Guard’s Cyber Shield tests power-sector OT with physical components
Power-sector response gets ugly when an intrusion crosses from information technology into equipment that actually moves electricity.
TL;DR
DefenseScoop reports that the National Guard’s 2026 Cyber Shield, running July 12-25 in Little Rock, is focused on defending power-sector operational technology (OT). More than 1,000 troops and civilian experts from 44 U.S. states and territories and 23 international partners are participating. The useful shift is the fully integrated physical component: state teams are rehearsing incidents where an information technology foothold turns into equipment damage and longer outages.
DefenseScoop reports that Cyber Shield 2026 has moved its annual critical-infrastructure scenario to the power sector, with more than 1,000 troops and civilian experts working the exercise in Little Rock through July 25. That is not a compliance deadline. It is a signal about what state responders expect the ugly incident to look like: an information technology (IT) foothold, a move into operational technology (OT), and recovery work that does not end when the malware sample is named.
The new part is the physical layer. Lt. Col. Seth Barun said the exercise has used a physical component before, but this is the first year it is fully integrated into the system, alongside power-grid simulation and real-world tactics, techniques and procedures from malicious actors. Tim Conway of SANS Institute put the practical problem plainly: attacks on generation, transmission and distribution can destroy equipment and produce outages that are harder to unwind than ordinary IT incidents.
For utilities, state cyber teams and Guard units, the Monday lesson is narrow and hard: incident response plans that stop at network containment are incomplete. The exercise is practicing the handoff from IT forensics to OT recovery, where defenders have to find the attacker and bring power-sector equipment back without extending the outage.
Published ·Deep Fathom