* Identify risks that can kill people. Strongly isolate systems where risk exists. Assume a hostile capability at the StuxNet level.
* Beef up black start capability for energy grids, so that in the event of a major failure, power is 90% back up in an hour. Test this annually.
* Stock up on long lead time items, especially HV grid transformers.
* Systems which handle other people's money must have continuous backups to write-once media and be able to 99% recover from a total loss of online data within 24 hours.
* Telecommunications systems must be capable of a cold restart from a known good state for 90% of users within one hour, 99% within 24 hours.