Practical attack simulations in Critical National Infrastructure (CNI): Oh the perils, or oh the fun?

There are two commonly held perceptions when it comes to CNI security: that they are under constant threat, and that any form of practical security testing is a bad idea. So how can we provide demonstrable assurance that these environments are secure?

