The numbers are no longer abstract. Between January 2023 and January 2024, global critical infrastructure sustained over 420 million cyberattacks — an average of 13 attacks per second, representing a 30% year-on-year increase. The energy sector absorbed 1,162 documented attacks in 2024 alone, a 70% increase from the previous year. The annual financial exposure from ransomware incidents in US critical infrastructure is estimated at a floor of $27.1 billion. Downtime costs for ransomware average $53,000 per hour.
These are not statistics about a future threat. They are measurements of a present reality. And the threat model is changing faster than the institutional response.
This sovereign paper argues that the shift from reactive patching to proactive, hardware-enforced resilience is no longer a strategic option — it is a structural necessity. The emergence of agentic AI in offensive operations has created a qualitative discontinuity in the threat landscape that software-based defences were not designed to address. Nations and organisations that continue to treat cybersecurity as a compliance exercise rather than a sovereignty question will find themselves structurally exposed to adversaries who have already made that transition.
The Threat Landscape: A Structural Assessment
Ransomware 3.0: From Encryption to Existential Risk
Ransomware has undergone three distinct evolutionary phases. The first generation — simple file encryption with a ransom demand — was a nuisance. The second generation — Ransomware-as-a-Service (RaaS), which industrialised the attack model by separating core developers from affiliates and Initial Access Brokers — was a business model. The third generation, which is the current reality, is something qualitatively different: a whole-of-business crisis that combines data encryption, data exfiltration, DDoS attacks on public infrastructure, direct harassment of victims' customers, and regulatory complaints designed to maximise leverage.
The RaaS economy has matured into a supply chain of remarkable sophistication. Core developers provide toolkits and infrastructure. Initial Access Brokers sell pre-compromised credentials, collapsing attack timelines from weeks to hours. Affiliates execute campaigns and share revenue with developers. The industrialisation of this supply chain means that the barrier to entry for sophisticated ransomware attacks has fallen dramatically, while the capability ceiling has risen.
In 2025, the FBI reported over 2,100 ransomware incidents targeting US critical infrastructure, with healthcare, manufacturing, and energy sectors facing the highest exposure. By August 2026, the "Gunra" ransomware variant — derived from the leaked Conti source code — had emerged as a significant threat, utilising a double-extortion model and targeting utilities and government services. The Waterfall Security Threat Report 2026 noted a 25% decrease in cyber breaches with physical consequences in 2025, but characterised this as a temporary trend driven by transient factors, with activity expected to resume increasing through 2027.
The Agentic Inflection
The most significant development in the 2026 threat landscape is the emergence of agentic AI in offensive operations. Agentic ransomware — autonomous systems that can navigate networks, identify high-value assets, and execute encryption without human intervention — represents a qualitative shift in the threat model. Previous generations of ransomware required human operators to make decisions at key points in the attack chain. Agentic systems can execute the full attack lifecycle autonomously, from initial access through lateral movement, data exfiltration, and encryption.
Between January 2023 and January 2024, global critical infrastructure sustained over 420 million cyberattacks — averaging 13 attacks per second. The energy sector alone absorbed 1,162 documented attacks in 2024, a 70% increase from the previous year.
The World Economic Forum's Global Cybersecurity Outlook 2026 identifies AI as the primary driver of change in the cybersecurity landscape, with 94% of organisations identifying it as the most significant factor. The report documents a dual dynamic: AI is simultaneously enabling more sophisticated offensive operations and providing new defensive capabilities. The percentage of organisations with processes to assess the security of AI tools before deployment grew from 37% in 2025 to 64% in 2026 — a significant increase, but one that still leaves more than a third of organisations without systematic AI security assessment.
State-sponsored actors have demonstrated the most sophisticated application of persistent, long-duration attack strategies. Groups such as Volt Typhoon and Salt Typhoon have maintained persistent access to essential networks — including energy, water, and transportation — for extended periods, sometimes spanning up to five years before detection. These are not ransomware operations; they are pre-positioning for potential disruption at a time of geopolitical crisis. The distinction between criminal ransomware and state-sponsored pre-positioning is increasingly blurred, as state actors use criminal infrastructure for plausible deniability and criminal actors benefit from state-developed tools.
The Resilience Gap
Against this threat landscape, the resilience of critical infrastructure is inadequate. Approximately 23% of public-sector and international organisations report having insufficient cyber-resilience capabilities, according to the WEF Global Cybersecurity Outlook 2026. In the water sector, the situation is particularly acute: over 70% of US systems inspected by the Environmental Protection Agency in 2024 failed to meet minimum cybersecurity standards under the Safe Drinking Water Act.
Between January 2023 and January 2024, global critical infrastructure sustained over 420 million cyberattacks — averaging 13 attacks per second. The energy sector alone absorbed 1,162 documented attacks in 2024, a 70% increase from the previous year.
The confidence gap is equally concerning. 31% of global respondents report low confidence in their country's response capabilities for major cyber incidents targeting critical infrastructure. This is not a marginal finding — it represents a significant proportion of the global population living in countries whose governments do not believe they are adequately prepared for the cyber threats they face.
Agentic ransomware — autonomous systems that navigate networks, identify high-value assets, and execute encryption without human intervention — represents a qualitative shift in the threat model that software-based defences were not designed to address.
The Regulatory Architecture: NIS2 and Its Limits
The NIS2 Framework
The EU's NIS2 Directive (Directive (EU) 2022/2555) represents the most comprehensive regulatory framework for critical infrastructure cybersecurity currently in force in any major jurisdiction. It establishes mandatory security requirements for essential and important entities across a wide range of sectors, including energy, transport, banking, health, water, digital infrastructure, and public administration. It requires incident reporting, risk management measures, and supply chain security obligations. It empowers national authorities to conduct audits, inspections, and issue binding instructions. Non-compliance can result in fines of up to €10 million or 2% of global annual turnover, and personal liability for management bodies.
The implementation record is mixed. The original transposition deadline was 17 October 2024. By mid-2026, 22 of 27 EU member states had fully adopted the necessary national legislation; five — including France, Ireland, Luxembourg, the Netherlands, and Spain — remained in the legislative process. The European Commission had initiated infringement proceedings against several member states for failing to notify their transposition measures.
On 20 January 2026, the Commission proposed targeted amendments to the NIS2 Directive, including scope adjustments to bring submarine data transmission infrastructure under the directive, new requirements for ransomware payment reporting, and expanded obligations for non-EU companies offering regulated services in the EU. The amendments reflect a recognition that the original directive, adopted in 2022, did not fully anticipate the pace of change in the threat landscape.
The Limits of Compliance-Based Cybersecurity
The NIS2 framework is a necessary but insufficient response to the current threat environment. Its limitations are structural rather than incidental.
First, compliance-based cybersecurity creates a floor, not a ceiling. Organisations that meet NIS2 requirements are not necessarily resilient against sophisticated, persistent, or novel attacks. The directive establishes minimum standards; adversaries are not constrained by minimum standards.
Second, the directive's enforcement timeline is misaligned with the threat timeline. The amendments proposed in January 2026 will take time to negotiate, adopt, and transpose. The threat landscape is evolving on a timescale of months, not years.
Third, the directive's scope, while broad, does not cover all critical dependencies. The interconnection between IT and OT (Operational Technology) systems — the industrial control systems that manage physical infrastructure — creates attack surfaces that are not fully addressed by information security frameworks designed for IT environments.
CISA and other national cybersecurity agencies have increasingly emphasised that software-based defences are insufficient for safety-critical environments. Guidance now advocates for "cyber-informed engineering" — the integration of cybersecurity principles into the design of physical systems — and the deployment of deterministic, hardware-enforced protections such as data diodes, which ensure that even if IT systems are compromised, OT processes remain safe.
A Framework for Sovereign Cyber Resilience
The concept of sovereign cyber resilience goes beyond compliance with regulatory frameworks. It encompasses the capacity of a nation or organisation to maintain essential functions in the face of sophisticated, persistent, and novel cyber threats — and to recover rapidly when those functions are disrupted. It requires a fundamental rethink of how critical infrastructure is designed, operated, and governed.
Agentic ransomware — autonomous systems that navigate networks, identify high-value assets, and execute encryption without human intervention — represents a qualitative shift in the threat model that software-based defences were not designed to address.
Principle 1: Resilience by Design, Not by Patch
The dominant paradigm in critical infrastructure cybersecurity has been reactive: identify vulnerabilities, apply patches, respond to incidents. This paradigm is structurally inadequate against adversaries who can identify and exploit vulnerabilities faster than patches can be developed and deployed, and who can maintain persistent access for years without detection.
Resilience by design requires that critical systems be architected to maintain essential functions even when components are compromised. This means network segmentation that limits lateral movement, redundant systems that can operate independently, and hardware-enforced boundaries between IT and OT environments that prevent compromise of one from cascading to the other.
The data diode — a hardware device that allows data to flow in only one direction — is the canonical example of a hardware-enforced boundary. It is physically impossible for a data diode to transmit data in the prohibited direction, regardless of what software is running on either side. For safety-critical OT environments, this kind of deterministic protection is qualitatively different from software-based firewalls, which can be misconfigured, exploited, or bypassed.
Principle 2: Supply Chain Security as Sovereignty
The most sophisticated attacks on critical infrastructure in recent years have exploited supply chain vulnerabilities — compromising software or hardware components that are widely deployed across multiple organisations, and using those compromises as a vector for access to the organisations' networks. The SolarWinds attack of 2020 and the Kaseya attack of 2021 demonstrated the scale of damage that a single supply chain compromise can cause.
Supply chain security is a sovereignty question because it determines the degree to which a nation's critical infrastructure depends on components whose integrity it cannot verify. The US GAIN Act, included in the FY2026 National Defense Authorization Act, reflects a legislative commitment to prioritising domestic access to critical AI hardware — a recognition that supply chain security for AI systems is a national security issue, not merely a commercial one.
The NIS2 Directive's supply chain security obligations — which require essential entities to assess the cybersecurity practices of their suppliers and to include security requirements in procurement contracts — are a step in the right direction. But they are minimum requirements, not a comprehensive supply chain security strategy. A sovereign approach to supply chain security requires active investment in domestic capability, not merely the imposition of requirements on existing suppliers.
Principle 3: The Human Layer as Distributed Detection
Phishing and credential theft remain the primary entry vectors for ransomware attacks. Despite decades of security awareness training, human error continues to be the most exploited vulnerability in critical infrastructure cybersecurity. This is not a failure of individual employees — it is a structural feature of systems that rely on human judgement as the last line of defence against increasingly sophisticated social engineering.
The appropriate response is not to blame individuals but to redesign systems so that human error is less consequential. This means implementing multi-factor authentication that is resistant to phishing, deploying email security tools that can identify and quarantine sophisticated spear-phishing attempts, and creating organisational cultures in which reporting suspected incidents is encouraged rather than stigmatised.
Security awareness training, when well-designed, can create what security professionals describe as a "distributed detection network" — a workforce that is alert to anomalous behaviour and empowered to report it. This is not a substitute for technical controls; it is a complement to them. The most resilient organisations combine technical controls that limit the impact of human error with cultural practices that make human error less likely.
Principle 4: Immutable Backups as Sovereignty Infrastructure
The most reliable defence against ransomware is the ability to restore systems from backups that the attacker cannot reach or corrupt. Immutable backups — stored offline, in segmented environments, and protected against modification — are the foundation of operational resilience against ransomware. They do not prevent attacks; they limit the leverage that attackers can exercise.
Attackers have recognised this and increasingly target backup infrastructure as part of their campaigns. Modern ransomware operations routinely include reconnaissance of backup systems and attempts to corrupt or encrypt backup data before deploying the primary payload. Organisations that have not implemented offline, immutable, and segmented backups are providing attackers with the leverage they need to extract ransom payments.
31% of global respondents report low confidence in their country's response capabilities for major cyber incidents targeting critical infrastructure — a finding that should concentrate the minds of every national security council on the planet.
The UK Home Office's proposal to ban ransomware payments for public sector bodies and critical infrastructure reflects a recognition that ransom payments fund the development of more sophisticated attacks and create incentives for further targeting of the same organisations. A ban on payments is only viable if organisations have the resilience to recover without paying — which requires investment in backup infrastructure that most public sector organisations have not made.
Principle 5: Governance as a Board-Level Imperative
The NIS2 Directive's provision for personal liability of management bodies — including temporary bans from leadership roles for non-compliance — reflects a deliberate policy choice to make cybersecurity a board-level imperative rather than a technical function. This is the correct framing. Cybersecurity decisions — about investment levels, risk tolerance, supply chain dependencies, and incident response — are strategic decisions that require board-level engagement.
31% of global respondents report low confidence in their country's response capabilities for major cyber incidents targeting critical infrastructure — a finding that should concentrate the minds of every national security council on the planet.
The WEF Global Cybersecurity Outlook 2026 documents that 91% of the largest organisations have modified their cybersecurity approaches in response to geopolitical volatility. This is a significant shift from the pre-2022 era, when cybersecurity was frequently treated as a technical function with limited strategic visibility. The shift has been driven by a combination of regulatory pressure, high-profile incidents, and the recognition that cyber risk is inseparable from operational and reputational risk.
Effective board-level cybersecurity governance requires not just awareness but capability: the ability to ask the right questions, interpret the answers, and make informed decisions about risk tolerance and investment. This requires investment in board education and in the translation of technical risk into business terms that boards can engage with meaningfully.
The Agentic Threat: A Forward Assessment
The emergence of agentic AI in offensive operations is the most significant development in the threat landscape since the industrialisation of RaaS. Its implications for critical infrastructure cybersecurity are profound and not yet fully understood.
Agentic attack systems can operate at machine speed, making decisions and taking actions faster than human defenders can respond. They can adapt to defensive measures in real time, identifying and exploiting new vulnerabilities as they are encountered. They can operate continuously, without the fatigue and attention limitations that constrain human attackers. And they can be deployed at scale, running multiple simultaneous campaigns against multiple targets.
The defensive response to agentic threats requires agentic defences: AI systems capable of detecting and responding to attacks at machine speed, without waiting for human authorisation at each decision point. This creates a new governance challenge: how to deploy autonomous defensive systems that can act quickly enough to be effective, while maintaining human oversight and accountability for the decisions those systems make.
The governance frameworks for agentic defensive AI are still being developed. The EU AI Act's provisions for high-risk AI systems — which include AI used in critical infrastructure — will apply to defensive AI systems as well as offensive ones. The requirement for human oversight is in tension with the operational requirement for machine-speed response. Resolving this tension requires careful system design, clear escalation protocols, and ongoing human review of autonomous defensive actions.
Conclusion: Sovereignty Requires Investment
Sovereign cyber resilience is not a technical problem with a technical solution. It is a governance problem that requires sustained political will, institutional investment, and strategic clarity about what essential functions must be protected and at what cost.
The data is unambiguous: the threat is real, growing, and qualitatively changing. The regulatory architecture — NIS2, the EU AI Act, CISA guidance — provides a framework, but frameworks are not resilience. Resilience requires investment in hardware-enforced boundaries, supply chain security, immutable backup infrastructure, and the human and organisational capabilities to detect, respond to, and recover from sophisticated attacks.
The nations and organisations that will be most resilient in the agentic threat era are those that treat cybersecurity not as a compliance exercise but as a sovereignty question — one that requires the same level of strategic attention and sustained investment as any other dimension of national security. The 31% of global respondents who report low confidence in their country's response capabilities are not describing a technical gap. They are describing a governance failure. Closing that gap requires political leadership, not just technical expertise.
The infrastructure of sovereignty is digital. Protecting it is not optional.






