Underfunded cybersecurity in critical infrastructure

Underfunding

If you ever wondered what keeps a modern city upright and not descending into a howling medieval mess, the answer is simple: a stack of creaking infrastructure systems held together by ancient protocols, budget cuts, and engineers who have been told since birth that taking anything offline is a sin punishable by eternal paperwork.

Imagine the Ankh-Morpork power grid. Imagine the pipes under the Shades. Imagine the rail system during peak hour. Now imagine trying to secure all of that with thirty years of overdue updates and a budget that would not stretch to a tray of Klatchian coffee. Energy grids, water utilities, and transport networks share much the same affliction: old systems, flat networks, and a proud tradition of shouting availability first whenever the word security wanders too close. Upgrade cycles move at the speed of a hungover troll. Vulnerabilities gather dust. Attackers gather interest.

The infrastructure under the pavement

There is an entire underworld of pipes, wires, signals and pumps that few think about until it stops working. Much of it was built by engineers who understand electricity and pressure but regard cyber threats as impolite rumours, in an age when a network was a tangle of serial cables and remote access meant leaning in from across the table. Beneath the blinking lights sit protocols that practically deserve heritage plaques: SCADA systems from a period when security meant keeping the dog in the courtyard, Modbus from 1979, still cleartext, still blissfully unaware that adversaries exist. None of this was bad design. It was design for a world where an attacker had to physically break in, and that world has since acquired laptops. The systems were networked for efficiency and remote monitoring; security was not invited along, because improvements cost money and downtime, both of which make managers pale and shaky.

Availability first, security maybe later

Operations engineers worship uptime, patching threatens uptime, and therefore patching is suspicious. A typical conversation:

Security: Patch this or attackers will break in.
Operations: Rebooting causes outage.
Security: Only fifteen minutes.
Operations: Out of the question. Next maintenance window is months away.
Security: But attackers are actively exploiting this.
Operations: Have they exploited us?
Security: Not yet.
Operations: Good enough.

This is not malice; it is incentives. Uptime is measurable and prevented attacks are invisible, so change becomes the enemy and vulnerabilities become interesting footnotes. Segmentation is possible but fiddly, and often vetoed in case a firewall adds milliseconds, so what counts as segmentation may be a single VLAN, firewall rules written by someone who left five years ago, and a diagram that insists on separation while reality chuckles behind it.

The certification straitjacket

Equipment in critical infrastructure can last forty years. Vendors vanish, firmware updates never existed, and safety certification freezes systems in time while security requires constant change. When a certified system gains a critical vulnerability, a patch may exist, but installing it invalidates the certification, leaving a choice between breaking the rules and staying insecure. Guess which one wins. Hence the frequent decision to write the risk down in a report and then heroically ignore it, and hence controllers installed decades ago still running because replacement would cost millions and an outage long enough to get politicians involved. Boards do not fund invisible improvements.

The maintenance budget fiction

Physical maintenance is grudgingly funded; digital maintenance is often treated like decorative shrubbery. Capital expenditure buys new kit and gets money. Security lives in operational expenditure, which is invisible and therefore cut, until a crisis happens and emergency budgets appear like mushrooms after rain. Afterwards everyone vows to learn lessons, then forgets. Private operators often underfund because security eats into profits; public ones because voters prefer shiny projects to boring necessities. Meanwhile the real incidents often begin not with hostile states but with a bored engineer and a USB stick, because the approved process involves seventeen forms and a blood sacrifice. Everyone knows the infrastructure is vulnerable. Reports are written, conferences held, heads nodded. Knowing is easy. Doing is ruinously expensive. Until something breaks loudly enough, the edifice runs on inertia and the optimistic assumption that attackers are busy bothering someone else.

The clerk’s brief

From the clerks, for the Patrician’s eyes

Compiled July 2026. Newest first, as ever; the long patterns settle into the running account at the end. The clerks would like it minuted that every figure below was available to every budget committee that declined to read it.

October 2025: The year counted, and the count is not flattering

The ENISA Threat Landscape 2025, published October 2025, analysed 4,875 incidents between July 2024 and June 2025: DDoS dominated at 77 per cent of reported incidents, while ransomware accounted for 81.1 per cent of cybercrime incidents against EU organisations and remained the most financially damaging threat, with energy, transport, and manufacturing among the targets of state-aligned activity. The sectors least able to afford downtime remain the sectors attackers find most persuasive to visit, which the clerks note is not a coincidence but a business model.

July 2025: The price of a breach, unevenly distributed

IBM’s Cost of a Data Breach report, published July 2025, put the global average at 4.44 million dollars, with Germany at 3.87 million euros and the UK at £3.29 million. The averages fell where security automation was deployed; breaches involving legacy systems and unpatched vulnerabilities consistently exceeded them, and legacy environments frequently lack the integration points that automation needs. The saving, in other words, went to those who had already spent, which is the kind of joke the clerks suspect only accountants find funny.

February 2025: The budget that eats itself

Software Improvement Group’s analysis, published February 2025 and drawing on McKinsey research, estimates that around 40 per cent of an IT budget is absorbed dealing with the fallout of technical debt, that 10 to 20 per cent of budgets earmarked for new development are quietly redirected to servicing it, and that a typical stack is 20 to 40 per cent pure debt. The money for security improvements is not so much refused as pre-spent. The clerks have checked the arithmetic and regret to confirm it.

January 2025: Every organisation profiled says the same sentence

The UK’s State of digital government review, published January 2025, records that every organisation profiled cited insufficient funding to manage legacy technology and technical debt, while critical services depend on decades-old systems whose scale is not even consistently measured. When the operators of essential services agree unanimously on anything, the clerks consider it worth writing down. This is the only sentence on which they agree unanimously.

The running account

The funding pattern has not moved in years: security sits in operational expenditure, operational expenditure is what gets cut, and emergency money arrives only after an incident, at emergency prices. The measurements now exist, since January 2025 in the UK’s official reviews, since February 2025 in the budget analyses, and since October 2025 in ENISA’s incident counts, and they all point the same way: the debt is being serviced out of the budgets meant to retire it. The regulatory response, chronicled in the regulatory file, obliges the same underfunded operators to do more with the same money. The clerks’ standing assessment is unchanged: budgets will materialise after something breaks loudly enough, and the only open question in the file is what, and when, and who is standing under it.