Why Protecting Critical Infrastructure Security Requires a Military Mindset
Key Highlights
- Critical infrastructure is increasingly targeted by nation-states and opportunistic actors using AI-enhanced cyber tactics, demanding advanced preparedness.
- Traditional security measures are insufficient; organizations must develop deeper visibility, anomaly detection, and contingency plans to ensure operational continuity.
- Military principles like redundancy, manual workflows, and isolation are vital for civilian infrastructure resilience in the face of cyber disruptions.
- Cross-functional, role-based training and exercises are essential to empower teams to act swiftly and effectively during cyber crises.
- Future resilience depends on adopting wartime-level readiness, focusing on survivability, adaptability, and mission continuity over mere prevention.
The uninterrupted connectivity of critical infrastructure is foundational to today’s society, from hospitals to telecommunications, energy grids, and more. Foreign adversaries see this as an opportunity.
Cyber operations are increasingly shaping national security and strategic competition, and recent regulatory actions like CISA’s CI Fortify initiative show how essential emergency planning is in the face of geopolitical cyberattacks. In fact, planning is now less about traditional cybersecurity pillars and more about adopting wartime-style continuity and contingency operations.
Many national security experts now view cyber operations as a likely first phase of conflict between nation states. These cyberattacks are a precursor to kinetic operations on the battlefield, designed to create advantage in three ways. First is friction, intended to disrupt communications and remove advantages of cyber capabilities; second is chaos to hinder coordination; and third is psyops to create confusion and undermine confidence in institutions.
Military organizations have long prepared for contested and degraded environments where communications may fail from these efforts - or worse, infrastructure is destroyed completely. Critical infrastructure operators now face a similar reality. Attack prevention is no longer sufficient, especially when cyber adversaries are boosted by AI, unlimited resources and funding.
The real challenge is planning for and continuing operations when facing a real-life cyberattack.
How Cyber Warfare is Now Modern Battlefield Preparation
Threat actors are no longer solely focused on catastrophic outages. The days of “go loud” cyberattacks are fewer, as nation-state cyber operations mirror military battlefield strategies that create operational friction and uncertainty before or during conflict. So, what does this look like?
Oftentimes, the disruptions are designed to be easy to mistake for internal misconfigurations or technical failures, and difficult to troubleshoot. These “ghosts in the network” scenarios are what start to slow operations and delay response efforts.
Countries like Russia and China have deeply integrated cyber warfare into their broader military, intelligence, economic and information campaigns. Russian cyber activity has frequently emphasized disruption and psychological impact, where Chinese operations have historically focused more on long-term access, strategic positioning and persistent infiltration of critical systems.
This mindset is not just limited to nation-state actors. Hacktivist groups and opportunistic threat actors increasingly view essential services as strategic targets too, often launching retaliation attacks in response to geopolitical conflicts.
We are at a critical juncture of geopolitical tension and AI advancement, creating an opportunity for maximum impact. Now armed with AI, these attackers can accelerate and scale their efforts. AI can help automate reconnaissance, mimic legitimate user behavior, and improve other tactics like vulnerability discovery and phishing.
Countries like Russia and China have deeply integrated cyber warfare into their broader military, intelligence, economic and information campaigns. Russian cyber activity has frequently emphasized disruption and psychological impact, where Chinese operations have historically focused more on long-term access, strategic positioning and persistent infiltration of critical systems.
The result? Critical infrastructure has never been more at risk.
Why Critical Infrastructure is Especially Vulnerable to Attack
Critical infrastructure systems were never designed for today’s threat landscape. Oftentimes, OT and industrial systems are built around legacy environments and tooling that is not easily patched or modernized. Many of these systems must remain operational 24/7 and cannot be taken down for maintenance like patching or rebooting.
For example, hospitals model how operational realities complicate cybersecurity. Medical devices and healthcare systems often cannot be taken offline without impacting patient care. This creates significant challenges for patching, upgrades, and routine security maintenance, so these tasks are often left by the wayside and contribute to mounting technical debt.
Limited tolerance for downtime is reflected across critical infrastructure, compounded by visibility challenges. Reliance on interconnected vendors and third-party services adds complexity; weak supply chain visibility and IT staffing shortages create the perfect storm for potential cascading operational impacts.
In the context of these longstanding vulnerabilities, critical infrastructure operators must consider that “disconnecting to survive” may become a realistic strategy. Military organizations routinely plan for these scenarios by temporarily isolating systems, restricting connectivity, operating manually, or functioning with reduced digital dependencies to preserve essential services.
One of the most critical lessons military contingency planning offers is how to maintain operational continuity when portions of the operating environment are degraded, isolated, or under attack. Redundancy, diversity, decentralized operations, segmentation, fallback communications, manual workflows, and rehearsed continuity procedures have long been foundational principles. Similar concepts must increasingly apply to critical infrastructure cyber resilience.
What Critical Infrastructure Must Do Differently to Endure
First and foremost, critical infrastructure operators need greater visibility inside their digital environment. Perimeter-focused security alone is no longer enough, as cyber adversaries can bypass traditional endpoints and stealthily escalate privileges without detection. This investment must go deeper into what’s actually happening on the network.
Monitoring and detection for IT and OT environments needs to be designed around the idea that attackers have already gained access. This means focusing on what’s happening inside, such as identity movement and behavioral anomalies, to detect suspicious behavior rather than simply watching for intrusion. AI tools can support anomaly detection, threat prioritization, and reduced alert fatigue for short-staffed teams, and are critical to match the pace of adversarial efforts.
In the event of an active cyberattack, there may be a point when access to certain security and AI tools is unavailable. This is when continuity and isolation planning is most essential.
Military organizations approach potential communications degradation through PACE planning (Primary, Alternate, Contingency, Emergency). Tabletop and live exercises can help organizations understand how infrastructure affects services and provide an opportunity to design and practice isolation and restoration priority lists.
Red team assessments and continuity drills will prepare leaders for ambiguity in these scenarios. Understanding the network, how services are delivered, and how important each service delivered is critical and will help decision makers know how to prioritize, take down and restore capabilities. This is the real preparation that tests how teams operate during extended outages, ransomware events, or infrastructure failures.
Military organizations approach potential communications degradation through PACE planning (Primary, Alternate, Contingency, Emergency). Tabletop and live exercises can help organizations understand how infrastructure affects services and provide an opportunity to design and practice isolation and restoration priority lists.
How leadership functions in these moments of contingency is an important marker for true resilience. Critical infrastructure security teams are often small but their role is outsized in these moments, as they must be empowered to act quickly during escalating threats. Delayed decisions, unclear authority, and bureaucratic processes can significantly worsen operational disruption during cyber incidents.
Most importantly, organizations must stop viewing cyber resilience solely as an IT responsibility. Cyber resilience is an operational necessity that requires cross-functional teams to plan, exercise, and act. Role-based, mission-focused training ensures everyone involved at the point of disruption understands what takes priority and what actions they need to take.
Modern Resilience Hinges on Wartime-Level Readiness
For decades, military organizations have understood that survivability depends on preparation before conflict begins. Training, redundancy, contingency planning, and operational discipline cannot be "figured out" during a crisis. The same applies to critical infrastructure resilience.
CISA’s CI Fortify initiative demonstrates a growing understanding that critical infrastructure is a significant target, and that cybersecurity is becoming inseparable from national resilience planning. The cybersecurity conversation can no longer focus exclusively on prevention. Investments must focus on survivability, adaptability, continuity, and operational resilience during disruption.
In the years ahead, the organizations best positioned to succeed will not necessarily be those that prevent every intrusion. They will be the organizations capable of continuing their mission even under contested conditions.
About the Author

Sarah Cleveland
Senior Director of Federal Strategy at ExtraHop
Sarah Cleveland is the Senior Director of Federal Strategy at ExtraHop. She has been working as a career Cyber Officer for over 26 years. Retiring as a Colonel, Sarah has led at the Squadron, Group Commands, and Joint Directorate levels (J6, G6, & A6). She has been responsible for providing cyber operations in garrison and deployed (disadvantaged/disconnected environments). Her operational experience includes combat operations in Iraq, Afghanistan, other areas in the Middle East, as well as training Colombian and Polish Special Operations Forces in communications tactics, techniques, and procedures.
In her final Air Force position, Sarah was responsible for the global NC3 (nuclear) sensor network (operations, maintenance, and sustainment) in support of global nuclear monitoring and other organizations. She oversaw emergency action plans for NC3 Continuity of Operations (COOP) as well as facility management and personnel actions for all Air Force Technical Applications Center sites globally.
