It’s not news that the life-security critical functions on which our nation relies are under threat. With the evolving geopolitical landscape, that threat is escalating. And with the advent of AI, that threat is accelerating. The foundations of our health and safety are fragile and under duress. Those defending on the frontlines of our critical infrastructure are often “cyber-poor” – lacking in incentives, information, or resources. They need help.
The Institute for Security and Technology has convened volunteers from across OT/ICS, critical infrastructure, cybersecurity, AI, engineering, cyber policy and various other fields to respond to this need.
The Fragile Foundations Sprint launched on September 3rd, 2026 to help life security critical services become more resilient to cyber and AI-related threats. Over a 100-day sprint, we are examining and addressing how the emergence of AI compounds the existing resources and cyber capabilities challenges imperiling many small-to-medium or rural critical infrastructure operators. The foundational importance of these operators makes them extremely desirable targets for politically-motivated attackers.
Fragile Foundations will operate as a focused collaborative sprint effort until December 10th, 2026. It will then publish its findings, recommendations, and various tooling developed to support continued effort in the fight against AI cyber disruption to cyber-poor life-safety critical functions.
To learn more about the initiative, you can watch the Kick-Off or review the slides.
To get involved, register your interest in our working groups. More information below.
If you would like to donate to support this project, please contribute via the GiveLively platform on our donate page or get in touch with [email protected].
"Effective solutions for resilience will often come from non-cyber-oriented approaches. As such and in order to maintain public safety, it is essential that those with AI, cybersecurity, cyber policy and engineering expertise collaborate effectively with the people literally keeping the lights on (not to mention water, healthcare, emergency services, etc!)."
Jen Ellis MBE
Life-Safety Critical Functions
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has identified 55 ‘National Critical Functions’ (NCFs), which it defines as:
“The functions of government and the private sector so vital to the United States that their disruption, corruption, or dysfunction would have a debilitating effect on security, national economic security, national public health or safety, or any combination thereof.”
Of these, we consider a far narrower subset to be truly essential and foundational to directly maintaining human health and safety. We term these ‘Life-Safety Critical Functions” or LSCFs.
To launch the Fragile Foundations Sprint, we have identified the following functions as the most immediately critical to life-safety:
- Generate, distribute, and transmit electricity
- Supply water and manage wastewater
- Provide medical care and maintain access to medical records
- Provide public safety
- Prepare for and manage emergencies
- Produce and provide human and animal food products and services
- Transport Cargo and Passengers by Rail
- Transport Materials by Pipeline
- Provide Wireline Access Network Services; provide Internet Routing, Access, and Connection Services
Please note, the work of the Consequences Analysis Working Group may result in this list being updated.
Fragile Foundations Working Groups
The Fragile Foundations Sprint will create change through five active working groups, detailed on this page. If you would like to join one (or more) of these groups to help protect our cyber-poor life-safety critical functions, please register your interest.
If you are a life-safety critical function operator and would be interested in speaking with us, we want to hear from you! Please reach out to us or request to join our Slack channel, and consider joining one or more of the sprint efforts.
Consequences Analysis
When everything is critical, nothing is critical. This group will examine which US National Critical Functions are most consequential when disrupted (esp life-safety), how the disruption of these critical functions affects other dependent critical functions (2nd & 3rd order effects), which are most vulnerable, and which are typically least resourced. Once identified, it should assess/characterize the relative preparedness of each responsible sector’s public-private-partnership – as well as headwinds and tailwinds to improving resilience. Lastly, it will make recommendations for preventing and/or responding to the domino effects of disruption and restoring service as quickly, efficiently, and effectively as possible.
Target Deliverables of the Consequences Analysis Working Group:
- Detailed write up of the WG process and findings, including focus areas, decision-making factors, and response recommendations.
- A list of the most consequential NCF disruptions on their own.
- Mappings of which NCFs depend upon each other, revealing/suggesting.
- Prioritised risk map for our highest priority NCFs for resilience/recovery efforts.
This effort will be led by Mark Montgomery and Éireann Leverett.
The Kick-Off call for this group takes place on Friday, September 4th, 09:00 ET/ 06:00 PT (sorry to those on the West Coast!). Request an invite.
OT/ICS Sector Engagement
This group will identify and engage with major OT/ICS suppliers, smaller-but-vital sector-specific systemically-important entities (SIE), system integrators and key service providers, and will determine where there are gaps in engagement or support for cyber poor operators in critical sectors. It will evaluate how ready and suitable the sector is to truly assess and respond to the needs of the cyber-poor – as opposed to the better-funded ends of the market. It will drill down into specific aspects of support/engagement that may add extra friction or offer resilience benefits, for example, considerations around legacy and entrenched tech debt, exploring whether AI will only worsen gaps or could also offer potential solutions, and examining whether SBOMs can be meaningfully adopted for impact analysis from a larger volume of CVE and exploits. Aimed at the highest consequence communities, the group will also propose options for better supporting the most at-risk customers (e.g. Cash for Clunkers to replace/update unsupported tech with patchable tech… e.g. prioritizing assistance/response/simulations).
Target Deliverables of the OT/ICS Sector Engagement Working Group:
- Initial inventory of important cross-sector suppliers most depended upon across the most consequential national critical functions.
- Initial sector-specific, smaller-but-vital suppliers, systems integrators and service providers for each of the priority NCFs.
- Wish-lists for how frontier models can help the suppliers.
- Detailed summary of analysis including discussion of incentives, challenges, and current status.
- Craft realistic requests and offers for best supporting at-risk operators.
- Draft ecosystem map/visualization.
- Suggest inputs for Policy & Incentives Design and Pragmatic Guidance (and possible omissions to Consequence Analysis).
This effort will be led by Alison King and Mike Holcomb.
The Kick-Off call for this group takes place on Friday, September 4th 11:00 ET / 08:00 PT. Request an invite.
Pragmatic Guidance for Cyber-Poor Operators
We need to resist the instinct to bring F2000 Enterprise IT confidentiality advice to the cyber-poor operators of OT/ICS who need availability of life-safety services. Meet people where they are – and help them to be more resilient within that context. It may be that the internet has become too dangerous: if you can’t protect it, disconnect it. There may be no going back: so the best guidance may be to run a “Day Without Internet” manual downtime drill. It is less likely about adding cyber, but rather adding engineering or removing complexity or connectivity. This group will explore the realities of cyber-poor LSCF environments and develop realistic, pragmatic, actionable, jargon-free guidance for operators that lack access or suitability for standard cybersecurity recommendations. These organizations are unlikely to deploy AI-powered defenses. The group will need to assess which guidance is broadly applicable cross-sector, and which is specific to the priority NCFs. There may be multiple sets of guidance developed, depending on timing and focus of the group. Some of the help can be “top 3 questions for your: Equipment vendors, System Integrators, Insurers, etc.” Model Contract addendums might be a useful input to Policy and Incentives Design.
Target Deliverables of the Pragmatic Guidance Working Group:
- Suggest top-line strategies about unsound dependence (e.g. Less connected / “Day without Internet” exercise).
- Segmented or cross-sector guidance(s) – leaning towards talent pools and resources (e.g. engineering).
- Produce “N Critical Questions for your (Suppliers, Integrators, Insurers, etc).”
- Craft prioritized resources lists (like CI Fortify, INL CIE, “free” help, sector specific SRMA guidance – maybe crawl, walk, run in phases toward initial cyber guidance after resilience goals met – like CISA CPGs, free cyber-help, etc.). These will be indicators, but not exhaustive given time limitations and sector specifics.
- Documentation of analysis and decision-making processes.
- This group will also deliver a glossary / mapping of terms in partnership with the other working groups.
This effort will be led by Whitney Bowman-Zatzkin and Samara Moore.
The Kick-Off call for this group takes place on Friday, September 4th 12:00 ET/ 09:00 PT. Request an invite.
Novel Mitigation Analysis
It took us decades to slowly create these dangerous dependencies and exposures, but we will have a fraction as much time to adapt to AI and become more resilient. Bold, novel thinking is required. Fresh solutions must be lawful, ethical, safe, effective, fast, and fit for purpose. For example, BrickerBot was breaking reachable busybox without recognising that many medical devices run busybox. Since the advent of AI, we frequently hear proclamations of the death or irrelevance of various security practices. This group will surface and evaluate alternative or novel mitigation strategies proposed for mitigating harms under the growing volume, variety, and velocity of AI-era disruptions. The group must embrace unconventional thinking for problem solving in unresourced and mission-critical environments. Some potentially dangerous ideas are being whispered. Perhaps better alternatives can be surfaced. The group will develop a framework for evaluating the practical application and viability of these novel mitigation strategies, which may vary by sector or other organizational factors. The framework will be used to prioritize recommendations. Sample attributes to be assessed could include: legal, ethical, effectiveness, scalability, speed, proven track record, and where authority sits. You could also consider whether there are “Break glass” pre-conditions or the potential for collateral damage. One hope is that by exploring and assessing existing ideas, we may catalyze or surface more and better ideas.
Target Deliverables of the Novel Mitigations Analysis Working Group:
- Document analysis and decision-making process. Cite third party proposals for unconventional mitigations as well as the group’s own suggestions.
- Create an initial list of novel mitigations – scored against your analytical/viability framework.
- Include recommendations to Policy and Incentives WG to support the adoption of the most pragmatic and suitable mitigations.
This effort will be led by Michael Daniel and Art Manion.
The Kick-Off call for this group takes place on Friday, September 4th 13:00 ET/ 10:00 PT. Request an invite.
Policy and Incentives Design
Most of the cyber advice policymakers receive comes from IT security vendors and F2000 enterprises solving for the confidentiality of data. The needs and constraints of foundational life-safety critical functions differ greatly. This needs to be clear to policymakers if we are going to adapt and build resilience to AI cyber-related threats in time – especially for the critical-but-under-resourced who must not be abandoned. This group will explore the realities and incentives across LSCF ecosystem stakeholders and document the factors driving barriers to adoption of resilience. The group will examine how different constraints (pricing, staffing, resources, supply chain, awareness, incentives) drive exposure, vulnerability and fragility across cyber-poor operators. The group will brainstorm public policy approaches to identify, realign or replace perverse incentives. They will consider the viability of approaches to restore resources or circumvent their lack. They will consider how best to equip policymakers and other leaders to take action on these issues. This group will collaborate with the other working groups to align recommendations that will accelerate adoption of mitigations and remove structural barriers. What are the OT/ICS life-safety critical functions “Do’s & Dont’s” for policy and incentives to truly improve our resilience?
Target Deliverables of the Policy and Incentives Design Working Group:
- Document the priority outcomes/equities that life-safety national critical functions need – especially resilience of under-resourced operators/industries.
- Analysis of misaligned and/or perverse incentives and barriers to adoption of resilience, and resulting recommendations for policy or other remediations (ensuring alignment with other WGs and addressing gaps).
- Legislative cheat-sheets and briefings; public and private evangelism of recommendations (in collaboration with IST).
- Target audiences can include local, state, federal and international legislators and regulators.Target Deliverables of the Novel Mitigations Analysis Working Group.
This effort will be led by Matt Hayden and Megan Samford. The Kick-Off call for this group took place on Thursday, September 3rd, 15:00 ET/ 12:00 PT.