
When most people hear "critical infrastructure security," their minds jump immediately to cyber: ransomware, OT intrusions, and data breaches. Yet many of the systems that underpin modern economies remain fundamentally physical. Electricity networks, pipelines, substations, communications infrastructure and industrial facilities are a blend of software and physical assets spread across vast geographic areas, where disruption carries immediate economic and societal consequences.
For decades, physical security was largely treated as a localised asset-protection problem. Operators focused on protecting individual sites through perimeter security, inspections and periodic monitoring. That model assumed physical attacks were geographically contained. That assumption is breaking down. Geopolitical tensions, infrastructure interdependence and the growing strategic importance of energy and communications networks are increasing both the frequency and impact of physical disruptions.

The evidence is becoming difficult to ignore. Eleven Baltic Sea cables were damaged in the 15 months leading up to January 2025, prompting NATO to launch Baltic Sentry to monitor critical undersea infrastructure. Across North America, NERC's Electricity Information Sharing and Analysis Center (E-ISAC) recorded more than 3,500 physical security incidents affecting the power grid in 2025, up from roughly 2,800 the year before and nearly ten times the level seen a decade ago. Governments are responding accordingly. The EU's Critical Entities Resilience (CER) Directive is pushing operators toward a more systematic approach to resilience, while NATO and national governments are increasing investment in the protection of strategic infrastructure. Physical resilience is increasingly becoming a funded priority rather than a contingency plan.
The implications are particularly significant for energy infrastructure. Unlike most critical assets, energy systems operate as large-scale base networks rather than discrete facilities. Electricity must be generated, transmitted, distributed and balanced continuously across thousands of interconnected assets, creating dependencies that extend far beyond any individual site. A disruption affecting a single component can have consequences that propagate across a much wider system.
A recent IEA analysis found that disruptions affecting critical energy infrastructure impacted energy supplies for more than 200 million households worldwide, with outages costing an estimated USD 100 billion annually. As the energy system expands, the challenge is becoming less about protecting individual assets and more about understanding what is happening across the network as a whole. Operators increasingly need to detect anomalies, identify threats and assess potential impacts across infrastructure that was never designed to be continuously, holistically observed.
Once security becomes a question of system observability, the problem shifts from protecting individual assets to understanding entire networks. The companies creating value in this market are building the infrastructure needed to detect, interpret, and respond to threats across large-scale energy and infrastructure systems. Every company in this market is ultimately trying to answer one of three questions: what is happening, what does it mean, and what should we do.

Awareness. Operators are increasingly deploying satellites, fibre-optic sensing, acoustic sensing and distributed edge sensors to create continuous awareness of infrastructure conditions and potential threats across assets that were never designed to be watched. The shift is from periodic asset-specific inspection to always-on machine sensing of the entire network.
Intelligence. Raw observation creates massive volumes of data, most of it noise. The goal is to convert it into actionable intelligence by fusing disparate data: distinguishing a fishing vessel from a dragging anchor, weather from a genuine intrusion, or a routine anomaly from a threat. This layer transforms data into understanding.
Resilience coordination. Operators need systems that coordinate response, simulate impact, manage incidents and support decision-making across a fragmented ecosystem. This layer takes the form of command platforms, orchestration systems or digital twins. It is also the least mature, and potentially most defensible, part of the stack.
These deployments demonstrate the emergence of a new security stack built around continuous awareness, intelligence and coordinated response.

A handful of early deployments point to where this stack is already proving out. Fibre-sensing platforms are giving grid operators real-time detection of faults and physical disturbances across transmission networks. Satellite monitoring is being used to detect excavation activity and other third-party interference across pipeline corridors. Autonomous drone operations are providing continuous surveillance and anomaly detection across energy sites, and AI-powered video analytics are enabling automated detection of intrusions across solar farms.
While the technologies involved are diverse, most companies in the market are ultimately solving one of three problems: creating awareness across distributed infrastructure, turning observations into actionable intelligence, or coordinating response when incidents occur. This framework reflects the shift from protecting individual sites to maintaining continuous awareness across entire infrastructure networks. A subcategory around autonomous security operations, particularly drones and robotic systems, is also emerging quickly, but sits adjacent to the core software and sensing stack that is the focus of this piece.
The first wave of value creation is occurring at the sensing layer, where operators are deploying new technologies to monitor assets that historically could not be continuously observed. Satellite constellations, distributed fiber sensing, ambient sensors and AI-enabled imaging are extending visibility across infrastructure networks that were designed to operate with limited monitoring.

As these technologies mature, however, the bottleneck increasingly shifts from observation to interpretation. Operators must make sense of a growing volume of signals across geographically dispersed assets and distinguish routine events from genuine threats.
Over time, we expect value to accrue to platforms that combine high-quality infrastructure data with operational context and coordinated response capabilities, creating a common operating picture across entire networks rather than individual sites.