Security teams should assume breaches will happen and design for containment, not perfect prevention. That means tightening visibility across critical assets, segmenting high-value environments, and limiting how far an attacker can move once inside. In essential services, resilience depends on reducing blast radius, maintaining secure connectivity, and practicing response paths that keep core operations running under attack.
Why This Matters for Security Teams
When cyberattacks are paired with geopolitical conflict, the objective is often disruption rather than quiet compromise. Critical infrastructure operators face a mixed threat set that includes destructive malware, credential theft, pre-positioning, influence operations, and attacks against suppliers or remote access paths. Current guidance from CISA cyber threat advisories and the MITRE ATT&CK Enterprise Matrix shows that defenders need to prepare for persistence, lateral movement, and operational disruption at the same time.
The practical risk is that resilience gets treated as a continuity exercise after a major incident, instead of a core security design requirement. In essential services, a weak identity boundary, flat network, or overtrusted remote access path can turn a contained compromise into a wider outage. Security teams also have to account for fast-changing attacker tactics, including AI-assisted reconnaissance and social engineering, which is why the lessons in Anthropic’s first AI-orchestrated cyber espionage campaign report matter beyond the AI sector.
In practice, many security teams encounter resilience gaps only after a regional event has already exposed dependency failures, rather than through intentional stress testing.
How It Works in Practice
Resilience improves when defenders reduce the attacker’s freedom of movement and preserve essential services under degraded conditions. That means segmenting operational technology and business systems, enforcing strong authentication for administrative access, and ensuring that backups, recovery tooling, and incident communications are not reachable from the same trust zone as production. The control intent aligns well with NIST SP 800-53 Rev 5 Security and Privacy Controls, especially around access control, contingency planning, monitoring, and system integrity.
- Identify mission-essential services and define what “degraded but acceptable” operations look like.
- Separate administrative, user, vendor, and OT control paths so one compromise does not expose all tiers.
- Use allowlisted remote access, short-lived credentials, and strong device trust for privileged operators.
- Keep immutable backups and recovery keys offline or isolated from the same identity plane.
- Test incident playbooks with operators, not only security staff, so response decisions fit plant or service realities.
For threat-informed defence, map likely adversary actions to MITRE ATT&CK and prioritise detection on credential abuse, remote services, and destructive tooling. Where AI is being used by the attacker or defender, MITRE ATLAS adversarial AI threat matrix helps teams think about model manipulation, prompt injection, and AI-assisted reconnaissance as part of the broader campaign. In the EU context, EU NIS2 Directive reinforces the need for incident handling, supply chain vigilance, and resilience governance across essential and important entities.
These controls tend to break down when legacy OT, shared service accounts, and always-on vendor tunnels are still required for production continuity because the trust model is too coarse to contain a fast-moving intruder.
Common Variations and Edge Cases
Tighter resilience controls often increase operational overhead, requiring organisations to balance outage tolerance against speed, maintenance access, and restoration complexity. That tradeoff is real in utilities, transport, healthcare, and telecoms, where some systems cannot be patched or rebooted on demand. In those environments, current guidance suggests focusing on compensating controls such as segmented failover, manual override procedures, and independently validated recovery paths rather than assuming full hardening is always possible.
There is no universal standard for this yet on how much AI should be used in crisis response, but the safest pattern is to keep AI advisory, not autonomous, for high-consequence decisions. Where AI supports analysis, teams should validate outputs against authoritative telemetry and avoid letting generative tools directly alter access, routing, or safety settings. The ENISA Threat Landscape is useful here because it highlights how sector-specific dependency chains can amplify regional shocks.
For NHI governance, critical infrastructure operators should also review whether service identities, API keys, and automation tokens are part of the resilience plan. If those secrets are not rotated, scoped, and recoverable under incident conditions, restoration can fail even when the core systems are intact. That is why resilience planning now overlaps with identity security, not just network engineering.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK and OWASP Non-Human Identity Top 10 address the attack surface, NIST CSF 2.0 set the technical controls, and NIS2 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | RC.RP-1 | Recovery planning is central when services must keep running during active attacks. |
| MITRE ATT&CK | T1021 | Remote services are common paths for intrusion and propagation in critical environments. |
| NIS2 | NIS2 requires resilience, incident handling, and supply chain risk management for essential entities. | |
| OWASP Non-Human Identity Top 10 | Service identities and secrets must be governed so recovery works during conflict. |
Define and rehearse recovery playbooks that restore essential services under degraded conditions.
Related resources from NHI Mgmt Group
- How should security teams validate resilience in interconnected critical infrastructure?
- How should security teams apply identity security to critical infrastructure resilience and compliance?
- How should security teams improve cyber resilience when data visibility is incomplete?
- How should security teams use identity monitoring during geopolitical cyber escalation?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 27, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org