‘Fire Sale’ as in Die Hard 4.0: cinematic fantasy or real threat?

In the film “Die Hard 4.0”, the attackers’ grand finale is called “Fire Sale” – a made-up term, but a very apt metaphor for modern attacks on critical infrastructure. In this article, we use this scenario to illustrate just how interconnected our world has become, what chain reactions are realistically possible today, and why operators must act by implementing NIS2, technical measures and a clear security strategy before fiction becomes reality.

Category
KRITIS & NIS2
Topic
Fire Sale scenario & critical infrastructure
Audience
KRITIS operators & security managers
Reading time
approx. 9 minutes

In the film, attackers take control of transport systems, financial infrastructure and energy supplies one after the other, plunging an entire country into chaos. What was intended as an action film no longer seems so far removed from reality in 2026, because more and more critical systems are being digitised, networked and can be controlled remotely.

For organisations involved with KRITIS systems, this is an uncomfortable truth: explosives are no longer needed to paralyse infrastructure; often, all it takes is a compromised account, a vulnerability in remote maintenance or a poorly segmented network. The film merely exaggerates what could, at least in part, be technically replicated today using purely digital means.

‘Fire Sale’: a Hollywood term, but a real attack strategy

In the film, the ‘Fire Sale’ is explained as a three-stage attack: first transport, then financial systems, then the utilities infrastructure – ‘Everything must go’. The term originally comes from US English, where it means ‘clearance sale’, and is not an official attack model in cybersecurity. Nevertheless, the underlying logic describes much of what we see in real-world campaigns today.

Modern threat actors do not plan isolated individual attacks, but rather coordinated campaigns. First, an entry point is found, for example via Phishing or a vulnerability. Permissions are then expanded, further systems compromised and, finally, targeted attacks are launched against areas whose failure would have far-reaching consequences. In the real world, we speak of hybrid threats, combined cyber-physical impacts and attacks on entire industries or states; however, the basic idea of a ‘fire sale’ with successive stages remains recognisable.

Everything connected to the network today: from traffic lights to gas pipelines

Many elements that are dramatised in the film have long since become part of everyday life. Traffic lights, tunnels, pipelines, power stations, waterworks and logistics centres are operated via digital control systems and communication networks.

  • Energy: Electricity grids, substations, gas compressors and pipelines rely on SCADA and ICS systems, as well as telecontrol technology, which is increasingly IP-based.
  • Water and wastewater: Waterworks, pumping stations and sewage treatment plants use digital control systems and remote management. Attacks can directly compromise quality, availability and safety.
  • Transport: Traffic management systems, traffic lights, railway signalling systems and tunnel technology are connected to control centres via data networks.
  • Digital infrastructure: Data centers, Cloud platforms, internet nodes, DNS and telecommunications networks are themselves defined as critical infrastructure.

These systems are interlinked. Traffic lights and transport systems depend on communication networks and electricity; waterworks on energy and control IT; and logistics on IT systems, wireless networks and Cloud services. Every additional connection is a potential point of attack or another point where a fault can trigger a chain reaction.

When one failure brings everything else down: interdependencies

The real horror of a ‘fire sale’ lies in the interdependencies between infrastructures, not in the failure of a single system.

Energy is considered a ‘super-critical’ sector: if the power goes out, waterworks, petrol stations, refrigeration systems, IT systems, telecommunications and logistics will function only to a limited extent, if at all.

Digital infrastructures are equally critical. Without functioning networks, DNS, Cloud platforms and data centers, control centres lose telemetry and remote control capabilities, even if the physical facilities themselves remain intact. This is particularly evident in the food supply chain. Production, processing, storage, refrigeration and transport are all controlled by IT. If this fails, supply problems arise within a matter of hours or days.

A ‘fire sale’-like scenario does not, therefore, necessarily mean that everything is compromised simultaneously. It is sufficient for a central sector – such as energy, the network or identity systems – to be affected, with other sectors being dragged into the maelstrom due to their interdependencies.

NIS2: Regulation to counter the ‘fire sale’ scenario

The NIS2 directive and its implementation in Germany are designed to address precisely these systemic risks. It requires essential and important operators in sectors such as energy, transport, drinking water supply, wastewater, healthcare, digital infrastructure, public administration and parts of the food supply chain to maintain an appropriate, risk-based level of security.

Key requirements include:

  • Risk management and vulnerability handling: systematically identifying, assessing and addressing risks with appropriate measures.
  • Technical and organisational measures: for example, access control, network segmentation, patch management, Monitoring and backup strategies.
  • Incident handling and reporting obligations: Detecting, analysing, reporting and dealing with security incidents in a structured manner.
  • Business continuity and resilience: plans and capabilities to maintain operations during disruptions or to perform recovery quickly.

Particularly in the context of the food supply chain – for instance, in production facilities, warehouses and cold chains – NIS2 makes it clear that IT and OT security are not merely ‘nice-to-haves’, but are directly linked to security of supply. A ‘fire sale’-like scenario is precisely what this regulation aims to prevent.

When everything collapses: what really matters in a crisis

When several critical systems fail simultaneously, the focus shifts from protection to survival in crisis mode. What is crucial then is a well-rehearsed emergency response organisation with clear roles, responsibilities and decision-making processes; emergency manuals that are also available offline; defined priorities such as energy, water, medical care, food and public safety; and technical resilience through segmented networks, offline backups, redundant communication channels and manual operating modes.

The aim is not to prevent every incident, but to ensure that an attack does not trigger an uncontrollable domino effect. Drills, crisis management team training and technical tests are just as important as Firewalls and patches. Without these preparations, the response in an emergency becomes nothing more than improvisation.

How Mint Secure supports you

The ‘Fire Sale’ from *Die Hard 4.0* is a Hollywood construct, but as a metaphor for the vulnerability of our networked infrastructures, it is alarmingly apt. Each of the areas described above can be linked to specific measures, where we, as a specialist security service provider, can offer support.

1

Understanding the status quo

The question of how close we already are to the film’s scenario can only be answered if we know our own current situation. This is where NIS2 audits and security assessments come in, as they evaluate the security organisation, processes and technology against current requirements and threat landscapes.

2

Realistically test attack chains

Multi-stage, campaign-style attacks cannot be assessed using isolated, one-off measures. Through red teaming and penetration testing, we can realistically simulate precisely such attack chains – from the initial point of entry right through to critical areas – and highlight where defence lines are currently too weak.

3

Securing interconnected infrastructure

Whilst it is technically necessary for traffic lights, waterworks, pipelines, control centres and Cloud platforms to be interconnected, this must not become a point of entry. Security assessments and architecture reviews help to neatly segment IT and OT networks, secure remote access and harden critical interfaces. In addition, targeted M365 hardening ensures that identities and collaboration services do not become a backdoor into the control room.

4

Identifying interdependencies

Chain reactions occur where single points of failure and unrecognised dependencies exist. Through joint analyses and tests, we help to identify precisely these critical paths – for example, by explicitly simulating and assessing the failure of identity services, Firewalls or Cloud services in red team scenarios.

5

Putting NIS2 into practice

NIS2 stipulates what needs to be done, but not how to implement it in a practical way. We provide support in translating regulation into practice, through NIS2 audits, in setting up or further developing an ISMS, and in establishing risk management, vulnerability management and Incident Response processes.

6

Training for crisis response

The best prevention is worthless if, in an emergency, nobody knows what to do. Through red teaming, crisis exercises and the review of contingency and recovery plans, we help bridge the gap between theory and practice, including how to communicate securely in a crisis and how to ensure that M365-based communication channels are set up to support the response rather than hinder it.

“The film depicts the escalation over 120 minutes. In reality, it is a process lasting years that determines whether organisations are vulnerable to fire sales or can absorb attacks in a controlled manner.”
Mint Secure GmbH

How do you measure up against the film’s scenario? We’ll assess your current situation against the latest threat landscape. Get in touch.

Conclusion

The film depicts the escalation over 120 minutes; in reality, it is a process that takes years.

This process determines whether organisations are vulnerable to fire sales or can mitigate attacks in a controlled manner.

Our role is to provide expert support throughout this process, from the initial assessment through targeted hardening measures to the development of effective crisis management capabilities. Talk to us.