Lee Rossey is CTO of SimSpace, advancing AI proving grounds to help orgs prove cyber readiness.
In early April 2026, the Cybersecurity and Infrastructure Security Agency (CISA), in partnership with the FBI, National Security Agency (NSA), the Department of Energy and other federal agencies, announced that Iranian-backed threat actors had targeted the nation’s water and wastewater infrastructure, among other critical facilities.
Although no specific group was blamed for the attacks, details of which were also kept confidential for national security reasons, officials said the attacks were similar to those conducted by the “CyberAv3ngers” group, a hacker collective affiliated with the Iranian Revolutionary Guard Corps, in 2023. Those attacks targeted programmable logic controllers (PLCs) at several energy facilities, as well as operational technology (OT) such as supervisory control and data acquisition (SCADA) displays at critical sites across the U.S.
Critical Infrastructure Can’t Afford To Learn During An Attack
The response to these threats must be swift and effective, but—as in any crisis situation—the human element is typically the most unpredictable. Cyber Florida and SimSpace recently conducted the Jack Voltaic (JV) Tampa cyber resilience exercise, which aimed to prepare critical security personnel for the realities of a real-time network intrusion on mission-critical infrastructure. More than 100 organizations across government, the energy sector, the armed forces, emergency management agencies and private enterprise took part in the exercise, which simulated an attack on regional water infrastructure and demonstrated how utilities and public sector organizations can validate their operational readiness against sophisticated attacks targeting OT and mitigate those threats preemptively.
As the simulation progressed, participants moved away from triaging isolated technical incidents and adopted an integrated incident response posture, which resulted in greater shared situational awareness as the scenario unfolded and improved cross-functional collaboration between participating teams.
Confidence In AI Isn’t The Same As Proof
CISA and other agencies warn that further cyberattacks on critical infrastructure are increasingly likely, which makes urgent preparation vital. However, many security leaders are deploying unproven, untested agentic solutions to production environments without validating how those agents interact with their networks, data or human operators. Compounding that risk is the fact that many security leaders are highly confident in the capabilities of their agentic cyberdefenses, but their teams demonstrate significantly lower defensive security readiness scores in SimSpace testing environments. These scores typically improve over time for teams that regularly train and respond to highly realistic threat simulations in secure, sandboxed environments.
AI Agents Need To Be Tested Before They’re Trusted
SimSpace internal data indicates that overall defensive readiness is higher on average among OT security practitioners than their private sector counterparts, but with the lives and safety of millions of people on the line, the stakes are simply too high to deploy untested technologies to production before validating agentic behaviors. Just as soldiers in the military conduct regular testing exercises using live ammunition to test their mettle under fire, it’s vital that critical infrastructure facilities are thoroughly prepared for the realities of a nation-state cyberattack. Live-fire training conditions soldiers to the reality of being shot at with live rounds, but it also reveals weaknesses in communication structures that may not have been otherwise identified. The principle is exactly the same in the AI proving grounds.
Preemptive Defense Requires Government And Industry To Train Together
The 2026 JV Tampa cyber resilience exercise was just the first step. Private enterprise has never worked so closely with the federal government, and recent initiatives such as Executive Order 14409 are paving the way toward even greater collaboration between government and industry. However, the risks facing the nation have never been higher, and the speed with which the technological arms race between attackers and defenders is escalating puts security leaders under even greater pressure. Innovation is meeting this moment, and collaborative efforts such as the 2026 JV Tampa cyber resilience exercise are another step toward a safer, more secure future.
Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?


