CyberDefenseMagazine

Strengthening Cyber Resilience in Smart City Infrastructures: Practical Lessons from a Real-World Smart Parking Validation Pilot (CASPER)


Smart-city infrastructures extend beyond traditional IT systems by combining sensors, communication networks, cloud services, and citizen-facing applications into complex cyber-physical environments. Although these technologies support important urban services, they also create new attack surfaces, dependencies, and cybersecurity management challenges.

Cybersecurity incidents in such environments can disrupt services, reduce public trust, and affect the resilience of critical urban functions. In this context, CASPER examines how AI-enhanced cybersecurity capabilities can support risk management, operational visibility, threat detection, incident response, collaborative intelligence, and resilience in realistic smart-city conditions.

The INTEL ANN smart-parking environment provides a representative case for this work. Through this validation context, CASPER explores how integrated cybersecurity technologies can protect interconnected smart-city services while also producing lessons that are relevant to other urban infrastructures with similar technical and operational characteristics.

Smart parking infrastructures illustrate many of the cybersecurity challenges associated with modern urban digitalisation. Their operation depends on multiple interconnected components, including sensors, gateways, communication networks, cloud-based management systems, user interfaces, and services. As these environments become more interconnected, cyber incidents affecting one component may propagate across the wider operational ecosystem.

Traditional cybersecurity approaches often focus on individual security controls or isolated technology evaluations. Within CASPER, the validation activities show that operators of smart-city infrastructures increasingly require a broader understanding of how AI-enhanced cybersecurity capabilities perform under realistic operational conditions, particularly in relation to risk assessment, threat detection, incident response, interoperability, and operational resilience. Operators need to understand not only whether attacks can be detected, but also how incidents can be investigated, unfold, how evidence can be collected, and how decisions can be supported during real operational disruptions.

In CASPER, the validation followed an evidence-oriented approach based on realistic attack scenarios and controlled attack simulations in a smart-parking environment. The activities examined how CyberSecDome capabilities, including dynamic risk assessment, intrusion detection and prevention, automated security testing, incident management, investigation, collaborative intelligence, knowledge sharing, and situational awareness, worked together during attack-related conditions. This approach provided practical evidence on the applicability, operational value, and limitations of integrated AI-enhanced cybersecurity technologies for strengthening resilience in smart-city infrastructures.

In the CASPER validation process, eight (8) attack and stress scenarios were used to examine how the CyberSecDome capabilities reacted under different smart-parking threat conditions. These scenarios covered

  • network scanning,
  • brute-force,
  • login attempts,
  • SQL injection,
  • API flooding/resource-depletion attacks,
  • unauthorised API access,
  • SYN-flood,
  • LLM-based PCAP file obfuscation.

Together, these attacks represented different risks for the INTEL ANN smart-parking environment, from service disruption and abnormal traffic behaviour to unauthorised access, data manipulation, and reduced operational trust.

The validation process relied on controlled attack simulations, technical artifacts, and operational observations from the INTEL ANN smart-parking environment. This approach supported the successful assessment of the CyberSecDome capabilities under conditions closer to real smart-city operations than isolated laboratory testing. It also showed that cybersecurity resilience depends on the combined operation of risk assessment, monitoring, investigation, information sharing, and decision support, rather than on separate technical tools working independently.

Lesson 1: Asset Visibility Matters More Than Tool Capabilities

One of the main lessons learned from CASPER was that each cybersecurity tool becomes more useful when it is connected to a clear understanding of the operational environment. Dynamic risk assessment (DRA), intrusion detection and prevention(IDPS/IPS), automated securitytesting (ADAPT/DAIR), incident management (Prophecy/FVT) investigation (FVT/XAI), collaborative intelligence(Prophecy), knowledge sharing, and situational awareness tools (VR) depend on well-defined assets, data flows, dependencies, vulnerabilities, and attack scenarios. The validation showed that integrated tools can provide stronger operational value when their outputs are interpreted together, rather than assessed as separate technical results. In order to accomplish this and get accurate results a comprehensive asset inventory is necessary in order to better understand the infrastructure and feed that information to the relevant tools for accurate results. In the case of the CyberSecDome prototype the dynamic risk assessment tool was the heart of the integrations and everything started from that tool and the required input were the assets.

Lesson 2: Evidence-Oriented Validation Provides Better Cybersecurity Insights

Traditional cybersecurity testing often focuses on isolated technical metrics, such as the number of alerts generated or vulnerabilities identified. However, the validation activities demonstrated that collecting and correlating operational evidence provides significantly greater value.

For example, an alert produced during a network-scanning or API-flooding scenario becomes more meaningful when it is examined alongside the related network evidence, incident artifacts, risk-assessment outputs, and operational observations. This combined view supports a clearer understanding of how the event affects the INTEL ANN smart-parking environment and how the different cybersecurity capabilities contribute to detection, assessment, investigation, and response. This part in particular highlighted the importance of integrated solutions that work in unison rather than standalone technologies. This was possible through the use of an evidence based validation process that gathered realistic traffic information and attack traffic that was used in the evaluation of the CyberSecDome prototype.

Risk assessment outputs, observations, incident artifacts, network evidence, and security events collectively provided a more comprehensive understanding of cybersecurity performance than individual technical indicators alone.

Lesson 3: Controlled Attack Simulation Remains Essential

The use of controlled attack scenarios and security testing activities provided valuable insights regarding operational preparedness and cybersecurity resilience. Attack simulation activities enabled the evaluation of detection, investigation, and response capabilities under realistic conditions while maintaining a controlled environment. They also provided useful vulnerability information for early remediation and investigation of potential breaches caused by them (e.g. newly discovered exploits). Such activities can help organisations better understand the strengths and limitations of their cybersecurity controls.

Lesson 4: Situational Awareness Improves Cybersecurity Decision-Making

The validation activities demonstrated the importance of visualisation and situational awareness capabilities for cybersecurity operations.

Advanced visualisation approaches can support the interpretation of complex cybersecurity information, facilitate incident investigation activities, and improve operational decision-making. Although visualisation technologies do not replace traditional cybersecurity analysis, they can significantly improve the understanding of operators in cybersecurity events and their impact and can also help communicate them better to C-level executives.

The CASPER validation provided practical value for security teams by showing how integrated cybersecurity tools can improve risk understanding, threat detection, incident investigation, and operational awareness in the INTEL ANN smart-parking environment. It also highlighted that successful adoption depends not only on tool performance, but also on interoperability, evidence management, and alignment with real operational workflows.

The CASPER validation showed the positive, challenging, and less visible aspects of integrating multiple cybersecurity technologies in an operational smart-city environment. The positive aspect was that the combined use of different tools improved the understanding of risks, threats, incidents, and operational impacts. The challenging aspect was that interoperability, coordination, evidence management, and workflow alignment required continuous attention during validation. The less visible but important lesson was that technical performance alone was not sufficient: the tools had to produce outputs that security teams could understand, compare, and use within real operational decision-making.

The experience gained through CASPER shows that cybersecurity resilience cannot be achieved through advanced technologies alone. Detection tools, AI techniques, and automated analysis are valuable only when they are connected to risk management, operational visibility, evidence-based validation, collaborative intelligence, and human decision support. In the INTEL ANN smart-parking context, this means that resilience depends on how well the different capabilities support real operational understanding and coordinated response. For smart-city operators, the main lesson is clear: meaningful cybersecurity validation must demonstrate practical applicability, usable evidence, and operational resilience, not only technical performance.

References

1. European Union Agency for Cybersecurity (ENISA). Threat Landscape for Smart Cities. ENISA, 2023.

2. European Parliament and Council of the European Union. Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union (NIS2 Directive), 2022.

3. European Union Agency for Cybersecurity (ENISA). Threat Landscape for Smart Cities. ENISA, 2023. https://www.enisa.europa.eu/publications/enisa-threat-landscape-2023

4. European Union Agency for Cybersecurity (ENISA). ENISA Threat Landscape 2023. ENISA, 2023. https://www.enisa.europa.eu/publications/enisa-threat-landscape-2023

5. European Union Agency for Cybersecurity (ENISA). Foresight Cybersecurity Threats for 2030 – Update 2024. ENISA, 2024. https://www.enisa.europa.eu/publications/foresight-cybersecurity-threats-for-2030-update-2024

6. European Union Agency for Cybersecurity (ENISA). Baseline Security Recommendations for IoT in the Context of Critical Information Infrastructures. ENISA, 2017. https://www.enisa.europa.eu/publications/baseline-security-recommendations-for-iot

7. European Union Agency for Cybersecurity (ENISA). Good Practices for Security of IoT. ENISA, 2019. https://www.enisa.europa.eu/publications/good-practices-for-security-of-iot-1

8. European Union Agency for Cybersecurity (ENISA). Guidelines for Securing the Internet of Things. ENISA, 2020. https://www.enisa.europa.eu/publications/guidelines-for-securing-the-internet-of-things

9. European Parliament and Council of the European Union. Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union (NIS2 Directive). Official Journal of the European Union, 2022. https://eur-lex.europa.eu/eli/dir/2022/2555/oj/eng

10. European Parliament and Council of the European Union. Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act). Official Journal of the European Union, 2024. https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng

11. National Institute of Standards and Technology (NIST). The NIST Cybersecurity Framework (CSF) 2.0. NIST, 2024, PDF version. https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf



Source link