
The CIPRE Interview with Rodrigo Zúñiga Calvo of IndraMind
Critical infrastructure operators are not short of data. Cameras, physical sensors, operational technology, cybersecurity platforms, drones and external intelligence sources can all detect part of a developing incident. The difficulty is connecting those signals quickly enough to understand what is happening, why it matters and what may happen next.
For Rodrigo Zúñiga Calvo, Head of IndraMind Business Development in Europe, that ability to anticipate is becoming central to resilience. Europe’s infrastructure is increasingly interconnected across sectors and borders. A cyber incident can produce physical consequences; a drone can disrupt an essential service; and a failure affecting energy, telecommunications or transport can spread rapidly into other systems and countries.
Operators are aware of this changing threat environment. The gap lies between awareness and operational readiness. Information often remains fragmented between systems and organisations, making it difficult to build a shared picture and coordinate a response. IndraMind’s approach is to add an intelligence layer that integrates existing sources and turns them into real-time situational awareness, while keeping people responsible for critical decisions.
IndraMind is a Gold Sponsor of CIPRE 2026 and will host an invitation-only breakfast workshop on Wednesday 21 October.
Ben Lane spoke with Rodrigo about hybrid threats, sovereign artificial intelligence, human oversight and the practical cooperation Europe needs to protect interconnected infrastructure.
Ben Lane: Could you begin by telling us about your role and how you came to work with IndraMind in Europe?
Rodrigo Zúñiga Calvo: I joined Indra around a year and a half ago and have been involved with IndraMind from the outset, initially in Barcelona before moving to Brussels.
I am now based there as Head of IndraMind Business Development in Europe, leading our business development activity across the region. My role is very much about translating IndraMind’s capabilities into a European growth strategy — identifying priority markets and opportunities, positioning the company around key European priorities and programmes, and helping turn those into concrete business opportunities.
Before joining Indra, my professional background was international and cross-sectoral. I worked in the Netherlands across the automotive and enterprise software sectors, including a US-listed technology company. That background gave me a useful combination of industrial exposure, enterprise technology and international experience — all highly relevant to IndraMind, which sits at the intersection of AI, security and mission-critical operations.
Being in Brussels gives me a particularly useful perspective because many of the areas we work in — AI, security, defence and critical infrastructure resilience — are increasingly shaped at European level and require cooperation across national borders.
Ben Lane: In your conversations with European infrastructure operators, which risks are moving fastest up the agenda and where is the biggest gap between awareness and readiness?
Rodrigo Zúñiga Calvo: One of the biggest changes is that operators can no longer treat physical security, cybersecurity and operational risk as separate issues. The threat environment is increasingly hybrid. A cyber incident can have physical consequences, a drone can disrupt an essential service, and a problem affecting energy, telecommunications or transport can quickly cascade into other sectors.
There is also a European dimension. Critical infrastructure no longer operates as a collection of isolated national assets. Energy interconnectors and subsea cables between the UK and continental Europe are clear examples. These systems do not stop at national borders, and neither do the consequences of disruption. These interdependencies create enormous value, but they also mean that an incident in one sector or country can have effects far beyond it.
Operators understand that the threat environment has changed. The main challenge is turning that awareness into operational readiness. We already have an enormous amount of information, but much of it remains fragmented across systems and organisations. Resilience depends on integrating that information, understanding its context and turning it into operational intelligence quickly enough to anticipate and respond. It also means accepting that not every incident can be prevented, while ensuring that critical services can continue when something does happen.
Ben Lane: IndraMind describes an approach combining sovereign AI and cyber resilience. What should sovereignty mean in practice for a critical infrastructure operator?
Rodrigo Zúñiga Calvo: The simplest explanation is control over your infrastructure, your data and your intelligence. In the current geopolitical environment, that is more than a technology preference. For critical capabilities, it is increasingly a security requirement.
Control also requires strong data and AI governance. An operator needs to know where sensitive information is processed, who can access it, which technologies the organisation depends on, which models and versions are deployed, which data those models can access, who is authorised to make changes and how their use can be traced and audited. The real test comes during a crisis. If an organisation faces a cyber attack, degraded communications or disruption to its supply chain, it must still be able to understand what is happening, make decisions and maintain essential operations.
Sovereignty cannot mean isolation. Critical infrastructure requires interoperability and secure information sharing between operators, authorities and countries. The objective is sovereignty without creating new silos: retaining control of critical capabilities while remaining able to work as part of a wider European security and resilience ecosystem.
Ben Lane: Many CIPRE delegates manage assets where physical security, operational technology and cybersecurity meet. Where can a shared operational picture make the greatest difference?
Rodrigo Zúñiga Calvo: The biggest difficulty is often not a lack of systems, but the gaps between them. An organisation may already have cameras, physical sensors, operational technology monitoring, cybersecurity platforms, drones and external intelligence sources. Each may be seeing a different part of the same event.
A camera might detect unusual activity while an operational technology system identifies an anomaly, and a cybersecurity platform generates an alert. Individually, none of those signals may explain what is happening. When the information is integrated and correlated in context, the operator can build a common operational picture and begin to anticipate how the situation may develop. Just as importantly, that shared picture gives the teams and organisations involved in the response a common operational reference, so they can coordinate actions, responsibilities and resources more effectively when time matters.
That is where IndraMind comes in. The aim is to add an intelligence layer over the systems an operator already uses, bringing multiple sources together and transforming fragmented information into real-time situational awareness and actionable intelligence. Operators do not need another dashboard producing more alerts. They need to understand what is happening, why it matters, what may happen next and how they should respond.
Ben Lane: AI can help teams interpret huge amounts of information, but operators must be able to trust the decisions that follow. What should they ask a prospective AI partner?
Rodrigo Zúñiga Calvo: The first questions should be simple: can I understand why the system is making this recommendation, and do I remain in control of the decision? In a mission-critical environment, AI cannot operate as a black box. The operator needs to know where the information comes from, how different sources are correlated, how the system has been validated and how it performs when conditions are imperfect. But explainability is only one part of trust; governance matters just as much. Operators should ask how the AI is governed across its full lifecycle — from development and validation through deployment and updates — including roles and permissions, access to data, monitoring and auditability.
That last point is important because critical operations rarely take place under ideal conditions. Data may be incomplete, communications may be degraded and part of the infrastructure may already be compromised. An AI system needs to be designed for that operational reality, rather than judged only by its performance under normal conditions.
AI can analyse large volumes of information, identify patterns, anticipate scenarios and propose courses of action much faster than a person working alone. However, the human must remain in the loop for critical infrastructure decisions. The objective is to shorten the journey from data to understanding and from understanding to action, without removing human accountability. AI should improve an operator’s understanding and ability to act without taking control away.
Ben Lane: Your work involves building relationships across Europe. What makes cooperation between technology providers, infrastructure operators and public authorities effective across borders?
Rodrigo Zúñiga Calvo: Effective cooperation starts with a clear operational problem and an agreed understanding of the role each organisation will play. Technology alone does not create cooperation. Operators bring knowledge of operational reality, public authorities provide the framework and priorities, and industry turns those requirements into capabilities that work in the field.
Trust is fundamental. Organisations need clarity about responsibilities, what information can be shared, who owns the data and who makes the final decision during an incident. Europe also needs to improve its ability to move from discussion into experimentation. A pilot or operational exercise can quickly reveal where the real problems lie. They may be technological, but they are often organisational, regulatory or connected to information sharing.
There is a strategic dimension as well. Genuine European technological sovereignty requires the industrial capacity to design, build and scale critical security technologies in Europe. The strongest models combine operational knowledge, public responsibility and industrial capability, and then test that cooperation through realistic scenarios. Exercises allow us to identify weaknesses and gaps before they are exposed during a real incident.
Ben Lane: IndraMind will host a breakfast workshop at CIPRE 2026. What question would you most like operators and policymakers in the room to tackle together?
Rodrigo Zúñiga Calvo: I would ask a practical question: what information are we missing today that would allow us to detect a developing threat earlier and make a better decision? In many cases, the information already exists somewhere. It may sit with an infrastructure operator, a security team, a public authority, another sector or another organisation. The difficulty is that the right person may not have access to it at the right moment, or the mechanisms do not exist to put the different pieces into context.
Situational awareness does not require collecting everything. It requires identifying which information matters, who needs it, when they need it and under what conditions it can be shared. Technology can correlate signals, identify patterns and provide context, but the organisations involved also need a framework of trust.
A useful outcome from the breakfast would be to identify two or three scenarios in which better information sharing or better correlation of existing information would materially improve anticipation and response. That would give us something practical to develop after the event. Ideally, the discussion would lead to pilots or exercises where the ideas can be tested in realistic conditions.
IndraMind at CIPRE 2026, Brussels, 20–22 October
Hear from IndraMind
IndraMind Breakfast Workshop
Wednesday 21 October, 7.30–8.45am (breakfast included).
Building Trusted Situational Awareness for Critical Infrastructure Protection
Connect fragmented cyber, OT and physical-security signals to support earlier, defensible decisions
At CIPRE 2026, IndraMind Security will host a small executive breakfast focused on a question central to critical infrastructure protection: how can responsible AI and cognitive technologies strengthen situational awareness while keeping human accountability firmly in control?
Drawing on the innovation behind IndraMind’s cognitive engine, the discussion will explore how cyber, OT, physical security and operational signals can be connected to reveal meaningful patterns, assess potential consequences and support earlier action.
Participants will leave with actionable insights on how to apply this approach within their own organisations:
• Where cognitive engines can add value to critical infrastructure protection
• How to design AI with human oversight, traceability and governance
• How to turn augmented situational awareness into defensible operational decisions
This focused exchange will help participants identify practical steps, priorities and conditions for applying responsible AI in critical infrastructure environments.
To register your interest, please contact CIPRE Event Director Neil Walker at neilw@torchmarketing.co.uk
Thursday 22 October, 9.00–10.30am
Jose Ruiz Cristina, IndraMind Security Business Development Director at Indra Group, Spain, will speak in the Technologies to Detect and Protect session:


