Can DHS Protect the Nation’s Critical Infrastructure Against Cyber Threats?

By COL Charles McGrue

| Gray Space, 2026 E-Edition

Read Time: < 5 mins

A hardened padlock resting on a laptop keyboard bathed in red and green light, symbolizing cybersecurity.

The nation’s critical infrastructure is a sprawling grid of complex nodes and wires that have been around since their inception. With subtle changes over time, some of the critical infrastructure has migrated from analog machines with bells and whistles to digital data centers capable of impacting thousands of people at the flick of a switch. Even though transitions are occurring, the nation’s critical infrastructure is still ill-prepared, outdated, and lacks the protection required to avert a national crisis. Imagine that you are at home and the power goes out. An hour goes by, and it has yet to come back on. You try using your mobile phone to check on the status of the outage, and you are unable to get a cellular signal. You walk over to your neighbor’s house to see if they are having the same problem, only to see other neighbors outside wondering what is going on. Two hours have gone by and there is still no sign of power or cellular phone capabilities. These are impacts that can occur when there are issues with our nation’s critical infrastructure. These issues can cause uncertainty and panic across the nation, but with proper foresight, they can be planned for and avoided.

The Department of Homeland Security (DHS) Cybersecurity and Infrastructure Security Agency (CISA) can adequately support and protect the nation’s critical infrastructure against cyber threats by investing in modernization with industry partners, utilizing highly skilled contract support, and leveraging military resources to address catastrophic events with the appropriate level of concern. If they leverage these three areas of focus, they should be able to increase their ability to defend the country from threats to the homeland.

Investing in modernization and collaborating with industry partners and municipalities nationwide. This will require the U.S. government to spend money on updated equipment and more modern systems to control critical infrastructure in the days of enhanced cyber threats. This funding can be supported by grants, loans, and other means. For example, there are federal infrastructure grants that can be used for various infrastructure projects to help states, tribes, localities, and territories with building out infrastructure (GAO, 2025). Within this funding source, there is a carve out for the CISA under DHS that is focused on “developing and implementing cybersecurity governance and planning, assessing and evaluating systems and capabilities, implementing security protections commensurate with risk, and building the workforce” (FEMA, 2025). This funding can assist tremendously in improving cybersecurity hygiene and culture across the country if it is properly implemented based on its intended purpose. Through proper implementation, CISA can enact a nationwide cybersecurity strategy—starting from the national level down to the municipalities—that supports a robust cybersecurity culture that leverages the funding provided through modernization.

Leveraging highly skilled contract support. This will mean spending money on capable small-business contractors that have the skillset to transition critical infrastructure systems from old to new systems. One such small business is Dragos, whose core business focuses on protecting critical infrastructure. During a National Public Radio (NPR) broadcast, they briefly interviewed the Chief Executive Officer (CEO) of Dragos, Robert M. Lee, who is a former SANS Institute Certified Instructor. During this NPR interview, Lee mentioned that they collaborate with critical infrastructure organizations and provide free tools that support securing our nation’s critical infrastructure (Dragos, 2025). This is done through the Dragos Community Defense Program that provides tools, training, and threat analysis to small utilities and cooperatives to improve their cybersecurity efforts (Dragos, 2025). This focus is mainly on small utilities and cooperatives since those are the ones that don’t have the budget on par with large utilities and cooperatives that can afford to leverage organizations like Palo Alto Networks, CrowdStrike, Cisco Security, Fortinet, and Microsoft Security. I realize this might come across as an advertisement for Dragos, but the intent is mainly to convey that critical infrastructure organizations of all sizes need to look for opportunities to employ cybersecurity to protect their infrastructure. A combination of small and large industry partnerships would be needed to address protecting the nation’s critical infrastructure, and these efforts can leverage the funding provided through the grant funding that is meant to bring on the necessary talent.

Leveraging military resources to provide support commensurate with the level of concern a catastrophic event should be handled. This concern could be a nationwide blackout or a cyberattack on the electrical grid. When you look at the news, it is already proven that attacks on critical infrastructure are on the rise. Since 2023, there have been numerous attacks. Three of them were targeted industrial control system (ICS) attacks with Volt Typhoon being the most notable (CISA, 2025; Office of the Director of National Intelligence, 2024; CISA, 2024). These ICS attacks on critical infrastructure caused effects that require a serious look at how the U.S. addresses and leverages the whole of government and industry support. However, the U.S. military already has a well-trained staff capable of conducting offensive and defensive operations. They also have the authorities needed to conduct various operations to secure and deter threats to the nation’s critical infrastructure. In addition, it is part of the National Defense Strategy and Department of War Cybersecurity Strategy to defend the homeland (U.S. Department of War, 2022; U.S. Department of War, 2023). Leveraging the various cybersecurity entities within the military to support cybersecurity defensive operations of the nation’s critical infrastructure will reduce the number of staff or contracts needed to address the effort. It will also simultaneously develop the military’s cybersecurity professionals while allowing for appropriate use of the U.S. military to support security of the nation. This use of the military will help to provide purpose and could result in improved retention of the cybersecurity operators.

Although it will require significant investments and time, the Cybersecurity Infrastructure Security Agency can support and protect the nation’s critical infrastructure. They can do this through modernization with industry partners that will allow the agency, states, and municipalities to employ up-to-date cybersecurity tools and equipment to address possible threats. CISA can do this by leveraging highly skilled contract support that focuses primarily on critical infrastructure as their core business and augment that with other professionals skilled in complementary areas of cybersecurity. CISA can do this by leveraging military resources to provide the necessary support that matches the level of concern to defend the nation’s infrastructure and reduce the threats to our national security. The combination of these options will help to improve the capabilities of the nation’s critical infrastructure and put it on the right path to be hardened against both current and potential threats to the country.

References

Cybersecurity and Infrastructure Security Agency (CISA). (2024, February 7). PRC state-sponsored actors compromise and maintain persistent access to U.S. critical infrastructure. Cybersecurity and Infrastructure Security Agency CISA. Retrieved September 14, 2025, from https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-038a

CISA. (2025, May 1). Threat actors target U.S. critical infrastructure with LummaC2 malware. Cybersecurity and Infrastructure Security Agency CISA. Retrieved September 14, 2025, from https://www.cisa.gov/news-events/alerts/2025/05/21/threat-actors-target-us-critical-infrastructure-lummac2-malware

Dragos. (2025). Community defense program. dragos.com. https://www.dragos.com/community/community-defense-program/

FEMA. (2025, September 3). Fiscal year 2025 state and local cybersecurity grant program fact sheet. fema.gov. Retrieved September 14, 2025, from https://www.fema.gov/fact-sheet/fiscal-year-2025-state-and-local-cybersecurity-grant-program-fact-sheet-0

GAO. (2025, April 29). Infrastructure grants: status of funding to tribes, states, localities, and territories as of December 31, 2024, GAO-25-107243. Retrieved September 14, 2025, from https://www.gao.gov/products/gao-25-107243.

Office of the director of national intelligence. (2024). Recent cyber attacks on US infrastructure underscore vulnerability of critical US systems, November 2023–April 2024. dni.gov. Retrieved September 14, 2025, from https://www.dni.gov/files/CTIIC/documents/products/Recent_Cyber_Attacks_on_US_Infrastructure_Underscore_Vulnerability_of_Critical_US_Systems-June2024.pdf

U.S. Department of Defense. (2022). 2022 national defense strategy of the United States of America, 12. U.S. Department of Defense. https://apps.dtic.mil/sti/trecms/pdf/AD1183514.pdf

U.S. Department of Defense. (2023). 2023 cyber strategy of The Department of Defense. U.S. Department of Defense. https://media.defense.gov/2023/Sep/12/2003299076/-1/-1/1/2023_DOD_Cyber_Strategy_Summary.PDF

Author

COL Charles McGrue is a CISSP-ISSMP, CISM, and 8xGIAC Certified Army Reserve Signal Officer with over 35 years of service. In his civilian capacity, COL McGrue is Mr. Charles McGrue and the Principal Cybersecurity Consultant for Connexmore, LLC, which focuses on providing cybersecurity, information technology, data governance, and disaster-recovery consultation to federal, state, local, and private organizations.