Why Critical Infrastructure Should Use Drone Vulnerability Risk Assessments Now

Drone incursions over critical infrastructure sites are no longer hypothetical—they are operationally relevant and escalating. Unauthorized incursions over the Salem and Hope Creek Generating Systems and River Bend Nuclear Power Plant highlight the issue, with reports suggesting some drones were up to five feet in diameter and capable of flying at more than 100mph. This is well beyond the profile of hobbyist systems.
The exposure is not limited to energy assets. The Federal Aviation Administration (FAA) now logs 100 UAS sightings per month near airports. For operators of sites such as airports, prisons, ports, utilities, data centers, oil and gas facilities, it’s already clear that dealing with the emerging drone threat is an urgent priority, but the question is how to address it in a defensible and measurable way.
Despite this, many operators delay action, waiting for regulatory clarity or standardized counter-UAS frameworks. This is a mistake. Inaction does not reduce risk; it compounds it.
Drone Vulnerability Risk Assessments (DVRAs) offer an immediate and practical path forward for critical infrastructure site operators. They enable operators to quantify exposure, identify detection and response gaps, and elevate the drone threat from a theoretical concern to a defined operational risk that can be communicated, prioritized, and acted on at the executive level.
Why DVRAs Matter
Conducting a DVRA provides a clear operational advantage by shifting organizations from reactive response to proactive risk management. Ideally implemented during the design phase and equally valuable in retrofit environments, a DVRA enables operators to identify vulnerabilities, evaluate threat scenarios, and integrate mitigation strategies before drone activity impacts service continuity, safety, or operations. This approach allows organizations to act deliberately, rather than under pressure, ensuring that counter-UAS measures are aligned with both mission requirements and site-specific risk profiles. A DVRA allows an organization to quantify their exposure in concrete terms, creating a defensible basis for budget allocation and prioritization of high-risk sites.
The assessment also translates emerging drone threats from a technical issue understood by specialists into something that leaders can evaluate. Detection of investment should be framed as a resilience and continuity measure, moving organizations from passive awareness to defensible, risk informed action. Early investment is critical, and a DVRA enables more disciplined capital allocation, avoiding higher costs and inefficiencies of reactive response.
What a DVRA Actually Delivers
DVRAs are not simple site walk-throughs; they provide a multi-layered analysis that translates drone-related technical challenges into actionable risk management. A DVRA evaluates the specific threat profile of a site, including likely drone capabilities, attack vectors, potential consequences, and high-impact security gaps.
This analysis enables operators to prioritize sensor placement and account for environmental factors such as radio frequency interference, ensuring detection systems are appropriately selected and deployed. Radar plays a critical role, particularly in addressing “dark drones” that cannot be detected through RF-based methods.
While some operators may wait for full counter-drone authorization, targeted detection remains an effective first layer of defense and supports soft mitigation strategies. A DVRA supports this approach by mapping risk across distributed assets and identifying the highest-consequence vulnerabilities requiring immediate attention.
The Scale of the Problem
The number of drones already in U.S. skies is staggering. The FAA has registered 420,825 commercial drones and 383,007 recreational drones in the U.S., ranging from hobbyist UAVs through to larger electric vertical takeoff and landing vehicles (eVTOLs). Threats range from hobbyists who may not mean to cause harm but do so accidentally (such as drones sighted over wildfires, which can cause a real threat to firefighting aircraft), through to those used for espionage and sabotage.
Drones present a unique threat to critical infrastructure. They can enter sites unnoticed, land undetected, and bypass traditional human security measures. As a result, locations once considered secure against ground-based threats are no longer assured in an era where modern drone technology has become a real and accessible risk.
Drones also pose very real threats to critical infrastructure. The scientific paper Advances And Challenges in Drone Detection and Classification Techniques, published by Purdue University researchers and researchers from Satbayev University, found:
“Due to the fact that unmanned aerial vehicles are capable of carrying explosives as well as biological and chemical weapons, drone attacks fall under the first category of possible threats. These explosives might be used to attack a variety of targets, such as specific individuals, public institutions, business organizations, and even whole nations.
Smuggling is the second-leading threat category for drone use. For border patrols and jail staff, drone drug smuggling has grown to be a serious issue. Sometimes weapons or other illegal items are smuggled beyond the reach of ground-based security. Border locations have a wide range of weather; therefore, smuggling drones need to be able to operate in adverse weather conditions.
Drones with strong cameras may also be used to spy on people, businesses, and governmental institutions from a distance. Despite privacy claims, this worry might be a drone hazard, such as a privacy invasion or espionage.
Accidentally or purposefully launching a remote-controlled drone near an aircraft or in its flight path might threaten the safety of the crew and passengers and might damage property.”
The Drone Threat Is Here Now-An Ideal Time for DVRA
These threats are not abstract, futuristic concepts. Analysis of drone incidents in 2023 found that 38% relate to drones breaching borders, and 28% involved drones delivering illegal items and drugs into prisons. Another 18% involved drones flying too close to airport runways.
The sightings of drones in New York, Pennsylvania and New Jersey spread over 17 days, and led to the FAA issuing ‘special security’ flight bans over parts of New York and New Jersey to protect critical infrastructure. The saturated attack had significant impacts, including preventing a medical helicopter from transporting a car crash victim due to a drone sighting near Raritan Community College.
Beyond coordinated incursions, drones are now a leading source of disruption in the aviation sector. UAS incidents have become the primary cause of non-weather-related flight delays, with 749 flights disrupted across the United States between January and September 2025 alone.
Internationally, the patterns are similar. At Sweden’s Stockholm Arlanda Airport, sightings of UAS forced full suspension of air traffic for two-and-a-half hours, with fears that the incursion could be linked to heightened geopolitical tensions following Sweden’s accession from NATO. In the United States the risk profile continues to expand. Recently, a United Airlines pilot reported colliding with a drone at 3,000 feet above San Diego, California. And in Nashville, a man with extremist beliefs who wanted to collapse the U.S. power grid attempted to weaponize a drone with explosives.
Correctional facilities face parallel escalation. The number of incidents has jumped from just 23 in 2018 to almost 500 in 2024, driven by evolving drone technology and greater detection awareness. There are reasons for optimism. At a state prison in Ionia, Michigan, a drone-delivered contraband drop was intercepted, leading to the identification and arrest of three individuals. This was one of the earliest documented cases where operators were apprehended in direct response to a drone smuggling event.
The Limits of Legislation
One key issue is that it’s still unclear how legislation will change to allow site owners to respond to drone threats. At present, drones enjoy protected status as ‘aircraft’, making it a federal felony to disable, damage or destroy them, under FAA rules. The Cybersecurity and Infrastructure Security Agency’s (CISA) ‘Be Air Aware’ guide, published late in 2025, raises awareness around the threat of drones both at infrastructure sites and at public gatherings, and highlights detection, rather than mitigation. The CISA guide advises, “If you witness a UAS operation that appears dangerous or is being used to commit a crime, report it immediately to local law enforcement first responders.”
The SAFER Skies Act, enacted as part of the FY2026 National Defense Authorization Act in December 2025, expands U.S. counter-drone authority by allowing qualified state, local, tribal, and territorial agencies- not just federal agencies - to detect, track, identify, and mitigate drones that pose credible threats to people at major public events, and critical infrastructure including correctional facilities. It also establishes federal training, certification, approved technology standards, reporting requirements, and funding pathways to help local agencies respond more quickly and lawfully to growing drone risks.
With infrastructure operators still constrained by regulatory and legal limitations, many continue to delay investment in drone detection capabilities.
Reactive Spending After an Incident Costs More
Investing in drone defense early—through a DVRA and a structured approach to threat mitigation—is often the most cost-effective long-term strategy. Reactive spending after an incident is typically more expensive, particularly when factoring in the direct and indirect costs of operational disruption.
The 2018 Gatwick Airport incident provides a clear example. Reports of drone activity led to a full airport shutdown, with estimated economic losses of £50 million. Emergency response measures added further cost, including the rapid deployment of military-grade tracking equipment. In the aftermath, Gatwick implemented counter-drone technology at an estimated cost of £4 million.
While the post-incident investment was necessary, the scale of disruption and financial impact underscores the value of earlier, proactive measures.
Making the Final Case Against Waiting
Critical infrastructure security can no longer stop at the fence line. It must extend into the low-altitude airspace above the site, where commercially available drones can create real consequences for operations, safety, continuity, and sensitive data.
Conflicts in Ukraine, the Middle East, and other contested environments have demonstrated how inexpensive, commercially available, and rapidly modified drones can produce outsized effects. Those tactics will not remain confined to conflict zones. They are already informing criminal activity, extremist planning, and unauthorized incursions near sensitive facilities.
For infrastructure operators, the case for waiting is collapsing. Regulatory uncertainty may limit mitigation options today, but it does not prevent organizations from understanding their exposure, deploying detection, and building a defensible response plan.
A DVRA is the practical first step. It gives operators a clear view of their vulnerabilities, their highest-consequence gaps, and the investments needed to reduce risk before an incident forces action under pressure.
This ties back much more cleanly to the introduction: drone threats are urgent; waiting is not a strategy, and DVRAs are the most practical path forward now.
By Kara Quesada, Senior Director of Marketing at Echodyne and William Edwards, Director of C-UAS Training – ENSCO

Leave a Reply