Skip to main content

Attacks on critical infrastructure: Colombia

Colombia's power, water and transport systems reach into difficult, sparsely held country where long grid and pipeline links cross terrain that armed groups and criminal networks contest. That exposure makes the systems that keep cities and industry running a target from the network, the ground and the air at once, often far from where the consequences are felt.

Long links across contested, sparsely held country

Power generation, water supply and the transport that moves the country's goods are interdependent and often carried by long links crossing remote terrain, so an adversary who can darken a substation, disrupt a supply or halt a corridor imposes consequence well beyond the point of attack. Infrastructure hardening reduces the attack surface of the supervisory control systems that run these utilities, so an intruder cannot force a shutdown or defeat a safety interlock. Many of those control networks were built for reliability rather than adversarial resilience, and were never designed to be attacked.

Where cyber intrusion and physical strike converge

What sharpens the Colombian case is that the same remote links exposed to physical sabotage are also reachable through their control systems, so a strike far from any city can reach essential services through either route. Defensive cybersecurity provides continuous monitoring and incident response around the control networks, while Counter-UAS addresses the drone threat to physical plant such as substations and pumping stations. All three come from independent, non-aligned makers, so the protection of essential services is accountable to the national operator, with localisation arrangements scoped per programme and subject to export controls and end-use approvals.

How engagement works in Colombia

Unstrat engages as an accountable, non-aligned single channel: one team representing the manufacturers directly, with end-use certified equipment and in-region sustainment rather than a distribution arrangement. A programme typically begins by assessing which control systems are most exposed and where a single failure would cascade, then hardens what matters most first. Because critical infrastructure is where a nation is most coercible, the non-aligned position keeps the knowledge of the country's weaknesses national rather than shared with a foreign supplier.

Protecting essential services across contested country

Work opens with a briefing that assesses which control systems are most exposed and where a single failure would cascade along the long grid, pipeline and transport links crossing sparsely held, contested terrain, the reach that lets a strike far from any city touch essential services. Because this reveals where a nation is most coercible, no maker is represented until end-use is confirmed and the export-control and end-use approvals are settled, and the knowledge stays national. Infrastructure hardening, defensive cybersecurity and Counter-UAS are then matched to the operator's real plant, so the most exposed links are protected first. Sustainment is phased in-region so essential services keep running under pressure, keeping the mission accountable to the national operator, with localisation arrangements scoped per programme, subject to export controls and end-use approvals.

Relevant capability

Adjacent priorities in Colombia

Relevant solutions

Colombia: security context

Colombia's priorities converge on its interior and its edges: counter-narcotics operations across demanding terrain, surveillance of remote jungle regions, protection of critical infrastructure, and monitoring of extensive borders. It is an environment where reach into difficult, sparsely held areas defines the security task.

An accountable single-channel engagement gives Colombia a coherent counterpart for those priorities: counter-narcotics support, remote-area and jungle surveillance, infrastructure protection and border surveillance. A defence ministry gains end-use certified equipment, disciplined export-control handling and localisation arrangements scoped per programme rather than promised in advance.

About this challenge

Power grids, water systems and transport networks face both physical and cyber attack. Hardening the control systems behind them, defending the networks around them and countering the drone threat above them keeps essential services running under pressure.

Frequently asked questions

Why are Colombia's infrastructure links especially exposed?

Long grid, pipeline and transport links cross remote, contested country far from where the consequences are felt, so a strike far from any city can reach essential services through the network, the ground or the air. Hardening the control systems, defending the surrounding networks and countering the drone threat as one problem closes the door piecemeal defence leaves open.

What does hardening the control systems actually prevent?

It reduces the attack surface of the supervisory systems behind power, water and transport, so an intruder cannot manipulate a process, defeat a safety interlock or force a shutdown. Combined with continuous cyber monitoring, it keeps essential services running under deliberate pressure.

Who holds the knowledge of where Colombia's infrastructure is weakest?

The national operator does. All three capabilities come from independent, non-aligned makers, so the picture of where the country's infrastructure is most exposed is accountable to Colombia, with localisation arrangements scoped per programme and subject to export controls and end-use approvals.

Attacks on critical infrastructure: Markets

Contact us

Tell us the requirement. Specifications and the export position are confirmed in briefing, not published here.