![]() |
| Experts warned that organisations relying on third-party providers to run critical services are creating new cybersecurity and resilience risks. Photo: KT file |
The concept of critical infrastructure has changed a lot as businesses transition from using their own internal systems to relying on cloud services and other infrastructure from outside providers.
Cybersecurity leaders
emphasized that this shift has introduced new risks related to cybersecurity
and system resilience that organizations can no longer ignore. During a panel
discussion at the third edition of Future Sec, hosted by Khaleej Times, experts
discussed how this evolution has impacted the definition of critical
infrastructure.
Dee Deu, Group Director of Information Security at Chalhoub Group,
explained that ten or twenty years ago, critical infrastructure was something
that organizations owned and managed in-house, with their own IT teams.
Today, however, the landscape has changed. "We now have
infrastructure as a service," Deu said. "We look at the cloud and how
we've moved to cloud-based solutions in certain situations."
Many organizations today use a combination of on-premise infrastructure
they own and cloud or other services from external providers, which creates a
greater dependence on outside vendors.
"If you look at the recent AWS incident and the number of
organizations affected, the concept of critical infrastructure has to be viewed
through that lens," Deu added. "It's no longer about what we own but
what services are essential for our operations."
The panel also addressed the issue of third- and fourth-party risks.
As organizations grow more dependent on external providers, it becomes
harder to fully understand the scope of their technology environment. Patrick
Pitchappa, CISO of Equiti Group, pointed out that many organizations aren't
managing these dependencies well. "I don’t think any organization has it
right," he said, highlighting the long-standing issue of shadow IT and the
growing challenge of shadow AI.
Pitchappa used the Cloudflare outage and the subsequent AWS incident as
examples of how being overly reliant on a single external provider can have
widespread effects.
"You build large infrastructures, but then there's this one
third-party that you're so reliant on," he explained. "There are a
lot of third- and fourth-party dependencies. That's where I think we start. We
miscalculate."

