Curtis Walters, Vice President of Critical Infrastructure Sales, Echodyne tells SJA about the counter-drone solutions available to critical infrastructure sites.
Article Chapters
ToggleThere are three primary threats facing critical infrastructure at the moment, although we’re starting to see these converge.
These are: cyber, physical and unmanned or drone-based threats. Â
For critical infrastructure, cyber-attacks and ransomware have long been threats facing operational and information technology systems.
Meanwhile, physical sabotage and insider activity is still a challenge. Often these two will be used in conjunction with one another, but now we’re also seeing drones being used not just as a kinetic threat, but as a cyber one too.
These small, inexpensive drones can be fitted with sensors and explosives, placed exactly where an attacker wants them.
They can bypass the normal boundaries of a fenceline and other perimeter protection solutions, potentially causing a great deal of damage.
One of the biggest shifts we have seen in the industry is the airspace above critical infrastructure sites becoming an attack surface that anyone with a charged battery and $100 dollars’ worth of equipment can target.
Put simply, drones are very inexpensive. Someone willing to spend a few hundred dollars can cause millions upon millions of dollars in damages.
They’re also very readily available to bad actors. If they can make their way past perimeters, then they can loiter for surveillance purposes, drop contraband or even carry explosives to destroy vulnerable equipment.
However, there may be drones flying around critical infrastructure sites that are used for official reasons, such as by the facility to check on equipment and maintenance issues, or from others who are not bad actors but are flying drones for fun.
There’s a lot of noise to sift through.
That can make it very easy for bad actors to hide among the proper drones that are supposed to be there, adding to the challenge of detecting them.
Traditionally, RF sensors that detect signals between a controller and its drone have been the primary method of detecting these threats.
Depending on where you are, there can be potential legal hurdles against the physical mitigation of drones, because they are considered aircraft.
We’re starting to see those laws changing though and there’s actually some tailwinds in our favor.
Very recently, we’ve seen developments with the Department of Homeland Security (DHS) and Federal Emergency Management Agency (FEMA) funding around the FIFA events that are occurring in the US later this year, with law enforcement now having the capability to mitigate the threat of drones.
So, these laws are continuing to evolve and there is legislation that could potentially extend that mitigation capability into critical infrastructure, security teams and others.
Without that today though, we still feel it’s important to assess your environment and understand flight patterns.
If you’re not taking steps to really understand the airspace around your facility, it’s going to be much more difficult to differentiate good and proper use versus the true bad actors.
Even if facilities cannot physically mitigate the threat of drones, there is still a lot of benefit in detecting them using sensors. It means if contraband is dropped on a correctional facility, it can be collected before it an inmate can obtain it.
If you are protecting an electrical substation, then you’ll understand why the airspace is so critical from a mitigation perspective, so teaming up with local law enforcement can help as they often have the capability to physically mitigate drones.
You will also have an understanding of when the facilities drones are in use, so any solution that allows you to detect an unknown drone means you can pass this information along to law enforcement, telling them you think some suspicious activity is happening.
The more you can prepare yourself the better, so when the threat does come you can react swiftly.
Having a sensor to detect a drone is not the only solution available, however. These can be integrated with cameras, video analytics and other solutions.
This helps the threats to stick out to you, rather than looking for a needle in a haystack.
I’d say you take keep track of trade organizations.
Attend events, partner with your local law enforcement agencies and surround yourself with others who are ahead of the curve when dealing with these types of situations.
That’s the best way to keep up to speed.
In terms of technology, I think we’ll be seeing tighter integrations.
There will be more use of machine learning and AI to really understand the threat among the massive volumes of data that are generated each day.
I also think that counter-UAS, airspace safety and security solutions are going to become a standard line item for security teams to consider and purchase.
I don’t think they’re going to be special projects for airports and stadiums. We’ll be seeing these solutions in the same category as surveillance and access control systems.
We’re only going to be seeing more drones used by bad actors and they’re going to become even better at what they’re doing.
Drones are going to fly faster. Swarms are going to be an issue. Autonomous drones that coordinate with each other will be seen. So, these sophisticated attacks are going to evolve.
That’s why a hardened system that can see everything day, night, rain, shine and then quickly identify whether or not this is an actual threat is crucial.
From the vendor perspective, we’ll see enhanced performance, improved range and better classification.
Stronger sensors will help to solve this problem, as well as becoming more interconnected with other solutions providers.
I’d say don’t wait. Don’t wait for the perfect solution, for the ideal perfect law to come into place. This is going to evolve quickly. You need to stay ahead of the curve.
Every environment is different and every location is different. So, understanding your needs and requirements will allow you to truly build out your test and response plans.
I would be suspicious of single point solutions. Really evaluate and look at the fusion of radar, RF cameras, remote ID and smart software and understand the strengths and weaknesses of each.
Know how each of these will work for you and use that to become more resilient against these threats.
If you wait until an event occurs, you’re really going to be behind and it’s going to be a challenge to keep up if you haven’t done some of the homework to begin with.
This article was originally published in the March edition of Security Journal Americas. To read your FREE digital edition, click here.