Woven by Toyota
Sky
ETEL (European Tyre Enterprise Ltd)
Transport for London (TfL)
Pearson
Trainline
TieTa
Vodafone
Post Office
Liberty Global
Virtually Informed
Condé Nast
Cadent Gas
Manchester Airports Group (MAG)
WPP Group
Sky
Taylor & Francis Group
Pearson
BP
Virgin Media O2
Vodafone
Hutchison Whampoa (Europe) Limited
BBC
Penguin Random House
British Airways
Sky

Employee Size

10,000+
10,000+
10,000+
1000-1999
10,000+
10,000+
10,000+
10,000+
10,000+
10,000+
5000-9999
10,000+
10,000+
10,000+
10,000+
10,000+
500-999
3000-4999
10,000+
100-499
10,000+
10,000+
10,000+
10,000+
10,000+
10,000+
10,000+
10,000+
5000-9999
100-499
10,000+
100-499
3000-4999
1000-1999
1000-1999
5000-9999
10,000+
5000-9999
10,000+
10,000+
3000-4999
1000-1999
1-99
10,000+
10,000+
1000-1999
10,000+
1000-1999
10,000+
10,000+
10,000+
10,000+
3000-4999
1-99
1000-1999
5000-9999
3000-4999
10,000+
10,000+
10,000+
10,000+
10,000+
10,000+
10,000+
500-999
3000-4999
10,000+
10,000+
1000-1999
10,000+
10,000+
10,000+
1000-1999
10,000+
500-999
5000-9999
100-499
10,000+
100-499
10,000+
2000-2999
10,000+
10,000+
1000-1999
500-999
5000-9999
10,000+
10,000+
10,000+
10,000+
10,000+
10,000+
5000-9999
10,000+
2000-2999
1000-1999
10,000+
5000-9999
10,000+
5000-9999
1000-1999
10,000+
10,000+
10,000+
10,000+
10,000+
10,000+
10,000+
1000-1999
10,000+
10,000+
10,000+
5000-9999
1000-1999
5000-9999
10,000+
10,000+
10,000+
3000-4999
10,000+
10,000+
10,000+
5000-9999
10,000+
3000-4999
10,000+
1000-1999
10,000+
10,000+
10,000+
10,000+
10,000+
10,000+
100-499
10,000+
5000-9999
10,000+
Jan-99
5000-9999
5000-9999
5000-9999
10,000+
1000-1999
3000-4999
10,000+
10,000+
10,000+
5000-9999
1000-1999
10,000+
10,000+
2000-2999
10,000+
500-999
10,000+
5000-9999
10,000+
10,000+
3000-4999
100-499
500-999
10,000+
10,000+
5000-9999
10,000+
10,000+
10,000+
10,000+
10,000+
500-999
10,000+
5000-9999