Cyber-physical risk poses a life safety threat. That was the impetus for the Cyber Safety Summit held on June 10th at the National Academy of Sciences in Washington, D.C. But a life-safety issue needs an accountable party, and the summit’s sessions made clear that none currently exists. Panels of experts addressed the inevitable question: who is professionally and legally accountable when a connected physical system is compromised and what is the cyber safety standard of care? There is currently no recognized engineer of record for cyber-physical risk, and a growing number of engineers, insurers and policymakers are debating whether the answer is a new discipline: cyber safety engineering.

Cyber Safety Engineering Is Following An Old Pattern

As described in the summit’s strategy framework, engineering standards of care have historically been built only reactively. They have followed a consistent sequence: a hazard is identified, people are harmed, the profession organizes and a standard is codified – often after insurers, regulators and public outcry force the issue following a tragedy. In the mid-1800s, fatal boiler explosions across America occurred almost every four days until a novel insurance product linked to quality inspection was established, eventually leading to the development of the American Society of Mechanical Engineers boiler and pressure vessel code. The Great Chicago Fire killed roughly 300 people and destroyed 17,000 buildings, leading to building fire codes. The collapse of the Quebec Bridge in 1907, which killed 75 ironworkers due to a calculation error and engineering inexperience, helped establish the professional engineer as a guardian of public safety. Wyoming passed the first engineering licensure law in 1907, and other states quickly followed.

John Kliem, director of federal strategy at Johnson Controls, expressed his concern about following this pattern. “What scares me, is are we going to have to have a Pearl Harbor-level cybersecurity event to have more visibility?” he asked. Brian May, president of federal programs at Michael Baker International, agreed. “If a single incident causes a mass casualty event, our profession will be scrambling to develop standards under duress,” he said. “I believe we must start thoughtfully working this problem now, before we’re forced to account for a preventable catastrophe.”

Cyber-physical systems present the same conditions that drove every prior standard: foreseeable hazards, repeatable failure modes and potentially catastrophic consequences. The 2021 Colonial Pipeline attack, in which ransomware seized monitoring and billing systems connected to physical valves and meters, is one recent example. State-sponsored intrusions into U.S. infrastructure are ongoing. The open question is whether cyber safety engineering follows the historical pattern and waits for a disaster, or whether the profession moves first.

The Engineering Profession Doesn’t Yet Own The Cyber Safety Risk

May asserted that the profession has reached a turning point. “Connected, smart technologies are present in nearly every new or retrofitted building system,” he said. “Practically speaking, engineers can no longer meet their professional obligation to deliver safe designs without considering and taking reasonable steps to mitigate cyber risk.” David Brearley of HDR noted that, in retrospect or in litigation after a cyber-physical incident, most parties would agree that the event was foreseeable. Yet no clear standards or accountability exist.

A gap in ownership was raised throughout the summit. Adam Gladsden, co-founder and CEO of construction insurer ConfigRisk, argued that the biggest risk issue is one of accountability and traceability. Adam Firestone, CEO of the quantum-secure communication platform SIX3RO, emphasized that the absence of a dedicated cybersecurity engineer requires decisive action. “We need to start saying that we will not be able to deliver unless we include a dedicated cybersecurity engineer,” he said. “That is one of the biggest things we can do for the engineering profession.”

The Case For A Cyber Safety Engineering License

Advocates of specialty licensure assert that it is necessary for cyber safety engineering to function as a professional discipline rather than an informal best practice. Summit organizer and Building Cyber Security CEO Lucian Niemeyer offered two options: create a 25th professional engineering discipline or include cyber safety in the existing control systems professional engineer license. His concern with a standalone license is the time it will take to establish. Students could spend four years completing an engineering degree in a new field without a clear licensure path waiting for them at the end.

The National Council of Examiners for Engineering and Surveying administers the P.E. licensing exams used across states. The existing control systems P.E. exam already includes a security-focused section that covers access controls, risk assessment and verification of security levels. Summit organizers are proposing specific additions to that section, including consequence-based classification for connected physical systems, a required technology registry documenting connected systems throughout a project’s lifecycle and formal cyber commissioning as a condition of project acceptance. A joint formal proposal by the National Academy of Engineering, National Academy of Construction, United Engineering Foundation and Building Cyber Security is targeted for submission to NCEES by October 2026, positioning cyber safety engineering as a near-term addition to an existing exam while continuing to work on state licensure recognition. This is the first of seven phases recommended in the strategy framework through 2033.

Would A Cyber Safety Engineering Credential Attract Enough Demand?

Even with a licensure pathway, a new cyber safety engineering discipline will only take hold if there is market demand, professional society guidance, and insurance ecosystem support. Firestone said the engineering industry currently isn’t doing enough demand-generation work – employers who require cyber safety professionals and career paths that reward it – and needs to work directly with employers to create that pull rather than assuming it will materialize on its own.

Niemeyer pointed to Building Cyber Security’s challenges in getting facility owners to care about the operational technology threat. Other safety issues such as electrical grounding or fire protection are assumed to be included in facility design and construction without owners stating them as required, he said, noting that this is not the case with cyber threats.

In the meantime, student demand is emerging. Matthew Jablonski of George Mason University pointed to the school’s cybersecurity engineering major, founded in 2015, as one of its fastest-growing programs. He said that industry demand was part of Virginia’s State Council of Higher Education’s approval process for the department to offer it as a distinct major. Given how quickly the cybersecurity field evolves, Brian Correia of the SANS Institute recommended that schools employ adjunct professors who are active in industry to keep curricula up to date.

And then there is the ethical obligation of engineers. When asked by Niemeyer what he would ask of engineering deans if he could, Acting Director of the Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency Nick Anderson said, “we have the guilty knowledge of what the risk and potential threat are. Will you be able to look your family in the eye and explain to them why you knew this was a possibility and did nothing about it?”

Cyber Safety Engineering Remains An Open Governance Question

The Cyber Safety Summit defined the framework for cyber safety engineering through legal and code compliance, consensus technical standards, professional duty of care and insurance enforcement. It includes a distributed set of obligations across engineers, owners, vendors and insurers, each carrying what the summit’s working framework calls “proportionate responsibility” for protecting human life, safety and health. Whether that framework becomes a licensed engineering discipline, and how quickly, remains an open question for the profession, its regulators, industry and the insurers who ultimately price the risk.

Did you enjoy this story on cyber safety engineering? Don’t miss my next one: use the blue “follow” button at the top of the article near my byline to follow my work, and check out my other columns here.

Share.
Leave A Reply

Exit mobile version