TESTIMONIALS

“Received the latest edition of Professional Security Magazine, once again a very enjoyable magazine to read, interesting content keeps me reading from front to back. Keep up the good work on such an informative magazine.”

Graham Penn
ALL TESTIMONIALS
FIND A BUSINESS

Would you like your business to be added to this list?

ADD LISTING
FEATURED COMPANY
Cyber

Convergence of threats

by Mark Rowe

Intelligence is the cornerstone of physical-cyber threat protection, writes Lewis Shields, Director of Dark Ops at the cyber platform ZeroFox.

Threats within the cyber and physical domains have become increasingly intertwined and indistinct. The convergence of real-world physical threats and cyber threats is a double-sided coin. We are now in an interconnected world, in which physical assets, infrastructure, and systems are increasingly disrupted by cyber threat actors. Not only are we witnessing a growing number of cyber attacks on critical infrastructure systems–with the FBI reporting that more than two in five ransomware attacks in 2023 targeted critical infrastructure organisations–rising geopolitical tensions are underpinning a rise in physical threats appearing in online spaces.

Organisations must therefore continually adapt their security posture to combat threats emerging from cyber-physical convergence and to protect both company assets and their people. Understanding the totality of the threats in the first place is key. While many organisations’ security teams focus on cyber threat intelligence, physical threats are often secondary, and can even be poorly understood or neglected.

Enter physical security intelligence (PSI). PSI specifically maps physical threats that originate online, via online sources across the surface, deep, and dark web, to spot things in the digital realm that could pose a risk to physical security in the real world, improving situational security awareness. With cyber threats increasingly leading to real-world consequences, and indicators of physical exposures often surfacing first online, let’s explore what’s driving the convergence of cyber and physical threats and how physical security intelligence can inform better protection.

Understanding cyber-physical convergence

Cyber-physical convergence is no longer one-dimensional. All of us rely on the cyber realm to ensure our physical existence is efficient, comfortable, fun, and civil. However, the physical safety of our friends and colleagues is increasingly jeopardised by bad actors obtaining online information to both threaten and harm unsuspecting victims in the physical world. While this is not a new concept, it’s recently intensified by the sheer volume of information about us readily available in the digital space due to the prominence of public forums and social media in our everyday lives.

In parallel, growing geopolitical tensions around the globe are adding to the dual physical and cyber risks for unsuspecting organisations and executives, driven by political, economic and social unrest, terrorist attacks, and environmental disasters. Top issues–including Russia’s war in Ukraine, competition between the West and China, the Israel-Hamas war, and the energy transition–have resulted in both physical and cyber risks to organisations around the globe. Oftentimes, adversarial cyber actors–including nation state actors and state-linked cyber criminals–seek to accomplish in the cyber domain what they cannot on the battlefield or in the boardroom. Adversarial states openly target each other’s cyber vulnerabilities prior to–and alongside–kinetic activity in the event of a war. Even criminal cyber groups unconnected to specific nation-states are taking advantage of geopolitical tensions to exploit emerging technologies like AI to encourage physical protests and acts of sabotage.

The recent Russian disinformation campaign aimed at disrupting the Paris Olympics serves as a poignant example of how cyber threats can bleed into the physical realm. Russian influence actors are alleged to have released fake, AI-enabled content warning attendees to stay away from the event due to the possibility of a terror attack in addition to content threatening violence against Israelis amid geopolitical tensions. In cases like this, it’s easy to think that more information can make it easier to defend against something you can see coming. In reality, however, these blurred boundaries of credible and fictitious threats create an extremely complex threat landscape, making it challenging for stretched-thin security teams to track what’s happening and triage all potential risks. That’s the larger issue: both cyber and physical threats are on the rise, and on-site security teams don’t have the resources to adequately vet them and alert the right people rapidly, leading to greater potential for physical harm.

The good news is that PSI is designed to find, triage, and assess risk of cyber-physical threats to help security teams address what matters most. While the term “physical security” has traditionally brought to mind cameras, guards, and locked gates – it’s an outdated view. More and more, physical security teams are modernising and including a significant digital element to monitoring and responding to physical threats.

Where physical security intelligence can help

Physical threats often leave trails across digital spaces, like social media and dark web forums. Understanding the credibility of threats requires sifting through an incredible amount of information. To ensure holistic physical and digital protection, security teams need to know what’s really out there – which means identifying, validating, and mapping all of the potential threats that exist in your digital footprint. It’s one thing to know who your enemy is; it’s another to know exactly where they are and what they might do. Given the vast amount of information sources across the internet, this is a tough task to tackle alone. Solid PSI pairs AI-driven technology that scours the surface, deep, and dark web to collect proactive threat intelligence with a team of highly-skilled analysts who ensure high-fidelity alerts.

Armed with this knowledge, security teams can move at the speed of threats and more effectively mitigate the physical threats that are most likely to pose a risk to their organization and its key personnel. Not all threats are credible, nor are all threats made equal. Knowing when to alert impacted parties helps to stave off panic and ensures that true threats are taken seriously.

Organizations can no longer ignore the urgency for a holistic, integrated approach to security – one that addresses both the cyber and the physical landscape. By consolidating digital and physical security technologies and leveraging PSI, security teams can reinforce their defenses and establish a unified front against all evolving threats, no matter their realm.

Related News

  • Cyber

    Digital watershed in 2026

    by Mark Rowe

    Ben Schilz, CEO at Wire, predicts for 2026 movements towards a sovereign Europe, quantum-ready encryption and a slow goodbye to Big Tech.…

  • Cyber

    Pay gaps pose risks

    by Mark Rowe

    Demand for Web3 cybersecurity people is sending salaries higher at the expense of Web2 specialists with pay in the European Union, and…