Let’s be clear-eyed about this — and then get to work.
The risk to American infrastructure is real and documented. It is not a reason to panic; it is a reason to prepare. On this page we lay out exactly what we’re up against, in plain terms and from the agencies responsible for defending against it — and then we point you to what can actually be done about it.
What we mean by a Black Sky Event
A Black Sky Event is a long-duration, wide-area loss of the infrastructure modern life depends on — power, water, communications, fuel — lasting not hours or days, but weeks or longer.
It can come from a natural cause, like a severe geomagnetic storm. It can come from an accident. And it can come from a deliberate act by a capable adversary. What makes it different from an ordinary disaster is duration: the systems that normally come back in 72 hours don’t. That is the gap most communities have never planned for — and the one that is entirely possible to close.
72 hours vs. 30+ days
Most emergency plans are built for a three-day disruption. A Black Sky Event runs far longer. The distance between those two numbers — everything past Day 4 — is exactly where FIR works.
This is confirmed, not speculated
Everything below comes from public statements by the agencies charged with national defense and cybersecurity. We don’t need to exaggerate it — the record is serious enough on its own.
Nation-state actors
China, Russia, Iran, and North Korea have each been identified as pursuing or holding access to U.S. critical infrastructure.
Agencies on the record
The FBI, NSA, and CISA have confirmed, in public advisories and testimony, intrusions into power, water, and communications systems.
Critical infrastructure sectors
The interdependent sectors a prolonged outage would cascade through — from water and energy to food, health, and finance.
Where exposure begins
The point at which most communities’ plans run out — and the first day a resilient community keeps functioning on its own.
Sources for the threat record are collected in our Strategic Documents and the Four-Party Ecosystem analysis, each fully cited.
Three ways the lights go out — and one that combines them
A Black Sky Event doesn’t arrive by magic. It arrives through a small number of well-understood attack paths, each already demonstrated somewhere in the world. Knowing them isn’t alarming — it’s what lets you harden against the specific thing, not a vague fear.
Cyber attack
Reversible · but only while poweredA coordinated intrusion into the SCADA and industrial control systems that run the grid, water plants, and pipelines. Done well, it doesn’t just disrupt — it disables automated protections and blinds operators to the real state of their own systems. Its defining limit: it only works while the systems are still powered and networked.
Physical / kinetic attack
Irreversible · lowest barrierDirect destruction of the hardware itself — substations, transformers, pumps, towers, chokepoints — using rifle fire, small drones, or improvised explosives. It is the most immediately executable path because it needs no nation-state cyber tools, just reconnaissance and standoff. And the damage is physical, not digital.
EMP / GMD
Wide-area · electronics-levelA single high-altitude nuclear detonation produces an electromagnetic pulse (EMP) that destroys unshielded electronics across a continental footprint in an instant. A severe geomagnetic disturbance (GMD) — a Carrington-class solar storm — is the natural twin: different trigger, but the same physics that saturates and destroys the grid’s large transformers. One is deliberate; one comes from the sun.
Any one of these can stand on its own — a cyber intrusion that trips a region’s grid, a coordinated strike on a cluster of substations, a single detonation. But the scenario defense planners weigh most heavily is the one where they’re used together, in a deliberate order.
When the vectors are sequenced, not just stacked
The most serious threat isn’t any single attack — it’s a coordinated campaign that runs the vectors in the order that does the most lasting harm. Each phase is chosen to disable the response to the next. This is the sequence FIR’s analysis treats as the planning baseline.
Cyber goes first
Pre-positioned intrusions activate while the grid is still live — because cyber only works while systems are powered. Automated protections are disabled and operators are blinded to the real state of the grid.
Physical destruction
With the automated safeguards already down, kinetic attacks destroy transformers, pumps, and pipelines — irreversible damage, on equipment that takes 18–24 months to replace.
Institutional pressure
Attacks on leadership and emergency operations, plus attribution confusion and disinformation, slow the coordinated response and amplify the chaos at exactly the moment decisions need to be made.
EMP held in reserve
A wide-area pulse is the optional “insurance” — used only if the earlier phases left too much intact — to eliminate whatever electronics survived.
Why the order matters: a combined-arms campaign is designed to defeat recovery, not merely to cause damage. Each phase degrades the community’s ability to respond to the one that follows. That is precisely why the work has to be done before — and why a community that has already hardened is one this sequence can’t unravel.
The threat has a weakness, and it’s us
An adversary’s plan only works if our communities have no plan for Day 4.
Take that away, and the leverage disappears. A town that can keep its water running, its lights on, and its people fed without the national grid simply cannot be held hostage by a threat to that grid. That is not wishful thinking — it is how American communities operated for most of their history, before we quietly outsourced our resilience to systems we don’t control.
So the honest picture leads somewhere hopeful: the work is concrete, it’s affordable in the right doses, and every community that does it makes the whole country harder to coerce.
The full threat library
For those who want the detail, our analysis is published and sourced. Start anywhere.
Understanding the threat is step one. Step two is yours.
You don’t have to solve all of it. You have to take the next sensible step — and we’ll help you find it.
