TL;DR
  • The SAFER SKIES Act, signed in December 2025 as part of the FY2026 NDAA, extended limited counter-drone mitigation authority to certified state, local, tribal, and territorial law enforcement for the first time.
  • Mitigation requires a credible threat determination, and the authority expires December 31, 2031. It does not give facility operators the right to take down a drone.
  • NERC has pointed to rising drone activity near substations and generating plants, including drones used to map sites and test response times. Detection without a workable response plan does not reduce risk.

For years, the honest answer to "what can we do about a drone over our facility" was almost nothing. Mitigation authority sat with a short list of federal agencies. Everyone else could watch, document, and call someone.

That changed in December 2025, and most facility security plans have not been updated to reflect it.

What the SAFER SKIES Act actually did

The act was signed into law in December 2025 as part of the Fiscal Year 2026 National Defense Authorization Act. It extended limited counter-drone mitigation authority to certified state, local, tribal, and territorial law enforcement agencies for the first time. The authority requires a credible threat determination before any mitigation, and it expires December 31, 2031.

Read the limits as carefully as the grant. This did not give private facility operators authority to interfere with an aircraft, and a drone is legally an aircraft. What it did was make your local law enforcement agency a potentially capable partner rather than a bystander, provided that agency has pursued certification.

That is the practical question for a site plan, and it is answerable with a phone call: has the agency that responds to your facility been certified under this authority, and what does its response actually look like?

The threat is documented, not speculative

NERC has pointed to a rise in drone incidents near substations and generating plants. The pattern of concern is not hobbyists straying off course. Drones are being used to map sites, identify weak points in physical security, and test response times.

The incident record supports treating this as a category rather than an anomaly. In November 2024, the FBI arrested a man who planned to destroy a Nashville electrical substation using a drone armed with C-4. In 2020, a drone was used in an attempt to disrupt the grid by dropping a metal cable across high voltage lines at a Pennsylvania substation. That attempt was unsuccessful. Unauthorized drones have penetrated airspace over military installations including Barksdale Air Force Base, forcing operational disruptions.

A drone does not need to destroy a facility to matter. It only needs to interrupt one. A temporary shutdown at a port, an airport, or a substation moves through supply chains and public confidence well beyond the site itself.

Surveillance is the incursion you will misclassify

The most common category of drone activity is intelligence collection, and it is the one most likely to be logged as a nuisance and forgotten. A drone operating over your perimeter transmitting video to a remote operator is collecting guard positions, patrol timing, and camera coverage.

Treated as a trespass annoyance, it produces an incident note. Treated as pre-operational surveillance, it produces a change to patrol patterns and a report to the people who would need to correlate it with activity at other sites. The classification decision is made by whoever is on shift, which makes it a training question rather than a technology question.

A drone approaching from a mile out at low altitude can be inside the perimeter in under three minutes. At most sites, detect, verify, communicate, and respond takes longer than that.

The timeline problem

That gap is the core of it. Detection capability is often evaluated on whether it sees the drone. The better question is whether detection leaves enough time for any meaningful response before the aircraft has already done what it came to do.

If your response cycle is longer than your detection window, adding sensors improves your incident documentation and nothing else. Closing that gap is procedural work: who has authority to act, who gets called, what gets locked down, and what happens without waiting for confirmation.

What to review this quarter

The gap worth closing

The legal landscape moved in your favor for the first time in years. The operational question it raises is not whether you can buy detection. It is whether your site knows what to do in the three minutes after detection, and whether anyone has ever tested that.

Test the response before you need it.

WorldSafe assesses perimeter and response capability at critical infrastructure sites, and runs the tabletop exercises that surface authority and communication gaps while they are still cheap to fix.

Critical infrastructure security