CIPRNA – The Event

There are 16 critical infrastructure sectors whose assets, systems, and networks — whether physical or virtual — are considered so vital to the United States that their incapacitation or destruction would have a debilitating effect on national security, economic security, public health, or safety.

In 2024, the government adopted a new foundational policy, National Security Memorandum on Critical Infrastructure Security and Resilience (NSM-22), which replaced the previous framework established by Presidential Policy Directive 21 (PPD-21). Under NSM-22, federal departments and agencies — acting as Sector Risk Management Agencies (SRMAs) — are assigned responsibility for managing risk in each of the 16 sectors. The memorandum elevates the role of Cybersecurity and Infrastructure Security Agency (CISA) as the national coordinator for critical-infrastructure security and resilience.

NSM-22 emphasizes the importance of establishing minimum security and resilience requirements for critical infrastructure entities. It calls for effective accountability mechanisms, which may include the use of regulation, federal procurement standards, grants, and financial incentives, to encourage owners and operators to meet or exceed these baseline security standards.

Under NSM-22, federal roles include coordinating cross-sector risk management; enhancing real-time information and intelligence sharing; and promoting investments in technologies and practices that strengthen resilience against evolving threats — from cyberattacks to natural hazards and supply-chain disruptions.

Since the return of the Trump administration in 2025, cybersecurity policy has been reshaped again. In June 2025, a new executive order, Sustaining Select Efforts To Strengthen the Nation’s Cybersecurity (EO 14306), amended prior cybersecurity orders and re-emphasized protections for digital infrastructure, cyber resilience, and secure software development. The new order tasks federal agencies — including CISA — with accelerating adoption of stronger security practices, post-quantum cryptography, and modern secure-software development standards.

The 2025 order underlines the need to defend against nation-state cyber threats (notably from countries such as China, Russia, Iran, and North Korea) targeting U.S. systems — including those tied to critical infrastructure. It directs federal departments to harden network security, improve software supply-chain resiliency, and update standards for procurement and operations.

In this updated context, U.S. policy reflects a hybrid approach that combines the structural risk-management framework under NSM-22 with renewed, more technical cybersecurity directives under the new Trump-era order, seeking to defend critical infrastructure against both digital and physical threats in a rapidly evolving threat environment.

We must be prepared

We must remain vigilant. The nation’s critical infrastructure underpins everyday life — in energy, communications, water, healthcare, transportation, and more — and defending it requires coordinated, updated, and adaptive efforts across government, private sector, and civil society.

Critical Infrastructure Protection and Resilience Americas will bring together leading stakeholders from industry, operators, agencies and governments to collaborate on securing North America.