602-725-2818Licensed, insured & bondedSchedule a Consultation
Call 602-725-2818Consultation

Critical infrastructure: the threat picture and the regulatory frame

Critical infrastructure” sounds like someone else’s problem — a federal category covering power stations and pipelines, staffed by people with clearances. In Arizona it is a much wider net than that, and a surprising number of ordinary commercial sites sit inside it without their owners realising.

Two definitions matter, and they are not the same definition.

The federal frame

At national level, CISA identifies sixteen critical infrastructure sectors whose assets, systems and networks are considered so vital that their incapacity would have a debilitating effect on security, the economy, public health or safety. Each sector has a designated Sector Risk Management Agency responsible for coordinating security and resilience within it.

Sitting inside a designated sector generally does not, by itself, impose obligations on a private operator. The regulatory weight comes from sector-specific regimes: NERC CIP standards for the bulk electric system, TSA security directives for pipelines and certain surface transportation, NRC requirements for nuclear facilities, sector rules for water systems, and so on. Those bite hard where they apply and not at all where they do not.

For most Arizona businesses the federal frame is context. The state statute is the one with teeth.

The Arizona frame, which is broader than people expect

A.R.S. § 13-3729 makes it a class 6 felony — class 5 for a second or subsequent offence — to operate an unmanned aircraft to intentionally photograph or loiter over or near a critical facility in furtherance of a criminal offence. To do that, the statute has to define “critical facility”, and its list is long:

  • Petroleum or alumina refineries.
  • Petroleum, chemical or rubber production, transportation, storage or processing facilities.
  • Chemical manufacturing facilities.
  • Water or wastewater treatment facilities, and water development, distribution or conveyance systems including dams.
  • Electric generation facilities and any associated substation or switchyard.
  • Electrical transmission or distribution substations.
  • Electrical transmission lines of at least sixty-nine thousand volts.
  • Electronic communication stations or towers.
  • Energy control centres and distribution operating centres.
  • Natural gas transfer or distribution facilities, including compressor, regulator, city gate and pressure limiting stations, liquefied natural gas facilities and supplier tap facilities.
  • Any railroad infrastructure or facility.
  • Federal, state, county or municipal courts.
  • Public safety or emergency operation facilities.
  • Jails, prisons and other facilities in which persons are incarcerated.
  • Federal or state military installations or facilities.
  • Hospitals that receive air ambulance services.

Set that against a map of Pinal or Maricopa County. Substations, communication towers, canal and conveyance infrastructure, rail, and natural gas assets are distributed across ordinary industrial and even suburban ground. A great deal of Arizona is within photographing distance of something on that list.

What this actually changes for an operator

If you own or manage listed infrastructure, the statute is a tool. Loitering aircraft over your site in furtherance of an offence is a felony, which means an incident log with timestamps, photographs and flight behaviour is worth building. Most sites record nothing, and then have nothing to hand over.

If you operate near listed infrastructure — and most industrial sites do — the statute is a constraint. A drone flown for a legitimate purpose, over your own property, that drifts within photographing range of a neighbouring substation, creates a situation you have to be able to explain. Intent is what separates lawful from criminal here, and intent is much easier to demonstrate when the flight was scoped in writing beforehand. That planning is covered in our piece on Part 107, LAANC and Arizona drone law.

If you are a contractor working on listed infrastructure, your people, vehicles and access credentials become part of that site’s exposure. Vetting standards, escort requirements and equipment control are usually specified in the contract, and they are usually specified more tightly than a general commercial contract would be.

The physical threats that actually recur

Whatever the regulatory category, the incidents at infrastructure sites in the Southwest are consistent and mundane.

Metal theft. Copper grounding conductors are stolen from substations, which is both a theft and a serious safety hazard for anyone subsequently working on the equipment. It is dangerous enough that thieves are regularly injured or killed. Rising copper prices drive the rate directly.

Remote-site attrition. Fencing, gates, cameras and lighting degrade, and unmanned sites go unvisited for long periods. Failures are typically discovered during an incident rather than before one.

Reconnaissance. Repeated presence at a fence line, photography, questions asked of staff, or attempted access under a false pretext. These leave a pattern only if someone records them, and at most sites nobody does.

Contractor and insider access. The routine route into a controlled site is a legitimate credential, which is why access records and their reconciliation matter more than the gate itself.

What a proportionate programme looks like

  • Know your status. Determine whether your site meets the Arizona statutory definition and whether any federal sector regime applies. These are separate questions with separate answers.
  • Log suspicious activity in a structured way — date, time, location, description, photographs where lawful. A pattern is only visible in aggregate.
  • Inspect remote assets on a schedule rather than on complaint. Unmanned does not mean unvisited.
  • Treat contractor access as a control, not paperwork. Issue, log and reconcile.
  • Write down the drone posture for your own operations and for reporting aircraft over the site.
  • Vary patrols. Fixed-interval coverage at a remote site is a published timetable.

Honeybadger Solutions works infrastructure and industrial ground in Arizona — posture design, patrol structure, and the drone element where a site is large enough to justify it. Aerial coverage sits under drone operations and, for permanent installations, autonomous drone systems. Where reconnaissance appears to be organised rather than opportunistic, that becomes a matter for private investigations.

This is general information about Arizona and federal frameworks, not legal advice.

Where a physical-security assessment actually starts

The federal government organises critical infrastructure into sixteen sectors — energy, water and wastewater, communications, chemical, transportation, healthcare, financial services, food and agriculture, and the rest — and the Cybersecurity and Infrastructure Security Agency (CISA) is the coordinating body most operators deal with. Regulation of the physical layer is sector-specific rather than a single law: NERC’s CIP-014 standard governs physical security of the bulk electric system, TSA security directives reach pipelines and transport, and other sectors carry their own regimes. That patchwork is exactly why a proportionate assessment does not start with the rulebook — it starts with consequence. Identify the handful of assets whose loss actually stops the mission (the “crown jewels”), then work the standard threat-vulnerability-consequence model against each: what could realistically happen to it, how exposed it is today, and what the loss would cost in dollars, downtime, and public safety. Only then does spending get allocated, because it flows to the few points where a determined intruder does the most damage — not evenly across a fence line.

Frequently asked questions

What counts as critical infrastructure?

CISA recognises sixteen sectors whose incapacity would have a debilitating effect on national security, the economy, or public health and safety — including energy, water, communications, chemical, transportation, healthcare, and financial services. In practice it also includes the private facilities that feed those sectors: substations, data centres, water-treatment plants, logistics hubs, and telecoms sites.

Is physical security legally required for critical infrastructure?

For some sectors, explicitly — NERC CIP-014 for the bulk electric system and TSA directives for pipelines and transport are two examples. For others it is driven by insurance, liability, and contractual obligations rather than a single statute. Either way, a documented, risk-based programme is the defensible position.

Who regulates critical-infrastructure security in the United States?

CISA coordinates across sectors, but enforcement is sector-specific: NERC for the electric grid, TSA for transport and pipelines, the EPA for water systems, and so on. There is no single regulator, which is why operators need an assessment that maps their own obligations.

What is the difference between physical and cyber protection here?

They are two halves of the same risk. A substation can be taken offline by a rifle as easily as by malware, and attackers increasingly combine the two. A serious programme assesses physical access, cyber exposure, and the points where they meet — remote access panels, control rooms, and unmanned sites — together.

How often should a critical site be reassessed?

At least annually, and after any material change — a new threat pattern, an incident, a facility expansion, or a regulatory update. Assessments age quickly because both the threat picture and the site change; a plan that is three years old is usually describing a facility that no longer exists.

What is CISA?

The Cybersecurity and Infrastructure Security Agency — the federal body that coordinates protection of the sixteen critical-infrastructure sectors. It issues guidance, threat information, and assessment resources, while sector-specific enforcement sits with regulators such as NERC, TSA, and the EPA.

Assess your critical facility against the real threat

Whether you run a substation, a data centre, a water plant, or a logistics hub, the first move is a consequence-driven assessment. See our critical infrastructure security, security assessments, and managed cyber security services. Honeybadger Solutions is a veteran-owned, Arizona-licensed firm — request a consultation to scope yours.