Urgency overhead: how utilities can conduct a drone threat risk assessment

Urgency overhead: how utilities can conduct a drone threat risk assessment

Share this content

Facebook
Twitter
LinkedIn

Kara Quesada, Senior Director of Marketing at Echodyne looks at how utilities can conduct a drone vulnerability and risk assessment.

A step-by-step approach

Utility security teams – across substations, transmission networks, water facilities, renewable energy sites, data centers (especially with the surge in AI) and other critical assets – are increasingly aware that the drone, also referred to as a Small Unmanned Aircraft System (sUAS), threat to critical infrastructure is real, persistent and evolving. Because of this, there is a growing sense of urgency to honor the industry’s “duty of care”, the legal and ethical obligation to take reasonable measures to protect people, assets and information from foreseeable harm.

This urgency is not theoretical. Under the current Administration, we are seeing significant momentum to secure everything from large-scale events (including funding to incorporate counter-drone systems at the World Cup) to granting trained state, local, tribal and territorial (SLTT) law enforcement the authority to mitigate drone threats under the recently passed Safer Skies Act. The reason is simple: drone incidents continue to surface globally – at airports, utilities, stadiums and more – and security leaders know it is far better to get ahead of the problem than chase a solution once it’s too late.

This is where structured leadership matters. As COL (R) Bill Edwards, a nationally recognized counter-UAS expert and Drone Vulnerability and Risk Assessment (DVRA) creator, emphasizes, “Organizations must move beyond general awareness and adopt disciplined, repeatable frameworks such as the DVRA to transform anxiety into action. A DVRA provides utilities with a doctrinal method for prioritizing sites, evaluating airspace vulnerabilities, assessing threat actor capabilities, identifying detection gaps and integrating findings into enterprise risk management and emergency response planning.”

Below is a step-by-step approach aligned with a few DVRA principles and informed by real-world sUAS operational experience.

Step 1: Identify the threat

The drone threat takes many forms and security professionals must understand the full spectrum of sUAS capabilities. Some operators conduct reconnaissance – capturing imagery, mapping facilities or surveilling security patterns. Others use drones to carry payloads or act as destructive agents, capable of damaging equipment, disrupting operations or harming personnel. Recent examples include an individual attempting to deploy an explosive-laden drone near a Nashville power plant and another intentionally crashing a drone into a Pennsylvania substation.

Drones can also be used as vectors for cyber-intrusion. Small, inexpensive Wi-Fi hacking devices can be flown into a site and left behind to enable wireless data exfiltration. And finally, utilities must account for the “reckless” or uninformed hobbyist who unintentionally violates restricted airspace – and may yet cause operational disruption and property damage.

As COL (R) Edwards often notes, “intent does not change impact.” Whether due to carelessness or malice, every drone incursion has operational, safety and reputational consequences. Understanding these threat types is the foundation of any credible DVRA.

Step 2: Identify critical assets

Once threats are defined, utilities must also identify the assets that matter most. Every site has a unique mix of people, visitors, sensitive data, command-and-control systems and operational machinery essential for daily operations. Each can be affected differently by a drone incursion.

For utilities, critical assets often include transformers, switchgear, communications infrastructure, control buildings and energy storage systems. Renewable energy sites must consider solar arrays, inverters and wind turbines. A comprehensive asset catalogue allows security teams to prioritize what must be protected and where deeper analysis is required.

This step aligns directly with DVRA doctrine: you cannot protect what you have not defined.

Step 3: Identify the vulnerabilities

With a clear inventory, teams can now assess how each asset could be exposed to aerial threats. This is where many utilities discover that their legacy security posture is over-indexed on ground-based threats. Traditional protection models assume adversaries approach horizontally – not vertically.

From a drone’s vantage point, vulnerabilities become obvious. Transformers and control systems are exposed from above. Terrain such as hills, ridgelines or adjacent buildings may provide concealed approach paths. Public roadways or open fields may offer easy launch points.

A DVRA forces teams to adopt the adversary’s perspective – to think like a drone operator, not a fence designer.

Step 4: Determine the consequences

Once vulnerabilities are understood, utilities must determine the consequences of a successful drone incursion: personnel injury, power outages, fires, equipment damage, environmental impact, reputational harm and regulatory exposure. In some systems, a single point of failure can cascade across multiple sites.

For example, if a drone were to crash – intentionally or accidentally – into a gas storage tank, the team must understand the potential blast radius, typical personnel presence and the operational impact on the broader system.

This is not fearmongering; it is leadership. As COL (R) Edwards teaches, “Critical asset identification and consequence analysis are the means by which organizations prioritize resources and justify investment.”

Step 5: Determine risk mitigation

With threats, assets, vulnerabilities and consequences defined, utilities can now identify mitigation strategies. These may include enhanced monitoring, changes to operational protocols, coordination with law enforcement or the adoption of drone-detection technologies.

Mitigation should aim to reduce both the probability of a successful drone incident and the response time once a drone enters the airspace. This step often reveals a hard truth: conventional security systems were never designed to “look up.” Addressing aerial threats requires purpose-built technologies and trained personnel.

This is where DVRA transitions into Drone Emergency Response Planning (DERP) – a structured approach to detection, decision‑making, communication and response.

From risk assessment to layered security

Once the DVRA is complete, utilities can begin architecting solutions. For sites where drones pose a risk, layered detection is essential. No single sensor can protect a utility on its own.

  • Radar is the backbone of any effective detection system. It is the only sensor capable of detecting all drone types – including “dark drones” that emit no RF signals – and operating day or night in all weather conditions
  • Pan-tilt-zoom cameras provide visual confirmation, enabling teams to determine payloads, intent and flight behavior
  • RF sensors offer additional verification and, in some cases, the ability to identify the drone operator’s location

When integrated, these sensors create a layered architecture that increases situational awareness and gives operators data intelligence and time to act before a disruption occurs.

This layered approach reflects the leadership principles COL (R) Edwards champions: education, DVRA, layered detection, DERP and Left‑of‑Launch planning.

From awareness to assessment to action

As drones become more sophisticated, they will continue to challenge traditional security models. Their ability to bypass ground-based defenses gives them an advantage – but only if utilities remain reactive.

Forward-leaning organizations are now embracing DVRA-driven frameworks, integrating layered detection technologies and treating airspace security as a core component of their duty of care. By shifting from awareness to assessment to action, utilities can take control of their airspace and reduce the likelihood of operational disruption.

This is the leadership mindset utilities need today: proactive, structured and informed by real-world sUAS expertise.

This article was originally published in the April edition of Security Journal Americas. To read your FREE digital edition, click here.