ai-cybersecuritytrade-pressNewsThe Broadside2 min read

AI sharpens threat to underfunded commercial critical infrastructure

A Pentagon cyber warfare official says the economics of defending commercially owned critical infrastructure weren't right before AI, and the gap is widening.


TL;DR

John Garstka, director of cyber warfare under the Pentagon's acquisition arm, warned at the Billington Cybersecurity Summit on Sept. 8 that AI is compounding the cybersecurity challenges facing commercially owned critical infrastructure providers, the same entities the Defense Department depends on for missions like those of U.S. Transportation Command. Garstka said providers "below the cybersecurity poverty line" are most exposed, and noted that Iranian nation-state actors are already creating effects against commercial critical infrastructure. DOD has run workshops with the Maryland National Guard on water, wastewater, and energy sectors to help operators build continuity plans for cyber attacks.

John Garstka, director of cyber warfare within the Office of the Deputy Assistant Secretary of Defense for Platform and Weapon Portfolio Management, told a Billington Cybersecurity Summit panel on Sept. 8 that AI is making an already bad economics problem worse for the commercial critical infrastructure sector.

"The existing cybersecurity challenges are getting exacerbated," Garstka said. "The most likely course of action is that cyber plus AI means that everybody's neighborhood is more dangerous."

Garstka placed the highest risk squarely on commercial providers (many of them smaller organizations that he described as "below the cybersecurity poverty line") that underpin mission-critical DOD operations. He pointed to U.S. Transportation Command as an example of a military function dependent on infrastructure the Pentagon doesn't own.

The threat isn't theoretical. Garstka cited Iranian nation-state actors actively creating effects against commercial critical infrastructure in multiple states. "The adversary gets a vote," he said. A CISA advisory updated July 22 details Iran-affiliated threats to programmable logic controllers, the kind of OT equipment that runs water systems, pipelines, and power grids.

CISA and international partners have been pressing OT owners on supply chain risk for some time. A January 2025 joint guide, "Secure by Demand," warned that threat actors target specific OT products rather than specific organizations, exploiting weak authentication, known vulnerabilities, and insecure defaults that let them move across multiple victims. In March 2024, GAO reported that CISA faced challenges delivering its 13 OT cybersecurity products and services effectively, a gap that matters more as the attack surface expands.

"We haven't gotten the economics of cyber defense right, even before AI showed up," Garstka said. "The demands of AI makes things even more challenging."

DOD has begun running critical infrastructure cybersecurity workshops through the Maryland National Guard, focused on water and wastewater and energy sectors. Garstka said one finding was that owners and operators haven't internalized that a large fraction of commercial providers could be hit in a single campaign, and they hadn't developed continuity-of-operations plans for scenarios where power, water, and standard communications are all down simultaneously.

For the compliance director at a mid-tier utility, the takeaway is concrete: if you can't operate without the grid, without water, and without your usual comms channels, you don't have a plan B. Garstka's point is that most operators still don't.


Published ·Deep Fathom

AI sharpens threat to underfunded commercial critical infrastructure — The Broadside