Critical Infrastructure Security: What the Counter-Drone Threat Landscape Actually Looks Like
- 4 days ago
- 9 min read

In November 2024, the FBI arrested a Tennessee man for plotting to destroy a Nashville electrical substation using a drone armed with C-4 explosives. It wasn't the first incident. In 2020, a drone was recovered near a Pennsylvania electrical substation that had been modified in a way that could have caused a short circuit and disrupted the facility's equipment. That was the first known case of a drone specifically configured to target U.S. energy infrastructure.
These incidents are part of a critical infrastructure threat landscape that has expanded significantly in the past five years. The combination of widely available commercial drones, declining costs, and well-documented adversary use of drone weaponization overseas has made UAS threats to critical infrastructure a documented operational reality in the United States, not a hypothetical future concern.
The threat isn't limited to attacks. Surveillance drones operating over power generation sites, water treatment facilities, and communications infrastructure create intelligence collection risks that are often less visible than an attack attempt but potentially more consequential over time. Understanding what the actual counter-drone threat landscape looks like for critical infrastructure is the starting point for building a program that addresses it.

Why Critical Infrastructure Has Become a Counter-Drone Priority
The drone threat to critical infrastructure is growing for reasons that are structural, not circumstantial.
Commercial drones have become cheaper, more capable, and easier to operate with each successive product generation. A drone capable of carrying a meaningful payload, flying several miles from its operator, and transmitting live video feeds to a remote location costs a few hundred dollars. The operational knowledge required to deploy it doesn't require specialized training. The consequence of a successful attack or prolonged surveillance operation on critical infrastructure, by contrast, can be severe and cascading.
The scale of the surveillance problem is significant. In 2024, more than 13,000 grid incursions were recorded at U.S. power generation sites. General Gregory Guillot testified before the Senate Armed Services Committee in February 2025 that the U.S. military detected 350 drone incursions across more than 100 installations in 2024. The NRC updated its regulations to require nuclear power plant licensees to report drone sightings directly to the NRC, the FAA, the FBI, and local law enforcement, a recognition that the volume of incidents had made formal reporting tracking necessary.
CISA has specifically designated unauthorized drone activity over critical infrastructure as a priority concern, releasing three dedicated guidance documents: UAS Detection Technology Guidance for Critical Infrastructure, Suspicious UAS Activity Guidance for Critical Infrastructure Owners and Operators, and Safe Handling Considerations for Downed UAS. The fact that a federal agency produced three separate operational guides for the same threat category reflects how seriously the government is treating the problem.
The threat is not evenly distributed across infrastructure types. Power generation and transmission, water treatment, communications towers, and fuel storage facilities represent the highest-consequence targets because a successful disruption affects large populations, is difficult to remediate quickly, and creates downstream effects across interconnected systems. But the surveillance risk, less visible than an attack and sometimes mistaken for casual consumer drone activity, applies broadly across any critical site.
What the Incidents Show About How Drone Threats to Critical Infrastructure Work
The documented incidents provide a clearer picture of how the threat actually operates than any hypothetical framework does.
Reconnaissance precedes action. Organized threat actors don't attack facilities they haven't studied. Drone surveillance over a critical infrastructure site is often a preliminary step to understanding perimeter access points, shift change timing, security camera placement, and facility layout. A drone visible over a power substation may not be the threat itself. It may be the intelligence-gathering phase of a threat that comes later.
Modification for disruption is simple. The 2020 Pennsylvania incident demonstrated that a commercially available drone can be modified to create electrical interference without requiring sophisticated engineering. The components needed are inexpensive and available. The operational expertise is minimal. The gap between a consumer drone and a disruptive device is smaller than most facility security teams appreciate.
Weaponization follows overseas models. The FBI's Nashville arrest involved C-4 explosives, reflecting the same drone weaponization pattern that has been documented in conflict zones overseas. Non-state actors carried out more than 800 documented drone attacks between 2018 and 2024 internationally, and federal law enforcement has explicitly cited overseas operational models as informing domestic threat assessments. GridEx, the grid security exercise hosted by the Electricity Information Sharing and Analysis Center in November 2025, specifically studied drone-based attack scenarios against power generation infrastructure.
The window between detection and consequence is short. A drone approaching a substation from a mile away at low altitude may be within the facility perimeter in under three minutes. At most critical infrastructure sites, the security response cycle, detect, verify, communicate, respond, takes longer than that. The operational question for facility security programs isn't just whether drone incursions are being detected. It's whether the detection capability allows any meaningful response before a threat has already acted.

The Three Threat Categories Critical Infrastructure Operators Face
Not all drone threats to critical infrastructure look the same. Understanding the categories helps prioritize the right detection and response architecture.
Surveillance and intelligence collection is the most common category and the one most likely to be misidentified as nuisance activity. An unauthorized drone operating over a facility perimeter and transmitting video to a remote operator may be collecting operational intelligence: guard positions, patrol timing, camera coverage angles, access point locations. This information has value both for planning a direct attack and for other criminal operations, such as theft of materials or equipment. The frequency of this category makes consistent aerial monitoring of facility perimeters a baseline requirement.
Contraband and payload delivery involves drones carrying materials across secure perimeters without requiring physical access. At correctional facilities, this is well-documented. At critical infrastructure sites, the concern extends to components capable of damaging equipment, jamming communications, or disrupting industrial control systems. Detecting a drone carrying a payload before it reaches a target requires detection at a range sufficient to allow response.
Direct attack is the category with the highest consequence per incident, even if it remains the least frequent. The FBI's Nashville arrest and the 2020 Pennsylvania incident both fall into this category. Federal law enforcement and congressional testimony have documented that domestic threat actors have studied weaponized drone tactics from overseas conflicts and have attempted to apply them to U.S. energy infrastructure.
The Legal Authority Gap: What Critical Infrastructure Operators Can Currently Do
Here's where facility security teams frequently misunderstand their position: the legal authority to actually stop a drone threatening a critical infrastructure site is, in most circumstances, not held by the facility operator.
Before December 2025, federal authority to detect and mitigate drone threats was held by four agencies: the Department of Homeland Security, the Department of Justice, the Department of Defense, and the Department of Energy. Private sector operators, regardless of what infrastructure they operated or how credible the drone threat was, were legally limited to detection and reporting. They could observe a threatening drone. They could report it. They could not legally jam its signal, spoof its GPS, or take any action to bring it down.
The SAFER SKIES Act, signed into law in December 2025 as part of the Fiscal Year 2026 National Defense Authorization Act, extended limited counter-drone mitigation authority to certified state, local, tribal, and territorial law enforcement agencies for the first time. The act expires December 31, 2031, and requires a "credible threat" determination before any mitigation action can be taken. DHS and DOJ have 180 days from signing to publish implementing regulations.
A separate legislative proposal, the Critical Infrastructure Airspace Defense Act, would go further by allowing certain private-sector operators to detect, track, and mitigate drone threats at designated facilities after federal training and certification. That bill had not been enacted as of mid-2026.
The practical implication for most critical infrastructure facility operators today: detection is what you own. Mitigation requires law enforcement. Any counter-drone program at a critical facility must be built on the premise that the detection layer enables rapid law enforcement coordination, not direct neutralization.
That means the detection capability has to be fast, accurate, and integrated with the communication chain to the agencies that do hold mitigation authority.
What CISA's Detection-First Framework Requires in Practice
CISA's guidance for critical infrastructure operators is structured around detection as the primary responsibility. The three guides released in 2024 and 2025 provide an operational framework that breaks into three phases.
Detect. The first requirement is identifying unauthorized UAS activity at or near the facility. Detection technologies include radio frequency analysis (identifying drone communication signals), acoustic detection (identifying rotor noise signatures), radar, and optical/thermal sensors. Each technology has range and accuracy characteristics that make it more or less suitable for specific facility types and environments. CISA's guidance outlines the tradeoffs and recommends a layered approach for high-consequence sites.
Assess and report. Once a drone is detected, CISA's framework calls for operators to assess the threat, document what was observed, and report to the appropriate authorities. The reporting chain differs by facility type and incident severity. A drone sighting at a nuclear facility triggers a specific multi-agency notification sequence. A suspicious incursion at an energy facility has a different reporting path. CISA's suspicious activity guidance provides the framework for both.
Coordinate. Because mitigation authority rests with law enforcement and federal agencies, the coordination layer between detection and response is operationally critical. A detection system that identifies a drone threat and generates a real-time alert to coordinating law enforcement agencies provides meaningfully more useful response options than one that generates a log entry for a post-incident review.
The emphasis throughout CISA's guidance is on establishing the detection and communication infrastructure that makes law enforcement response possible within the threat's operational timeline.
How Managed Counter-Drone Monitoring Fits Into a Critical Infrastructure Security Program
The operational gap at most critical infrastructure sites isn't an absence of awareness that the threat exists. It's the absence of a continuous, managed detection layer that is actively monitoring the facility's airspace and generating real-time alerts when an unauthorized UAS is present.
A passive perimeter, one relying on cameras and periodic patrols, doesn't detect drone threats until a drone is close enough to have already completed much of its mission. At a large facility with significant outdoor acreage and airspace exposure, by the time a drone is visible to a ground-level camera, it may have already collected the surveillance data it was sent to gather.
LandSkyAI's AirGuard program provides active counter-drone detection, geolocation, and managed monitoring for critical infrastructure facilities. The program monitors facility airspace continuously, identifies unauthorized UAS activity at operationally relevant detection ranges, geolocates the drone and, where technically achievable, its operator, and provides real-time alerts to the facility security team and coordinating law enforcement.
Detection at range is what enables the response window. When a drone is identified at a distance sufficient to allow coordinated law enforcement response before it reaches a sensitive area of the facility, the detection layer is doing its job. When it's only identified after it's already inside the perimeter, the detection layer has provided documentation, not protection.
AirGuard integrates with LandSkyAI's broader security operations capability. A facility running both AirGuard for counter-drone detection and SkyGuard for autonomous aerial perimeter patrol has a combined picture of both what's happening on the ground and what's operating in the airspace above it, managed from the same remote operations center by trained personnel with continuous coverage through the overnight and weekend windows when most unauthorized drone activity concentrates.
For critical infrastructure operators working through what their detection program needs to look like, the CISA guidance is the right starting framework. Building the technical and operational layer that puts that framework into practice is where a managed program adds value.
LandSkyAI provides counter-drone detection and managed aerial security for power generation facilities, water utilities, communications infrastructure, and other critical sites. If you're assessing your facility's current airspace monitoring capability against what the threat environment actually requires, we can walk through what an AirGuard deployment looks like for your specific site.
What's your current biggest counter-drone challenge at your facility?
Detecting drones early enough to allow a meaningful response
Understanding what you're legally authorized to do when one
Integrating airspace monitoring with your existing security
Did you find this article useful? Are you interested in seeing us in action?
MissionControl is LandSkyAI’s ongoing town hall style webinar where you can get to know who we are, what we do, and how we’ve built our autonomous security programs. We also conduct a fully live remote drone demo, every time!
Our next event is on Wednesday, July 29th 2026
Thank you for reading SkyBlog! Found it interesting? Hit that link 🔗 button and send to a friend! If you have questions or want to explore how these solutions apply to your environment, contact the LandSkyAI team below to start a conversation. ✌️
Sources
Protect Critical Infrastructure and Public Gatherings | CISA
Federal Laws Restrict Counter-Drone Measures for Critical Infrastructure | Dronelife
How Utilities Are Tackling Rising Physical Threats to Power Grids | IEEE Spectrum
Drone Attack Simulation Exposed a Grid Vulnerability, Utilities Say | Utility Dive
EPA and WaterISAC Caution Utilities on Drone Threats | Industrial Cyber
Protecting Critical Infrastructure From Weaponized Drones | Domestic Preparedness
Beyond Visual Line of Sight (BVLOS) | Federal Aviation Administration



