Skip to content
← Explore all topics

Critical Infrastructure & OT

Energy, water, ports, and industrial control systems — the operational technology that keeps the lights on.

37 briefings
The Pattern Hidden in Every Breach
Practitioner OperationsJuly 24, 2026
The Pattern Hidden in Every Breach

Every major incident looks like its own story - AI governance one week, an enterprise authentication bypass the next, then a banking malware campaign, a cloud migration, a nation-state compromise, a national blackout. Read enough of them and the same thing keeps surfacing underneath. The breach is rarely the beginning of the story; the beginning is almost always an assumption that had never been tested. Storm-0558 exposed the assumption that a consumer signing key could never authenticate an enterprise account. ServiceNow, that the platform holding the map of every system deserved less scrutiny than the systems. Kimi K3, that self-hosting a model resolves the trust question. The Iberian blackout, that transparency and operational security are the same objective. FASTCash, that banks on shared payment rails carry risk independently. The subject of the analysis is not the technology - it is the widening distance between what organisations believe about their systems and how those systems actually behave under pressure, which may be one of the most important attack surfaces in modern security.

The War Has a Fifth Front, and It Runs Through Your Water Treatment Plant
Chokepoint DoctrineJuly 24, 2026
The War Has a Fifth Front, and It Runs Through Your Water Treatment Plant

AA26-097A's 22 July update added a seventh agency and, more importantly, moved the CyberAv3ngers campaign off Israeli-made Unitronics controllers onto the Western-made Rockwell, Siemens, and Schneider systems that run the industrial base. The mechanism — making a plant's control screen lie to its operator — this desk documented in April. The escalation, from a symbol to the backbone, is the story.

When the Sky Stopped Being Neutral
Chokepoint DoctrineJuly 23, 2026
When the Sky Stopped Being Neutral

Iran's defection from GPS to China's BeiDou, a stalked Finnish satellite over Ukraine, and a NATO assessment of an orbital shrapnel weapon are three signals of one shift: positioning, navigation, and timing has stopped being a neutral utility and become a contested chokepoint — and the law, the insurance market, and every GPS-dependent economy have no answer for it yet. Part I of two.

Every Company Is China-Free. The Refinery Says Otherwise.
Chokepoint DoctrineJuly 10, 2026
Every Company Is China-Free. The Refinery Says Otherwise.

Bloom Energy's CEO said it for years: no China supply chain. A short-seller says otherwise — but Bloom is a symptom, not the story. Concealing Chinese origin is now an industrial practice ($549M in aluminium as 'pallets'; tungsten laundered through Taiwan; Chinese magnets in the F-16, the F-18 and the F-35 three times over), because 'China-free' is worth a fortune and origin is structurally unverifiable. The deeper move: China controls these inputs by export licence, not ban — and every licence forces disclosure of the end user. Beijing holds a more accurate map of American critical dependencies than America's own regulators do. My assessment of the real risk, and where it goes in a Taiwan crisis.

The Shadow of the Future — Q2 2026 Special Report
Special ReportJuly 8, 2026
The Shadow of the Future — Q2 2026 Special Report

Our Q2 2026 Special Report. Robert Axelrod showed cooperation among rivals survives only where four conditions hold - a long shadow of the future, clear signals, enforceable reciprocity, and legible reputation. Across every domain we cover - chokepoints, ransomware, cyber attribution, the AI race, the quantum transition, digital identity, and the dollar itself - the security environment is systematically destroying those four conditions. The report scores seven games on one board, asks whose game we are actually in (China's Go, Russia's reflexive control, the West's chess), names the Defection Premium as the largest unpriced liability on the balance sheet, and grades our own Q2 forecasts in the open. Read the interactive report or download the 67-page PDF.

The MOU Is Dead. The Series Called It.
Chokepoint DoctrineJune 28, 2026
The MOU Is Dead. The Series Called It.

Breaking update. Between 2 and 3am on 28 June 2026, Iran's IRGC launched ballistic missiles and drones at two US military facilities at once - the Ali Al Salem Air Base in Kuwait and the Fifth Fleet headquarters at Salman Port in Bahrain - claiming eight installations destroyed, after a second wave of US strikes on Iran. It is the end of a 48-hour collapse: the drone strike on the container ship Ever Lovely and the IMO's paused evacuation of 11,000 sailors on 25 June, a US strike on the 27th, Iran's drone hit on the tanker Kiku carrying 2 million barrels of crude, a second US strike, and Israel's approval of continued operations in southern Lebanon two days after a ceasefire. The Versailles MOU of 17 June is functionally dead. A week ago, in 'The War That Cannot End,' my assessment was that the MOU was as valid as its weakest enforcement node, and that the node was in Jerusalem. Four written judgments - the Lebanon tripwire, Netanyahu's electoral calendar, Iran's temporal asymmetry, and the resumption of tanker attacks - have now been confirmed in 48 hours. This is a fight over a shipping lane, and Iran is enforcing a claimed sovereignty over Hormuz with ballistic missiles. The MOU was the pause, not the settlement.

The New Munitions List
Chokepoint DoctrineJune 16, 2026
The New Munitions List

In the early 1990s, exporting strong cryptography from the United States was, legally, exporting a weapon. A T-shirt with RSA source code was a controlled export. Phil Zimmermann spent three years under US Customs investigation for publishing PGP. It took most of a decade — and Executive Order 13026 in November 1996 — to dismantle the regime. The signal, WhatsApp, Telegram, TLS, and every banking app on every phone exist in their current globally-available form because that restriction was eventually lifted. On Friday 12 June 2026, at 5:21pm ET, the same structural argument returned in a sharper form. A letter from the US government to Anthropic. Fable 5 and Mythos 5 suspended for any foreign national worldwide. The artefact has changed — from published math to hosted frontier model. The mechanism has changed — from court enforcement to a configuration flag at a single provider. The argument has not. The market consequence will not either. Whoever fills the gap during the restricted years keeps the customers after liberalisation. The companion historical-precedent piece to “The Export Control That Reached Inside the Model.”

The Export Control That Reached Inside the Model
Chokepoint DoctrineJune 15, 2026
The Export Control That Reached Inside the Model

At 5:21pm ET on Friday 12 June 2026, a US government letter directed Anthropic to suspend Fable 5 and Mythos 5 for any foreign national, anywhere in the world, including its own non-US employees. Anthropic complied within hours, in full, worldwide — while publicly dissenting from the action and stating that the underlying capability is freely available from competing models without restriction. Sixteen days earlier, the European Commission had published the Tech Sovereignty Package built for exactly this scenario. The letter is the first operational use of Export Control Classification Number 4E091, finalised in the BIS Framework for AI Diffusion on 15 January 2025 to cover frontier model weights trained on more than 10^26 computational operations. The pattern it completes — CLOUD Act 2018, Schrems II 2020, the chip rules 2022, the AI weight rule 2025, the ICC sanctions, the Solvinity block, the EU package, now this — is the ladder of US extraterritorial reach this series has been mapping. The new layer is cognition itself. With the eight-rung extraterritoriality timeline, the seven-region cognitive-dependency map, and the strategic read for EU, UK, India, China, Japan, Korea, Middle East, and Africa.

The Platform That Holds Every Key
Chokepoint DoctrineJune 12, 2026
The Platform That Holds Every Key

ServiceNow’s third authentication bypass in eight months — and the first where attackers reached customer data before a patch was applied. The June 2026 REST endpoint shipped with requires_authentication=false. IP 51.159.98.241 queried tenant tables on June 2–3. The patch landed silently on June 5. Public disclosure on June 9, gated behind a customer support login. October 2025 (BodySnatcher impersonation), January/February 2026 (AI sandbox RCE), and now this. Three components. Three mechanisms. One consistent root cause category. ServiceNow is the system the organisation tells everything to. In this framing, it is not the target — it is the map. The ITSM blind spot in enterprise security architecture, and the question every security team should be asking about every platform that knows about everything else.

Call Your Families. Say Goodbye.
Chokepoint DoctrineJune 2, 2026
Call Your Families. Say Goodbye.

On 27 April 2026 the Iranian MOIS cover group Handala (Storm-0842) sent personalised WhatsApp messages to US service members at Naval Support Activity Bahrain naming them by rank, unit, and personal phone number, and the next day published the claimed details of 2,379 named US Marines — home address, family, daily commute, shopping habits, nightly leisure. The data was not stolen. It was bought. This convergence article ties the DSI adtech surveillance piece, the connected vehicle piece, and the Handala profile from the Stryker article into a single argument: three commercial data streams, one mosaic, one targeting package, no breach.

The Cable Gap
Critical InfrastructureMay 21, 2026
The Cable Gap

An industry post circulating this week articulated an accurate diagnosis: the subsea cable sector is being asked to deliver 2030 capacity with a 2005 procurement model. The diagnosis is correct. The prescription is incomplete. The three-to-five-year MOU-to-RFS gap is not a market efficiency problem awaiting a market solution. It is a strategic vulnerability that adversaries have already mapped, exploited in active conflict, and that a state actor is systematically addressing through state-subsidised construction priced twenty to thirty percent below Western competitors. HMN Technologies (formerly Huawei Marine Networks) went from 11% market share in 2021 to 18% of global cables laid in the next four years. The Digital Silk Road's stated ambition is 60%. The private build trend the industry post celebrates as innovation is, in documented cases, going to HMN because Western alternatives cannot deliver on timeline or price. ZTT commenced construction of a new cable-laying vessel in August 2025. The 2030 cable infrastructure landscape will be the operational expression of choices being made over the next thirty-six months.

The Nigerian Banking Sector Under Siege: What the 2026 Incident Pattern Tells Security Leaders
Threat AssessmentMay 21, 2026
The Nigerian Banking Sector Under Siege: What the 2026 Incident Pattern Tells Security Leaders

A Tier 1 Nigerian bank lost billions on a Friday evening. The institution did not report the breach to its peers. Within 48 hours, two other banks were compromised by the same group. This briefing examines what the 2026 incident pattern is telling CISOs in the Nigerian banking sector — and why individual-bank defence has stopped working.

The Inverted Field
Critical InfrastructureMay 20, 2026
The Inverted Field

Air gaps. No budget. Asset inventory first. One template across sectors. Information as the crown jewel. The five widely held OT security misconceptions share a common origin in the unconscious inheritance of IT security defaults by environments where the threat model is structurally inverted. In IT, information is the asset. In OT, information is the threat vector — and the operational integrity of the physical process is the crown jewel. The FrostyGoop incident of January 2024 took the heating off six hundred apartment buildings in Lviv during subzero wartime conditions because the OT environment was defended on IT defaults that the documented incident record had already invalidated. This piece walks the five misconceptions, names the inversion, and proposes the threat-driven architecture that NIS2 supervisory authorities have started to indicate produces the better enforcement outcomes — and the better operational ones.

The Ghost in Lake Chad
Power DynamicsMay 20, 2026
The Ghost in Lake Chad

On 16 May 2026, a joint US-Nigerian precision strike in Mitile killed Abu-Bilal al-Minuki, the second-in-command of the Islamic State. The same year, Nigeria recorded the highest Belt and Road Initiative construction volume on earth — $24.6 billion in Chinese contracts, up from $1.8 billion the year before. Tinubu's government is splitting its great-power dependencies by domain: the United States for intelligence and counterterrorism; China for railways, telecoms, and oil. The arrangement is being studied as the multipolar playbook for the Global South. The complication: the ghost the Eagle is hunting in Lake Chad is one the Eagle helped to birth — through CPA Order 2 in 2003, Camp Bucca, and the August 2012 DIA memo that predicted exactly the outcome it became.

When the Sky Goes Dark
Critical InfrastructureMay 20, 2026
When the Sky Goes Dark

Every business continuity plan contains assumptions so foundational they are never written down. GPS works. Satellites are up. The timing signal is accurate. The Iran war moved all four assumptions from the constants column to the variables column. This piece is the operational framework for the GPS timing audit your organisation has almost certainly never done, the Starlink paradox where your resilience measure becomes your single point of failure, the commercial earth observation dependency nobody has classified as critical, and the satellite ground station supply chain whose cybersecurity floor your continuity plan inherits without auditing.

The Search Query That Returns Two Catastrophes
Regulatory RiskMay 13, 2026
The Search Query That Returns Two Catastrophes

You type NIS2 into your regulatory database. It returns two results: the EU cybersecurity directive that just took effect in Sweden, and nickel disulfide — a Group 1 human carcinogen. If you work in Swedish chemical manufacturing, both are now your problem simultaneously, governed by three different regulators with no coordination between them. This is the governance gap where the incident happens.

The Human Stack: When Founders Become Strategic Assets
AI Risk AnalysisApril 28, 2026
The Human Stack: When Founders Become Strategic Assets

China blocks Meta's $2B acquisition of Manus AI and exit-bans its founders, establishing that technological nationality follows people, not incorporation documents. The AI control stack now extends from rare earths through chips and models to the human layer -- the one you cannot replicate.

Bit by Bit
Strategic AnalysisApril 22, 2026
Bit by Bit

On April 9, Finance Minister Smotrich described territorial expansion as state policy in two words. Ten days later, Argentina signed over water infrastructure to the expanding state's national utility. The pattern is not hidden. It does not need to be.

The Compliance Gap You Could Drive a Forklift Through: Why an $18 Billion Industry Still Can't Tell You If It Passes
Risk IntelligenceApril 20, 2026
The Compliance Gap You Could Drive a Forklift Through: Why an $18 Billion Industry Still Can't Tell You If It Passes

Jaguar Land Rover shut down for five weeks. Nucor halted steel production. Both made the same calculation: when you cannot prove IT/OT segmentation holds, you stop everything. An $18 billion monitoring industry can tell you what's on your network — but not whether it passes IEC 62443. This special report maps the gap between 160,000 newly regulated EU entities and the 33 certifications issued last year.

The Plumbing of the War Machine: How 33 Crates at Liège Exposed the Architecture That Keeps the Bombs Falling
Strategic AnalysisApril 16, 2026
The Plumbing of the War Machine: How 33 Crates at Liège Exposed the Architecture That Keeps the Bombs Falling

Belgian customs seized 33 crates of British military components bound for Israel at Liège Airport. The seizure exposed a logistics pipeline — from Wolverhampton factories to Challenge Airlines freighters — that has been moving weapons without permits or scrutiny. This is the architecture that keeps the bombs falling.

While You Were Reading This, Iran Was Already Inside
Chokepoint DoctrineApril 16, 2026
While You Were Reading This, Iran Was Already Inside

On April 7, six US agencies confirmed Iranian APT actors had disrupted PLCs across water, energy, and government systems. Over 700 flights experienced GPS spoofing. 1,100 vessels lost navigation in 24 hours. The EU's NIS2 framework is still being transposed. CISA has been cut by $707 million. Three crises. One structural failure.

The Boomerang of Hormuz
Strategic AnalysisApril 13, 2026
The Boomerang of Hormuz

A Soviet submarine missile, adapted by North Korean isolation, refined by Iranian persistence, guided by Chinese satellites, striking an American radar built to defend against exactly this scenario. In Part Four of the Strait of Hormuz series, Aimé Césaire's boomerang thesis meets the technology transfer pipeline that Western analysts spent decades pretending did not exist.

The Digital Blockade: Sixty Threat Groups and the Cyber War Behind the Strait of Hormuz
Infrastructure AnalysisApril 12, 2026
The Digital Blockade: Sixty Threat Groups and the Cyber War Behind the Strait of Hormuz

While the US Navy prepares to blockade the Strait of Hormuz with destroyers and carrier strike groups, Iran's cyber forces have already breached seventy-five industrial control systems across American critical infrastructure. The blockade runs on three fronts — physical, digital, and insurance. Two of them are already inside your network.

When the Bank Is the Target: How the Iran War Declared Open Season on the Financial Infrastructure the World Runs On
Chokepoint DoctrineApril 10, 2026
When the Bank Is the Target: How the Iran War Declared Open Season on the Financial Infrastructure the World Runs On

In 2012, Iran hit 46 US banks with 140 Gbps DDoS attacks in response to SWIFT sanctions. In March 2026, the IRGC publicly named US and Israeli-linked banks as military targets. Citi, Goldman, Standard Chartered, and HSBC evacuated Gulf offices. Sixty hacktivist groups are active. Handala deploys wiper malware that permanently destroys data. The Bangladesh Bank precedent shows 32 days to restore SWIFT access. AI-generated deepfakes target the human authentication layer above every technical control. The financial chokepoint is where a successful attack disrupts the trust architecture the entire global economy depends on.

The Breaker Box: Half of the Data Centres Planned for 2026 May Never Come Online
Critical InfrastructureApril 9, 2026
The Breaker Box: Half of the Data Centres Planned for 2026 May Never Come Online

Sixteen gigawatts of data centre capacity is scheduled to come online this year. Only five gigawatts is under construction. The transformer shortage, grid interconnection queues stretching to seven years, and a bipartisan revolt across American towns have created a bottleneck that no amount of capital can force open. The AI infrastructure buildout has hit the physical limits of the electrical grid — and the security implications of concentrated compute are already being tested by Iranian drones.

The Dashboard Is Lying: Iran, an Unpatchable Flaw, and the Next Phase of Industrial Sabotage
OT SecurityApril 9, 2026
The Dashboard Is Lying: Iran, an Unpatchable Flaw, and the Next Phase of Industrial Sabotage

Your HMI says everything is normal. It is not. Iranian-affiliated actors are exploiting an architectural vulnerability that Rockwell Automation admits cannot be patched — manipulating what operators see while physical processes drift. The joint advisory tells you to disconnect from the internet. It does not tell you what comes next.

The Port Is the Next Stryker: Why Maritime Operational Technology Is the Most Exposed Critical Infrastructure Nobody Is Defending
Chokepoint DoctrineApril 8, 2026
The Port Is the Next Stryker: Why Maritime Operational Technology Is the Most Exposed Critical Infrastructure Nobody Is Defending

The Iran war has removed the word 'crossfire' from the maritime threat model. The targeting is now direct. The port is no longer collateral damage — it is the target. PYROXENE is already inside the supply chain. Lab Dookhtegan has demonstrated fleet-scale impact. The IRGC has declared infrastructure warfare as doctrine. The sector that moves 80% of world trade has the lowest cybersecurity maturity of any comparably critical industry.

The Quiet Subsidy: How European Innovation Money Funds the Military Pipeline It Pretends Not to See
Power DynamicsMarch 29, 2026
The Quiet Subsidy: How European Innovation Money Funds the Military Pipeline It Pretends Not to See

Israel has received €395.7 million from the European Innovation Council Accelerator — more than twice Ireland’s €175.7 million. More than Italy. More than Belgium, Denmark, and most of the European Union. A non-EU country ranks fifth in capturing EU innovation funding, while defence contractors appear in “civilian” research programmes and a suspension vote fails because Hungary says no.

Barrels and Bytes: What the Energy Analysts Cannot See
Strategic AnalysisMarch 29, 2026
Barrels and Bytes: What the Energy Analysts Cannot See

The most-cited energy analyst in the world told you the global economy could collapse by May if Hormuz stays closed. He is right about the timeline. He is wrong about why. The crisis is not barrels — it is that every barrel now moves through infrastructure that is simultaneously physical and digital, kinetic and networked. And the invisible half is under attack.

The Data Centre Was Never a Bunker — How the Kinetic Envelope Changed Everything Europe Built Its Digital Future On
Critical InfrastructureMarch 27, 2026
The Data Centre Was Never a Bunker — How the Kinetic Envelope Changed Everything Europe Built Its Digital Future On

Iranian drones struck three AWS data centres in the UAE and Bahrain on March 1, 2026 — the first known physical attacks on data centres in history. The demonstrated 3,800km strike on Diego Garcia has placed every European data centre within a threat envelope that no risk model had previously contemplated. Europe built the sovereign cloud without building the sovereign defence around it.

Eight Seconds to Darkness: The Blackout Report That Accidentally Became an Attack Manual
Critical InfrastructureMarch 26, 2026
Eight Seconds to Darkness: The Blackout Report That Accidentally Became an Attack Manual

ENTSO-E published 472 pages of peer-reviewed engineering detail on the April 2025 Iberian blackout — the largest power failure in European history. The security community should be treating it like a threat actor whitepaper, because that is functionally what it is. The cascade physics, protection relay thresholds, and voltage control gaps are now public. The threat actors are already studying them.

The $2M Problem: Why Every Interceptor Fired Over the Gulf Is a Missile That Won't Be There for Taiwan
Critical InfrastructureMarch 25, 2026
The $2M Problem: Why Every Interceptor Fired Over the Gulf Is a Missile That Won't Be There for Taiwan

A $20K Shahed drone versus a $4.2M Patriot interceptor. A 200:1 cost ratio in the attacker's favour. US interceptor stocks at 25% of required levels, with no new THAAD deliveries until 2027. The defence economics of the Iran war are rewriting the strategic calculus from the Gulf to the Taiwan Strait.

The Weakest Link Was Never on the Map: How GRC Architecture Failed the Infrastructure It Was Built to Protect — and What Comes Next
Critical Infrastructure GovernanceMarch 23, 2026
The Weakest Link Was Never on the Map: How GRC Architecture Failed the Infrastructure It Was Built to Protect — and What Comes Next

The Chokepoint Doctrine. Subsea cable infrastructure does not fit cleanly into any existing critical infrastructure mechanism. It falls between sectors, belongs to no single agency, and has no Tier-1 classification — yet it carries 95% of intercontinental data. The Iran war arrived into that governance gap at the worst possible moment.

The Repair Crisis: Sixty Ships, Five Hundred Cables, and a Queue That Never Ends
Critical InfrastructureMarch 22, 2026
The Repair Crisis: Sixty Ships, Five Hundred Cables, and a Queue That Never Ends

Sixty ageing ships maintain 570 submarine cable systems carrying 95% of intercontinental data. When cables break in conflict zones, the queue for repair stretches from weeks into months — and the fleet is running out of time.

Who Fixes the Internet When the Repairmen Can't Get There?
Critical InfrastructureMarch 20, 2026
Who Fixes the Internet When the Repairmen Can't Get There?

The cable fleet is aging, the warzones are expanding, and the $2.2 trillion AI bet is sitting on top of a repair problem nobody budgeted to solve. Sixty ships service 1.48 million kilometres of submarine cable. Four companies control the entire fleet.

The Floor of the Ocean Is the New Front Line: How the Iran War Put the Internet Itself at Risk
Critical InfrastructureMarch 19, 2026
The Floor of the Ocean Is the New Front Line: How the Iran War Put the Internet Itself at Risk

Seventeen submarine cables carry 30% of global internet traffic through the Persian Gulf. When Iran closed the Strait of Hormuz, it didn't just threaten oil — it threatened the physical infrastructure of the internet itself. The floor of the ocean is now a battlefield.

The Convergence: How State-Sponsored Cyber Operations Are Reshaping NATO's Eastern Flank Security Architecture
Featured AnalysisMarch 13, 2026
The Convergence: How State-Sponsored Cyber Operations Are Reshaping NATO's Eastern Flank Security Architecture

A comprehensive analysis of adversarial digital operations targeting critical infrastructure across NATO member states, the attribution challenges that complicate collective defense obligations, and the business risk implications for firms operating in affected corridors.