top of page

Private Sector Hybrid Threats: The Convergence of Physical & Cyber Security Risks

8 minutes ago
6 min read
Private Sector Hybrid Threats

Hybrid Threats: New Considerations for Private Sector Resilience


Recent Cyber Attack on Minnesota’s Water Infrastructure


In late July 2026, water utility operators in Minnesota began troubleshooting a problem that initially presented as equipment failure. But the continued surge of unexplained pressure drops, flooding, and loss of system functionality called for a formal investigation.


The FBI confirmed that malicious actors had gained remote access to the internet-facing programmable logic controllers (PLCs) responsible for monitoring and controlling system equipment. PLC hardware was targeted across at least 7 states, with attackers altering log-in credentials and IP addresses to degrade operations in facilities that supply water to hundreds of thousands of Americans. 


These incidents reflect a trend that security practitioners have been tracking for decades, the convergence of physical and cybersecurity risks. Often described as hybrid threats, these campaigns are deliberately designed to keep attribution unclear, letting attackers operate below the threshold of open conflict. This can lead to severe implications for the private sector, which hybrid threats are increasingly drawn to, particularly civilian infrastructure and commercial entities. 


Private targets carry less escalatory risk for attackers. A strike on a water facility does not invoke the same retaliation from a host state that an attack on government or military assets would. The private sector is a softer target, as effective business operations and effective cybersecurity typically pull in opposite directions. Companies are built to maximize speed, accessibility, and uptime, while security is often associated with restriction, segmentation, and friction.


Implications for the Private Sector: The New Front Line of Hybrid Threats


Leading cybersecurity firms link the tradecraft used in the Minnesota attack to an ongoing pattern of activity conducted by CyberAv3ngers, an offensive cyber group affiliated with Iran’s Islamic Revolutionary Guard Corps (IRGC). While attribution is still being federally investigated, the Cybersecurity and Infrastructure Security Agency (CISA) published an advisory four days prior to the attack, warning of Iran-affiliated actors compromising PLCs across U.S. water, energy, and government sectors. In the advisory, CISA references a “significant escalation” in Iran-affiliated activity since February 2026. Joint intelligence reporting has acknowledged upticks in similar infrastructure-directed activity from other state-affiliated groups, indicating that these threats extend beyond any single actor or geopolitical conflict.


The risk to the private sector has intensified, especially when considering that federal protection mechanisms for cyber-attacks have been significantly reduced. CISA reported that their workforce had been cut by nearly one-third throughout 2025. Historically, CISA has been able to help businesses defend against, respond to, and recover from cyber-attacks by providing threat intelligence and incident response coordination for the private sector.


Fewer agency personnel translate to slower incident response support, delayed threat intelligence sharing, and less capacity to help companies recover once an intrusion is underway.


This feedback loop has triggered a widening gap between the sophistication of cyber threats and the resources available to counter them at the organizational level. Paired with the inherent need for companies to rely on extensive digital exposure, shared systems access, and internet-connected equipment, even limited intrusions have the capacity to significantly disrupt productivity and threaten safety. For companies operating on exposed infrastructure, or those sharing vendors and networks with companies that do, that gap is a direct and growing operational liability, placing businesses on the front line of geopolitical conflict. 


The Organizational Challenge: When Disruption Becomes a Business Crisis


Hybrid threats are an operating reality inside most organizations because business networks are built for connectivity. Internal systems, IoT devices, and third-party vendors are routinely allowed to interact with minimal friction. The physical security infrastructure protecting a facility, including access control panels, camera systems, and building management platforms, sits on that same connected network far more often than most security programs account for. Once inside, a threat actor's objective shifts from access to reach.


The Minnesota water attacks illustrate what that pivot looks like in practice. Attackers did not need to breach a hardened core network. They needed an internet-facing PLC secured with the same standardized components and default administrative credentials found across thousands of similar deployments elsewhere.


The same exposure exists well beyond critical infrastructure. Consider a distribution facility where the badge access system is managed remotely by a third-party vendor for convenience. An attacker who compromises that vendor's credentials does not need to touch payroll data or intellectual property to cause damage. Disabling access control at a single facility, unlocking doors that should stay secured, or blinding a camera system can halt operations, expose employees, and open the door to physical intrusion, all without the attacker ever setting foot on the property.


That is the essence of convergence risk. A cybersecurity intrusion that never touches a company's most sensitive data can still produce a physical security failure with immediate operational and safety consequences. A single overlooked device, an unpatched legacy system, or a default password left in place after installation becomes the entry point, and the exposure it creates is measured in facility access, physical safety, and operational continuity.


Meeting the Challenge: Reframing Incident Response


As operational and geopolitical risks become increasingly interconnected, traditional incident response approaches have proven less effective at addressing hybrid risks. Business resilience is no longer defined solely by an organization's ability to contain and recover from an incident. It increasingly depends on its capacity to maintain continuous situational awareness, assess evolving risk, and anticipate how a disruption elsewhere will reach its own operations before it does.


Insite addresses this convergence through two physical security capabilities built to work both independently and in tandem.


Global Security Operations Center


Insite's Global Security Operations Center functions as a security nerve center, operating 24/7 to monitor global conditions and flag emerging threats before they reach a client's people, facilities, or operations. That includes tracking the geopolitical activity most likely to precede a hybrid incident, such as global conflicts, sanctions regimes, and civil unrest. When a threat emerges, our GSOC team is positioned to respond in real time, verifying which locations are affected, notifying the right stakeholders, and coordinating the physical response needed to keep operations running through the disruption. Core GSOC capabilities include:


  • Continuous global threat monitoring and proximity alerting across an organization's facilities, personnel, and travel 

  • Geofencing facilities to detect nearby incidents in real time

  • Crisis management and response coordination, including incident verification and predefined escalation thresholds

  • 24/7 staffing through embedded, outsourced, or hybrid support models built around the client's existing capabilities

Security Technology Assessment and Gap Analysis


To build long-term resilience against hybrid threats, many organizations turn to Insite’s Security Technology team. Access control panels, camera systems, and building management platforms are physical security infrastructure, but they get managed like any other networked device, complete with administrative logins, firmware, and patch cycles that are easy to overlook once installed. Insite's security technology assessment and gap analysis exists to catch vulnerabilities that lead to risk exposure.


Core assessment capabilities include:


  • Evaluation of current-state access control, video surveillance, and integrated systems, including configurations, permissions, and device health

  • Identification of default, shared, or outdated administrative credentials across physical security platforms

  • Assessment of legacy equipment and standardized components that make a single exploit reusable across multiple sites

  • Benchmarking against industry best practices and enterprise standards

  • A prioritized remediation roadmap sequenced by risk, cost, and operational impact

Hybrid threats have collapsed the distinction between a cybersecurity risk and a physical security one. As attribution grows harder to establish and federal capacity to respond continues to contract, the organizations best positioned to withstand this shift will be the ones that have paired continuous, real-time awareness of the threats developing around them with a disciplined, ongoing evaluation of where their own physical security infrastructure remains exposed.


Private organizations must either build these increasingly essential capabilities internally or leverage specialized partners. For companies without the talent pipeline to maintain a security function ready to combat today’s threats, or those seeking to mitigate the cost of delays in their overarching risk management strategy, outsourcing is often the most practical and effective choice for operational resilience.


Insite Risk Management helps organizations close the gap between risk and readiness through its bespoke Global Security Operations Center (GSOC) and Security Technology services. Through continuous monitoring, actionable threat intelligence, and cross-functional coordination, Insite equips businesses to navigate an increasingly complex threat landscape without the need to build these capabilities from the ground up.


Contact Insite today to learn how a tailored GSOC or security technology program can provide value in strengthening your organization’s operational resilience.


bottom of page