← Research Library
BRF-03· EWSRC· Brief ·2026

Iran Cyber Threat Brief

Iran-linked threats to U.S. and allied critical infrastructure and the distinction between signaling, disruption and pre-positioning.

By Christopher Braccia, Founder & Director of ResearchORCID 0009-0003-7867-2923
Abstract

Iran-linked operations against critical infrastructure are frequently read as either noise or imminent attack. This brief separates three distinct behaviors — signaling, disruption and pre-positioning — and argues that conflating them leads defenders to misprice the threat in both directions. Built entirely from open sources mapped against The Observatory, it offers a framework for reading Iranian activity against U.S. and allied infrastructure with appropriate proportion.

Key findings
  • 01Signaling, disruption and pre-positioning demand different defensive responses and are routinely conflated.
  • 02Water and energy targeting patterns show intent that is legible before impact.
  • 03Proportion — not alarm — is the correct posture the open record supports.
Commission related work
Cite this research

Braccia, C. “Iran Cyber Threat Brief.” EWSRC (BRF-03), 2026.

Themes
Nation-State Infrastructure OperationsCross-Sector Infrastructure Risk