Advertisement

Latest Guard-led Cyber Shield exercise is focused on protecting the power sector, including OT

More than 1,000 troops and civilian experts are participating in the event.
Listen to this article
0:00
Learn more. This feature uses an automated voice, which may result in occasional errors in pronunciation, tone, or sentiment.
Arkansas Army National Guard Chief Warrant Officer 2 Robert Ellison, assigned to the 179th Cyber Protection Team, participates in the Capture the Flag event during Cyber Shield 2026 at the Professional Education Center in Little Rock, Ark., July 17, 2026. (U.S. Army National Guard photo by Spc. Brooke Kentler/Released)

The 2026 iteration of Cyber Shield, a massive annual National Guard-led exercise, is focused on honing participants’ skills in defending the power sector and associated operational technology from digital attacks, according to officials involved in the effort.

More than 1,000 troops and civilian experts from 44 U.S. states and territories and 23 international partners are participating in this year’s event, which kicked off July 12 in Little Rock, Arkansas, and will run until July 25.

“This is our biggest Cyber Shield so far, with the most international participants,” Lt. Col. Seth Barun, G-6 chief information officer in the North Carolina National Guard and the executive officer in charge of the effort, told reporters during a roundtable Tuesday.

“Each year we focus on a critical infrastructure sector. This year we chose to focus on the power sector, and by doing that, it gives the participants in the exercise — not just the blue teams, the training audience, but also our opposing forces, [the] red team — the ability to deep dive into some of the threats and vulnerabilities that are in those particular systems … and then building tactics, techniques, and procedures to try and remediate those. And they have the ability to then take that back to their states or countries and start to implement some of those things that they’ve learned and harden the networks,” he said.

Advertisement

Incidents such as the 2021 Colonial Pipeline ransomware episode and the threat posed by China-linked Volt Typhoon actors have highlighted the need to protect America’s critical infrastructure from digital attacks, including operational technology connected to the cyber domain.

Threats to OT have shaped this year’s Cyber Shield exercise.

“It’s not just a digital environment, but there is a physical component to it this year. And I think that adding that realistic piece to it, while also improving our cyber range ability to simulate the power grid, really brings a new level to the realistic scenario. At the same time, we also were taking real-world tactics, techniques and procedures from malicious actors and integrating those into the exercise. So everything we do here is based on attacks that we have seen in the real world. So combining those two things — a physical component as well as the latest trends and attack vectors — really gives us the ability to up our skill set, as well as make it a little bit more challenging for the blue teams,” Barun said.

“We did it a few years ago, but this is our first year where it’s fully integrated into the system,” he said of the physical component. “It was sort of a standalone thing previously, but now it’s fully integrated.”

Attacks on the electric sector can have major impacts on other critical infrastructure and sectors of the economy, Tim Conway, technical director of ICS and SCADA programs at the SANS Institute, noted during Tuesday’s roundtable.

Advertisement

Cyberattacks on power generation, transmission and distribution have occurred in the real world, and they continue to evolve. They can lead to equipment destruction, creating longer-term outages that are harder to recover from, Conway said.

Incidents impacting industrial control systems and operational technology are very different from IT attacks confined to an IT environment, he noted, and responders need to know how to recover those types of systems.

Adding OT elements to training events like Cyber Shield is a complex undertaking.

“As we look at any of these exercises, and we consider what we want to train when we bridge this gap between IT and OT, there needs to exist an IT infrastructure that can emulate what an adversary will get an initial foothold in,” Conway said. “But as we begin to talk about impacts in the cyber-physical world — so the delivery of clean water, the delivery of natural gas for your home heating, the delivery of electricity for essential services and key resources — you have to begin to understand this pivot from the IT to the OT world, and all of the interconnected systems and interdependent systems. And in order to simulate that, you need to then make all of those extended OT systems as part of this exercise. Then you need to move down to the final control elements in the actual OT and industrial control systems. So this becomes a very complex exercise environment to make sure that you are training resources in an adequate fashion and in a way that reflects the real world.”

Cyber Shield isn’t meant to be a “validating exercise,” Barun said, but an opportunity for participants to test new ideas, make mistakes and learn.

Advertisement

“We bring a wide variety of blue teams. Some have been together for a long time. Some, like my own in North Carolina, I take my subject matter experts and I move them onto the opposing forces, the red team, and I let my sort of beginners or newer people be on to the blue team so that they can learn and develop those skill sets in threat hunting and incident response,” he told DefenseScoop during the roundtable.

Blue teams are continually showing improvement year over year, according to Barun.

“For Cyber Shield, we invest a significant amount of resources into the assessment process. And so we have a full assessment team that spends the first week of the exercise just learning how to do cyber exercise assessment. They go through the process. And so each team at the end of the exercise, what they’ll get within 30 days after they leave is a customized report for that particular enclave that shows them, hey, here’s where you were strong, here’s where you were deficient, here are the areas that you can work on. And that’s based on the exercise goals and objectives,” he told DefenseScoop.

“Overall, there’s always a need to increase our operational technology learning,” he added. “It’s still new to a lot of our participants and, you know, just investing in the training is critical. But each team will get a custom report that they can take away and then build their training plan for the next year so that when they come back to Cyber Shield 2027, they’re much more prepared for what we’ll see next year.”

Barun said that artificial intelligence is being integrated into this year’s exercise “to a certain extent,” but he declined to provide details.

Advertisement

AI and the cloud are technology areas that officials involved in planning Cyber Shield exercises want to lean more heavily into in the coming years, according to Barun.

“It’s definitely in future plans,” he said. “It is a small part of this year, but I think as we evolve … the exercise, I think that will certainly, next year, become a bigger portion of it.”

Latest Podcasts