602-725-2818Licensed, insured & bondedSchedule a Consultation
Call 602-725-2818Consultation

Honeybadger Solutions LLC

Critical infrastructure: the threat picture and the regulatory frame

Why utilities, water and energy sites carry a different risk profile, and the standards that govern how they are protected.

Assets that cannot go dark

Infrastructure sites fail differently from other property. An intrusion is rarely the incident itself; it is the opening move toward disruption, sabotage or data. That changes what a post is for. Officers on these sites are briefed on what an early indicator looks like, who to escalate to, and how fast — not simply on where to stand.

Because Honeybadger runs guards, investigators, intelligence analysts and aircrew under one contract, a suspicious pattern noticed at a gatehouse can be worked as an investigation rather than filed as a log entry. That is the practical difference between a guard company and a security program.

The threat picture, specifically

Critical infrastructure is mostly unattended, mostly unfenced from anything that matters, and mostly a long way from help. Substations, pump stations, lift stations, telecom huts, tank farms, solar arrays and cell sites share a profile: high consequence, low occupancy, and a response time measured in tens of minutes rather than minutes. That combination shapes everything about how they are protected.

The most common loss is metal theft, and it is not petty. Stripping copper from a substation ground grid does not just cost the copper; it removes the fault path that keeps equipment and people safe, and the damage is often discovered during the next fault rather than at the time. Cut fibre and severed conduit follow the same pattern — small object of theft, large consequence. Above that sit deliberate attacks on equipment, which have moved from theoretical to demonstrated across the United States in recent years and have made ballistic protection, sightline management and rapid detection ordinary conversations rather than exotic ones.

Then there is access. Most infrastructure breaches are not fence cuts; they are gates left open, contractor keys never returned, locks swapped for a personal padlock, and vendors who were escorted the first time and waved through the second. Drone overflight of restricted sites is now a routine observation rather than an unusual one, and the correct response is to observe, record and report rather than to intervene.

Arizona adds its own conditions. Transmission and water corridors run for miles across open desert with vehicle access from unpaved roads that appear on no map anybody uses. Solar generation concentrates high-value copper and inverter equipment in remote arrays. Summer heat is an operational constraint, not a comfort issue: it dictates patrol timing, vehicle and equipment reliability, water planning and officer safety. Monsoon washouts change access routes overnight.

The regulatory frame around the post

Infrastructure security is governed by sector, not by a single rulebook, and the differences matter to how a post is written.

For the bulk electric system, NERC CIP-014 requires identification of transmission stations whose loss could cause instability, third-party verification of that assessment, and evaluation and implementation of physical security measures for the ones identified. NERC CIP-006 governs physical security of the cyber systems that operate it, including visitor control and logging. Where a client is subject to either, our post orders, access logs and visitor records are written to be produced in an audit rather than reconstructed for one.

Community water systems fall under the America’s Water Infrastructure Act, which requires risk and resilience assessments and emergency response plans covering physical security among other things. Pipelines operate under TSA security directives. Chemical facilities were covered by the CFATS programme until its statutory authority lapsed in 2023; the standards it set are no longer federally enforced, but the underlying risk did not change and many operators continue to hold the line voluntarily. We will work to whichever standard you are actually holding.

In Arizona, guard services are licensed under A.R.S. Title 32, Chapter 26 and regulated by the Department of Public Safety. Honeybadger holds Security Guard Agency licence 1759798 and Private Investigations Agency licence 1759795. Officers are not peace officers: they observe, document, deny access under your authority, and call law enforcement. They do not pursue across open ground, and on a remote desert site at night that is not caution, it is competence.

What Honeybadger Solutions provides

Honeybadger Solutions is an Arizona-licensed security guard and private investigations agency — Guard 1759798, PI 1759795 — with investigations, digital forensics and cyber work delivered nationwide. This article is background on the problem. For what we actually provide, see Critical Infrastructure Security, or book a confidential consultation.