RITICS Fest 2026
The Research Institute in Trustworthy Inter-Connected Cyber-Physical Systems (RITICS) is pleased to announce the 3rd year running of the annual workshop series. The event offers a unique platform to showcase and discuss the latest advancements in the security of Industrial Control and Cyber-Physical Systems across the UK.
Presentation Summaries
Determinism is a unique feature of real-time cyber-physical systems not found in their IT equivalents. This ability to predict normal/expected behaviors within this poorly understood, to the detriment of cyber-physical IDS design. This presentation describes how intrinsic, structural, configuration and real-time determinism can be exploited to reduce false positive and negative detection rates in practical IDSs.
This presentation describes BYOT-CPS (Build Your Own Cyber-Physical Systems Testbed), a hybrid testbed developed to support realistic and repeatable cybersecurity experimentation for such environments. The work addresses a familiar problem in this area: simulation and emulation platforms offer scalability, controllability, and reproducibility, but they do not fully capture firmware-specific behaviour, management interfaces, implementation weaknesses, and communication patterns that often determine real-world exploitability and defensive visibility. Physical-only laboratories provide stronger realism, but they are more costly, harder to extend, and more difficult to reproduce. BYOT-CPS is intended as a practical middle ground, combining real connected devices with virtualised infrastructure in a controlled and isolated environment.
Faced with a Critical National Infrastructure cyber obsolescence crisis, an extension of security techniques successfully deployed by government and defence agencies to successfully move data across different security levels has been considered. The use of hardware for cryptography is not new, its use for Threat Elimination within a Cross Domain Security (CSD) Solution is. The presentation will discuss how CDS can be utilised to deliver localised trust zones, which securely transit untrusted OT networks. The presentation shall highlight published testing by DSTL, EDF and the US Navy, including a UKCS renewables deployment. The presentation shall highlight areas for future research and development opportunities.
This research addresses the challenge of reconstructing cyberattack paths from large volumes of security logs generated by Security Information and Event Management (SIEM) systems. While SIEM platforms collect extensive event data, they do not explicitly model attack structure or the temporal and causal relationships needed to connect individual events into an attack campaign. To address this limitation, we propose a framework that integrates MulVAL-based attack graph generation with temporal causal learning to reconstruct likely cyberattack paths from incident logs, while also enabling alignment with known attack patterns (e.g., APT behaviors) and vulnerability intelligence (e.g., CVE databases) for enhanced threat context analysis.
Security Operations Centre (SOC) analysts face overwhelming alert volumes that contribute to fatigue, missed threats, and delayed response. We present AGSSA, an AI-assisted multi-agent framework integrating interpretable machine learning, explainable AI, dual short- and long-term memory, and agentic orchestration. A modality-adaptive detection layer identifies suspicious activity using XGBoost classifiers for labelled network telemetry and Isolation Forest for unlabelled host-process logs, while an orchestration layer transforms alerts into analyst-ready incident summaries, root-cause explanations, and prioritized mitigations aligned with NIST SP 800-61r2. We evaluate AGSSA across five heterogeneous datasets spanning three telemetry planes: network flow (CIC-IDS2017, UNSW-NB15, TON_IoT), host-process telemetry (MITRE BRAWL), and multi-source host logs (NGIDS-DS-v2). The supervised pipeline achieves 99.91% accuracy and 99.97% PR-AUC on CIC-IDS2017, 99.90% accuracy on TON_IoT, and 86.98% accuracy with 98.88% PR-AUC on UNSW-NB15, while the unsupervised BRAWL pipeline surfaces 523 review candidates from 47,026 events with ATT&CK coverage across six adversarial techniques. LIME explanations and counterfactual perturbations provide feature-level evidence across all pipelines, while locally hosted open-source large language models generate structured reports in privacy-preserving, on-premises environments. Under policy-controlled settings, AGSSA achieves alert-reduction rates of 80.29% (CIC-IDS2017), 33.10% (UNSW-NB15), 23.67% (TON_IoT), 98.89% (BRAWL), and 98.81% (NGIDS-DS-v2). Across more than 1.2 million evaluated events, it converts heterogeneous detector outputs into structured, explainable, and auditable incident packages with severity labels, LIME- or perturbation-based evidence, ATT&CK mappings, and recommended actions.
Modern cyber-physical systems (such as critical infrastructures, UAVs, next-generation fighter aircraft, and command-and-control (C2) platforms) rely on the continuous interaction of software, hardware, sensors, networks, and physical processes, making their cybersecurity difficult to assess using simple secure or insecure judgments. This presentation introduces a framework for quantifying confidence in the cybersecurity of cyber-physical systems by treating confidence as a combined inductive and deductive but continuous function of multiple evidence-based factors, including vulnerability evidence, threat likelihood, system criticality, control effectiveness, resilience capability, and operational impact. Instead of producing a fixed binary outcome, the proposed model incrementally builds confidence from available security evidence and updates it as system conditions, threats, and controls change. This enables a more realistic assessment of how strongly a cyber-physical system can resist, detect, respond to, and recover from attacks. The presentation highlights how such a confidence-based approach can support transparent risk reasoning, prioritised mitigation, assurance reporting, and decision-making in safety-critical and operational environments.
Future-Proofing Critical Infrastructure: Can QKD Deliver Security from Physics?- Dr Robert Starkwood
This research looks at the use of artefacts such as cybersecurity demonstrators (cascading effects on critical national infrastructure (CNI)- conceptual education) and testbeds (cyberattacks on cyber-physical systems (CPS)- technical instruction) for cybersecurity education. Leading on from the research in the paper, Pedagogical approaches for cyber-physical system education: critical national infrastructure vulnerability and mitigation awareness for long term cyber resilience, my research is looking to integrate CPS education into high school curriculums, facilitated by the creative approach of the curriculum for Wales that allows each school to design their own curriculum. Working with a pilot school in association with CyberFirst Wales, with plans of expanding to several local Welsh schools my research looks to address the problem that general knowledge of vulnerabilities within CNI is lacking, by introducing the conceptual topic in mainstream education. It also looks to educate the cybersecurity workforce of the future by introducing technical topics related to CPS such as control loops and hardware security into cybersecurity curriculums.
This talk looks at environments such as testbeds, and virtual environments for cybersecurity research and education. Alex works as a cybersecurity research engineer building testbeds for both research and education, and supporting undergraduate student projects. Projects this year included a virtual environment for lateral movement from Industrial-IoT edge devices onto OT networks, and a virtual environment for the testing of rootkits (including the creation of one). In this talk we will discuss example environments and the process that goes into designing a suitable test environment or ‘cyber range’. Alex is looking into pursuing a PhD related to streamlining the creation of these environments using his three years’ experience designing and building these environments.