Analyst Mark Almond argues that Houthi drone strikes on Saudi Arabia’s East-West pipeline and Red Sea shipping routes pose a significant threat to global supply chains. While the Houthis state they are targeting only Saudi forces and their proxies, the article notes that confidence in this limitation is currently low.
America's cyber strategy overlooks the infrastructure that actually keeps the military moving
Summary
America’s cyber strategy overlooks the infrastructure that actually keeps the military moving There is little reason to believe the war with Iran will end anytime soon. Even as efforts to resolve the conflict continue, Iran remains unpredictable, with an enduring ability to disrupt shipping and energy markets via actions in the Strait of Hormuz. So what does a prolonged conflict mean for cybersecurity here at home? U.S. agencies need to prepare for sustained Iranian cyber operations and conduct defensive wargames now. I spent part of my career in Navy intelligence supporting expeditionary and special warfare operations. This experience taught me to look beyond individual attacks to the larger objectives they serve. Iran’s likely objectives are relatively straightforward: impose enough pain on critical infrastructure, businesses, and public services to increase pressure on Washington, while disrupting the industrial and civilian systems that allow the U.S. to sustain military operations. Iran may not be a top-tier cyber power like China or Russia, but it doesn’t have to be. We recently mapped 130 documented attack techniques used by five Iranian threat groups. Much of their playbook relies on well-known, repeatable techniques rather than advanced capabilities. Success does not require extraordinary capabilities, only the ability to create enough disruption, uncertainty, and delay is enough. America’s greatest vulnerability may not be any single network or piece of critical infrastructure, but the links in between. Critical infrastructure: Prepare for volume, not just catastrophe When Americans imagine a cyberattack on critical infrastructure, we tend to think of catastrophic events, such as a large-scale blackout, a poisoned water supply, or some other digital Pearl Harbor. But in an extended conflict, the more realistic possibility is persistent attacks across many targets. Small water systems, manufacturers, transportation providers, energy infrastructure, and local governments all serve as disruptive targets. The recent string of attacks on mostly smaller water utilities across 12 states is a prime example; so too is the four-day outage of a small-scale power plant in the UK. Attackers do not need to destroy these systems. Any intrusion that manipulates industrial systems, interrupts operations, or forces operators to determine whether equipment can still be trusted consumes valuable time and resources. Multiply that across dozens of organizations, and federal, state, local, and private-sector response capacity will be stretched thin. The cumulative strain on the country’s ability to respond may be more important than any single attack. Iran does not need the world’s most sophisticated cyber force if its affiliated hacking groups can generate problems faster than cyber defenders can investigate and remediate them. Defense contractors must prepare for destructive attacks Defense contractors have long faced espionage threats targeting military secrets. While that threat remains, the war has significantly changed Iran’s motives and risk calculus. The same access used to steal information from the defense industrial base (DIB) can also be used to destroy data and disrupt operations. Destructive malware such as wipers and ransomware could destroy engineering files, disable production systems or force manufacturers offline, directly affecting the military’s ability to replenish equipment and supplies. An attacker does not have to shut down production to disrupt it. Consider a compromised calibration setting, altered test result, or unauthorized change to engineering data. Discovering that an adversary had persistent access to a manufacturing environment raises difficult questions: Which files were touched? Which designs can still be trusted? Which components were manufactured from them? The incident quickly becomes a production problem as parts must be quarantined, engineering data re-validated, and products retested. NIST SP 800-171 and CMMC provide an essential security baseline, which makes the current pause in CMMC implementation particularly concerning. However, contractors must also be prepared to operate through destructive attacks and establish that their systems, data, and products can still be trusted. This preparedness must extend down the supply chain, where a smaller manufacturer, software provider, or managed service provider may present a greater vulnerability than a well-defended prime. The military attack surface extends far beyond DoD networks The U.S. military is extraordinarily capable at defending its own networks, but its operations depend on infrastructure it doesn’t own or control. Troops and equipment move on commercial railroads, materiel flows through commercial ports, and military airlift can depend on commercial carriers. Military installations and defense contractors also depend on commercial power, telecommunications, and other infrastructure. In an ongoing conflict, those dependencies become part of the attack surface. An adversary like Iran does not have to penetrate military command-and-control to interfere with these operations. At a time when speed matters most, cyberattacks that disrupt port scheduling, corrupt logistics information, or degrade power and communications can introduce critical delays and uncertainty that hamper operations. This is why the line between civilian and military infrastructure becomes blurred during a conflict. A commercial railroad carrying military equipment to a strategic port may be civilian infrastructure administratively, but operationally it is part of the nation’s ability to operate its military power. The same is true of the utilities, communications providers, and other civilian infrastructure supporting military installations and defense production. Their resilience can quickly become a matter of military readiness. Cyber defense must cross organizational boundaries American cybersecurity is organized around sectors, organizations, and authorities that make administrative sense, but aren’t necessarily designed for wartime. The boundaries between them can become a serious liability. Our adversaries in Tehran do not care about administrative boundaries. They care about weak spots. A vulnerability anywhere in the chain connecting civilian infrastructure, industrial production, transportation, communications, and military operations can affect everything downstream. We need to ask: Who is responsible for the cyber resilience of a commercial railroad essential to a military deployment? Who ensures the utility serving a critical defense manufacturer can withstand a sustained nation-state campaign? Who identifies the supplier whose failure could disrupt multiple defense programs? And who coordinates the response when several are attacked simultaneously? Those questions should shape how we prepare. Critical infrastructure exercises should assume simultaneous incidents across multiple sectors and regions. We should also be extremely cautious about weakening the incentives driving cybersecurity improvements across the DIB, such as the current pause on CMMC. Additionally, defense manufacturers should also test their ability to operate through destructive attacks and determine whether their engineering data, production systems, and finished products can still be trusted. DoD exercises should treat civilian infrastructure, including rail, ports, energy, and communications, as a routine part of the operating environment and an attractive target for adversaries. Catastrophic scenarios deserve attention, but exercises should also account for lower-level attacks that are less spectacular but still highly consequential. Iran does not need overwhelming cyber capability to impose significant costs. Persistent disruption at home can increase political and economic pressure surrounding the war, while disruption of defense production and military logistics can make it harder for the U.S. to sustain operations abroad. We have spent years strengthening the individual pieces of America’s cyber defenses. A prolonged war with Iran may test the links between them.
Actors involved
Sources
- Greg Otto; Darron MakrokanisBy Greg Otto; Darron Makrokanis
America’s cyber strategy overlooks the infrastructure that actually keeps the military moving There is little reason to believe the war with Iran will end anytime soon. Even as efforts to resolve the conflict continue, Iran remains unpredictable, with an enduring ability to disru…
See this event through different lenses
Compare how Western, Iranian, Israeli, Global South, and Pro-Peace perspectives frame this event.
Compare PerspectivesCommunity Notes
Community Notes
Loading notes...
Related events
A UN fact-finding mission reported having reasonable grounds to believe U.S. forces conducted strikes on a school in Iran that officials said killed more than 150 people, while also alleging Iranian authorities committed crimes against humanity during recent protests.
The report is being submitted to the UN Human Rights Council, and while U.S. officials stated their operations complied with the law of armed conflict, Iran has rejected allegations of systematic rights violations.
The UN Independent International Fact-Finding Mission has called for an immediate ceasefire after reported U.S. airstrikes in Hormozgan province resulted in civilian casualties, a situation the body states raises serious questions regarding the protection of civilians, though no war crimes have been officially determined.
According to reports, strikes on a home in Kuhestak and a residence in Qeshm allegedly killed at least six people and injured others, with the UN noting these areas are home to historically marginalized Baloch and Sunni communities.
UN mission finds grounds to believe US committed war crimes in Iran GENEVA, Sept 17 (Reuters) - A UN fact-finding mission on Iran said on Thursday it had reasonable grounds to believe the United States was behind two military strikes on a school and sports facility in Iran in February, and that these constituted war crimes.
It also found that Iranian authorities committed crimes against humanity during their deadly crackdown on anti-government protests. The findings in a new report by the Independent International Fact-Finding Mission on Iran, to be submitted to the UN Human Rights Council in Geneva, examined the US's conduct during the Iran war that began in February and the Iranian government's response to nationwide unrest that begun in late December.
The Iranian and US permanent missions in Geneva did not immediately respond to Reuters requests for comment. US officials have previously said military operations are conducted in accordance with the law of armed conflict, while Iran has consistently rejected allegations of systematic rights violations.
Minab school strike The UN experts said they found reasonable grounds to believe US forces were responsible for an attack on the Shajareh Tayyebeh Primary School in the city of Minab, where more than 150 people were killed, including around 120 schoolchildren, according to Iranian officials.
The attack constituted an indiscriminate attack causing civilian deaths and damage to civilian infrastructure, amounting to a war crime under international law, the mission concluded. According to the report, the US relied on intelligence suggesting a senior Iranian military commander was present at the site but failed to adequately verify the information before launching the strike.
Investigators said the failure to update targeting intelligence and confirm the building was a military objective amounted to more than mere negligence. "Rather, the US directed the strikes at the building of the school while being aware of a substantial risk of striking a civilian object and acting recklessly as regards the possibility that this would happen.
" In June US President Donald Trump said that "nobody" purposefully attacked a girls' school in Iran in February, citing an investigation into the incident. Reuters first reported that an initial internal U.S. military investigation showed US forces were likely responsible for the fatal strike in Minab in southern Iran.
The Pentagon has since elevated the probe but it has not published any preliminary findings. UN experts said the school was a clearly identifiable civilian object and found no evidence that it was being used for military purposes. The experts reached a similar conclusion over a strike on a sports centre in Lamerd.
The report said the attack damaged nearby residential buildings and a school and killed and injured 22 civilians. It concluded that the strike was indiscriminate and therefore constituted a war crime. US Central Command said in a statement in March that US forces did not launch any strikes into the city of Lamerd on that day.
Iran abuses The UN mission probe found that the Iranian authorities carried out a widespread and systematic attack against civilians during protests that erupted in late December last year, involving unlawful killings, torture, arbitrary detention, enforced disappearances and severe restrictions on freedom of expression.
Rights groups say bystanders were among those killed during the biggest crackdown since Shi'ite Muslim clerics took power in the 1979 revolution. Tehran blamed "terrorists and rioters" backed by exiled opponents and foreign foes the US and Israel. The probe said it could not independently verify the death toll, but that it believed the number of dead and injured was likely far higher than official figures which say 3,038 people were killed, and 25,000 people injured.
The government's response to the protests - including violence and killings, cutting off the internet and use of the death penalty, marked a significant escalation from previous patterns of suppressing dissent, the report said.