July 20, 2026
July 20, 2026
Joe Weiss argues that cyber-physical risk management in critical infrastructure cannot rely on network security alone. Although modern control systems increasingly use standard IT networking technologies, they are fundamentally different from ordinary IT systems because they directly monitor and control physical processes. Network security can reduce the likelihood of compromise, but it does not fully address the consequences of cyberattacks, equipment failures, sensor malfunctions or engineering errors once they affect real-world operations.
The article stresses that past control-system incidents across multiple sectors have caused equipment damage, environmental releases and deaths, showing the danger of treating cybersecurity mainly as a network problem. Weiss says cybersecurity teams are typically focused on preventing, detecting and responding to compromise, while engineering teams are better equipped to understand and reduce physical consequences. Effective protection of critical infrastructure therefore requires genuine collaboration between engineering and cybersecurity, not just technical convergence around networks.
Source: SCADA Magazine