Skip to content
SPECIAL

THREATS TO CRITICAL INFRASTRUCTURE IN IRAN CONFLICT

READ MORE

Iran may strike back in cyberspace – and U.S. infrastructure could be in the crosshairs

(Department of Energy)

By Don Kauffman

Just over a week after Israeli airstrikes targeted Iran’s nuclear facilities, cybersecurity experts are warning that U.S. infrastructure could be hit as Iran strikes back.

In a new To the Point interview, retired Rear Adm. Mark Montgomery, senior fellow at Auburn University’s McCrary Institute and former executive director of the Cyberspace Solarium Commission, said the risk of Iranian cyber retaliation is both credible and growing.

“Is it possible? Yes. Is it likely? Yes,” Montgomery said. “We already see a 700% increase in Iranian attacks on Israeli critical infrastructures.”

While many of those attempts have not been successful, Montgomery cautioned that the same types of systems – especially water, energy and transportation – are often more vulnerable in the U.S. than the public realizes.

“The vast majority of the critical infrastructures we have to worry about are water systems, electrical power systems, transportation systems like ports and rails and aviation,” he said. “And the vast majority of them are not as well protected either by industry or supported by the government.”

To underscore how real these risks are, Montgomery pointed to Chinese operations such as Volt Typhoon as recent proof of how foreign actors have already compromised U.S. infrastructure through pre-positioned malware. “They proved it,” he said. “Volt Typhoon… placed what we call operational preparation of the battlefield: put accesses in for future gain or installed malware for future disruptive activity.”

Iran’s retaliation, he added, may not come only in the form of cyberattacks. Influence operations – designed to amplify disinformation through social media – are also a growing concern.

“They’re further assisted by our own social media, which pretty much has an all-comers attitude toward information when it first hits it,” he said. “Over time it might be removed, but initially it gets full play.”

Despite these risks, Montgomery expressed concern that the federal government has not adopted the proactive posture it displayed at the outset of Russia’s war on Ukraine. “I have not seen that this time,” he said. “I think CISA’s probably… in a slightly less forward-facing stance right now because of some significant changes that would happen when any change of party happens.”

He called for the confirmation of key cyber leadership positions, including new chiefs for the Office of the National Cyber Director and CISA. He urged officials to once again rally the private sector with a clear warning: “We need a ‘shields up’ narrative to be getting out there to industry.”

To improve national readiness, he proposed investing in a dedicated cyber force, strengthening the National Guard’s cyber capabilities and expanding reserve programs.

Montgomery also warned that the U.S. is leaving a critical domain underprotected: space. He urged the administration to designate space as critical infrastructure, calling it a “missed opportunity” under the last administration.

“Space is exceptionally important to communications, to energy, to timing, to position [and] navigation,” he said.

As tensions mount in the Middle East, Montgomery’s message was direct: The cyber threat landscape is shifting, and the U.S. needs to be ready.

Click to listen highlighted text!