Vision Detection Systems
Critical Infrastructure Physical Security: A Practical Playbook for Site Operators
BLOG | UTILITY SECURITY

Critical Infrastructure Physical Security: A Practical Playbook for Site Operators

Physical attacks and theft against critical infrastructure are rising across nearly every dataset regulators publish. This playbook covers the threat picture, what regulation does and does not require, and a layered deter-detect-verify-respond model that site operators can apply to substations, water plants, towers, and energy facilities.

BYVDS Editorial
PUBLISHEDAugust 2026
READ8 min
UTILITY
SUMMARY

Critical infrastructure physical security is the discipline of protecting substations, water treatment plants, cell towers, pipelines, and energy facilities against intrusion, sabotage, theft, and vandalism. The problem is measurable and growing. Per IEEE Spectrum's coverage of E-ISAC and NERC data, a trade-press summary of E-ISAC data, the E-ISAC's latest annual report logged more than 3,500 physical security incidents against the grid, up from roughly 2,800 the year before, with about 3 percent of those incidents disrupting electricity. No regulation covers most of these sites, so protection comes down to a layered model: deter intruders, detect them early, verify what is actually happening, and get the right responder there fast. This playbook walks through each layer and how it applies across the electric, water, telecom, and energy sectors.

How serious is the physical threat to critical infrastructure?

Every major public dataset points the same direction: physical incidents against infrastructure are climbing, and in some regions they are climbing fast.

The regional numbers are the starkest. The FERC 2025 Summer Assessment reported 220 physical security incidents in the Western Interconnection in 2024, more than double the 107 recorded in 2023. Federal outage reporting shows the same trajectory over a longer window. According to an analysis of DOE OE-417 filings by the Kansas Legislative Research Department, the data recorded at least 175 physical attacks or threats against grid infrastructure in 2023, roughly double the 2021 figure.

The motives split into two broad categories, and they call for overlapping but distinct defenses.

Deliberate attacks on equipment

Gunfire against transformers, cut fences at transmission stations, and sabotage attempts target the function of the asset itself. These incidents are less frequent than theft but carry outsized consequences: a damaged high-voltage transformer can take months or longer to replace, and a coordinated attack on a handful of key sites can affect service far beyond the fence line. This is the scenario that federal regulation, covered below, was written to address.

Theft and vandalism at scale

The far more common threat is economic. Copper grounding wire, cable, tools, and equipment draw thieves to unmanned sites, and the damage they cause on the way out often exceeds the value of what they take. The scale is easy to underestimate: AT&T reported more than 10,000 copper theft incidents in 2025, with losses above $80 million, at one company. Rising copper prices keep the incentive strong, a trend we track in detail in our 2026 copper theft outlook.

What does regulation cover, and what does it leave out?

The short answer: mandatory physical security standards cover a thin slice of the grid, and almost nothing else.

For the electric sector, NERC CIP-014 is the binding standard. It requires transmission owners to identify stations and substations whose loss could cause instability or cascading outages, assess their vulnerabilities, and implement documented physical security plans. But CIP-014 was deliberately scoped to the most consequential sites, which means the vast majority of distribution substations fall outside it. Our deep dive on substation physical security and CIP-014 covers what the standard requires, who it applies to, and what to do if your sites are not on the list.

Outside the bulk electric system, the picture is mostly voluntary. Water utilities, telecom operators, and many energy facilities work from guidance rather than mandates. The best starting point is CISA, the federal agency responsible for critical infrastructure security, which publishes sector guidance, vulnerability assessment tools, and free field services that any operator can use regardless of size.

One federal requirement does reach camera procurement itself. Section 889 of the 2019 NDAA bars federal agencies and their contractors from using video surveillance equipment from certain covered manufacturers, including Hikvision and Dahua, and many utilities now apply the same bar as internal policy even when not contractually required. If your organization touches federal contracts or simply wants to align with federal supply-chain policy, our NDAA compliance overview explains what the restriction covers and how to verify equipment.

The practical takeaway for operators: treat regulation as the floor, not the plan. If you wait for a mandate to secure a site, most of your sites will never be secured.

Layered perimeter protection at an infrastructure site
Deter, detect, verify, respond — in that order

The layered protection model: deter, detect, verify, respond

No single control protects an unmanned site. Fences get cut, cameras without monitoring only document losses, and response without verification wastes everyone's time. The model that works stacks four layers so that each one covers the failure mode of the layer before it.

LayerGoalTypical measures
DeterMake the site a poor targetFencing, lighting, signage, visible cameras, audio warnings
DetectKnow about intrusion in minutes, not morningsPerimeter cameras, AI motion analytics, monitored alerts
VerifyConfirm a real threat before anyone rollsTrained operators reviewing live video, escalation criteria
RespondPut the right person on a confirmed incidentDocumented call trees, law enforcement handoff, security partner dispatch

Deterrence: most incidents are prevented, not interrupted

Visible security changes target selection. Marked camera units, working lighting, and intact fencing signal that a site is watched and that easier targets exist elsewhere. Live audio talk-down, where an operator addresses an intruder through an on-site speaker, extends deterrence into the moment of intrusion and resolves many events before anything is cut or taken.

Detection and verification: the pairing that makes cameras useful

Detection without verification produces alert fatigue; remote sites generate constant nuisance triggers from wildlife, weather, and vegetation. Human verification through 24/7 remote video monitoring filters those out, so an alert that reaches a responder comes with a confirmed description of who is on site and what they are doing. That confirmation matters downstream: law enforcement consistently prioritizes verified in-progress incidents over automated alarms.

Response: decide the call tree before the incident

Write down who gets called for each incident type, in what order, and with what information. A verified intrusion at a CIP-014 site, a copper thief at a rural substation, and a trespasser at a water plant each warrant a different first call. Sites that skip this step lose the value of fast detection to slow, improvised response.

Sector notes: how the playbook changes by asset type

The four layers apply everywhere, but the emphasis shifts with the asset.

Electric: substations and switchyards

Substations face both threat categories at once: deliberate attacks on transformers and relentless theft of copper grounding conductor. Grounding theft is especially dangerous because it can leave equipment and workers unprotected against fault current long before anyone notices the loss. Start with the substation physical security playbook for the regulatory and layout context, then see our guide to preventing copper theft at substations for the theft-specific measures.

Water and wastewater

Water systems combine public health exposure with thin security budgets and widely distributed unmanned sites: treatment plants, remote wells, lift stations, and storage tanks. Verified video coverage of chemical storage areas and access points does double duty for security and regulatory documentation. Our guide to security cameras for water treatment facilities covers site-by-site priorities.

Telecom: towers and exchange infrastructure

Tower sites and cable routes are the epicenter of the copper theft surge reflected in AT&T's numbers above, and a single cut line can sever 911 access for a whole area, which raises the stakes well beyond the scrap value taken. Remote tower compounds are rarely staffed and often lack grid power for security equipment, which is why self-powered monitored units fit them well. See our breakdown of cell tower security and copper theft.

Energy: pipelines, terminals, and renewable sites

Pipeline rights-of-way, tank farms, and solar and wind facilities share a common profile: long perimeters, remote locations, and high-value copper and equipment concentrations. Solar farms in particular hold miles of copper cabling and rows of inverters far from any road. The same layered model applies, with extra weight on wide-area detection and on response plans that account for long law enforcement drive times.

Monitoring as a force multiplier for utility security teams

Utility security teams and their security partners cannot staff every remote site, and they should not have to. Monitored surveillance works as a force multiplier: cameras and operators provide continuous watch across dozens or hundreds of unmanned locations, and people, yours or your security partner's, handle the verified incidents that actually need a human on scene. Patrols get directed by confirmed information instead of fixed routes, and guard-force hours concentrate where live incidents and high-risk windows demand them.

This is where Vision Detection Systems fits the infrastructure problem specifically. VDS deploys solar-powered mobile surveillance units backed by 24/7 monitoring, so coverage does not depend on grid power, trenching, or network buildout at the site, and units can move as construction phases, outage seasons, or threat patterns shift. For operators aligning procurement with federal supply-chain policy, equipment provenance is documented against the NDAA covered list.

Where to start: a practical first-90-days sequence

  1. Inventory and rank your sites. List every unmanned facility and score it on consequence of loss, theft attractiveness (copper, tools, chemicals), and incident history.
  2. Check your regulatory posture. Confirm which sites, if any, fall under CIP-014 or contractual NDAA requirements, and pull the relevant CISA sector guidance for the rest.
  3. Walk your top five sites. Look for cut-and-repaired fencing, missing grounding straps, dark corners, and dead cameras. Prior repair marks usually mean repeat visits.
  4. Close the verification gap first. If cameras exist but nobody watches them, adding monitored verification typically changes outcomes faster than adding hardware.
  5. Write the call tree. Define escalation contacts per site and incident type, share it with local law enforcement, and test it once a quarter.

Attackers and thieves both look for the same thing: sites where nothing happens when they arrive. A layered program, applied first to your highest-consequence and highest-theft sites, takes that assumption away.

Frequently asked questions

What is critical infrastructure physical security?

It is the protection of physical assets like substations, water treatment plants, cell towers, and energy facilities against intrusion, sabotage, theft, and vandalism, using layers of deterrence, detection, human verification, and response rather than any single control.

Does CIP-014 cover my facility?

NERC CIP-014 applies only to a small set of transmission stations and substations whose loss could cause instability or cascading outages, so most substations, all water and telecom sites, and most energy facilities fall outside it and rely on voluntary guidance such as CISA's.

What is the deter-detect-verify-respond model?

It is a layered protection approach where visible measures discourage intrusion attempts, sensors and cameras detect activity early, trained operators verify whether an alert is a real threat, and a defined escalation path sends the right responder to confirmed incidents.

Why does human verification matter for infrastructure sites?

Remote perimeter sites generate frequent nuisance alerts from wildlife, weather, and vegetation, and human verification filters those out so law enforcement and security teams respond to confirmed incidents with real-time details instead of chasing false alarms.

Does remote video monitoring replace on-site security teams at utility sites?

No, it works as a force multiplier alongside utility security teams and their security partners, watching many unmanned sites continuously and escalating verified incidents so people handle the situations that actually need them.

Protect Your Critical Sites

Solar-powered mobile surveillance units with 24/7 monitoring deploy at substations, water facilities, towers, and remote energy sites without trenching or grid power. Talk to our team about your asset list.