
The boundaries between government, the military, business, and ordinary civilian life are rarely crossed by a cyberattack on critical infrastructure. Why? A power outage, water system interference or the manipulation of an industrial-control line can quickly shift from being a technical glitch to becoming causing harm in public places.
This is why activities such as Cyber Fortress 26 are valuable.
The Virginia Army National Guard’s 91st Cyber Brigade conducted the exercise from July 25 to August 8, 2026, at the State Military Reservation in Virginia Beach, where military units, government agencies, international partners, and private-sector specialists gathered. A cyberattack on hydroelectricity was the focus of this year’s scenario, which also questioned participants’ ability to respond to an actual attack on critical infrastructure.
To me, the most important thing about Cyber Fortress 26 wasn’t just its technology. Prior to a genuine emergency, the objective was to bring various institutions into one shared operational environment.
Cyberattacks Are No Longer Only IT Problems
IT departments had been primarily concerned with cybersecurity for many years. System was monitored by a network chief, an intelligence unit investigated suspicious behaviour and an organisation restored. all affected devices.
That model has become insufficient.
The modern critical infrastructure merges traditional information technology with operational technology, which is systems that manage physical processes. A hydroelectric facility may have a range of equipment and systems, such as turbines (fans, pumps, generators or generator) and sensors, valves/ventils, electrical equipment, industrial-control systems etc, as well as platforms for supervisory control and data acquisition.
An attacker compromising an email for business purposes may have limited immediate damage. A system that controls physical equipment can be vulnerable to attacks from an attacker, resulting in significantly more serious consequences.
The impact may include:
-> Disruption of electricity generation.
-> Damage to industrial equipment.
-> Absence of visibility for plant operations.
-> Potential dangers for workers and their surrounding communities.
-> Disruption to hospitals, transportation, communications and water.
-> Economic losses and public anxiety.
-> Pressure on government emergency-response systems.
For this reason, the individuals responsible for cyber defence should consist of engineers; emergency managers; law-enforcement officers; intelligence analysts; infrastructure operators; military personnel; and political decision-makers.
Cyber Fortress 26 was created to fit that reality.
A Whole-of-Government Exercise
The military had a diverse scope for the exercise. Included were components of the military, the reserve and National Guard, as well a variety of NATO affiliates who cooperated with various local and state agencies, federal agencies from various states or territories, and representatives from private industries. The Virginia Department of Emergency Management, the Virginia State Police, and the VA Defence Force were among the entities listed. Army Reserve, the U.S. Marine Corps, cyber personnel from Finland and Estonia.
This broad spectrum of involvement is important because no single organization has the complete response to a major domestic cyber incident.
The first to notice unusual activity could be a private energy company.’ Emergency services may be arranged with the state government.? Federal agencies may furnish intelligence and technical support.'”. The armed forces may introduce advanced cyber capabilities. Public safety and public communication are also managed by local authorities.
The legal mandate, operational culture, and information system of each organization are distinct. If disagreements cannot be resolved beforehand, crisis-related decisions may take longer than anticipated. e.g.
An activity provides an occasion to pose challenging inquiries:.
-> Who reports the incident?
-> Who is responsible for identifying affected systems? Request.
-> What is the process for transferring classified data to private operators?
-> Which agency leads public communication?
-> What are the circumstances that would prompt military cyber forces to take part?
-> What steps can be taken to ensure that safety and continuity are maintained while investigators are on the job?
-> How would communication be affected if it is disrupted?
-> In what ways does the organization differentiate between an attack and a technical failure?
The answers are either fast and well-coordinated or fragmented, despite the administrative nature of these questions.
The Hydroelectricity Scenario
Cyber Fortress 26 prioritized hydroelectricity as a crucial choice, given the strong connection between energy systems and almost every aspect of modern society.
Hospitals, water treatment, communications, transport, financial services, manufacturing, emergency services and government operations all rely on electricity. How is electricity used? (e.g. When organizations rely on the same grid, data network, or backup infrastructure, disruption can be cascading and even more severe when it occurs locally.
This also drew attention to operational technology. During the initial week, trainees were taught to safeguard industrial-control and supervisory control and data acquisition systems, as well as cyber threat intelligence, malware analysis, and electrical systems.
This combination is important. The protection of operational technology involves more than just detecting malicious code. Understanding the equipment’s operation, normal functioning, and potential consequences of shutting down or manipulating a device is crucial for teams. Additionally, understanding the condition should be noted.
An IT expert may be aware of server issues. For example, an engineer may know that a change in pressure or temperature can result in ‘hazardous’ physical conditions. Effective response requires both perspectives.
The exercise taught me that cyber security and engineering safety cannot be treated as separate disciplines when physical infrastructure is dominated by digital systems.
The Red Team and the Blue Team
In the second week, a cyber exercise involving force was conducted. Integrated teams of Blue were responsible for incident response, threat analysis, and defensive cyber operations, while a Red team was assigned to simulate multiple threat actors within simulated critical-infrastructure networks.
The usual arrangement of serious cyber exercises is reflected in this structure.
The Red team creates pressure. It is prone to introducing suspicious files, breaching accounts, redirecting network traffic or services, or sending misleading signals.eg. It’s not just about breaking down systems. This isn’t the point of system destruction. It’s to uncover vulnerabilities in identification, exchange, evaluation, and rehabilitation.
The Blue team is required to identify the intrusion, determine what has been impacted, safeguard any remaining systems, and keep essential operations running. Additionally, it must determine when to disconnect a device, retrieve evidence, and restore services.
The situation is managed by a White cell or exercise-control group, which then evaluates the decisions and introduces new information. The range of possibilities includes media coverage, political pressure, equipment malfunctions, public complaints, intelligence updates, or signs of the attacker’s movement to another location.
There are few cyber crises that actually don’t clean up. But there is no one full and accurate report for those who answered. Their tasks involve utilizing bits of data, conflicting indicators, and fluctuating circumstances.
Force-on-force exercises are advantageous as they evaluate people’s behavior under pressure, rather than relying on paper planning.
The Importance of CISA and Civilian Partners
During the construction of Cyber Fortress 26, CISA was instrumental in developing and leading a cyber incident-response tabletop exercise, contributing personnel to the Red team and White cell, and working with the 91st Cyber Brigade intelligence section and Virginia Fusion Center to develop realistic scenario injects. This is significant news for Fort Belkin.
That partnership exemplifies the significance of civilian-military cooperation.
Its specialized resources, disciplined command structures and experience of working in contested environments make it the military capable of doing well. Civilian agencies typically have control, local expertise, regulatory duties, and connections with infrastructure proprietors. Private organizations are cognizant of the technology and business processes of their defended systems.
The abilities mentioned are not enough on their own.
A cyber force may recognize a hostile adversary but not be able to control an unoccupied power plant. It is possible for a private company to have knowledge of system failures without access to national intelligence. Information about threats can be held by a federal agency, but it must first be converted into useful language.
Establishing trusted relationships through exercises is essential to fill those gaps.
Certification and Readiness
The certification and recertification of cyber capabilities were also backed by Cyber Fortress 26. The validation of the South Carolina National Guard’s 125th Cyber Protection Battalion coincided with the reconfirmation of California’S Cyber Protective Team 171 and Ohio’s Cyberprotective team 172.
The task is more than just administrative in nature. Since the threat changes rapidly, it is important to test cyber capabilities repeatedly.
While a team is fully equipped to defend against solitary network intrusion, they are not as well-prepared for attacks that involve cloud services, operational technology, stolen credentials, supply-chain compromise, or disinformation. Testing the effectiveness of personnel in real-world scenarios and the ability of commanders to apply technical knowledge to operational decisions is one of the objectives of certification exercises.
The status of readiness is not permanent. There is no stopping it as we continue to validate.
Systems change. Personnel rotate. Vendors update software. New vulnerabilities appear. Threat actors change their methods.
Why International Participation Matters
Cyber threats cross borders easily. It is possible for an attacker to operate from one country, use infrastructure in another, target an organization in a third, and affect international systems.
The inclusion of cyber specialists from Finland and Estonia brought more than just a multinational identity to the task. Having faced persistent cyber threats, both countries operate in an area where state-sponsored cyber activity poses a continuous security risk.
Partner groups can engage in activities such as comparing procedures, sharing practical experiences, and distinguishing between incidents by their classification and response.
The fact that cyber defence is now a collective effort highlights its importance. Despite the differences in laws and institutions among countries, they share common issues with ransomware, espionage, infrastructure disruption, disinformation, and attacks on public services.
Sharing information rapidly can be just as crucial as identifying an intrusion.
Lessons for Private Infrastructure Operators
One of the primary target markets for Cyber Fortress 26 is the private sector.
The energy, transport, communications, finance, and manufacturing systems are frequently managed by private entities. Government agencies may offer support, but companies are still expected to maintain systems, manage staff, control vendors, and continue operating.
Numerous lessons for private operators should be derived from the exercise.
Initially, incident-response plans must consider operational technology beyond just corporate networks. Why? Companies must establish a clear communication strategy with state and federal agencies during an incident. What actions are required? They should also identify the functions that can be safely isolated and the services that require immediate continuity.
Imperfection in their decision-making process is necessary for them to use it.
It is not always apparent whether a failure is due to malware, equipment malfunction, insider activity, or reliance on faulty suppliers. This can be challenging for SMEs. The attacker can gain access to the network if they wait for some assurance. It is possible that too much aggression could cause the disruption of essential services or the destruction of evidence.
Pre-established thresholds and well-defined escalation procedures are necessary for readiness.
Third-party risk should be considered by companies. A large infrastructure operator may have access to a small contractor or software supplier.cn. The conclusion of security cannot occur at the front of the organization.
The Human Dimension
The effectiveness of cyber exercises is largely dependent on human actions, even though they are often described in technical language.
People require the option to choose who to contact. The readiness of leaders to act before every fact is known demands their action. Analysts must communicate findings clearly. Technical risks must be communicated to non-technical officials by engineers. Why? Secret information must be kept by public-information officers.
Trust is especially important.
In the event of a major incident, organizations may choose not to disclose information due to concerns about reputational harm, legal action, or regulatory consequences. Early information sharing can enhance collective defence, as demonstrated in exercises.
A company that reports a suspicious event promptly can provide protection against the same attacker, which could potentially protect other operators. A state agency that has similar compromise indicators may be able to prevent the spread of the threat by preventing it from spreading.
The issue of cybersecurity encompasses more than just tools. The other aspects involve relationships, culture, and leadership.
What Exercises Cannot Do
Cyber exercises are effective, but they do not guarantee the absence of an attack.
A properly planned exercise may not accurately reflect the uncertainty, cost, legal issues, media exposure, and public dread of a true event. Those who are aware of the event being simulated may exhibit different behavior.
The objective isn’t to predict the exact actions of the next attacker. Adaptation skills are being developed.
The key to a successful exercise is to identify flaws, not perfection. Why? When teams discover that outdated contact lists, unclear authority, or inaccessible technical data are discovered by decision-makers, it’s a positive outcome.
Afterwards, we should record those results, assign accountability, establish deadlines for actions, and test the improvements later.
An activity that does not require follow-up is nothing but an event. An exercise that involves corrective action is transformed into a readiness programme.
The Broader Security Environment
During a time when the security situation is becoming more complex, Cyber Fortress 26 was happening. Critical infrastructure is vulnerable to attacks from state-sponsored groups, criminal organizations, insiders, hacktivists and opportunistic attackers.
Some adversaries seek money. Others want intelligence. Others seek to create disorder or political pressure.’. The attribution process can be challenging due to the overlap of their methods.
Multiple groups may be aiming at the same network. A state-sponsored group may also seek to exploit a similar vulnerability, which could be taken advantage of by if the criminal actor did so. The data leak can facilitate spying, extortion, disinformation, or physical harm. All of these actions are possible.
This environment requires flexible defence.
Both cyber and physical attacks must be addressed by organizations. The implications of a network intrusion on equipment, public trust, supply chains, emergency response, and political decision-making must be taken into account.
Building Resilience Before the Attack
Cyber Fortress 26 proved that defending critical infrastructure isn’t the responsibility of an individual agency or profession. This mandates coordination among troops, civilian officials and contractors, private enterprises, emergency responders (CSOs), international allies and communities that depend on these services.
The exercise’s emphasis on hydroelectricity, operational technology, threat intelligence, malware analysis, incident response, and force-on-force cyber operations made those elements of the relationship test applicable.
To me, the most important advantage of using it is to establish habits that lead to a crisis, such as speedy communication and information sharing, safeguarding critical operations, trusting partners, and making decisions when pressure mounts.
Agency responses to jurisdictional questions will not be resolved until after a cyberattack on critical infrastructure is launched. Why? Leaders will not have to wait for contact information or decision-making until it’s too late. Preparation must be determined beforehand to ensure readiness.
Cyber Fortress 26 was not just a military exercise. It evaluated the capacity of a contemporary society to respond collectively to physical and cyber threats caused by digital attacks.
The true measure of success is achieved when participants implement their learning, correct any weaknesses they encounter, and continue to train for unknown threats.
The preparation process in cybersecurity is never complete. Why? It’s been built, tested, improved, and retested.




