1. Learn
  2. Align
  3. Perform
  4. Review

LearnCritical Infrastructure, part 2 of 38 min read

What Every Power Company Security Team Should Know About Critical Infrastructure Threats

By J Damien Scott, Trusted Advisor

Every security professional understands that threats change. What deserves closer attention is how the threat landscape for energy sector critical infrastructure has evolved from isolated criminal acts into coordinated, ideologically motivated campaigns targeting the physical and cyber systems that sustain national power generation and distribution.

The evolving threat to energy infrastructure

Critical infrastructure in the energy sector faces a threat environment that has fundamentally shifted over the past decade. What was once primarily a concern about opportunistic theft or vandalism has evolved into a landscape characterized by ideologically motivated domestic extremism, state-sponsored cyber operations, and coordinated physical attacks designed to cause cascading failures across interconnected systems.

The attacks on electrical substations across the United States, including the 2022 Moore County incident in North Carolina and subsequent copycat attempts, demonstrated that relatively unsophisticated physical attacks can cause widespread service disruptions affecting hundreds of thousands of customers. These incidents revealed vulnerabilities in the protection of transformer infrastructure that takes months or years to replace.

The convergence of physical sabotage and cyber intrusion against energy infrastructure is not a theoretical risk. It is an operational reality that demands a unified security response.

Regulatory frameworks and compliance obligations

Energy sector security teams operate within a complex regulatory environment defined by NERC-CIP standards for bulk electric system cybersecurity, CFATS for chemical facility anti-terrorism, and MTSA for maritime transportation security where applicable. These frameworks establish minimum security requirements, but compliance alone does not constitute security. The gap between regulatory compliance and actual operational resilience represents the space where sophisticated threat actors operate.

Security leaders in the energy sector must understand that these regulatory frameworks were designed to establish baseline protections, not to address the full spectrum of modern threats. A security program built solely around compliance checkboxes will satisfy auditors while remaining vulnerable to adversaries who study the same public standards to identify gaps and exploit the predictability of compliance-driven security postures.

Building resilience beyond compliance

Effective critical infrastructure protection requires a security architecture that integrates physical security, cybersecurity, and intelligence functions into a unified operational framework. The traditional organizational separation between IT security, OT security, and physical security creates seams that adversaries exploit. A coordinated attack that combines a cyber intrusion into SCADA systems with physical surveillance of response procedures requires a converged security response.

Security teams should establish intelligence-sharing relationships with sector-specific ISACs, maintain active coordination with FBI and DHS field offices, and develop internal threat assessment capabilities that can evaluate both the physical and cyber dimensions of emerging threats. The goal is not merely to harden individual assets but to build organizational resilience: the capacity to detect, absorb, adapt to, and recover from disruptions while maintaining essential functions.

Converged SecurityNERC-CIP compliancePhysical-cyber convergenceThreat evolution

Originally published on LinkedIn. Read it there

Field Notes · by email

One email when a new article publishes. Nothing else.

Field notes on converged security from J Damien Scott, Trusted Advisor: the article, its summary, and the phase it belongs to. No digests, no offers, no third party reading over your shoulder.

Email delivery is being set up. The feed carries every article the day it publishes. About Field Notes

Related reading

All articles