Abstract
Iran-linked operations against critical infrastructure are frequently read as either noise or imminent attack. This brief separates three distinct behaviors — signaling, disruption and pre-positioning — and argues that conflating them leads defenders to misprice the threat in both directions. Built entirely from open sources mapped against The Observatory, it offers a framework for reading Iranian activity against U.S. and allied infrastructure with appropriate proportion.
Key findings
- 01Signaling, disruption and pre-positioning demand different defensive responses and are routinely conflated.
- 02Water and energy targeting patterns show intent that is legible before impact.
- 03Proportion — not alarm — is the correct posture the open record supports.
Cite this research
Braccia, C. “Iran Cyber Threat Brief.” EWSRC (BRF-03), 2026.
Themes