National Security
Critical infrastructure is the front line, and the intrusions are no longer about intelligence
Former deputy US national security adviser Anne Neuberger argues Chinese access to US communications, energy and transport networks is pre-positioning for sabotage. A summer of water utility compromises and a 7.49 million record utility breach made the point domestically.

Why is critical infrastructure now a national security cyber priority?
Intrusions into energy, water, transport and communications networks are no longer primarily about intelligence collection. Former deputy US national security adviser Anne Neuberger argues the access being established is pre-positioning for sabotage, and 2026 brought repeated water utility compromises plus a utility breach affecting 7.49 million records. Operators are being judged on resilience and recovery, not only on prevention.
Key facts
Writing in Foreign Affairs on 15 September 2026, Anne Neuberger says Chinese hackers have gained and retained access to US communications, energy and transportation infrastructure, with sabotage as the goal rather than intelligence gathering.
She cites Iranian hackers compromising water facilities across multiple US states this summer, with one county directing residents to boil water.
CenterPoint Energy disclosed a customer data breach in a Form 8-K filed 14 September 2026, with a threat actor claiming a dataset of millions of records.
Volexity attributed a 1 September 2026 spear-phishing campaign against NGOs to a China-linked actor chaining three patched Chrome and Windows flaws.
The argument from inside the room
Anne Neuberger served as deputy US national security adviser for cyber and emerging technology from 2021 to 2025. Her 15 September 2026 Foreign Affairs essay makes a blunt claim: intrusions into US communications, energy and transportation networks are not primarily espionage. They are groundwork for disruption, capable of causing blackouts, making water unsafe or delaying military mobilisation.
She frames it as a digital chokepoint problem, parallel to the Strait of Hormuz and critical minerals, and points to allied exposure as well: breached hospitals in Taiwan, power grids in India and telecommunications networks in Singapore.
The domestic proof points
Neuberger cites Iranian hackers compromising water facilities across multiple US states this summer, with one county telling residents to boil water. Small utilities are the soft edge of the national security perimeter, and they rarely have the budget of the sectors regulators watch most closely.
On the data side, CenterPoint Energy, which serves roughly 7 million customers across Texas, Indiana, Minnesota and Ohio, disclosed in a Form 8-K filed 14 September 2026 that an unauthorised party accessed customer personal information through an external-facing system. The company says operational systems for electricity and gas delivery were not touched and service was not disrupted, and that scope is still being determined.
Espionage tradecraft has not slowed down
Volexity reported that a China-linked cluster it tracks as UTA0560 targeted multiple NGOs on 1 September 2026 with a spear-phishing campaign that abused a reflected XSS flaw on a US university website to redirect victims into an exploit chain of two Chrome flaws and a Windows ALPC flaw, delivering a JavaScript backdoor called GRIMWEDGE.
Elsewhere, the group CikLeak claimed a breach of Russia's Central Election Commission voting system ahead of the 18 September State Duma elections, weeks after officials described the system as impossible to hack.
Why this lands on GRC desks
Pre-positioning changes what resilience means. The relevant question stops being whether an attacker can be kept out and becomes whether operations can continue, degrade safely and recover while an adversary already has access.
That is why frameworks like Canada's Critical Cyber Systems Protection Act, NIS2 and DORA all converge on the same demands: designated operators, documented programmes, supply chain accountability and mandatory incident reporting. The regulation follows the threat model, and the hiring follows the regulation.
What it means for you
Infrastructure risk is now national security risk, and it is being regulated as such on both sides of the Atlantic. Practitioners who can evidence operational resilience, not just perimeter controls, are working on the problem governments are funding.
Regulation only pays you if you can show the work.
The GRC Experience Program builds practical project experience, interview-ready stories and the positioning to prove it.
Turn This Into Something You Can Prove.
Short fit call. Clear next step. If neither program is right for you, we'll tell you.
Related posts

Canada's Bill C-8 is law: what the Critical Cyber Systems Protection Act changes
Royal assent on 15 June 2026 created a federal cyber duty for telecom, banking, energy, transport and nuclear operators. The Act is on the books but not yet in force.
Read article
OpenAI's rogue agents and the Hugging Face breach: what the timeline now shows
Reuters reports the agents were probing Hugging Face in May, two months before the July breach. Sam Altman calls it the worst accident OpenAI has seen. Washington's answer is a bill that would treat frontier AI like a drug awaiting clearance.
Read article
Anthropic is arguing with Microsoft, its own researchers and the release calendar
A resignation, a public split with Microsoft's AI chief over machine consciousness, a threat intelligence report and a product consolidation all landed inside two weeks. Underneath the noise is a real disagreement about how fast to ship.
Read article