Critical Infrastructure Security: A Sector Guide to Physical Protection

Power lines and towers at sunset

Critical infrastructure security is the protection of the assets, systems, and facilities that a society depends on to keep water flowing, power on, and gas moving through pipelines without interruption. These systems are the backbone of our modern world and that makes them a high-value target. When they fail, the consequences aren't measured in data loss. They're measured in public safety, economic disruption, and national security outcomes that take months to unwind.

The threat environment has changed significantly over the past several years. The sector faces an 140% surge in cyberattacks that led to physical consequences. Regulatory pressure is tightening across every major sector too, with new incident-reporting obligations and updated federal frameworks redefining what compliance actually means. And with growing extreme weather events, the resilience of critical infrastructure all over the globe is more imperative than ever.

At Gallagher Security, we've spent more than three decades working alongside utilities operators and critical infrastructure teams worldwide, helping to keep essential services moving. Before any facility manager can make a sound investment decision, they need to understand who is at risk, what frameworks apply, and what a real layered defense looks like. That's where this guide starts.

 

Key takeaways

  • Critical infrastructure faces dual threats: Power grids, water systems, healthcare, and transportation networks must defend against both cyberattacks (up 140%) and physical security risks, alongside increasing disruption from extreme weather events.
  • Layered security is best practice: No single solution stops every attack, so critical infrastructure protection (CIP) combines perimeter security, access control, and cybersecurity in escalating tiers to delay intruders and protect high-value assets.
  • Compliance failures are enforcement failures: Frameworks like NERC CIP, AWIA, TSA directives, and PHMSA rarely penalize utilities for a missing policy. They penalize the inability to prove that policy was enforced when a regulator or investigator asked.
  • Credential lifecycle is the most common audit gap: Across electric, water, and pipeline sites alike, incidents trace back to access that outlived a role, contract, or certification, not to a missing fence or camera.

 

What is critical infrastructure security?

Critical infrastructure security combines three layers of physical control, perimeter security, access control, and cybersecurity. Each is applied with escalating strictness the closer you get to a site's highest-risk assets. Whether the facility supplies power, treats drinking water, delivers fuel, or houses government operations, the goal is to prevent unauthorized access and detect it immediately when prevention fails.

What sets these sites apart from a typical commercial building isn't only the value of what's inside. It's that a failure doesn't stay contained. A breach at a substation or a water treatment facility has consequences for every household and business that depends on it, which is why frameworks like NERC CIP and the CISA Cross-Sector Cybersecurity Performance Goals treat physical security controls as enforceable requirements rather than best-practice suggestions.

How many critical infrastructure sectors are there?

In the United States, the Cybersecurity and Infrastructure Security Agency (CISA) defines 16 sectors as critical infrastructure. Each has its own regulatory touchpoints, but all 16 share the same underlying exposure: a physical security failure with consequences that extend beyond the site's fence line.

  • Chemical Sector
  • Commercial Facilities Sector
  • Communications Sector
  • Critical Manufacturing Sector
  • Dams Sector
  • Defense Industrial Base Sector
  • Emergency Services Sector
  • Energy Sector
  • Financial Services Sector
  • Food and Agriculture Sector
  • Government Facilities Sector
  • Healthcare and Public Health Sector
  • Information Technology Sector
  • Nuclear Reactors, Materials, and Waste Sector
  • Transportation Systems Sector
  • Water and Wastewater Systems

The threat environment driving urgency across every sector

Critical infrastructure security has moved from a compliance checkbox to a board-level priority. The reason is straightforward: cyber and physical threats are converging, and OT environments sit squarely in the crosshairs. The distinction between a cyber incident and a physical outage has all but collapsed.

Vandalism, tampering, and unauthorized access to field equipment remain persistent risks alongside the cyber threat. A substation fence, a pump station door, and a remote communications cabinet are all physical entry points that can cause the same operational disruption as a network intrusion. Effective critical infrastructure security addresses both threat vectors on one integrated platform, not as separate programs that never speak to each other.

 

Sector

Framework

Who it applies to

What it requires

Water

America's Water Infrastructure Act (AWIA)

U.S. community water systems serving over 3,300 people.

Mandatory Risk and Resilience Assessments and Emergency Response Plans, certified to EPA and recertified on a rolling schedule.

Water

AWWA J100

Water and wastewater utilities of any size, used voluntarily.

The risk-assessment methodology most utilities actually use to satisfy AWIA's RRA requirement, covering physical facility protection, intrusion detection, and personnel/contractor screening.

Oil, Gas, & Pipeline

TSA Pipeline Security Directives

Natural gas pipelines, hazardous liquid pipelines, and LNG facilities in the U.S.

Control access to critical facilities, detect and report incidents, and demonstrate accountability for who accessed what, when, and why.

Oil, Gas, & Pipeline

PHMSA

Pipeline and hazardous materials operators, regulated by the U.S. DOT.

Operators must show that only qualified personnel can reach safety-critical assets like compressor stations and valve sites.

Cross-sector

NIST CSF 2.0

Cross-sector, used as a voluntary baseline by most operators.

A common language for identifying, protecting, detecting, responding to, and recovering from both cyber and physical incidents.

Cross-sector

CISA Cross-Sector CPGs (CPG 2.0)

All 16 critical infrastructure sectors in the U.S.

A prioritized, achievable starting point rather than a full program.

Use these as a baseline, not a ceiling. CISA is explicit that the CPGs are a prioritized, achievable starting point, not a comprehensive program on their own.

Best practices for implementing critical infrastructure security measures

A layered critical infrastructure security strategy enables a site to put multiple security levels in place and increase the complexity the closer you get to higher risk assets. By doing this, it reduces the possibility of a security threat being realized through delaying intruders and providing security personnel more time to detect unauthorized entry.

No single security solution will stop every attack, every time, so when protecting high-risk sites, a layered approach incorporating critical infrastructure solutions is best practice.

Critical infrastructure perimeter protection

Perimeter security is the first line of defense for any organization. It can provide detection and deterrence, alerting the business and emergency services to potential security threats while delaying and preventing any loss or damage due to theft, vandalism, or other criminal acts. A robust perimeter security system is essential to protect your site from criminal threats, especially in critical and high security sectors. 

Critical infrastructure access control

Robust access control is an essential component of a comprehensive physical security strategy for critical infrastructure protection. These measures are specifically designed to prevent or mitigate the threat to people, information, and assets. A critical infrastructure access control system should protect against unauthorized access, maintain integrity and availability, and provide evidence of access.

Access control solutions provide a foundation for creating layered security protection and achieve much more than just allowing access via electronic credentials. This technology can provide a complete record of who entered a facility, which areas they accessed, and the duration of their stay, thereby enhancing critical infrastructure security.

One example of this is utilizing an access control system to manage user privileges and assigning different access permission for employees. Entry control points can be easily established to only allow authorized individuals initial access to a facility or within specific areas. The rule of least privilege ensures that users are given the minimum levels of access or permissions needed to perform their job and can be a fundamental layer in protecting high-value assets or data, while reinforcing critical infrastructure protection.

High security zones within an access solution often have a dual authority rule where two authorized people must be authenticated at the same time before access is granted. A no alone zone can be used for areas where there must be two people present and if they don’t leave within the allocated grace period an alarm will be generated. In more capable critical infrastructure access control systems, that rule can be modified to require at least one person of a supervisor role to be present.

Keeping remote sites secure

Most security strategies handle connected, centrally managed sites reasonably well. The real test is what happens at a remote pump station, wind farm, or gas installation when connectivity drops. This is the gap that most programs don't solve, and it's where operational risk concentrates.

Many of the most operationally critical infrastructure sites are also the most geographically isolated. Rural water treatment facilities, offshore platforms, and wind farms sit far outside reliable network coverage. 

Gallagher's OneLink solution is purpose-built for this challenge. It enables operators to secure any site, no matter how remote, through resilient connectivity architecture that uses secure, authenticated cloud connections rather than requiring VPN infrastructure extensions. 

Five steps to strengthen your critical infrastructure security posture

Each step below maps to a theme covered in this article. Taken in sequence, they give facility managers a practical path from current state to a defensible security posture.

  1. Map your assets and identify exposure points: Build a full inventory of OT and ICS devices, remote access paths, and connections between IT and operational environments. Be specific about where those assets physically live, since SCADA servers, RTU cabinets, relay rooms, and control houses each carry different exposure than a general office area. 
  2. Align with your sector's regulatory framework: Identify which frameworks apply to your organization including NERC CIP, AWIA, or TSA directives. Treat them as a baseline, not a finished program 
  3. Layer physical and cyber defenses on one platform: Perimeter intelligence, access control, and intruder alarms operate most effectively on a single integrated platform that shares event data across all three functions. Siloed systems create gaps. When an alarm at the fence line immediately cross-references access logs and notifies the right personnel, operators respond to a confirmed event rather than investigating noise.
  4. Plan for offline operation at every remote site: Test your security system's behavior when network connectivity fails. If it stops working, your protection stops with it. Run a scheduled offline test at least quarterly. Disconnect the site from the network, attempt a credentialed access event, and verify that local controller logic executes correctly without cloud confirmation. Gallagher's controllers are designed specifically for this requirement, executing access and alarm logic locally regardless of network status.
  5. Close the contractor and credential lifecycle gap: Across electric, water, and pipeline sites alike, the same failure mode keeps surfacing in post-incident reviews: credentials that outlived the role, contractor engagement, or certification they were tied to. A technician's access should end the moment their training certification lapses or their contract ends, not at the next scheduled review. Audit for orphaned or shared credentials on a fixed cadence, and treat the speed of revocation, not just the existence of an offboarding policy, as the metric that matters. This is consistently where PHMSA, TSA, and NERC CIP-004 investigations find the gap between what was authorized and what was actually enforced. 
     

The importance of cybersecurity in critical infrastructure security

Critical infrastructure security isn't a line item to minimize or a box to check once a year. It's the operational foundation that keeps utilities running and communities served without interruption, and the frameworks governing it will keep tightening as threats evolve. The five steps above work regardless of where your program currently stands, but the sequencing matters less than starting.

If you're mapping which framework applies to your sites, contact our team to walk through NERC CIP, AWIA and AWWA J100, TSA and PHMSA requirements against your current setup. If you work with a regional integrator, find a Certified Gallagher Channel Partner to scope a deployment.

High Security Solutions

With Gallagher’s high security solutions, you’ll experience an unparalleled sense of security while meeting the standards of the ever-evolving high security industry.

Learn more


What if security is capable of so much more?

By challenging what's possible, Gallagher empowers businesses to be more connected with their people, their goals, and their potential.

Unlock More


Do you have a question?

Let us put you in contact with one of our team members.

CONTACT US


Want to hear more from Gallagher?

Get the latest Gallagher news, updates, and event information delivered straight to your inbox.

SUBSCRIBE

Stay up to date with Gallagher

Get the latest Gallagher news, updates, and event information delivered straight to your inbox.