
Joseph Carson at Delinea shares his insights into defending CNI from nation state threats and from the risks caused by technological change including a shift to the cloud
In recent years, Critical National Infrastructure (CNI) has become a frequent target of advanced persistent threats.
As CNI networks are expanding, they extend beyond the perimeter of existing security networks, often without proper due diligence. Shifting pre-existing control systems to the cloud whilst extending network access to third parties and Internet of Things (IoT) devices has blurred the boundaries between Information and Operational (IT and OT) technologies. Consequently, this has led to more vulnerabilities for threat actors to exploit.
Another threat to CNI is that of nation-state actors and state-supported organised criminal groups. Governments themselves often give these actors abundant resources and expertise to launch sophisticated cyber-attacks on their perceived adversaries. For example, this year, we’ve already seen several incidents of Russian state-backed ransomware groups targeting UK schools and US healthcare providers,and Microsoft’s latest research shows that 40% of all CNI attacks last year were carried out by nation-state actors.
So, in the face of these intense and complex challenges, how can CNI organisations proactively safeguard their networks?
Business leaders at CNI providers must first ask – where are the vulnerabilities mostly originating from? According to Forrester, privileged identities are one of the most vulnerable points for any cyber-attack, accounting for 80% of all security breaches.
"Privileged identities" were previously limited to individuals with elevated access, such as system administrators, who were responsible for overseeing and managing an IT infrastructure or enterprise-level software and hardware. However, today, almost every user is a privileged user and it is no longer about what changes they can make but what data they can access. Moreover, it’s common to find many users with far more privileged powers than they need for their roles. Overprivileged users are already a serious issue in most industries, but it becomes dangerously critical in CNI as a breach potentially carries a national impact.
The first step is to understand who has privileged access to systems, applications, code, infrastructure and data, and why. Nobody would give the keys to access a nuclear reactor to any employee working at their heating contractor. Yet on the digital side, large numbers of employees and third parties routinely have privileged access to critical systems and applications.
Further, privileged identities include not only people but also systems, devices, applications, code, and data. The rapid proliferation of remote working and cloud-based environments mean that an individual user is likely to use multiple different devices and accounts to access the organisational assets. Each of these devices has a separate unique identity, in terms of IP addresses, MAC addresses, credentials, network settings and so on.
Therefore, CNI organisations need to establish effective control, oversight and management over every aspect of an individual’s privileged identity that is used to digitally access their resources.
When trying to secure its privileged identities, organisations often make three common mistakes that eventually lead to dire consequences.
The first mistake is to think that once access has been granted, perhaps requiring Multi-Factor Authentication (MFA), there is no need for any further control. This creates more scope for threat actors, as they can laterally move across the entire network by compromising a single privileged account.
Instead, CNI organisations must implement a least privilege approach, where user access to applications and systems only allows them to perform the tasks for which it has been granted…
In any organisation, internal assets and systems have different levels of importance. A single user should not have over-privileged access to any resources that are not relevant to their subsequent roles. A least privilege approach secures critical assets by requiring users to perform additional levels of identification and authentication if they want to access assets outside of their administrative privileges.
The second mistake is having over-privileged third-party contractors. Organisations often provide third-parties with access to critical resources and assets for improving efficiency. However, this creates a wider attack path for threat actors, as they can compromise third-party networks and laterally escalate their privileges to compromise the core organisational assets.
Therefore, privileged access management (PAM) must be at the centre of an organisation’s security strategy, which must be based on Zero Trust strategy and the principle of least privilege. Policies should be defined and established to ensure any access is suspicious until it’s securely verified.
The third mistake is not strongly enforcing the organisation’s password policy. It might sound like an obvious statement, but organisations in different industries are still not strengthening their password policies across the board.
Security teams must be able to strictly manage a strong password policy and analyse all suspicious activities within their organisation also when third parties are involved, including contractors and suppliers. This is the means to achieve greater effectiveness in defending against continuous threats, whether they come from cyber-criminals or state actors.
The growing threat of cyber-attacks on critical national infrastructure is a serious concern that requires immediate attention. The OT systems that define so many CNI sectors were not designed for the fast-paced world of cyber-security. Gaining centralised visibility and implementing security functions such as role-based access control and MFA is extremely challenging without specialist tools.
Governments and organisations must act now to protect CNI before these gaps are exploited to carry out serious disruptive attacks. By implementing robust PAM solutions incorporated with the principle of least privilege access and a Zero Trust strategy, CNI organisations can ensure the continued functioning of essential services and the security of sensitive information.
Joseph Carson, Chief Security Scientist (CSS) and Advisory CISO at Delinea
Main image courtesy of iStockPhoto.com
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543