Executive Summary

BLUF: Europe’s southern energy and water systems face a growing hybrid risk in which the control-room display, the physical process and the operator’s authority can be deliberately separated.
The most consequential pathway may require neither malware nor a conventional network compromise.
Physical access, insider enablement, unauthorized mode changes and deceptive HMI (Human Machine Interface) states can produce operational ambiguity before defenders classify an incident as hostile.
Water scarcity increases the consequences of even limited disruption in Cyprus, Malta, Greece, Italy, Spain, Portugal and Türkiye.
Existing EU legislation correctly adopts an all-hazards model, but implementation can remain divided between cybersecurity, physical protection, engineering safety and contractor management.
The five-year outlook indicates rising exposure as legacy OT, remote maintenance, distributed generation, desalination and water-reuse infrastructure become more interconnected.
The decisive defensive capability is independent verification: operators must be able to compare HMI representations with trusted field telemetry, process physics, physical-access records and authenticated operating states.
The interactive model below is a transparent scenario instrument, not a forecast of any specific installation.

Europe’s Invisible Infrastructure Threat: When the Control Room No Longer Shows Reality

Europe has fortified critical infrastructure against malware, ransomware and remote intrusion. Its next vulnerability may be harder to classify: the deliberate separation of what an operator sees from what a physical system is actually doing. In energy and water networks, manipulated human-machine interfaces, unauthorized local control, insider-enabled actions and poorly recorded maintenance can create operational effects without resembling a conventional cyberattack. The danger is greatest on Europe’s southern periphery, where water scarcity, energy dependence, island systems, tourism peaks and ageing infrastructure compress response margins. The strategic contest is no longer confined to penetrating networks. It concerns control over operational reality—and the ability of governments and utilities to establish the truth before a localized anomaly becomes a regional crisis.

The New Attack Surface

Human-machine interfaces, or HMIs, translate thousands of process measurements into the graphical environment from which operators supervise pumps, treatment stages, reservoirs, substations, breakers and generation assets. If that representation becomes incomplete, delayed or deceptive, the control room may continue making technically legitimate decisions on the basis of an inaccurate process state.

The risk is documented, not theoretical. In September 2022, the US Cybersecurity and Infrastructure Security Agency described how an adversary could prevent an HMI from updating while selectively changing the information shown to the operator. In December 2024, CISA warned that exposed water-sector HMIs could allow unauthorized parties to view interfaces and modify operational settings where adequate controls were absent. Control System Defense: Know the Opponent – CISA – September 2022; Internet-Exposed HMIs Pose Cybersecurity Risks to Water and Wastewater Systems – CISA – December 2024.

Yet remote compromise is only one pathway. Effective control can also be altered through authorized credentials used for an unauthorized purpose, unsupervised contractor access, an undocumented maintenance change or a transition to local operation that supervisory systems fail to represent correctly. The essential distinction is between authentication and authority: a valid identity does not prove that an action is operationally authorized.

The Southern Exposure

The Mediterranean risk profile is shaped by consequence, not simply by the number of vulnerabilities. The European Environment Agency reported that water scarcity affected 28% of EU territory and 32% of the EU population during at least one quarter of 2023. Approximately 30% of southern Europe’s population lives under permanent water stress, while as much as 70% can experience summer stress. Cyprus and Malta exceeded the severe-scarcity threshold of 40% on the seasonal Water Exploitation Index Plus; Greece, Portugal, Italy and Spain experienced pronounced scarcity during spring and summer. Water Scarcity Conditions in Europe – European Environment Agency – November 2025.

These figures alter the security calculation. A pumping anomaly during a period of abundant storage may remain manageable. The same event during drought, extreme heat and peak tourism can affect pressure, treatment, allocation and emergency reserves before investigators determine whether the cause is technical, accidental or hostile.

Seasonality also raises electricity demand for cooling precisely when water networks may require more energy for pumping, reuse and desalination. Drought can reduce hydropower flexibility; heat and wildfires can restrict field access; coastal and island populations can expand rapidly during the tourism season. The result is a recurring period in which both operational margins and diagnostic time contract.

Italy’s Double Deficit

Italy illustrates the convergence between resource loss and informational uncertainty. ISTAT calculated that in 2022 the country abstracted 9.1 billion cubic metres of water for drinking purposes, equivalent to 424 litres per resident per day. Approximately 8 billion cubic metres entered municipal networks, but only 4.6 billion were delivered for authorized uses.

Total distribution losses reached 3.4 billion cubic metres, or 42.4% of all water introduced into the networks. According to ISTAT, that volume could have met the annual water requirements of 43.4 million people. Water Statistics, 2020–2023 – Italian National Institute of Statistics – March 2024.

Not all reported losses represent physical leakage: measurement errors, apparent losses and unauthorized consumption can contribute to the total. That distinction is strategically important. Imperfect metering and uncertain network balances weaken the independent evidence against which operators can test what an HMI displays.

Modernizing Italy’s water networks is therefore not only a conservation policy. District metering, verified sensor calibration, trusted timestamps and reconciliation among inflow, storage, pressure and consumption reduce the informational space in which errors or deception can remain credible. Every litre that becomes measurable improves both efficiency and security.

The Island Equation

Malta and Cyprus present an even tighter water-energy nexus. In 2021, desalination supplied approximately 50% of public water in both countries, compared with only 1.4% across the EU. Water Savings for a Water-Resilient Europe – European Environment Agency – June 2025.

Desalination provides strategic protection against rainfall volatility, but it makes water availability more dependent on electricity, specialist maintenance, membranes, chemicals and the coordination of production, storage and distribution. Eurostat reported that in 2024 energy-import dependence reached 98% in Malta and 88% in Cyprus, against an EU average of 57%. Energy in Europe, 2026 Edition – Eurostat – 2026.

Interconnections can reduce isolation, but they create additional infrastructure to protect: subsea cables, converter stations, landing points, metering systems and cross-border control channels. The European Commission’s second Union list of Projects of Common and Mutual Interest, adopted on 1 December 2025, retained the proposed connection of Malta to the European gas network through Gela in Sicily. Second Union List of Projects of Common and Mutual Interest – European Commission – December 2025.

The strategic objective must be resilient interdependence, not isolation: diversified supply combined with protected nodes, alternative communications and restoration plans tested across national boundaries.

Legacy Meets Connectivity

Europe’s energy systems contain equipment installed long before modern cybersecurity requirements existed. The European Commission identifies three structural complications: real-time operating requirements can limit the use of conventional authentication mechanisms; interconnected grids can propagate disruption across borders; and legacy systems must now interact with smart meters, connected appliances and modern automation. Critical Infrastructure and Cybersecurity – European Commission, Directorate-General for Energy – updated 2026.

Age alone does not make equipment insecure. A well-understood older controller with tightly governed access may present less risk than a newly connected platform with opaque dependencies. The decisive questions concern supportability, configuration control, recoverability, data lineage, spare parts and the operator’s ability to verify physical conditions independently.

Incremental modernization creates mixed estates: a contemporary HMI may display data originating from older controllers through gateways, protocol converters and proprietary interfaces. The screen appears unified; the underlying reliability, timing and security assumptions are not. This is where operational ambiguity grows.

The Insider Dimension

Insider risk should not be reduced to identifying malicious employees. It includes contractors, integrators, temporary staff, vendors and former personnel whose access has not been fully withdrawn. Enablement may be deliberate, coerced, negligent or entirely unintentional.

A contractor may possess valid building access but no authorization for a specific cabinet or change. An engineer may use legitimate privileges outside the approved maintenance sequence. Emergency vendor support may resolve one failure while introducing an undocumented configuration. None of these events proves hostile intent; each creates an evidentiary gap.

The correct control is purpose-bound access. Identity, location, time, equipment, assigned task, configuration change and observed process effect must form one auditable chain. CISA’s April 2026 guidance on adapting Zero Trust to operational technology reinforces continuous verification while recognizing the safety and availability requirements of industrial systems. Adapting Zero Trust Principles to Operational Technology – CISA and International Partners – April 2026.

Europe’s Regulatory Pivot

The EU has begun moving from a cyber-only model toward all-hazards resilience. Directive (EU) 2022/2557, adopted on 14 December 2022, requires critical entities in sectors including energy, drinking water and wastewater to assess natural and human-induced risks and implement proportionate resilience measures. Directive on the Resilience of Critical Entities – European Parliament and Council – December 2022.

Italy transposed the NIS2 Directive through Legislative Decree No. 138 of 4 September 2024, published in the Official Gazette on 1 October 2024. The measure designates the National Cybersecurity Agency, ACN, as the competent national authority. Legislative Decree No. 138/2024 – Italian Official Gazette – October 2024.

The unresolved issue is implementation. Compliance documents cannot establish whether a utility can identify the effective controller, validate the physical process without its primary HMI, revoke emergency access or restore a clean configuration. ENISA defines stress testing as an assessment of preparedness, response and recovery, using metrics such as time to detect and time to recover. Handbook for Cyber Stress Tests – ENISA – May 2025. Europe now needs equivalent metrics for establishing a trusted physical state.

Water as Industrial Policy

The Commission’s Water Resilience Strategy contains more than 50 actions and sets the objective of improving EU water efficiency by 10% by 2030. It also calls for reduced network leakage, infrastructure modernization, digitalization, artificial intelligence and stronger security preparedness.

The economic dimension is substantial. The Commission estimates that Europe’s water industry generates €107 billion, supports 1.7 million jobs and holds 40% of global water-technology patents. It places the annual health-related cost associated with persistent PFAS pollution at €52–84 billion. European Water Resilience Strategy – European Commission – updated June 2026.

This turns infrastructure security into industrial strategy. Europe can build an exportable market in secure sensors, leakage analytics, resilient automation, trusted industrial AI, digital-twin assurance and recovery engineering. But digitalization without independent verification would modernize the interface faster than the underlying truth.

The 2031 Divide

By 2031, the decisive divide will not run between digital and analogue utilities. It will separate entities capable of proving resilience from those that merely report it. The mature operator will know which critical variables possess independent confirmation; who holds effective control; how physical and logical access relate to authorized work; how quickly a trusted state can be established; and whether minimum service can continue without the primary supervisory interface.

The alternative is a dangerous paradox: more sensors, more automation and more dashboards, but less certainty about which representation deserves trust.

Europe’s southern periphery is the place where this question becomes urgent first. Water scarcity, imported energy, island logistics, interconnectors and seasonal demand convert delayed diagnosis into economic and political exposure. The cost of inaction will not necessarily appear as a spectacular cyberattack. It may emerge as an unexplained sequence of local failures whose combined effect reveals that Europe digitized its critical infrastructure without securing its operational reality.


Navigational Index

  1. Threat convergence — HMI deception, physical access, insider enablement and operational ambiguity
  2. Southern-periphery exposure — water stress, energy interdependence, legacy OT and seasonal demand
  3. 2026–2031 outlook — competing hypotheses, Bayesian indicators, scenarios and resilience priorities

Master Abstract

The control interface as contested reality

HMI (Human Machine Interface) ghosting” is best treated as an analytical category rather than a standardized technical term: it describes circumstances in which the picture presented to operators becomes materially different from the physical state, command path or control authority of the underlying process. That divergence may arise from malicious display manipulation, compromised data acquisition, unauthorized local operation, deceptive maintenance activity, sensor disagreement or a physical intervention that the supervisory environment cannot reliably observe. The crucial distinction is that an adversary does not necessarily need to achieve the classic objective of persistent remote penetration. If a hostile actor can exploit legitimate access, manipulate the operator’s confidence, interfere with independent verification or cause an unauthorized transition between supervisory and local control, the resulting operational effect can cross the cyber–physical boundary while leaving conventional perimeter telemetry incomplete. CISA has explicitly documented the defensive significance of HMI integrity: an actor may prevent an operator display from updating while selectively changing what the operator sees. Control System Defense: Know the Opponent – Cybersecurity and Infrastructure Security Agency – September 2022verified primary source. CISA subsequently warned that exposed water-sector HMIs can permit unauthorized visibility and operational changes when safeguards are absent. Internet-Exposed HMIs Pose Cybersecurity Risks to Water and Wastewater Systems – Cybersecurity and Infrastructure Security Agency – December 2024verified primary source. These documents establish the plausibility of display–process divergence, but they should not be misread as evidence that every anomalous display indicates a sophisticated attack. Sensor failure, stale data, maintenance errors and ordinary control-system defects remain strong competing explanations. The intelligence problem is therefore forensic attribution under uncertainty: investigators must correlate control-room observations with trusted field measurements, physical-access records, maintenance authorization, controller state, safety-system events and process constraints. No single log source can establish the truth when the interface itself may be part of the contested evidence.

Why Europe’s southern periphery carries disproportionate consequence

The southern European exposure is not adequately represented by counting internet-facing devices or published vulnerabilities. Consequence depends on the interaction of water scarcity, seasonal demand, cross-border energy flows, treatment capacity, desalination dependence, aging field equipment, dispersed pumping infrastructure, contractor access and the time available for operators to detect contradictory process evidence. The European Environment Agency reported that water scarcity affected 28% of EU territory and 32% of the EU population in 2023; it further assessed that approximately 30% of southern Europe’s population lives under permanent water stress and as much as 70% can experience seasonal summer stress. Water Scarcity Conditions in Europe – European Environment Agency – November 2025verified primary source. Cyprus and Malta recorded the most severe seasonal conditions among EU members, while Greece, Portugal, Italy and Spain experienced pronounced spring and summer scarcity. This environmental pressure acts as a risk multiplier: when storage margins, treatment capacity or electricity availability are already constrained, a limited control disturbance can produce a larger service consequence and compress the time available for diagnosis. The Commission’s 2025 strategy consequently treats water resilience as a matter encompassing infrastructure, investment, digitalization, security and preparedness, rather than environmental management alone. European Water Resilience Strategy – European Commission, Directorate-General for Environment – June 2025verified primary source. Energy systems exhibit an analogous convergence. The Commission states that increased digitalization expands cyber exposure while interconnected electricity and gas systems create cascading risks, and it explicitly places malicious physical, cyber and hybrid threats within the EU preparedness framework. Critical Infrastructure and Cybersecurity – European Commission, Directorate-General for Energy – updated 2026verified primary source. The resulting analytic conclusion is not that southern utilities are inherently less secure. It is that equivalent technical anomalies can carry unequal strategic consequences because climatic stress, geographic distribution, interdependency and recovery logistics differ materially across Europe.

Competing hypotheses and the five-year trajectory

The 2026–2031 outlook should be governed by at least five competing hypotheses rather than a single threat narrative. H₁ — conventional cyber compromise: remote or supply-chain access alters supervisory visibility or commands. H₂ — insider-enabled manipulation: an authorized employee, contractor or coerced intermediary misuses legitimate access. H₃ — physical-control substitution: unauthorized local activity creates a process state that supervisory monitoring detects late or interprets incorrectly. H₄ — hybrid coercion: limited disruption, ambiguity and information manipulation are combined to impose political or economic costs without producing immediately attributable strategic damage. H₅ — non-hostile technical failure: maintenance defects, configuration drift, sensor failure or communications loss imitate deliberate ghosting. H₆ — compound climate–technical event: scarcity, heat, wildfire, flooding or power instability amplifies an otherwise manageable control failure. Initial priors must remain installation-specific; no defensible government dataset currently supplies a universal probability for “HMI ghosting.” Bayesian updating should therefore use evidence classes: unexplained disagreement among independent sensors; abnormal changes in local or remote operating state; unauthorized physical presence; maintenance actions inconsistent with work orders; loss of synchronized time; contradictory safety-system evidence; repeated anomalies aligned with geopolitical timing; and attempted suppression of operator escalation. Monte Carlo modeling can estimate consequence distributions only after the operator supplies validated parameters for restoration time, redundancy, reserve margins, demand, spare parts and interdependencies. The present dashboard therefore uses synthetic values and a disclosed scoring rule, not fabricated empirical precision. Structurally, the central risk is likely to rise through 2031 because digitalization expands while legacy control equipment remains in service, but the trajectory is not predetermined. Directive (EU) 2022/2557 requires an all-hazards resilience framework covering energy, drinking water and wastewater, thereby providing a legal basis for integrating physical security, continuity and cyber assurance. Directive (EU) 2022/2557 on the Resilience of Critical Entities – European Parliament and Council – December 2022verified official text. The highest-value intervention is consequently architectural and organizational: create trustworthy evidence paths outside the potentially deceptive interface, reconcile physical and digital access governance, test degraded operations, maintain recoverable configurations and exercise cross-sector crisis coordination.

Defensive foresight · 2026–2031

HMI–Physical Control Divergence

● MODEL ACTIVE

Scenario controls

Illustrative Bayesian-style risk engine. It supports defensive prioritisation; it is not an incident predictor and contains no operational bypass instructions.

Composite posterior risk
63

Elevated: verification gaps can turn local manipulation into system-level disruption.

DISPLAY–PROCESS DIVERGENCECompare HMI state with independent field telemetry and process physics.
PHYSICAL CONTROL INTEGRITYDetect unauthorized presence, mode changes and abnormal maintenance activity.
RECOVERY ASSURANCEValidate safe-state procedures, trusted baselines and communications continuity.

Five-year scenario distribution

Probability-weighted outlookConsequence pressure

Decision thresholds

≤ 34 · CONTROLLEDIndependent sensing and access governance constrain escalation.
35–64 · ELEVATEDRun cross-domain exercises and close verification blind spots.
≥ 65 · SEVEREPrioritise immediate engineering assurance and continuity safeguards.

Model logic: prior exposure is updated by HMI dependence, physical access, operational stress and verification maturity. Values are synthetic scenario outputs, not measurements of any named operator or installation.

Threat Convergence: When HMI, Insider and Physical Access Merge

The disappearance of the conventional perimeter

The convergence of HMI deception, physical access, insider enablement and operational ambiguity changes the fundamental intelligence question confronting energy and water operators. The conventional model asks whether an external adversary penetrated an industrial network; the converged model asks whether operators can still determine, with independently corroborated evidence, who controls the physical process, whether the displayed state corresponds to reality and whether apparently legitimate activity remains within an authorized operational purpose. “HMI ghosting” is used here as an analytical label, not a universally standardized engineering term: it encompasses any intentional separation between the process state perceived by operators and the physical, logical or administrative state actually governing the installation. The divergence can exist at several layers: the interface may show stale or selectively altered values; a control asset may have entered an unexpected operating mode; local activity may not be represented accurately at the supervisory level; an authorized account may perform an unauthorized function; or a legitimate maintenance intervention may create evidence indistinguishable from malicious preparation. CISA has publicly described the defensive problem in precise terms: a hostile actor could prevent an operator display from updating and selectively change what is presented, thereby disrupting the operator’s ability to perceive the true process condition. Control System Defense: Know the Opponent – Cybersecurity and Infrastructure Security Agency – September 2022verified primary source. CISA separately warned that inadequately protected, internet-exposed water-sector HMIs may allow unauthorized parties to view interfaces and alter operational settings. Internet-Exposed HMIs Pose Cybersecurity Risks to Water and Wastewater Systems – Cybersecurity and Infrastructure Security Agency – December 2024verified primary source. Neither finding means that network exposure is necessary for the broader threat. It demonstrates that the HMI is not merely a screen: it is an epistemic control point through which personnel decide whether the plant is stable, abnormal or moving toward an unsafe condition. Once confidence in that evidence channel becomes contestable, physical security, personnel assurance, engineering safety and cyber incident response can no longer operate as separate governance domains.

Convergence layerObject requiring protectionDefensive intelligence questionHigh-value corroborating evidencePrimary analytical failure
RepresentationHMI graphics, trends, alarms and timestampsDoes the displayed state correspond to the current process?Independent field telemetry, historian comparison, trusted time sourceTreating one interface as ground truth
Command authoritySupervisory, engineering and local-control statesWhich person or system currently possesses effective authority?Mode-state records, authorization logs, physical inspectionAssuming authenticated access equals authorized purpose
Physical processPumps, valves, breakers, drives and treatment stagesIs equipment behaving consistently with commands and process physics?Electrical load, flow, pressure, level, chemistry and safety-system dataInvestigating only digital artifacts
Human accessEmployees, contractors, vendors and escortsWas access legitimate, necessary, supervised and temporally consistent?Rosters, work orders, badge records, video and tool custodyReviewing personnel and cyber evidence separately
RecoverySafe-state transition, manual continuity and restorationCan the operator recover without trusting the suspected interface?Tested procedures, clean baselines, independent communicationsDiscovering dependencies during the incident

HMI deception as an attack on operational knowledge

An HMI-deception incident does not need to falsify every data point or maintain a flawless simulation of the plant. From a defender’s perspective, a limited inconsistency may be strategically sufficient if it delays recognition, directs attention toward the wrong subsystem, encourages an inappropriate but otherwise legitimate operator response or obscures the moment when control authority changes. The decisive variable is therefore not visual sophistication; it is whether the deceptive representation remains credible for longer than the plant’s operational tolerance permits. In an electricity environment, seconds or minutes can matter for protection, balancing and cascading conditions. In a drinking-water or wastewater system, the relevant tolerance may range from minutes to hours, depending on storage, treatment stages, redundancy and the availability of trusted laboratory or field measurements. NIST treats OT as a domain with distinctive reliability, safety and real-time requirements and explicitly includes industrial control, physical-access control and physical-environment monitoring within the security problem. Guide to Operational Technology Security, NIST Special Publication 800-82 Revision 3 – National Institute of Standards and Technology – September 2023verified primary source. This broader definition is crucial because a badge reader, field sensor, engineering workstation and operator display may participate in the same incident even when their logs are owned by different departments. Investigators should consequently distinguish four forms of divergence: representational divergence, in which displayed information conflicts with trusted observation; temporal divergence, in which correct information arrives too late to remain operationally useful; authority divergence, in which the assumed controller is not the effective controller; and procedural divergence, in which a technically legitimate action lacks a valid operational purpose. These categories are defensive abstractions rather than instructions for creating an incident. Their value lies in preventing premature closure. A conventional security operations centre may classify the absence of malware or remote-access evidence as exculpatory; an engineering team may classify contradictory values as sensor failure; physical security may regard a valid badge event as routine. The convergence framework treats each conclusion as provisional until cross-domain evidence has been reconciled.

Divergence typeObservable defensive symptomBenign explanation to test firstHostile explanation retainedRequired adjudication
RepresentationalHMI value differs from independent measurementCalibration fault, communications loss, stale historianSelective falsification or suppressed updateSensor lineage and physical-process validation
TemporalAlarm, trend or event arrives unexpectedly lateCongestion, clock drift, equipment failureDeliberate delay intended to extend uncertaintyTrusted-time reconstruction
AuthorityCommand source conflicts with expected operating stateMaintenance or emergency interventionUnauthorized assumption of local or privileged controlWork-order and access reconciliation
ProceduralValid credential performs an unusual but permitted actionHuman error or undocumented troubleshootingInsider misuse or coerced actionPurpose, supervision and sequence analysis
Physical–digitalEquipment behavior contradicts command recordMechanical defect or sensor disagreementPhysical interference or concealed local activityField inspection and independent telemetry

Physical access as a control-plane variable

Physical access should not be modeled as a binary condition in which a person either entered a secure space legitimately or did not. In operational environments, effective access is multidimensional: identity, role, location, duration, escort status, task authorization, equipment custody, time window and the relationship between the intervention and the plant’s changing state must all align. A contractor can possess valid entry authorization while lacking authorization for a particular cabinet, engineering function or deviation from the approved work package. An employee can be correctly authenticated while acting outside duty, sequence or purpose. A maintenance team can be scheduled legitimately while poor change control makes its actions forensically indistinguishable from hostile preparation. CISA’s defense-in-depth guidance states that physical-access controls should ensure that only authorized people reach controlled spaces, while NIST emphasizes that physical and logical protections must be adapted to OT availability and safety requirements. Recommended Practice: Improving Industrial Control System Cybersecurity with Defense-in-Depth Strategies – Cybersecurity and Infrastructure Security Agency – September 2016verified primary source. The relevant security objective is therefore not simply exclusion; it is accountable control over the full intervention lifecycle. Defenders require a trustworthy chain linking the approved task to the person, place, device, change, observed process effect and closure evidence. An unexplained mismatch should not automatically be labeled malicious, because informal troubleshooting and incomplete documentation remain widespread causes of ambiguity. It should, however, increase the probability assigned to insider-enabled or physically enabled hypotheses when multiple independent inconsistencies co-occur. Europe’s Critical Entities Resilience framework reinforces this integration by requiring resilience against natural and human-induced risks through an all-hazards approach, rather than limiting the operator’s obligation to network security. Directive (EU) 2022/2557 on the Resilience of Critical Entities – European Parliament and Council – December 2022verified official text. Energy, drinking water and wastewater are explicitly within its sectoral scope, making the separation of physical protection, business continuity and cyber assurance increasingly difficult to justify.

Access dimensionWeak evidence modelStrong evidence modelEscalation indicator
IdentityBadge acceptedBadge, roster, supervisor and task identity reconciledCredential use inconsistent with assigned person
Purpose“Maintenance” recordedSpecific asset, action, limit and expected result documentedActivity lacks a corresponding authorized change
TimeEntry and exit timestampsAccess aligned with process events and maintenance windowAnomaly begins during or immediately after access
LocationBuilding-level entryZone, cabinet or asset-level accountabilityPresence near affected equipment cannot be explained
EquipmentTools not recordedPortable devices, media and specialist tools controlledUnregistered equipment appears in a restricted zone
ClosureJob marked completeConfiguration, physical state and process response verifiedPlant state differs from documented completion state

Insider enablement without simplistic profiling

Insider risk must be analyzed as an opportunity structure, not as a psychological stereotype. The relevant population includes employees, temporary staff, integrators, equipment vendors, cleaning and facilities personnel, outsourced monitoring teams, consultants and former personnel whose access has not been completely withdrawn. Enablement can be deliberate, coerced, financially motivated, ideologically motivated, negligent or entirely unknowing. A privileged engineer may facilitate an incident by violating a two-person rule without malicious intent; a vendor may introduce an unapproved configuration during emergency support; a former contractor may retain documentation or credentials; a supervisor may suppress escalation to avoid reputational consequences. These pathways generate different indicators and require different interventions. NIST’s manufacturing cybersecurity practice guidance recognizes threats from malicious and non-malicious insiders alongside external actors, demonstrating that intent cannot be inferred merely from the possession of legitimate access. Protecting Information and System Integrity in Industrial Control System Environments, NIST Special Publication 1800-10 – National Cybersecurity Center of Excellence – May 2018verified primary source. The strongest insider-risk architecture therefore relies on separation of duties, minimum necessary privilege, rapid lifecycle management, supervised sensitive work, behavioral baselines tied to functions rather than personalities, and protection for personnel who report anomalies. Chinese government documentation provides a useful multilingual governance comparison: official industrial-control guidance emphasizes enterprise responsibility, physical and environmental protection, monitoring, incident response and organizational coordination across production, operations, maintenance and information functions. Interpretation of the Industrial Control System Information Security Action Plan – Xuchang Municipal Bureau of Industry and Information Technology – January 2018verified Chinese government source. This does not establish Chinese offensive intent and must not be used for attribution. It establishes that major regulatory systems recognize industrial security as an organizational and physical governance problem, not merely a firewall problem. The intelligence implication is that anomalous personnel activity should update a hypothesis only when it is linked to operational evidence, authorization inconsistencies or concealed changes.

Operational ambiguity as the principal force multiplier

Operational ambiguity is the interval during which defenders cannot determine whether they face technical failure, operator error, legitimate maintenance, malicious cyber activity, physical interference, insider misuse or a compound event. That interval is often more strategically consequential than the original anomaly because it delays protective action, fragments command authority and creates opportunities for misinformation. Energy and water organizations are particularly vulnerable when responsibility is distributed among a network operations centre, plant control room, corporate security team, outsourced integrator, municipal authority, emergency services and national regulator. Each organization may possess a valid but incomplete fragment of the evidence. The European Union Agency for Cybersecurity’s stress-test handbook describes scenarios spanning cyberattacks on SCADA, sabotage, physical insider threats, supply shortages and combined cyber–physical escalation. Handbook for Cyber Stress Tests – European Union Agency for Cybersecurity – May 2025verified primary source. The handbook’s value lies in treating preparedness, incident management and recovery as connected capabilities. Operational ambiguity should therefore be measured rather than discussed abstractly. Useful defensive metrics include time to establish a trusted process state; time to identify the effective control authority; percentage of critical signals with an independent verification path; proportion of privileged physical and logical activity reconciled within a defined window; percentage of emergency procedures tested without the primary HMI; and time required to produce a cross-domain event chronology. None of these metrics reveals how to bypass a system. They reveal whether defenders can reason accurately when ordinary evidence channels are unreliable. A mature operator should also establish an “epistemic safe state”: a pre-defined operational posture adopted when the organization cannot confirm that its displays, commands or access records remain trustworthy. The exact posture must be determined by qualified plant engineers because an inappropriate generic response could create additional danger. Intelligence teams should support that decision by clearly separating verified facts, inferred relationships, missing evidence and competing explanations.

Ambiguity metricDefinitionDefensive significanceFive-year target direction
Trusted-state establishment timeTime needed to validate the physical process independentlyDetermines how long deception can influence decisionsStrong decrease
Authority-resolution timeTime needed to determine effective command ownershipLimits conflicting operator actionsStrong decrease
Independent verification coverageShare of critical variables corroborated outside one interfaceReduces single-source epistemic failureIncrease toward complete critical coverage
Physical–logical reconciliation rateSensitive access events matched to authorized work and system changesExposes unexplained insider opportunityIncrease
Degraded-operation exercise rateCritical sites exercising without primary supervisory visibilityTests organizational rather than theoretical resilienceIncrease
Forensic time coherenceShare of relevant systems aligned to trustworthy timingEnables sequence reconstructionIncrease
Unresolved change inventoryChanges lacking validated purpose, owner or closureMeasures accumulated operational ambiguityStrong decrease

Analysis of Competing Hypotheses

A disciplined assessment should begin with hypotheses that are mutually distinguishable at the evidence level, even when more than one may ultimately be true. H₁ is ordinary equipment, sensor or communications failure; H₂ is unintentional human error or undocumented maintenance; H₃ is conventional remote cyber compromise affecting visibility or control; H₄ is malicious or coerced insider activity using legitimate access; H₅ is unauthorized physical intervention producing a state not reliably represented at the supervisory layer; H₆ is supply-chain or vendor-mediated compromise; H₇ is a coordinated hybrid operation combining limited technical disruption with deception, political pressure or public-information effects; and H₈ is a compound environmental and technical event. Investigators should score evidence by diagnostic value, reliability and independence rather than simply counting observations. A disagreement between an HMI and a sensor is weak evidence if both depend on the same communications path. A field measurement from an independent instrument, verified by a second team and aligned with physical process behavior, is much stronger. Evidence of valid badge access is not exculpatory unless task, location, timing and process consequences also align. Conversely, geopolitical tension is not technical proof of state involvement. Russian primary legislation defines automated control systems as part of the protected critical-information-infrastructure domain. Federal Law No. 187-FZ on the Security of the Critical Information Infrastructure of the Russian Federation – Official Legal Information Portal of the Russian Federation – July 2017verified Russian government source. That legal fact demonstrates strategic recognition of control systems; it does not establish responsibility for any incident. ACH must actively resist mirror imaging and attribution by capability. The most defensible conclusion may remain “unresolved compound anomaly” if evidence cannot discriminate among H₃, H₄ and H₅.

EvidenceH₁ failureH₂ errorH₃ cyberH₄ insiderH₅ physicalH₆ supplierH₇ hybridDiagnostic value
Independent field data contradicts HMICCCCCCCLow alone
Unauthorized access near affected assetIINCCNCHigh if independently verified
Valid credential, invalid work purposeICNCCCCHigh
Similar anomalies across separated sitesIICIICCHigh
Evidence of ordinary hardware degradationCCIIINIHigh
Public coercive narrative synchronized with disruptionNNNNNNCModerate; attribution remains unproven
Vendor activity precedes multiple anomaliesICNNNCNHigh
Safety-system data agrees with independent physics but not HMIIICCCCCHigh for deception, weak for actor identity

Legend: C means broadly consistent; I means inconsistent; N means neutral or weakly relevant.

Bayesian updating and Monte Carlo discipline

Bayesian analysis should be implemented as a controlled evidence-update process, not as decorative mathematics that creates false precision. Each hypothesis receives an initial prior derived from the operator’s own incident history, architecture, access population, threat intelligence and environmental conditions. New observations update those priors according to their likelihood under each hypothesis, but correlated evidence must not be counted repeatedly. For example, three alarms derived from the same sensor or communications path constitute one underlying evidence family, not three independent confirmations. The probability assigned to H₄ should rise materially when an unexplained access event, an unauthorized work sequence and a coincident process-state anomaly are independently verified; it should not rise merely because an employee worked an unusual shift. H₇ requires still stronger discipline because geopolitical motive, public claims and technical capability are not substitutes for incident-specific evidence. Monte Carlo analysis belongs on the consequence side: operators can sample uncertain detection delays, restoration times, reserve margins, seasonal demand, redundant equipment availability, communications loss and cross-sector dependencies to estimate distributions of service interruption and recovery requirements. The simulation should not estimate the probability that a named country will attack a named installation unless a defensible empirical basis exists. The graph below instead uses synthetic indices to compare three transparent policy scenarios: baseline convergence, climate-stress amplification and accelerated resilience. Its numerical values are analytical assumptions, not observed frequencies. The principal sensitivity proposition is defensible even without invented probabilities: higher operational stress and greater dependence on a single supervisory representation widen the potential consequence of ambiguity, while independent sensing, access reconciliation and exercised degraded operations reduce it. Results should be reported as ranges and percentile bands, accompanied by assumptions, rather than as a single authoritative number. This preserves decision usefulness while preventing the model from laundering judgment into apparently empirical certainty.

Monte Carlo variableIllustrative distribution classRequired operator inputOutput influenced
Detection delayEmpirical or triangularHistorical alarm-to-validation timesDuration of deceptive influence
Independent verification timeEmpirical or lognormalField-team mobilization and measurement dataAmbiguity interval
Storage or reserve marginSeasonal empiricalReservoir, fuel, generation or treatment capacityService continuity
Repair durationEmpirical with supply-chain tailAsset-specific restoration historyRecovery distribution
Communications availabilityBernoulli or state-transitionRedundancy and outage performanceCoordination effectiveness
Demand stressSeasonal distributionWater, electricity or gas demand historyConsequence severity
Spare-part availabilityDiscrete scenarioInventory and supplier lead timesTail recovery risk
Cross-sector dependencyConditional scenarioPower, telecom, water and transport mappingCascading consequence

Shadow dimensions: proxies, cyber norms and liquidity

The “shadow” layer should be assessed cautiously because it contains the greatest risk of analytical overreach. Mercenary or proxy dynamics may involve commercial intrusion services, politically aligned groups, criminal facilitators, corrupt insiders or intermediaries with legitimate industrial access. Open-source evidence often reveals capability claims but rarely proves command relationships. Analysts should therefore separate sponsorship, direction, tolerance and opportunistic alignment as distinct propositions. A contractor’s financial distress or an unusual payment is not proof of recruitment; it is a potential investigative lead requiring lawful financial and personnel review. Liquidity analysis should focus on defensible organizational exposure: concentration of maintenance contracts, emergency procurement outside standard controls, opaque subcontracting chains, abnormal invoice structures, rapid vendor changes and financially stressed suppliers occupying privileged positions. Cyber-norm analysis should examine whether an actor seeks reversible disruption, strategic signaling, persistent access or destructive effect, but norms are expectations rather than safety guarantees. ENISA’s 2030 foresight identifies advanced hybrid threats in which physical or offline attacks increasingly combine with cyber activity. Foresight Cybersecurity Threats for 2030, 2024 Update – European Union Agency for Cybersecurity – November 2024verified primary source. This supports a convergence outlook but not attribution to a particular state or proxy. Chinese government policy for future industrial internet research emphasizes reliable interconnection among humans, machines and physical objects and the integration of industrial processes, networks and value chains. Major Research Plan for Future Industrial Internet Fundamental Theory and Key Technologies – National Natural Science Foundation of China – September 2025verified Chinese government source. Again, this establishes strategic technological direction, not hostile intent. The defensible OSINT task is to map how expanding industrial connectivity changes opportunity, dependency and potential consequence across all jurisdictions.

Five-year outlook, 2027–2031

The baseline outlook anticipates a gradual increase in convergence pressure through 2031, driven by greater OT connectivity, distributed assets, remote support, AI-assisted operations, contractor dependence and continuing coexistence between legacy equipment and modern supervisory platforms. This is not a forecast of a proportional increase in successful attacks. It is a forecast that incidents will become harder to classify because more legitimate systems and people can influence the operational picture. Between 2027 and 2028, the principal governance challenge will be converting EU all-hazards obligations into site-level controls that reconcile physical, cyber, safety and contractor evidence. During 2029, organizations are likely to face an expanding verification problem as AI-generated recommendations, automated anomaly detection and digital twins become additional epistemic layers. These tools may improve detection, but they can also create correlated trust dependencies if they consume the same compromised or defective data. During 2030–2031, the distinction between primary industrial control, distributed field automation, energy management and climate-adaptation infrastructure will become less clear. Water reuse, desalination, storage, renewable integration and demand management will create resilience benefits while enlarging the number of geographically dispersed assets requiring accountable access and trusted telemetry. Southern Europe faces a particularly consequential interaction with scarcity. The EEA reported that water scarcity affected 28% of EU territory and 32% of its population in 2023, while southern Europe experiences persistent and severe seasonal pressures. Water Scarcity Conditions in Europe – European Environment Agency – November 2025verified primary source. The strategic priority is therefore not indiscriminate technological replacement. It is preservation of independent operational truth: field-verifiable process measurements, robust time coherence, controlled intervention paths, trustworthy recovery configurations, cross-domain event reconstruction and leadership structures capable of acting before perfect attribution becomes available.

PeriodExpected convergence developmentPrincipal ambiguityDefensive priorityResidual risk
2027CER and NIS-related implementation reaches more operational processesCompliance evidence confused with operational effectivenessSite-level all-hazards validationFragmented ownership
2028Contractor and remote-support ecosystems deepenLegitimate access versus legitimate purposeUnified physical–logical access governanceThird-party opacity
2029AI analytics and digital-twin adoption expandIndependent analysis may share compromised source dataData-lineage and model-independence testingCorrelated epistemic failure
2030Distributed energy and water assets increaseCentral visibility versus local effective authorityField-verification coverage and trusted timingGeographic dispersion
2031Climate and demand stress interact with complex automationTechnical failure versus hostile exploitation of stressExercised degraded operations and cross-sector recoveryCompound-event tails
DEFENSIVE SCENARIO MODEL · SYNTHETIC OUTPUT

Figure 1: Five-Year Threat-Convergence Projection

Index 0–100; higher values indicate greater combined detection-and-consequence pressure.

Method note: values are transparent analytical scenarios, not measurements of any operator and not forecasts of attack frequency. The baseline combines HMI trust dependence, physical-access exposure, insider opportunity and operational stress; the resilience case assumes stronger independent sensing, access reconciliation and exercised recovery.

Southern-Periphery Exposure: The Water–Energy–OT Stress Corridor

A vulnerability produced by convergence

Europe’s southern periphery should not be described as a uniformly weak technological region. Its distinctive exposure arises from the convergence of four structural conditions: persistent or seasonal water scarcity; high energy-import or interconnection dependence; long-lived operational technology installed across heterogeneous infrastructure generations; and demand patterns compressed into increasingly hot, dry and tourism-intensive summer periods. Each condition is manageable in isolation. Their intersection, however, narrows operating margins and increases the strategic consequence of incomplete, delayed or deceptive information. Water utilities need electricity for abstraction, conveyance, pumping, treatment, desalination, disinfection, pressure regulation, wastewater processing and reuse. Electricity systems simultaneously depend on water for hydropower, thermal-generation cooling, fuel processing, firefighting and the physical maintenance of grid infrastructure. Tourism and irrigation raise water demand during periods when heat also increases cooling loads; drought can reduce hydropower availability while increasing pumping and desalination requirements; wildfires and extreme temperatures can interfere with transmission, communications and field access. Legacy OT adds a further dimension because operators must integrate controllers, remote terminal units, sensors and supervisory platforms designed under different assumptions about connectivity, authentication, data integrity and vendor support. The European Commission now explicitly treats water security as a matter of preparedness, infrastructure investment, digitalization and strategic resilience. European Water Resilience Strategy – European Commission, Directorate-General for Environment – June 2025verified primary source. The strategy’s significance for HMI-related risk is indirect but profound: greater digitalization can improve forecasting, leakage detection and resource allocation, yet it also increases the number of data relationships on which operators depend. Southern-periphery exposure is therefore not captured by a simple cyber-vulnerability count. It is a combined detection-and-consequence problem in which an identical HMI anomaly can be operationally minor during a low-demand month but strategically serious when reservoirs, generation margins, interconnectors, field crews and treatment capacity are already under stress.

Structural factorDirect operational effectCross-sector amplificationHMI/OT implicationStrategic consequence
Water scarcityLower storage and abstraction marginsMore pumping, reuse and desalination demandGreater reliance on accurate flow, pressure and quality dataLess time to classify anomalies
Heat and seasonal demandHigher cooling, tourism and irrigation loadsCoincident pressure on electricity and waterAlarm volumes and operator workload increaseLocal failures can escalate faster
Energy-import dependenceExposure to external supply and maritime logisticsWater treatment depends on imported-energy continuityBackup assumptions become criticalRecovery costs and political sensitivity rise
Electricity interdependenceReliance on cross-border balancing and interconnectorsDisturbance may propagate beyond one jurisdictionControl-centre coordination becomes decisiveNational incident becomes regional
Legacy OTUneven visibility, support and security capabilityDifficult integration with newer analyticsMultiple representations of the same processGreater operational ambiguity
Geographic dispersionRemote pumps, reservoirs, substations and treatment assetsField verification requires time and transportCentral HMI may be the dominant evidence sourcePhysical-state confirmation is delayed

Water scarcity as a control-system multiplier

The European Environment Agency’s latest indicator demonstrates that scarcity is not a distant climate scenario. In 2023, water-scarcity conditions affected 28% of EU territory and 32% of the EU population during at least one quarter; the longer-run annual averages for 2000–2023 were approximately 30% of territory and 33% of population. Southern Europe carries a sharper seasonal concentration: approximately 30% of its population lives in areas experiencing permanent water stress, while as much as 70% can face summer-season stress. Cyprus and Malta recorded the most significant seasonal scarcity among EU member states, with seasonal WEI+ values above 40%; Greece, Portugal, Italy and Spain also experienced scarcity particularly during spring and summer. Water Scarcity Conditions in Europe – European Environment Agency – November 2025verified primary source. WEI+ measures freshwater consumption relative to renewable freshwater availability after accounting for returns, and the EEA uses 20% as a scarcity threshold and 40% as a severe-scarcity threshold. It should not be misinterpreted as the percentage probability of shortage or infrastructure failure. Its security importance lies in the shrinking buffer between ordinary operations and service disruption. When resource availability is abundant, an erroneous reading, delayed alarm or temporarily unavailable pumping station may be absorbed by storage, alternative sources or flexible scheduling. Under severe seasonal stress, the same anomaly can affect allocation decisions, reservoir drawdown, pressure zoning, irrigation restrictions or desalination scheduling before its cause is fully determined. Scarcity also complicates anomaly detection because legitimate operating patterns change rapidly: pumps run for different durations, networks are reconfigured, pressure targets move, emergency sources enter service and maintenance may be deferred. A malicious or accidental divergence can consequently resemble an adaptive operational response. Defensive analysis must therefore compare an observed action not only with a static baseline but also with the approved drought-operating plan, current storage position, forecast demand and the precise authorization governing temporary configurations.

Official water indicatorObserved valueReference periodDefensive interpretation
EU territory affected by scarcity in at least one quarter28%2023Wide geographic exposure; not confined to the Mediterranean
EU population affected by scarcity in at least one quarter32%2023Material societal dependence on stressed systems
Southern population under permanent stressAround 30%Latest EEA assessmentReduced year-round operating margin
Southern population exposed to summer stressUp to 70%Latest EEA assessmentStrong seasonal concentration of consequences
Cyprus and Malta seasonal WEI+Above 40%2023Severe scarcity category
Greece, Portugal, Italy and SpainSpring–summer scarcity2023Recurrent seasonal exposure rather than uniform annual scarcity
TürkiyeMost severely challenged EEA member country2023Important non-EU component of the regional water–energy system

Italy: network losses as both resource and observability risk

Italy illustrates how climatic pressure interacts with infrastructure efficiency and operational visibility. ISTAT reported that in 2022 Italian systems abstracted approximately 9.1 billion m³ of water for drinking purposes, equivalent to 424 litres per resident per day; approximately 8.0 billion m³, or 371 litres per resident per day, entered municipal distribution networks, while only 4.6 billion m³, or 214 litres per resident per day, were delivered for authorized uses. Total distribution losses reached 3.4 billion m³, equal to 42.4% of the water introduced into the networks. ISTAT estimated that this lost volume could have met the water requirements of 43.4 million people for an entire year. Le statistiche sull’acqua, anni 2020–2023 – Istituto Nazionale di Statistica – March 2024verified primary source. These losses are not automatically evidence of physical leakage alone: the total-loss measure can include real losses, apparent losses, measurement problems and unauthorized consumption. For OT risk analysis, this distinction matters. A network with imperfect metering, uncertain district balances or incomplete telemetry gives operators a weaker physical reference against which to evaluate HMI information. If the expected relationship among input volume, pressure, storage and authorized consumption already contains substantial uncertainty, a deceptive, stale or erroneous interface state may remain plausible for longer. Italy’s fragmentation adds organizational complexity. Water service coverage extends across thousands of municipalities, while terrain, settlement patterns, operator scale and infrastructure age vary sharply between northern metropolitan areas, central regions, the Mezzogiorno and the islands. National averages therefore cannot be treated as installation-level exposure scores. The strategic priority is to convert leakage reduction into an observability programme: district metering, verified sensor lineage, pressure and flow reconciliation, calibrated instrumentation, trusted timing, controlled configuration changes and independent confirmation of critical storage and treatment variables. Such investments simultaneously conserve water and reduce the informational space in which operational ambiguity can persist.

Italy water balanceVolume in 2022Per-capita equivalentShare or implication
Water abstracted for drinking purposes9.1 billion m³424 litres/dayItaly ranked third in Europe for per-capita abstraction
Water entering distribution8.0 billion m³371 litres/dayStarting volume for municipal distribution
Water delivered for authorized uses4.6 billion m³214 litres/dayApproximately 57.6% of input volume
Total distribution losses3.4 billion m³Approximately 157 litres/day42.4% of network input
Population-equivalent of lost volume43.4 million people/yearIllustrates resilience opportunity, not recoverable volume at every site

Malta and Cyprus: desalination converts scarcity into energy dependence

Malta and Cyprus reveal the most concentrated water–energy coupling inside the EU’s southern periphery. The EEA reported that in 2021 approximately 50% of total public water supply in both countries came from desalinated water, even though desalinated sources represented only about 1.4% of total public water supply across the EU. Water Savings for a Water-Resilient Europe – European Environment Agency – June 2025verified primary source. Desalination provides strategic diversification from rainfall and conventional freshwater abstraction, but it transforms water security into a more direct function of electrical continuity, energy cost, membrane and chemical supply chains, specialized maintenance and intake–treatment–distribution coordination. This does not make desalination intrinsically insecure. It means that water resilience must be evaluated together with generation, fuel logistics, grid configuration and reserve capability. Eurostat reported that the EU’s overall energy-import dependency rate was 57% in 2024, compared with 98% for Malta and 88% for Cyprus. Energy in Europe, 2026 Edition – Eurostat – 2026verified primary source. The dependency indicator measures net imports as a proportion of gross available energy; it is not an electricity adequacy measure and does not by itself prove insecurity. Nevertheless, the combination of severe seasonal WEI+, high import dependence and desalination creates a distinctive compound-exposure profile. A disturbance affecting electricity, fuel delivery, treatment or supervisory visibility can influence several layers of essential service simultaneously. The critical defensive question becomes whether operators can verify water production, storage and quality independently if primary supervisory data are unavailable or suspect, while energy authorities determine whether the supporting electrical state remains sustainable. Planned interconnections can reduce isolation and provide diversification, but they also introduce converter stations, subsea infrastructure, cross-border operating rules and new digital coordination dependencies. Resilience should consequently be judged by the quality of alternative operating states and exercised recovery, not simply by the number of connections.

IndicatorMaltaCyprusEU contextSecurity meaning
Seasonal WEI+Above 40%Above 40%20% scarcity; 40% severe scarcityBoth fall in the severe seasonal category
Public supply from desalinationAround 50%Around 50%EU average 1.4%Electricity becomes a major water-security input
Energy-import dependency98%88%EU 57%Strong exposure to external energy flows
Geographic conditionIsland systemIsland systemContinental systems generally have more terrestrial optionsRecovery and logistics require island-specific planning
Principal resilience opportunityInterconnection, storage, efficiency and reuseInterconnection, storage, efficiency and reuseEU Water Resilience StrategyDiversification must preserve independent operational verification

Spain, Portugal and the western Mediterranean bottleneck

The Iberian Peninsula combines substantial renewable potential, hydropower variability, irrigation demand, large tourism economies and limited electricity exchange capacity across the Pyrenean interface relative to the size of its power system. This creates a paradox: Spain and Portugal possess valuable solar, wind and LNG infrastructure, but their contribution to wider European balancing and their ability to draw on continental flexibility remain constrained by interconnection topology. Water stress compounds that limitation because drought can simultaneously reduce reservoir availability, alter hydropower scheduling, increase agricultural abstraction and raise pumping or desalination demand. The EEA’s 2023 assessment places both countries among those experiencing pronounced spring and summer scarcity. This is operationally important because average annual energy balances can obscure short periods of coincident stress. A summer week characterized by high cooling load, weak hydrological conditions, variable renewable output, wildfire risk and heavy tourism can impose a substantially different control environment from an annual national average. ENTSO-E’s seasonal outlook methodology assesses European adequacy across interconnected study zones and is intended to inform national and European authorities about emerging system risks. Summer Outlook 2025 – European Network of Transmission System Operators for Electricity – May 2025verified primary source. The report should not be interpreted as a prediction of local OT incidents: it models resource adequacy, interconnection and system conditions at zonal level and explicitly applies simplifying assumptions. Its relevance is that OT anomaly consequences depend on the surrounding adequacy environment. If neighbouring zones possess spare capacity and transmission paths remain available, a local disturbance is easier to absorb. If scarcity and demand coincide across several zones, the same event consumes a larger share of regional flexibility. Iberian resilience therefore requires integration of drought planning, grid adequacy, wildfire procedures, tourism-season forecasts, water-utility demand and cross-border operational coordination. The intelligence unit should monitor compound thresholds rather than treating every stressor as an independent warning.

Iberian stressorWater-system effectEnergy-system effectOT/HMI consequence
Multi-season droughtLower reservoirs and tighter allocationsReduced hydropower flexibilityRapidly changing operating baselines
Extreme heatHigher municipal demand and evaporationCooling-load increaseMore alarms and less reserve margin
Irrigation seasonHigh abstraction and pumpingGreater agricultural electricity consumptionComplex schedules and remote-asset activity
Tourism concentrationCoastal and island demand peaksCooling and transport-energy demandTemporary operations and staffing pressure
Wildfire conditionsThreat to catchments, pumps and access routesThreat to lines, substations and field accessDelayed physical verification
Limited continental interconnectionFewer indirect energy-support optionsConstrained cross-border balancingGreater consequence of regional disturbances

Greece, Italy and the central–eastern Mediterranean interdependence arc

The central and eastern Mediterranean form an expanding interdependence corridor extending through Italy, Greece, Malta, Cyprus and the western Balkans toward Türkiye and the eastern Mediterranean. Electricity cables, gas pipelines, LNG facilities, renewable-generation zones, shipping routes and prospective hydrogen infrastructure increasingly connect markets that historically contained islanded or weakly connected systems. Interconnection creates resilience by sharing generation, improving market integration and reducing the probability that every jurisdiction must independently carry all contingency resources. It also creates common-mode dependencies: converter stations, subsea cable landing points, telecommunications, synchronized operational procedures and cross-border restoration protocols become strategically important nodes. The Commission’s Projects of Common Interest framework includes priority electricity and gas corridors across southern Europe and has repeatedly identified the objective of ending energy isolation, including the connection of Malta with Italy and eastern Mediterranean electricity links. The 2025 second Union list included the proposed connection of Malta to the European gas network through an interconnection with Italy at Gela. Commission Delegated Regulation establishing the second Union list of Projects of Common and Mutual Interest – European Commission – December 2025verified primary source. Project inclusion is not equivalent to commissioning, guaranteed completion or immediate resilience; status, permitting and delivery must be evaluated separately. The OT implication is that greater physical interconnection must be accompanied by stronger operational-state reconciliation across control centres. A disturbance can be technically local while its balancing, market and political consequences become regional. Greece’s islands and Italy’s major islands require particular attention because local generation, subsea connections, tourism demand and water systems can interact differently from mainland networks. The correct policy is neither autarky nor unconditional interconnection. It is resilient interdependence: diverse routes, validated restoration plans, transparent operational authority, spare-equipment strategies, protected landing and conversion facilities and communications able to function when ordinary supervisory channels are degraded.

Interdependence assetResilience gainNew dependencyRequired assurance
Electricity interconnectorShared capacity and balancingCable, converter and landing infrastructureCondition monitoring and restoration exercises
Gas pipelineSupply diversification and market integrationCompressor, metering and geopolitical-route dependencePhysical protection and verified flow-state data
LNG terminalSource and route diversificationShipping, weather and specialized equipmentInventory visibility and continuity planning
Renewable corridorLower fuel-import exposureWeather variability and distributed-control complexityForecast quality and secure field telemetry
Desalination facilityDrought-independent water productionElectricity and specialist supply dependencePower continuity and independent quality validation
Regional control coordinationFaster mutual assistanceDependence on shared data and communicationsTrusted timing, authentication and fallback channels

Legacy OT: age is not the only problem

“Legacy OT” should not be equated automatically with obsolete, exposed or insecure technology. Some older systems remain operationally stable, physically isolated, well understood and supported by disciplined procedures; some newly connected systems can introduce greater risk through configuration complexity, cloud dependence or poorly governed remote access. The relevant analytical variables are supportability, observability, recoverability, authentication capability, configuration control, component provenance, network architecture, spare availability and the operator’s ability to verify the physical state independently. NIST emphasizes that OT security must preserve performance, reliability and safety while accounting for equipment lifecycles that are typically longer than conventional IT lifecycles. Guide to Operational Technology Security, NIST Special Publication 800-82 Revision 3 – National Institute of Standards and Technology – September 2023verified primary source. Southern European water infrastructure magnifies lifecycle diversity because utilities may control mountain sources, wells, reservoirs, urban treatment plants, coastal desalination, wastewater facilities and thousands of dispersed pumping or pressure-management assets. Energy systems add substations, distributed renewables, island generation, gas infrastructure and market-control functions. Modernization frequently occurs incrementally, producing mixed estates in which a modern HMI displays information originating from older controllers and field instruments through gateways, protocol converters or vendor-specific integrations. The resulting risk is epistemic as much as technical: operators may see a unified graphic representation of equipment whose underlying data quality, timing and control capabilities differ materially. A cybersecurity programme focused only on patching will miss unsupported firmware, uncertain asset inventories, undocumented dependencies, mismatched clocks, fragile replacement procedures and obsolete engineering knowledge. The priority is risk-ranked lifecycle governance. Critical assets that cannot be replaced immediately require compensating protections, controlled access, configuration baselines, independent monitoring and tested restoration. Modernization should preserve the operator’s ability to reason about the process rather than adding opaque abstraction.

Legacy-OT dimensionWeak assessmentHigh-value assessmentResilience decision
AgeInstallation year aloneAge plus support, condition and operational criticalityReplace only where risk justifies disruption
ConnectivityConnected or isolatedActual pathways, trust relationships and temporary accessRemove unnecessary paths and govern exceptions
VisibilityAsset appears in inventoryState, firmware, configuration, owner and dependencies knownPrioritize blind assets
AuthenticationPassword capabilityIdentity, purpose, privilege and session accountabilityAdd compensating controls where native capability is weak
RecoveryBackup reportedBackup restored and validated against safe configurationExercise recovery
Time integrityClock existsEvents align across HMI, historian, controller and access systemsCorrect forensic blind spots
Process verificationHMI values availableCritical variables corroborated independentlyReduce single-interface dependence

Seasonal demand as a predictable but underestimated threat window

Seasonal demand should not be treated merely as a planning statistic because it changes the entire operating context in which anomalies are interpreted. Southern-periphery summer conditions can combine tourism, irrigation, heat-driven cooling, wildfire precautions, lower river flows, hydropower constraints, high evaporation, water-quality challenges and maintenance restrictions. The individual peak for each variable may not occur on the same day; the strategic risk emerges when several remain elevated long enough to consume operational flexibility. Tourism can multiply the effective population of islands and coastal municipalities while staffing patterns, temporary accommodation and transport activity complicate demand forecasting. Heat raises electricity consumption for cooling and can affect equipment performance, while water utilities may require more energy to move water over longer distances or operate desalination and reuse systems more intensively. Drought can also constrain thermal generation where cooling-water availability matters, although the importance varies by generation mix and installation. ENTSO-E’s 2026 Summer Outlook reports continuing expansion of renewable capacity across Europe and evaluates whether available resources and cross-border exchanges can cover demand under seasonal conditions. Summer Outlook 2026 – European Network of Transmission System Operators for Electricity – 2026verified primary source. An adequacy outlook cannot represent every distribution-level restriction, ramping constraint or local OT dependency; ENTSO-E’s associated methodology notes important modelling simplifications. Consequently, national adequacy does not guarantee that every municipality, island or water facility possesses adequate local resilience. Operators need layered seasonal thresholds that combine reservoir position, groundwater status, desalination availability, electricity margin, interconnector status, wildfire access, staffing, maintenance backlog and trusted-telemetry coverage. A high-risk window should trigger heightened verification and reduced discretionary change, not panic or attribution. The purpose is to recognize when ordinary uncertainty could produce unusually large consequences.

Seasonal variableNormal planning viewSecurity-adjusted interpretationRequired indicator
HeatCooling-demand forecastHigher load plus equipment and workforce stressTemperature-adjusted reserve margin
TourismConsumption forecastRapid population change and temporary operational loadDaily population-equivalent demand
IrrigationAgricultural allocationPumping concentration and remote-site activityEnergy and water abstraction profile
DroughtResource deficitLower redundancy and altered operating baselinesStorage, WEI+ and source availability
WildfireCivil-protection hazardField-access, telecom and line exposureAsset accessibility and route redundancy
MaintenanceSeasonal work programmeIncreased legitimate privileged activityAuthorized-change reconciliation rate
Renewable variabilityGeneration forecastNeed for balancing and interconnectionForecast error and available flexibility

Analysis of Competing Hypotheses

A southern-periphery anomaly requires an ACH structure capable of distinguishing a hostile act from climate, infrastructure and operational explanations. H₁ is ordinary equipment degradation or sensor failure; H₂ is scarcity-driven reconfiguration that was legitimate but poorly documented; H₃ is operator error under seasonal workload; H₄ is communications or interconnection disturbance; H₅ is a supply-chain or vendor-support failure; H₆ is malicious cyber manipulation; H₇ is physically or insider-enabled interference; H₈ is a compound climate–technical event; and H₉ is a coordinated hybrid action exploiting an already stressed system. The prior probability of H₈ may increase during a heatwave or drought without increasing the probability of H₉ by the same amount. Geopolitical tension should never be treated as a substitute for technical evidence. Conversely, the existence of severe environmental stress does not exclude malicious exploitation. Investigators should identify evidence that discriminates: whether the affected state is consistent with process physics; whether independent measurements agree; whether a configuration change had a valid work order; whether the anomaly is geographically correlated with weather or with shared vendor activity; whether access records align with task requirements; and whether apparently separate water and energy anomalies share a time source, communications dependency or contractor. Bayesian updates should discount correlated observations. Five alarms originating from the same defective sensor are not five independent facts. Monte Carlo modelling should focus on consequence distributions—detection delay, storage depletion, restoration time, interconnector availability and demand—not fabricate a probability that a named actor will attack. The result may legitimately remain unresolved. An analytically honest “compound anomaly with insufficient attribution evidence” is more useful than a prematurely confident conclusion that sends operators toward the wrong recovery strategy.

EvidenceH₁ failureH₂ reconfigurationH₃ errorH₄ interconnectionH₅ vendorH₆ cyberH₇ physical/insiderH₈ climate compoundH₉ hybrid
Similar anomalies across drought-affected sitesNCNNNNICN
Independent field measurement contradicts HMICNNNCCCNC
Unapproved change during legitimate maintenanceICCICCCIC
Cross-border electrical disturbance precedes water anomalyIIICNNNCN
Valid access without valid operational purposeIININNCIC
Weather explains timing and geographic distributionNNNNNIICI
Coordinated disinformation accompanies disruptionIIIIINNIC

Legend: C means broadly consistent, I inconsistent and N neutral or weakly diagnostic.

Outlook 2027–2031

The five-year baseline is a gradual rise in compound exposure rather than an inevitable rise in successful hostile action. During 2027, implementation of the Critical Entities Resilience framework and the European Water Resilience Strategy should push more operators toward all-hazards assessments, but formal compliance may initially move faster than engineering remediation. During 2028, water-efficiency investment, smart metering, desalination, reuse and distributed renewable integration will expand visibility while increasing the number of connected assets and vendor relationships requiring governance. During 2029, AI-assisted forecasting and digital twins will become more influential in water allocation, predictive maintenance and grid management. Their benefit will depend on data lineage: an analytic layer cannot provide independent verification when it relies on the same defective or compromised source as the primary HMI. During 2030, interconnections and cross-border flexibility should reduce isolation for parts of the Mediterranean, but restoration dependencies and converter or landing-point criticality will become more prominent. By 2031, repeated hot-dry seasons could produce the most consequential divergence between operators that invested in loss reduction, verified telemetry, storage, workforce capability and degraded-operation exercises and those that digitized without addressing physical-system fragility. The priority hierarchy is clear. First, reduce resource losses and uncertainty simultaneously. Second, establish independent verification for critical water and energy variables. Third, reconcile physical, logical and contractor access with work purpose. Fourth, test operations during loss of primary supervisory visibility. Fifth, map water–electricity–telecommunications dependencies at installation level. Sixth, maintain climate-adjusted seasonal thresholds and pre-authorized escalation criteria. Seventh, preserve local engineering competence during modernization. Southern Europe’s vulnerability is not geographic destiny. It is the product of margins, dependencies and observability—and those variables can be changed.

YearDominant developmentPrincipal riskRequired resilience milestone
2027All-hazards compliance implementationDocumentation exceeds operational capabilitySite-level dependency and trusted-state assessment
2028Expansion of smart water, reuse and distributed energyConnected-asset and vendor proliferationUnified asset, access and change governance
2029AI and digital-twin integrationCorrelated trust in shared dataIndependent data-lineage and model assurance
2030Greater Mediterranean interconnectionNew common-mode dependenciesCross-border restoration and fallback exercises
2031Stronger climate and seasonal variabilityPersistent compound stressMeasurable reduction in ambiguity and recovery time
SOUTHERN PERIPHERY · SYNTHETIC FORESIGHT

Figure 2: Seasonal Infrastructure Stress, 2027–2031

Composite index 0–100. Scenario output, not observed attack probability.
Water pressure
Scarcity, leakage, storage and treatment dependence
Energy pressure
Cooling demand, imports and interconnector reliance
Legacy-OT burden
Lifecycle, visibility and integration constraints
Compound exposure
Joint detection-and-consequence pressure

Method: transparent scenario indices derived from directional assumptions about climate stress, seasonal demand, import/interconnection dependence, legacy OT and resilience investment. They are not empirical country scores, installation measurements or forecasts of hostile action.

2026–2031 Outlook: From Ambiguous Anomaly to Measurable Resilience

Forecasting discipline under radical uncertainty

The 2026–2031 outlook for HMI deception, physical access, insider enablement and operational ambiguity must begin by separating four quantities that are frequently—and dangerously—collapsed into a single “risk score”: the probability that an abnormal event will occur; the probability that a particular hypothesis explains an observed event; the severity of the consequences if that hypothesis is true; and the analyst’s confidence in the evidence used to reach the assessment. A low-frequency hypothesis can justify urgent resilience investment when its consequences are severe and existing controls are difficult to validate. Conversely, a technically plausible hostile hypothesis should not dominate an investigation when ordinary equipment failure, configuration drift or undocumented maintenance better explains the available evidence. ENISA defines a cyber stress test as a targeted assessment of an entity’s ability to withstand and recover from significant incidents while maintaining critical services; it explicitly states that stress tests are not forecasts, but instruments for identifying failure points, interdependencies and resilience gaps. Handbook for Cyber Stress Tests – European Union Agency for Cybersecurity – May 2025verified primary source. This distinction should govern the entire five-year model. The outlook does not claim that a specific number of “HMI ghosting” incidents will occur, because no official incident taxonomy or reporting series supports such precision. It assesses how the opportunity for display–process divergence, unauthorized control and delayed classification may evolve as utilities add connectivity, AI, digital twins, remote services and distributed infrastructure while continuing to operate legacy assets. The central forecast is that operational ambiguity will increase unless the growth of digital complexity is matched by independent process verification, controlled access, evidence integration and tested recovery. The most important future metric is therefore not merely incidents prevented, which is difficult to observe, but the time required to establish a trusted physical state and restore accountable control when the primary interface or control path cannot be assumed reliable.

QuantityCorrect analytical questionCommon misuseRequired output
Event probabilityHow likely is an abnormal condition within a defined period?Treating possibility as probabilityRange with assumptions
Hypothesis posteriorWhich explanation best fits the observed evidence?Treating it as general attack frequencyRelative, incident-specific probability
Consequence severityWhat happens if the hypothesis is true?Multiplying arbitrary scoresService, safety, economic and recovery distribution
Evidence confidenceHow reliable, independent and complete is the evidence?Hiding uncertainty inside one scoreExplicit confidence grade
Resilience maturityCan the operator withstand, verify and recover?Equating policy existence with capabilityTested performance metrics
Attribution confidenceWhat actor-level evidence supports responsibility?Inferring responsibility from motive or capabilitySeparate technical and actor assessments

Competing hypotheses for the 2026–2031 environment

The core Analysis of Competing Hypotheses should retain at least seven explanations throughout initial triage. H₁ is ordinary technical failure involving sensors, communications, controllers, field equipment or supporting power. H₂ is human error, undocumented maintenance or configuration drift. H₃ is remote cyber compromise affecting visibility, command or engineering functions. H₄ is malicious, coerced or negligent insider enablement through legitimate access. H₅ is unauthorized physical intervention or local-control activity not accurately represented at the supervisory layer. H₆ is a compound climate–technical event in which heat, drought, flooding, wildfire or energy stress creates abnormal process behavior. H₇ is coordinated hybrid activity combining cyber, physical, insider, economic or information effects. An eighth hypothesis, H₈, should cover vendor or supply-chain failure because the same supplier, software component or maintenance process may connect otherwise separate installations. These hypotheses are not mutually exclusive in reality: a climate event may expose a technical weakness that an opportunistic actor subsequently exploits, while poor maintenance documentation may conceal or imitate insider behavior. ACH remains useful because it forces investigators to identify which evidence would be expected or unexpected under each proposition. ENISA’s 2030 foresight assessed advanced hybrid threats as increasingly combining physical or offline activity with cyber operations and identified manipulation of hardware or software, abuse of authorizations and physical access among relevant future concerns. Identifying Emerging Cybersecurity Threats and Challenges for 2030 – European Union Agency for Cybersecurity – March 2023verified primary source. That official foresight supports maintaining H₇; it does not establish that H₇ should receive the highest prior in every incident. Analysts must actively search for disconfirming evidence. A verified equipment defect with a complete physics-consistent failure sequence should reduce hostile hypotheses even during geopolitical tension. An unexplained access event may raise H₄ and H₅, but only if identity, location, timing, purpose and operational consequences are independently established.

HypothesisCore propositionEvidence expectedEvidence that weakens itPrincipal collection requirement
H₁ Technical failureEquipment or communications degraded naturallyFailure signatures, condition history, consistent process physicsConcealed configuration change or coordinated cross-site timingEngineering inspection and independent measurement
H₂ Human or maintenance errorLegitimate activity produced an unintended stateWork activity, procedural deviation, incomplete documentationNo relevant activity or deliberate concealmentWork orders, interviews and change records
H₃ Remote cyber compromiseDigital access altered visibility or controlAccount, network, controller or engineering anomaliesVerified isolation and no affected digital pathOT telemetry and identity evidence
H₄ Insider enablementAuthorized access supported unauthorized effectsValid access with invalid purpose or sequenceComplete supervision and independently verified workPhysical–logical access reconciliation
H₅ Physical interventionLocal activity changed effective control or process statePhysical evidence and supervisory inconsistencyNo plausible physical opportunityField inspection and zone-level access data
H₆ Climate–technical compoundEnvironmental stress produced or amplified failureGeographic and temporal weather correlationAnomaly inconsistent with environmental exposureWeather, demand and asset-condition correlation
H₇ Coordinated hybrid actionSeveral domains were synchronized for strategic effectCross-domain timing, targeting logic and independent hostile evidenceOne ordinary failure chain explains all observationsMulti-agency chronology and attribution evidence
H₈ Vendor or supply chainShared provider or component created common exposureSame supplier, update or maintenance patternIndependent systems with no shared dependencySupplier lineage and deployment records

Bayesian indicators: what should change analytical probability

Bayesian updating provides a disciplined language for revising beliefs, but the calculation is only as defensible as the priors, likelihoods and independence assumptions supplied to it. Operators should establish priors using their own equipment-failure history, maintenance quality, personnel-access environment, architecture, threat reporting and seasonal conditions. A regional or vendor-wide statistic should not be imported into a specific plant model without demonstrating comparability. Each observation must then be assessed on three axes: reliability of the source, independence from other observations and diagnosticity across competing hypotheses. An HMI alarm, historian entry and automated SOC alert may appear to be three sources while all derive from the same underlying sensor or timestamp. Counting them independently would exaggerate the update. Conversely, a calibrated field instrument, a safety system with a separate data path and a physical process measurement may provide genuinely independent corroboration. CISA’s 2026 guidance on adapting Zero Trust to OT applies verification principles while recognizing OT’s safety, reliability and availability requirements. Adapting Zero Trust Principles to Operational Technology – Cybersecurity and Infrastructure Security Agency and international partners – April 2026verified primary source. In this context, “never trust, always verify” should not be interpreted as indiscriminately adding latency or authentication to time-critical control functions. Its analytical value is that identity, device, communication, process state and operational purpose should not inherit trust merely from network location or successful login. The highest-value Bayesian indicators are combinations that are difficult for benign explanations to produce: independent field evidence contradicting the HMI; valid physical access without a corresponding authorized task; synchronized anomalies across separated sites sharing a supplier or communications dependency; or safety-system data that agree with process physics while the supervisory representation does not. None establishes actor identity by itself. It changes the relative probability of hypotheses and determines the next collection action.

IndicatorReliability requirementHypotheses increasedHypotheses reducedUpdate strength
Independent field measurement contradicts HMICalibrated device, separate path, trusted timeH₃, H₄, H₅, H₈Pure display-free equipment explanationHigh for divergence; low for attribution
Valid badge, invalid work purposeIdentity and location independently confirmedH₄, H₅H₁, H₆High
Multiple alarms from one sensorShared provenance documentedNone materiallyNoneVery low; one evidence family
Cross-site synchronizationCommon time reference and independent sitesH₃, H₇, H₈Isolated H₁High
Weather-aligned geographic patternAuthoritative environmental data and exposed assetsH₆H₄, H₅, sometimes H₇Moderate to high
Verified degraded componentInspection, history and physics-consistent chainH₁H₃–H₇High
Unusual privileged actionFull identity and task contextH₂, H₃, H₄, H₈H₆Moderate until purpose is established
Public claim of responsibilityAuthenticated publication and timingH₇ slightlyNone conclusivelyLow without technical corroboration

From qualitative ACH to auditable posterior ranges

A defensible Bayesian workflow should preserve an audit trail showing how every observation affected every hypothesis, rather than producing an unexplained number in a dashboard. The process begins with explicit priors expressed as ranges where evidence is weak. Analysts then record each observation, source, timestamp, provenance, reliability grade, relationship to other evidence and likelihood under each hypothesis. The resulting posterior should be accompanied by sensitivity analysis: if changing one uncertain likelihood assumption reverses the ranking, the conclusion is fragile and must be reported as such. If H₁ remains dominant across a wide range of assumptions, confidence can increase even when the exact percentage remains uncertain. Decision thresholds should be based on expected consequence and reversibility, not solely on whichever hypothesis ranks first. An operator may need to enter a carefully engineered degraded state while H₁ and H₃ remain evenly balanced, because both imply that primary HMI information cannot be trusted. Directive (EU) 2022/2557 requires critical entities to conduct risk assessments addressing relevant natural and human-induced risks and implement proportionate resilience measures. Directive on the Resilience of Critical Entities – European Parliament and Council – December 2022verified official text. The Commission’s 2026 guidelines further support consistent application of the Directive and the identification of risks capable of disrupting essential services. Guidelines on the Application of Directive (EU) 2022/2557 – European Commission – 2026verified official source. These obligations align with Bayesian governance because both require the operator to reason across cyber, physical, climatic, personnel and supply-chain factors. The mature output is not “cyberattack probability 67%.” It is a statement such as: H₃ and H₄ jointly dominate because two independent evidence families contradict H₁ and H₂; confidence remains moderate because controller-state records are incomplete; protective action is justified because continued operation under either leading hypothesis exceeds the operator’s tolerance.

Analytical fieldMinimum contentQuality-control question
PriorRange, source and reference classIs it installation-relevant or merely generic?
ObservationExact fact without interpretationWhat was directly observed?
ProvenanceOrigin, custody and transformationCan the evidence be reproduced?
ReliabilitySource and collection confidenceCould the source be mistaken or compromised?
IndependenceRelationship to other observationsAre multiple alerts derived from one origin?
Likelihood judgmentCompatibility with each hypothesisWhat would be expected if the hypothesis were true?
PosteriorRange and sensitivityDoes the ranking survive reasonable assumption changes?
Decision relevanceAction, consequence and reversibilityWhat must be done before attribution is complete?
ConfidenceHigh, moderate or low with reasonsWhat evidence is missing?

Scenario architecture for 2026–2031

The scenario model should use at least five distinct futures because a baseline-versus-catastrophe comparison conceals the policy choices that determine resilience. Scenario S₁, managed modernization, assumes continued digitalization accompanied by gradual asset discovery, access governance and lifecycle replacement. Scenario S₂, accelerated convergence, assumes remote services, AI-supported operations, distributed generation, desalination and smart-water infrastructure expand faster than verification and workforce capability. Scenario S₃, climate-stress amplification, assumes repeated hot-dry summers compress water and electricity margins while increasing tourism, cooling and pumping demand. Scenario S₄, hybrid-pressure environment, assumes geopolitical tension raises the frequency of ambiguous physical, cyber, proxy and information incidents without necessarily producing destructive effects. Scenario S₅, resilience acceleration, assumes operators implement independent sensing, cross-domain event correlation, trusted recovery baselines, contractor control, cross-border exercises and spare-equipment strategies. Scenario S₆, regulatory–operational gap, assumes policies and assessments proliferate while technical remediation and testing remain incomplete. ENISA’s stress-test handbook recommends plausible scenarios, different stress levels and resilience metrics such as time to detect and time to recover; it also emphasizes systemic risk and cascading interdependencies. Handbook for Cyber Stress Tests – European Union Agency for Cybersecurity – May 2025verified primary source. Scenarios should not encode attack instructions. They should specify which evidence sources are unavailable, which service dependencies are stressed and which decisions leaders must make. The key comparative output is resilience loss under each scenario: how long the operator requires to establish trusted state, maintain minimum service, resolve authority, mobilize field verification and restore a validated configuration.

ScenarioPrincipal assumptionExpected ambiguity trendPrimary resilience test
S₁ Managed modernizationConnectivity and assurance grow togetherModerate, then decliningWhether controls scale with new assets
S₂ Accelerated convergenceConnectivity outpaces governanceStrongly increasingWhether independent truth survives complexity
S₃ Climate-stress amplificationRepeated compound seasonal stressEpisodically severeWhether minimum service survives reduced margins
S₄ Hybrid-pressure environmentMore ambiguous cross-domain incidentsPersistently highWhether attribution uncertainty delays protection
S₅ Resilience accelerationVerification and recovery receive sustained investmentDecliningWhether improvements are demonstrated in exercises
S₆ Regulatory–operational gapDocumentation exceeds engineering executionHidden until crisisWhether controls exist beyond policy statements

Monte Carlo modelling without invented certainty

Monte Carlo simulation is appropriate for consequences and operational performance because many relevant quantities are uncertain but measurable: detection delay, field-verification time, reservoir or fuel margin, repair duration, spare-part lead time, communications availability, interconnector status, staff mobilization and demand. The model should sample these variables thousands of times from empirically justified distributions and calculate outcomes such as service interruption, population-equivalent exposure, unserved electricity or water, recovery cost and probability of exceeding continuity thresholds. The simulation should preserve correlations. Heat may simultaneously increase electricity demand, water demand and equipment stress; treating those variables as independent would understate tail risk. Drought may reduce hydropower flexibility while increasing pumping and desalination requirements. A common telecommunications failure can delay both operational control and crisis coordination. Attack frequency should not be inserted as a precise distribution unless the operator possesses a defensible, relevant dataset. Instead, the model can condition consequences on scenarios: if primary HMI trust is lost for a specified interval, what is the distribution of service outcomes under different reserve and verification assumptions? The European Commission notes that energy systems present real-time requirements, cascading cross-border effects and challenges created by integrating legacy equipment with new automation and connected devices. Critical Infrastructure and Cybersecurity – European Commission, Directorate-General for Energy – updated 2026verified primary source. These conditions justify modelling dependencies rather than isolated assets. Every simulation output should include median, high-percentile and extreme-tail results, input assumptions and sensitivity. A policy that performs well only under median conditions is not resilient. Conversely, designing every facility for an unconstrained worst case may be economically impossible. The purpose is to identify which investments most reduce the harmful tail: additional storage, independent sensors, communications diversity, faster field confirmation, spare equipment, trained local control or cross-border mutual assistance.

Simulation variablePreferred evidence sourceDistribution approachPrincipal outcome affected
Detection delayIncident and exercise historyEmpirical or lognormalDuration of unrecognized divergence
Trusted-state establishmentField-validation exercisesEmpirical or triangularAmbiguity interval
DemandSeasonal operational recordsWeather-conditioned empiricalContinuity margin
Water, fuel or storage reserveOperator recordsScenario-conditioned rangeTime before service restriction
Repair timeAsset-specific historyHeavy-tailed empiricalRecovery duration
Spare-part lead timeProcurement and inventory dataDiscrete supplier scenariosExtreme recovery tail
Communications availabilityReliability historyState-transition modelCoordination and remote visibility
Interconnector availabilityTSO and operator dataConditional scenarioRegional balancing capacity
Workforce mobilizationExercise recordsEmpirical distributionField confirmation and restoration
Evidence integrityAudit and architecture reviewDiscrete maturity stateConfidence in diagnosis

Five-year trajectory

During 2026, the dominant requirement is to establish baselines. Operators cannot perform meaningful Bayesian updating when asset inventories, data lineage, access ownership and configuration history remain incomplete. CISA’s January 2026 secure-connectivity principles for OT provide a defensive framework for designing and managing connections into industrial environments. Secure Connectivity Principles for Operational Technology – Cybersecurity and Infrastructure Security Agency and partners – January 2026verified primary source. During 2027, CER implementation and NIS2-related measures should push entities toward integrated risk assessments, but regulatory compliance will need to be tested against operating performance. During 2028, the main exposure will shift toward third-party and remote-service ecosystems as more utilities use specialized vendors, cloud analytics and managed operations. During 2029, AI integration will become a major assurance problem. CISA’s multinational guidance states that AI should be integrated into OT while maintaining security, reliability and safety. Principles for the Secure Integration of Artificial Intelligence in Operational Technology – Cybersecurity and Infrastructure Security Agency and international partners – December 2025verified primary source. AI can improve anomaly detection but cannot serve as independent confirmation if it consumes the same compromised data. During 2030, cross-sector and cross-border dependencies will become more important than single-asset vulnerabilities. During 2031, the central distinction will be between organizations that can demonstrate recovery through repeated exercises and those that possess extensive documentation but unverified capability. The outlook is therefore conditional: S₂, S₃ and S₆ produce rising ambiguity; S₅ can reverse the trend. Technology growth is not the independent variable. Assurance growth relative to complexity determines the trajectory.

YearDominant developmentLeading riskRequired evidence of progress
2026Connectivity and evidence baseliningUnknown assets and trust pathsValidated inventory, lineage and ownership
2027CER and NIS2 operationalizationCompliance–capability gapSite-level all-hazards exercise results
2028Vendor and remote-service expansionPrivileged third-party opacityPurpose-bound access and rapid revocation
2029AI-assisted OT operationsCorrelated data and model trustIndependent inputs, auditability and safe fallback
2030Deeper cross-sector interdependenceCascading and common-mode failureJoint water–energy–telecom exercises
2031Resilience differentiationUntested recovery at lagging entitiesMeasured reductions in detection and recovery time

Resilience priorities and investment sequencing

The highest-priority investment is the creation of independent operational truth. Every critical process variable should have a documented evidence lineage showing sensor, communications path, transformation, display and fallback verification. The second priority is authority resolution: operators must be able to determine who or what possesses effective control, whether the control state is authorized and how it can be transferred safely. The third is physical–logical reconciliation, linking personnel presence, privileged access, work orders, configuration changes and process consequences. Fourth is recovery assurance: clean configuration baselines, tested backups, spare-equipment strategies and degraded-operation procedures must be demonstrated rather than merely documented. Fifth is evidence coherence, especially trustworthy time across controllers, HMIs, historians, identity systems, physical access and safety systems. Sixth is supplier governance across the full service lifecycle, including emergency access and contract termination. Seventh is cross-sector dependency mapping, because water, electricity, telecommunications, transport and emergency response cannot be modelled independently. Eighth is workforce retention: modernization that removes local engineering understanding can create hidden dependence on external specialists. ENISA’s 2026–2028 programming identifies Union-coordinated resilience preparedness tests and supply-chain risk assessments as continuing priorities and explicitly seeks evidence that regulatory measures improve real sectoral security rather than remaining on paper. ENISA Single Programming Document 2026–2028 – European Union Agency for Cybersecurity – November 2025verified primary source. Investment should be sequenced by marginal reduction in service-risk tails, not by product novelty. A modest programme that cuts trusted-state establishment from hours to minutes may outperform an expensive monitoring platform that generates more alerts without independent validation.

Priority2026 baseline metric2031 target directionBoard-level evidence
Independent operational truthCritical variables with separate verificationToward complete coverage of safety- and service-critical variablesExercise-confirmed verification time
Authority resolutionTime to identify effective controllerStrong reductionRecorded mode and command ownership
Access reconciliationSensitive activity matched to valid purposeNear-real-time reconciliationException rate and closure evidence
Recovery assuranceBackups reportedRestorations repeatedly demonstratedSuccessful validated recovery
Time coherenceSystems using trusted synchronized timeFull critical-event coherenceReconstructable cross-domain chronology
Supplier resilienceVendors inventoriedDependencies, access and exit paths testedSupplier failure and revocation exercises
Cross-sector preparednessDependency maps documentedJoint exercises and mutual assistanceDemonstrated continuity under shared stress
Workforce capabilityTraining completionRole-specific performance under degraded conditionsExercise results, not attendance counts

Strategic judgment

The most probable 2031 outcome is neither universal infrastructure compromise nor complete resilience. It is widening divergence between mature operators and entities that digitalize faster than they can verify, govern and recover. HMI deception will remain only one component of the wider problem. The more consequential issue is whether an operator can maintain a trustworthy understanding of the physical process when interface data, access records, vendor activity and environmental stress produce conflicting explanations. Bayesian indicators provide disciplined updating, ACH prevents premature attribution, and Monte Carlo analysis quantifies consequence tails; none compensates for missing evidence or untested engineering procedures. The principal strategic warning is that ambiguity itself can become an operational effect. A hostile actor does not need to produce maximum physical damage if uncertainty delays decisions, fragments command, consumes scarce field resources or undermines public confidence. Equally, defenders can create their own strategic failure by attributing an ordinary breakdown prematurely and overlooking the equipment, maintenance or climatic cause needed for recovery. The 2026–2031 resilience programme should therefore optimize for decision quality under degraded trust. The decisive board questions are concrete: How long does it take to establish a trusted physical state? Which critical variables have independent confirmation? Can the organization operate safely without its primary HMI? Are physical and logical access events reconciled with purpose? Can clean configurations be restored? Which external services create single points of failure? Have water, energy and telecommunications dependencies been exercised together? If these questions have measured answers, rising digital complexity need not produce rising systemic risk. If the answers remain policy statements, the region’s exposure will grow even if conventional cybersecurity spending increases.

BAYESIAN ANALYTIC DEMONSTRATOR · SYNTHETIC PRIORS

Figure 3: Posterior Hypothesis Shift Under New Evidence

Relative probability allocation; illustrative only, not incident attribution.
Initial priors must come from the operator’s own history and threat environment. They are placeholders here.

Method note: each evidence package is treated as a scenario-level likelihood update. Values are normalized to 100. Real investigations must score evidence reliability, independence and diagnosticity; correlated observations must not be counted repeatedly.


Copyright of debuglies.com – Even partial reproduction of the contents is not permitted without prior authorization – Reproduction reserved

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Questo sito utilizza Akismet per ridurre lo spam. Scopri come vengono elaborati i dati derivati dai commenti.