- Critical infrastructure operators are heavily regulated, and compliance documentation is often mistaken for security.
- Regulations set a floor. Determined adversaries plan against the floor, because the floor is published.
- The gap is rarely the perimeter. It is detection, response time, and the assumptions made about insider and vendor access.
Operators of critical infrastructure carry a compliance burden most industries never see. NERC CIP for the bulk electric system. TSA security directives for pipelines. Sector-specific requirements layered on top of state and local rules. Meeting them takes real effort, and the documentation that proves compliance is substantial.
That documentation is necessary. It is also where a dangerous assumption takes hold: that a facility which is compliant is a facility which is secure. Those are different claims, and the gap between them is where incidents happen.
Compliance is a floor, not a program
A regulation describes the minimum an operator must do. It is written to be auditable, which means it is written to be general enough to apply across many sites. Your facility is specific. Its terrain, its access points, its neighbors, its staffing, and its history are not captured in a standard that has to fit every operator in the sector.
Meeting the standard means you have cleared the floor. It does not mean you have addressed the risks specific to your site, because the standard was never designed to find them.
What a determined adversary plans against
There is a second problem with treating compliance as security. The requirements are published. An adversary planning against a regulated facility can read the same standard you comply with and assume you have done exactly what it requires, and no more. Compliance, by itself, makes your defenses predictable.
A perimeter tells an adversary where the line is. What matters is what happens in the ninety seconds after they cross it.
The perimeter is not the problem
When we assess critical infrastructure sites, the perimeter is usually the part that has received the most attention. Fencing, gates, signage, and cameras are typically in place, because they are visible and they map cleanly to requirements. The gaps are further in.
- Detection that depends on someone watching a monitor that no one is watching at 3 a.m.
- Response times that have never been measured against an actual intrusion, only assumed.
- Interior zones that are treated as secure because the perimeter is secure, with no second layer.
- Camera coverage that stops at the fence line and never follows the path an intruder would actually take.
Detection and response time
For a critical facility, the question that matters is not whether someone can get over the fence. Someone determined can. The question is how quickly you know, and how quickly you respond. A perimeter that delays an intruder by ninety seconds is only useful if those ninety seconds trigger a response that arrives in time to matter.
Most operators have never tested this end to end. They know the alarm works. They have not measured the full sequence from breach to detection to response under realistic conditions. That measurement is where real resilience is built or found wanting.
Insider access and the vendor question
The perimeter is built to stop outsiders. A significant share of risk at critical facilities comes from people who are already inside the line: employees, contractors, and vendors with legitimate access. Maintenance crews, integrators, and service providers move through secured areas routinely, often with credentials that were issued once and never reviewed.
A serious assessment looks hard at this. Who has access, why, when it was last verified, and what they could reach. For regulated operators, the insider and vendor pathway is frequently the least examined part of the program, precisely because it does not feel like a threat. That is what makes it one.
Sources and further reading
Resilience for operations that cannot go down.
WorldSafe assesses critical facilities against the threats specific to your site, then builds the ongoing program that keeps pace through RaaS.
Learn about RaaS