Information Security 2 min read

Protecting critical infrastructure against new cyberattack tactics

An overview of emerging cyber threat tactics targeting critical infrastructure, with recommendations for phased Zero Trust adoption and security hardening.

Emerging cyber threat tactics targeting critical infrastructure

According to CERT-UA, spring 2026 saw an increase in cyberattacks targeting local governments and healthcare facilities. Attackers have shifted their tactics: instead of rapid data exfiltration, they now seek long-term persistence within IT systems. This poses ongoing risks to confidentiality and business continuity. The scale of the issue is highlighted by an ENISA report, which documented 4,875 incidents between July 2024 and June 2025.

Cybersecurity in telecommunications and FPV

The FPV technology sector is also exposed to threats due to vulnerabilities in telecommunication channels. According to CFCA, global telecom fraud losses rose from $38.95 billion in 2023 to $41.82 billion in 2025. Protecting unmanned systems requires radio channel encryption, data protection on the ground and in the air, and software integrity controls.

How this affects the sector

The shift toward long-term persistence within IT networks means that critical infrastructure, healthcare, and telecom sectors face prolonged, undetected exposure to cyber threats. This increases the risk of sudden operational disruptions, massive financial losses from telecom fraud, and severe compliance penalties under frameworks like NIS2.

A phased approach to Zero Trust implementation

A common mistake is attempting an overnight transition to the Zero Trust model. An effective strategy requires a phased approach. The first step should be strengthening Identity and Access Management (IAM) with mandatory multi-factor authentication (MFA). The next phase involves network microsegmentation to isolate potential compromises, followed by the implementation of continuous risk assessment.

Recommendations

To build robust defenses, critical infrastructure organizations are recommended to take the following measures:

  1. Optimizing SIEM systems for monitoring and rapid detection of network anomalies.
  2. Implementing IAM and MFA for all users, especially for privileged accounts.
  3. Network microsegmentation to isolate critical systems (including OSS/BSS) from external threats.
  4. Deploying EDR solutions to protect endpoints and workstations.
  5. Developing an Incident Response Plan (IRP) targeting a 24/72-hour response window in compliance with NIS2 requirements.
  6. Supply chain risk assessment and regular employee training in cyber hygiene basics.

Prepared by a Software Ukraine member. Original publication.

Sources & materials

Materials and sources used in this article.

  1. Original publication — intecracy.com