Enable breadcrumbs token at /includes/pageheader.html.twig

Cyber Shield 2026 Tackles OT Vulnerabilities in the Power Sector

Participants in this year's exercise are practicing proactive threat hunting.

Cyber Shield 2026, the U.S. National Guard’s 13th annual unclassified cyber defense exercise, is running July 12-25 at the Professional Education Center in Little Rock, Arkansas. The exercise has brought more than 1,000 cyber professionals from 44 states and territories and 23 partner nations together to tackle the most pressing cyber threats. This year’s focus is on the power sector.

Like past Cyber Shields, participants have been divided into two teams: the red team, which emulates the attackers, and the blue team, which represents the defenders. Through real-world scenarios, the teams practice infiltrating and defending systems to strengthen cyber capabilities, defense techniques and global partnerships. The exercise event incorporates both classroom instruction and hands-on training exercises.

According to Lt. Col. Seth Barun, the exercise officer in charge, this year’s Cyber Shield is bigger than ever before, with more international participation. The training environment has also evolved.

“It's not just a digital environment, but there is a physical component to it this year, and I think that adding that realistic piece to it, while also improving our cyber range ability to simulate the power grid, really brings a new level to the realistic scenario,” Barun said during a media roundtable Tuesday alongside fellow Cyber Shield 2026 leaders.

Tim Conway, an industry partner with a background in utilities systems operations, said this year’s emphasis on the power and electric sector of critical infrastructure is important because attacks on the electric sector impact all sectors instantaneously.

“Whether it's generation, transmission, distribution, we've now seen attacks across all of them that have occurred in the real world, and they continue to change . . . from impacts in the previous years of just outages, to equipment destruction,” Conway said.

Brig. Gen. Russell McGuire said the National Guard Bureau has been focusing on training soldiers and airmen to keep cyber actors off of operational technology (OT) networks because OT has become one of the greatest vulnerabilities.

Many information technology (IT) and OT systems are interconnected and impact the power sector, including the delivery of clean water, natural gas and electricity to homes and businesses, so a large part of Cyber Shield 2026 is simulating the complex systems architectures and finding the paths adversaries take to stay hidden while attacking networks.

“As we look at any of these exercises and we consider what we want to train when we bridge this gap between IT and OT, there needs to exist an IT infrastructure that can emulate what an adversary will get an initial foothold in,” Conway explained. “You need to then make all of those extended OT systems as part of this exercise. Then you need to move down to the final control elements in the actual OT and industrial control systems.

 

 

 

 

 

 

 

 

 

 

“So, this becomes a very complex exercise environment to make sure that you are training resources in an adequate fashion and in a way that reflects the real world.”

To adequately train against the techniques used by adversaries, Cyber Shield participants use open-source tools, like Security Onion, a platform designed for threat hunting and security monitoring, Barun shared.

According to Barun, this year’s training has involved home smart meters and unmanned aircraft systems. The technologies used and how they are integrated into the annual exercise are recommended by subject matter experts, he said.

Capt. Gonçalo Atanásio, a cyber command officer with Portugal, said this year’s exercise involves a lot of threat hunting, which is the practice of proactively seeking out hidden cyber threats that have bypassed automated security defenses. He said threat hunting can either be behavior-driven or hypothesis-driven, the latter being the most common.

Hypothesis-driven threat hunting involves questioning possible links between compromised systems, like if an IT breach can lead to an OT breach, Atanásio explained.

“If that hypothesis is proven, it's not about finding the threat, but proactively protecting yourself,” Atanásio said. “So, you basically understood that it's possible, [and] you are going to secure your network even if you are not compromised.”

Atanásio also said it’s important to start securing small systems that are not typically secured because adversarial cyber actors can infiltrate systems from any vulnerable access point.

The leaders emphasized that Cyber Shield 2026 has strengthened the partnerships between the United States and allied nations, which is crucial in the fight against adversarial cyber actors.

“No person can do it alone,” McGuire said. “It's that collaboration. It's that constant communication. And that's what's going to help us face the threats that are facing us all.”

 

Comments

The content of this field is kept private and will not be shown publicly.

Plain text

  • No HTML tags allowed.
  • Lines and paragraphs break automatically.
  • Web page addresses and email addresses turn into links automatically.
Enjoying The Cyber Edge?