Group Purchasing
Group Purchasing

Securing the Next 250: What It Takes to Defend Critical Infrastructure Today

Protecting operational technology is no longer just an industry concern, it's a matter of national resilience.

Authored bySANS Institute
SANS Institute

For most of us, critical infrastructure fades into the background. We flip on a light switch, turn on the faucet, or fill up at the gas station without giving much thought to the systems that make those everyday moments possible.

That was the starting point for our recent webcast, "Securing the Next 250: ICS Threats, Practical Defense, and the Skills Gap We Need to Close," where SANS CEO James Lyne sat down with SANS Certified Instructor Jason Christopher to discuss the evolving threat landscape facing industrial control systems (ICS) and what organizations can do to strengthen their defenses.

The conversation couldn't have been timelier. As geopolitical tensions continue to rise and cyberattacks against critical infrastructure become more common, protecting operational technology (OT) is no longer just an industry concern, it's a matter of national resilience.

Critical Infrastructure Faces a Different Kind of Security Challenge

One of the biggest themes throughout the discussion was that securing ICS environments isn't simply an extension of traditional IT security. In enterprise environments, confidentiality often takes center stage. In OT, the priorities are different. Safety and availability come first. If a security control causes a power plant, refinery, or water treatment facility to stop operating safely, the consequences extend far beyond lost productivity.

Christopher explained that many industrial environments still rely on legacy systems that were never designed with today's cyber threats in mind. Some devices have limited processing power, making it difficult, or impossible, to deploy the same security tools organizations routinely use in corporate networks. Even adding encryption or endpoint protection can introduce latency or operational risks that aren't acceptable in industrial environments.

Visibility Is Still One of the Biggest Gaps

Before organizations can improve security, they need to understand what they're protecting. Christopher emphasized that asset visibility remains one of the biggest challenges in OT environments. Many organizations are still working toward a complete understanding of the devices, communications, and dependencies that exist across their operational networks.

Without that visibility, it's difficult to detect abnormal behavior, prioritize vulnerabilities, or make informed risk decisions. Building an accurate picture of the environment remains one of the most practical and impactful places to start.

AI Is Changing the Landscape, but Fundamentals Still Matter

The discussion also explored the growing role of artificial intelligence in cybersecurity. Both Lyne and Christopher agreed that attackers will continue to adopt AI to increase speed and scale, but that doesn't diminish the importance of experienced defenders. Instead, it raises the value of professionals who understand both cybersecurity and industrial operations. Technology will continue to evolve, but understanding how industrial processes work, recognizing operational risk, and making sound decisions during incidents remain skills that AI cannot replace.

Closing the Skills Gap Takes More Than Hiring

One of the most important conversations centered on the industry's workforce challenge. Rather than describing it simply as a talent shortage, Lyne framed it as a skills challenge. Organizations don't just need more cybersecurity professionals. They need people with practical, hands-on experience who understand the unique realities of industrial environments.

Christopher echoed that point, noting that effective ICS security depends on people, processes, and technology working together. Organizations benefit from multidisciplinary teams where engineers learn cybersecurity principles, and security professionals gain a deeper understanding of operational technology. That kind of cross-functional knowledge becomes increasingly important as critical infrastructure continues to modernize.

Build the ICS Skills Your Mission Requires

SANS ICS Security offers role-based learning paths designed for every team that touches an industrial system, from program leaders and cyber defenders making the transition from IT to OT to engineers taking on cyber responsibility and advanced responders working in high-consequence environments.

Key courses are aligned with GIAC certifications, GICSP, GCIP, and GRID. These certifications are independently proctored and recognized across federal agencies and the contractor community.

Security Is a Shared Responsibility

The webcast closed with an important reminder: protecting critical infrastructure isn't something any one organization can accomplish alone. The systems that power communities, move goods, produce clean water, and keep essential services running are deeply interconnected. Strengthening their resilience depends on collaboration across asset owners, vendors, governments, educators, and the broader cybersecurity community.

For 250 years, critical infrastructure has quietly supported nearly every aspect of modern life. Keeping it secure for the next 250 will require continued investment in practical defenses, stronger visibility into operational environments, and a workforce equipped with the skills to meet tomorrow's challenges.

If you missed the live session, you can watch the webcast recording here.