- Learn
- Align
- Perform
- Review
AlignCritical Infrastructure, part 1 of 310 min read
From Guard Gates to Grid Resilience: Why Physical Security Is Now Critical Infrastructure Risk Management
By J Damien Scott, Trusted Advisor
Power-company security has always been about gates, badges, cameras, patrols, and response. But the threat landscape has evolved so fundamentally that physical security must now be understood as critical infrastructure risk management. This article argues that security teams in the electric sector must think in terms of function, consequence, and resilience rather than perimeter alone.
From perimeter to function
Critical infrastructure security in the energy sector has evolved beyond the traditional model of guarding physical perimeters. While access control, surveillance, and patrol remain essential activities, they now sit inside a much larger risk picture. A suspicious vehicle near a substation is not only a trespass issue. A lost badge is not only an access-control problem. A drone sighting is not only an unusual activity report. Each event may have operational, cyber, regulatory, reputational, and public-confidence implications.
CISA defines critical infrastructure as the assets, systems, and networks that provide functions necessary for daily life. For electric utilities, that means security teams must think about consequences, dependencies, and cascading effects. The central question is not only whether someone breached the fence. It is also what function could be affected, who depends on that function, and what decisions must be made now.
“A strong security program does not wait for perfect information. It builds a culture where people report early, share context, ask better questions, and learn from each event.”
Security as a connected system of disciplines
The North American Electric Reliability Corporation's Critical Infrastructure Protection standards address security management controls, personnel and training, electronic security perimeters, physical security of Bulk Electric System Cyber Systems, incident reporting, recovery planning, information protection, supply chain risk management, and physical security. In plain language, electric-sector security is not one discipline. It is a connected system of disciplines.
Security officers and field supervisors often see weak signals before anyone else. They notice changes in patterns. They know which gate is always tested by contractors. They know when a vehicle does not belong. Analysts and managers can connect those observations to threat information, operating conditions, law enforcement reporting, cyber concerns, and business continuity priorities. Executives can use that combined picture to make better risk decisions.
Building resilience in practice
Resilience is the ability to prepare before an incident, absorb pressure during an incident, adapt as facts change, and recover with discipline afterward. The Department of Energy's cybersecurity preparedness guidance emphasizes situational awareness, information sharing, risk analysis, continuous assessment of threats and vulnerabilities, and informed decision-making. Those same habits apply to physical security and converged security.
Instead of asking only whether the site was secured, a resilience-oriented security team asks whether it protected the function the site supports. Instead of asking only whether the procedure was followed, it asks whether the procedure helped people make good decisions under pressure. Instead of asking only whether security handled its part, it asks whether security helped the whole organization manage risk. This is where a Critical Infrastructure Security Book of Knowledge can help connect daily work to the bigger mission.
Originally published on LinkedIn. Read it there
Field Notes · by email
One email when a new article publishes. Nothing else.
Field notes on converged security from J Damien Scott, Trusted Advisor: the article, its summary, and the phase it belongs to. No digests, no offers, no third party reading over your shoulder.
Email delivery is being set up. The feed carries every article the day it publishes. About Field Notes
Related reading
More from Align
Learn · 4 May 2026
What Every Power Company Security Team Should Know About Critical Infrastructure Threats
Every security professional understands that threats change. What deserves closer attention is how the threat landscape for energy sector critical infrastructure has evolved from isolated criminal acts into coordinated, ideologically motivated campaigns targeting the physical and cyber systems that sustain national power generation and distribution.
8 min readReview · 4 May 2026
Building a Security Knowledge Base for the Energy Sector: From Lessons Learned to Better Decisions
Critical infrastructure security teams in the energy sector need more than scattered documents and compliance files. They need a structured Book of Knowledge that consolidates operational experience, regulatory requirements, threat intelligence, and lessons learned into a reasoning-capable resource that supports action under pressure.
9 min readAlign · 22 July 2026
When the Lights Go Out: What ISO 22301 Actually Does for Your Business
ISO 22301 is the international standard for business continuity management. This article explains what it actually requires, why it belongs in the boardroom rather than the risk register, and how to start applying its thinking before you pursue certification.
9 min read