Ferndon Consulting offers an innovative Intelligence as a Service (IaaS) that utilizes detailed intelligence to enhance risk management processes, thereby fostering organizational resilience during times of dynamic change. Our expertise focuses on supporting both public and private critical infrastructure and those engaged with it.
We provide a fundamental toolkit aimed at executives, risk managers, security managers, and stakeholders to deepen their understanding of the emerging security threats and evolving risks faced by critical infrastructure today. The Executive White Paper is a concise 3-page document, complete with a summary and a Table of Contents, that addresses the key highlights. In addition, other documents delve deeper and provide comprehensive context and justification, primarily tailored for security managers, risk managers, emergency managers, or individuals seeking a better understanding to support their personal awareness or assist in resource justification.
System-Transmitted Disasters in Critical Infrastructure: Executive White Paper (2026) (pdf)
DownloadAdversarial Capabilities impacting Critical Infrastructure: China, Russia, Iran, and more in 2026 (pdf)
DownloadCase Studies regarding Threat to Critical Infrastructure: Complex Interdependency in 2026 (pdf)
DownloadComments from Lt. Gov. Jarrid (Jay) Collins (FL), reproduced with permissions (pdf)
Download
Many attacks are intentionally targeting critical infrastructure, and some of our opponents are overtly encouraging their operators to exploit the 'weak links' within our critical infrastructure to maximize damage to our society. Achieving organizational resilience requires more than just hardening individual assets; it necessitates understanding how failure propagates through the system. This is where Intelligence as a Service plays a crucial role, enabling dynamic resilience for organizations facing security threats.
Critical infrastructure serves as both a pillar of our society and a vulnerable aspect of our nation. By employing intelligence-driven risk management, we can maximize agility and resilience in rapidly evolving and complex environments.

China perceives economic marginalization as a legitimate military threat, particularly in terms of its impact on critical infrastructure. The Chinese military doctrine underscores the importance of targeting opponents’ critical infrastructure to mitigate kinetic conflict effectively. Concurrently, their national strategy adopts a ‘whole o
China perceives economic marginalization as a legitimate military threat, particularly in terms of its impact on critical infrastructure. The Chinese military doctrine underscores the importance of targeting opponents’ critical infrastructure to mitigate kinetic conflict effectively. Concurrently, their national strategy adopts a ‘whole of nation’ approach to conflict, officially integrating their ‘Military-Civil Fusion’ concept. The strategic objective is not merely data theft; rather, it aims to establish dormant access points that can disrupt or paralyze critical sectors such as energy, water, and transport during a geopolitical flashpoint, reflecting a sophisticated understanding of risk management and organizational resilience against potential security threats.

Russia has been intentionally targeting both opponents’ and critical infrastructure related to potential supply chains. This approach has rendered many traditional laws of warfare inconsequential; hospitals, international underwater cables, and telecommunications infrastructure are all considered legitimate targets. Furthermore, commercia
Russia has been intentionally targeting both opponents’ and critical infrastructure related to potential supply chains. This approach has rendered many traditional laws of warfare inconsequential; hospitals, international underwater cables, and telecommunications infrastructure are all considered legitimate targets. Furthermore, commercial entities are increasingly viewed as economic proxies in broader geopolitical conflicts, highlighting the need for effective risk management and organizational resilience against evolving security threats. The rise of Intelligence as a Service also plays a crucial role in understanding and mitigating these risks.

Iranian proxies are already attacking American critical infrastructure, as evidenced by the 2026 Stryker attack, which was claimed by Iranian Proxy Groups. Iranian assets, surrogates, and radicalized extremists have emerged as significant security threats that require attention. While previous threats have predominantly focused on cyber a
Iranian proxies are already attacking American critical infrastructure, as evidenced by the 2026 Stryker attack, which was claimed by Iranian Proxy Groups. Iranian assets, surrogates, and radicalized extremists have emerged as significant security threats that require attention. While previous threats have predominantly focused on cyber access, the rise of radicalized extremists and proxy fighters has been identified as a legitimate concern in the US 2026 Counterterrorism Strategy. This highlights the need for robust risk management and organizational resilience, along with the integration of Intelligence as a Service to effectively counter these evolving threats.

Weather deserves to be highlighted not only for its compounding attacks but also for its everyday effects on critical infrastructure. Both water and heat are impacting operations and presenting compounding challenges directly at home and within the international supply chain, which necessitates effective risk management strategies. Weathe
Weather deserves to be highlighted not only for its compounding attacks but also for its everyday effects on critical infrastructure. Both water and heat are impacting operations and presenting compounding challenges directly at home and within the international supply chain, which necessitates effective risk management strategies. Weather Intelligence, also referred to as 'Climate Intelligence' (CLIMINT), is an emerging specialty that supports organizational resilience and addresses various security threats. Additionally, this field can be considered a vital aspect of Intelligence as a Service.

Financially motivated cybercrime and state-sponsored gray-zone operations do not operate in isolation. The contemporary threat landscape is marked by a perilous convergence where transnational criminal organizations (TCOs) and illicit financial networks are increasingly weaponized as state proxies. This exploitation of critical infrastruc
Financially motivated cybercrime and state-sponsored gray-zone operations do not operate in isolation. The contemporary threat landscape is marked by a perilous convergence where transnational criminal organizations (TCOs) and illicit financial networks are increasingly weaponized as state proxies. This exploitation of critical infrastructure vulnerabilities poses significant security threats, necessitating effective risk management strategies and a focus on organizational resilience. Moreover, the rise of Intelligence as a Service further complicates the dynamics of this evolving environment.
Please reach us at team@ferndon.com if you cannot find an answer to your question.
The federal government has maintained a centralized standard in conjunction with funds, grants, resources, and assessors to support the national security posturing for Critical Infrastructure. However, in 2025, this centralization was significantly reduced and most responsibility was returned to more local authorities without significant coordination of effort or allocation of resources. While many leaders in Critical Infrastructure have been leaning forward, information, resources, and even knowledge of shared risk has not been fully available during a time of rapid change and increased pressure.
This transition was not exhaustively planned, nor impacts projected, and much traditional resourcing for previously projected standards has not been maintained. Simultaneously, many other challenges have emerged in security and sustainability. The conjunction of reduced central efforts balancing the complex interdependencies of Critical Infrastructure with a rapidly changing threat environment amidst outdated baseline standards has created a perfect storm that marginalizes historical substantiating for risk management and emphasizes the need for increased transparency among inter-dependencies and collaborative input from subject matter experts.
While existing Risk Management Frameworks may be flexible enough to accommodate such material changes in context, the increased complexities and interdependencies in the risks, regulations, and control environments must be acknowledged in the application of those frameworks (e.g., in the understanding and assessment of risks and in the design of controls). Further, most Risk Management Frameworks leverage historical data and trends, many of which are increasingly less applicable for some future projections. Rapid geopolitical change, technological evolution, and widespread societal tensions all come together to create a very new operational environment wherein decision makers’ traditional understanding often falls short of optimal.
The interconnected Critical Infrastructure network is still regulated by outdated shared standards, several of which date back to the 2013 standards, as of June 2026 with no projected date for revision. While organizations abiding by federal standards are still in official compliance, this compliance is insufficient in face of the current and emerging risk environment. If focusing on compliance rather than contextually refined resilient risk management, organizations can become blind to contemporary vector mechanics, including automated exploit chains and multi-stage infrastructure infiltration. The Federal Government has been increasing other security parameters, such as increased cyber security standards for the Defense Industrial Base (DIB), but this is focused more directly on the defense sector, has not necessarily been tied to resources that can enable this increased security, and has not expanded to include other key sectors in Critical Infrastructure.
It is called “Critical Infrastructure” for a reason. This is the infrastructure in our country on which our way of life is dependent for its continuation and stability. However, like any large amalgamated entity, it has innumerable points of vulnerability that are both comparatively accessible and widely interconnected.
Critical infrastructure is interdependent across sectors and state lines: it does not fail neatly. Infrastructure doesn’t follow clear jurisdictional boundaries, and energy, transportation, communications, finance, water, healthcare, and cloud services are connected in ways that are prone to producing second and third order effects. While individual organizations may fastidiously harden their own internal systems, they remain fundamentally bound to a complex web of external dependencies, ranging from very rural access points and hubs to international energy and communication corridors.
The breadth of vulnerability exposes society – as a whole – to sudden losses of power, loss of financial accessibility, and loss of resources. This can be as significant as a traditional “eat all the ice cream in the freezer due to the power outage” instance, an isolation of emergency response personnel from their children or elderly parents in care homes, or significant reductions in available water, food, and other necessary life resources.
We have an exceptionally resilient and strong society. However, American has been isolated from the impacts of geopolitical conflict for most of her history. Attacks were made with physical weaponry – now attacks are not geographically bound. Additionally, America has had a very long tradition of a “Sovereign Nation of Many Sovereign States”: the Federal Government has assumed a lot of responsibility since WWII. Examples can be drawn from welfare, education standards, FEMA emergency response, and health insurances. Much of America is under-prepared to re-assume traditional responsibilities – many have not experienced a country without the Federal Government pushing resources down to states, municipal, and local authorities. And, in lieu of centralized, updated standards during a time of economic and supply chain upheaval, many organizations will cut costs wherever they can: they are less likely to focus on “Just in Case” or “good neighbor” security measures.
While many organizations and leaders have been intentionally forward-leaning and adapting rapidly to the emerging threats, the inter-nationality of these threats creates a different nuance for mitigation measures, and the intensity of the changes are often under-appreciated.
Working with Emergency Managers brought many of our original realizations to the fore-front. One particular conversation with a municipal Emergency Manager brought up his frustration with a sudden loss of all grant funding, his perceived refusal of his elected officials to allocate funds to off-set the grant reduction, what he saw as increased secrecy and stove-piping among industry and infrastructure within his jurisdiction, and his inbox being flooded with alerts regarding increased threats. He saw the challenge: the increasing liability of inter-connectedness with decreased resources and increased threat. And he didn't know how to feed the right information into the municipal RMF to justify attention from officials.
Some politicians are definitely aware of this challenge. Lt. Gov. Collins of Florida stated on June 10, 2026:
When I look at the threats facing Florida, I see cyber threats, physical security threats, foreign influence operations, narcotics trafficking, drones, combined and hybrid threats, weapons of mass destruction concerns, EMP threats, and other emerging risks. The world is evolving rapidly, and the threat environment is becoming more complex every year.
That concerns me.
Not because we have failed, but because I see how quickly the environment is changing.
(See the attached, full and lightly edited, transcript - reproduced with permission from the office of the Governor of Florida on July 16, 2026)

Ferndon Consulting has partnered with Loughnane Associates to provide you with our services, available through the GSA Schedule. Our offerings are flexible but currently include:
Our trainers and coaches have been there and done that. They're teaching with quality material in a context that can only come from years of experience.
Our offerings are able to be tailored and are designed to meet your need rather than provide a static training deck. Our intent is to enable your success within a context that you know best.
Our services are committed to a high standard. That means no "bait and switch" with under-qualified representatives or stagnant training decks developed by others.
Copyright © 2026 Ferndon - All Rights Reserved.
We use cookies to analyze website traffic and optimize your website experience. By accepting our use of cookies, your data will be aggregated with all other user data.