Protecting America’s Critical Infrastructure: A Shared Responsibility in an Era of Escalating Cyber Threats

A Wake-Up Call for Critical Infrastructure
The recent cyberattacks targeting municipal water facilities across multiple U.S. states serve as another reminder that America’s critical infrastructure remains under constant attack. According to the FBI, Environmental Protection Agency (EPA), and the Cybersecurity and Infrastructure Security Agency (CISA), attackers successfully compromised operational technology (OT) devices, including programmable logic controllers (PLCs), by exploiting Internet-connected systems, changing administrator credentials, and disrupting normal operations. Fortunately, local operators responded quickly by isolating affected systems, restoring backups, and preventing what could have become a significant public health crisis.
While these incidents focused on water treatment facilities, they represent a much larger national security issue. The United States relies on eighteen critical infrastructure sectors that support every aspect of daily life, including communications, energy, transportation, healthcare, financial services, emergency services, chemical facilities, food and agriculture, dams, defense industrial base, government facilities, nuclear reactors, information technology, manufacturing, commercial facilities, and water and wastewater systems. Disruption of any one of these sectors has the potential to create cascading consequences throughout the economy and society.
Unlike many nations where governments own essential infrastructure, approximately 85 percent of U.S. critical infrastructure is owned and operated by private companies. This unique model makes cybersecurity and physical security a shared responsibility requiring close collaboration among industry, federal agencies, state governments, and local operators.
Lessons from the Telecommunications Sector
Having spent more than sixteen years leading Security Operations and Investigations for Cox Communications, one of the nation’s largest telecommunications providers, I witnessed firsthand the complexity of protecting infrastructure that millions of customers depend upon every day. Telecommunications represent one of the most interconnected critical infrastructure sectors because every other sector depends upon reliable communications to operate. Disruption to communications can immediately affect emergency services, hospitals, financial institutions, transportation systems, utilities, and government operations.
Protecting a communications network requires far more than cybersecurity technology alone. Security had to be built into every layer of the organization through a combination of physical protection, cyber defense, personnel security, intelligence gathering, incident response, and executive leadership. Security operations centers monitored threats around the clock while investigators partnered closely with law enforcement to address criminal activity targeting company assets. Access controls, surveillance systems, intrusion detection technologies, background investigations, vendor risk management, and business continuity planning worked together to reduce organizational risk.
Most importantly, security was never viewed as solely an information technology responsibility. It was an enterprise-wide risk management function involving executives, engineers, physical security professionals, legal counsel, compliance officers, business continuity planners, and government partners. That philosophy remains just as relevant today as cyber threats become increasingly sophisticated.
The Growing Threat to Operational Technology
The recent attacks against water treatment facilities illustrate a growing concern surrounding operational technology (OT). For decades, industrial control systems were isolated from external networks. Today’s operational efficiencies increasingly rely upon remote monitoring, cloud connectivity, mobile applications, and Internet-connected devices. While these technologies improve productivity and reduce operational costs, they also expand the attack surface available to adversaries.
Nation-state actors organized criminal enterprises, hacktivists, and ransomware groups increasingly recognize that operational technology presents opportunities to create real-world consequences. Unlike traditional information technology attacks that focus primarily on stealing information, attacks against OT systems can interrupt essential services, damage equipment, disrupt supply chains, or threaten public safety.
The FBI and EPA recommendations following the recent attacks reinforce well-established cybersecurity principles: remove industrial control devices from direct Internet exposure, implement secure gateways and firewalls, require strong authentication, enforce access control lists, and continuously monitor for unauthorized activity. While these controls appear straightforward, implementation can be difficult for small municipalities operating with limited budgets, aging infrastructure, and few dedicated cybersecurity professionals.
Former CISA Director Jen Easterly accurately described this challenge by noting that nation-state adversaries operate on a geopolitical level while defense often rests with small municipal organizations lacking adequate resources. This imbalance highlights why protecting critical infrastructure cannot become solely the responsibility of local operators.
The Role of Federal Policy and Public-Private Partnerships
Fortunately, the United States has developed an extensive framework supporting critical infrastructure protection. Presidential Policy Directive 21 (PPD-21) established national policy for strengthening the security and resilience of critical infrastructure through an integrated approach involving federal agencies and private-sector owners. Complementing PPD-21, the National Infrastructure Protection Plan (NIPP) provides a risk management framework emphasizing resilience, partnership, information sharing, and continuous improvement across all infrastructure sectors.
More recently, the National Cybersecurity Strategy, Executive Order 14028 on Improving the Nation’s Cybersecurity, and sector-specific cybersecurity performance goals have continued strengthening expectations for both government agencies and private operators. CISA now serves as the nation’s central coordinator for cyber defense, providing threat intelligence, vulnerability assessments, incident response assistance, tabletop exercises, and voluntary cybersecurity services to infrastructure owners nationwide. Supplementing CISA is Infra-Gard and FBI led partnership with critical infrastructure operators in the USA.
However, policy alone is insufficient without meaningful implementation. The recommendations recently advanced by the Operational Technology Cybersecurity Coalition deserve thoughtful consideration. These include establishing Binding Operational Directives for operational technology security, expanding federal cybersecurity grants for state and local governments, extending the Cybersecurity Information Sharing Act, and investing in modernization of aging industrial control systems. Such initiatives recognize that cybersecurity is no longer simply an information technology expense but rather a national security investment.
Building Resilience Through Collaboration
Information sharing remains one of the most effective tools available for defending critical infrastructure. Throughout my corporate career, partnerships with the FBI, InfraGard, fusion centers, local law enforcement, industry associations, and peer security professionals frequently provided early warning regarding emerging threats. Security cannot operate in isolation. Organizations that share threat intelligence, lessons learned, indicators of compromise, and best practices collectively improve national resilience.
Equally important is integrating cybersecurity with business continuity and disaster recovery planning. Every organization should assume that prevention will eventually fail. The true measure of resilience is the ability to detect attacks quickly, isolate affected systems, continue essential operations, communicate effectively with stakeholders, and restore services safely. The Minnesota water facilities demonstrated this principle by switching to manual operations while restoring affected systems, preventing disruption of public water supplies.
Critical infrastructure protection must also address the human element. Technology alone cannot defend organizations against phishing, social engineering, insider threats, or poor security practices. Continuous employee awareness training, executive engagement, role-based access controls, vendor risk management, and regular incident response exercises remain essential components of organizational resilience.
Looking Ahead
Artificial intelligence, autonomous systems, cloud computing, and the rapid expansion of the Internet of Things will continue transforming critical infrastructure operations. These innovations offer tremendous opportunities for efficiency and improved service delivery while simultaneously creating new vulnerabilities that adversaries will attempt to exploit. Security professionals must adopt a proactive approach by incorporating security into system design, procurement decisions, software development, and operational planning from the outset.
The recent attacks against America’s water infrastructure should not be viewed as isolated events but rather as warning indicators of an increasingly contested cyber environment. Every one of the nation’s eighteen critical infrastructure sectors faces similar risks. Whether protecting electrical grids, telecommunications networks, transportation systems, healthcare organizations, financial institutions, or water treatment facilities, the underlying objective remains the same: ensuring the continuous delivery of essential services upon which Americans depend.
Protecting critical infrastructure is not solely the responsibility of government, nor can private industry accomplish the mission alone. Success depends upon trusted partnerships, intelligence sharing, regulatory guidance, sustained investment, resilient organizational cultures, and strong executive leadership. As cyber threats continue to evolve, our collective commitment to securing America’s critical infrastructure must evolve even faster. The resilience of our economy, our public safety, and our national security depend upon it.
Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!









