The war involving Iran is highlighting a growing cyber threat that extends far beyond the Middle East: the vulnerability of critical infrastructure that societies depend on every day.

Recent reports of a cyberattack that forced a British power plant offline for four days have raised concerns about what could happen if a similar attack were directed at a much larger facility. Although the British government stressed that the incident did not threaten the wider energy system, the episode demonstrates why even smaller attacks deserve close attention.

There have been concerns elsewhere as well. Water and wastewater systems in at least 12 US states have recently reported cyberattacks, while more than 30 community water systems in Minnesota alone were affected. One incident in Georgia reportedly caused water pressure to fall and resulted in a boil-water advisory.

The US government has not publicly attributed those attacks to Iran. However, reports have pointed towards a hacking group believed to be linked to Iran's Islamic Revolutionary Guard Corps.

The incidents demonstrate how the nature of cybersecurity threats is changing.

For years, cyberattacks were mainly discussed in terms of stolen data, compromised passwords, financial theft or ransomware. Attacks against critical infrastructure create a different kind of danger because the digital systems being targeted can directly control physical equipment.

Electricity grids, water treatment facilities, transport networks and telecommunications systems increasingly rely on connected technology. That technology can make services more efficient, but it can also provide attackers with a route into systems that control the physical world.

US authorities have specifically warned about Iranian-affiliated actors attempting to target internet-connected programmable logic controllers, or PLCs. These industrial devices are used to control machinery and physical processes.

Authorities have identified activity involving water, energy and government services, including incidents that have resulted in operational disruption.

One of the most important features of cyberwarfare is that geography provides relatively little protection.

A company or government facility does not need to be located near Iran or Israel to become involved in a cyber conflict. Infrastructure thousands of kilometres away can become a target because of its location, political connections, technology, suppliers or simply because attackers identify an opportunity.

Not every cyberattack is necessarily designed to cause catastrophic damage.

Attackers may be looking for intelligence, disruption, publicity or political leverage. In some cases, they may simply want to demonstrate that they can penetrate a system.

That makes apparently minor incidents significant. If attackers manage to compromise a relatively small facility, the immediate damage may be limited, but their access can reveal important information about their capabilities and intentions.

Another major concern is the interconnected nature of critical infrastructure.

Electricity supports communications, transport, healthcare, finance and industry. Communications networks support payments and emergency services. Water systems depend on electricity and digital controls.

This means an attack does not necessarily have to bring down an entire national system to cause serious disruption. Problems can spread when organisations and services depend on one another.

That is why resilience is becoming as important as prevention.

Governments and companies need to protect their networks, but they also have to accept that no defence can guarantee that every attack will be stopped.

Operators need plans for what happens if an attacker gets through. They need to know whether essential services can continue, whether compromised systems can be isolated and whether manual controls can be used when necessary.

They also need to understand how quickly affected operations can be restored and which suppliers and connected systems could become secondary points of vulnerability.

The FBI has already advised affected US water utilities to practise switching back to manual controls if automated systems are compromised.

The recommendation underlines an important principle: cybersecurity for critical infrastructure ultimately means ensuring that essential physical services can continue even when digital technology fails.

Governments and infrastructure operators therefore need to review their exposure now, particularly where operational technology is connected to the internet.

They also need to examine the cybersecurity of suppliers and prepare for situations in which an attacker succeeds despite existing defensive measures.

The recent incidents show that cybersecurity is no longer simply about protecting information. When attackers can interfere with electricity or water systems, cybersecurity becomes directly connected to public safety and the ability of society to function normally.

The Iran conflict may therefore represent a warning for governments well beyond the Middle East. Critical infrastructure operators need to prepare for cyberattacks as part of their broader security planning rather than treating them as a separate, purely digital problem.

Discovering weaknesses only after a serious attack would be too late. The priority now is to identify vulnerabilities, strengthen defences and ensure that essential services can continue operating even when parts of the technology supporting them are compromised