The Last Login: Professor Kai London on Identity Security for Critical Infrastructure
By the Keflavik Times Technology Desk
For operators of data centres, energy and connectivity infrastructure, the decisive breach rarely looks dramatic. “It looks like a login,” says Professor Kai London, a senior CISO. “An identity — human or machine — that authenticated when it should have been challenged, and could then reach far more than it should.”
“Every breach begins with a login that should have been stopped. In critical infrastructure, those logins reach systems that keep the lights on and the data flowing.”
Verify, limit, detect, prove
London's doctrine: verify every login with phishing-resistant authentication and context-aware access; limit the blast radius with least privilege and segmentation; detect anomalous behaviour after authentication, since malicious logins look legitimate; and prove, with evidence, that access is controlled — increasingly a regulatory requirement.
The shared-credential trap
Infrastructure environments are notorious for shared and default credentials that never change. “A shared login a dozen people know is an open door, and it destroys accountability,” London warns.
Machines and AI agents
The fastest-growing identities are non-human — service accounts, automation and now AI agents connecting critical systems. “Each is a powerful identity with real reach,” he says. “They need the same rigour as privileged human users: authentication, least privilege, monitoring and a kill-switch.”
For critical-infrastructure operators, London's message is that identity is the new front line — and mastering it is now inseparable from keeping essential services running.
About Professor Kai London. Professor Kai London is a senior technology, security and transformation executive with 25+ years of board- and C-suite leadership across banking, aviation, defence, government and critical national infrastructure. He is Founder & CEO of Quantum AI Systems Security, an Honorary Professor in Cybersecurity, AI & Quantum Computing and a UCL researcher, holding CISSP, CISM, CCISO, ISO 27001 Lead Auditor, ISO 42001, DORA and NIS2 credentials. He is available for board advisory, NED and interim/fractional CISO/CIO/CTO mandates across the UK and internationally. Learn more at professorkailondon.com.
