RITICS: Securing cyber-physical systems
Discover the Research Institute in Trustworthy Inter-connected Cyber-physical Systems.

For those who don't know, RITICS is the Research Institute in Trustworthy Inter-connected Cyber-physical Systems. In this blog post I'd like to explain what exactly a cyber physical system is, and talk a little about the work RITICS is doing to help make them safe.
Cyber-physical systems
Cyber-physical systems have physical inputs and/or outputs which are controlled by computers. At one extreme this means industrial control systems and some critical infrastructure, like power generation and distribution. At a smaller scale, many IoT devices are also cyber-physical systems. I'm talking here about things like domestic thermostats and other 'smart' appliances.
It turns out that the physical interactions which make up one side of a cyber-physical system present some novel cyber security challenges. Not least among this is developing an understanding how safety requirements mesh with security needs.
The role of RITICS
Our interconnectedness with cyber physical systems is a fact which permeates our lives. The issue that faces us is, how do we ensure that systems we have in our homes and across all forms of industry are safe and secure?
Our main objectives at RITICS are to research areas which will lead to a better understanding of cyber-physical interactions, in particular, how cyber attacks might have physical outcomes. We also explore ways to better communicate risk and new approaches to protecting such systems. We look at the socio-technical issues too, including the economics of protecting cyber-physical systems and some of the barriers to adoption of good practice.
RITICS was founded in 2014 as a coordinated group of 5 research projects. Today it is an open community of university research teams, supported by a mix of industry and government partners. We work closely with the CNI Team at the NCSC.
Projects and partnerships
The world of cyber-physical systems can sound a bit theoretical, so here's a round up of what RITICS has been doing since its first steps, back in 2014.
Phase one
RITICS phase one ran from 2014 to 2018, during which time there were some noteworthy achievements. Here's a quick rundown of the highlights:
- Construction of proof-of-concept tools for building models of complex cyber physical systems.
- Construction of test beds for experiments on the security of various critical infrastructures (for example electricity distribution, water treatment and distribution).
- Production of a serious game for studying security decisions.
- Secure implementation of synchro-phasor technologies for use in power distribution systems.
- Development of a new key management system for the European Rail Traffic Management System (ERTMS) supporting key generation, key distribution and lifecycle management with broader application to Internet of Things.
- Contribution to the Rail Cyber Security Strategy (published by Railway Delivery Group, January 2017).
White papers
The RITICS team produced two white papers. The first provided a review of open test beds for critical national infrastructure.
The second reviewed open-source tool sets for the analysis and protection of critical national infrastructure. Both white papers are available from the RITICS website.
Phase 2 - Funding growth
The second phase, which began in mid 2018, has seen a substantial growth in the number of universities involved and the community of interest that has developed them.
The universities receive funding from a variety of sources including UK Research and Innovation (UKRI), the European Union (Horizon 2020) and industrial partners.
RITICS has also held three funding calls using money from the National Cyber Security Programme. The first of the calls paid for three projects to look at various aspects of the Network and Information Systems (NIS) Directive. The main focus of these projects has been on approaches to securing the supply chain, understanding the differences between sectors and identifying barriers to compliance.
The second call funded four projects based on the ICS Community of Interest problem book. The projects were:
- understanding the interactions between safety and security
- exploring the role of agile techniques in incident response
- developing a secure approach to the use of the cloud in ICS implementations
- developing new approaches to forensic training in safety-related industrial control systems
Proposals received for the third call are still being reviewed. Please watch the website for updates.
Show and tell
Most of the projects funded by the second phase of RITICS are still running and so have yet to produce results that can be deployed. However, we hold regular showcase events to update the community on progress and there is a quarterly newsletter.
If you are not already part of the RITICS community and would like to hear more about our projects and progress, please either contact us via the RITICS website, or you can email me directly.


