Q&A: The next threat to critical infrastructure is manipulation
To securely protect critical infrastructure, organisations need to evolve their operational technology (OT) security approach. This is the approach recommended by Logan Spillner, Manager of Network Security at SHI. Spillner explains more to Digital Journal.
Digital Journal: For years, operational technology (OT) security has focused on protecting systems and networks. Why do you believe organizations need to rethink that approach today?
Logan Spillner: Traditional OT security programs are built around protecting assets like industrial control systems, PLCs, and other endpoints from unauthorized access or disruption. Those investments remain critical, but the threat landscape has evolved. Increasingly, adversaries are targeting the people who operate these environments rather than the technology itself.
This is what we refer to as cognitive warfare: the deliberate manipulation of human decision-making to achieve operational outcomes. We’ve seen evidence that nation-state actors are maintaining long-term access within critical infrastructure environments, learning how organizations operate, how decisions are made and who operators trust. The goal isn’t always immediate disruption. In many cases, it’s positioning themselves to influence decisions when the timing is right.
If an attacker can manipulate an operator’s judgment, they may never need to compromise a system at all. That’s why organizations need to start viewing human decision-making as part of their attack surface.
DJ: How is AI accelerating this threat?
Spillner: AI changes the scale and speed at which these operations can be conducted. Historically, building an influence campaign requires significant time, research and human effort. An attacker had to understand an organization’s culture and communication patterns. AI dramatically reduces that burden. It can analyze large amounts of information, identify key influencers, generate highly credible messages and mimic organizational communication styles at a level that would have required a dedicated team in the past.
We’re also seeing advances in deepfakes, voice cloning and synthetic media that make it easier to impersonate trusted individuals. In an OT environment, where operators may need to make rapid decisions based on limited information, that creates a very real risk. AI is making deception more convincing, more personalized and more scalable than ever before.
DJ: Why aren’t existing OT security frameworks adequately addressing this issue?
Spillner: Most established OT security frameworks do an excellent job of addressing technical risk. They focus on access controls, defensible architecture, asset visibility, secured remote access, and operational safety.
Current frameworks even address OT security awareness, but they fall short by treating operators primarily as vectors of generalized cybersecurity attacks, rather than intentional targets of sophisticated adversarial activity. These frameworks generally assume that if you secure the systems and teach your operators basic security hygiene, you’ve secured the environment. But these cognitive attacks don’t necessarily exploit a technical weakness, and don’t rely on traditional cybersecurity attacks. They exploit trust, decision-making and human behavior.
As a result, many organizations have mature technical defenses but limited capability to detect when someone is attempting to manipulate the people responsible for operating critical systems.
DJ: What are some warning signs that an organization may be experiencing this type of activity?
Spillner: One challenge is that traditional security tools are unlikely to detect these attacks. Organizations should pay attention to changes in behavior rather than just technical indicators. That could include unusual shifts in operational decision-making, guidance arriving through unapproved channels, pressure to bypass normal validation or escalation steps, unexplained deviations from standard workflows, or recurring misinformation appearing in operational communications.
Another indicator is the appearance of highly targeted messages that seem credible but cannot be fully validated. In many cases, the signal is found in patterns of behavior rather than logs or alerts. That’s why organizations need to broaden their understanding of detection beyond purely technical telemetry.
DJ: What should CISOs and security leaders be doing today to prepare?
Spillner: The first step is acknowledging that this threat exists and that it deserves the same level of attention as technical attacks. Organizations should focus on five key areas: recognition, information integrity, detection, governance, and response. Teams need to understand what influence campaigns look like in operational environments. They need stronger controls around how information enters critical workflows and better processes for validating communications and operational guidance.
It’s also important to establish clear response procedures. Just as organizations have playbooks for ransomware or operational disruptions, they should have processes for investigating and responding to suspected manipulation campaigns. Building these capabilities takes time, which is why organizations should start now rather than wait for an incident.
DJ: What’s your message to industrial organizations that may view this as a future problem rather than a current one?
Spillner: The biggest misconception is that this is theoretical. Recent government advisories have confirmed that nation-state actors are maintaining long-term access inside critical infrastructure environments today. When adversaries spend years observing an organization, they’re learning much more than network architecture. They’re learning how people make decisions, how trust is established and where influence can be applied.
The organizations that will be most resilient in the future are the ones that recognize security is no longer just about protecting systems. It’s about protecting the people, processes and decisions that keep operations running. If an organization only defends its technology, it may miss the attack entirely until the consequences become visible in the physical world.
Q&A: The next threat to critical infrastructure is manipulation
#threat #critical #infrastructure #manipulation