With water systems in at least 12 States targeted by cyber attacks in the summer of 2026 alone, strikes on critical infrastructure are front page news. These recent incidents may be getting a lot of visibility, but adversarial targeting of water, energy, healthcare and other critical infrastructures is a continual long-term challenge.
In its 2026 Annual Threat Assessment of the U.S. Intelligence Community report, the Office of the Director of National Intelligence described ongoing cyber activity by nation-state adversaries attempting to compromise U.S. critical infrastructure interests. Threats of this nature have been included in the report since 2008. Among the current findings:
- Iran poses a threat to U.S. networks and critical infrastructure in the form of cyber espionage and cyber attacks. The report noted that on March 11 Iranian-linked hackers claimed responsibility for a cyber attack against a U.S. medical technology company in retaliation for U.S. attacks against Iran. While not confirmed as of this writing, Iran is largely believed to be responsible for the series of attacks on water systems as well as attacks on automatic tank gages at gas stations throughout the U.S., with activity escalating since the start of the war in February.
- China is the most active and persistent cyber threat to U.S. Government, private-sector, and critical infrastructure networks, while Russia poses a persistent, advanced cyber attack and foreign intelligence threat. Both countries are continuing their R&D and pre-positioning efforts to advance their premier cyber-attack capabilities for use against the U.S.
- North Korea is capable of and sets strategic objectives for conducting espionage, cybercrime and cyber attacks against diverse targets; North Korean cyber actors’ expansion of ransomware attacks and other cybercriminal activities increase the disruptive threat to U.S. IT systems and critical infrastructure entities.
The DNI holds that cyber actors from these nations and other ransomware groups have the ability to pre-position or execute disruptive and destructive attacks that pose serious threats to U.S. networks and critical infrastructure.
The FBI’s IC3 Annual Report 2024 confirms the danger, noting that its Internet Crime Complaint Center received 4,878 cyber threat complaints from organizations across U.S. critical infrastructure sectors―with total ransomware complaints hitting 3,156, up 9% from 2023.
This unsettling reality leaves us dangerously exposed. It simply makes sense to leverage cyberattacks against critical infrastructure as a modern foundational aggression strategy: disrupting power generators, transformers and water sources will certainly weaken the hearts and minds of an opponent’s warfighters and citizens.
In response, leaders from the U.S. government, military and private sector must collaborate on a multi-step defense plan that’s specifically designed for our most essential CI/OT assets:
- Establish fortified communications: Because our networks are so interconnected, users representing different operations and security clearances need to exchange information in real-time. Because the risk of compromising the information remains significant, leaders should strongly consider deploying cross domain solutions (CDS) in these situations.
A proven tool in optimal network segmentation, a CDS delivers what is essentially a ‘firewall with superpowers.’ Two different users with two different security clearances from two different domains can access and transfer information safely. By establishing a fortified wall between separate trust domains, a CDS automatically transfers sanitized, relevant and appropriate intelligence directly to the right users in real-time without putting data at risk.
- Reinforce with data diodes: Hardware-based data diodes often support CDS capabilities, providing unidirectional protection for high-risk zones while preventing reverse data flow. Because data diodes are hardware-based, they are more resistant to the threats that expose software-based systems.
- Ensure accountability: While OT and IT systems were traditionally kept separated, critical infrastructure operators rightfully want the operational efficiency, real-time insights, predictive maintenance and economic benefits of connecting them. Even though CDS and data diodes can make this connectivity happen safely, those managing the OT vs. IT sides are often reluctant to accept the responsibility. There’s a need for senior-most leadership in these organizations to make the determination, set the direction and define policies that keep both OT and IT engaged and accountable for security hygiene.
Today’s cyber threats are at a more troublesome level than we have seen before. Our adversaries are more capable, and perhaps more willing than ever, to engage in proactive aggression that leverages any and all emerging technologies to disrupt vital critical infrastructure systems.
Incorporating a multi-layered defense plan that includes the deployment of CDS and data diodes for maximum information-exchange assurance will be a major step in protecting the infrastructure we all depend on.
This is an updated version of an article that originally appeared in SC Media. Read the original here: Three Ways We Can Protect U.S. Critical Infrastructure
Scott Orton is chief executive officer, Owl Cyber Defense