RITICS Fest 2026

The Research Institute in Trustworthy Inter-Connected Cyber-Physical Systems (RITICS) is pleased to announce the 3rd year running of the annual workshop series. The event offers a unique platform to showcase and discuss the latest advancements in the security of Industrial Control and Cyber-Physical Systems across the UK. 

Presentation Summaries

Industrial cyber-physical systems (CPS) increasingly face threats from stealthy multi-stage attacks that utilise Living-off-the-Land (LOTL) techniques. By abusing legitimate administrative tools and native system functions, these attacks can blend into normal operational activities, making reliable detection difficult in safety-critical industrial environments.
This presentation introduces a digital twin-inspired framework for detecting multi-stage LOTL attacks through cross-domain anomaly detection and decision fusion across IT and OT environments. The work is based on multiple CPS simulation testbeds developed for safe and repeatable cyber threat experimentation and data collection.
The presentation discusses a two-level decision fusion approach that integrates process anomalies, industrial network anomalies, process alarms, and host-based anomalies to improve situational awareness under partial observability. Experimental evaluation was conducted using a five-stage LOTL attack chain involving initial access, remote execution, HMI interaction, lateral movement, and process manipulation.
Results demonstrate that anomaly fusion improves detection reliability and timeliness compared with isolated single-modality approaches. The presentation will also discuss implications for cyber resilience, explainability, and AI-enabled decision support in industrial CPS environments.
Paul, cover how many organisations have converged their environment organically, rather than fully planned, how you can also converge your teams and why this is important for incident response, shared expertise if required to effectively respond to a cyber incident in OT.
He will also share some key takeaways on how to build rapport, highlight key information that is need to prepare for incident response, key activities during an incident and key considerations to enact one recover has been completed.

Determinism is a unique feature of real-time cyber-physical systems not found in their IT equivalents. This ability to predict normal/expected behaviors within this poorly understood, to the detriment of cyber-physical IDS design. This presentation describes how intrinsic, structural, configuration and real-time determinism can be exploited to reduce false positive and negative detection rates in practical IDSs.

Connected cyber-physical environments increasingly rely on networked components for sensing, monitoring, actuation, and operational support. In settings such as smart buildings, connected campuses, logistics systems, and digitally managed infrastructure, devices such as network cameras, controllable power devices, lighting controllers, and embedded edge components are becoming part of the operational fabric of the system. Their compromise may therefore affect not only cyber security, but also service continuity, system visibility, and confidence in operational decision-making.

This presentation describes BYOT-CPS (Build Your Own Cyber-Physical Systems Testbed), a hybrid testbed developed to support realistic and repeatable cybersecurity experimentation for such environments. The work addresses a familiar problem in this area: simulation and emulation platforms offer scalability, controllability, and reproducibility, but they do not fully capture firmware-specific behaviour, management interfaces, implementation weaknesses, and communication patterns that often determine real-world exploitability and defensive visibility. Physical-only laboratories provide stronger realism, but they are more costly, harder to extend, and more difficult to reproduce. BYOT-CPS is intended as a practical middle ground, combining real connected devices with virtualised infrastructure in a controlled and isolated environment.

The presentation will outline the design principles, architecture, and prototype deployment of the framework. In the prototype, physical devices including IP cameras, controllable smart plugs, and smart lighting components are integrated into segmented virtual server, enterprise, attack, and monitoring zones. The purpose is not to study these as generic consumer IoT endpoints, but as connected components within broader cyber-physical environments where they contribute to observation, control, and operational continuity. This allows the testbed to support questions around compromise of connected components, attack propagation, resilience, service disruption, and the operational consequences of degraded trust in network-connected devices.
The talk will discuss six requirements that shaped the framework: fidelity, heterogeneity, scalability, reproducibility, extensibility, and independence. It will then present examples of the kinds of security activity the testbed supports, including vulnerability assessment, penetration testing, passive traffic monitoring, controlled denial-of-service scenarios, and manipulation of connected devices with observable operational effects. These examples show how attacks on connected cyber-physical components can extend beyond conventional IT concerns, for example by degrading surveillance capability, interrupting controllable services, or reducing the visibility needed to support ongoing operations.
A further contribution of BYOT-CPS is its use as a vendor-neutral environment for evaluating security monitoring and visibility platforms. This provides a basis for assessing asset discovery, traffic visibility, behavioural monitoring, and detection capabilities under controlled but realistic conditions, rather than relying solely on vendor-led demonstrations. The framework is therefore relevant not only to academic research and teaching, but also to practitioners and organisations seeking independent ways to assess security technologies for connected operational environments.
Overall, the presentation argues that hybrid testbeds such as BYOT-CPS provide a useful basis for CPS security research and evaluation because they preserve real-device behaviour while retaining the flexibility, containment, and repeatability needed for structured experimentation. The work should be of interest to researchers and practitioners concerned with the security, resilience, and assurance of connected systems that support monitoring, control, and operational continuity.

Faced with a Critical National Infrastructure cyber obsolescence crisis, an extension of security techniques successfully deployed by government and defence agencies to successfully move data across different security levels has been considered. The use of hardware for cryptography is not new, its use for Threat Elimination within a Cross Domain Security (CSD) Solution is. The presentation will discuss how CDS can be utilised to deliver localised trust zones, which securely transit untrusted OT networks. The presentation shall highlight published testing by DSTL, EDF and the US Navy, including a UKCS renewables deployment. The presentation shall highlight areas for future research and development opportunities.

This presentation reports our research trajectory in healthcare CPS, focusing on AI-based solutions spanning centralised information systems, distributed cyber-physical systems and Human-AI collaboration in healthcare.
The first part of the research focuses on security assessment in centralised healthcare information systems. In our published research work on AI-based ethical hacking for healthcare environments [1], we have extended the NIST ethical hacking methodology. The framework introduced optimisation and control components and applied Ant Colony Optimisation (ACO) to improve attack-path discovery and exploit selection. Using a realistic OpenEMR-based healthcare testbed comprising electronic health records, database services, web services, and remote access infrastructure, we conducted experimental evaluations and demonstrated improved vulnerability discovery, attack-path identification, and penetration testing efficiency compared with conventional approaches. This work established a systematic approach for identifying vulnerabilities and compromise routes in centralised healthcare infrastructures.
The second part of the research examines the security challenges associated with distributed healthcare CPS. As healthcare organisations increasingly deploy Internet of Medical Things (IoMT) devices, edge intelligence, and privacy-preserving collaborative analytics, federated learning has become an attractive mechanism for distributed AI deployment. Drawing upon our ongoing ESRC-funded research [2] and a current study under review at TDSC, we present SHIELD-FL, a federated intrusion detection framework designed for healthcare CPS environments [3]. SHIELD-FL combines device-specific behavioural profiling using a CNN-BiLSTM-ARGUS-LSTM architecture with a novel Data-Quality Federated Aggregation (DQ-Fed) mechanism that weights client contributions according to training quality and stability. We further evaluate healthcare-specific adversarial threat models, including model poisoning and label-flipping attacks, and assess the effectiveness of Byzantine-resilient aggregation mechanisms. Experimental results show that quality-aware federation improves resilience and detection performance while preserving privacy across distributed healthcare infrastructures.
Finally, the presentation discusses an emerging challenge for next-generation healthcare CPS: the interaction between human decision-makers and AI-enabled systems. As healthcare increasingly relies on AI-supported recommendations and autonomous decision-support services, cyber-attacks are no longer confined to technical systems. Compromised AI outputs can influence clinical decision-making, operational responses, and ultimately physical outcomes. These challenges motivate ongoing research through a recently awarded NABS+ Visiting Fellowship [4] in collaboration with RITICS (Mentor: Prof. Chris Hankin) which investigates Human-AI Interaction in Cyber-Physical Systems with a focus on trust, decision-making, security, and resilience.
The work aligns with several RITICS themes, including AI applied to CPS security, AI vulnerabilities in CPS, resilience against adversarial attacks, healthcare CPS security, and the combined cyber, physical, and human dimensions of security.
Reference:
[1] He, Y., Zamani, E., Yevseyeva, I., & Luo, C. (2023). Artificial intelligence–based ethical hacking for health information systems: A simulation study. Journal of Medical Internet Research, 25, e41748.
[2] Research Grants Return on Cyber Security Investment (ROCSI), ESRC-funded project (Grant Nos. ES/W005964/1 and ES/W005964/2). 2023-2025
[3] He, Y. SHIELD-FL: Adversarial Resilient Federated Intrusion Detection for IoMT Healthcare. Under review at IEEE Transactions on Dependable and Secure Computing.
[4] Fellowships and Awards NABS+ Visiting Fellowship, CREST. 2026 -2027
Operational Technology (OT) cyber incidents rarely begin with a bang—they begin with gaps: gaps in preparation, gaps in documentation, and gaps in coordination. This session explores the anatomy of an incident, outlining a practical process that takes the organization from discovery through recovery and back to business-as-usual.
Drawing from Booz Allen’s extensive field experience across critical infrastructure environments, we will then discuss a recent OT incident case study and give the blow-by-blow of how the response unfolded and an accounting of client outcomes once the dust settled. We will also break down recurring challenges seen during live OT incidents as well as the pre-incident best practices that can help you avoid becoming a case study.
Lessons learned from real experience illustrate how preparation translates directly into reduced downtime, safer containment decisions, increased resilience, and faster recovery when an incident occurs. Attendees will leave with a technically grounded blueprint for sharpening OT incident response programs before the alarms sound.

This research addresses the challenge of reconstructing cyberattack paths from large volumes of security logs generated by Security Information and Event Management (SIEM) systems. While SIEM platforms collect extensive event data, they do not explicitly model attack structure or the temporal and causal relationships needed to connect individual events into an attack campaign. To address this limitation, we propose a framework that integrates MulVAL-based attack graph generation with temporal causal learning to reconstruct likely cyberattack paths from incident logs, while also enabling alignment with known attack patterns (e.g., APT behaviors) and vulnerability intelligence (e.g., CVE databases) for enhanced threat context analysis.

Security Operations Centre (SOC) analysts face overwhelming alert volumes that contribute to fatigue, missed threats, and delayed response. We present AGSSA, an AI-assisted multi-agent framework integrating interpretable machine learning, explainable AI, dual short- and long-term memory, and agentic orchestration. A modality-adaptive detection layer identifies suspicious activity using XGBoost classifiers for labelled network telemetry and Isolation Forest for unlabelled host-process logs, while an orchestration layer transforms alerts into analyst-ready incident summaries, root-cause explanations, and prioritized mitigations aligned with NIST SP 800-61r2. We evaluate AGSSA across five heterogeneous datasets spanning three telemetry planes: network flow (CIC-IDS2017, UNSW-NB15, TON_IoT), host-process telemetry (MITRE BRAWL), and multi-source host logs (NGIDS-DS-v2). The supervised pipeline achieves 99.91% accuracy and 99.97% PR-AUC on CIC-IDS2017, 99.90% accuracy on TON_IoT, and 86.98% accuracy with 98.88% PR-AUC on UNSW-NB15, while the unsupervised BRAWL pipeline surfaces 523 review candidates from 47,026 events with ATT&CK coverage across six adversarial techniques. LIME explanations and counterfactual perturbations provide feature-level evidence across all pipelines, while locally hosted open-source large language models generate structured reports in privacy-preserving, on-premises environments. Under policy-controlled settings, AGSSA achieves alert-reduction rates of 80.29% (CIC-IDS2017), 33.10% (UNSW-NB15), 23.67% (TON_IoT), 98.89% (BRAWL), and 98.81% (NGIDS-DS-v2). Across more than 1.2 million evaluated events, it converts heterogeneous detector outputs into structured, explainable, and auditable incident packages with severity labels, LIME- or perturbation-based evidence, ATT&CK mappings, and recommended actions.

The Threat
Adversaries are systematically harvesting encrypted traffic from critical infrastructure, SCADA, power distribution, industrial control systems to decrypt when quantum computers emerge. For CPS with 20-30 year operational lifespans, data captured today becomes intelligence tomorrow. UK critical infrastructure lacks quantum-safe cryptographic defences against this threat model.
The Gap
NIST standardised post-quantum cryptography (FIPS 203, 204, 205), yet operational deployment in CPS remains minimal. Legacy systems cannot tolerate integration friction. Supply chains lack quantum-safe verification. Organisations lack hybrid cryptographic governance frameworks. Academic research exists; production-ready solutions do not.
The Solution: QSafe DataShare
QSafe DataShare is a live post-quantum cryptographic platform operationalising NIST algorithms (ML-KEM/CRYSTALS-Kyber, ML-DSA/CRYSTALS-Dilithium) for critical infrastructure. Deployed since September 2025, it delivers:
Zero operational disruption: Integrates into existing ICS/CPS control flows without system redesign
NIST compliance: Full FIPS 203/204/205 alignment
Supply chain visibility: Quantum-safe verification embedded across cryptographic workflows
Hybrid-ready: Seamless coexistence with legacy and quantum-safe material
Why Now
NIS2 Compliance: UK regulatory trajectory mandates quantum-safe readiness for essential services. Threat Reality: Harvest-now-decrypt-later is operational adversary doctrine, not theoretical. Competitive Edge: Early adopters secure infrastructure integrity for two decades; delayed action inherits breach liability.

Modern cyber-physical systems (such as critical infrastructures, UAVs, next-generation fighter aircraft, and command-and-control (C2) platforms) rely on the continuous interaction of software, hardware, sensors, networks, and physical processes, making their cybersecurity difficult to assess using simple secure or insecure judgments. This presentation introduces a framework for quantifying confidence in the cybersecurity of cyber-physical systems by treating confidence as a combined inductive and deductive but continuous function of multiple evidence-based factors, including vulnerability evidence, threat likelihood, system criticality, control effectiveness, resilience capability, and operational impact. Instead of producing a fixed binary outcome, the proposed model incrementally builds confidence from available security evidence and updates it as system conditions, threats, and controls change. This enables a more realistic assessment of how strongly a cyber-physical system can resist, detect, respond to, and recover from attacks. The presentation highlights how such a confidence-based approach can support transparent risk reasoning, prioritised mitigation, assurance reporting, and decision-making in safety-critical and operational environments.

This presentation will discuss my recent work on trustworthy agentic cyber defense from two connected directions. First, I will present an explanation-audit framework for learned cyber-defense policies. The key argument is that an explanation should not only sound reasonable to a security analyst; it should also be tested against the agent’s actual behavior. Our framework combines graph-based evidence, cybersecurity knowledge checks, intervention tests, graph ablation, and analyst-facing reports to examine whether an explanation is faithful to the policy it is meant to explain.
Second, I will present ongoing work on topology-aware recovery scheduling for cyber-physical drone swarms. In this setting, drones communicate through a changing wireless topology, while some drones may become compromised, lost, or unable to act as reliable recovery sources. We formulate defense as a recovery-scheduling problem: deciding how many recovery actions to take, which clean drones should act as sources, and which compromised or lost drones should be repaired first. Our current system uses a graph neural network scheduler and counterfactual outcome checks to make these decisions more structured and auditable.
Together, these studies argue that trustworthy autonomous cyber defense should be evaluated not only by reward or task performance, but also by whether its decisions can be inspected by human operators. The broader goal is to support cyber-physical defense agents whose actions are both effective and understandable in dynamic, safety-relevant environments
Cyber-physical systems in sectors such as transport, manufacturing and energy are becoming increasingly interconnected, software-defined and dependent on adaptive digital services. This creates a challenge for conventional assurance approaches, which often assume stable system boundaries, deterministic behaviour and point-in-time certification. In practice, modern CPS evolve through software updates, AI-enabled components, and changing operational environments. This raises the question: how can cyber resilience be engineered, analysed and maintained throughout the operational life of a system?
This presentation introduces the methodology being developed within ENCYRCLE, a Prosperity Partnership between Swansea University and Thales. The methodology treats cyber resilience as the integration of safety, security and liveness. The proposed approach is organised around three connected layers. First, ENCYRCLE develops a through-life model of cyber resilience that incorporates safety, security and liveness, with particular emphasis on the operational phase. Second, it develops and implements a systems and property specification language, ENCYRCLE-SysML, to support cyber resilience design and analysis. Third, it identifies and applies AI-driven tools for the analysis and verification of cyber resilience properties, linking system models to hardware-in-the-loop simulation, test generation and experimental evidence.
This work develops in the context of post-quantum cryptography migration and emerging lifecycle-oriented regulation. The UK NCSC’s post-quantum migration timeline requires organisations, particularly those operating critical national infrastructure and industrial control systems, to begin discovery and planning activities now, complete early high-priority migration activities by 2031, and complete migration by 2035. For automotive and other CPS domains, this migration may introduce timing, performance, compatibility and assurance challenges across secure boot, software updates, key management, communication protocols and embedded platforms. ENCYRCLE therefore treats quantum migration as a resilience problem: one where security upgrades must be analysed alongside safety, operational continuity and system recovery.
The regulatory context reinforces this need for through-life reasoning. The EU Cyber Resilience Act introduces cybersecurity obligations covering the planning, design, development and maintenance of products with digital elements, including vulnerability handling across the product lifecycle. In the automotive domain, UN Regulation No. 155 requires cybersecurity management systems and risk-based governance for vehicle cybersecurity, closely aligning with ISO/SAE 21434. These developments sit alongside established safety and assurance practices, including ISO 26262 for functional safety and ISO 21448 for safety of the intended functionality.
The presentation will discuss how the ENCYRCLE methodology can support current assurance practices by linking lifecycle models, resilience properties, AI-generated scenarios, simulation results and physical testbed evidence into the assurance argument. The intended contribution is a practical research pathway for moving from high-level cyber resilience principles to analysable engineering artefacts. The work is relevant to CPS domains where security, safety, autonomy, cryptographic agility and operational continuity cannot be assessed in isolation.
This presentation builds on prior work on smart topology inference in IoT/OT environments, presented at a previous RITICS event, and extends it toward a structured analysis of how regulatory and operational constraints jointly define the feature requirements for passive OT security systems.
The central argument is that NIS2 Article 21 — specifically its obligations around anomaly detection, documented risk management, and network monitoring — when read alongside the operational constraints endemic to OT and ICS environments (prohibition on active scanning, inability to deploy agents on legacy devices, air-gap requirements, production continuity obligations), creates a well-defined and underexplored requirements space that existing tools address only partially.
The presentation proceeds in three parts.
First, we revisit the structural analysis problem in OT networks: why communication topology carries security-relevant information that device inventory tools do not capture, and why passive inference from traffic patterns is the only operationally viable approach in production ICS environments. We situate this within the broader literature on structural risk in networked control systems.
Second, we present a systematic requirements derivation exercise conducted as part of an Innovate UK CyberASAP project. Drawing on NIS2 Article 21 obligations, NCSC guidance, IEC 62443 framework requirements, and structured research into SOC analyst and IT/OT security manager operational workflows, we derive a prioritised feature set for passive OT network monitoring — distinguishing between features that are technically differentiating, features that are compliance-necessary, and features that existing tools already address adequately.
Third, we discuss the implications of this requirements analysis for system design: specifically, how the intersection of regulatory obligation and operational constraint narrows the viable solution space in ways that favour structural and behavioural analysis over signature-based or inventory-centric approaches. We reflect on the methodological value of constraint-driven feature derivation as an alternative to capability-first product design in the OT security domain.
The presentation does not describe a deployed system or commercial product. It presents a requirements analysis methodology and its outputs, grounded in regulatory text, operational research, and engagement with the ICS/OT security practitioner community. The work is ongoing; findings from structured interviews with manufacturing and energy organisations (in progress, June–July 2026) will be incorporated where available.
As Matter adoption and device deployment continue to grow, it is important to assess alignment with international IoT security frameworks and standards. This interim study evaluates Matter against 18 such frameworks to identify key compliance areas and security gaps.
Using the Cloud Security Alliance (CSA) IoT security taxonomy as a foundation, the analysis focuses on six core security domains: device certification, attack-surface minimisation, secure communications, software update mechanisms, logging and telemetry, and secure storage.
The results highlight areas where Matter provides strong guidance and where it is less prescriptive compared to regulations and frameworks such as the Cyber Resilience Act (CRA), National Institute of Standards and Technology (NIST), and European Telecommunications Standards Institute (ETSI).
Ongoing work will extend this mapping to additional domains, providing a more comprehensive view of Matter’s security posture and offering insights for manufacturers, developers, and regulators.
This presentation is based on a short four-page paper presenting work in progress. The paper has been accepted for the Workshop on Security and Privacy in Standardized IoT (SDIoTSec) at the Network and Distributed System Security Symposium (NDSS) 2026, San Diego, USA.
This work may provide insights into the future regulatory oversight of Cyber-Physical Systems (CPS).
In this presentation we will explore the security of the Combined Charging System (CCS), the leading DC fast-charging standard for electric vehicles (EVs) in Europe, North America and parts of Asia. The charging communication, defined by the ISO 15118 standards, is carried over Power-Line Communication, known as HomePlug Green PHY (HPGP). We will discuss how the inherent design of the physical layer, in particular its unintended wireless leakage out of a nominally wired charging cable, opens the door to wireless attacks, ranging from passive eavesdropping to denial-of-service to a real-time Man-in-the-Middle hijacking of the charging communication. We will show that these attacks are not merely a loss of availability but carry safety-critical, cyber-physical consequences: manipulating the charge parameters lets an attacker force an overcharge at a significantly higher current than requested. We close by discussing potential countermeasures that could be deployed given the pace of the rollout.
Presentation Outline:
Introduction to CCS EV Charging
– Power-Line Communication (PLC) for High-Level Communication
Why is CCS Vulnerable to Wireless Attacks?
– PHY Properties of HomePlug Green PHY and the Unintended Wireless Leakage
– Signal Level Attenuation Characterisation Protocol (SLAC) and the Cleartext Network Key
Disruption of EV Charging at Scale
– Exploiting Carrier Sense Multiple Access/Collision Avoidance
– The Brokenwire Attack: A Closer Look
– How to Protect Against Brokenwire?
Taking Control: From Message Injection to Man-in-the-Middle
– How Little of the Deployed Infrastructure Actually Uses TLS
– The Charging Plug as Attack Vector
– Bypassing TLS: Stripping and Version Downgrade
– Hijacking CCS Charging Sessions: Manipulating Charge Parameters and Forcing Unsafe Power Delivery
Conclusion & Outlook
– How can we increase the robustness of CCS given the fast rollout?
– What about the North American Charging Standard (NACS)?

This research looks at the use of artefacts such as cybersecurity demonstrators (cascading effects on critical national infrastructure (CNI)- conceptual education) and testbeds (cyberattacks on cyber-physical systems (CPS)- technical instruction) for cybersecurity education. Leading on from the research in the paper, Pedagogical approaches for cyber-physical system education: critical national infrastructure vulnerability and mitigation awareness for long term cyber resilience, my research is looking to integrate CPS education into high school curriculums, facilitated by the creative approach of the curriculum for Wales that allows each school to design their own curriculum. Working with a pilot school in association with CyberFirst Wales, with plans of expanding to several local Welsh schools my research looks to address the problem that general knowledge of vulnerabilities within CNI is lacking, by introducing the conceptual topic in mainstream education. It also looks to educate the cybersecurity workforce of the future by introducing technical topics related to CPS such as control loops and hardware security into cybersecurity curriculums.

This talk looks at environments such as testbeds, and virtual environments for cybersecurity research and education. Alex works as a cybersecurity research engineer building testbeds for both research and education, and supporting undergraduate student projects. Projects this year included a virtual environment for lateral movement from Industrial-IoT edge devices onto OT networks, and a virtual environment for the testing of rootkits (including the creation of one). In this talk we will discuss example environments and the process that goes into designing a suitable test environment or ‘cyber range’. Alex is looking into pursuing a PhD related to streamlining the creation of these environments using his three years’ experience designing and building these environments.

More than half of European industrial environments still run legacy operating systems such as Windows XP, and the unpatchable base keeps growing (Windows 10 reached end-of-support in October 2025). Across critical national infrastructure — energy, water, health and manufacturing — these hosts cannot be patched or replaced owing to cost, operational criticality and a lack of OEM support, yet OT/IT integration increasingly exposes them. The real risk is rarely the industrial-control protocols themselves but the unpatchable OS services beside them (SMBv1, RDP, DCOM, NetBIOS): an attacker who exploits one gains control of the host and can then drive connected OT equipment using legitimate-looking local commands.
ASHA, an NCSC-funded project, asks whether generative AI agents can autonomously harden these exposed services while preserving the access and process behaviour operators depend on. We will demonstrate a working end-to-end system built on a dual digital-twin architecture that needs no access to deployed OT: baseline (control) and hardened (intervention) twins are attacked with the same real exploits, and we measure three signals: (1) was the exploit blocked, (2) can operators still connect over RDP, and (3) does the controlled process behave identically to baseline. The presentation (optional live demo) shows a real attack chain (nmap → EternalBlue → SYSTEM-level access → rogue Modbus writes that overflow a tank), then an AI agent reasoning over an agnatically controlled system, deploying hardening configurations and patches, and verifying its own work against all three signals.
Patching is not coming for these systems, but they underpin essential services. ASHA offers a credible, evidence-generating route to retrofit security to legacy CNI hosts, and a reusable testbed for evaluating agentic hardening, without risking operational systems.
The talk is technical and research-focused with no product or service on offer.
The framework shifts deception from a passive detection tool to an active eviction mechanism. It utilizes a hybrid “Adaptive Agentic Honeypot” that combines a deterministic structured simulation layer for routine commands with a governed multi-agent LLM Layer for complex adversary interactions. This dual-tier architecture effectively resists timing-based fingerprinting and sustained adversary engagement through 73% of the MITRE ATT&CK kill chain in testing, without producing hallucinated forensic artefacts.
Furthermore, SAARTHI facilitates a “Privacy-Preserving Sector Alliance” to overcome the data-sovereignty barriers that limit current CNI information sharing to roughly 40%. By employing post-quantum agile cryptographic protocols. The platform allows operators to compute the union of threat indicators and validate sector-wide significance without revealing sensitive raw data or local prevalence statistics. In evaluations across 100 nodes, this decentralized approach achieved a detection rate of 0.912 and an F1 score of 0.936, significantly outperforming centralized sharing models while keeping origin-identification leakage within 1.7% of the random-guess floor.
A powerful enough quantum computer to break cryptography will threaten the public-key systems e.g. RSA and ECC, which quietly underpin the UK’s critical national infrastructure. This risk isn’t just theoretical, it’s already here. Under the “harvest now, decrypt later” approach, attackers can collect encrypted data today and wait until quantum computers are ready to crack it. Mosca’s inequality makes this urgent: if the time needed to secure and update an asset, plus its required security lifetime, is longer than the years left before quantum computers arrive, then organisations are already behind. This is especially worrying for operational technology (OT), where equipment often stays in service for 20 years if not more.
The UK has responded early, with the NCSC’s Timelines for migration to post-quantum cryptography. This sets out a step-by-step plan including discovery and planning by 2028, high-priority upgrades by 2031, and full migration by 2035, anchored on NIST’s finalised standards (ML-KEM, ML-DSA, and SLH-DSA) and reinforced by the UK National Quantum Strategy, It’s a credible plan. However, its main approach, listing assets, swapping algorithms, checking, and retiring old systems, is based on enterprise IT, and OT doesn’t work the same way.
This is where the challenge lies, and why it matters for safety as much as security. Systems using IEC 61850 (e.g. GOOSE and Sampled Values) operate within strict milliseconds. The larger keys, signatures and handshakes of post-quantum cryptography can introduce overhead which might be negligible in IT but can disturb the timing that safety function relies upon. Cryptographic functions are often built into silicon or coded in firmware, so changing algorithms might mean replacing equipment, not just updating software. Many organisations don’t even have a clear view of their cryptographic assets, without a cryptographic bill of materials, you can’t prioritise what you can’t see. The supply chain also sets the pace, vendor firmware updates will drive much of the change, even as companies like Siemens start to publish their post-quantum plans.
This presentation connects the NCSC’s phases to the real world of OT, showing where the roadmap fits, where it needs adjustment, and where OT needs its own plan based on hardware refresh cycles rather than IT timelines. For government and regulators, it gives a realistic view of what 2035 means for the toughest cases, and where policy needs to allow for exceptions tied to hardware. For asset owners and operators, it suggests practical first steps, discovering cryptographic assets, creating a cryptographic bill of materials, risk-based prioritisation, using hybrid classical and post-quantum schemes, and compensating controls to protect assets that can’t be updated. For researchers, it highlights key gaps such as performance benchmarks on real hardware and efficient post-quantum cryptography for limited devices.
The main point is straightforward: the 2035 target is achievable, but only if OT is included from the start, not as an afterthought, and only if discovery begins now.