Cyber-Physical Risk

What Do Cyber-Physical Attacks Reveal About Buildings?

The line between network defense and construction decisions was never real. When an attack crosses from software into physical systems, or from physical access into software, the building decides how far the damage travels.

cyber-physical attackOTcritical infrastructure
What Do Cyber-Physical Attacks Reveal About Buildings?

By Authentic Intelligence Research · Published

That digital and physical security were never separate. When an attack crosses between software and physical systems, the envelope, rooms and access design determine how far the damage travels and how fast operations recover.

Security programs are usually split in two. One team defends the network; another manages guards, locks and cameras. Attackers do not respect the split, and the incidents that have shaped critical infrastructure policy over the last decade mostly happened in the seam between them.

Three incidents, three directions

Software into physical. On December 23, 2015, attackers used remote access to operate distribution equipment at three Ukrainian utilities. The E-ISAC and SANS analysis found that about 225,000 customers lost power for several hours. The attackers also disabled equipment that operators would have needed to restore service remotely, forcing crews to go to substations and operate them by hand.

Business network into operations. On May 7, 2021, Colonial Pipeline shut down its entire pipeline system after ransomware hit its business network. An Idaho National Laboratory case study found that the operational network was not compromised. The shutdown was a precaution against the infection spreading. The system, 5,500 miles serving 13 states, restarted on May 12 and 13. A precaution taken in software stopped a physical supply chain for days.

Physical into communications. Before firing on PG&E's Metcalf substation in 2013, attackers cut underground telephone cables in a nearby vault. The first move was against the facility's ability to report.

Be careful with the examples

Some widely repeated cases do not hold up. The 2021 incident at the water plant in Oldsmar, Florida, was reported at the time as a hack. In 2023 the FBI said its investigation could not confirm the incident was initiated by a cyber intrusion, and the city's former manager described it as likely employee error. Planning should rest on incidents with a documented record.

The threat itself is not in doubt. In April 2026, the FBI, CISA, NSA, EPA, DOE and U.S. Cyber Command jointly warned that Iranian-affiliated actors were exploiting programmable logic controllers across U.S. government facilities, water and energy systems.

What the building contributes

Field implication

Materials, personnel trust, communications, operations and network defense interact. Critical infrastructure needs them planned as one system, because that is how they fail.

Sources

  1. E-ISAC and SANS, Analysis of the Cyber Attack on the Ukrainian Power Grid (Mar. 18, 2016)
  2. U.S. DOE, Colonial Pipeline Cyber Incident
  3. Idaho National Laboratory, CyOTE Case Study: Colonial Pipeline (2022)
  4. NPR, Sniper attack on California power station raises terrorism fears (Feb. 5, 2014)
  5. Tampa Bay 28, FBI and former city manager say Oldsmar cyberattack never happened (2023)
  6. FBI, CISA, NSA, EPA, DOE and USCYBERCOM, Joint advisory on PLC exploitation (Apr. 7, 2026)

Cite this article: Authentic Intelligence Research, “What Do Cyber-Physical Attacks Reveal About Buildings?” Authentic Intelligence, September 30, 2026, https://authenticint.com/articles/the-built-environment-after-cyber-physical-attack.html.

Continue reading

What Happens When a Building Becomes an Evidence System? · Why Vet Vendors Before Data Center Construction Starts?

Return to research library