Key Takeaways

  • Foreign control over critical infrastructure and critical mineral supply chains represents a major national security vulnerability, functioning alongside ongoing cyber threats to centralized networks.
  • Recent disruptions affecting water systems and Canvas illustrate how vulnerabilities can cascade through essential physical and public services.
  • Federal initiatives, including Project Vault and increased CFIUS scrutiny, are aggressively targeting supply chain resilience and infrastructure protection to mitigate concentration risks.

Cyberattacks against water systems in several states are exposing a difficult trade-off at the center of the digital economy. Organizations have consolidated data and operational control to reduce costs, coordinate services, and improve speed. The same consolidation can give attackers a small number of high-value targets capable of producing widespread disruption.

A September 2, 2026 commentary published in the Bend Bulletin titled "America's hidden national security vulnerability" highlighted how this exposure extends deeply into physical supply chains. The commentary warned of the risks associated with foreign (especially Chinese) control over U.S. critical infrastructure, specifically pointing to critical minerals and land assets near sensitive military and energy sites.

The scale of the threat to these combined physical and digital networks is substantial. In 2024, more than 859,000 cyberattacks were reported, averaging nearly 100 per hour, while associated financial losses approached $17 billion. That compares with $2.7 billion in 2018. Nearly 4,900 of the 2024 incidents targeted critical infrastructure supporting the physical and digital economy.

Those figures are consistent with the broader threat documented by the FBI Internet Crime Complaint Center, although reported complaints and confirmed attacks are not interchangeable measures. The distinction matters. Even so, both indicate sustained pressure on the systems businesses and public agencies use to deliver routine services.

Sometimes the consequences are immediately visible. Canvas, the learning management system used by K-12 schools, colleges, universities, and corporate training centers, was crippled by a ransomware attack in May. Because Canvas supports both remote education and classroom instruction, the interruption affected workflows involving millions of users.

Water presents a more direct cyber-physical concern. Treatment facilities often combine operational technology, industrial controls, connected sensors, and conventional business networks, sometimes across equipment of very different ages. The Cybersecurity and Infrastructure Security Agency identifies water and wastewater systems as a critical infrastructure sector, reflecting the public-health and economic consequences of extended disruption.

Aviation provides another stark example. More than 2.5 million people use air travel each day, and their journeys depend on centralized passenger service systems. These platforms coordinate reservations, ticketing, seat assignments, crew schedules, and ground operations. They oversee much of a passenger's path from booking through arrival.

The operational efficiency of these systems is undeniable. Travel agents and airlines can coordinate complicated itineraries almost instantly, while airports process enormous passenger volumes. But severe disruptions occur when the shared digital layer disappears.

Several European airports encountered that problem in 2025, when a cyberattack forced staff to process travelers manually. Applying a paper-based fallback to the roughly 2.5 million to 3 million passengers traveling daily in the United States could quickly overwhelm available staff and terminal capacity. The Federal Aviation Administration tracks the scale and operational density of the national airspace system, illustrating why even localized technology failures can propagate through schedules, crews, gates, and connecting flights.

Physical infrastructure presents parallel vulnerabilities. The Interior Department's 2025 List of Critical Minerals identifies 60 minerals vital to national security that face severe disruption risks. To counter this, the 2026 U.S. National Security Strategy and initiatives like Project Vault (backed by up to $10 billion in Export-Import Bank lending) aim to establish strategic critical mineral reserves. The State Department also reported more than $30 billion in government-backed investments in early 2026 to strengthen supply chain resilience. Meanwhile, mining and processing companies such as MP Materials, Albemarle, and Lynas Rare Earths remain central to allied efforts to reduce dependence on foreign-controlled refining.

Regulatory bodies are actively adapting to these overlapping physical and digital threats. The Committee on Foreign Investment in the United States (CFIUS) now heavily scrutinizes foreign investments involving critical technologies, critical infrastructure, and sensitive data under updated 2026 frameworks. The committee is actively reviewing foreign-backed energy and land purchases near military bases and grid assets.

For technology and business leaders, the issue is not simply whether systems are centralized. It is whether organizations understand their concentration risk. Vendor dependencies, identity services, cloud control planes, remote-access tools, and shared databases can become operational choke points even when the underlying infrastructure appears distributed.

That said, decentralization alone is no cure. More systems can mean more interfaces, inconsistent controls, and a larger attack surface. A practical resilience program tends to combine network segmentation, redundant communications, protected backups, strict supplier assessments, and recovery exercises that assume important platforms will be unavailable. Manual fallbacks also require realistic capacity estimates rather than untested contingency plans sitting untouched on a shelf.

Connected services and critical supply chains have become deeply embedded in ordinary commerce and public life. Their operational benefits are difficult to separate from their national security risks. The sharper business question is whether organizations have designed for disruption before a centralized platform or vital supply chain fails, ensuring that the pursuit of efficiency does not quietly displace resilience.