DCS-CI 2026
Design of Cyber-Secure
Critical Infrastructure
An International Conference on Secure-by-Design for Critical Infrastructure
September 2-3, 2026
The Water Tower, Buford, Georgia, USA
https://dcs-ci.github.io/

Understanding the vision, scope, and evolution of the Design of
Cyber-Secure Critical Infrastructure conference series.

About the Conference

Why This Conference Exists

Critical infrastructures underpin the functioning of modern
societies. They enable the continuous provision of essential services,
support economic activity, safeguard public safety, and contribute to
national and societal resilience. Water treatment plants, electrical
grids, transportation systems, and healthcare networks are
increasingly reliant on interconnected digital systems—systems that
must be protected not merely as an afterthought, but as a fundamental
design principle.

As the flagship venue, DCS-CI aims at convening leading researchers,
engineers, policymakers, and practitioners who share a commitment to
embedding security into the very architecture of the systems upon
which societies depend.

In an era of escalating cyber threats—ranging from nation-state actors
to criminal enterprises—traditional perimeter-based defenses are
insufficient. DCS-CI 26 promotes a paradigm shift toward
secure-by-design and secure-by-default methodologies: approaches that
consider security as intrinsic to system engineering, not as a
supplementary layer applied after deployment.

Building on DCS-Water 24 and DCS-Water 25

The DCS-CI series has its origins in the DCS-Water conferences, which
focused specifically on the cybersecurity challenges facing water and
wastewater utilities. DCS-Water 24 and DCS-Water 25, held under the
auspices of the iTrust research centre at the Singapore University of
Technology and Design, brought together world-leading experts to
address operational technology (OT) vulnerabilities, cyber-physical
attack scenarios, and resilience strategies for water critical
infrastructure.

These conferences demonstrated the value of cross-disciplinary
dialogue—bringing together control systems engineers, cybersecurity
researchers, utility operators, and regulatory bodies. The insights
generated and collaborations formed have influenced both academic
research and industry practice.

DCS-CI 26 expands upon this foundation. While water infrastructure
remains a vital concern, the conference now embraces the full spectrum
of critical infrastructure sectors: energy, transportation,
healthcare, telecommunications, and beyond. This broader scope
reflects the recognition that many of the challenges—and many of the
solutions—transcend sectoral boundaries. Secure-by-design principles,
threat modeling frameworks, and resilience engineering methodologies
are applicable across all domains where cyber and physical systems
intersect.  Why System-Level, Secure-by-Design Thinking is Critical

Modern critical infrastructure systems are complex socio-technical
assemblages. They comprise legacy industrial control systems,
contemporary IT networks, cloud-based analytics platforms, and human
operators—all interacting in intricate and often unpredictable
ways. Securing such systems requires a holistic, system-level
perspective.

Secure-by-design thinking acknowledges that security cannot be
effectively retrofitted. It must be embedded from the earliest stages
of system conception, through design, implementation, deployment, and
ongoing operations. This approach requires:

    Threat modeling that anticipates adversary capabilities and motivations
    Architectural patterns that minimise attack surfaces and contain breaches
    Defense-in-depth strategies that layer multiple controls
    Resilience engineering that enables graceful degradation and rapid recovery
    Continuous validation through testing, red-teaming, and assurance processes

DCS-CI 26 provides a forum for the presentation of original research,
case studies, and position papers that advance these objectives. It
welcomes contributions from academia and industry alike, recognizing
that the most impactful insights often emerge at the intersection of
theoretical innovation and practical experience.

Call for Submissions

We invite original research contributions addressing the design,
implementation, and assurance of cyber-secure critical infrastructure
systems.

Invitation to Contribute

The Design of Cyber-Secure Critical Infrastructure (DCS-CI) 26
conference invites researchers, practitioners, and thought leaders to
submit original work that advances our collective understanding of how
to design, deploy, and maintain secure critical infrastructure
systems.

We welcome submissions from diverse disciplinary perspectives,
including computer science, control systems engineering, security
studies, public policy, and operations management. Interdisciplinary
contributions that bridge theoretical innovation with practical
application are particularly encouraged.

The conference seeks work that is rigorous, relevant, and
actionable—research that not only advances academic knowledge but also
informs the practices of infrastructure operators, system integrators,
and regulatory bodies.

There will also be a Best Paper Award to recognize outstanding
research contributions.


Topics of Interest

DCS-CI 26 welcomes original contributions across a broad range of
topics related to the design and assurance of cyber-secure critical
infrastructure.  Secure-by-Design and Secure-by-Default Architectures

Research addressing the integration of security principles into the
foundational architecture of critical infrastructure systems.

Example sub-topics

    Architectural patterns that embed security from system conception
    Secure-by-default configurations for operational technology environments
    Zero-trust architectures for industrial control systems
    Security reference architectures for specific infrastructure sectors
    Design methodologies that minimize attack surfaces while
      maintaining operational functionality

Cyber-Physical Risk, Safety, and Resilience

Studies examining the intersection of cybersecurity, physical safety,
and system resilience in infrastructure contexts.

Example sub-topics

    Risk assessment frameworks for cyber-physical systems
    Safety-security co-engineering methodologies
    Resilience quantification and measurement approaches
    Attack impact analysis and consequence modeling
    Recovery and restoration strategies following cyber incidents
    Business continuity in the context of cyberattacks

Operational Technology (OT) and Automation Security

Contributions focused on securing industrial control systems, SCADA
networks, and automation platforms.

Example sub-topics

    ICS/SCADA security monitoring and anomaly detection
    Secure remote access for industrial environments
    Legacy system protection and secure integration
    Protocol security for industrial communications (Modbus, DNP3, OPC UA, etc.)
    Security challenges in IT/OT convergence
    Human factors in OT security operations

System Lifecycle and Engineering Perspectives

Work that addresses security across the full system lifecycle, from
requirements through decommissioning.

Example sub-topics

    Security requirements engineering for critical infrastructure
    Secure development practices for embedded and control systems
    Security considerations in procurement and supply chain management
    Patch management and vulnerability remediation in operational contexts
    Security implications of system modernization and digital transformation
    Decommissioning and secure disposal of infrastructure components

Digitalisation and Emerging Technologies

Research on security implications of digital transformation and new
technology adoption in infrastructure.

Example sub-topics

    AI/ML applications in infrastructure security and their vulnerabilities
    Cloud computing security for infrastructure operations
    IoT security in infrastructure monitoring and control
    5G and communications security for critical infrastructure
    Digital twins and simulation for security analysis
    Blockchain and distributed ledger applications in infrastructure

Testing, Validation, and Assurance

Methodologies and case studies related to verifying and validating
security controls in infrastructure settings.

Example sub-topics

    Penetration testing methodologies for OT environments
    Red team and purple team exercises for infrastructure
    Security testbed design and implementation
    Formal verification and assurance approaches
    Compliance frameworks and security auditing
    Metrics and indicators for infrastructure security posture

AI for Cyber-Physical System Security

Innovative use of AI for novel and effective approaches to attack and
defence in cyber-physical systems.

Example sub-topics

    Machine learning for intrusion detection in industrial control systems
    AI-driven threat hunting and anomaly detection in OT networks
    Adversarial machine learning and AI system robustness
    Automated vulnerability discovery and exploit generation
    AI-assisted incident response and forensic analysis
    Generative AI for attack simulation and red teaming

Digital Twins and Cyber Twins *

Virtual replicas and simulation environments for security analysis,
testing, and operational resilience in critical infrastructure.

Example sub-topics

    Digital twin architectures for critical infrastructure security
    Cyber twin models for attack simulation and defence validation
    Real-time synchronisation and fidelity challenges in security contexts
    AI-assisted design and implementation of digital twins and cyber ranges
    Predictive security analytics using digital twin simulations
    Integration of digital twins with SIEM and SOC operations

*We define Cyber Twins as "purpose-built digital twins for cyber use cases"
Submissions Outside Listed Topics

The topics listed above are indicative rather than
exhaustive. Submissions that address cyber-secure critical
infrastructure from perspectives not explicitly listed may still be
considered if they are relevant to the conference themes and meet
academic quality standards. Authors are encouraged to contact the
program chairs if uncertain about the suitability of their topic.

Key dates and deadlines for DCS-CI 26. All submission deadlines are at
23:59 AOE.

All deadlines are at 23:59 AOE (anywhyere on earth) on the stated date.

13 February 2026
Call for Submissions Opens
The submission system opens for paper submissions via EasyChair.
closed

4 May 2026
Submission Deadline
Final deadline for all paper submissions.
closed

15 June 2026
Acceptance Notification
Authors will be notified of the paper acceptance decision.
closed

1 July 2026
Camera-Ready Deadline
Final camera-ready versions due for accepted papers.
closed

2–3 September 2026
Conference Dates
DCS-CI 26 conference at The Water Tower, Buford, Georgia, USA.
upcoming