Cyberattacks are consistently ranked among the greatest threats to our society, alongside pandemics and extreme weather. Attacks on power grids, hospitals and public authorities are no longer hypothetical: they are daily operations, frequently state-sponsored, and they have been described as the new strategic weapons.
For most organisations that framing is unhelpful, because it does not say what to do differently on Monday. This page is about the part of the problem that ordinary IT security cannot reach.
What has actually changed
Opportunistic crime is still the volume, but the attacks that matter for critical infrastructure are patient, funded and specific. An actor prepared to spend a year inside a network is not deterred by measures designed to raise the cost of a quick attempt.
Control systems that were designed on the assumption of physical isolation have been connected – for remote monitoring, for efficiency, for perfectly good operational reasons. The assumption they were built on quietly stopped being true, and the equipment lifecycle in that world is measured in decades, so it will remain untrue for a long time.
Software-defined radio moved the cost of a capable receiver from specialist laboratory equipment to a few hundred euros. Reconstructing information from a device’s electromagnetic emissions still requires skill and proximity, but the group of actors who can do it has grown well beyond state intelligence services. TEMPEST and RÖS covers that attack in detail.
Compromising one supplier to reach hundreds of customers is now an established pattern rather than a theoretical concern. Where the hardware was designed and built, and who could touch it on the way, has become a security question rather than a procurement preference.
Why software defences are necessary but insufficient
Firewalls, endpoint detection, segmentation and patching are all essential, and none of this argues against them. But they share one property: they are software, and software can be misconfigured, bypassed or exploited.
That is acceptable for most systems. It is not acceptable for the small number where compromise would be unrecoverable – a grid control system, a classified network, an evidence chain. For those, security should not depend on a configuration being correct every day for a decade. It should be physical:
- A data diode cannot be reconfigured to let traffic back in. There is no configuration.
- A TEMPEST-certified workstation does not emit signals worth intercepting, whatever software is running on it.
- A fiber optic link offers no galvanic path and cannot be tapped inductively without detectable loss.
The common property is that the guarantee survives an administrator’s mistake, an unpatched vulnerability and an attacker already inside the adjacent network.
What large organisations should do
Identify the systems where compromise is unacceptable. Not the important systems – the ones where recovery is not a realistic plan. In most organisations this is a short list, and it is worth the argument required to make it short. Protection that is applied everywhere is applied thinly.
Separate them physically from general IT, with one-way transfer where data must flow out. This is the step that most often turns out to be simpler than expected: the flows that genuinely need to cross the boundary are usually logs, telemetry and reports, and all of those travel one way natively.
Certify the workplaces that handle the most sensitive information against compromising emanations, matched to the environment rather than to the classification. The certification levels explain how that choice is made.
Ask where equipment is designed, where it is manufactured, and who can modify it in between. Require the answer in the tender rather than discovering it afterwards – procurement support covers how to word it.
The purpose of a physical control is that it holds when the assumptions around it fail. Design so that a compromise on one side of it is survivable, and verify that assumption occasionally rather than trusting the diagram.
A note on proportion
Not every organisation needs TEMPEST-certified equipment, and it does no one any good to suggest otherwise. Emanation security becomes relevant when three things are true together: the information is valuable enough for a capable actor to invest in collecting it, that actor can get physically close, and disclosure would be serious.
If those three do not hold, ordinary information security is the right investment and this equipment is not. If they do hold, no amount of ordinary information security addresses the channel in question.
Fibersystem has supported the Swedish Total Defence with this layered approach for over 40 years. The same protection is available to enterprises and to operators of critical infrastructure, and the first conversation is usually about which of your systems belong on the short list.




