From Cybersecurity In Critical Infrastructure To Risk Analyses In The Context Of Military Products: Start Me Up Monday On September 28, 2026

Eine Person tippt auf einem Laptop, auf dem Symbole für Cybersicherheit zu sehen sind, darunter ein leuchtendes Schild und ein Vorhängeschloss, die für Datenschutz und sicheren Zugriff für mehrere Benutzerprofile stehen, vor einem dunklen Hintergrund.

17 September, 2026

On September 28, 2026, at 5 p.m., UAS Technikum Wien will dedicate its “Start me up Monday” event series to the highly topical subject of security and modern protection systems. One of the participants, Sascha Kristament of Rheinmetall, speaks in an interview in this preview article.

Whether it’s cybersecurity in critical infrastructure, deep technologies and the funding landscape, risk analyses in the context of military products, or data-autonomous communication: The program for Start me up Monday on September 28, 2026, at the UAS Technikum Wien (in the small ballroom) will explore the key issues of digital resilience—from research to industry to startups.

Interview: Cyber Risk Analyses in a Military Context

Ahead of the event, we spoke with Sascha Kristament (Vehicle Cyber Security Manager, Rheinmetall MAN Military Vehicles Austria GesmbH). On September 28, he will speak on “Cyber Risk Analyses in a Military Product Context—Challenges, Limitations, and Areas for Action.” Here is the interview:

What fundamentally distinguishes cyber risk analyses in a military context from those in the civilian automotive sector?

Sascha Kristament: The most important distinction is likely reflected in the attacker model. In the civilian sector, we consider cybercriminals, vehicle theft, and vehicle modifications. In the military context, however, we must primarily take state actors into account. These differ in terms of motivation and available resources. State actors act with the motivation to cause serious damage, whereas civilian actors often have only financial gain in mind. Accordingly, the attacker’s motivation or objective can lead to a threat to the mission in the military sector.

How do you integrate cybersecurity into the entire product lifecycle—from the concept phase to field operation?

Sascha Kristament: The basic principle remains the same in every phase—identify, analyze, mitigate, monitor. What changes between the phases are the information sources, methods, and responsibilities. During development, assets requiring protection are identified, potential cyber risks are analyzed and assessed, the risks are mitigated using security mechanisms, and the assets are subsequently transferred to security monitoring. In the field, security monitoring detects vulnerabilities, identifies the affected assets, and remedies the vulnerabilities via software updates.

How do you test and validate assumptions from the risk analysis (e.g., red teaming, threat modeling, penetration testing) under realistic operational conditions?

Sascha Kristament: Based on the specified operational profile and the assumed damage scenarios within the threat analysis, the necessary test cases are defined and prioritized. These are tested, whenever possible, on real, production-ready vehicles in representative vehicle conditions. The testers specialize in identifying vulnerabilities and exploiting them in various ways. If the actual results do not match those from the threat analysis, the process is repeated.

Event Information: (September 28, 2026 – UAS Technikum Wien)

Participation in the event is free of charge. We ask that you register.

For more information about the event, other participants, and registration:

https://www.technikum-wien.at/events/start-me-up-monday-sicherheit/

Digitale Veranstaltungsgrafik mit dem Text „Start Me Up Monday“, einem Raketensymbol, dem Wort „SICHERHEIT“ und dem Hinweis „Save the Date: 28. September 2026“ auf einem dunkelblauen Hintergrund im Tech-Stil.