For decades, cybersecurity in industrial environments was often viewed as separate from operations. PLCs were considered isolated, SCADA systems remained local, and engineering workstations were accessible only to trusted personnel. Substations, renewable energy parks, power plants and Battery Energy Storage Systems (BESS) were viewed as highly specialized environments, unlikely to become attractive cyber targets.
That reality has fundamentally changed.
Modern Operational Technology (OT) environments have evolved into highly interconnected ecosystems where industrial control systems, remote access platforms, cloud services, enterprise applications and third-party vendors continuously exchange information. This connectivity enables greater efficiency, visibility and operational flexibility, but it also transforms cyber risk.
For critical infrastructure operators, the challenge is no longer simply securing digital environments. It is protecting the physical operations that those digital systems control. This shift requires a fundamental change in how organizations approach OT cybersecurity.
From Cybersecurity to Cyber-Physical Risk
Cyberattacks against industrial environments are not new. What has changed is the scale, accessibility and potential operational impact of those attacks.
IT/OT convergence, remote maintenance, vendor connectivity, cloud-enabled services and increasingly distributed energy assets have dramatically expanded the attack surface. Every new connection creates another potential pathway into operational environments.
More importantly, the consequences of a successful cyberattack have evolved. The objective is no longer limited to stealing information or disrupting IT services. Increasingly, attackers seek to influence the availability, integrity and safe operation of physical processes.
Cyber risk has become cyber-physical risk.

A Warning Sign from Poland
The cyberattacks against Poland's energy sector on 29 December 2025 illustrate how the evolution of cyber threats is becoming an operational reality for modern energy infrastructure.
According to the official CERT Polska / NASK report, coordinated destructive attacks targeted wind farms, solar farms, a manufacturing company and a combined heat and power plant supplying heat to nearly half a million customers. More than thirty renewable energy sites were affected.
Although electricity generation continued and the national power system remained stable, communication with distribution system operators was disrupted, while investigators concluded that the attackers had obtained access capable of affecting electricity generation.
The significance of this incident extends well beyond its immediate operational impact.
It demonstrates that geographically distributed energy assets can no longer be viewed as isolated operational sites. Instead, they form interconnected cyber-physical systems where a cyber compromise has the potential to affect critical operations across multiple locations.
More fundamentally, the incident highlights a broader shift in how organizations should think about OT cybersecurity. The objective is no longer simply preventing unauthorized access, but ensuring that critical operations remain safe, reliable and recoverable when cyber incidents occur.
As the energy transition accelerates, organizations continue deploying renewable generation, Battery Energy Storage Systems (BESS) and remotely managed infrastructure. Operational risk is becoming increasingly distributed, interconnected and dynamic, making cyber-physical resilience an operational necessity rather than simply a cybersecurity objective.
The Evolving OT Threat Landscape
At the same time, the capabilities available to attackers continue to evolve.
Artificial Intelligence represents another step in the evolution of the threat landscape. Its greatest impact is unlikely to come from entirely new attack techniques, will not magically “hack OT” on its own, nor will it instantly turn every attacker into an OT expert.
What it does is enable attackers to move more quickly through enterprise environments and analyze vast amounts of information at unprecedented scale. It can interpret stolen documentation, network diagrams, and vendor manuals, generate scripts, translate technical artifacts, and help identify the operational "crown jewels" that matter most.
In other words, AI reduces the effort required to understand complex industrial environments once attackers have established access. It enables them to make faster, better-informed decisions throughout the attack lifecycle, increasing the likelihood that operational systems -not just enterprise IT- become the ultimate objective.
Defenders are also beginning to leverage AI to improve visibility, prioritization and analysis. However, OT environments differ fundamentally from traditional IT. Decisions affecting industrial operations require engineering expertise, operational context and human judgment. Incorrect prioritization or unsupervised automated actions can introduce operational risk.
The emerging challenge is therefore not autonomous AI attacking industrial systems. It is human attackers becoming significantly more effective at reaching the systems that matter most: generation, protection, engineering workstations, remote access infrastructure, telemetry and operational recovery capabilities.

Regulation establishes the Baseline
Regulators have recognized these changes.
NIS2 establishes a broader cybersecurity risk management framework for essential and important entities across the European Union. The Cyber Resilience Act introduces cybersecurity requirements for products with digital elements. IEC 62443 continues to provide the OT community with a practical framework for securing industrial automation and control systems through risk-based security principles. Similar approaches are reflected in NERC CIP, Germany's KRITIS framework and Saudi Arabia's Operational Technology Cybersecurity Controls.
These initiatives represent an important step forward.
However, regulation establishes a baseline, not resilience.
Compliance demonstrates that specific controls have been implemented at a particular point in time. It does not demonstrate that an organization can safely continue operating during a cyber incident, maintain critical industrial processes under degraded conditions or recover essential operations quickly enough to avoid significant operational consequences.
Passing an audit does not necessarily mean an organization is prepared for tomorrow's cyber threats.
Resilience is the New Measure of OT Security
This is where OT cybersecurity must evolve.
For many organizations, OT cybersecurity has traditionally been measured by a simple question:
"Are we compliant?"
Cyber-Physical Resilience asks a different question:
"Can our operations continue safely, reliably and recover effectively when a cyber incident occurs?"
That distinction changes everything.
Cyber-Physical Resilience recognizes that cyber incidents cannot always be prevented. Rather than focusing solely on preventing compromise, it emphasizes understanding operational dependencies, protecting the industrial processes that matter most, and ensuring organizations can anticipate, withstand, respond to and recover from cyber events without compromising safety, availability or business continuity.
In modern energy infrastructure, cybersecurity is no longer measured solely by the number of implemented controls or successful compliance audits. It is measured by the resilience of the operation itself.

Engineering Cyber-Physical Resilience for Critical Infrastructure
As industrial operations become increasingly digital, distributed and interconnected, cyber-physical resilience has become as much an engineering challenge as it is a cybersecurity one. Protecting critical infrastructure requires understanding how digital systems, physical processes and engineering decisions interact under both normal and adverse operating conditions.
At PROTASIS, this philosophy shapes the way we help organizations understand operational risk, strengthen cyber-physical resilience and move beyond compliance toward long-term operational resilience. By combining expertise in OT cybersecurity, industrial automation and critical energy infrastructure, we help operators build resilience that supports both security and operational continuity.
Because ultimately, the objective is not simply to prevent cyber incidents. It is to ensure that the critical infrastructure that society depends upon can continue operating safely and reliably, even when those incidents occur.