search.noResults

search.searching

saml.title
dataCollection.invalidEmail
note.createNoteMessage

search.noResults

search.searching

orderForm.title

orderForm.productCode
orderForm.description
orderForm.quantity
orderForm.itemPrice
orderForm.price
orderForm.totalPrice
orderForm.deliveryDetails.billingAddress
orderForm.deliveryDetails.deliveryAddress
orderForm.noItems
they challenge expectations about control, assurance, and accountability, and they challenge our understanding of dependencies and exposure. These concerns don’t belong to one sector or point to threat from any one source; they reflect a change in the environment we all operate in.


Reassess your exposure connected world Six pressure points


For security professionals, this introduces a series of interlocking consequences that cut across domains:


1. An expanded digital attack surface. Every new connection inevitably increases the potential access points available to hostile actors. Internet of Things and endpoint devices, particularly in the consumer domain, are rarely built with security as a primary consideration. Regardless of provenance, the design characteristics common to many connected devices challenge long-held expectations around system control, assurance and accountability.


2. A dispersed physical attack surface. Though it may feel intangible, digital connectivity rests on a vast and very real hardware footprint. Endpoint devices, terrestrial and subsea telecommunications cables, data centres, internet exchanges, and satellite systems form a complex web that spans countries and continents. This physical sprawl means that vulnerabilities are not confined to single sites, networks, or attack domains; they emerge wherever the physical components supporting connectivity are exposed.


3. Supply chains further complicate this picture. Connected ecosystems are assembled from layered hardware and software components of mixed provenance, forming complex and obscured supply chains that organisations are unable to map comprehensively. Even then, considering the fluidity of investment and ownership, any mapping of supply chains and dataflows is only point-in-time. Without end-to-end visibility and assurance, changes to upstream service agreements can erode trust in system integrity and data over time.


4. Insider risk is also reshaped by connectivity. As connected ecosystems grow, so too does the number of individuals with access to, or influence over, their components, including contractors, technology vendors, integrators, and third-party service providers, many of whom will sit outside traditional personnel security models. Security teams struggle to exercise effective oversight, which is obscured by patterns of legitimate access, remote maintenance, and shared responsibility models.


5. Systems increasingly rely on real-time data feeds to function. What once were add-ons or functionality enhancements have become operationally critical. This reliance introduces new dependencies on connectivity and data availability; disruption to data streams, whether accidental or malicious, can have cascading effects. Under degraded conditions, systems may behave unpredictably; understanding how a system is designed to operate without connectivity becomes as important as performance under normal operation.


6. Finally, adversaries can use data-rich environments as powerful sources for virtual hostile reconnaissance against individuals, premises and organisations. Aggregated fragments from across multiple sources can reveal sensitive insights, whilst seemingly harmless in isolation. Revealed patterns of behaviour, system usage, physical layouts, and operational processes may be exploited by hostile actors to undermine security in the physical world, acquire sensitive information, subvert process, or influence individuals.


Taken together, these developments point to a shift in the security environment. They challenge assumptions about our traditional models of security disciplines,


© CITY SECURITY MAGAZINE – SUMMER 2026 www.citysecuritymagazine.com


This shift will continue, and as security professionals we must be prepared to engage with it deliberately. Connected technologies are already embedded in our organisations, supply chains, and daily lives; opting out is not realistic. What is within our control is how intentionally we understand those connections, how clearly we define responsibility for them, and how routinely we test the assumptions that underpin trust in our systems.


NPSA recommends that security leaders and practitioners take the time to reflect on their own connected ecosystem, and whether existing models of responsibility still reflect the environment you protect.


This evolution will present differently to you depending on your sector, your technologies, your customers, and the threats you face. Many readers may be familiar with these challenges already; we encourage you to start those conversations within your organisations, and contribute to the wider professional dialogue. Bringing experiences into the open by sharing what has worked, what has not, and where tensions remain will be essential to developing more resilient practice.


Where consequences are most acute, NPSA and our partner national technical authorities will continue to work to make the UK, your people, and organisations, more resilient to terrorism, state threats, cyber and technical attack. This begins with a collective baseline of preparedness, of which security professionals across the country are the essential part.


Further guidance and support are available at npsa.gov.uk, but the first step begins with asking: do our current security assumptions still match the world we operate in today?


National Protective Security Authority (NPSA)


www.npsa.gov.uk


>


8


Page 1  |  Page 2  |  Page 3  |  Page 4  |  Page 5  |  Page 6  |  Page 7  |  Page 8  |  Page 9  |  Page 10  |  Page 11  |  Page 12  |  Page 13  |  Page 14  |  Page 15  |  Page 16  |  Page 17  |  Page 18  |  Page 19  |  Page 20  |  Page 21  |  Page 22  |  Page 23  |  Page 24  |  Page 25  |  Page 26  |  Page 27  |  Page 28  |  Page 29  |  Page 30  |  Page 31  |  Page 32  |  Page 33  |  Page 34  |  Page 35  |  Page 36