As cyber threats targeting critical infrastructure continue to grow in both scale and sophistication, operators face mounting pressure to secure environments where availability, safety, and operational continuity are non-negotiable.
We speak with Andrea Doyle, Head of ESET Corporate Solutions, NORAM (North America), ahead of her in-person participation at the upcoming CIPRNA Conference.
Andrea represents ESET’s Corporate Solutions division, delivering tailored, intelligence-driven cybersecurity solutions at scale for enterprise and public-sector organizations.
With more than 20 years of experience in cybersecurity, she works closely with organizations across North America, including critical infrastructure operators, Fortune 100 enterprises, leading global technology providers and the Magnificent 7.
In this interview, Andrea shares her perspective on today’s most pressing cybersecurity challenges facing critical infrastructure operators, the role of actionable threat intelligence, and how prevention-first security strategies can help build long-term cyber resilience.
Ben Lane: Andrea, thank you for joining us. To begin, when you look across critical infrastructure sectors globally, what do you see as the most pressing cybersecurity challenges operators are facing?
Andrea Doyle: Thank you, Ben, and thank you for including me in this interview. I’m very excited to be part of CIPRNA and to continue these conversations in person in Baton Rouge this March.
From our discussions with large critical infrastructure operators and partners across North America and globally, three key challenges consistently emerge.
The first is the continued reliance on mission-critical legacy technology. These systems are often difficult, expensive, or operationally impossible to replace, yet they were never designed with today’s cyber threat landscape in mind. Still, they must be protected.
The second challenge is the rise of increasingly sophisticated adversaries, including nation-state and organized criminal groups. These actors understand operational technology environments very well and deliberately exploit the gaps that exist between traditional IT security and OT security.
The third major challenge is visibility. Many organizations still struggle to see what is happening across their environments in real time, particularly in operational networks where traditional scanning or monitoring tools could disrupt processes. Without that visibility, it becomes extremely difficult to prioritize risk or prevent incidents before they escalate.
Together, these three challenges define much of what critical infrastructure operators are grappling with today.
What makes this especially challenging is that these issues reinforce one another – legacy systems reduce visibility, which sophisticated adversaries are very effective at exploiting.
Ben Lane: You mentioned visibility and anticipation. How does threat intelligence help organizations move from reacting to incidents toward preventing them?
Andrea Doyle: Threat intelligence plays a critical role because it fundamentally shifts security from a retrospective exercise to a forward-looking one. Instead of asking, “What just happened?” organizations can start asking, “What is most likely to happen next, and how can we reduce exposure now?”
Effective threat intelligence connects adversary behaviour, tools, and targeting patterns directly to an organization’s specific environment. That allows operators to focus on their critical systems harden them proactively, and allocate limitless resources where they’ll have the greatest impact. In critical infrastructure environments, that usually means prioritizing the systems where failure would have the greatest impact on safety or service continuity.
When done correctly, prevention becomes a strategic decision rather than just a technical outcome. It’s no longer about responding faster after an incident occurs, but about reducing the likelihood of that incident happening at all.
Ben Lane: Information sharing comes up frequently in these discussions. How important are public-private and cross-sector intelligence-sharing initiatives for critical infrastructure security?
Andrea Doyle: They are absolutely essential. No single organization, whether public or private, has complete visibility into today’s threat landscape.
Adversaries reuse techniques across sectors, regions, and technologies. Very often, early signals detected in one environment later appear as indicators in another. Public-private and cross-sector intelligence sharing allows organizations to recognize those patterns earlier, validate risks more quickly, and respond with greater confidence and agility, limiting possible damage.
When intelligence flows both ways – combining government insights, private-sector telemetry, and the operational experience of infrastructure operators – the entire ecosystem becomes stronger. It enables prevention, not just reaction, and reduces the likelihood that lessons have to be learned the hard way.
Ben Lane: One theme that often emerges at CIPRNA is cascading risk and how an incident in one sector can impact many others. How do you see this playing out from a cybersecurity perspective?
Andrea Doyle: Cascading effects are a real and growing concern. Critical infrastructure sectors are deeply interconnected, and disruption in one area can have serious downstream consequences elsewhere.
For example, outages in energy or communications can rapidly affect transportation, emergency response, or water services.
That is why cross-sector collaboration is so important. Understanding how systems depend on one another, whether across transportation, communications, energy, or water, helps operators identify shared vulnerabilities and prioritize resilience measures, accordingly, appointing clear roles and responsibilities, including critical SLAs
Ben Lane: Many operators are working with aging infrastructure. How can organizations extend the life of legacy systems while still maintaining acceptable security and compliance levels?
Andrea Doyle: The starting point is a clear understanding of the operational environment, business priorities, and risk tolerance. This knowledge comes from identifying industry specifics and mapping those with probable threats depending on the nature of the business.
Frameworks such as the MITRE ATT&CK for ICS help operators identify realistic threat scenarios and understand how adversaries might target their specific attack surfaces. Given the long service lives and technical constraints common in critical infrastructure, full system replacement is often not feasible in the short term.
Instead, organizations rely on risk-informed compensating controls and layered defenses tailored to legacy environments. These include system hardening, strong identity and access controls, network segmentation, and monitoring technologies designed to operate reliably over extended lifecycles and serve everchanging business requirements.
When applied together, these measures provide visibility, detection, and containment while supporting safe and predictable degradation if an incident occurs.
This approach allows operators to reduce cyber risk, preserve safety and availability, and meet regulatory obligations even when modernization must occur incrementally.
Ben Lane: Resilience is often discussed at a strategic level, but where do you most often see gaps during real-world incidents?
Andrea Doyle: One of the most common gaps is the disconnect between security teams and operational teams during an incident. If roles, escalation paths, and decision authority are not clearly defined in advance, response efforts can stall at exactly the wrong moment, or even worsen the consequences.
Another challenge is over-reliance on manual processes. Whether it’s triaging alerts, validating threats, or coordinating response actions, manual workflows can quickly become bottlenecks under pressure.
Organizations that invest in prevention, automation, and clear operational playbooks are far better positioned to maintain continuity. Those preparations make a real difference when time is critical, and decisions must be made quickly.
Ben Lane: What roles do independent cybersecurity vendors such as ESET, and specifically ESET Corporate Solutions, play in supporting long-term resilience across critical infrastructure ecosystems in North America?
Andrea Doyle: Independent cybersecurity vendors play a vital role, particularly by providing unbiased research, deep technical expertise, and long-term commitment to unique customer environments and needs.
In critical infrastructure, trust, transparency, and operational stability are just as important as innovation. Within ESET’s Corporate Solutions division, the focus is on prevention-first security designed to scale across complex operational environments including air-gapped, semi-isolated, and fully connected systems.
By combining advanced threat intelligence, non-intrusive detection, and long-term support for legacy systems, ESET helps operators reduce cyber risk while strengthening long-term resilience across their ecosystems and ensuring business continuity.
Ben Lane: A recurring theme is the difficulty organizations face in moving from reactive security to prevention. Why do you think that transition can be so challenging?
Andrea Doyle: There are several reasons. Legacy systems, limited visibility, and constrained tools all play a role. In some cases, organizations lack the tools or knowledge needed to detect threats early enough. In others, they may not have the operational context required to act confidently on intelligence.
What we are hearing from the organizations we work with is that they recognize the need to move in this direction, but they need practical, operationally safe ways to make that shift – without increasing risk to safety or availability
Ben Lane: Looking ahead to CIPRNA, what are you most looking forward to discussing with attendees in Baton Rouge?
Andrea Doyle: I’m very much looking forward to engaging directly with operators and stakeholders in Baton Rouge. Events like this create the opportunity for meaningful, practical conversations, not just about challenges, but about what is actually working. It also created the opportunity to build a community between a vast array of industries that will togteher help protect our families and business from any sophisticated threat.
Critical infrastructure security is moving toward prevention, actionable intelligence, and resilience by design. Having the right tools, timely and contextualized intelligence, and strong collaboration across sectors is essential.
I’m excited to continue these discussions, learn from others’ experiences, and explore how we can collectively strengthen the resilience of critical infrastructure across North America.
Ben Lane: Thank you for your time and we look forward to seeing you soon.
Andrea Doyle will be participating in the Critical Infrastructure Protection & Resilience North America Conference this March in Baton Rouge. To continue the conversation, join industry leaders, operators, and policymakers for in-depth discussions on cybersecurity, resilience, and infrastructure protection.

