Cyber security and engineering
Contents |
[edit] Introduction
Reading ICE’s State Of The Nation: Digital report, it struck me that civil engineering, like many kinds of engineering, is driven by the fundamental vision to make people’s lives better.
New digital technologies can help achieve this by advancing functionality and enabling better ways of working. But they also introduce new vulnerabilities and it’s important that we reduce the harm that might arise if these vulnerabilities are exploited.
It doesn’t matter if harm arises from a safety flaw in a construction, a legal loophole in a process, a cyber security issue or a combination of factors, we’re all trying to achieve the same thing – to build a resilient system. Tackling this problem independently can't ever be as effective as taking a holistic approach.
[edit] Cyber security and engineering collaboration crucial
Communication across different disciplines like IT and civil engineering isn't always easy. Our perspectives and language differ, as you'd expect, because they've evolved independently around our respective 'technologies'.
Take your 'caissons' and 'BIM', and our 'TCP/IP stacks' and 'APTs'. But as our two worlds become more connected we've both realised that concentrating solely on technical aspects is no longer enough.
We need to work out how to collaborate more effectively and concentrate less on outputs for us and more on outcomes for people.
For this reason cyber security shouldn't exist as a separate 'IT thing’, or 'somebody else's problem'. It must be integrated into the engineering process not bolted-on later as an afterthought.
Consider the relative longevity of construction/infrastructure systems and their building design information (i.e. the BIM data). Once we take into account planning, construction, commissioning, handover stages and then the post-completion warranty period. The common data environment (CDE) may need to remain in service for up to 20 years and some of that data will need to be accessible for the lifetime of the built asset (say, 60-plus years).
How people will use and interact with the building? Therefore, how this data is stored, protected and accessed by all the different parts of the supply chain will evolve significantly during this time, so a robust, security-minded approach is needed.
An excellent starting guide is the Centre for the Protection of National Infrastructure (CPNI)’s Digital Built Assets and Environments. It includes more information and links about the specification for security-minded building information modelling, digital built environments and smart asset management: PAS 1192-5.
Considering how this approach is supported by the engineering process to achieve the right level of resilience now and in the future will require a more collaborative effort than we have ever seen before. Cyber security needs to be part of the conversations from the start.
At the NCSC we understand that cyber security is a complex topic, and that these conversations will probably involve more questions than answers to begin with. As part of realising our vision of making the UK the safest place to live and do business online we need to break through some of the fear, uncertainty and doubt that commonly dominates the narrative.
[edit] Cyber security research in practice
The NCSC carries out a lot of research, because we want our outputs to be evidence based, not best guesses. We want the things we do and say to really make a difference to people, so we know we need to understand the social and behavioural aspects of our customers as well as their technical concerns.
To do this the NCSC formed a new Sociotechnical Security Group (StSG) in January last year. The group's research topics are spread across three main themes: people, risk and engineering processes.
At the moment, having confidence that engineering processes adequately consider cyber security beyond compliance is very difficult. Our research needs to support engineers from all disciplines to navigate through a whole-life model of security and assurance: embracing both a risk-based and people-centred approach rather than simply a tick-box exercise.
We need to enable you to identify and cost-effectively address the foundational building blocks of your engineering process to gain confidence that what you're building is secure enough for the business’ needs.
But we also want to ensure we produce something that talks in a language that everyone can relate to, not just cyber security experts.
This article was originally published here on 19 Sept 2017 by ICE. It was written by the National Cyber Security Centre.
--The Institution of Civil Engineers
[edit] Related articles on Designing Buildings
- Articles by ICE on Designing Buildings Wiki.
- Building energy management systems BEMS.
- Cyber-security and phishing.
- Cyber threats to building automation and control systems.
- Data Protection Act.
- Digital technology.
- Infrastructure and cyber attacks.
- Measuring the success of smart cities.
- Mitigating online risk.
- Security consultant.
- Smart technology.
- State of the nation: Digital transformation.
- UK organisations encouraged to review cyber security in response to situation in and around Ukraine.
Featured articles and news
Future Homes Standard Essentials launched
Future Homes Hub launches new campaign to help the homebuilding sector prepare for the implementation of new building standards.
Building Safety recap February, 2026
Our regular run-down of key building safety related events of the month.
Planning reform: draft NPPF and industry responses.
Last chance to comment on proposed changes to the NPPF.
A Regency palace of colour and sensation. Book review.
Delayed, derailed and devalued
How the UK’s planning crisis is undermining British manufacturing.
How much does it cost to build a house?
A brief run down of key considerations from a London based practice.
The need for a National construction careers campaign
Highlighted by CIOB to cut unemployment, reduce skills gap and deliver on housing and infrastructure ambitions.
AI-Driven automation; reducing time, enhancing compliance
Sustainability; not just compliance but rethinking design, material selection, and the supply chains to support them.
Climate Resilience and Adaptation In the Built Environment
New CIOB Technical Information Sheet by Colin Booth, Professor of Smart and Sustainable Infrastructure.
Turning Enquiries into Profitable Construction Projects
Founder of Develop Coaching and author of Building Your Future; Greg Wilkes shares his insights.
IHBC Signpost: Poetry from concrete
Scotland’s fascinating historic concrete and brutalist architecture with the Engine Shed.
Demonstrating that apprenticeships work for business, people and Scotland’s economy.
Scottish parents prioritise construction and apprenticeships
CIOB data released for Scottish Apprenticeship Week shows construction as top potential career path.
From a Green to a White Paper and the proposal of a General Safety Requirement for construction products.
Creativity, conservation and craft at Barley Studio. Book review.
The challenge as PFI agreements come to an end
How construction deals with inherited assets built under long-term contracts.
Skills plan for engineering and building services
Comprehensive industry report highlights persistent skills challenges across the sector.
Choosing the right design team for a D&B Contract
An architect explains the nature and needs of working within this common procurement route.
Statement from the Interim Chief Construction Advisor
Thouria Istephan; Architect and inquiry panel member outlines ongoing work, priorities and next steps.

























