Information Security 3 min read

Securing critical infrastructure against potential artificial intelligence risks

An overview of implementing the NIST AI RMF 1.0 standard to protect critical infrastructure from AI-specific threats and integrate it with cybersecurity.

Managing artificial intelligence risks in critical infrastructure

Implementing artificial intelligence (AI) in critical infrastructure management systems requires a comprehensive approach to security that goes beyond evaluating model accuracy. Traditional metrics do not guarantee reliability, as up to 27.7% of failures in industrial AI assistants are linked to unpredictable concept drift. Furthermore, systems face specific threats such as evasion attacks, data poisoning, and model reverse engineering.

The four pillars of NIST AI RMF 1.0

To minimize threats, organizations use the NIST AI Risk Management Framework (AI RMF 1.0) standard, which defines the risk management lifecycle through four key functions:

  • Govern: building an AI risk management culture and eliminating the shadow use of technologies.
  • Map: defining the context of use and architectural limitations of the system.
  • Measure: quantitatively assessing risks and testing models for resilience.
  • Manage: implementing incident response procedures and real-time monitoring.

Integration with corporate security and practical experience

The NIST AI RMF 1.0 framework does not replace traditional cybersecurity measures but complements them by integrating with the updated NIST CSF 2.0 standard. This creates a unified security perimeter where traditional IT controls protect the infrastructure, while new tools safeguard model logic and data.

Approximately 53.7% of organizations face challenges in ensuring algorithm explainability in industrial systems. To address these challenges in regulated environments, Ukrainian developers, including Softengi (a member of Intecracy Group), are implementing solutions based on the ISO/IEC 42001:2023 standard. Utilizing secure platforms like UnityBase with RBAC and RLS mechanisms allows for data isolation and ensures compliance with ISO/IEC 27001 and NIS2 directive requirements.

How this affects the sector

Unaddressed AI risks, such as concept drift and data poisoning, directly threaten the stability of critical infrastructure, potentially leading to system failures and security breaches. Furthermore, with 53.7% of organizations struggling with algorithm explainability, failure to adopt structured frameworks risks non-compliance with strict regulatory standards like the NIS2 directive, leaving businesses vulnerable to both legal penalties and operational disruptions.

How to prepare

To safeguard critical infrastructure and ensure compliance, organizations should take the following steps:

  • Adopt NIST frameworks: Integrate NIST AI RMF 1.0 with NIST CSF 2.0 to establish a unified security perimeter for both traditional IT and AI model logic.
  • Implement international standards: Align operations with ISO/IEC 42001:2023 and ISO/IEC 27001 to resolve algorithm explainability challenges and meet regulatory demands.
  • Deploy secure platforms: Use robust solutions like UnityBase with RBAC and RLS mechanisms to guarantee data isolation and protect critical systems from unauthorized access.

Prepared by a Software Ukraine member. Original publication.

Sources & materials

Intecracy Group products and solutions referenced in this article.

  1. UnityBase — unitybase.info
  2. Розробка ПЗ з використанням ШІ та AI-консалтинг — softengi.com
  3. Megapolis.DocNet — inbase.com.ua
  4. А5 Персонал — inbase.com.ua
  5. Xplorum AI Platform — softengi.com
  6. Ionbond AI Visual Inspection — softengi.com