New security threats combine physical and cyber attacks New security threats combine physical and cyber attacks, according to Raúl Porras Martín, Chief Information Security Officer at Desico (Grupo Casnova), during the presentation he gave at SICUR 2026, which focused on security systems in a connected operational environment. In Raúl Porras’s view, the adoption and integration of Internet of Things (IoT) devices, Industrial Internet of Things (IIoT), IT/OT systems, Building Management Systems (BMS), and physical security systems has led to an increasingly interconnected mesh of cyber-physical systems. “We are no longer talking about isolated infrastructures, but about fully connected ecosystems,” he stated. During his participation at SICUR 2026, Porras highlighted the growing importance of hybrid threats in physical security systems and warned of new challenges posed by cyberattacks. According to his explanation, current threats result from attacks jointly targeting physical and cyber assets. The expert indicated that security systems combine traditional IT technologies, OT systems and IoT devices. Regarding information technology (IT), he emphasized the importance of TCP/IP protocols, application servers and databases, software, and virtualised environments. In relation to operational technology (OT), he referred to SCADA platforms, PSIM, VMS, PLCs and protocols such as OSDP or Wiegand, as well as identification technologies such as Mifare or Desfire. Added to this are IoT devices such as CCTV cameras, biometric and card readers, IP intercoms, and connected video door entry systems. Adapting to cross-cutting challenges Porras stated that the challenges are cross-cutting, but questioned whether they are also being managed that way. His answer was no. “The functions and responsibilities of physical security and cybersecurity are disconnected and, in many cases, still operate completely independently.” The strategy for physical security is limited to the following functions: protection of facilities, people, assets and physical access against deliberate threats; definition of security policies and