TL;DR
  • The SAFER SKIES Act, signed in December 2025 as part of the FY2026 NDAA, extended limited counter-drone mitigation authority to certified state, local, tribal, and territorial law enforcement for the first time.
  • Mitigation requires a credible threat determination, and the authority expires December 31, 2031. It does not give facility operators the right to take down a drone.
  • NERC has pointed to rising drone activity near substations and generating plants, including drones used to map sites and test response times. Detection without a workable response plan does not reduce risk.

For years, the honest answer to "what can we do about a drone over our facility" was almost nothing. Mitigation authority sat with a short list of federal agencies. Everyone else could watch, document, and call someone.

That changed in December 2025, and most facility security plans have not been updated to reflect it.

What the SAFER SKIES Act actually did

The act was signed into law in December 2025 as part of the Fiscal Year 2026 National Defense Authorization Act. It extended limited counter-drone mitigation authority to certified state, local, tribal, and territorial law enforcement agencies for the first time. The authority requires a credible threat determination before any mitigation, and it expires December 31, 2031.

Read the limits as carefully as the grant. This did not give private facility operators authority to interfere with an aircraft, and a drone is legally an aircraft. What it did was make your local law enforcement agency a potentially capable partner, provided that agency has pursued certification.

That is the practical question for a site plan, and it is answerable with a phone call: has the agency that responds to your facility been certified under this authority, and what does its response actually look like?

The threat is documented

NERC has pointed to a rise in drone incidents near substations and generating plants. Drones are being used to map sites, identify weak points in physical security, and test response times.

The incident record supports treating this as a recurring category. In November 2024, the FBI arrested a man who planned to destroy a Nashville electrical substation using a drone armed with C-4. In 2020, a drone was used in an attempt to disrupt the grid by dropping a metal cable across high voltage lines at a Pennsylvania substation. That attempt was unsuccessful. Unauthorized drones have penetrated airspace over military installations including Barksdale Air Force Base, forcing operational disruptions.

Interrupting a facility is enough to matter. A temporary shutdown at a port, an airport, or a substation moves through supply chains and public confidence well beyond the site itself.

Surveillance is the incursion you will misclassify

The most common category of drone activity is intelligence collection, and it is the one most likely to be logged as a nuisance and forgotten. A drone operating over your perimeter transmitting video to a remote operator is collecting guard positions, patrol timing, and camera coverage.

Classified as pre-operational surveillance, it produces a change to patrol patterns and a report to the people who would correlate it with activity at other sites. That classification is made by whoever is on shift, which makes it a training question.

A drone approaching from a mile out at low altitude can be inside the perimeter in under three minutes. At most sites, detect, verify, communicate, and respond takes longer than that.

The timeline problem

That gap is the core of it. Detection capability is often evaluated on whether it sees the drone. The better question is whether detection leaves enough time for a meaningful response before the aircraft has already done what it came to do.

If your response cycle is longer than your detection window, adding sensors improves only your incident documentation. Closing that gap is procedural work: who has authority to act, who gets called, what gets locked down, and what happens without waiting for confirmation.

What to review this quarter

The gap worth closing

The legal landscape moved in your favor for the first time in years. The operational question it raises is whether your site knows what to do in the three minutes after detection, and whether anyone has ever tested that.

Sources and further reading

Test the response before you need it.

WorldSafe assesses perimeter and response capability at critical infrastructure sites, and runs the tabletop exercises that surface authority and communication gaps while they are still cheap to fix.

Critical infrastructure security
About the author
Joe Heinzen
CEO & Founder, WorldSafe

Joe founded WorldSafe in 2022 to bring enterprise-grade security intelligence and resilience planning to organizations of all sizes. Before WorldSafe, he served as VP of Public Safety at LiveSafe, working with enterprises, universities, and government agencies on real-time safety and threat communication. His earlier career includes security consulting at Neustar and enterprise technology leadership at Oracle.

Security TechnologyCrisis ManagementEnterprise SafetyBusiness Continuity
LinkedIn