At the National Academy on June 10, engineers proposed a licensed signatory for buildings, plants, and grids; the historical forcing function for engineering standards was an insurance product, not a code.
On June 10, 2026, the Cyber Safety Summit opened inside the National Academy of Sciences in Washington, D.C., with a single question on the table: who signs off that a connected building, plant, or grid is safe? The organizers' answer is a discipline that does not yet exist: a licensed cyber safety engineer who would carry the same legal weight as the civil engineer who certifies a bridge or the boiler inspector who certifies a pressure vessel.
The audience for that question is the cyber insurance market, which underwrites billions of dollars in physical-asset risk every year and is, in 2026, actively rewriting what counts as a covered loss.
In the mid-1800s, fatal boiler explosions killed Americans roughly every four days. Engineers, mechanics, and state inspectors argued for years about how to stop them. What forced the change was not a code and not a professional society. Insurance carriers that specialized in boiler coverage built their business around inspecting pressure vessels and refusing to write policies on equipment that failed inspection. The ASME boiler and pressure vessel code, drafted two decades later, codified the inspection regime the insurance industry had already enforced.
The National Academy summit is trying to reproduce that pattern, code as the lagging artifact and insurance inspection as the leading edge, for cyber safety. The summit's framework document, "Cyber Safety Standard of Care for the Built Environment — Framework & Roadmap," is authored by Dr. Georgianna Shea and Lucian Niemeyer. It argues that cyber-physical systems, meaning buildings, hospitals, factories, transit, and consumer devices whose software failures can cause physical harm, have no recognized standard of care and no licensed professional accountable for them.
The framework includes a 90-day action plan with named owners and deadlines, plus a longer roadmap toward professional licensure for a new cyber safety engineering discipline. "The fear is that if a single incident causes a mass casualty event, our profession will be scrambling to develop standards under duress," Brian May, president of federal programs at Michael Baker International, said at the summit. "I believe we must start thoughtfully working this problem now, before we're forced to account for a preventable catastrophe."
The Quebec Bridge collapse in 1907 killed 75 ironworkers after a calculation error and an inexperienced engineering board approved the design. The collapse, and a smaller second failure a year later, helped produce the first U.S. state engineering licensure law in Wyoming in 1907 and seeded the "professional engineer" role that still signs off on bridges, hospitals, and pressure vessels today. That is the shape cyber safety advocates want: a licensed signatory whose name, license, and liability travel with the design.
An insurance product, not a code, would force a cyber safety "engineer of record" into the market. Cyber insurers are already raising rates and tightening terms for industrial control, building management, and operational technology in 2026, and some carriers are starting to require third-party attestations as a condition of coverage. If a major carrier commits in writing to exclusions that name a certified cyber safety engineer as a condition of coverage on a connected building or plant, the framework's 90-day plan meets its forcing function. If the carriers hold back, the framework stays a framework.
A June 2026 preprint from researchers working adjacent to the summit argues along similar lines for a reasonable cyber safety standard of care, though it has not been peer-reviewed. The summit's 90-day action plan runs through early September.