Understanding cyber security risks for a critical national infrastructure
This topic covers cyber security risks specific to critical national infrastructure (CNI), including threats, access control, and incident response. It emphasises the importance of protecting essential services.
Assessment criteria
Topic Overview
The ProQual Level 2 Award in Cyber Security Awareness for Critical National Infrastructure (CNI) introduces learners to the unique cyber threats facing essential services such as energy, water, transport, and healthcare. This qualification focuses on the specific security challenges within CNI, where a cyber attack could cause significant disruption to national security, public safety, or economic stability. Students will explore key concepts like the difference between CNI and general IT systems, the types of threats (e.g., state-sponsored attacks, ransomware, insider threats), and the importance of protective security measures.
Understanding CNI cyber security is vital because these systems often rely on Operational Technology (OT) and Industrial Control Systems (ICS), which have different security priorities than traditional IT. For example, in a power plant, availability and safety are paramount, whereas in a bank, confidentiality is key. This course covers how to identify vulnerabilities in CNI, apply risk management principles, and implement basic security controls. It also emphasises the role of human factors, such as social engineering awareness, and the legal and regulatory frameworks like the Network and Information Systems (NIS) Regulations.
This award fits into the wider subject of cyber security by providing a specialised foundation for those working in or aspiring to work in CNI sectors. It complements general cyber security qualifications by focusing on the operational technology environment and the criticality of protecting national infrastructure. Students will gain practical knowledge that can be applied in roles such as security operations centre (SOC) analysts, OT security technicians, or compliance officers within CNI organisations.
Key Concepts
Core ideas you must understand for this topic
- →Critical National Infrastructure (CNI): Sectors and assets essential for the functioning of society and the economy, such as energy, water, transport, and healthcare. Cyber attacks on CNI can have severe physical and societal impacts.
- →Operational Technology (OT) vs Information Technology (IT): OT controls physical processes (e.g., SCADA systems in power grids) and prioritises availability and safety, while IT manages data and prioritises confidentiality and integrity. Security approaches differ significantly.
- →Threat Landscape for CNI: Includes state-sponsored actors, cyber terrorists, hacktivists, insider threats, and ransomware groups. Attacks often aim to disrupt services, cause physical damage, or steal sensitive data.
- →Risk Management in CNI: The process of identifying, assessing, and mitigating risks specific to CNI environments. This includes understanding the impact of a breach on public safety and national security, and applying controls like network segmentation, access control, and incident response planning.
- →Regulatory Frameworks: Key regulations include the Network and Information Systems (NIS) Regulations 2018, which impose security and incident reporting obligations on operators of essential services, and the Cyber Assessment Framework (CAF) used to assess cyber resilience.
Learning Objectives
What you need to know and understand
- Understand the principles of Cyber Security within a critical national infrastructure, Understand the cyber threats to organisational and personal security, Understand how to identify cyber risks specific to their organisational role or business area, Understand the principles of access control and management, Understand the importance of cyber incident response, disaster recovery and business continuity, Understanding the safe usage of social and professional networks within an organisation
Assessment Criteria
Key criteria assessors look for in your portfolio
- Identify cyber threats to CNI and their potential impact.
- Explain principles of access control and management.
- Describe the importance of incident response and business continuity.
- Recognise safe usage of social and professional networks.
Assessment Guidance
Guidance for achieving higher grades
- 💡Learn about real-world CNI cyber incidents.
- 💡Understand the role of the National Cyber Security Centre (NCSC).
- 💡Focus on risk management and mitigation strategies.
- 💡Use specific examples from CNI sectors (e.g., the 2015 Ukraine power grid attack) to illustrate your points. Examiners look for real-world application of concepts, not just definitions.
- 💡Understand the difference between IT and OT security priorities. In exam questions, if a scenario involves a power plant or water treatment facility, highlight that availability and safety are paramount, and explain how that affects security decisions.
- 💡Be familiar with the NIS Regulations and the Cyber Assessment Framework (CAF). Questions may ask about legal obligations or how to assess compliance. Know the key principles: governance, risk management, security architecture, and incident response.
Common Mistakes
Common errors to avoid in your coursework
- Underestimating the sophistication of cyber attacks on CNI.
- Confusing confidentiality, integrity, and availability (CIA triad).
- Failing to distinguish between personal and organisational cyber risks.
- Misconception: CNI cyber security is the same as general IT security. Correction: While some principles overlap, CNI security focuses on OT/ICS environments where availability and safety are critical. Patching a system might require scheduled downtime to avoid disrupting essential services, and security controls must not interfere with operational processes.
- Misconception: Only large organisations are targets for CNI attacks. Correction: Small suppliers and subcontractors within CNI supply chains are often targeted as entry points. The NIS Regulations apply to all operators of essential services, regardless of size, and supply chain security is a key concern.
- Misconception: Physical security is separate from cyber security in CNI. Correction: Physical and cyber security are closely linked. For example, unauthorised physical access to a control room could allow an attacker to install malware or disrupt systems. A holistic approach is required.
Frequently Asked Questions
Common questions students ask about this topic
Pass / Merit / Distinction Evidence Checklist
How your portfolio evidence is graded for PROQUAL AWARDING BODY Understanding cyber security risks for a critical national infrastructure
Every vocational unit is marked against named criteria rather than an exam percentage. Your tutor's brief lists the exact codes for this unit — here is what each band is asking you to do.
Demonstrate baseline knowledge, accurate terminology, and core practical application.
Provide detailed analysis, structured explanations, and clear workplace reasoning.
Deliver thorough evaluation, original problem solving, and fully justified recommendations.
Before You Start
Prior knowledge that will help with this topic
- •Basic understanding of cyber security concepts (e.g., threats, vulnerabilities, risk).
- •Familiarity with general IT systems and networks (e.g., TCP/IP, firewalls).
- •Awareness of the UK's critical national infrastructure sectors (e.g., energy, transport, water).
Coursework AI Review
Paste your assignment brief and check your draft against its P/M/D criteria
Key Terminology
Essential terms to know
- Understand the principles of Cyber Security within a critical national infrastructure, Understand the cyber threats to organisational and personal security, Understand how to identify cyber risks specific to their organisational role or business area, Understand the principles of access control and management, Understand the importance of cyber incident response, disaster recovery and business continuity, Understanding the safe usage of social and professional networks within an organisation
Ready to learn?
AI-powered learning tailored to this unit