Rahim's Letter 047: The Risks to Critical National Infrastructure - Que Pasa?

← Back to Random Thoughts

I sat down this evening to write an introductory note on UK Critical National Infrastructure, to kick start myself into writing that report on how ever-improving AI makes attacks on CNI so much easier. 


A series of rabbit-holes followed, and so this note is going to be a compilation of everything I ended up reading. In theory, there should be some sort of flow to it and it should form the basis of the wider report I end up writing. In practice… well it’s probably a bit rough round the edges. Thoughts/comments/throwaways always welcome. 



So what prompted me to spend my Saturday evening reading and writing about CNI? Well, we had a CNI incident this week - the power went out for 90-seconds at a National Rail operations centre in Manchester on Thursday. That knocked out or reset loads of signalling systems, and caused some physical damage that people needed to go out and actually repair, and so even though the actual outage was only 90-seconds (and National Rail are insisting it was less), getting things up and running again took a while. The disruption also meant that when things were working again, the trains and the crews were all in the wrong place, which piled onto the disruption. 


There’ll be an investigation I’m sure and they’ll commit to making the systems more resilient, but that doesn’t take away from the reality that when these systems go down, there’s serious knock-ons that disrupt people’s lives and so making these systems as resilient as possible is critical, hence critical national infrastructure. 


Despite that, Network Rail decided to move from a system of lots and lots of signal boxes (many of which, admittedly, had been around since the railways were laid) across the country into 12 critical nodes that each control a much larger area. Now that works really well if you’re trying to improve efficiency and trying to run a bigger system with the same budget whilst everything else is getting expensive. But it also means that when one of these nodes goes down, it affects a much larger area too, and so the critical-ness of each individual nodes rises. I’d argue that equals less resilient.


And it’s not just signalling that this affects. London-based readers might remember the landslip at Hook a few years ago, where intense rainfall caused the land under aging Victorian infrastructure to slip, leaving one of the main lines into London out of action for over a month. As costs continue to rise and budgets stay the same, it’s harder for the organisations responsible for maintaining our CNI to replace aging infrastructure, and so the likelihood of seeing major outages increases.  


Now thankfully, there are whole branches of government committed to making sure that doesn’t happen, most prominently the National Protective Security Authority, which is responsible for “target hardening the UK’s economy, infrastructure, industries and crowded places.” The Government also released a Resilience Action Plan last year, which included a commitment to improving the resilience of our Critical National Infrastructure. 


Another incident that got a special mention in the report was the fire at the North Hyde substation last year, which caused a major power outage at Heathrow Airport. Now that happened because some controls that should’ve been put in place by the National Grid in 2018, weren’t, which ultimately led to a fire seven years later, in 2025. Now when Heathrow built out their own electric network, they knew that if this substation went down, they would lose power across some critical systems that would mean they’d have to shut down the airport. But, they assumed that the energy network would be resilient enough that they didn’t need to worry about it. 


At the same time, the National Grid had no idea that this substation was so critical to keeping Heathrow operating. This incident highlighted how energy network operators had no idea which bits of their system were linked to CNI and CNI operators weren’t compelled to make sure they had backups. The Resilience Action Plan tries to fix both of these. 



So what, the Government’s on it and everything’s fine right? Well firstly, a big part of the Plan is that everyone across society has to come together to help protect the nation against disruptive events, and there’s an ongoing effort to bring different parts of society together to do just that. But the second point I wanted to make is just how quickly the threat landscape is evolving. 


Now a key assumption to really draw that out is that every single thing is hackable. If it’s on a computer and someone is determined enough, they can get into it and cause chaos.


That’s because all computers and all programmes have millions and millions of lines of code, and it’s practically impossible for there to be nothing in there that can be manipulated to do something that you didn’t intend for it to do. And almost all computers are run by humans, who fuck up tremendously frequently. Those two premises have led to an explosion in the development of cyber weapons in the last 15 years or so (if you want to hear more about that, you should read This Is How They Tell Me The World Ends, by Nicole Perlroth), mostly because nation-states started paying big money for it. 


Famously, the Russians stole loads of tools from the NSA in 2015 (via the Moscow-based Kaspersky anti-virus software, in case you’re still using it) and dumped them onto the internet. One of those was called EternalBlue, which was a flaw in Windows that the NSA had discovered in 2012, but kept to themselves because, well, it was useful to them. Bad actors then used those tools to build other attacks (you may remember hearing about NotPetya and WannaCry) to cause billions of pounds of damage. 


NotPetya always stands out for me - the Russians used it in Ukraine to effectively turn off most of the screens in the country. That meant ATMs stopped working, your card machine wouldn’t work and the radiation sensors at Chernobyl stopped working (which meant people had to don hazmat suits and go out with handheld radiation monitors). 


It then leaked out of Ukraine and went on a world tour, turning off screens worldwide. There was no undo button - these screens never turned on again. At Maersk, where it basically shut down the entire business, they had to throw out and replace 4,000 servers, 45,000 computers and reinstall 2,500 apps in ten days. 


So, you can hack pretty much anything and cause chaos. 



Now if you’re a bad state actor (for our purposes, read Russia, China, Iran), and you want to use your ability to hack pretty much anything and cause chaos in nations you see as a threat, well what would you do? 


Well, why speculate when we can see for ourselves? 


Ukraine’s energy infrastructure is under constant assault by Russian hackers, regularly trying to knock out their power as another lever in the war. The Russians have form here - another example that always stands out for me was in 2015, where Russian hackers used malware to cause a blackout 2 days before Christmas (which, in Ukraine, means it’s freezing). At the tail-end of last year, we also saw Russian hackers target energy infrastructure in Poland (NATO member, might I add), which came very close to leaving half a million Poles without power in the middle of winter. 


Looking across to the US, it’s been known for a few years now that a Chinese state-sponsored hacking group called Volt Typhoon keeps breaking into US energy infrastructure and just sitting there, which you could speculate is pre-positioning to be able to do something in the future. There’ve been similar incidents with the US water system, including right now, where Iran-backed (allegedly, because it hasn’t actually been proven yet and Trump is  using it to attack Tim Walz, who’s Governor there) hackers have caused equipment failures that could lead to contaminated water supplies. In this case, it’s been caught and water companies seem to have resorted to manual checks again to make sure the system continues to function, and asking people to boil their water before drinking in other instances. 


Here in Britain, we’re seeing a constant wave of attacks, with 200 attacks against UK CNI in the last 12 months, 75% of which have been linked to state actors according to the National Cyber Security Centre. Our National Security Risk Assessment added cyberattacks against water infrastructure and police systems this year, alongside existing entries of cyber risks against health, energy, fuel, transport and telecommunications systems. 


So, the countries that want to do us harm are going to keep trying to use their ability to hack pretty much anything to hack our CNI systems and cause chaos in our lives. 



But wait, I’ve been talking about things like this happening time and time again over the last decade and so why am I going on about it now? Because AI makes it infinitely easier to do these things. 


Case in point - in January (pre-Mythos and the latest wave of frontier models, a technological lifetime ago in our current world), someone attacked the water supply system in Monterrey in Mexico. They did so using Claude to map out the water system and it then helpfully identified a weakness, built an attack for it and tried to execute it. It didn’t work, but it’s a meaningful step change from humans taking months and years to do this research and build the tools to execute an attack like this. 


Anthropic themselves issued a report last September where they found Chinese state-sponsored hackers using Claude Code to attack tech, finance and chemical companies as well as government agencies without much human oversight. In some cases, it was successful. 


This means we now live in a world where the countries that want to do us harm can leverage AI to cut the time to map out vulnerabilities in our critical systems (which we know exist, because you can hack pretty much anything) and increase the chances of a successful attack. 



As AI improves, it’s only going to get easier and so it’s imperative that we’re using the most cutting edge systems to defend ourselves. 


How? 


Well, that’s for the next part of the report. Watch this space. 


RH