Antonio Tejeda Encinas. President Euro-American Committee of Digital Law – CEA Digital Law
Most of us living in the Western world have had the tremendous privilege of being able to take for granted the workings of critical infrastructure. Clean water, reliable roads, high-quality healthcare, electricity, reliable telephones, and email are all so fundamental to modern existence that it is impossible to imagine life without them.
The advent of the internet has made critical infrastructure more complex, more interdependent, and therefore more fragile. We have become complacent in our reliance on critical infrastructure, but recent developments have been a rude awakening. It is now clear that cyberwarfare can have an impact on the physical world through attacks on critical infrastructure. The often vaguely understood interdependencies between critical infrastructure sectors pose a serious risk. A hit to one critical infrastructure sector could cause cascading second-order effects on other sectors, leading to a large-scale catastrophe that would spiral out of control.
Cyberattacks on critical infrastructure
Critical infrastructure consists of systems that have been considered fundamental to the functioning of a society and economy, such as energy, transportation, telecommunications, food and water supply, and vital health services. The disruption or destruction of critical infrastructure would have an immediate and direct impact on economic activity, daily life, and the safety of those affected.
The advancement of cyberweapons and hacker toolkits now allow malicious actors to attack critical infrastructure in ways that have an immediate and frightening effect on the physical world. In 2015, Ukraine was the target of a shocking cyberattack that managed to disable a portion of the nation’s power grid. The attack, believed to have been carried out by Russia, intentionally led to widespread blackouts for hundreds of thousands of people. Although the attack and similar incidents targeting Ukraine in the years that followed were only temporary disruptions, they provide ample evidence of the scale of the damage cyberattacks could inflict on critical infrastructure. Hospitals had to use pens and paper again during the attack.
Digital technology has made the world smaller, and critical infrastructure in Western nations is not safe from this new danger. The U.S. government has denounced Russia for infiltrating the country’s power grid and gaining remote access to the energy sector’s computer networks (U.S. Department of Homeland Security 2018). In 2017, the WannaCry ransomware epidemic disabled Britain’s National Health Service for several days, leading to the cancellation of 19,000 appointments. In Denmark, the headquarters of Maersk, responsible for around a fifth of the world’s shipping, was crippled by the NotPetya malware, leading to transport disruptions at port facilities around the world.
As a result of these events, cyberattacks on critical infrastructure have become a preeminent concern for national security.
What makes the potential consequences of a major cyberattack on critical infrastructure difficult to predict is the interdependence between various sectors. An attack on one sector could have indirect effects on the other sectors that depend on it. The transportation sector relies on the supply of electricity by the energy sector to power trains and traffic control systems, just as the energy sector relies on the timely delivery of fuel and other inputs through the transportation sector. Regarding the threat of remote infiltration, a working group of industry experts and government officials from MIT’s Internet Policy Research Initiative warned that no one currently understands the extent to which electricity generation is coupled with other sectors. and therefore, the risk of catastrophic macroeconomic failure in the event of a cyberattack is not adequately known. Coming to a proper understanding of the interdependence between critical infrastructure sectors is vital to fully appreciating the inherent risks.




