Executive Summary
BLUF: Europe’s southern energy and water systems face a growing hybrid risk in which the control-room display, the physical process and the operator’s authority can be deliberately separated.
The most consequential pathway may require neither malware nor a conventional network compromise.
Physical access, insider enablement, unauthorized mode changes and deceptive HMI (Human Machine Interface) states can produce operational ambiguity before defenders classify an incident as hostile.
Water scarcity increases the consequences of even limited disruption in Cyprus, Malta, Greece, Italy, Spain, Portugal and Türkiye.
Existing EU legislation correctly adopts an all-hazards model, but implementation can remain divided between cybersecurity, physical protection, engineering safety and contractor management.
The five-year outlook indicates rising exposure as legacy OT, remote maintenance, distributed generation, desalination and water-reuse infrastructure become more interconnected.
The decisive defensive capability is independent verification: operators must be able to compare HMI representations with trusted field telemetry, process physics, physical-access records and authenticated operating states.
The interactive model below is a transparent scenario instrument, not a forecast of any specific installation.
Europe’s Invisible Infrastructure Threat: When the Control Room No Longer Shows Reality
Europe has fortified critical infrastructure against malware, ransomware and remote intrusion. Its next vulnerability may be harder to classify: the deliberate separation of what an operator sees from what a physical system is actually doing. In energy and water networks, manipulated human-machine interfaces, unauthorized local control, insider-enabled actions and poorly recorded maintenance can create operational effects without resembling a conventional cyberattack. The danger is greatest on Europe’s southern periphery, where water scarcity, energy dependence, island systems, tourism peaks and ageing infrastructure compress response margins. The strategic contest is no longer confined to penetrating networks. It concerns control over operational reality—and the ability of governments and utilities to establish the truth before a localized anomaly becomes a regional crisis.
The New Attack Surface
Human-machine interfaces, or HMIs, translate thousands of process measurements into the graphical environment from which operators supervise pumps, treatment stages, reservoirs, substations, breakers and generation assets. If that representation becomes incomplete, delayed or deceptive, the control room may continue making technically legitimate decisions on the basis of an inaccurate process state.
The risk is documented, not theoretical. In September 2022, the US Cybersecurity and Infrastructure Security Agency described how an adversary could prevent an HMI from updating while selectively changing the information shown to the operator. In December 2024, CISA warned that exposed water-sector HMIs could allow unauthorized parties to view interfaces and modify operational settings where adequate controls were absent. Control System Defense: Know the Opponent – CISA – September 2022; Internet-Exposed HMIs Pose Cybersecurity Risks to Water and Wastewater Systems – CISA – December 2024.
Yet remote compromise is only one pathway. Effective control can also be altered through authorized credentials used for an unauthorized purpose, unsupervised contractor access, an undocumented maintenance change or a transition to local operation that supervisory systems fail to represent correctly. The essential distinction is between authentication and authority: a valid identity does not prove that an action is operationally authorized.
The Southern Exposure
The Mediterranean risk profile is shaped by consequence, not simply by the number of vulnerabilities. The European Environment Agency reported that water scarcity affected 28% of EU territory and 32% of the EU population during at least one quarter of 2023. Approximately 30% of southern Europe’s population lives under permanent water stress, while as much as 70% can experience summer stress. Cyprus and Malta exceeded the severe-scarcity threshold of 40% on the seasonal Water Exploitation Index Plus; Greece, Portugal, Italy and Spain experienced pronounced scarcity during spring and summer. Water Scarcity Conditions in Europe – European Environment Agency – November 2025.
These figures alter the security calculation. A pumping anomaly during a period of abundant storage may remain manageable. The same event during drought, extreme heat and peak tourism can affect pressure, treatment, allocation and emergency reserves before investigators determine whether the cause is technical, accidental or hostile.
Seasonality also raises electricity demand for cooling precisely when water networks may require more energy for pumping, reuse and desalination. Drought can reduce hydropower flexibility; heat and wildfires can restrict field access; coastal and island populations can expand rapidly during the tourism season. The result is a recurring period in which both operational margins and diagnostic time contract.
Italy’s Double Deficit
Italy illustrates the convergence between resource loss and informational uncertainty. ISTAT calculated that in 2022 the country abstracted 9.1 billion cubic metres of water for drinking purposes, equivalent to 424 litres per resident per day. Approximately 8 billion cubic metres entered municipal networks, but only 4.6 billion were delivered for authorized uses.
Total distribution losses reached 3.4 billion cubic metres, or 42.4% of all water introduced into the networks. According to ISTAT, that volume could have met the annual water requirements of 43.4 million people. Water Statistics, 2020–2023 – Italian National Institute of Statistics – March 2024.
Not all reported losses represent physical leakage: measurement errors, apparent losses and unauthorized consumption can contribute to the total. That distinction is strategically important. Imperfect metering and uncertain network balances weaken the independent evidence against which operators can test what an HMI displays.
Modernizing Italy’s water networks is therefore not only a conservation policy. District metering, verified sensor calibration, trusted timestamps and reconciliation among inflow, storage, pressure and consumption reduce the informational space in which errors or deception can remain credible. Every litre that becomes measurable improves both efficiency and security.
The Island Equation
Malta and Cyprus present an even tighter water-energy nexus. In 2021, desalination supplied approximately 50% of public water in both countries, compared with only 1.4% across the EU. Water Savings for a Water-Resilient Europe – European Environment Agency – June 2025.
Desalination provides strategic protection against rainfall volatility, but it makes water availability more dependent on electricity, specialist maintenance, membranes, chemicals and the coordination of production, storage and distribution. Eurostat reported that in 2024 energy-import dependence reached 98% in Malta and 88% in Cyprus, against an EU average of 57%. Energy in Europe, 2026 Edition – Eurostat – 2026.
Interconnections can reduce isolation, but they create additional infrastructure to protect: subsea cables, converter stations, landing points, metering systems and cross-border control channels. The European Commission’s second Union list of Projects of Common and Mutual Interest, adopted on 1 December 2025, retained the proposed connection of Malta to the European gas network through Gela in Sicily. Second Union List of Projects of Common and Mutual Interest – European Commission – December 2025.
The strategic objective must be resilient interdependence, not isolation: diversified supply combined with protected nodes, alternative communications and restoration plans tested across national boundaries.
Legacy Meets Connectivity
Europe’s energy systems contain equipment installed long before modern cybersecurity requirements existed. The European Commission identifies three structural complications: real-time operating requirements can limit the use of conventional authentication mechanisms; interconnected grids can propagate disruption across borders; and legacy systems must now interact with smart meters, connected appliances and modern automation. Critical Infrastructure and Cybersecurity – European Commission, Directorate-General for Energy – updated 2026.
Age alone does not make equipment insecure. A well-understood older controller with tightly governed access may present less risk than a newly connected platform with opaque dependencies. The decisive questions concern supportability, configuration control, recoverability, data lineage, spare parts and the operator’s ability to verify physical conditions independently.
Incremental modernization creates mixed estates: a contemporary HMI may display data originating from older controllers through gateways, protocol converters and proprietary interfaces. The screen appears unified; the underlying reliability, timing and security assumptions are not. This is where operational ambiguity grows.
The Insider Dimension
Insider risk should not be reduced to identifying malicious employees. It includes contractors, integrators, temporary staff, vendors and former personnel whose access has not been fully withdrawn. Enablement may be deliberate, coerced, negligent or entirely unintentional.
A contractor may possess valid building access but no authorization for a specific cabinet or change. An engineer may use legitimate privileges outside the approved maintenance sequence. Emergency vendor support may resolve one failure while introducing an undocumented configuration. None of these events proves hostile intent; each creates an evidentiary gap.
The correct control is purpose-bound access. Identity, location, time, equipment, assigned task, configuration change and observed process effect must form one auditable chain. CISA’s April 2026 guidance on adapting Zero Trust to operational technology reinforces continuous verification while recognizing the safety and availability requirements of industrial systems. Adapting Zero Trust Principles to Operational Technology – CISA and International Partners – April 2026.
Europe’s Regulatory Pivot
The EU has begun moving from a cyber-only model toward all-hazards resilience. Directive (EU) 2022/2557, adopted on 14 December 2022, requires critical entities in sectors including energy, drinking water and wastewater to assess natural and human-induced risks and implement proportionate resilience measures. Directive on the Resilience of Critical Entities – European Parliament and Council – December 2022.
Italy transposed the NIS2 Directive through Legislative Decree No. 138 of 4 September 2024, published in the Official Gazette on 1 October 2024. The measure designates the National Cybersecurity Agency, ACN, as the competent national authority. Legislative Decree No. 138/2024 – Italian Official Gazette – October 2024.
The unresolved issue is implementation. Compliance documents cannot establish whether a utility can identify the effective controller, validate the physical process without its primary HMI, revoke emergency access or restore a clean configuration. ENISA defines stress testing as an assessment of preparedness, response and recovery, using metrics such as time to detect and time to recover. Handbook for Cyber Stress Tests – ENISA – May 2025. Europe now needs equivalent metrics for establishing a trusted physical state.
Water as Industrial Policy
The Commission’s Water Resilience Strategy contains more than 50 actions and sets the objective of improving EU water efficiency by 10% by 2030. It also calls for reduced network leakage, infrastructure modernization, digitalization, artificial intelligence and stronger security preparedness.
The economic dimension is substantial. The Commission estimates that Europe’s water industry generates €107 billion, supports 1.7 million jobs and holds 40% of global water-technology patents. It places the annual health-related cost associated with persistent PFAS pollution at €52–84 billion. European Water Resilience Strategy – European Commission – updated June 2026.
This turns infrastructure security into industrial strategy. Europe can build an exportable market in secure sensors, leakage analytics, resilient automation, trusted industrial AI, digital-twin assurance and recovery engineering. But digitalization without independent verification would modernize the interface faster than the underlying truth.
The 2031 Divide
By 2031, the decisive divide will not run between digital and analogue utilities. It will separate entities capable of proving resilience from those that merely report it. The mature operator will know which critical variables possess independent confirmation; who holds effective control; how physical and logical access relate to authorized work; how quickly a trusted state can be established; and whether minimum service can continue without the primary supervisory interface.
The alternative is a dangerous paradox: more sensors, more automation and more dashboards, but less certainty about which representation deserves trust.
Europe’s southern periphery is the place where this question becomes urgent first. Water scarcity, imported energy, island logistics, interconnectors and seasonal demand convert delayed diagnosis into economic and political exposure. The cost of inaction will not necessarily appear as a spectacular cyberattack. It may emerge as an unexplained sequence of local failures whose combined effect reveals that Europe digitized its critical infrastructure without securing its operational reality.
Navigational Index
- Threat convergence — HMI deception, physical access, insider enablement and operational ambiguity
- Southern-periphery exposure — water stress, energy interdependence, legacy OT and seasonal demand
- 2026–2031 outlook — competing hypotheses, Bayesian indicators, scenarios and resilience priorities
Master Abstract
The control interface as contested reality
“HMI (Human Machine Interface) ghosting” is best treated as an analytical category rather than a standardized technical term: it describes circumstances in which the picture presented to operators becomes materially different from the physical state, command path or control authority of the underlying process. That divergence may arise from malicious display manipulation, compromised data acquisition, unauthorized local operation, deceptive maintenance activity, sensor disagreement or a physical intervention that the supervisory environment cannot reliably observe. The crucial distinction is that an adversary does not necessarily need to achieve the classic objective of persistent remote penetration. If a hostile actor can exploit legitimate access, manipulate the operator’s confidence, interfere with independent verification or cause an unauthorized transition between supervisory and local control, the resulting operational effect can cross the cyber–physical boundary while leaving conventional perimeter telemetry incomplete. CISA has explicitly documented the defensive significance of HMI integrity: an actor may prevent an operator display from updating while selectively changing what the operator sees. Control System Defense: Know the Opponent – Cybersecurity and Infrastructure Security Agency – September 2022 — verified primary source. CISA subsequently warned that exposed water-sector HMIs can permit unauthorized visibility and operational changes when safeguards are absent. Internet-Exposed HMIs Pose Cybersecurity Risks to Water and Wastewater Systems – Cybersecurity and Infrastructure Security Agency – December 2024 — verified primary source. These documents establish the plausibility of display–process divergence, but they should not be misread as evidence that every anomalous display indicates a sophisticated attack. Sensor failure, stale data, maintenance errors and ordinary control-system defects remain strong competing explanations. The intelligence problem is therefore forensic attribution under uncertainty: investigators must correlate control-room observations with trusted field measurements, physical-access records, maintenance authorization, controller state, safety-system events and process constraints. No single log source can establish the truth when the interface itself may be part of the contested evidence.
Why Europe’s southern periphery carries disproportionate consequence
The southern European exposure is not adequately represented by counting internet-facing devices or published vulnerabilities. Consequence depends on the interaction of water scarcity, seasonal demand, cross-border energy flows, treatment capacity, desalination dependence, aging field equipment, dispersed pumping infrastructure, contractor access and the time available for operators to detect contradictory process evidence. The European Environment Agency reported that water scarcity affected 28% of EU territory and 32% of the EU population in 2023; it further assessed that approximately 30% of southern Europe’s population lives under permanent water stress and as much as 70% can experience seasonal summer stress. Water Scarcity Conditions in Europe – European Environment Agency – November 2025 — verified primary source. Cyprus and Malta recorded the most severe seasonal conditions among EU members, while Greece, Portugal, Italy and Spain experienced pronounced spring and summer scarcity. This environmental pressure acts as a risk multiplier: when storage margins, treatment capacity or electricity availability are already constrained, a limited control disturbance can produce a larger service consequence and compress the time available for diagnosis. The Commission’s 2025 strategy consequently treats water resilience as a matter encompassing infrastructure, investment, digitalization, security and preparedness, rather than environmental management alone. European Water Resilience Strategy – European Commission, Directorate-General for Environment – June 2025 — verified primary source. Energy systems exhibit an analogous convergence. The Commission states that increased digitalization expands cyber exposure while interconnected electricity and gas systems create cascading risks, and it explicitly places malicious physical, cyber and hybrid threats within the EU preparedness framework. Critical Infrastructure and Cybersecurity – European Commission, Directorate-General for Energy – updated 2026 — verified primary source. The resulting analytic conclusion is not that southern utilities are inherently less secure. It is that equivalent technical anomalies can carry unequal strategic consequences because climatic stress, geographic distribution, interdependency and recovery logistics differ materially across Europe.
Competing hypotheses and the five-year trajectory
The 2026–2031 outlook should be governed by at least five competing hypotheses rather than a single threat narrative. H₁ — conventional cyber compromise: remote or supply-chain access alters supervisory visibility or commands. H₂ — insider-enabled manipulation: an authorized employee, contractor or coerced intermediary misuses legitimate access. H₃ — physical-control substitution: unauthorized local activity creates a process state that supervisory monitoring detects late or interprets incorrectly. H₄ — hybrid coercion: limited disruption, ambiguity and information manipulation are combined to impose political or economic costs without producing immediately attributable strategic damage. H₅ — non-hostile technical failure: maintenance defects, configuration drift, sensor failure or communications loss imitate deliberate ghosting. H₆ — compound climate–technical event: scarcity, heat, wildfire, flooding or power instability amplifies an otherwise manageable control failure. Initial priors must remain installation-specific; no defensible government dataset currently supplies a universal probability for “HMI ghosting.” Bayesian updating should therefore use evidence classes: unexplained disagreement among independent sensors; abnormal changes in local or remote operating state; unauthorized physical presence; maintenance actions inconsistent with work orders; loss of synchronized time; contradictory safety-system evidence; repeated anomalies aligned with geopolitical timing; and attempted suppression of operator escalation. Monte Carlo modeling can estimate consequence distributions only after the operator supplies validated parameters for restoration time, redundancy, reserve margins, demand, spare parts and interdependencies. The present dashboard therefore uses synthetic values and a disclosed scoring rule, not fabricated empirical precision. Structurally, the central risk is likely to rise through 2031 because digitalization expands while legacy control equipment remains in service, but the trajectory is not predetermined. Directive (EU) 2022/2557 requires an all-hazards resilience framework covering energy, drinking water and wastewater, thereby providing a legal basis for integrating physical security, continuity and cyber assurance. Directive (EU) 2022/2557 on the Resilience of Critical Entities – European Parliament and Council – December 2022 — verified official text. The highest-value intervention is consequently architectural and organizational: create trustworthy evidence paths outside the potentially deceptive interface, reconcile physical and digital access governance, test degraded operations, maintain recoverable configurations and exercise cross-sector crisis coordination.
HMI–Physical Control Divergence
Scenario controls
Illustrative Bayesian-style risk engine. It supports defensive prioritisation; it is not an incident predictor and contains no operational bypass instructions.
Elevated: verification gaps can turn local manipulation into system-level disruption.
Five-year scenario distribution
Decision thresholds
Model logic: prior exposure is updated by HMI dependence, physical access, operational stress and verification maturity. Values are synthetic scenario outputs, not measurements of any named operator or installation.
Threat Convergence: When HMI, Insider and Physical Access Merge
The disappearance of the conventional perimeter
The convergence of HMI deception, physical access, insider enablement and operational ambiguity changes the fundamental intelligence question confronting energy and water operators. The conventional model asks whether an external adversary penetrated an industrial network; the converged model asks whether operators can still determine, with independently corroborated evidence, who controls the physical process, whether the displayed state corresponds to reality and whether apparently legitimate activity remains within an authorized operational purpose. “HMI ghosting” is used here as an analytical label, not a universally standardized engineering term: it encompasses any intentional separation between the process state perceived by operators and the physical, logical or administrative state actually governing the installation. The divergence can exist at several layers: the interface may show stale or selectively altered values; a control asset may have entered an unexpected operating mode; local activity may not be represented accurately at the supervisory level; an authorized account may perform an unauthorized function; or a legitimate maintenance intervention may create evidence indistinguishable from malicious preparation. CISA has publicly described the defensive problem in precise terms: a hostile actor could prevent an operator display from updating and selectively change what is presented, thereby disrupting the operator’s ability to perceive the true process condition. Control System Defense: Know the Opponent – Cybersecurity and Infrastructure Security Agency – September 2022 — verified primary source. CISA separately warned that inadequately protected, internet-exposed water-sector HMIs may allow unauthorized parties to view interfaces and alter operational settings. Internet-Exposed HMIs Pose Cybersecurity Risks to Water and Wastewater Systems – Cybersecurity and Infrastructure Security Agency – December 2024 — verified primary source. Neither finding means that network exposure is necessary for the broader threat. It demonstrates that the HMI is not merely a screen: it is an epistemic control point through which personnel decide whether the plant is stable, abnormal or moving toward an unsafe condition. Once confidence in that evidence channel becomes contestable, physical security, personnel assurance, engineering safety and cyber incident response can no longer operate as separate governance domains.
| Convergence layer | Object requiring protection | Defensive intelligence question | High-value corroborating evidence | Primary analytical failure |
|---|---|---|---|---|
| Representation | HMI graphics, trends, alarms and timestamps | Does the displayed state correspond to the current process? | Independent field telemetry, historian comparison, trusted time source | Treating one interface as ground truth |
| Command authority | Supervisory, engineering and local-control states | Which person or system currently possesses effective authority? | Mode-state records, authorization logs, physical inspection | Assuming authenticated access equals authorized purpose |
| Physical process | Pumps, valves, breakers, drives and treatment stages | Is equipment behaving consistently with commands and process physics? | Electrical load, flow, pressure, level, chemistry and safety-system data | Investigating only digital artifacts |
| Human access | Employees, contractors, vendors and escorts | Was access legitimate, necessary, supervised and temporally consistent? | Rosters, work orders, badge records, video and tool custody | Reviewing personnel and cyber evidence separately |
| Recovery | Safe-state transition, manual continuity and restoration | Can the operator recover without trusting the suspected interface? | Tested procedures, clean baselines, independent communications | Discovering dependencies during the incident |
HMI deception as an attack on operational knowledge
An HMI-deception incident does not need to falsify every data point or maintain a flawless simulation of the plant. From a defender’s perspective, a limited inconsistency may be strategically sufficient if it delays recognition, directs attention toward the wrong subsystem, encourages an inappropriate but otherwise legitimate operator response or obscures the moment when control authority changes. The decisive variable is therefore not visual sophistication; it is whether the deceptive representation remains credible for longer than the plant’s operational tolerance permits. In an electricity environment, seconds or minutes can matter for protection, balancing and cascading conditions. In a drinking-water or wastewater system, the relevant tolerance may range from minutes to hours, depending on storage, treatment stages, redundancy and the availability of trusted laboratory or field measurements. NIST treats OT as a domain with distinctive reliability, safety and real-time requirements and explicitly includes industrial control, physical-access control and physical-environment monitoring within the security problem. Guide to Operational Technology Security, NIST Special Publication 800-82 Revision 3 – National Institute of Standards and Technology – September 2023 — verified primary source. This broader definition is crucial because a badge reader, field sensor, engineering workstation and operator display may participate in the same incident even when their logs are owned by different departments. Investigators should consequently distinguish four forms of divergence: representational divergence, in which displayed information conflicts with trusted observation; temporal divergence, in which correct information arrives too late to remain operationally useful; authority divergence, in which the assumed controller is not the effective controller; and procedural divergence, in which a technically legitimate action lacks a valid operational purpose. These categories are defensive abstractions rather than instructions for creating an incident. Their value lies in preventing premature closure. A conventional security operations centre may classify the absence of malware or remote-access evidence as exculpatory; an engineering team may classify contradictory values as sensor failure; physical security may regard a valid badge event as routine. The convergence framework treats each conclusion as provisional until cross-domain evidence has been reconciled.
| Divergence type | Observable defensive symptom | Benign explanation to test first | Hostile explanation retained | Required adjudication |
|---|---|---|---|---|
| Representational | HMI value differs from independent measurement | Calibration fault, communications loss, stale historian | Selective falsification or suppressed update | Sensor lineage and physical-process validation |
| Temporal | Alarm, trend or event arrives unexpectedly late | Congestion, clock drift, equipment failure | Deliberate delay intended to extend uncertainty | Trusted-time reconstruction |
| Authority | Command source conflicts with expected operating state | Maintenance or emergency intervention | Unauthorized assumption of local or privileged control | Work-order and access reconciliation |
| Procedural | Valid credential performs an unusual but permitted action | Human error or undocumented troubleshooting | Insider misuse or coerced action | Purpose, supervision and sequence analysis |
| Physical–digital | Equipment behavior contradicts command record | Mechanical defect or sensor disagreement | Physical interference or concealed local activity | Field inspection and independent telemetry |
Physical access as a control-plane variable
Physical access should not be modeled as a binary condition in which a person either entered a secure space legitimately or did not. In operational environments, effective access is multidimensional: identity, role, location, duration, escort status, task authorization, equipment custody, time window and the relationship between the intervention and the plant’s changing state must all align. A contractor can possess valid entry authorization while lacking authorization for a particular cabinet, engineering function or deviation from the approved work package. An employee can be correctly authenticated while acting outside duty, sequence or purpose. A maintenance team can be scheduled legitimately while poor change control makes its actions forensically indistinguishable from hostile preparation. CISA’s defense-in-depth guidance states that physical-access controls should ensure that only authorized people reach controlled spaces, while NIST emphasizes that physical and logical protections must be adapted to OT availability and safety requirements. Recommended Practice: Improving Industrial Control System Cybersecurity with Defense-in-Depth Strategies – Cybersecurity and Infrastructure Security Agency – September 2016 — verified primary source. The relevant security objective is therefore not simply exclusion; it is accountable control over the full intervention lifecycle. Defenders require a trustworthy chain linking the approved task to the person, place, device, change, observed process effect and closure evidence. An unexplained mismatch should not automatically be labeled malicious, because informal troubleshooting and incomplete documentation remain widespread causes of ambiguity. It should, however, increase the probability assigned to insider-enabled or physically enabled hypotheses when multiple independent inconsistencies co-occur. Europe’s Critical Entities Resilience framework reinforces this integration by requiring resilience against natural and human-induced risks through an all-hazards approach, rather than limiting the operator’s obligation to network security. Directive (EU) 2022/2557 on the Resilience of Critical Entities – European Parliament and Council – December 2022 — verified official text. Energy, drinking water and wastewater are explicitly within its sectoral scope, making the separation of physical protection, business continuity and cyber assurance increasingly difficult to justify.
| Access dimension | Weak evidence model | Strong evidence model | Escalation indicator |
|---|---|---|---|
| Identity | Badge accepted | Badge, roster, supervisor and task identity reconciled | Credential use inconsistent with assigned person |
| Purpose | “Maintenance” recorded | Specific asset, action, limit and expected result documented | Activity lacks a corresponding authorized change |
| Time | Entry and exit timestamps | Access aligned with process events and maintenance window | Anomaly begins during or immediately after access |
| Location | Building-level entry | Zone, cabinet or asset-level accountability | Presence near affected equipment cannot be explained |
| Equipment | Tools not recorded | Portable devices, media and specialist tools controlled | Unregistered equipment appears in a restricted zone |
| Closure | Job marked complete | Configuration, physical state and process response verified | Plant state differs from documented completion state |
Insider enablement without simplistic profiling
Insider risk must be analyzed as an opportunity structure, not as a psychological stereotype. The relevant population includes employees, temporary staff, integrators, equipment vendors, cleaning and facilities personnel, outsourced monitoring teams, consultants and former personnel whose access has not been completely withdrawn. Enablement can be deliberate, coerced, financially motivated, ideologically motivated, negligent or entirely unknowing. A privileged engineer may facilitate an incident by violating a two-person rule without malicious intent; a vendor may introduce an unapproved configuration during emergency support; a former contractor may retain documentation or credentials; a supervisor may suppress escalation to avoid reputational consequences. These pathways generate different indicators and require different interventions. NIST’s manufacturing cybersecurity practice guidance recognizes threats from malicious and non-malicious insiders alongside external actors, demonstrating that intent cannot be inferred merely from the possession of legitimate access. Protecting Information and System Integrity in Industrial Control System Environments, NIST Special Publication 1800-10 – National Cybersecurity Center of Excellence – May 2018 — verified primary source. The strongest insider-risk architecture therefore relies on separation of duties, minimum necessary privilege, rapid lifecycle management, supervised sensitive work, behavioral baselines tied to functions rather than personalities, and protection for personnel who report anomalies. Chinese government documentation provides a useful multilingual governance comparison: official industrial-control guidance emphasizes enterprise responsibility, physical and environmental protection, monitoring, incident response and organizational coordination across production, operations, maintenance and information functions. Interpretation of the Industrial Control System Information Security Action Plan – Xuchang Municipal Bureau of Industry and Information Technology – January 2018 — verified Chinese government source. This does not establish Chinese offensive intent and must not be used for attribution. It establishes that major regulatory systems recognize industrial security as an organizational and physical governance problem, not merely a firewall problem. The intelligence implication is that anomalous personnel activity should update a hypothesis only when it is linked to operational evidence, authorization inconsistencies or concealed changes.
Operational ambiguity as the principal force multiplier
Operational ambiguity is the interval during which defenders cannot determine whether they face technical failure, operator error, legitimate maintenance, malicious cyber activity, physical interference, insider misuse or a compound event. That interval is often more strategically consequential than the original anomaly because it delays protective action, fragments command authority and creates opportunities for misinformation. Energy and water organizations are particularly vulnerable when responsibility is distributed among a network operations centre, plant control room, corporate security team, outsourced integrator, municipal authority, emergency services and national regulator. Each organization may possess a valid but incomplete fragment of the evidence. The European Union Agency for Cybersecurity’s stress-test handbook describes scenarios spanning cyberattacks on SCADA, sabotage, physical insider threats, supply shortages and combined cyber–physical escalation. Handbook for Cyber Stress Tests – European Union Agency for Cybersecurity – May 2025 — verified primary source. The handbook’s value lies in treating preparedness, incident management and recovery as connected capabilities. Operational ambiguity should therefore be measured rather than discussed abstractly. Useful defensive metrics include time to establish a trusted process state; time to identify the effective control authority; percentage of critical signals with an independent verification path; proportion of privileged physical and logical activity reconciled within a defined window; percentage of emergency procedures tested without the primary HMI; and time required to produce a cross-domain event chronology. None of these metrics reveals how to bypass a system. They reveal whether defenders can reason accurately when ordinary evidence channels are unreliable. A mature operator should also establish an “epistemic safe state”: a pre-defined operational posture adopted when the organization cannot confirm that its displays, commands or access records remain trustworthy. The exact posture must be determined by qualified plant engineers because an inappropriate generic response could create additional danger. Intelligence teams should support that decision by clearly separating verified facts, inferred relationships, missing evidence and competing explanations.
| Ambiguity metric | Definition | Defensive significance | Five-year target direction |
|---|---|---|---|
| Trusted-state establishment time | Time needed to validate the physical process independently | Determines how long deception can influence decisions | Strong decrease |
| Authority-resolution time | Time needed to determine effective command ownership | Limits conflicting operator actions | Strong decrease |
| Independent verification coverage | Share of critical variables corroborated outside one interface | Reduces single-source epistemic failure | Increase toward complete critical coverage |
| Physical–logical reconciliation rate | Sensitive access events matched to authorized work and system changes | Exposes unexplained insider opportunity | Increase |
| Degraded-operation exercise rate | Critical sites exercising without primary supervisory visibility | Tests organizational rather than theoretical resilience | Increase |
| Forensic time coherence | Share of relevant systems aligned to trustworthy timing | Enables sequence reconstruction | Increase |
| Unresolved change inventory | Changes lacking validated purpose, owner or closure | Measures accumulated operational ambiguity | Strong decrease |
Analysis of Competing Hypotheses
A disciplined assessment should begin with hypotheses that are mutually distinguishable at the evidence level, even when more than one may ultimately be true. H₁ is ordinary equipment, sensor or communications failure; H₂ is unintentional human error or undocumented maintenance; H₃ is conventional remote cyber compromise affecting visibility or control; H₄ is malicious or coerced insider activity using legitimate access; H₅ is unauthorized physical intervention producing a state not reliably represented at the supervisory layer; H₆ is supply-chain or vendor-mediated compromise; H₇ is a coordinated hybrid operation combining limited technical disruption with deception, political pressure or public-information effects; and H₈ is a compound environmental and technical event. Investigators should score evidence by diagnostic value, reliability and independence rather than simply counting observations. A disagreement between an HMI and a sensor is weak evidence if both depend on the same communications path. A field measurement from an independent instrument, verified by a second team and aligned with physical process behavior, is much stronger. Evidence of valid badge access is not exculpatory unless task, location, timing and process consequences also align. Conversely, geopolitical tension is not technical proof of state involvement. Russian primary legislation defines automated control systems as part of the protected critical-information-infrastructure domain. Federal Law No. 187-FZ on the Security of the Critical Information Infrastructure of the Russian Federation – Official Legal Information Portal of the Russian Federation – July 2017 — verified Russian government source. That legal fact demonstrates strategic recognition of control systems; it does not establish responsibility for any incident. ACH must actively resist mirror imaging and attribution by capability. The most defensible conclusion may remain “unresolved compound anomaly” if evidence cannot discriminate among H₃, H₄ and H₅.
| Evidence | H₁ failure | H₂ error | H₃ cyber | H₄ insider | H₅ physical | H₆ supplier | H₇ hybrid | Diagnostic value |
|---|---|---|---|---|---|---|---|---|
| Independent field data contradicts HMI | C | C | C | C | C | C | C | Low alone |
| Unauthorized access near affected asset | I | I | N | C | C | N | C | High if independently verified |
| Valid credential, invalid work purpose | I | C | N | C | C | C | C | High |
| Similar anomalies across separated sites | I | I | C | I | I | C | C | High |
| Evidence of ordinary hardware degradation | C | C | I | I | I | N | I | High |
| Public coercive narrative synchronized with disruption | N | N | N | N | N | N | C | Moderate; attribution remains unproven |
| Vendor activity precedes multiple anomalies | I | C | N | N | N | C | N | High |
| Safety-system data agrees with independent physics but not HMI | I | I | C | C | C | C | C | High for deception, weak for actor identity |
Legend: C means broadly consistent; I means inconsistent; N means neutral or weakly relevant.
Bayesian updating and Monte Carlo discipline
Bayesian analysis should be implemented as a controlled evidence-update process, not as decorative mathematics that creates false precision. Each hypothesis receives an initial prior derived from the operator’s own incident history, architecture, access population, threat intelligence and environmental conditions. New observations update those priors according to their likelihood under each hypothesis, but correlated evidence must not be counted repeatedly. For example, three alarms derived from the same sensor or communications path constitute one underlying evidence family, not three independent confirmations. The probability assigned to H₄ should rise materially when an unexplained access event, an unauthorized work sequence and a coincident process-state anomaly are independently verified; it should not rise merely because an employee worked an unusual shift. H₇ requires still stronger discipline because geopolitical motive, public claims and technical capability are not substitutes for incident-specific evidence. Monte Carlo analysis belongs on the consequence side: operators can sample uncertain detection delays, restoration times, reserve margins, seasonal demand, redundant equipment availability, communications loss and cross-sector dependencies to estimate distributions of service interruption and recovery requirements. The simulation should not estimate the probability that a named country will attack a named installation unless a defensible empirical basis exists. The graph below instead uses synthetic indices to compare three transparent policy scenarios: baseline convergence, climate-stress amplification and accelerated resilience. Its numerical values are analytical assumptions, not observed frequencies. The principal sensitivity proposition is defensible even without invented probabilities: higher operational stress and greater dependence on a single supervisory representation widen the potential consequence of ambiguity, while independent sensing, access reconciliation and exercised degraded operations reduce it. Results should be reported as ranges and percentile bands, accompanied by assumptions, rather than as a single authoritative number. This preserves decision usefulness while preventing the model from laundering judgment into apparently empirical certainty.
| Monte Carlo variable | Illustrative distribution class | Required operator input | Output influenced |
|---|---|---|---|
| Detection delay | Empirical or triangular | Historical alarm-to-validation times | Duration of deceptive influence |
| Independent verification time | Empirical or lognormal | Field-team mobilization and measurement data | Ambiguity interval |
| Storage or reserve margin | Seasonal empirical | Reservoir, fuel, generation or treatment capacity | Service continuity |
| Repair duration | Empirical with supply-chain tail | Asset-specific restoration history | Recovery distribution |
| Communications availability | Bernoulli or state-transition | Redundancy and outage performance | Coordination effectiveness |
| Demand stress | Seasonal distribution | Water, electricity or gas demand history | Consequence severity |
| Spare-part availability | Discrete scenario | Inventory and supplier lead times | Tail recovery risk |
| Cross-sector dependency | Conditional scenario | Power, telecom, water and transport mapping | Cascading consequence |
Shadow dimensions: proxies, cyber norms and liquidity
The “shadow” layer should be assessed cautiously because it contains the greatest risk of analytical overreach. Mercenary or proxy dynamics may involve commercial intrusion services, politically aligned groups, criminal facilitators, corrupt insiders or intermediaries with legitimate industrial access. Open-source evidence often reveals capability claims but rarely proves command relationships. Analysts should therefore separate sponsorship, direction, tolerance and opportunistic alignment as distinct propositions. A contractor’s financial distress or an unusual payment is not proof of recruitment; it is a potential investigative lead requiring lawful financial and personnel review. Liquidity analysis should focus on defensible organizational exposure: concentration of maintenance contracts, emergency procurement outside standard controls, opaque subcontracting chains, abnormal invoice structures, rapid vendor changes and financially stressed suppliers occupying privileged positions. Cyber-norm analysis should examine whether an actor seeks reversible disruption, strategic signaling, persistent access or destructive effect, but norms are expectations rather than safety guarantees. ENISA’s 2030 foresight identifies advanced hybrid threats in which physical or offline attacks increasingly combine with cyber activity. Foresight Cybersecurity Threats for 2030, 2024 Update – European Union Agency for Cybersecurity – November 2024 — verified primary source. This supports a convergence outlook but not attribution to a particular state or proxy. Chinese government policy for future industrial internet research emphasizes reliable interconnection among humans, machines and physical objects and the integration of industrial processes, networks and value chains. Major Research Plan for Future Industrial Internet Fundamental Theory and Key Technologies – National Natural Science Foundation of China – September 2025 — verified Chinese government source. Again, this establishes strategic technological direction, not hostile intent. The defensible OSINT task is to map how expanding industrial connectivity changes opportunity, dependency and potential consequence across all jurisdictions.
Five-year outlook, 2027–2031
The baseline outlook anticipates a gradual increase in convergence pressure through 2031, driven by greater OT connectivity, distributed assets, remote support, AI-assisted operations, contractor dependence and continuing coexistence between legacy equipment and modern supervisory platforms. This is not a forecast of a proportional increase in successful attacks. It is a forecast that incidents will become harder to classify because more legitimate systems and people can influence the operational picture. Between 2027 and 2028, the principal governance challenge will be converting EU all-hazards obligations into site-level controls that reconcile physical, cyber, safety and contractor evidence. During 2029, organizations are likely to face an expanding verification problem as AI-generated recommendations, automated anomaly detection and digital twins become additional epistemic layers. These tools may improve detection, but they can also create correlated trust dependencies if they consume the same compromised or defective data. During 2030–2031, the distinction between primary industrial control, distributed field automation, energy management and climate-adaptation infrastructure will become less clear. Water reuse, desalination, storage, renewable integration and demand management will create resilience benefits while enlarging the number of geographically dispersed assets requiring accountable access and trusted telemetry. Southern Europe faces a particularly consequential interaction with scarcity. The EEA reported that water scarcity affected 28% of EU territory and 32% of its population in 2023, while southern Europe experiences persistent and severe seasonal pressures. Water Scarcity Conditions in Europe – European Environment Agency – November 2025 — verified primary source. The strategic priority is therefore not indiscriminate technological replacement. It is preservation of independent operational truth: field-verifiable process measurements, robust time coherence, controlled intervention paths, trustworthy recovery configurations, cross-domain event reconstruction and leadership structures capable of acting before perfect attribution becomes available.
| Period | Expected convergence development | Principal ambiguity | Defensive priority | Residual risk |
|---|---|---|---|---|
| 2027 | CER and NIS-related implementation reaches more operational processes | Compliance evidence confused with operational effectiveness | Site-level all-hazards validation | Fragmented ownership |
| 2028 | Contractor and remote-support ecosystems deepen | Legitimate access versus legitimate purpose | Unified physical–logical access governance | Third-party opacity |
| 2029 | AI analytics and digital-twin adoption expand | Independent analysis may share compromised source data | Data-lineage and model-independence testing | Correlated epistemic failure |
| 2030 | Distributed energy and water assets increase | Central visibility versus local effective authority | Field-verification coverage and trusted timing | Geographic dispersion |
| 2031 | Climate and demand stress interact with complex automation | Technical failure versus hostile exploitation of stress | Exercised degraded operations and cross-sector recovery | Compound-event tails |
Figure 1: Five-Year Threat-Convergence Projection
Method note: values are transparent analytical scenarios, not measurements of any operator and not forecasts of attack frequency. The baseline combines HMI trust dependence, physical-access exposure, insider opportunity and operational stress; the resilience case assumes stronger independent sensing, access reconciliation and exercised recovery.
Southern-Periphery Exposure: The Water–Energy–OT Stress Corridor
A vulnerability produced by convergence
Europe’s southern periphery should not be described as a uniformly weak technological region. Its distinctive exposure arises from the convergence of four structural conditions: persistent or seasonal water scarcity; high energy-import or interconnection dependence; long-lived operational technology installed across heterogeneous infrastructure generations; and demand patterns compressed into increasingly hot, dry and tourism-intensive summer periods. Each condition is manageable in isolation. Their intersection, however, narrows operating margins and increases the strategic consequence of incomplete, delayed or deceptive information. Water utilities need electricity for abstraction, conveyance, pumping, treatment, desalination, disinfection, pressure regulation, wastewater processing and reuse. Electricity systems simultaneously depend on water for hydropower, thermal-generation cooling, fuel processing, firefighting and the physical maintenance of grid infrastructure. Tourism and irrigation raise water demand during periods when heat also increases cooling loads; drought can reduce hydropower availability while increasing pumping and desalination requirements; wildfires and extreme temperatures can interfere with transmission, communications and field access. Legacy OT adds a further dimension because operators must integrate controllers, remote terminal units, sensors and supervisory platforms designed under different assumptions about connectivity, authentication, data integrity and vendor support. The European Commission now explicitly treats water security as a matter of preparedness, infrastructure investment, digitalization and strategic resilience. European Water Resilience Strategy – European Commission, Directorate-General for Environment – June 2025 — verified primary source. The strategy’s significance for HMI-related risk is indirect but profound: greater digitalization can improve forecasting, leakage detection and resource allocation, yet it also increases the number of data relationships on which operators depend. Southern-periphery exposure is therefore not captured by a simple cyber-vulnerability count. It is a combined detection-and-consequence problem in which an identical HMI anomaly can be operationally minor during a low-demand month but strategically serious when reservoirs, generation margins, interconnectors, field crews and treatment capacity are already under stress.
| Structural factor | Direct operational effect | Cross-sector amplification | HMI/OT implication | Strategic consequence |
|---|---|---|---|---|
| Water scarcity | Lower storage and abstraction margins | More pumping, reuse and desalination demand | Greater reliance on accurate flow, pressure and quality data | Less time to classify anomalies |
| Heat and seasonal demand | Higher cooling, tourism and irrigation loads | Coincident pressure on electricity and water | Alarm volumes and operator workload increase | Local failures can escalate faster |
| Energy-import dependence | Exposure to external supply and maritime logistics | Water treatment depends on imported-energy continuity | Backup assumptions become critical | Recovery costs and political sensitivity rise |
| Electricity interdependence | Reliance on cross-border balancing and interconnectors | Disturbance may propagate beyond one jurisdiction | Control-centre coordination becomes decisive | National incident becomes regional |
| Legacy OT | Uneven visibility, support and security capability | Difficult integration with newer analytics | Multiple representations of the same process | Greater operational ambiguity |
| Geographic dispersion | Remote pumps, reservoirs, substations and treatment assets | Field verification requires time and transport | Central HMI may be the dominant evidence source | Physical-state confirmation is delayed |
Water scarcity as a control-system multiplier
The European Environment Agency’s latest indicator demonstrates that scarcity is not a distant climate scenario. In 2023, water-scarcity conditions affected 28% of EU territory and 32% of the EU population during at least one quarter; the longer-run annual averages for 2000–2023 were approximately 30% of territory and 33% of population. Southern Europe carries a sharper seasonal concentration: approximately 30% of its population lives in areas experiencing permanent water stress, while as much as 70% can face summer-season stress. Cyprus and Malta recorded the most significant seasonal scarcity among EU member states, with seasonal WEI+ values above 40%; Greece, Portugal, Italy and Spain also experienced scarcity particularly during spring and summer. Water Scarcity Conditions in Europe – European Environment Agency – November 2025 — verified primary source. WEI+ measures freshwater consumption relative to renewable freshwater availability after accounting for returns, and the EEA uses 20% as a scarcity threshold and 40% as a severe-scarcity threshold. It should not be misinterpreted as the percentage probability of shortage or infrastructure failure. Its security importance lies in the shrinking buffer between ordinary operations and service disruption. When resource availability is abundant, an erroneous reading, delayed alarm or temporarily unavailable pumping station may be absorbed by storage, alternative sources or flexible scheduling. Under severe seasonal stress, the same anomaly can affect allocation decisions, reservoir drawdown, pressure zoning, irrigation restrictions or desalination scheduling before its cause is fully determined. Scarcity also complicates anomaly detection because legitimate operating patterns change rapidly: pumps run for different durations, networks are reconfigured, pressure targets move, emergency sources enter service and maintenance may be deferred. A malicious or accidental divergence can consequently resemble an adaptive operational response. Defensive analysis must therefore compare an observed action not only with a static baseline but also with the approved drought-operating plan, current storage position, forecast demand and the precise authorization governing temporary configurations.
| Official water indicator | Observed value | Reference period | Defensive interpretation |
|---|---|---|---|
| EU territory affected by scarcity in at least one quarter | 28% | 2023 | Wide geographic exposure; not confined to the Mediterranean |
| EU population affected by scarcity in at least one quarter | 32% | 2023 | Material societal dependence on stressed systems |
| Southern population under permanent stress | Around 30% | Latest EEA assessment | Reduced year-round operating margin |
| Southern population exposed to summer stress | Up to 70% | Latest EEA assessment | Strong seasonal concentration of consequences |
| Cyprus and Malta seasonal WEI+ | Above 40% | 2023 | Severe scarcity category |
| Greece, Portugal, Italy and Spain | Spring–summer scarcity | 2023 | Recurrent seasonal exposure rather than uniform annual scarcity |
| Türkiye | Most severely challenged EEA member country | 2023 | Important non-EU component of the regional water–energy system |
Italy: network losses as both resource and observability risk
Italy illustrates how climatic pressure interacts with infrastructure efficiency and operational visibility. ISTAT reported that in 2022 Italian systems abstracted approximately 9.1 billion m³ of water for drinking purposes, equivalent to 424 litres per resident per day; approximately 8.0 billion m³, or 371 litres per resident per day, entered municipal distribution networks, while only 4.6 billion m³, or 214 litres per resident per day, were delivered for authorized uses. Total distribution losses reached 3.4 billion m³, equal to 42.4% of the water introduced into the networks. ISTAT estimated that this lost volume could have met the water requirements of 43.4 million people for an entire year. Le statistiche sull’acqua, anni 2020–2023 – Istituto Nazionale di Statistica – March 2024 — verified primary source. These losses are not automatically evidence of physical leakage alone: the total-loss measure can include real losses, apparent losses, measurement problems and unauthorized consumption. For OT risk analysis, this distinction matters. A network with imperfect metering, uncertain district balances or incomplete telemetry gives operators a weaker physical reference against which to evaluate HMI information. If the expected relationship among input volume, pressure, storage and authorized consumption already contains substantial uncertainty, a deceptive, stale or erroneous interface state may remain plausible for longer. Italy’s fragmentation adds organizational complexity. Water service coverage extends across thousands of municipalities, while terrain, settlement patterns, operator scale and infrastructure age vary sharply between northern metropolitan areas, central regions, the Mezzogiorno and the islands. National averages therefore cannot be treated as installation-level exposure scores. The strategic priority is to convert leakage reduction into an observability programme: district metering, verified sensor lineage, pressure and flow reconciliation, calibrated instrumentation, trusted timing, controlled configuration changes and independent confirmation of critical storage and treatment variables. Such investments simultaneously conserve water and reduce the informational space in which operational ambiguity can persist.
| Italy water balance | Volume in 2022 | Per-capita equivalent | Share or implication |
|---|---|---|---|
| Water abstracted for drinking purposes | 9.1 billion m³ | 424 litres/day | Italy ranked third in Europe for per-capita abstraction |
| Water entering distribution | 8.0 billion m³ | 371 litres/day | Starting volume for municipal distribution |
| Water delivered for authorized uses | 4.6 billion m³ | 214 litres/day | Approximately 57.6% of input volume |
| Total distribution losses | 3.4 billion m³ | Approximately 157 litres/day | 42.4% of network input |
| Population-equivalent of lost volume | — | 43.4 million people/year | Illustrates resilience opportunity, not recoverable volume at every site |
Malta and Cyprus: desalination converts scarcity into energy dependence
Malta and Cyprus reveal the most concentrated water–energy coupling inside the EU’s southern periphery. The EEA reported that in 2021 approximately 50% of total public water supply in both countries came from desalinated water, even though desalinated sources represented only about 1.4% of total public water supply across the EU. Water Savings for a Water-Resilient Europe – European Environment Agency – June 2025 — verified primary source. Desalination provides strategic diversification from rainfall and conventional freshwater abstraction, but it transforms water security into a more direct function of electrical continuity, energy cost, membrane and chemical supply chains, specialized maintenance and intake–treatment–distribution coordination. This does not make desalination intrinsically insecure. It means that water resilience must be evaluated together with generation, fuel logistics, grid configuration and reserve capability. Eurostat reported that the EU’s overall energy-import dependency rate was 57% in 2024, compared with 98% for Malta and 88% for Cyprus. Energy in Europe, 2026 Edition – Eurostat – 2026 — verified primary source. The dependency indicator measures net imports as a proportion of gross available energy; it is not an electricity adequacy measure and does not by itself prove insecurity. Nevertheless, the combination of severe seasonal WEI+, high import dependence and desalination creates a distinctive compound-exposure profile. A disturbance affecting electricity, fuel delivery, treatment or supervisory visibility can influence several layers of essential service simultaneously. The critical defensive question becomes whether operators can verify water production, storage and quality independently if primary supervisory data are unavailable or suspect, while energy authorities determine whether the supporting electrical state remains sustainable. Planned interconnections can reduce isolation and provide diversification, but they also introduce converter stations, subsea infrastructure, cross-border operating rules and new digital coordination dependencies. Resilience should consequently be judged by the quality of alternative operating states and exercised recovery, not simply by the number of connections.
| Indicator | Malta | Cyprus | EU context | Security meaning |
|---|---|---|---|---|
| Seasonal WEI+ | Above 40% | Above 40% | 20% scarcity; 40% severe scarcity | Both fall in the severe seasonal category |
| Public supply from desalination | Around 50% | Around 50% | EU average 1.4% | Electricity becomes a major water-security input |
| Energy-import dependency | 98% | 88% | EU 57% | Strong exposure to external energy flows |
| Geographic condition | Island system | Island system | Continental systems generally have more terrestrial options | Recovery and logistics require island-specific planning |
| Principal resilience opportunity | Interconnection, storage, efficiency and reuse | Interconnection, storage, efficiency and reuse | EU Water Resilience Strategy | Diversification must preserve independent operational verification |
Spain, Portugal and the western Mediterranean bottleneck
The Iberian Peninsula combines substantial renewable potential, hydropower variability, irrigation demand, large tourism economies and limited electricity exchange capacity across the Pyrenean interface relative to the size of its power system. This creates a paradox: Spain and Portugal possess valuable solar, wind and LNG infrastructure, but their contribution to wider European balancing and their ability to draw on continental flexibility remain constrained by interconnection topology. Water stress compounds that limitation because drought can simultaneously reduce reservoir availability, alter hydropower scheduling, increase agricultural abstraction and raise pumping or desalination demand. The EEA’s 2023 assessment places both countries among those experiencing pronounced spring and summer scarcity. This is operationally important because average annual energy balances can obscure short periods of coincident stress. A summer week characterized by high cooling load, weak hydrological conditions, variable renewable output, wildfire risk and heavy tourism can impose a substantially different control environment from an annual national average. ENTSO-E’s seasonal outlook methodology assesses European adequacy across interconnected study zones and is intended to inform national and European authorities about emerging system risks. Summer Outlook 2025 – European Network of Transmission System Operators for Electricity – May 2025 — verified primary source. The report should not be interpreted as a prediction of local OT incidents: it models resource adequacy, interconnection and system conditions at zonal level and explicitly applies simplifying assumptions. Its relevance is that OT anomaly consequences depend on the surrounding adequacy environment. If neighbouring zones possess spare capacity and transmission paths remain available, a local disturbance is easier to absorb. If scarcity and demand coincide across several zones, the same event consumes a larger share of regional flexibility. Iberian resilience therefore requires integration of drought planning, grid adequacy, wildfire procedures, tourism-season forecasts, water-utility demand and cross-border operational coordination. The intelligence unit should monitor compound thresholds rather than treating every stressor as an independent warning.
| Iberian stressor | Water-system effect | Energy-system effect | OT/HMI consequence |
|---|---|---|---|
| Multi-season drought | Lower reservoirs and tighter allocations | Reduced hydropower flexibility | Rapidly changing operating baselines |
| Extreme heat | Higher municipal demand and evaporation | Cooling-load increase | More alarms and less reserve margin |
| Irrigation season | High abstraction and pumping | Greater agricultural electricity consumption | Complex schedules and remote-asset activity |
| Tourism concentration | Coastal and island demand peaks | Cooling and transport-energy demand | Temporary operations and staffing pressure |
| Wildfire conditions | Threat to catchments, pumps and access routes | Threat to lines, substations and field access | Delayed physical verification |
| Limited continental interconnection | Fewer indirect energy-support options | Constrained cross-border balancing | Greater consequence of regional disturbances |
Greece, Italy and the central–eastern Mediterranean interdependence arc
The central and eastern Mediterranean form an expanding interdependence corridor extending through Italy, Greece, Malta, Cyprus and the western Balkans toward Türkiye and the eastern Mediterranean. Electricity cables, gas pipelines, LNG facilities, renewable-generation zones, shipping routes and prospective hydrogen infrastructure increasingly connect markets that historically contained islanded or weakly connected systems. Interconnection creates resilience by sharing generation, improving market integration and reducing the probability that every jurisdiction must independently carry all contingency resources. It also creates common-mode dependencies: converter stations, subsea cable landing points, telecommunications, synchronized operational procedures and cross-border restoration protocols become strategically important nodes. The Commission’s Projects of Common Interest framework includes priority electricity and gas corridors across southern Europe and has repeatedly identified the objective of ending energy isolation, including the connection of Malta with Italy and eastern Mediterranean electricity links. The 2025 second Union list included the proposed connection of Malta to the European gas network through an interconnection with Italy at Gela. Commission Delegated Regulation establishing the second Union list of Projects of Common and Mutual Interest – European Commission – December 2025 — verified primary source. Project inclusion is not equivalent to commissioning, guaranteed completion or immediate resilience; status, permitting and delivery must be evaluated separately. The OT implication is that greater physical interconnection must be accompanied by stronger operational-state reconciliation across control centres. A disturbance can be technically local while its balancing, market and political consequences become regional. Greece’s islands and Italy’s major islands require particular attention because local generation, subsea connections, tourism demand and water systems can interact differently from mainland networks. The correct policy is neither autarky nor unconditional interconnection. It is resilient interdependence: diverse routes, validated restoration plans, transparent operational authority, spare-equipment strategies, protected landing and conversion facilities and communications able to function when ordinary supervisory channels are degraded.
| Interdependence asset | Resilience gain | New dependency | Required assurance |
|---|---|---|---|
| Electricity interconnector | Shared capacity and balancing | Cable, converter and landing infrastructure | Condition monitoring and restoration exercises |
| Gas pipeline | Supply diversification and market integration | Compressor, metering and geopolitical-route dependence | Physical protection and verified flow-state data |
| LNG terminal | Source and route diversification | Shipping, weather and specialized equipment | Inventory visibility and continuity planning |
| Renewable corridor | Lower fuel-import exposure | Weather variability and distributed-control complexity | Forecast quality and secure field telemetry |
| Desalination facility | Drought-independent water production | Electricity and specialist supply dependence | Power continuity and independent quality validation |
| Regional control coordination | Faster mutual assistance | Dependence on shared data and communications | Trusted timing, authentication and fallback channels |
Legacy OT: age is not the only problem
“Legacy OT” should not be equated automatically with obsolete, exposed or insecure technology. Some older systems remain operationally stable, physically isolated, well understood and supported by disciplined procedures; some newly connected systems can introduce greater risk through configuration complexity, cloud dependence or poorly governed remote access. The relevant analytical variables are supportability, observability, recoverability, authentication capability, configuration control, component provenance, network architecture, spare availability and the operator’s ability to verify the physical state independently. NIST emphasizes that OT security must preserve performance, reliability and safety while accounting for equipment lifecycles that are typically longer than conventional IT lifecycles. Guide to Operational Technology Security, NIST Special Publication 800-82 Revision 3 – National Institute of Standards and Technology – September 2023 — verified primary source. Southern European water infrastructure magnifies lifecycle diversity because utilities may control mountain sources, wells, reservoirs, urban treatment plants, coastal desalination, wastewater facilities and thousands of dispersed pumping or pressure-management assets. Energy systems add substations, distributed renewables, island generation, gas infrastructure and market-control functions. Modernization frequently occurs incrementally, producing mixed estates in which a modern HMI displays information originating from older controllers and field instruments through gateways, protocol converters or vendor-specific integrations. The resulting risk is epistemic as much as technical: operators may see a unified graphic representation of equipment whose underlying data quality, timing and control capabilities differ materially. A cybersecurity programme focused only on patching will miss unsupported firmware, uncertain asset inventories, undocumented dependencies, mismatched clocks, fragile replacement procedures and obsolete engineering knowledge. The priority is risk-ranked lifecycle governance. Critical assets that cannot be replaced immediately require compensating protections, controlled access, configuration baselines, independent monitoring and tested restoration. Modernization should preserve the operator’s ability to reason about the process rather than adding opaque abstraction.
| Legacy-OT dimension | Weak assessment | High-value assessment | Resilience decision |
|---|---|---|---|
| Age | Installation year alone | Age plus support, condition and operational criticality | Replace only where risk justifies disruption |
| Connectivity | Connected or isolated | Actual pathways, trust relationships and temporary access | Remove unnecessary paths and govern exceptions |
| Visibility | Asset appears in inventory | State, firmware, configuration, owner and dependencies known | Prioritize blind assets |
| Authentication | Password capability | Identity, purpose, privilege and session accountability | Add compensating controls where native capability is weak |
| Recovery | Backup reported | Backup restored and validated against safe configuration | Exercise recovery |
| Time integrity | Clock exists | Events align across HMI, historian, controller and access systems | Correct forensic blind spots |
| Process verification | HMI values available | Critical variables corroborated independently | Reduce single-interface dependence |
Seasonal demand as a predictable but underestimated threat window
Seasonal demand should not be treated merely as a planning statistic because it changes the entire operating context in which anomalies are interpreted. Southern-periphery summer conditions can combine tourism, irrigation, heat-driven cooling, wildfire precautions, lower river flows, hydropower constraints, high evaporation, water-quality challenges and maintenance restrictions. The individual peak for each variable may not occur on the same day; the strategic risk emerges when several remain elevated long enough to consume operational flexibility. Tourism can multiply the effective population of islands and coastal municipalities while staffing patterns, temporary accommodation and transport activity complicate demand forecasting. Heat raises electricity consumption for cooling and can affect equipment performance, while water utilities may require more energy to move water over longer distances or operate desalination and reuse systems more intensively. Drought can also constrain thermal generation where cooling-water availability matters, although the importance varies by generation mix and installation. ENTSO-E’s 2026 Summer Outlook reports continuing expansion of renewable capacity across Europe and evaluates whether available resources and cross-border exchanges can cover demand under seasonal conditions. Summer Outlook 2026 – European Network of Transmission System Operators for Electricity – 2026 — verified primary source. An adequacy outlook cannot represent every distribution-level restriction, ramping constraint or local OT dependency; ENTSO-E’s associated methodology notes important modelling simplifications. Consequently, national adequacy does not guarantee that every municipality, island or water facility possesses adequate local resilience. Operators need layered seasonal thresholds that combine reservoir position, groundwater status, desalination availability, electricity margin, interconnector status, wildfire access, staffing, maintenance backlog and trusted-telemetry coverage. A high-risk window should trigger heightened verification and reduced discretionary change, not panic or attribution. The purpose is to recognize when ordinary uncertainty could produce unusually large consequences.
| Seasonal variable | Normal planning view | Security-adjusted interpretation | Required indicator |
|---|---|---|---|
| Heat | Cooling-demand forecast | Higher load plus equipment and workforce stress | Temperature-adjusted reserve margin |
| Tourism | Consumption forecast | Rapid population change and temporary operational load | Daily population-equivalent demand |
| Irrigation | Agricultural allocation | Pumping concentration and remote-site activity | Energy and water abstraction profile |
| Drought | Resource deficit | Lower redundancy and altered operating baselines | Storage, WEI+ and source availability |
| Wildfire | Civil-protection hazard | Field-access, telecom and line exposure | Asset accessibility and route redundancy |
| Maintenance | Seasonal work programme | Increased legitimate privileged activity | Authorized-change reconciliation rate |
| Renewable variability | Generation forecast | Need for balancing and interconnection | Forecast error and available flexibility |
Analysis of Competing Hypotheses
A southern-periphery anomaly requires an ACH structure capable of distinguishing a hostile act from climate, infrastructure and operational explanations. H₁ is ordinary equipment degradation or sensor failure; H₂ is scarcity-driven reconfiguration that was legitimate but poorly documented; H₃ is operator error under seasonal workload; H₄ is communications or interconnection disturbance; H₅ is a supply-chain or vendor-support failure; H₆ is malicious cyber manipulation; H₇ is physically or insider-enabled interference; H₈ is a compound climate–technical event; and H₉ is a coordinated hybrid action exploiting an already stressed system. The prior probability of H₈ may increase during a heatwave or drought without increasing the probability of H₉ by the same amount. Geopolitical tension should never be treated as a substitute for technical evidence. Conversely, the existence of severe environmental stress does not exclude malicious exploitation. Investigators should identify evidence that discriminates: whether the affected state is consistent with process physics; whether independent measurements agree; whether a configuration change had a valid work order; whether the anomaly is geographically correlated with weather or with shared vendor activity; whether access records align with task requirements; and whether apparently separate water and energy anomalies share a time source, communications dependency or contractor. Bayesian updates should discount correlated observations. Five alarms originating from the same defective sensor are not five independent facts. Monte Carlo modelling should focus on consequence distributions—detection delay, storage depletion, restoration time, interconnector availability and demand—not fabricate a probability that a named actor will attack. The result may legitimately remain unresolved. An analytically honest “compound anomaly with insufficient attribution evidence” is more useful than a prematurely confident conclusion that sends operators toward the wrong recovery strategy.
| Evidence | H₁ failure | H₂ reconfiguration | H₃ error | H₄ interconnection | H₅ vendor | H₆ cyber | H₇ physical/insider | H₈ climate compound | H₉ hybrid |
|---|---|---|---|---|---|---|---|---|---|
| Similar anomalies across drought-affected sites | N | C | N | N | N | N | I | C | N |
| Independent field measurement contradicts HMI | C | N | N | N | C | C | C | N | C |
| Unapproved change during legitimate maintenance | I | C | C | I | C | C | C | I | C |
| Cross-border electrical disturbance precedes water anomaly | I | I | I | C | N | N | N | C | N |
| Valid access without valid operational purpose | I | I | N | I | N | N | C | I | C |
| Weather explains timing and geographic distribution | N | N | N | N | N | I | I | C | I |
| Coordinated disinformation accompanies disruption | I | I | I | I | I | N | N | I | C |
Legend: C means broadly consistent, I inconsistent and N neutral or weakly diagnostic.
Outlook 2027–2031
The five-year baseline is a gradual rise in compound exposure rather than an inevitable rise in successful hostile action. During 2027, implementation of the Critical Entities Resilience framework and the European Water Resilience Strategy should push more operators toward all-hazards assessments, but formal compliance may initially move faster than engineering remediation. During 2028, water-efficiency investment, smart metering, desalination, reuse and distributed renewable integration will expand visibility while increasing the number of connected assets and vendor relationships requiring governance. During 2029, AI-assisted forecasting and digital twins will become more influential in water allocation, predictive maintenance and grid management. Their benefit will depend on data lineage: an analytic layer cannot provide independent verification when it relies on the same defective or compromised source as the primary HMI. During 2030, interconnections and cross-border flexibility should reduce isolation for parts of the Mediterranean, but restoration dependencies and converter or landing-point criticality will become more prominent. By 2031, repeated hot-dry seasons could produce the most consequential divergence between operators that invested in loss reduction, verified telemetry, storage, workforce capability and degraded-operation exercises and those that digitized without addressing physical-system fragility. The priority hierarchy is clear. First, reduce resource losses and uncertainty simultaneously. Second, establish independent verification for critical water and energy variables. Third, reconcile physical, logical and contractor access with work purpose. Fourth, test operations during loss of primary supervisory visibility. Fifth, map water–electricity–telecommunications dependencies at installation level. Sixth, maintain climate-adjusted seasonal thresholds and pre-authorized escalation criteria. Seventh, preserve local engineering competence during modernization. Southern Europe’s vulnerability is not geographic destiny. It is the product of margins, dependencies and observability—and those variables can be changed.
| Year | Dominant development | Principal risk | Required resilience milestone |
|---|---|---|---|
| 2027 | All-hazards compliance implementation | Documentation exceeds operational capability | Site-level dependency and trusted-state assessment |
| 2028 | Expansion of smart water, reuse and distributed energy | Connected-asset and vendor proliferation | Unified asset, access and change governance |
| 2029 | AI and digital-twin integration | Correlated trust in shared data | Independent data-lineage and model assurance |
| 2030 | Greater Mediterranean interconnection | New common-mode dependencies | Cross-border restoration and fallback exercises |
| 2031 | Stronger climate and seasonal variability | Persistent compound stress | Measurable reduction in ambiguity and recovery time |
Figure 2: Seasonal Infrastructure Stress, 2027–2031
Scarcity, leakage, storage and treatment dependence
Cooling demand, imports and interconnector reliance
Lifecycle, visibility and integration constraints
Joint detection-and-consequence pressure
Method: transparent scenario indices derived from directional assumptions about climate stress, seasonal demand, import/interconnection dependence, legacy OT and resilience investment. They are not empirical country scores, installation measurements or forecasts of hostile action.
2026–2031 Outlook: From Ambiguous Anomaly to Measurable Resilience
Forecasting discipline under radical uncertainty
The 2026–2031 outlook for HMI deception, physical access, insider enablement and operational ambiguity must begin by separating four quantities that are frequently—and dangerously—collapsed into a single “risk score”: the probability that an abnormal event will occur; the probability that a particular hypothesis explains an observed event; the severity of the consequences if that hypothesis is true; and the analyst’s confidence in the evidence used to reach the assessment. A low-frequency hypothesis can justify urgent resilience investment when its consequences are severe and existing controls are difficult to validate. Conversely, a technically plausible hostile hypothesis should not dominate an investigation when ordinary equipment failure, configuration drift or undocumented maintenance better explains the available evidence. ENISA defines a cyber stress test as a targeted assessment of an entity’s ability to withstand and recover from significant incidents while maintaining critical services; it explicitly states that stress tests are not forecasts, but instruments for identifying failure points, interdependencies and resilience gaps. Handbook for Cyber Stress Tests – European Union Agency for Cybersecurity – May 2025 — verified primary source. This distinction should govern the entire five-year model. The outlook does not claim that a specific number of “HMI ghosting” incidents will occur, because no official incident taxonomy or reporting series supports such precision. It assesses how the opportunity for display–process divergence, unauthorized control and delayed classification may evolve as utilities add connectivity, AI, digital twins, remote services and distributed infrastructure while continuing to operate legacy assets. The central forecast is that operational ambiguity will increase unless the growth of digital complexity is matched by independent process verification, controlled access, evidence integration and tested recovery. The most important future metric is therefore not merely incidents prevented, which is difficult to observe, but the time required to establish a trusted physical state and restore accountable control when the primary interface or control path cannot be assumed reliable.
| Quantity | Correct analytical question | Common misuse | Required output |
|---|---|---|---|
| Event probability | How likely is an abnormal condition within a defined period? | Treating possibility as probability | Range with assumptions |
| Hypothesis posterior | Which explanation best fits the observed evidence? | Treating it as general attack frequency | Relative, incident-specific probability |
| Consequence severity | What happens if the hypothesis is true? | Multiplying arbitrary scores | Service, safety, economic and recovery distribution |
| Evidence confidence | How reliable, independent and complete is the evidence? | Hiding uncertainty inside one score | Explicit confidence grade |
| Resilience maturity | Can the operator withstand, verify and recover? | Equating policy existence with capability | Tested performance metrics |
| Attribution confidence | What actor-level evidence supports responsibility? | Inferring responsibility from motive or capability | Separate technical and actor assessments |
Competing hypotheses for the 2026–2031 environment
The core Analysis of Competing Hypotheses should retain at least seven explanations throughout initial triage. H₁ is ordinary technical failure involving sensors, communications, controllers, field equipment or supporting power. H₂ is human error, undocumented maintenance or configuration drift. H₃ is remote cyber compromise affecting visibility, command or engineering functions. H₄ is malicious, coerced or negligent insider enablement through legitimate access. H₅ is unauthorized physical intervention or local-control activity not accurately represented at the supervisory layer. H₆ is a compound climate–technical event in which heat, drought, flooding, wildfire or energy stress creates abnormal process behavior. H₇ is coordinated hybrid activity combining cyber, physical, insider, economic or information effects. An eighth hypothesis, H₈, should cover vendor or supply-chain failure because the same supplier, software component or maintenance process may connect otherwise separate installations. These hypotheses are not mutually exclusive in reality: a climate event may expose a technical weakness that an opportunistic actor subsequently exploits, while poor maintenance documentation may conceal or imitate insider behavior. ACH remains useful because it forces investigators to identify which evidence would be expected or unexpected under each proposition. ENISA’s 2030 foresight assessed advanced hybrid threats as increasingly combining physical or offline activity with cyber operations and identified manipulation of hardware or software, abuse of authorizations and physical access among relevant future concerns. Identifying Emerging Cybersecurity Threats and Challenges for 2030 – European Union Agency for Cybersecurity – March 2023 — verified primary source. That official foresight supports maintaining H₇; it does not establish that H₇ should receive the highest prior in every incident. Analysts must actively search for disconfirming evidence. A verified equipment defect with a complete physics-consistent failure sequence should reduce hostile hypotheses even during geopolitical tension. An unexplained access event may raise H₄ and H₅, but only if identity, location, timing, purpose and operational consequences are independently established.
| Hypothesis | Core proposition | Evidence expected | Evidence that weakens it | Principal collection requirement |
|---|---|---|---|---|
| H₁ Technical failure | Equipment or communications degraded naturally | Failure signatures, condition history, consistent process physics | Concealed configuration change or coordinated cross-site timing | Engineering inspection and independent measurement |
| H₂ Human or maintenance error | Legitimate activity produced an unintended state | Work activity, procedural deviation, incomplete documentation | No relevant activity or deliberate concealment | Work orders, interviews and change records |
| H₃ Remote cyber compromise | Digital access altered visibility or control | Account, network, controller or engineering anomalies | Verified isolation and no affected digital path | OT telemetry and identity evidence |
| H₄ Insider enablement | Authorized access supported unauthorized effects | Valid access with invalid purpose or sequence | Complete supervision and independently verified work | Physical–logical access reconciliation |
| H₅ Physical intervention | Local activity changed effective control or process state | Physical evidence and supervisory inconsistency | No plausible physical opportunity | Field inspection and zone-level access data |
| H₆ Climate–technical compound | Environmental stress produced or amplified failure | Geographic and temporal weather correlation | Anomaly inconsistent with environmental exposure | Weather, demand and asset-condition correlation |
| H₇ Coordinated hybrid action | Several domains were synchronized for strategic effect | Cross-domain timing, targeting logic and independent hostile evidence | One ordinary failure chain explains all observations | Multi-agency chronology and attribution evidence |
| H₈ Vendor or supply chain | Shared provider or component created common exposure | Same supplier, update or maintenance pattern | Independent systems with no shared dependency | Supplier lineage and deployment records |
Bayesian indicators: what should change analytical probability
Bayesian updating provides a disciplined language for revising beliefs, but the calculation is only as defensible as the priors, likelihoods and independence assumptions supplied to it. Operators should establish priors using their own equipment-failure history, maintenance quality, personnel-access environment, architecture, threat reporting and seasonal conditions. A regional or vendor-wide statistic should not be imported into a specific plant model without demonstrating comparability. Each observation must then be assessed on three axes: reliability of the source, independence from other observations and diagnosticity across competing hypotheses. An HMI alarm, historian entry and automated SOC alert may appear to be three sources while all derive from the same underlying sensor or timestamp. Counting them independently would exaggerate the update. Conversely, a calibrated field instrument, a safety system with a separate data path and a physical process measurement may provide genuinely independent corroboration. CISA’s 2026 guidance on adapting Zero Trust to OT applies verification principles while recognizing OT’s safety, reliability and availability requirements. Adapting Zero Trust Principles to Operational Technology – Cybersecurity and Infrastructure Security Agency and international partners – April 2026 — verified primary source. In this context, “never trust, always verify” should not be interpreted as indiscriminately adding latency or authentication to time-critical control functions. Its analytical value is that identity, device, communication, process state and operational purpose should not inherit trust merely from network location or successful login. The highest-value Bayesian indicators are combinations that are difficult for benign explanations to produce: independent field evidence contradicting the HMI; valid physical access without a corresponding authorized task; synchronized anomalies across separated sites sharing a supplier or communications dependency; or safety-system data that agree with process physics while the supervisory representation does not. None establishes actor identity by itself. It changes the relative probability of hypotheses and determines the next collection action.
| Indicator | Reliability requirement | Hypotheses increased | Hypotheses reduced | Update strength |
|---|---|---|---|---|
| Independent field measurement contradicts HMI | Calibrated device, separate path, trusted time | H₃, H₄, H₅, H₈ | Pure display-free equipment explanation | High for divergence; low for attribution |
| Valid badge, invalid work purpose | Identity and location independently confirmed | H₄, H₅ | H₁, H₆ | High |
| Multiple alarms from one sensor | Shared provenance documented | None materially | None | Very low; one evidence family |
| Cross-site synchronization | Common time reference and independent sites | H₃, H₇, H₈ | Isolated H₁ | High |
| Weather-aligned geographic pattern | Authoritative environmental data and exposed assets | H₆ | H₄, H₅, sometimes H₇ | Moderate to high |
| Verified degraded component | Inspection, history and physics-consistent chain | H₁ | H₃–H₇ | High |
| Unusual privileged action | Full identity and task context | H₂, H₃, H₄, H₈ | H₆ | Moderate until purpose is established |
| Public claim of responsibility | Authenticated publication and timing | H₇ slightly | None conclusively | Low without technical corroboration |
From qualitative ACH to auditable posterior ranges
A defensible Bayesian workflow should preserve an audit trail showing how every observation affected every hypothesis, rather than producing an unexplained number in a dashboard. The process begins with explicit priors expressed as ranges where evidence is weak. Analysts then record each observation, source, timestamp, provenance, reliability grade, relationship to other evidence and likelihood under each hypothesis. The resulting posterior should be accompanied by sensitivity analysis: if changing one uncertain likelihood assumption reverses the ranking, the conclusion is fragile and must be reported as such. If H₁ remains dominant across a wide range of assumptions, confidence can increase even when the exact percentage remains uncertain. Decision thresholds should be based on expected consequence and reversibility, not solely on whichever hypothesis ranks first. An operator may need to enter a carefully engineered degraded state while H₁ and H₃ remain evenly balanced, because both imply that primary HMI information cannot be trusted. Directive (EU) 2022/2557 requires critical entities to conduct risk assessments addressing relevant natural and human-induced risks and implement proportionate resilience measures. Directive on the Resilience of Critical Entities – European Parliament and Council – December 2022 — verified official text. The Commission’s 2026 guidelines further support consistent application of the Directive and the identification of risks capable of disrupting essential services. Guidelines on the Application of Directive (EU) 2022/2557 – European Commission – 2026 — verified official source. These obligations align with Bayesian governance because both require the operator to reason across cyber, physical, climatic, personnel and supply-chain factors. The mature output is not “cyberattack probability 67%.” It is a statement such as: H₃ and H₄ jointly dominate because two independent evidence families contradict H₁ and H₂; confidence remains moderate because controller-state records are incomplete; protective action is justified because continued operation under either leading hypothesis exceeds the operator’s tolerance.
| Analytical field | Minimum content | Quality-control question |
|---|---|---|
| Prior | Range, source and reference class | Is it installation-relevant or merely generic? |
| Observation | Exact fact without interpretation | What was directly observed? |
| Provenance | Origin, custody and transformation | Can the evidence be reproduced? |
| Reliability | Source and collection confidence | Could the source be mistaken or compromised? |
| Independence | Relationship to other observations | Are multiple alerts derived from one origin? |
| Likelihood judgment | Compatibility with each hypothesis | What would be expected if the hypothesis were true? |
| Posterior | Range and sensitivity | Does the ranking survive reasonable assumption changes? |
| Decision relevance | Action, consequence and reversibility | What must be done before attribution is complete? |
| Confidence | High, moderate or low with reasons | What evidence is missing? |
Scenario architecture for 2026–2031
The scenario model should use at least five distinct futures because a baseline-versus-catastrophe comparison conceals the policy choices that determine resilience. Scenario S₁, managed modernization, assumes continued digitalization accompanied by gradual asset discovery, access governance and lifecycle replacement. Scenario S₂, accelerated convergence, assumes remote services, AI-supported operations, distributed generation, desalination and smart-water infrastructure expand faster than verification and workforce capability. Scenario S₃, climate-stress amplification, assumes repeated hot-dry summers compress water and electricity margins while increasing tourism, cooling and pumping demand. Scenario S₄, hybrid-pressure environment, assumes geopolitical tension raises the frequency of ambiguous physical, cyber, proxy and information incidents without necessarily producing destructive effects. Scenario S₅, resilience acceleration, assumes operators implement independent sensing, cross-domain event correlation, trusted recovery baselines, contractor control, cross-border exercises and spare-equipment strategies. Scenario S₆, regulatory–operational gap, assumes policies and assessments proliferate while technical remediation and testing remain incomplete. ENISA’s stress-test handbook recommends plausible scenarios, different stress levels and resilience metrics such as time to detect and time to recover; it also emphasizes systemic risk and cascading interdependencies. Handbook for Cyber Stress Tests – European Union Agency for Cybersecurity – May 2025 — verified primary source. Scenarios should not encode attack instructions. They should specify which evidence sources are unavailable, which service dependencies are stressed and which decisions leaders must make. The key comparative output is resilience loss under each scenario: how long the operator requires to establish trusted state, maintain minimum service, resolve authority, mobilize field verification and restore a validated configuration.
| Scenario | Principal assumption | Expected ambiguity trend | Primary resilience test |
|---|---|---|---|
| S₁ Managed modernization | Connectivity and assurance grow together | Moderate, then declining | Whether controls scale with new assets |
| S₂ Accelerated convergence | Connectivity outpaces governance | Strongly increasing | Whether independent truth survives complexity |
| S₃ Climate-stress amplification | Repeated compound seasonal stress | Episodically severe | Whether minimum service survives reduced margins |
| S₄ Hybrid-pressure environment | More ambiguous cross-domain incidents | Persistently high | Whether attribution uncertainty delays protection |
| S₅ Resilience acceleration | Verification and recovery receive sustained investment | Declining | Whether improvements are demonstrated in exercises |
| S₆ Regulatory–operational gap | Documentation exceeds engineering execution | Hidden until crisis | Whether controls exist beyond policy statements |
Monte Carlo modelling without invented certainty
Monte Carlo simulation is appropriate for consequences and operational performance because many relevant quantities are uncertain but measurable: detection delay, field-verification time, reservoir or fuel margin, repair duration, spare-part lead time, communications availability, interconnector status, staff mobilization and demand. The model should sample these variables thousands of times from empirically justified distributions and calculate outcomes such as service interruption, population-equivalent exposure, unserved electricity or water, recovery cost and probability of exceeding continuity thresholds. The simulation should preserve correlations. Heat may simultaneously increase electricity demand, water demand and equipment stress; treating those variables as independent would understate tail risk. Drought may reduce hydropower flexibility while increasing pumping and desalination requirements. A common telecommunications failure can delay both operational control and crisis coordination. Attack frequency should not be inserted as a precise distribution unless the operator possesses a defensible, relevant dataset. Instead, the model can condition consequences on scenarios: if primary HMI trust is lost for a specified interval, what is the distribution of service outcomes under different reserve and verification assumptions? The European Commission notes that energy systems present real-time requirements, cascading cross-border effects and challenges created by integrating legacy equipment with new automation and connected devices. Critical Infrastructure and Cybersecurity – European Commission, Directorate-General for Energy – updated 2026 — verified primary source. These conditions justify modelling dependencies rather than isolated assets. Every simulation output should include median, high-percentile and extreme-tail results, input assumptions and sensitivity. A policy that performs well only under median conditions is not resilient. Conversely, designing every facility for an unconstrained worst case may be economically impossible. The purpose is to identify which investments most reduce the harmful tail: additional storage, independent sensors, communications diversity, faster field confirmation, spare equipment, trained local control or cross-border mutual assistance.
| Simulation variable | Preferred evidence source | Distribution approach | Principal outcome affected |
|---|---|---|---|
| Detection delay | Incident and exercise history | Empirical or lognormal | Duration of unrecognized divergence |
| Trusted-state establishment | Field-validation exercises | Empirical or triangular | Ambiguity interval |
| Demand | Seasonal operational records | Weather-conditioned empirical | Continuity margin |
| Water, fuel or storage reserve | Operator records | Scenario-conditioned range | Time before service restriction |
| Repair time | Asset-specific history | Heavy-tailed empirical | Recovery duration |
| Spare-part lead time | Procurement and inventory data | Discrete supplier scenarios | Extreme recovery tail |
| Communications availability | Reliability history | State-transition model | Coordination and remote visibility |
| Interconnector availability | TSO and operator data | Conditional scenario | Regional balancing capacity |
| Workforce mobilization | Exercise records | Empirical distribution | Field confirmation and restoration |
| Evidence integrity | Audit and architecture review | Discrete maturity state | Confidence in diagnosis |
Five-year trajectory
During 2026, the dominant requirement is to establish baselines. Operators cannot perform meaningful Bayesian updating when asset inventories, data lineage, access ownership and configuration history remain incomplete. CISA’s January 2026 secure-connectivity principles for OT provide a defensive framework for designing and managing connections into industrial environments. Secure Connectivity Principles for Operational Technology – Cybersecurity and Infrastructure Security Agency and partners – January 2026 — verified primary source. During 2027, CER implementation and NIS2-related measures should push entities toward integrated risk assessments, but regulatory compliance will need to be tested against operating performance. During 2028, the main exposure will shift toward third-party and remote-service ecosystems as more utilities use specialized vendors, cloud analytics and managed operations. During 2029, AI integration will become a major assurance problem. CISA’s multinational guidance states that AI should be integrated into OT while maintaining security, reliability and safety. Principles for the Secure Integration of Artificial Intelligence in Operational Technology – Cybersecurity and Infrastructure Security Agency and international partners – December 2025 — verified primary source. AI can improve anomaly detection but cannot serve as independent confirmation if it consumes the same compromised data. During 2030, cross-sector and cross-border dependencies will become more important than single-asset vulnerabilities. During 2031, the central distinction will be between organizations that can demonstrate recovery through repeated exercises and those that possess extensive documentation but unverified capability. The outlook is therefore conditional: S₂, S₃ and S₆ produce rising ambiguity; S₅ can reverse the trend. Technology growth is not the independent variable. Assurance growth relative to complexity determines the trajectory.
| Year | Dominant development | Leading risk | Required evidence of progress |
|---|---|---|---|
| 2026 | Connectivity and evidence baselining | Unknown assets and trust paths | Validated inventory, lineage and ownership |
| 2027 | CER and NIS2 operationalization | Compliance–capability gap | Site-level all-hazards exercise results |
| 2028 | Vendor and remote-service expansion | Privileged third-party opacity | Purpose-bound access and rapid revocation |
| 2029 | AI-assisted OT operations | Correlated data and model trust | Independent inputs, auditability and safe fallback |
| 2030 | Deeper cross-sector interdependence | Cascading and common-mode failure | Joint water–energy–telecom exercises |
| 2031 | Resilience differentiation | Untested recovery at lagging entities | Measured reductions in detection and recovery time |
Resilience priorities and investment sequencing
The highest-priority investment is the creation of independent operational truth. Every critical process variable should have a documented evidence lineage showing sensor, communications path, transformation, display and fallback verification. The second priority is authority resolution: operators must be able to determine who or what possesses effective control, whether the control state is authorized and how it can be transferred safely. The third is physical–logical reconciliation, linking personnel presence, privileged access, work orders, configuration changes and process consequences. Fourth is recovery assurance: clean configuration baselines, tested backups, spare-equipment strategies and degraded-operation procedures must be demonstrated rather than merely documented. Fifth is evidence coherence, especially trustworthy time across controllers, HMIs, historians, identity systems, physical access and safety systems. Sixth is supplier governance across the full service lifecycle, including emergency access and contract termination. Seventh is cross-sector dependency mapping, because water, electricity, telecommunications, transport and emergency response cannot be modelled independently. Eighth is workforce retention: modernization that removes local engineering understanding can create hidden dependence on external specialists. ENISA’s 2026–2028 programming identifies Union-coordinated resilience preparedness tests and supply-chain risk assessments as continuing priorities and explicitly seeks evidence that regulatory measures improve real sectoral security rather than remaining on paper. ENISA Single Programming Document 2026–2028 – European Union Agency for Cybersecurity – November 2025 — verified primary source. Investment should be sequenced by marginal reduction in service-risk tails, not by product novelty. A modest programme that cuts trusted-state establishment from hours to minutes may outperform an expensive monitoring platform that generates more alerts without independent validation.
| Priority | 2026 baseline metric | 2031 target direction | Board-level evidence |
|---|---|---|---|
| Independent operational truth | Critical variables with separate verification | Toward complete coverage of safety- and service-critical variables | Exercise-confirmed verification time |
| Authority resolution | Time to identify effective controller | Strong reduction | Recorded mode and command ownership |
| Access reconciliation | Sensitive activity matched to valid purpose | Near-real-time reconciliation | Exception rate and closure evidence |
| Recovery assurance | Backups reported | Restorations repeatedly demonstrated | Successful validated recovery |
| Time coherence | Systems using trusted synchronized time | Full critical-event coherence | Reconstructable cross-domain chronology |
| Supplier resilience | Vendors inventoried | Dependencies, access and exit paths tested | Supplier failure and revocation exercises |
| Cross-sector preparedness | Dependency maps documented | Joint exercises and mutual assistance | Demonstrated continuity under shared stress |
| Workforce capability | Training completion | Role-specific performance under degraded conditions | Exercise results, not attendance counts |
Strategic judgment
The most probable 2031 outcome is neither universal infrastructure compromise nor complete resilience. It is widening divergence between mature operators and entities that digitalize faster than they can verify, govern and recover. HMI deception will remain only one component of the wider problem. The more consequential issue is whether an operator can maintain a trustworthy understanding of the physical process when interface data, access records, vendor activity and environmental stress produce conflicting explanations. Bayesian indicators provide disciplined updating, ACH prevents premature attribution, and Monte Carlo analysis quantifies consequence tails; none compensates for missing evidence or untested engineering procedures. The principal strategic warning is that ambiguity itself can become an operational effect. A hostile actor does not need to produce maximum physical damage if uncertainty delays decisions, fragments command, consumes scarce field resources or undermines public confidence. Equally, defenders can create their own strategic failure by attributing an ordinary breakdown prematurely and overlooking the equipment, maintenance or climatic cause needed for recovery. The 2026–2031 resilience programme should therefore optimize for decision quality under degraded trust. The decisive board questions are concrete: How long does it take to establish a trusted physical state? Which critical variables have independent confirmation? Can the organization operate safely without its primary HMI? Are physical and logical access events reconciled with purpose? Can clean configurations be restored? Which external services create single points of failure? Have water, energy and telecommunications dependencies been exercised together? If these questions have measured answers, rising digital complexity need not produce rising systemic risk. If the answers remain policy statements, the region’s exposure will grow even if conventional cybersecurity spending increases.
Figure 3: Posterior Hypothesis Shift Under New Evidence
Method note: each evidence package is treated as a scenario-level likelihood update. Values are normalized to 100. Real investigations must score evidence reliability, independence and diagnosticity; correlated observations must not be counted repeatedly.



















