
I would say — take what you just said about Fable. What they were mainly worried about is high-level vulnerability discovery capability. Critical infrastructure is asymmetric in offence and defence: the attacker finds one kill chain, even one vulnerability, and succeeds; the defender must guard everything. Since Nick Bostrom at Oxford, people have generally held that in this situation you want defenders to get advanced capability for a period first — confirm the vulnerabilities you see, punch holes in your own systems, patch everything — rather than letting hostile forces that favour the attacker get that capability from the start, or global critical infrastructure is in trouble.