Leadership1 publisher3 min readPublished
Finding China Inside US Utilities Requires Washington, AI Labs and Infrastructure Operators to Work Together
Chinese hackers hold access to American communications, energy and transport networks in order to prepare sabotage, a Foreign Affairs essay says. Its proposed remedy depends on the private operators that ran those systems through two decades of light regulation.
The Board Room · Leadership desk

What happened
- Chinese hackers have gained and kept access to US communications, energy and transportation infrastructure, and a Foreign Affairs essay says the purpose goes beyond intelligence gathering to preparing sabotage.
- The same essay says China has breached hospitals in Taiwan, power grids in India and telecommunications networks in Singapore.
- Iranian hackers compromised water facilities across multiple US states this summer, and one county directed residents to boil their water.
Compiled by The Board RoomSomething wrong?How this is made
Why it matters
- constraint Because the US government is precluded from monitoring private critical networks the way Beijing monitors China's, the defensive work has to be commissioned by the companies that own the networks, on their own budgets.
- exposure Equipment without logging leaves an owner unable to demonstrate to a regulator, an insurer or a customer whether anyone is already inside it.
- capability If systemic-risk analysis no longer needs a manual engineering study, cost stops being an answer to why a given plant has never been assessed.
A chokepoint is leverage only when the holder can show it and the target cannot route around it. The comparisons the essay draws are physical and priceable: Iran's control of the Strait of Hormuz, and China's command of critical minerals as leverage in trade negotiations [4]. Access inside a utility network behaves differently, because it stays invisible until it is used. The essay states the purpose as a finding, saying the goal of the intrusions is "laying the groundwork for sabotage" [2], and names the effects as blackouts, water that is unsafe to drink, and delayed military mobilization [3]. In China, critical infrastructure is centralized and controlled by the state. In the United States it is owned and operated by a diverse array of private actors with varying levels of cyberdefense, according to the essay [9]. American laws and values preclude the US government from monitoring private communications and critical national networks in the ways the Chinese government does [7]. Beijing's firewalls both surveil and censor Chinese users and keep American offensive intrusions out [8]. From that pairing, the essay concludes that China can use cyberweapons against the United States and its allies with greater confidence that it can withstand retaliation [10]. Then there is the equipment. Power plants and pipelines run on decades-old hardware designed for physical reliability, not digital defense, and it often lacks logging, encryption or patching [15]. Modernization wired that hardware into computer networks and cloud services for remote monitoring [16]. Once, a saboteur needed explosives to destroy a gas pipeline; today, by the essay's illustration, a vandal might shut one off by hacking a poorly secured router sitting in a corporate office [17]. Logging is how an owner would establish whether anyone is already inside, and the essay says the equipment frequently does not have it [15]. Until recently, US utility companies had few incentives or requirements to shore up security, and before 2021 there were few if any cybersecurity regulations for critical infrastructure [18]. The Biden administration then established baseline standards for pipelines, ports, airports and water systems [20]. Determining systemic risk used to require manual, expensive engineering analysis [19]. A year ago, the essay claims, defending critical infrastructure with AI at scale was possible only in principle. It is now possible in practice, because the costs came down [12], even though the same essay holds that AI tends to benefit attackers more than defenders [11]. The remedy names three classes of actor, and only one of them owns the assets. Washington and the AI labs supply models and pressure; the infrastructure operators own the plants and grids to be stress-tested against cutting-edge models [13][22]. The owner decides whether to let outside models probe a plant serving a city or a military base, and whether to fund the repairs on a list the essay expects to run to decades of accumulated vulnerabilities [14]. This is one essay, and its intent finding, sabotage preparation as against espionage, is asserted in the text without the evidence behind it. That gap does not reach the hardware claims. Equipment built for physical reliability and running without logs is a maintenance fact, checkable by the owner in a week. The author has held the asymmetry argument since a Foreign Affairs essay last year [21]. The essay does not take up how an operator runs a grid or a pipeline while an intrusion is live; its remedy is to find and close the access before it is used [14]. A board writing manual-fallback procedures this quarter will source that operational planning elsewhere, working from the effects the essay names [3].
What to watch
- Whether any US operator publicly agrees to frontier-model stress-testing of a live grid or pipeline, and who pays for the findings.
- Whether the baseline standards the essay credits to the Biden administration for pipelines, ports, airports and water systems are kept, widened or rewritten.
- Any government attribution that separates espionage from sabotage preparation in these intrusions, which is the essay's contested claim.