The Invisible Attack Surface: How Open Data Is Redefining Critical Infrastructure Protection

September 29, 2026

Sabotage, hybrid threats and terrorist attack scenarios are forcing critical infrastructure operators to rethink what constitutes an attack surface. Sensitive intelligence on facilities, operational routines, supply dependencies and physical activity can increasingly be generated without breaching a single internal network. Publicly available data, sensor feeds and movement patterns can now be fused by artificial intelligence into a detailed operational picture. For security professionals across Europe and the Middle East, the key question is therefore no longer only how well an organisation protects its perimeter, systems and assets, but also how much of its operational reality can already be observed from the outside.

The prolonged power outage in Berlin at the beginning of 2026 provided a stark reminder of the vulnerability of critical infrastructure. On 3 January, several high-voltage power cables on a bridge across the Teltow Canal in the Lichterfelde district were set on fire. Around 45,400 households and 2,200 businesses initially lost power, and full restoration took more than 100 hours. The attack naturally raised questions about redundancy, emergency power provision and the physical protection of electricity infrastructure, but it also highlighted a less visible dimension of critical infrastructure security: how much information about networks, facilities, locations and operational structures is already available in the public domain, and what can be inferred from it when modern analytical tools are applied.

The issue reaches far beyond Germany. Across Europe and the Middle East, critical infrastructure is becoming more connected, more sensor-driven and increasingly dependent on digital coordination. Energy systems, ports, airports, industrial facilities, logistics hubs, water infrastructure and telecommunications networks generate enormous amounts of data, much of it for entirely legitimate reasons such as market transparency, operational safety, scientific cooperation, navigation, regulation or efficiency. The security problem does not necessarily lie in any individual data point. It lies in the ability to combine thousands of apparently harmless signals until they begin to reveal a coherent picture of physical activity.

A recent TrendAI analysis describes this development as an expanding cyber-physical attack surface. The internet no longer carries communications alone; it also carries a continuous, machine-readable representation of the physical world. Aircraft broadcast positions, ships transmit navigation information, sensors publish environmental conditions, cameras stream images and satellites provide frequently updated imagery. Individually, most of these sources may appear benign. When correlated across time and location, however, they can reveal far more than any single data owner ever intended to disclose. This ability to derive new intelligence from dispersed information fundamentally changes the risk environment for critical infrastructure operators.

How open data can create a picture of critical infrastructure

For security leaders, the first step is understanding the information channels through which such a picture can emerge. Publicly accessible data may originate from regulatory transparency platforms, public APIs, commercial information services, specialist aggregators and, in some cases, openly accessible web interfaces. The concern is not that every individual source contains highly sensitive or classified information. The concern is that multiple information streams can be combined until operational relationships, dependencies and behavioural patterns become visible.

One important category is energy and regulatory data. Public platforms may contain information on generation, consumption, grid activity, individual facilities or industrial loads. Such publication serves legitimate market and regulatory purposes, particularly in highly interconnected European energy markets. From a security perspective, however, the more important question is what becomes visible when those datasets are combined with other sources. Information that may appear harmless in isolation can acquire greater significance when correlated with logistics activity, satellite imagery, maintenance patterns, weather data or observed movement around a facility. Security assessment must therefore move beyond asking whether one dataset is sensitive and instead consider the intelligence value of the combined picture.

This issue is relevant not only in Europe, where transparency obligations form an established part of regulated infrastructure markets, but also in Middle Eastern economies that are rapidly expanding interconnected energy systems, industrial zones, logistics corridors and major infrastructure platforms. Greater digital visibility can improve efficiency, coordination and market transparency, yet it can also increase external observability. The challenge is therefore not to reverse digitalisation, but to understand what additional exposure accompanies it.

A second major source is aviation and maritime movement data. Aircraft equipped with ADS-B systems may broadcast identity, position, altitude and speed, while AIS data in the maritime sector can reveal a vessel’s location, course, speed, destination and estimated arrival time. These systems exist primarily for safety and navigation, but repeated observation over time can reveal patterns that extend well beyond their original purpose. TrendAI highlights, for example, how corporate aircraft movements may under certain circumstances indicate business activity that has not yet been publicly disclosed.

The same principle applies to critical infrastructure. Movements involving specialist contractors, service providers, vessels, charter flights or logistics assets can become part of the external signature of a facility. Over time, recurring patterns may indicate changes in operational intensity, maintenance activity or unusual events. This is particularly relevant to the Middle East, where critical infrastructure frequently intersects with aviation, maritime logistics, energy exports and large industrial ports. A security model focused exclusively on the physical perimeter of a facility may therefore overlook the substantial amount of operational information generated by the transport systems surrounding it.

Logistics and supply-chain data represent another important category. Container tracking, port calls, warehouse information, transport activity and other logistics signals can reveal supply routes and dependencies. When several sources are combined, they may also expose relationships between customers, suppliers and locations that have never been formally published as a complete network. For critical infrastructure operators, this matters because resilience rarely ends at the fence line.

A power station may depend on specialist components from only a handful of manufacturers, a water treatment facility may rely on specific chemicals or maintenance providers, a data centre may depend on fuel deliveries and cooling infrastructure, and an industrial complex may rely on transport nodes located hundreds or even thousands of kilometres away. In all of these cases, a critical dependency may exist outside the operator’s direct ownership. Supply-chain security therefore also becomes a form of information security. Organisations must consider not only what they themselves reveal, but also what suppliers, logistics companies, landlords, contractors and other partners make visible about their operations.

Sensors, cameras and radio signals

The picture becomes even more complex when cyber-physical sensors are included. TrendAI examines publicly accessible cameras, weather stations, software-defined radio receivers and other sensor platforms. A camera may reveal considerably more than a single image if it can be observed over time. It may expose vehicle flows, staffing patterns, activity around access points or changes in the intensity of operations. Weather stations may publish precise location information alongside environmental data, while radio receivers can collect signals from the surrounding environment.

Other connected sensors may indicate whether a location is active, how frequently it is being used or whether operational conditions have changed. Again, the principal risk is not necessarily the sensor itself, but the correlation of several signals. One isolated observation may reveal little, whereas multiple signals aligned by place and time can create a much more meaningful picture.

For physical security professionals, this changes the fundamental question. Security teams have traditionally asked which sensors are protecting a site and whether those systems provide sufficient coverage. Increasingly, they also need to ask which sensors in and around the site are producing information about the organisation. That distinction becomes especially important in smart industrial environments and connected cities, where the number of devices observing the physical world continues to grow, including many that have no formal relationship with the security department.

The internet can reveal what organisations have forgotten

A further dimension is the internet-wide discoverability of exposed devices and interfaces. Public-facing systems do not necessarily need to be known in advance; internet discovery platforms can identify exposed devices at scale. TrendAI’s research refers to services used to locate internet-accessible devices and sensors, demonstrating that external visibility can sometimes be mapped without any prior inside knowledge of the organisation.

For defenders, the same capability offers an important opportunity. Critical infrastructure operators should periodically examine their organisation from the perspective of an external observer and ask which devices, interfaces, cameras, sensors or other systems are visible from the public internet. They should also determine which exposures are authorised, which were introduced by contractors or business units and whether systems remain publicly reachable even though nobody inside the organisation still perceives them as externally exposed.

This is where External Attack Surface Management begins to overlap with physical security. A device exposed to the internet may not represent only an IT vulnerability. It may also become a source of intelligence about physical operations, making its relevance broader than the traditional cybersecurity function.

AI turns fragmented information into intelligence

Open-source intelligence is not new. Governments, intelligence agencies and commercial organisations have used publicly available information for decades. What has changed is the speed, automation and scale with which such information can now be processed. TrendAI describes a five-layer pipeline consisting of collection, transportation, fusion, analysis and dissemination. Data is first gathered and transported, after which different sources are combined. At the fusion stage, separate datasets begin to produce operational inference rather than remaining isolated streams of information.

Artificial intelligence changes the economics of this process significantly. Tasks that once required experienced analysts to spend hours reviewing multiple sources can increasingly be accelerated by AI systems. Large language models and agentic systems can correlate data, identify patterns and generate hypotheses far more rapidly than traditional manual analysis. For critical infrastructure security, this represents a fundamental shift because an adversary no longer necessarily requires one highly sensitive source. A useful operational picture can emerge from dozens or hundreds of ordinary sources whose significance becomes visible only after automated correlation.

TrendAI examines this development largely in the context of state, state-aligned and commercial intelligence actors, but the defensive lesson is broader. For a critical infrastructure operator, the central question is not which specific actor might collect the information, but what information about the organisation can theoretically be reconstructed from the outside. That makes the issue directly relevant to counter-sabotage, counter-terrorism and hybrid-threat planning.

The security problem nobody owns

One of the most important conclusions is organisational. Open cyber-physical telemetry often falls outside traditional security structures because it may not be an IT asset and therefore may not appear in an asset register. It may not represent a conventional software vulnerability and therefore may not be identified through vulnerability scanning. In many cases, it may not constitute a policy violation at all.

Instead, the exposure sits between several functions. The CISO may own cybersecurity, Physical Security may control buildings and access, Operations understands critical processes, Procurement manages suppliers, Corporate Affairs publishes information and Legal teams interpret transparency obligations. Yet no single department necessarily sees the complete external information footprint.

The problem becomes even more complex because much of the exposure may originate from assets the organisation does not own. A logistics company may reveal transport patterns, a landlord may operate a sensor, a service provider may publish project details, a supplier may disclose a facility relationship and a transport platform may expose recurring activity. The consequence is a crucial principle for critical infrastructure protection: an organisation’s information boundary is larger than its network boundary, its property boundary and even its ownership boundary.

From the asset register to the exposure register

TrendAI therefore proposes treating open cyber-physical telemetry as an exposure category in its own right. The practical implication is the creation of an open-telemetry exposure register alongside traditional asset inventories. Such a register should identify publicly visible signals associated with the organisation, including regulatory data, movement information, cameras, sensors, commercial imagery, logistics signatures and relevant exposures created by contractors or suppliers.

The central question is straightforward: What can an external observer see, at what level of detail and how quickly? For critical infrastructure operators, this can become the basis of an External Exposure Analysis. The perspective is deliberately reversed. Rather than asking only what information the organisation itself publishes, security teams ask what picture an external observer could construct about facilities, operations and dependencies using all available information. That difference is critical because security risks often emerge not from what one department discloses, but from how information from multiple departments and third parties can be assembled.

Where traditional physical security enters the picture

This is where the issue moves beyond cybersecurity and becomes highly relevant to the wider security industry. A digital intelligence picture is still only information; it produces security value only when it is linked to physical protection, intervention, crisis management and operational resilience. A practical process for critical infrastructure operators could therefore follow a logical sequence: identify external visibility, assess its physical relevance, review existing protective measures, monitor meaningful changes and adjust the security posture when necessary.

Traditional physical security has an essential role in every stage of that process. A cybersecurity team may identify an exposed camera or interface, but only physical security professionals may understand whether that exposure reveals a sensitive access route, a critical operational zone or a pattern associated with a protected process. Conversely, the site security manager may know exactly which areas are most sensitive but have limited visibility into the digital information available about those areas outside the company.

Neither perspective is sufficient on its own. Cybersecurity understands digital exposure, while Physical Security understands physical significance. Integrated protection requires both and, more importantly, requires a process through which both perspectives are brought together before a threat develops into an incident.

Bringing external intelligence into the security operations centre

Security operations centres and alarm receiving centres are particularly important in this model because they already combine multiple operational signals such as intrusion alarms, video events, access-control alerts, fire alarms and technical failures. More advanced environments use PSIM or other security management platforms to correlate such events. External exposure intelligence can add another layer to that picture, provided it is introduced in a structured and carefully filtered way.

The objective should not be to flood operators with raw open-source information, which would create noise rather than situational awareness. Instead, organisations should define relevant risk indicators in advance. If security analysts detect a meaningful change in the organisation’s external information footprint, unusual automated collection activity or another predefined exposure signal, that information can become additional context for the operational security picture.

A workable process would see Cybersecurity or Threat Intelligence identifying an unusual digital signal, after which Physical Security evaluates whether it has implications for a specific facility, process or group of employees. The security operations centre can then combine that assessment with current access-control, alarm and video information. Guarding or response teams implement defined measures where necessary, while crisis management and business continuity structures take over if the situation exceeds normal operational security procedures. This transforms abstract external intelligence into an operational security process.

A new role for security service providers

The development also creates opportunities for the private security industry. Security service providers traditionally support critical infrastructure through guarding, reception and access control, patrol and intervention services, alarm receiving centres and security consultancy. External exposure assessment could become an additional layer of such services without requiring traditional security companies to become cybersecurity firms.

A security review could examine not only whether a fence can be breached, whether CCTV has blind spots or whether an access point is adequately controlled, but also whether sensitive areas are externally visible through public information, whether operational patterns can be inferred from freely available data and whether third-party providers inadvertently reveal information about their work at the site. The objective would not be offensive reconnaissance against the customer, but defensive understanding of the organisation’s observable footprint before a hostile actor can exploit it.

Traditional physical security surveys could therefore evolve into broader cyber-physical exposure assessments. This would significantly extend the value of security consulting while preserving the core expertise of the classical security industry: interpreting what external information means in the real physical environment and translating that understanding into practical protective measures.

Video, access control and perimeter security gain new context

The same principle applies to security technology providers and systems integrators. Video systems are normally designed around the question of which areas must be observed and which events must be detected. External exposure analysis introduces the opposite perspective by asking which parts of a facility can already be observed from outside the organisation’s own security architecture and what conclusions can be drawn from that visibility.

Access-control systems can likewise be reconsidered in light of externally visible patterns. If predictable operating or delivery schedules become observable through other data sources, security teams may need to reassess whether existing control regimes remain appropriate. Perimeter security faces a similar challenge. Fences, detection systems and access controls are often designed on the basis of a threat and risk assessment that remains relatively static for several years. External intelligence could help make this assessment more dynamic and responsive to changing conditions.

The technology itself does not become obsolete. It gains additional context, allowing existing security investments to be deployed more intelligently according to the external threat environment.

Not every signal should trigger an alarm

There is, however, an important limitation. AI-driven correlation does not create certainty. An automated system can identify a pattern and still reach the wrong conclusion, while open-source information may be incomplete, outdated or misleading. Correlation is not causation, and security organisations must resist the temptation to treat machine-generated inference as established fact.

That has major implications for operational security. An external signal should not automatically trigger intervention. A layered validation process is required in which technology identifies the signal, an analyst checks its plausibility, Physical Security evaluates its relevance to the facility and only then are operational measures considered. Human-in-the-loop decision-making is therefore not an optional safeguard but a core security requirement.

Without such validation, false positives could consume personnel, generate unnecessary interventions and ultimately produce alarm fatigue. The practical objective must therefore be better situational awareness rather than simply more alerts.

From static to adaptive physical security

The integration of external intelligence also points towards a broader evolution in physical security. Many security concepts remain relatively static: a threat assessment is conducted, security levels are established and protective measures are implemented accordingly. Hybrid threats, however, require a more adaptive model in which changes in external visibility or threat indicators can temporarily justify greater attention by the security operations centre, modified access procedures, additional patrols or other predefined measures.

The key element is not any single signal but an agreed escalation framework. Organisations need to define which combinations of indicators require deeper analysis, at what point Physical Security is notified, when a site should move to a higher protection level and which measures can be activated without disrupting operations unnecessarily. In this sense, physical security may increasingly adopt a principle long familiar to cybersecurity: controls become more responsive to the observed threat environment rather than remaining fixed solely on the basis of a static risk assessment.

Reduce, delay and monitor

Not every public dataset should disappear, because transparency often has genuine economic, regulatory and safety value. The aim should therefore not be blanket secrecy, but a more proportionate examination of whether publicly available information genuinely needs its current level of precision, immediacy and accessibility.

Where public access is unnecessary, authentication may be appropriate. Where publication is required, aggregation, reduced precision or delayed release may retain legitimate value while making the information less useful for hostile intelligence collection. Operators should also monitor unusual automated access to publicly exposed systems, since repeated high-frequency collection, machine-like behaviour or systematic queries from changing networks may indicate that data is being harvested at scale.

This introduces another potentially valuable security indicator. The attack itself may not be the first observable event; increased interest in the information environment surrounding an organisation may precede it. Such signals should not be overinterpreted, but they can contribute to a broader situational picture when combined with other indicators.

A practical process for critical infrastructure operators

A defensive model can therefore be built around several connected activities. Operators first need to understand their external visibility by identifying which information about facilities, supply chains, movements and operating processes is publicly accessible. Physical Security and operational teams must then assess which of those signals have real-world significance, because a public dataset may be irrelevant in one context and highly sensitive in another.

The analysis also needs to extend to third parties. Suppliers, logistics providers, landlords, contractors and other partners may all contribute to the observable footprint of the organisation. Relevant changes should be assigned monitoring and escalation criteria, and validated external signals should be connected with existing security information, including access control, CCTV, intrusion detection and other operational data, rather than treated as a separate intelligence silo.

Finally, response plans should be established in advance. Organisations should know which measures are available when external intelligence indicates a heightened threat environment. In this model, External Exposure Management becomes part of the existing security organisation rather than another standalone platform or isolated analytical function.

The new attack surface belongs in exercises

Critical infrastructure operators should also incorporate this issue into training and exercises. Traditional security exercises often begin after an event has already occurred, such as an intrusion, suspicious person, cyber incident or technical failure. A more mature scenario could start earlier, with a change in the external information environment, increased collection against public-facing systems or a combination of signals suggesting unusual interest in the organisation.

The exercise could then test the interfaces between teams. Who receives the information, who validates it, when Physical Security becomes involved and what role the security operations centre plays should all be defined in advance. Operators should also know at what threshold protective measures are changed and when crisis management, public authorities or other external organisations should be engaged.

These questions reveal whether cyber and physical security are genuinely integrated or merely coexist within the same corporate structure. Exercises therefore provide an important means of testing not only technical systems, but also the organisational handovers on which an effective response depends.

Europe and the Middle East: different environments, the same exposure challenge

The relevance of this issue extends across both Europe and the Middle East, even though the operational contexts may differ. European operators frequently work within dense regulatory environments, interconnected energy markets and extensive transparency obligations. Their challenge is often to reconcile openness, regulatory reporting and public accountability with growing security requirements.

Across the Middle East, many critical systems are being developed at extraordinary scale and speed. Energy infrastructure, ports, airports, logistics corridors, industrial cities, water and desalination facilities, smart-city platforms and large digital infrastructure projects increasingly rely on integrated sensor networks and real-time operational data. That connectivity brings enormous efficiency benefits, but it can also increase the number of externally observable signals.

For security leaders in both regions, the underlying principle is therefore the same. Digital transformation changes not only how infrastructure is operated, but also how much of that operation can potentially be observed. The more connected the physical environment becomes, the more important it is to understand the information it emits.

Cybersecurity and Physical Security must converge

Open cyber-physical information cannot be managed by IT security alone. Physical Security understands sensitive locations, access routes and operational behaviour, while Cybersecurity understands exposed systems and automated digital activity. Supply-chain teams understand critical dependencies, Operations understands which processes cannot fail and enterprise risk functions are able to bring those perspectives together.

The solution is therefore not to create another isolated security discipline, but to integrate a missing information layer into existing security processes. This convergence is particularly important for critical infrastructure because modern hostile campaigns can cross traditional boundaries, combining digital reconnaissance, physical observation, information gathering, cyber intrusion and direct physical action at different stages.

Defence must be capable of crossing the same organisational boundaries. The quality of protection will increasingly depend on how effectively information can move between cyber teams, site security, control rooms, technical security systems, operations and crisis management.

Transparency rules need a modern threat model

The issue ultimately extends to regulators as well. Many disclosure requirements were developed under threat models that predate industrial-scale AI-based data fusion. Reconsidering those requirements does not mean abandoning transparency, but rather asking whether the same legitimate objectives can be achieved through tiered access, qualified API credentials, reduced precision or publication delays.

That question will become increasingly important in both Europe and the Middle East as regulators attempt to balance transparency, economic efficiency and national security. The policy issue is no longer simply whether information should be public. It is whether the combination, granularity and immediacy of public information create risks that were not anticipated when the disclosure rules were originally designed.

The adversary does not need to be inside the firewall

Critical infrastructure protection therefore begins before the perimeter, before the access-control system and before the firewall. It begins with visibility. Operators, security companies and public authorities increasingly need to view an organisation from the outside and ask what another party could already learn about it, which information comes from third parties, which operational patterns are visible and which apparently harmless sources become sensitive once combined.

Open cyber-physical telemetry should therefore be treated as a distinct exposure category: identified, monitored, reduced where possible and consciously incorporated into enterprise risk management where it cannot be eliminated. This changes the traditional understanding of critical infrastructure protection because a critical infrastructure operator must not only prevent an adversary from getting inside, but also understand what that adversary may already be able to see before attempting to do so.

This is where new intelligence capabilities meet the traditional security industry. Digital analysis may identify patterns and provide early indicators, but effective protection still depends on the operational translation of those insights into control rooms, guarding, access management, video security, crisis response and resilience. The decisive step is therefore not another isolated security platform, but a shared cyber-physical situational picture from which people, processes and technology can act together.


INFOBOX: Five ways critical infrastructure can become visible

Energy and transparency data: Public regulatory platforms and APIs may reveal information about generation assets, grid activity or industrial loads. The security issue is not the individual dataset alone, but what can be inferred when it is combined with other information.

Aviation and maritime movements: ADS-B and AIS data make aircraft and vessel movements observable. Long-term pattern analysis may reveal changes in operational activity and create additional intelligence about facilities or organisations.

Logistics and supply chains: Container tracking, port calls and other logistics information can reveal critical dependencies. Operators must therefore consider the external visibility of key suppliers and contractors as well as their own.

Sensors, cameras and radio signals: Publicly accessible cameras, weather stations and radio receivers can generate information about locations and operating patterns. Their intelligence value increases when multiple sources are correlated.

Internet-wide discoverability: Publicly accessible devices and sensors can be identified through discovery and exposure-management techniques. Operators should therefore regularly examine what is genuinely visible from outside their organisation.

The central security question is no longer simply: “What information is public?” It is: “What operational picture can be constructed from all publicly available information about us?”


PRACTICE BOX: Who does what in integrated critical infrastructure security?

Cybersecurity and Threat Intelligence identify digital exposure, unusual access patterns and changes in the external information environment, while Physical Security and guarding teams assess whether those findings have real-world implications for buildings, assets, access points, operations or personnel.

Security operations centres and alarm receiving centres combine validated intelligence with CCTV, access-control, intrusion and other operational security information. Security service providers can then implement defined control, presence and response measures and integrate external-exposure reviews into security surveys and consultancy services.

Security engineering and systems integration connect video, access control, perimeter protection and security management platforms with the wider situational picture. Operations and Supply Chain identify critical processes, suppliers and dependencies whose external visibility may create security risk, while Crisis Management and Business Continuity coordinate the wider organisational response when a threat exceeds normal security operations.

The objective is not another security silo, but a shared cyber-physical situational picture that enables operators to respond earlier, proportionately and with greater precision.

Related Articles

Will AI be conducting job interviews in future?

For the time being, it is usually a human who decides who is invited to a job interview. However, the line between digital support and automated recruitment is beginning to blur. According to a representative Bitkom survey, 12 per cent of companies in Germany are...

AI Infrastructure: Power and Cooling Become a System-Level Challenge

The expansion of artificial intelligence is changing not only servers and processors, but the physical architecture of data centres. As the power density of modern AI and high-performance computing systems increases, so do the demands placed on grid connections, power...

Share This