The UK Critical National Infrastructure is critically dependent on digital
technologies that provide communications, monitoring, control, and
decision-support functionalities. Digital technologies are progressively
enhancing efficiency, reliability, and availability of infrastructure, and
enabling new benefits not previously available. These benefits can introduce
vulnerabilities through the connectivity enabled by the digital systems, thus,
making it easier for would-be attackers, who frequently use socio-technical
approaches, exploiting humans-in-the-loop to break in and sabotage an
organization. Therefore, policies and strategies that minimize and manage risks
must include an understanding of operator and corporate behaviors, as well as
technical elements and the interfaces between them and humans. Better security
via socio-technical security Modelling and Simulation can be achieved if backed
by government effort, including appropriate policy interventions. Government,
through its departments and agencies, can contribute by sign-posting and
shaping the decision-making environment concerning cybersecurity M&S approaches
and tools, showing how they can contribute to enhancing security in Modern
Critical Infrastructure Systems.

