r/CPRE

▲ 1 r/CPRE+3 crossposts

What do you think about this latest news?

Assume Breach: If PLC Logic Can Be Manipulated, How Do We Prevent Physical Consequences?

In April 2026, the FBI, CISA, NSA, EPA, DOE, and U.S. Cyber Command issued a joint advisory warning that internet-connected operational technology (OT) devices, including Rockwell Automation/Allen-Bradley PLCs, were being actively exploited across multiple critical infrastructure sectors. The advisory was later updated to include Schneider Electric and Siemens PLCs, along with guidance for detecting malicious or unauthorized PLC project code.

Cybersecurity remains the first line of defense. Strong identity management, network segmentation, monitoring, and secure engineering practices are essential.

But what if we assume breach?
If an attacker can modify PLC logic or engineering project files, what additional engineering safeguards can prevent unsafe physical consequences?

Some examples:

  1. Independent physics-based validation of process commands.
  2. Process-aware controls that reject commands outside safe operating limits.
  3. Independent safety mechanisms that remain effective even if a PLC is compromised.
  4. Resilient architectures that maintain safe operations during cyber incidents.
  5. Digital twins or process models that continuously validate expected system behavior.

The objective isn’t just to recover after an attack—it’s to prevent a cyber incident from becoming a physical incident.

This is the problem space I believe Cyber Physical Resilience Engineering (r/CPRE) should address by integrating cybersecurity, control engineering, process safety, and operational resilience.

What additional engineering approaches do you think are needed to keep critical infrastructure operating safely when cyber defenses are bypassed?

Joint Cybersecurity Advisory (Official):
Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across U.S. Critical Infrastructure (AA26-097A)⁠ https://www.ic3.gov/CSA/2026/260407.pdf

reddit.com
u/kukap_ — 4 days ago
▲ 0 r/CPRE+5 crossposts

Why I Believe Cyber Physical Resilience Engineering (CPRE) Is the Next Frontier

Cybersecurity has matured significantly over the last three decades. Identity, Zero Trust, EDR, SIEM, threat intelligence, AI, and incident response have all made organizations more secure.

But critical infrastructure presents a different challenge.

If a corporate network is compromised, the impact is often measured in data, money, or downtime.
If a water treatment plant, power grid, or industrial control system is compromised, the consequences can become physical.

That led me to a simple question:
What if we designed critical infrastructure assuming cyber incidents will happen?

Instead of asking only “How do we stop attackers?”, we should also ask:
How do we keep water safe?
How do we keep electricity flowing?
How do we prevent unsafe physical states?
How do we recover while maintaining safe operations?

That is the motivation behind Cyber Physical Resilience Engineering (CPRE).

Cybersecurity remains essential. CPRE builds on that foundation by integrating engineering, operations, process safety, and resilience into the design and operation of critical infrastructure.

I’d love to hear your thoughts. What capabilities do you think are missing today?

reddit.com
u/kukap_ — 6 days ago
▲ 0 r/CPRE+2 crossposts

Is cybersecurity enough for critical infrastructure?

I've worked in cybersecurity for about 25 years. Over the last year, I've spent much more time with water utilities, power systems, and industrial control environments.

One thing keeps bothering me.

When something goes wrong in critical infrastructure, the real failure usually isn't the network, the firewall, or even the PLC.

It's things like:

  • Unsafe chemical dosing at a water treatment plant
  • Power instability or blackouts
  • Pumps or valves operating incorrectly leading to say water overflow
  • Operators no longer trusting the data they're seeing
  • Essential public services becoming unavailable

In other words, the real problem isn't that a computer was compromised.

The real problem is that a physical (e.g., electric, water, hospital etc.,) mission failed.

That made me wonder whether we're trying to solve an engineering problem using only cybersecurity thinking.

Over the past few months, I've been exploring a concept I'm calling Cyber-Physical Resilience Engineering (CPRE).

The basic idea is simple.

Instead of asking:

>

Start by asking:

>

Cybersecurity is still essential, but it becomes one part of a broader engineering discipline that also includes:

  • Operational Technology (OT/ICS)
  • Systems Engineering
  • Control Systems Engineering
  • Process Safety
  • Reliability Engineering
  • Resilience Engineering
  • Digital Twins
  • AI-assisted Operations

The goal isn't just preventing cyberattacks.

The goal is ensuring that drinking water remains safe, electricity stays on, transportation keeps moving, hospitals continue operating, and other critical services remain available, even under cyber, physical, or operational stress.

I'm not suggesting this replaces frameworks like NIST CSF, NIST SP 800-82, or IEC 62443. Those remain foundational.

I'm simply asking whether we've reached a point where protecting physical outcomes deserves its own engineering discipline.

I'm genuinely looking for feedback, not trying to promote a framework.

For those who work in or around critical infrastructure:

  • Does this describe a real gap you've experienced?
  • During incidents, did the hardest problems end up being cybersecurity, or engineering and operations?
  • If a discipline like Cyber-Physical Resilience Engineering existed, what capabilities would you expect it to add that don't exist today?

Some incidents that shaped my thinking:

• Oldsmar, Florida Water Treatment Facility (2021)
https://www.bbc.com/news/world-us-canada-55989843

• Colonial Pipeline Ransomware (2021)
https://www.cisa.gov/news-events/alerts/aa21-131a

• Muleshoe, Texas Water System Attack (2024)
https://www.govtech.com/security/overflowing-water-tank-linked-to-russian-cyber-attack

• CISA, EPA & FBI – Top Cyber Actions for Securing Water Systems
https://www.cisa.gov/news-events/alerts/2024/02/21/cisa-epa-and-fbi-release-top-cyber-actions-securing-water-systems

• Ukraine Power Grid Attack (2015)
https://www.cisa.gov/news-events/ics-alerts/IR-ALERT-H-16-056-01

I'd appreciate your thoughts, especially from people working in water, energy, manufacturing, transportation, healthcare, utilities, industrial automation, or engineering.

--------------------
If this resonates and you’d like to go deeper, we’re building r/CPRE as a focused community around Cyber‑Physical Resilience Engineering, bringing together cybersecurity folks, engineers, operators, researchers, students, and critical infrastructure leaders.

u/kukap_ — 9 days ago