Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecurityPhysicalPhysical SecurityInfrastructure:Electric,Gas & WaterGovernment: Federal, State and Local

Protecting America’s Critical Infrastructure: A Shared Responsibility in an Era of Escalating Cyber Threats

By Alan Saquella
American flag lit with people
Leif Christoph Gottwald via Unsplash
August 13, 2026

A Wake-Up Call for Critical Infrastructure

The recent cyberattacks targeting municipal water facilities across multiple U.S. states serve as another reminder that America’s critical infrastructure remains under constant attack. According to the FBI, Environmental Protection Agency (EPA), and the Cybersecurity and Infrastructure Security Agency (CISA), attackers successfully compromised operational technology (OT) devices, including programmable logic controllers (PLCs), by exploiting Internet-connected systems, changing administrator credentials, and disrupting normal operations. Fortunately, local operators responded quickly by isolating affected systems, restoring backups, and preventing what could have become a significant public health crisis.

While these incidents focused on water treatment facilities, they represent a much larger national security issue. The United States relies on eighteen critical infrastructure sectors that support every aspect of daily life, including communications, energy, transportation, healthcare, financial services, emergency services, chemical facilities, food and agriculture, dams, defense industrial base, government facilities, nuclear reactors, information technology, manufacturing, commercial facilities, and water and wastewater systems. Disruption of any one of these sectors has the potential to create cascading consequences throughout the economy and society.

Unlike many nations where governments own essential infrastructure, approximately 85 percent of U.S. critical infrastructure is owned and operated by private companies. This unique model makes cybersecurity and physical security a shared responsibility requiring close collaboration among industry, federal agencies, state governments, and local operators.

Lessons from the Telecommunications Sector

Having spent more than sixteen years leading Security Operations and Investigations for Cox Communications, one of the nation’s largest telecommunications providers, I witnessed firsthand the complexity of protecting infrastructure that millions of customers depend upon every day. Telecommunications represent one of the most interconnected critical infrastructure sectors because every other sector depends upon reliable communications to operate. Disruption to communications can immediately affect emergency services, hospitals, financial institutions, transportation systems, utilities, and government operations.

Protecting a communications network requires far more than cybersecurity technology alone. Security had to be built into every layer of the organization through a combination of physical protection, cyber defense, personnel security, intelligence gathering, incident response, and executive leadership. Security operations centers monitored threats around the clock while investigators partnered closely with law enforcement to address criminal activity targeting company assets. Access controls, surveillance systems, intrusion detection technologies, background investigations, vendor risk management, and business continuity planning worked together to reduce organizational risk.

Most importantly, security was never viewed as solely an information technology responsibility. It was an enterprise-wide risk management function involving executives, engineers, physical security professionals, legal counsel, compliance officers, business continuity planners, and government partners. That philosophy remains just as relevant today as cyber threats become increasingly sophisticated.

The Growing Threat to Operational Technology

The recent attacks against water treatment facilities illustrate a growing concern surrounding operational technology (OT). For decades, industrial control systems were isolated from external networks. Today’s operational efficiencies increasingly rely upon remote monitoring, cloud connectivity, mobile applications, and Internet-connected devices. While these technologies improve productivity and reduce operational costs, they also expand the attack surface available to adversaries.

Nation-state actors organized criminal enterprises, hacktivists, and ransomware groups increasingly recognize that operational technology presents opportunities to create real-world consequences. Unlike traditional information technology attacks that focus primarily on stealing information, attacks against OT systems can interrupt essential services, damage equipment, disrupt supply chains, or threaten public safety.

The FBI and EPA recommendations following the recent attacks reinforce well-established cybersecurity principles: remove industrial control devices from direct Internet exposure, implement secure gateways and firewalls, require strong authentication, enforce access control lists, and continuously monitor for unauthorized activity. While these controls appear straightforward, implementation can be difficult for small municipalities operating with limited budgets, aging infrastructure, and few dedicated cybersecurity professionals.

Former CISA Director Jen Easterly accurately described this challenge by noting that nation-state adversaries operate on a geopolitical level while defense often rests with small municipal organizations lacking adequate resources. This imbalance highlights why protecting critical infrastructure cannot become solely the responsibility of local operators.

The Role of Federal Policy and Public-Private Partnerships

Fortunately, the United States has developed an extensive framework supporting critical infrastructure protection. Presidential Policy Directive 21 (PPD-21) established national policy for strengthening the security and resilience of critical infrastructure through an integrated approach involving federal agencies and private-sector owners. Complementing PPD-21, the National Infrastructure Protection Plan (NIPP) provides a risk management framework emphasizing resilience, partnership, information sharing, and continuous improvement across all infrastructure sectors.

More recently, the National Cybersecurity Strategy, Executive Order 14028 on Improving the Nation’s Cybersecurity, and sector-specific cybersecurity performance goals have continued strengthening expectations for both government agencies and private operators. CISA now serves as the nation’s central coordinator for cyber defense, providing threat intelligence, vulnerability assessments, incident response assistance, tabletop exercises, and voluntary cybersecurity services to infrastructure owners nationwide. Supplementing CISA is Infra-Gard and FBI led partnership with critical infrastructure operators in the USA.

However, policy alone is insufficient without meaningful implementation. The recommendations recently advanced by the Operational Technology Cybersecurity Coalition deserve thoughtful consideration. These include establishing Binding Operational Directives for operational technology security, expanding federal cybersecurity grants for state and local governments, extending the Cybersecurity Information Sharing Act, and investing in modernization of aging industrial control systems. Such initiatives recognize that cybersecurity is no longer simply an information technology expense but rather a national security investment.

Building Resilience Through Collaboration

Information sharing remains one of the most effective tools available for defending critical infrastructure. Throughout my corporate career, partnerships with the FBI, InfraGard, fusion centers, local law enforcement, industry associations, and peer security professionals frequently provided early warning regarding emerging threats. Security cannot operate in isolation. Organizations that share threat intelligence, lessons learned, indicators of compromise, and best practices collectively improve national resilience.

Equally important is integrating cybersecurity with business continuity and disaster recovery planning. Every organization should assume that prevention will eventually fail. The true measure of resilience is the ability to detect attacks quickly, isolate affected systems, continue essential operations, communicate effectively with stakeholders, and restore services safely. The Minnesota water facilities demonstrated this principle by switching to manual operations while restoring affected systems, preventing disruption of public water supplies.

Critical infrastructure protection must also address the human element. Technology alone cannot defend organizations against phishing, social engineering, insider threats, or poor security practices. Continuous employee awareness training, executive engagement, role-based access controls, vendor risk management, and regular incident response exercises remain essential components of organizational resilience.

Looking Ahead

Artificial intelligence, autonomous systems, cloud computing, and the rapid expansion of the Internet of Things will continue transforming critical infrastructure operations. These innovations offer tremendous opportunities for efficiency and improved service delivery while simultaneously creating new vulnerabilities that adversaries will attempt to exploit. Security professionals must adopt a proactive approach by incorporating security into system design, procurement decisions, software development, and operational planning from the outset.

The recent attacks against America’s water infrastructure should not be viewed as isolated events but rather as warning indicators of an increasingly contested cyber environment. Every one of the nation’s eighteen critical infrastructure sectors faces similar risks. Whether protecting electrical grids, telecommunications networks, transportation systems, healthcare organizations, financial institutions, or water treatment facilities, the underlying objective remains the same: ensuring the continuous delivery of essential services upon which Americans depend.

Protecting critical infrastructure is not solely the responsibility of government, nor can private industry accomplish the mission alone. Success depends upon trusted partnerships, intelligence sharing, regulatory guidance, sustained investment, resilient organizational cultures, and strong executive leadership. As cyber threats continue to evolve, our collective commitment to securing America’s critical infrastructure must evolve even faster. The resilience of our economy, our public safety, and our national security depend upon it.

KEYWORDS: critical infrastructure critical infrastructure cybersecurity critical infrastructure security geopolitical risk national security operational resilience operational security

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Alan

Alan Saquella, CPP, is an influential security and investigations expert with more than 30 years of security and investigations experience in corporate and public organizations at the executive level. He served for many years as the Security Operations and Investigations Director at Cox Communications before assuming his current role as a faculty team member at Embry-Riddle Aeronautical University — College of Business, Security and Intelligence. Saquella is also the Director, Investigations and Research at Verensics and a Member of the Identity Theft Advisory Board. Image courtesy of Saquella

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Cyber tech background

    Security’s Top Cybersecurity Leaders 2026

    Security magazine’s Top Cybersecurity Leaders 2026 award...
    Cybersecurity
  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Career Intelligence
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • Northland Controls sponsored content
    Sponsored byNorthland Controls

    The Execution Gap: Why Great Security Design Doesn't Always Deliver Great Security

Popular Stories

Cargo ship sailing

You Can’t Secure a Ship Like a Laptop

Photograph of apartment complex patios

Enhancing Residential Building Security

2026 Women in Security

Security’s 2026 Women in Security

Trust

Building Public Trust in AI‑Enabled Security

Northland Controls sponsored content

The Execution Gap: Why Great Security Design Doesn't Always Deliver Great Security

Kaseware sponsored webinar
Schneider Electric sponsored webinar

Events

August 19, 2026

From Investigative Question to Defensible Answer: AI in Digital Forensics and Incident Response

LIVE: August 19, 2026 at 2 PM EDT We'll examine where AI can deliver meaningful value, where incomplete context or black-box reasoning can introduce risk, and what governance, validation, and evidence-traceability controls organizations should establish.

August 25, 2026

Critical Infrastructure Security Is National Security: Protecting Essential Operations in an Era of Escalating Risk

LIVE: August 25, 2026 at 2 PM EDT Learn why critical infrastructure security has become a national security imperative, and the strategies organizations can adopt to improve visibility, collaboration, and response across their security operations.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products


Alertmedia sponsored webinar

Related Articles

  • Domestic critical infrastructure is arguably now more at risk than at any point in living memory, and certainly in a peacetime context.

    Protecting critical infrastructure and distributed organizations in an era of chronic cybersecurity risk

    See More
  • Lightbulb on blue background

    The Great Security Culture Shift: Building a Proactive Defense in an Era of Advanced Threats and Social Engineering

    See More
  • Man walking with briefcase

    The Rising Tide of Executive Protection: Corporations Ramp Up Security in an Era of Heightened Threats

    See More

Related Products

See More Products
  • 150952519X.jpg

    Intelligence in An Insecure World, 3rd Edition

  • 1119490936.jpg

    Solving Cyber Risk: Protecting Your Company and Society

  • physical security.webp

    Physical Security Assessment Handbook An Insider’s Guide to Securing a Business

See More Products

Events

View AllSubmit An Event
  • August 25, 2026

    Critical Infrastructure Security Is National Security: Protecting Essential Operations in an Era of Escalating Risk

    LIVE: August 25, 2026 at 2 PM EDT Learn why critical infrastructure security has become a national security imperative, and the strategies organizations can adopt to improve visibility, collaboration, and response across their security operations.
  • April 30, 2026

    Building a Campus-Wide Culture of Security and Shared Responsibility

    ON DEMAND: In today’s higher education environment, where institutions face evolving & multifaceted incidents, safety must be embedded into the fabric of campus culture. Learn strategies for generating collective buy-in from faculty, staff, students & senior leadership. 
View AllSubmit An Event
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing