CrowdStrike 2026 Threat Hunting Report: Get insights from frontline experts.  Download report

The machines running modern infrastructure are no longer passive equipment waiting for human instruction. The power grid adjusting voltage in real time, the surgical robot responding to a surgeon's sub-millimeter movements, the autonomous vehicle navigating a rain-slicked intersection: all these systems make decisions, take actions, and reshape the physical world in ways that were unimaginable a generation ago.

Adversaries have noticed. AI-enabled attacks surged 89% year-over-year in 2025, and a significant share of that activity targets the systems where digital compromise translates directly into physical consequence.

Understanding how cyber-physical systems (CPS) work, and why securing them requires a fundamentally different approach, begins with the systems themselves.

What are cyber-physical systems?

Cyber-physical systems (CPS) are engineered systems that tightly couple computational processes with physical ones. The term was introduced in 2006 at the National Science Foundation to describe an orchestration of computers and physical components. Embedded processors continuously monitor real-world conditions, make decisions based on that data, and act on the physical environment through mechanical or electronic output. The result is a closed loop: the physical world shapes computation, and computation shapes the physical world, continuously and in real time.

That feedback loop is what separates CPS from earlier generations of industrial equipment. A traditional machine operates on a fixed program. A cyber-physical system responds, adapts, and optimizes based on what its sensors are observing right now.

Where CPS appear in everyday life

CPS are embedded in the infrastructure and devices most people rely on daily, often invisibly. Some of the most common environments where cyber-physical systems operate include:

  • Power and utilities: Smart grids use CPS to balance electricity supply and demand in real time and reroute power automatically when generation sources fluctuate or equipment fails.
  • Transportation: Modern vehicles, from commercial aircraft to passenger cars with advanced driver assistance, rely on CPS to process sensor data and make control decisions faster than any human driver could.
  • Healthcare: Implantable devices like pacemakers and insulin pumps are CPS that continuously monitor biological data and respond with precise physical action to keep patients stable.
  • Manufacturing: Factory floors use CPS through industrial control systems and robotics to coordinate complex assembly processes, monitor equipment health, and maintain production tolerances.
  • Buildings: Heating, ventilation, access control, and fire suppression systems in modern facilities are increasingly managed by CPS that optimize conditions automatically based on real-time occupancy and environmental data.

How cyber-physical systems work

The architecture of a cyber-physical system is built on a single governing principle: the physical world and the computational layer must remain in continuous, synchronized communication. A CPS delivers this through three tightly coupled capabilities: 

Sensors, actuators, and control loops

Sensors are the system's perception layer. They convert physical phenomena such as temperature, pressure, motion, voltage, and proximity into digital data the system can process.

That data flows to a computational layer: an embedded processor, a programmable logic controller (PLC), or a distributed control system that applies algorithms to decide what should happen next. The decision then flows to actuators, which are the system's hands. An actuator might open a valve, adjust a motor's speed, apply a brake, or trigger an alarm. Once the actuator acts, the physical environment changes, sensors detect the change, and the cycle begins again.

This feedback architecture is what gives CPS their power. Without it, a smart grid cannot balance load in real time, or an insulin pump can’t adjust its delivery based on continuous glucose readings. The loop is the system. 

Real-time data and decision-making

Cyber-physical systems operate under strict timing constraints. In an industrial control environment, a response delay measured in milliseconds can mean the difference between normal operation and catastrophic equipment failure. This is why CPS run on specialized real-time operating systems and communication protocols designed to guarantee latency thresholds rather than merely optimize for them.

The computational layer in a CPS often makes autonomous decisions without human intervention. That autonomy is a feature — human operators can't respond at the speeds CPS require. But it also means that if a CPS receives false data or compromised control logic, consequences follow immediately in the physical world.

Physical and digital interaction

What makes cyber-physical systems distinct from pure software systems is that the physical and digital domains are in constant, mutual interaction, each continuously shaping the other. A change in a physical process generates data that alters a computational decision, and that decision triggers a physical response that generates new data in turn. Neither domain is passive. The digital layer has no meaning without the physical process it governs, and the physical process loses its intelligence and adaptability without the digital layer interpreting its state.

This bidirectional dependency is also what makes CPS difficult to secure. An attack that corrupts data in the digital layer can produce tangible consequences in the physical world. A physical disruption to sensors or actuators can also corrupt the data the digital layer depends on to function correctly. The two domains are inseparable in operation — and inseparable in risk.

Core components and architecture of CPS

A cyber-physical system is built across three interdependent layers, each responsible for a distinct function.

Physical process layer

The physical process layer is the tangible substrate: the machinery, pipelines, power lines, vehicle components, or biological systems the CPS manages. Changes here are changes in the real world, whether in voltage, flow rate, rotational speed, or temperature. Everything else in the CPS architecture exists to monitor and control what happens at this layer.

Computing and networking layer

Embedded systems and real-time controllers process sensor data and execute control logic at this layer. Communication infrastructure connects sensors to controllers to actuators using protocols built specifically for industrial environments, such as Modbus, DNP3, or OPC-UA, that prioritize deterministic timing over the flexible, packet-switched behavior of standard IT networks. Cloud and edge computing increasingly extend this layer, adding analytics and machine learning capabilities to CPS that were previously limited to simple rule-based control.

Control and feedback mechanisms

The control layer closes the loop between sensing and actuation. Feedback mechanisms compare current system state to desired state and generate corrective commands. A simple thermostat does this mechanically. A modern distributed control system managing a refinery does it through thousands of simultaneous control loops, each with its own set points, tolerances, and response logic. At scale, the control architecture becomes as complex as any enterprise software system, and as difficult to secure.

Examples and applications of CPS

Cyber-physical systems are most visible in the industrial and critical infrastructure sectors. A few of the most consequential application areas include:

Manufacturing and industrial control

Industrial control systems (ICS) and supervisory control and data acquisition (SCADA) systems are foundational CPS. They manage assembly lines, regulate chemical processes, control water treatment plants, and operate power generation facilities. At this scale, CPS can coordinate hundreds of interconnected machines across multiple facilities, optimize throughput continuously, and detect anomalies before they become failures.

Healthcare and medical devices

In healthcare, CPS are implanted in and attached to patients. Pacemakers, infusion pumps, and continuous glucose monitors are all cyber-physical systems that sense biological data and respond with physical action. Next-generation surgical robotics extend a surgeon's physical capabilities with sub-millimeter precision that no human hand can match unaided. The stakes of a security failure in this context are immediate and personal.

Transportation, energy, and smart buildings

Autonomous vehicles simultaneously process data from radar, lidar, cameras, and GPS and fuse that input to make driving decisions in real time. Smart grid infrastructure uses CPS to balance electricity supply and demand dynamically, and it pulls data from distributed generation sources like solar and wind that produce variable output. In the built environment, smart building systems coordinate HVAC, lighting, access control, and fire suppression through integrated CPS architectures that optimize energy use and occupant safety in tandem.

Cyber-physical security and convergence

The security calculus for cyber-physical systems differs substantially from that of conventional IT environments, and the gap is wider than most security teams account for. A breached enterprise server is a serious problem: data is lost, operations are disrupted, and recovery costs mount. A compromised CPS in a power plant or water treatment facility can cause physical damage, create safety hazards, and affect communities far beyond the organization that was attacked. The consequences of a successful intrusion extend into the physical world in ways that make the risk profile categorically different.

What makes that risk harder to manage is how modern adversaries operate. In 2025, 82% of cyberattacks involved no malware at all. Adversaries logged in using stolen credentials and moved through systems using legitimate tools that security monitoring was never tuned to flag. In an environment where IT and OT networks are converged, that kind of lateral movement can carry an attacker from a compromised enterprise account to an industrial control system without tripping a single alert. 

How convergence changes the attack surface

CPS were often built in an era when operational technology (OT) ran on proprietary protocols and isolated networks. Security was achieved partly through obscurity: if an industrial control network had no connection to the internet, attacking it required physical access. The expansion of network connectivity and the convergence of IT and OT environments ended that model. Many CPS entered the connected world carrying assumptions about isolation that no longer hold, and legacy systems with fixed firmware cycles now sit on networks that adversaries actively probe.

This is the environment that threat actors are actively exploiting. Sophisticated adversaries, including nation-state groups targeting critical infrastructure, have demonstrated the capability and willingness to cross the IT/OT boundary. They leverage trusted access and identity compromise to move laterally from enterprise environments toward industrial control systems, often without triggering the alerts that traditional security tools are tuned to catch.

CPS vs. IoT and OT

How CPS, the Internet of Things (IoT), and OT relate to one another is frequently misunderstood — and the distinctions matter for security strategy. Each category overlaps with the others, but they differ in ways that directly affect how they should be assessed, monitored, and protected.

 IoTOTCPS
Primary functionData collection and exchangeMonitoring and controlling industrial equipmentTight integration of computation with physical processes
Real-time controlRarely requiredOften requiredAlways required
Physical consequence of failureLow to moderateHigh in industrial settingsHigh across all deployments
Network connectivityCore to functionHistorically isolated, increasingly connectedVaries; connectivity expanding rapidly
Security legacyConsumer-grade, often minimalAir-gapped by design, limited patchingMixed; many systems predate modern security practice
ExamplesSmart speakers, fitness trackers, connected thermostatsSCADA systems, PLCs, industrial sensorsSmart grids, autonomous vehicles, surgical robotics, implantable medical devices

As OT systems acquire connectivity and intelligence, the most capable and interconnected among them become cyber-physical systems. The boundary between the three categories continues to blur, but the fundamental risk question remains constant: what happens when this system fails or is attacked, and how severe are the physical consequences?