top of page
yava_white_logo.png

YAVA Monthly Report | August 2026: Critical Infrastructure, Drone Threats and Aviation Resilience

Aug 27
11 min read
Large industrial plant illuminated at night, with pipes, towers and processing infrastructure visible beneath a dark sky.
August showed how quickly geopolitical tension can move from the headlines into the systems that keep energy, water, transport and aviation operating. 

Welcome to YAVA’s Monthly Report, offering a clear snapshot of our latest projects, regional developments, and sector movements.


Each edition includes YAVA project updates, market analysis, and key news from Africa, the Middle East, India, and Europe — delivering practical insight across our operating landscape.


Visit www.yava.com for more.


Or follow us on LinkedIn (@YAVA_COM)


THE BATTLEFIELD NOW RUNS THROUGH CIVILIAN INFRASTRUCTURE


Large industrial plant illuminated at night, with pipes, towers and processing equipment beneath a dark sky.
Cyber conflict is moving closer to the physical systems that support everyday life. Attacks on energy, water and industrial infrastructure show how digital threats can create operational disruption.

A British power generator forced offline, attacks on US water systems and warnings over industrial control technology point to an uncomfortable reality: geopolitical conflict increasingly reaches the systems civilians depend on every day.


On 24 August, the UK government briefed energy industry leaders after reports that hackers linked to Iran had forced a small British electricity generator offline for four days in July.


Nobody lost power and the government stressed that the wider grid was never threatened. Attribution has not been publicly confirmed.


That makes the incident easy to dismiss.


It shouldn’t be.


A politically motivated cyberattack appears to have crossed from the digital environment into the physical operation of a British energy asset.


And it was not an isolated warning.


On 19 August, the NSA, FBI, Department of Energy, Environmental Protection Agency and CISA warned that cyber actors were actively targeting Siemens S7 programmable logic controllers used across energy, water, manufacturing, chemicals, food production, and other critical sectors.


The advisory is particularly significant because attackers are using AI-generated exploitation scripts, reducing some of the time and expertise historically required to attack industrial technology. Successful exploitation could disrupt industrial processes, cause equipment downtime, or create safety incidents. 


Water infrastructure has already provided a glimpse of what that can mean. Attacks reported across multiple US states this summer disrupted systems, changed passwords, and, in some cases, contributed to pressure loss, flooding and utilities being taken offline before manual recovery. More than 30 community water systems in Minnesota were targeted during one coordinated incident in late July. Attribution remains under investigation. 


The individual incidents may be limited, but the direction of travel is not.


Critical infrastructure is increasingly becoming part of the geopolitical battlespace.


For years, cyber conflict could often be discussed in terms of stolen information, disrupted websites, and compromised corporate networks. Operational technology changes the stakes. When digital access can interrupt electricity generation, alter water systems, or interfere with industrial processes, the distinction between cyberattack and physical disruption begins to narrow.


The preparedness picture remains uneven.


The UK Government’s Cyber Security Breaches Survey 2025/2026 found that 43% of businesses had identified a cyber breach or attack during the previous 12 months. Yet only 25% had a formal incident response plan, while 45% said they had none of the formal incident-response measures assessed by the survey.


The uncomfortable conclusion is that protecting infrastructure can no longer be reduced to keeping an attacker outside the network.


For operators responsible for energy, water, transport, and other essential systems, the question is changing.


It is no longer simply: “Can we keep attackers out?”


It is: “What happens when they get in?”


CRITICAL INFRASTRUCTURE RESILIENCE: ASSUME SOMETHING WILL GET THROUGH


Large industrial control room with rows of switches, gauges and monitoring equipment inside a power facility.
When disruption reaches operational systems, resilience depends on what can still be controlled, isolated and recovered. Critical infrastructure needs to be tested for failure.

The events of August reinforce a distinction that matters across critical infrastructure: security controls and operational continuity are related, but they are not the same thing.


An organisation can have firewalls, surveillance, access control, monitoring tools and incident plans and still discover during disruption that essential operations cannot continue without the systems that have just been compromised or isolated.


The question becomes practical: What still works?


Understand what must keep running


Critical infrastructure increasingly combines enterprise IT, operational technology, physical security, communications, cloud services, specialist equipment, contractors and staff procedures.


Those dependencies need to be understood together.


YAVA works at the asset itself, assessing the physical, technology, and human layers of the operating environment to understand what is in place, how systems depend on one another, and where an individual failure could become a wider operational problem. 


Design for degraded operations


Resilience is tested when the primary system is no longer available.


Can operations continue without normal connectivity? Can a site function if corporate IT is isolated? Can critical access still be controlled? Are alternative communications available? Can staff switch safely to a manual process?


The NCSC’s 2026 guidance for critical national infrastructure specifically recommends understanding critical systems, planning for degraded IT or OT, and rehearsing isolation and recovery procedures. 


Verify, don’t assume


Documentation can tell an organisation that a backup exists.


Testing establishes whether it can actually be restored.


The same principle applies to network segmentation, physical access, backup communications, privileged identities, and incident procedures. Controls should be tested in the environment where they are expected to perform.


YAVA’s engineering teams work on site because buildings, equipment, networks, power, connectivity and operating procedures differ from one location to another. Systems can therefore be tested under the conditions in which they have to operate. 


Fix and retest


Assessment should lead to action.


Depending on the environment, that might mean changes to networks, remote access, physical security, backup and recovery, communications, equipment or staff procedures.


YAVA combines assessment with design, systems integration, deployment, remediation and ongoing support, allowing weaknesses to be corrected rather than simply documented. 


That is important because resilience is not static.


Staff change. Suppliers change. Networks expand. Temporary access becomes permanent. Equipment ages. New systems are connected to old ones.


The lesson from August is not simply to add another layer of defence. It is to understand how the asset behaves when one of those layers fails.


GEOPOLITICS & WAR DEVELOPMENTS


  • Hormuz pressure returns to energy markets


Oil climbed around 5% on 9 August as hopes of a rapid reopening of the Strait of Hormuz faded. ADNOC had reported 15 missile and drone attacks on its vessels since the current conflict began, while continued Houthi attacks delayed operations at Saudi Arabia’s Jazan refinery. The disruption illustrates how quickly regional security can translate into shipping constraints, higher costs, and pressure on global energy markets.


  • Drone strike takes Russian refinery offline


A Ukrainian drone strike forced Russia’s Orsk refinery to shut completely in August. Regional authorities said repairs to key infrastructure could take up to six months, partly because sanctions have restricted access to imported replacement equipment. At the time, only 80% of the region’s 287 filling stations were operating. 


  • Nord Stream investigation moves forward


German prosecutors announced the arrest in Croatia of a second Ukrainian suspect in connection with the 2022 Nord Stream explosions. More than four years after the pipelines were damaged, the investigation remains a reminder that sabotage against strategic infrastructure can create geopolitical, legal and energy-security consequences long after the physical event itself. 


  • Ukraine's air defence pressure intensifies


Ukraine said allied deliveries of air-defence missiles in 2026 had fallen to around one-third of 2025 levels as Russia intensified strikes against Kyiv and southern port infrastructure. Ukrainian officials are also preparing for renewed attacks on energy assets during winter, putting further pressure on the protection of civilian infrastructure. 


INFRASTRUCTURE SECURITY TRENDS TO WATCH


Freight trains parked across multiple railway tracks in an illuminated rail yard at night.
Transport networks depend on physical and digital infrastructure operating continuously. Asset condition, maintenance and operational visibility are critical to keeping them moving.
  • Explosive drone discovered at German airport: A drone fitted with professional explosives and a detonator was discovered at Leipzig/Halle Airport in August, prompting Germany’s federal prosecutor to investigate what it described as a serious attack on transport and logistics infrastructure.


  • Sydney Airport records fourth close call: Australian investigators are examining whether common factors contributed to four separate air-traffic incidents at Sydney Airport in less than a month. The latest involved two Qantas aircraft being directed towards the same taxiway intersection. 


  • UK derailment puts track condition under scrutiny: Investigators examining the August derailment near Lewes found that CCTV from earlier services already showed a track geometry irregularity before the train reached the site. Previous maintenance activity and reports of rough riding are also being examined. 


  • Dulles approves $19.9bn overhaul Washington Dulles International Airport approved a $19.9 billion modernisation programme covering terminal reconstruction, underground transport and major infrastructure upgrades. The programme will add or renovate around five million square feet of airport space. 


TECHNOLOGY HIGHLIGHT: THE DRONE THREAT JUST CHANGED


Drone flying above a city skyline with buildings visible beneath it.
Drones are becoming a more serious infrastructure security threat, increasing pressure on critical assets to strengthen detection, preparedness and coordinated response.

For years, drones around airports were primarily treated as a nuisance: dangerous, disruptive, and expensive, but usually discussed in terms of flight delays and unauthorised airspace incursions.


An explosive-equipped drone changes that calculation.


The device discovered at Leipzig/Halle Airport was fitted with professional explosives and a detonator. Germany’s Interior Minister described the incident as a new level of danger, while federal prosecutors opened an investigation into a suspected attack on national security. 


The European Commission had already recognised the changing threat when it published its Action Plan on Drone and Counter-Drone Security in February.


The plan includes multi-sensor detection, AI-supported systems, counter-drone capability for critical infrastructure, an EU incident platform, stress testing, and annual large-scale exercises. The Commission also announced €400 million of spending on drone and counter-drone technology


But technology alone cannot provide complete protection.


In August, E.ON CEO Leonhard Birnbaum said comprehensive protection of an entire energy grid against drones was unrealistic, pointing instead towards the importance of restoring supply rapidly when an attack occurs. 


That is an important shift in thinking.


Counter-drone resilience is not simply a question of buying a detector. It involves surveillance, communications, security teams, law enforcement, infrastructure operators, incident procedures, and decisions about what happens when a threat is identified.


INDUSTRY SPOTLIGHT: THE AIRPORT HAS BECOME A DIGITAL CITY


Passengers moving through Singapore Changi Airport, with digital displays, automated systems and modern terminal infrastructure visible.
Modern airports operate like digital cities, connecting passengers, security, communications, logistics and technology across one highly interdependent environment.

An airport is no longer simply a terminal, runway, and control tower.


Modern airports combine passenger processing, border systems, baggage handling, communications, payments, access control, surveillance, building management, airline technology, airside operations, logistics, and hundreds of third-party suppliers.


Increasingly, those systems depend on one another.


August demonstrated why that matters.


At Leipzig/Halle, an explosive-equipped drone triggered a federal security investigation. At Sydney Airport, investigators are examining repeated operational close calls. In Washington, Dulles approved almost $20 billion of infrastructure modernisation.


Different events, but each illustrates the complexity of keeping a modern airport secure and operational.


Technology spending is accelerating accordingly.


SITA’s latest Air Transport IT Insights found that the aviation industry invested a record $50.8 billion in technology during 2025. Among airports, 71% rank cybersecurity as their top overall IT focus area, while 68% cite it as the main driver of infrastructure upgrades.


AI is becoming part of that security environment too. SITA reports that 64% of airports are already applying AI in cybersecurity use cases, while 63% expect their overall IT spending to increase in 2026.


More technology, however, creates more dependencies.


A problem affecting identity can affect access. A communications outage can disrupt operations. A compromised third party can create a route into systems that appear protected internally. A physical security incident can rapidly become an operational technology problem.


Governance has to keep pace.


A July review by the US Government Accountability Office found that although the FAA and TSA collaborate on aviation cybersecurity, the TSA’s cybersecurity roadmap was outdated and did not clearly define responsibilities for overseeing airport and aircraft-operator cybersecurity programmes.


For airport operators, three priorities stand out:


Create one operational view


Security, technology, and operations teams need to understand the same dependencies rather than maintaining separate pictures of the airport.


Design for disruption


Critical passenger, safety, communications, and security functions need tested fallback arrangements when primary infrastructure becomes unavailable.


Clarify ownership


Where airlines, airports, authorities, contractors and technology suppliers share systems, responsibility for failure and recovery needs to be explicit before an incident occurs.


The airport of the future will be more automated, more connected, and more data-driven.


Its resilience will depend on whether all of those systems can still work together when conditions deteriorate.


GLOBAL DEPLOYMENT IN ACTION: FROM ASSESSMENT TO ACTION


Engineer working with technical equipment at an outdoor infrastructure site in Nigeria.
Effective risk management starts on the ground, combining local knowledge, engineering capability and ongoing support to turn assessment into practical action.

Complex operating environments rarely present one isolated problem.


A physical security weakness can expose technology. A poorly configured network can compromise an otherwise secure asset. A procedural gap can bypass both.


In higher-risk markets, an organisation may also need local security, logistics, insurance support, and engineers capable of reaching the site.


YAVA’s delivery model is designed to bring those requirements together.


Start with what is happening


YAVA’s Risk Intelligence approach combines remote review with engineers attending the asset in person.


The assessment examines three connected layers: external and physical controls, internal technology including IT and OT, and human procedures.


Findings are supported by evidence, scored, and translated into a prioritised remediation plan.


The objective is practical visibility: What works? What does not? What needs to be fixed first?


Add operational capability


Through our partnership with SF Group, YAVA can combine technical capability with physical security, risk management and field operations in complex and higher-risk environments.


SF Group brings operational security and in-region capability. YAVA brings technology assessment, cyber, software, systems integration and infrastructure support.


Together, the two organisations can approach physical and digital security as parts of the same operating environment rather than separate workstreams. 


Connect risk with insurance


Through our partnership with Compass Point Assist, that model can also connect on-site assessment and practical risk improvement with insurance advice, risk placement support and insurer engagement.


Compass Point Assist helps clients and insurers identify where stronger evidence and controls are required. YAVA can then inspect the asset, identify weaknesses, and deliver the technical or engineering improvements.


The partnership can be used for a single high-value asset, a portfolio review, or an ongoing programme covering assessment, remediation, monitoring, and reassessment.


Stay with the asset


The objective is not another report that sits on a shelf.


Weaknesses identified through assessment need to be corrected. Systems need to be maintained. Changes in the operating environment need to be reflected in the risk picture.


That becomes particularly important across remote or difficult-to-assess portfolios, where the reality at an asset can change faster than central policies, questionnaires or annual reviews.


One engagement can move from visibility to action: assess the exposure, bring in the capability required, remediate the weakness, and keep the asset under review.


LOOKING AHEAD: THE NEXT DISRUPTION WILL EXPOSE WHAT WAS NEVER TESTED


Electricity pylons and power lines extending through a misty UK landscape at dawn.
Resilience is measured by what continues working when primary systems fail. Tested fallback arrangements and clear ownership become critical when disruption arrives.

August brought together several developments that are likely to shape the remainder of 2026.


Cyber activity is reaching operational infrastructure. Drones are moving further into the civilian security threat picture. Energy infrastructure remains exposed to conflict and sabotage. Airports are investing heavily in increasingly interconnected systems.


Governments and operators are consequently being forced to think less about whether disruption can be prevented entirely and more about what continues operating when prevention fails.


For leaders responsible for critical or high-value assets, four questions are becoming increasingly important:


Which functions absolutely have to continue?


Organisations need to distinguish between systems that are important and processes whose failure would immediately affect safety, revenue, security, or essential operations.


What do those functions depend on?


Networks, cloud platforms, power, communications, suppliers, staff access, and physical systems create dependencies that can remain invisible until one disappears.


Have fallback arrangements actually been tested?


A backup, generator, secondary connection, or manual procedure provides limited reassurance if nobody knows whether it works.


Who owns recovery?


Complex infrastructure frequently involves multiple suppliers, authorities, and internal teams. An incident is a poor time to discover that responsibility sits somewhere between them.


The direction of travel is clear.


Resilience will increasingly be judged through operational performance under pressure, rather than policies, architecture diagrams, or statements of preparedness.


Organisations that understand their dependencies, test what happens when systems fail and maintain practical delivery capability close to the asset will be better positioned for the next disruption, because the next crisis is unlikely to expose the control an organisation knows is missing.


It will expose the one everyone assumed was working.


EVENTS CALENDAR


Africa’s aerospace and defence exhibition brings together government, military, aviation and technology stakeholders across air, land and sea capability. 


International Security Expo brings together security and resilience professionals working across critical national infrastructure, counter-terrorism, physical security and cybersecurity. 



Reuters NEXT Gulf returns to Abu Dhabi with discussions spanning geopolitics, markets, finance, technology, AI and corporate leadership as the Gulf expands its role in global investment and advanced industry. 



GITEX GLOBAL moves to Expo City Dubai for 2026, bringing AI, cybersecurity, connectivity, data centres, physical AI, advanced manufacturing, and government technology together at its new venue. 

Comments


bottom of page