Digital

Why cybersecurity must be built in from day one

Written byOlivia Tempest
13 min read
Why cybersecurity must be built in from day one

As cyber threats become an ever-growing concern in the industrial sector, the importance of integrating cybersecurity early into the design and construction phases of critical infrastructure projects has never been clearer. Black & Veatch’s latest report, in partnership with Takepoint Research, titled: Secure by Design: A Market-Informed Guide to Cybersecurity for New Critical Infrastructure, sheds light on why “secure by design” is essential for modern capital projects and how its delay in implementation can lead to substantial long-term operational and financial risks.

The report, based on a survey of 451 global professionals involved in industrial projects, paints a compelling picture of the current state of cybersecurity integration

The report, based on a survey of 451 global professionals involved in industrial projects, paints a compelling picture of the current state of cybersecurity integration. Despite widespread acknowledgement of the need for early adoption, the research reveals that cybersecurity is often introduced too late in the project lifecycle. In fact, 72% of respondents indicated that cybersecurity requirements are either incorporated late or not at all during the design and build stages of new infrastructure projects. The consequences of such delays can be far-reaching, affecting everything from system performance to long-term operational costs and security posture.

One of the key insights from the report is that cybersecurity should no longer be considered a mere add-on to infrastructure projects. Instead, it must be integrated from the start. Decisions made early in a project, during the concept and feasibility stages, play a pivotal role in determining the project’s security outcomes. From defining the system’s architecture to establishing connectivity and trust boundaries, early-stage decisions shape the entire risk landscape of the asset. Unfortunately, when cybersecurity is only considered after these decisions are locked in, organisations are left with the costly and often inefficient task of retrofitting security measures.

The study found that organisations that integrate cybersecurity early see measurable benefits, including reduced downtime and enhanced operational resilience

The study found that organisations that integrate cybersecurity early see measurable benefits, including reduced downtime and enhanced operational resilience. Notably, 78% of survey respondents linked early cybersecurity adoption to fewer disruptions, while 62% saw a reduction in long-term operational risk. Early integration allows organisations to design more secure and flexible systems, which are easier to maintain and adapt to emerging cyber threats. When cybersecurity is embedded into the design process, it is far more effective and less costly than when it is retrofitted later in the project lifecycle.

Despite these clear benefits, the report reveals that many organisations struggle to implement “secure by design” principles. The challenges are not rooted in a lack of awareness of cybersecurity’s importance, but rather in the structural barriers within organisations. One of the primary issues is a disconnect between the project teams responsible for the design and build of infrastructure and the operations teams who will manage the assets once they are live. This division often leads to cybersecurity being treated as an afterthought, to be addressed only after the system has been delivered.

Moreover, the report highlights a lack of clear ownership of cybersecurity responsibilities, with 68% of respondents citing unclear accountability as a key breakdown in the process. In many cases, cybersecurity is seen as a responsibility that can be passed off to someone else, such as the engineering teams, procurement, or the asset owners. This fragmentation often results in the implementation of security measures that are inconsistent or delayed, leaving critical vulnerabilities exposed.

Another pointed barrier to early cybersecurity integration is the way that organisations govern capital projects. Project teams are often incentivised to deliver on time and within budget, with little regard for the long-term risks associated with delayed cybersecurity implementation. In contrast, the benefits of early cybersecurity, reduced downtime, improved safety, and lower long-term operational costs, are realised only after the project is completed, and these benefits are not directly tied to the project’s immediate success metrics. This misalignment of incentives often leads to cybersecurity being deprioritised during the design and build phases, with its integration delayed until later stages when it becomes more costly and difficult to implement effectively.

To address these issues, the report offers a practical roadmap for organisations looking to implement “secure by design” practices. This roadmap is designed to help organisations shift from a reactive, late-stage approach to a proactive, integrated model of cybersecurity. The roadmap outlines four key phases: alignment, foundation, integration, and scale.

The report reveals that many organisations struggle to implement “secure by design” principles

Another pointed barrier to early cybersecurity integration is the way that organisations govern capital projects. Project teams are often incentivised to deliver on time and within budget, with little regard for the long-term risks associated with delayed cybersecurity implementation. In contrast, the benefits of early cybersecurity, reduced downtime, improved safety, and lower long-term operational costs, are realised only after the project is completed, and these benefits are not directly tied to the project’s immediate success metrics. This misalignment of incentives often leads to cybersecurity being deprioritised during the design and build phases, with its integration delayed until later stages when it becomes more costly and difficult to implement effectively.

To address these issues, the report offers a practical roadmap for organisations looking to implement “secure by design” practices. This roadmap is designed to help organisations shift from a reactive, late-stage approach to a proactive, integrated model of cybersecurity. The roadmap outlines four key phases: alignment, foundation, integration, and scale.

The first phase, alignment, focuses on establishing clear ownership, defining roles and responsibilities, and ensuring that cybersecurity is recognised as a key consideration in the capital planning and approval processes. This phase should take place within the first three months of the project and requires executive-level buy-in to ensure that cybersecurity is treated as an integral part of the project’s scope from the outset.

The second phase, foundation, begins to translate cybersecurity principles into actionable project deliverables. During this phase, organisations should focus on embedding cybersecurity requirements into the project’s design documentation, contracts, and procurement processes. This phase also includes developing risk narratives and cost comparisons to help stakeholders understand the long-term value of integrating cybersecurity early.

The third phase, integration, focuses on embedding cybersecurity into active capital projects. During this phase, organisations should track early lifecycle key performance indicators (KPIs) and expand training for project teams and external partners. This phase also includes ensuring that cybersecurity acceptance testing is performed during Factory Acceptance Testing (FAT) and Site Acceptance Testing (SAT).

The final phase, scale, involves institutionalising “secure by design” across the project portfolio. By this stage, cybersecurity should be embedded into the organisation’s standard operating procedures and become a consistent part of the capital delivery process.

While regulatory pressures and industry standards are pushing organisations to adopt cybersecurity measures earlier in the project lifecycle, the report emphasises that the strongest driver for early integration is a demonstrated business case. Survey respondents identified cost avoidance, reduced downtime, and improved resilience as the most compelling reasons for adopting cybersecurity early. In fact, 76% of respondents indicated that the business case for cybersecurity was the most important factor in securing leadership buy-in.

By evaluating cybersecurity as a total cost of ownership (TCO) rather than a project-specific expense, organisations can make more informed decisions about when and how to integrate security measures. This approach allows companies to compare the cost of early integration with the cost of retrofitting cybersecurity later, including the long-term operational risks and potential downtime associated with retrofitting.

Cyber risk is compounding as systems become more interconnected and interdependent, and the findings from Black & Veatch’s 2026 cybersecurity report make it clear that integrating cybersecurity early into critical infrastructure projects not only reduces risk and cost but also enhances the resilience and operational efficiency of these assets over their lifecycle. Organisations that embrace the “secure by design” approach are not only ensuring that their assets are better protected from cyber threats but are also positioning themselves for long-term success in an increasingly complex and interconnected world. The time to act is now, and the path forward is clear: cybersecurity must be integrated from the start, not as an afterthought.

Follow us on Google Discover