Strategic Threat

Pre-positioning in Critical Infrastructure: Dormant Access for Future Crisis

Adversaries are implanting dormant footholds in power, water, and telecom systems — not to attack today, but to retain the option for a future conflict. Pre-positioning is the new deterrence frontier.

Last updated October 9, 2026

Overview

'Pre-positioning' describes the implantation of dormant access in critical infrastructure — energy, water, telecom, transportation — without immediate disruptive effect, retaining the capability to act during a future geopolitical crisis. Five Eyes agencies have repeatedly warned of such campaigns, most prominently the Chinese 'Volt Typhoon' activity tracked in US and allied networks since 2023.

The strategic logic differs from immediate espionage or disruption. Pre-positioning is about optionality and signalling: the attacker preserves the ability to degrade or disrupt an adversary's civilian infrastructure if a crisis escalates, while also demonstrating reach that may itself deter. Living-off-the-land techniques (using legitimate admin tools rather than malware) make these footholds extremely hard to detect, because the activity blends with normal operations.

Defence therefore demands baseline behavioural understanding: defenders must know what 'normal' looks like on OT and ICS networks to spot the subtle deviations pre-positioning creates. The US CISA 'Secure by Design' initiative and joint Five Eyes guidance on Volt Typhoon emphasise this shift from signature-based detection to anomaly-based hunting in critical sectors.

Key Points

Dormant, not disruptive

Pre-positioning retains access for future use rather than causing immediate impact, complicating detection and attribution.

Living-off-the-land

Attackers use legitimate administrative tooling rather than malware, blending with normal operations to evade signature detection.

Strategic signalling

The reach itself can deter; demonstrating presence in rival infrastructure is a form of cyber posture and coercion.

OT/ICS baselines

Detection depends on understanding normal OT network behaviour, then hunting subtle anomalies — a major capability gap in many sectors.

Five Eyes priority

Volt Typhoon and successor campaigns are top-priority advisories for CISA, NCSC, and allied agencies.

Latest Intelligence

Frequently Asked Questions

Defensive Intelligence

Encrygma produces defensive intelligence only. This analysis is derived from public reporting, government advisories, and OSINT — no exploit code or attack instructions.

Sovereign Defense Solutions
Weekly Briefing

Get the Weekly Cyberwarfare Briefing

State cyber operations, AI-powered attack campaigns, and offensive cyber industry developments — delivered to your inbox every week.

Defensive intelligence only. No spam — unsubscribe anytime.