TL;DR
  • Critical infrastructure operators are heavily regulated, and compliance documentation is often mistaken for security.
  • Regulations set a floor. Determined adversaries plan against the floor, because the floor is published.
  • The gap is rarely the perimeter. It is detection, response time, and the assumptions made about insider and vendor access.

Operators of critical infrastructure carry a compliance burden most industries never see. NERC CIP for the bulk electric system. TSA security directives for pipelines. Sector-specific requirements layered on top of state and local rules. Meeting them takes real effort, and the documentation that proves compliance is substantial.

That documentation is necessary. It is also where a dangerous assumption takes hold: that a facility which is compliant is a facility which is secure. Those are different claims, and the gap between them is where incidents happen.

Compliance is a floor, not a program

A regulation describes the minimum an operator must do. It is written to be auditable, which means it is written to be general enough to apply across many sites. Your facility is specific. Its terrain, its access points, its neighbors, its staffing, and its history are not captured in a standard that has to fit every operator in the sector.

Meeting the standard means you have cleared the floor. It does not mean you have addressed the risks specific to your site, because the standard was never designed to find them.

What a determined adversary plans against

There is a second problem with treating compliance as security. The requirements are published. An adversary planning against a regulated facility can read the same standard you comply with and assume you have done exactly what it requires, and no more. Compliance, by itself, makes your defenses predictable.

A perimeter tells an adversary where the line is. What matters is what happens in the ninety seconds after they cross it.

The perimeter is not the problem

When we assess critical infrastructure sites, the perimeter is usually the part that has received the most attention. Fencing, gates, signage, and cameras are typically in place, because they are visible and they map cleanly to requirements. The gaps are further in.

Detection and response time

For a critical facility, the question that matters is not whether someone can get over the fence. Someone determined can. The question is how quickly you know, and how quickly you respond. A perimeter that delays an intruder by ninety seconds is only useful if those ninety seconds trigger a response that arrives in time to matter.

Most operators have never tested this end to end. They know the alarm works. They have not measured the full sequence from breach to detection to response under realistic conditions. That measurement is where real resilience is built or found wanting.

Insider access and the vendor question

The perimeter is built to stop outsiders. A significant share of risk at critical facilities comes from people who are already inside the line: employees, contractors, and vendors with legitimate access. Maintenance crews, integrators, and service providers move through secured areas routinely, often with credentials that were issued once and never reviewed.

A serious assessment looks hard at this. Who has access, why, when it was last verified, and what they could reach. For regulated operators, the insider and vendor pathway is frequently the least examined part of the program, precisely because it does not feel like a threat. That is what makes it one.

Sources and further reading

Resilience for operations that cannot go down.

WorldSafe assesses critical facilities against the threats specific to your site, then builds the ongoing program that keeps pace through RaaS.

Learn about RaaS
About the author
Joe Heinzen
CEO & Founder, WorldSafe

Joe founded WorldSafe in 2022 to bring enterprise-grade security intelligence and resilience planning to organizations of all sizes. Before WorldSafe, he served as VP of Public Safety at LiveSafe, working with enterprises, universities, and government agencies on real-time safety and threat communication. His earlier career includes security consulting at Neustar and enterprise technology leadership at Oracle.

Security TechnologyCrisis ManagementEnterprise SafetyBusiness Continuity
LinkedIn