Critical infrastructure, critical expertise

Critical infrastructure, critical expertise

Share this content

Facebook
Twitter
LinkedIn

Partners best positioned to support utilities and critical infrastructure are the ones who have built genuine knowledge in the sector writes Nikki Cardenas, National Channel Partner Manager, Gallagher Security Americas, with contributions from Steve Sinclair, Convergint Director of Utilities Market Vertical.

When a utility’s security fails, the consequences reach far beyond the fence line. Power outages cascade across cities, water treatment interruptions can affect public health and fuel disruptions ripple through supply chains that entire nations depend on.

Utility operators have always understood the stakes. What has changed is the speed, complexity and convergence of the threats they now face and what that demands from the partners they trust to help secure critical infrastructure.

The challenge has outgrown the checklist

According to reports citing the US Department of Energy, physical attacks on US electricity infrastructure have increased by as much as 70 percent in recent years.

Cyber-attacks on utilities alone have scaled significantly, with some quarters showing year-over-year increases exceeding 200 percent.

The threat environment utilities are operating in today bears little resemblance to the one most of their security infrastructure was designed for.

Utilities are managing expanded perimeters, with remote substations and distributed assets that weren’t part of the original security design.

They’re navigating converging physical and cyber risk, where access control decisions interact with OT/IT network boundaries in ways that require closer coordination.

Regulatory scrutiny under frameworks like NERC CIP continues to tighten, and the gap between those two points is where real exposure builds.

Evaluating technology by its specifications alone doesn’t account for this reality. What matters equally is the expertise behind it.

Knowledge as a security tool

Partner expertise in the utilities sector goes beyond product knowledge or the ability to execute an installation.

It’s the accumulated understanding of how utilities operate, where the vulnerabilities tend to appear, how unique regulatory obligations translate into practical security requirements and what implementation decisions will hold up under these operational conditions.

This knowledge is held by the engineers and project managers who have commissioned access control systems at substations, supported utilities through NERC CIP audits and have seen what happens when a system that looked adequate in design falls short in practice.

And it extends well beyond deployment, through technology refreshes, system expansions and the emergence of new threats; without disrupting the critical services communities depend on.

For utilities evaluating their security partners, the right question isn’t just “can they deploy this system?” It’s “have they built the depth of knowledge required to deploy and maintain it well, in an environment like ours?”

Building the tools for the task

Steve Sinclair, Director of the Utilities Market Vertical at Convergint, has spent more than 25 years advising utilities on physical security strategy, regulatory compliance and operational resilience.

His perspective on partner expertise is shaped by that depth of engagement across electric, gas and water utilities operating in some of the most regulated environments in the Americas.

Convergint’s utilityshield framework was built around this reality, helping utility leaders connect risk awareness, technology implementation, operational performance and documentation across the full lifecycle.

“Compliance is the baseline,” Sinclair says. “The real work is threat mitigation and understanding how the threat landscape is evolving.

In utility environments, the challenge is not just selecting technology.

It is understanding how that technology performs across substations, control centers, remote assets and compliance-driven operations where uptime, documentation and response coordination all matter.”

Translating that into practice takes more than individual expertise.

Convergint and Gallagher have developed shared implementation frameworks, joint deployment playbooks and educational resources that help teams in the field apply the right solution to the right environment.

Building genuine sector knowledge for the utilities that depend on it is ongoing and central to the partnership.

“Nothing happens without power or water,” Sinclair adds. “These are not environments where you can afford to get the security program wrong. When we engage with a utility, we’re functioning as advisors as much as implementers.

“The technology decisions we make together need to reduce risk and create measurable value over the life of the system, and that requires us to understand their environment at a level that goes well beyond the scope of a typical integration project.”

Building an ecosystem that delivers

The manufacturer-integrator relationship in critical infrastructure works best when it functions as a genuine partnership.

For Gallagher, that means treating Channel Partnerships as long-term working relationships where the expertise Partners carry into the field is as critical to the outcome as the technology itself.

That collaboration runs both ways: integrators encounter conditions at the sharp end of utility deployments that no product roadmap fully anticipates.

When those insights flow back to the manufacturer, they sharpen training, inform product development and raise the capability of the entire partner ecosystem.

Being global companies also means utilities benefit from a wealth of cross-regional experience.

Challenges that have already been navigated in one regulatory environment – whether NERC CIP in North America, NIS2 in Europe, or sector-specific mandates in the Asia-Pacific – inform how we approach deployments elsewhere.

Proven frameworks travel, and local nuance is layered on top. The result is a partner ecosystem that learns continuously and applies that knowledge where it matters.

What this means in practice is that the integrator deploying your access control system or perimeter protection installation will make hundreds of decisions that your security posture depends on.

The manufacturer whose platform underpins it will make hundreds more through firmware updates, feature development and support response over the years that follow.

Both need to understand your environment well enough to get those decisions right.

The investment that compounds

Utilities are long-horizon organizations. Security investments need to be evaluated on the same timeframe, which means looking past the technology itself to the ecosystem of expertise that determines whether it performs consistently and withstands evolving threats.

The partners best positioned to support that need are the ones who have built genuine knowledge in this sector.

For security leaders evaluating their options for critical utility infrastructure, that expertise is the prerequisite everything else should be measured against.

This article was originally published in the August edition of Security Journal Americas. To read your FREE digital edition, click here.

References

National Conference of State Legislatures. “Human-Driven Physical Threats to Energy Infrastructure.” 2023. https://www.ncsl.org/energy/human-driven-physical-threats-to-energy-infrastructure

Dareen, S., and V. Srivastava. “Cyberattacks on U.S. Utilities Are Up 70% This Year.” Fast Company, September 11, 2024. https://www.fastcompany.com/91189181/cyberattacks-utilities-surge-70-percent-check-point

Glassman, J. “Cyberattacks on Utilities Rise 200% in 2023.” Exponent, February 29, 2024. https://www.exponent.com/article/cyberattacks-utilities-rise-200-2023

North American Electric Reliability Corporation. “CIP: Critical Infrastructure Protection Reliability Standards.” Accessed 2025. https://www.nerc.com/standards/reliability-standards/cip