Key Takeaways
- Cyber‑physical risk threatens life safety, yet no party is currently defined as professionally or legally accountable for protecting connected systems.
- Engineering standards of care have historically emerged only after tragic events; experts warn that waiting for a “Pearl Harbor‑level” cyber incident would repeat that reactive pattern.
- The engineering profession does not yet own cyber‑safety risk, but many argue that engineers must treat cyber risk as integral to safe design, similar to fire protection or structural integrity.
- A practical near‑term solution is to augment the existing Control Systems Professional Engineer (P.E.) exam with cyber‑safety‑specific content rather than creating a wholly new 25th engineering discipline.
- For any new credential to succeed, market demand, professional‑society guidance, and insurer support must be cultivated alongside academic programs that keep curricula current.
- Ethical obligations compel engineers to act now; knowing the foreseeable hazards of cyber‑physical systems creates a duty to mitigate risk before a preventable catastrophe occurs.
Summit Context and the Life‑Safety Imperative
The Cyber Safety Summit convened on June 10 at the National Academy of Sciences in Washington, D.C., driven by the recognition that cyber‑physical risk poses a direct threat to human life. Participants agreed that a life‑safety issue requires a clearly accountable party, yet the summit revealed that no such accountability currently exists for compromised connected physical systems. Expert panels grappled with the central question: who bears professional and legal responsibility when a cyber‑physical system is breached, and what constitutes the appropriate standard of care for cyber safety?
Historical Pattern of Reactive Engineering Standards
As outlined in the summit’s strategy framework, engineering standards of care have traditionally followed a reactive sequence: a hazard is identified, people are harmed, the profession organizes, and a standard is codified—often only after insurers, regulators, and public outcry force change following a tragedy. Examples cited include the mid‑1800s boiler explosions that spurred the ASME Boiler and Pressure Vessel Code, the Great Chicago Fire that led to modern fire‑protection regulations, and the 1907 Quebec Bridge collapse that helped establish the professional engineer as a guardian of public safety. John Kliem of Johnson Controls warned that waiting for a catastrophic cyber event would repeat this painful pattern, urging the profession to act pre‑emptively.
The Profession’s Current Lack of Ownership
David Brearley of HDR and Brian May of Michael Baker International emphasized that engineers can no longer fulfill their duty to deliver safe designs without addressing cyber risk. They noted that, in hindsight or litigation after a cyber‑physical incident, most stakeholders would deem the event foreseeable, yet no clear standards or accountability mechanisms exist today. Adam Gladsden of ConfigRisk highlighted accountability and traceability as the core risk issue, while Adam Firestone of SIX3RO argued that the absence of a dedicated cybersecurity engineer forces the profession to act decisively: “We need to start saying that we will not be able to deliver unless we include a dedicated cybersecurity engineer.”
Proposal for a Cyber Safety Engineering Credential
Advocates contend that cyber safety engineering must evolve from an informal best practice into a recognized professional discipline. Summit organizer Lucian Niemeyer of Building Cyber Security presented two pathways: create a 25th professional engineering discipline or embed cyber safety within the existing Control Systems P.E. license. He cautioned that a standalone license would take years to establish, potentially leaving students without a clear licensure route. Instead, the summit proposes augmenting the current Control Systems P.E. exam—already containing a security‑focused section—with additions such as consequence‑based classification for connected systems, a mandatory technology registry tracking devices throughout a project’s lifecycle, and formal cyber commissioning as a condition of project acceptance. A joint proposal from the National Academy of Engineering, National Academy of Construction, United Engineering Foundation, and Building Cyber Security is slated for submission to the National Council of Examiners for Engineering and Surveying (NCEES) by October 2026, positioning cyber safety as a near‑term addition to an existing exam while longer‑term state licensure work continues.
Market Demand, Academic Readiness, and Ethical Imperatives
Even with a licensure pathway, adoption will hinge on market demand, professional‑society guidance, and insurer support. Adam Firestone observed that the engineering industry currently does insufficient demand‑generation work—employers rarely require cyber‑safety professionals, and career paths that reward such expertise are scarce. He urged direct collaboration with employers to create pull rather than assuming it will emerge spontaneously. Lucian Niemeyer noted that, unlike electrical grounding or fire protection, cyber threats are not routinely assumed as required by facility owners, necessitating education and advocacy.
On the academic front, Matthew Jablonski of George Mason University pointed to the university’s rapidly growing cybersecurity engineering major (launched in 2015) as evidence of rising student interest. He stressed that curricula must stay current by employing adjunct professors who are active practitioners, a recommendation echoed by Brian Correia of the SANS Institute.
Finally, the summit highlighted the ethical dimension: Acting Director Nick Anderson of CISA challenged engineering deans to consider whether they could look their families in the eye knowing they had ignored a foreseeable cyber‑physical threat. This moral imperative reinforces the argument that engineers must treat cyber safety as an integral part of their professional duty of care, not an optional add‑on.
Governance and the Road Ahead
The Cyber Safety Summit outlined a framework that distributes responsibility among engineers, owners, vendors, and insurers, each bearing “proportionate responsibility” for protecting human life, safety, and health. Whether this framework crystallizes into a licensed engineering discipline—and how swiftly that occurs—remains an open question for the profession, its regulators, industry partners, and the insurers who ultimately price cyber‑physical risk. The consensus is clear: proactive steps now can avert the need for a disastrous catalyst later, aligning the engineering community with its historic role of safeguarding public welfare through anticipatory, standards‑based action.

