
Loading

Loading
We use strictly necessary cookies to run this site, and analytics cookies to understand how it's used. See our Privacy Policy for details.
The North Atlantic Treaty Organization should direct investments in activities to bolster the resilience of the critical infrastructure that underpins military transportation networks, according to a new report from the current iteration of the Cyberspace Solarium Commission.
Summary
“NATO’s military capacity rests on its ability to swiftly concentrate combat power at decisive points, rapidly moving forces and materiel to the battlefield. That ability depends not only on roads, railways, ports, and airfields but also on the cybersecurity of the civilian systems that enable military movement,” the report argues. The report was written by Jiwon Ma, senior policy analyst at the Foundation for Defense of Democracies, and published on Sept.
28. The Cyberspace Solarium Commission 2.0 is housed at FDD. FDD is hosting a Sept.
28 event to go over the report findings. CSC 2.0 argues the fragmented cybersecurity governance from NATO, national authorities and the European Union “leaves the civilian transportation operators on which alliance forces depend without consistent security standards or oversight.” “The result is a growing disconnect between NATO’s operational requirements and the resilience of the infrastructure supporting them,” the report says. According to CSC 2.0, NATO has the ability to coordinate efforts to secure the infrastructure and mobility capacities required by military forces, but “lacks the authority to impose binding standards on civilian operators.” “As a result, NATO forces cannot move as rapidly as they may need, and investment for upgrades lags behind NATO’s reinforcement requirements.
If NATO fails to align spending with reinforcement requirements, its ability to deter and defend will remain at risk,” the report says. To address this uneven implementation, Ma writes, “The alliance should thus pair its defense- and security-related spending commitment with a process that directs investment toward projects that enhance the physical and cyber resilience of assets integral to military mobility.” Ma describes the “uneven implementation of resilience requirements across its members” as one of the “most consequential challenges” for NATO. The report also emphasizes that the continued trend of Chinese-ownership of critical infrastructure in European Union members heightens the risk of compromise in the event of a conflict.
“Chinese state-linked firms hold stakes in more than 30 European port terminals, including facilities designated to receive U.S. military forces and equipment. The risk from these terminals falls directly on American forces, not only European ones,” Ma writes. Ma says, “In a crisis, Beijing could exploit these dependencies to delay or restrict NATO access.
Such investments also create potential digital avenues for intelligence collection and operational disruption.” The report discusses options for NATO to address cybersecurity threats to critical infrastructure in member states. CSC 2.0 recommends the NATO Integrated Cyber Defence Centre should be “operationalized” around the alliance’s battle plans. The NICDC was stood up in 2024 to provide NATO military commanders threat intelligence.
NATO member states should designate “national liaisons” to connect their transportation regulators and national cyber authorities to NICDC to coordinate cybersecurity activities, according to the report. In the event of conflict, NATO should operationalize its Integrated Cyber Defence Centre to “inform military commanders about cyber threats and vulnerabilities affecting NATO and allied networks,” the report says.
KazaSec's take
Incidents like this rarely start with the headline event itself — they usually trace back to an exposed remote-access endpoint, an unpatched perimeter system, or a credential phished weeks earlier. The organizations that recover fastest are the ones that tested their defenses and their incident response plan before they needed them.
Coverage details
Relevant from KazaSec
More security news
We help organizations find and fix the gaps before they make headlines.