> Markdown version of [/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # What makes Cybersecurity different for critical infrastructure? Enterprise IT is replaced quickly. Grid hardware must survive decades against state-sponsored hackers. Discover why protecting critical infrastructure demands an entirely different playbook. - **Speakers:** Kurt Eder - **Event:** WeAreDevelopers LIVE - **Published:** April 27, 2023 - **Duration:** 1:54:28 - **URL:** https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure ## Summary This presentation delves into the unique cybersecurity challenges facing critical infrastructure, drawing on field operations and strategic insights from Stadtwerke München (SWM). The core narrative highlights how operational technology diverges drastically from traditional enterprise IT. While typical office hardware is upgraded every few years, critical utility components like grid protection relays are designed to operate for up to 20 years. This legacy hardware continuously confronts an escalating threat landscape that has evolved from isolated individuals to highly organized, state-sponsored military cyber units. Furthermore, any resulting downtime in sectors like electricity or water poses severe, immediate risks to public welfare—a stark contrast to corporate disruption. To combat these vulnerabilities, organizations acting as system integrators must enforce stringent business continuity management strategies. The presentation details the necessity of operating under rigorous compliance frameworks, including iso 27000, the iec 62443 standard, and the sweeping nis2 directive. Because complete prevention of complex breaches is practically impossible, infrastructure operators prioritize robust resilience methodologies: detecting anomalous behavior, isolating attacks, and maintaining the capability to safely operate critical systems manually. Building transparent, honest relationships with hardware vendors is also highlighted as an absolute necessity for rapid root-cause analysis and seamless recovery. Focusing on the human element, the session explores the strategies utilized to recruit technically adept professionals into purpose-driven public utility environments aiming to "keep Munich running." With essential roles ranging from business continuity managers to OT security experts, the organization champions a talent acquisition approach that values agile workflow adoption, diversity, and intrinsically motivated problem-solvers. The discussion underscores that while continuous security awareness training is crucial, creating an empowering and highly collaborative workplace is the ultimate key to sustaining long-term smart grid resilience. **Keywords:** critical infrastructure cybersecurity, operational technology, business continuity management, state-sponsored cyberattacks, legacy hardware protection, ransomware recovery planning, iso 27000 compliance, nis2 directive, iec 62443 standard, cybersecurity recruitment, tech talent acquisition, hardware lifecycle management, vendor transparency, smart grid resilience, agile engineering teams ## Chapters 1. **Providing essential utility services for the city** (00:03) — Stadtwerke München operates critical infrastructure spanning energy, water, and mobility to support daily urban life. 1. **Acceptable downtime in critical infrastructure operations** (02:40) — Different utility sectors tolerate cyberattack-induced downtimes differently, with electricity requiring immediate recovery. 1. **The professionalization of modern cyber criminal groups** (08:20) — Cyber threats have evolved from individual hackers to highly organized, state-sponsored cyber operations. 1. **The convergence of IT and OT attacks** (14:39) — Real-world examples demonstrate how attackers exploit traditional IT networks to compromise operational technology grids. 1. **Security challenges of long OT equipment lifecycles** (17:05) — Operational technology often relies on decades-old hardware lacking modern encryption and access controls. 1. **Navigating new cybersecurity compliance frameworks and laws** (29:52) — Infrastructure operators must comply with fast-emerging regulations like ISO 27000, IEC 62443, and the Cyber Resilience Act. 1. **Partnering with hardware vendors on system security** (34:55) — Operators demand transparent communication from equipment manufacturers to quickly patch vulnerabilities and maintain grid stability. 1. **Prioritizing employee awareness and business continuity planning** (42:35) — Organizations must prepare for successful breaches by establishing manual fallback procedures and rigorous employee awareness drives. 1. **Balancing regulatory hardware testing with deployment speed** (46:41) — Regulators face trade-offs between implementing strict state certification for infrastructure devices and avoiding lengthy deployment delays. 1. **Exploring career opportunities and recruitment open positions** (60:59) — Stadtwerke München seeks developers, security professionals, and business continuity managers to support infrastructure resilience. 1. **Detecting malicious code with artificial intelligence models** (63:47) — Security systems leverage artificial intelligence to identify anomalous system behaviors that signature-based malware detection misses. 1. **Adapting agile practices and remote work models** (66:06) — Operational technology teams implement hybrid office policies and adapt frameworks like Scrum and Kanban for infrastructure projects. 1. **Managing outage risks through infrastructure hardware redundancy** (80:23) — Planners secure critical grid functions by maintaining duplicate SCADA systems and redundant fiberglass communication rings. 1. **Promoting diversity and employee benefits for staff** (87:28) — Public utilities offer competitive benefits like secure employment, pension schemes, and a highly inclusive international workspace. 1. **Essential soft skills and evaluating security candidates** (93:25) — Hiring teams prioritize strong communication, self-motivation, and technical curiosity alongside specific programming expertise. 1. **Continuous learning strategies and emerging industry trends** (104:07) — Security professionals stay updated by executing personal programming projects and studying modern architectures like zero trust. ## Related Moments - [Balancing critical infrastructure innovation with regulatory compliance](https://www.wearedevelopers.com/videos/1705-ai-in-leadership-how-technology-is-reshaping-executive-roles) (from "AI in Leadership: How Technology is Reshaping Executive Roles") - [Transitioning from software engineering to security roles](https://www.wearedevelopers.com/videos/1754-security-blindspots-and-how-to-learn-about-them-anna-oliveira) (from "Security Blindspots and How to Learn About Them - Anna Oliveira") - [Recapping vital capability shifts across security and enterprise infrastructure](https://www.wearedevelopers.com/videos/2097-ai-code-then-vs-now-from-complex-rubbish-to-co-piloting-in-12-months) (from "AI Code then vs now: From Complex rubbish to co-piloting in 12 months") - [Leveraging unique cultural backgrounds in engineering design](https://www.wearedevelopers.com/videos/906-one-size-fits-all-not-at-all) (from "One size fits all! Not at all!") - [The fragility and challenges of modern infrastructure management](https://www.wearedevelopers.com/videos/2084-your-infrastructure-is-not-a-playground-ai-agents-for-infra-done-right) (from "Your Infrastructure Is Not a Playground: AI Agents for Infra Done Right") - [Protecting infrastructure with the shared responsibility model](https://www.wearedevelopers.com/videos/691-building-well-architected-applications) (from "Building Well-Architected applications") ## Related Articles - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Developers are Building the Cities of the Future](https://www.wearedevelopers.com/magazine/536-developers-are-building-the-cities-of-the-future) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development) ## Related Jobs - [Endpoint Security Engineer - OT](https://www.wearedevelopers.com/jobs/ext/1998712-endpoint-security-engineer-ot) at **ZEISS Group** - [Endpoint Security Engineer - OT](https://www.wearedevelopers.com/jobs/ext/1306782-endpoint-security-engineer-ot) at **ZEISS Group** - [Senior Cybersecurity Incident Responder](https://www.wearedevelopers.com/jobs/ext/1601203-senior-cybersecurity-incident-responder) at **ZEISS Group** - [Penetration Tester / Red team Specialist](https://www.wearedevelopers.com/jobs/ext/293774-penetration-tester-red-team-specialist) at **Raiffeisen Bank International AG** - [Engineer, Offensive Security Organization](https://www.wearedevelopers.com/jobs/ext/1992296-engineer-offensive-security-organization) at **Twilio** - [Senior Cybersecurity Incident Responder](https://www.wearedevelopers.com/jobs/ext/1999049-senior-cybersecurity-incident-responder) at **ZEISS Group**