Feature Story

Mapping hidden organizational influence in US critical infrastructure

September 16, 2026

By Lisa Wilmore

The next major threat to U.S. critical infrastructure may not come from a cyberattack or natural disaster. It could arrive with a handshake and a signed contract.

A foreign company buys land near a power substation. Another secures a seat on the board of an aggregator. No malware, no breach. Investments, acquisitions or board appointments may appear routine but can cumulatively shift who holds influence over the systems that keep the nation running.

Foreign business influence is a blind spot in traditional cybersecurity and critical infrastructure protection. For decades, cybersecurity strategies have focused on firewalls, software patches and network defense.

Recognizing this evolving threat, researchers at the Idaho National Laboratory (INL) are developing a tool to illuminate hidden networks of organizational influence over critical infrastructure systems, ideally before they become national vulnerabilities.

Growing government response

Policymakers are starting to take notice of organizational risk. Idaho, Texas, Utah and other states have passed laws restricting foreign ownership of land near power plants, water systems and military bases. Idaho’s House Bill 356 and Senate Bill 1149 required foreign entities to divest agricultural and mineral rights by December 2025.

Several states, such as South Dakota, Tennessee and Maine, have enacted laws restricting government agencies from purchasing equipment from companies linked to countries of concern.

The Idaho State Capitol, where lawmakers passed House Bill 356 and Senate Bill 1149 requiring foreign entities to divest agricultural and mineral rights by December 2025.

At the federal level, the Committee on Foreign Investment in the United States has expanded oversight to include real estate and agricultural assets. Additional guardrails, such as Foreign Ownership, Control or Influence regulations limit the degree to which foreign entities can shape decisions within U.S. companies operating in sensitive sectors.

The One Big Beautiful Bill Act also increased requirements for tax credits and other federal energy incentives linked to foreign influence, affecting those with ties to adversarial governments.

In the energy domain, beneficial ownership in an electric utility company, for example, could grant access to sensitive grid data or influence operational decisions. Such investments strengthen economies during stable periods but can be leveraged to collect sensitive information or disrupt critical services if geopolitical tensions rise.

Security analysts call this “shadow warfare,” a contest fought in the gray zone between peace and open conflict. Instead of cyberattacks or military strikes, adversaries exploit legal and financial frameworks to achieve strategic objectives.

U.S. intelligence leaders face growing concern that adversaries could weaponize infrastructure assets during periods of conflict.

Despite expanding protections, legislation alone can’t keep pace with globally distributed supply chains, rapidly shifting ownership structures and the corporate networks that shape modern infrastructure. That’s where TOPGEAR comes in.

How TOPGEAR reveals risk

Technology, Organization and Person of Interest Graph Extraction, Analysis and Reporting (TOPGEAR) provides analysts with a multidimensional view of influence within and across critical sectors. The research and tool development is being led by INL distinguished researcher Gabriel Weaver, who has a doctorate in computer science. The platform maps relationships between organizations, people and assets to help reveal vulnerabilities traditional infrastructure assessments fail to capture.

TOPGEAR supports economic prosperity and national security by helping balance foreign investment against related risks.

“In theory, you can build something perfectly secure technically, but someone could acquire it,” Weaver explains. “TOPGEAR gives us a way to visualize the hidden influences that traditional cybersecurity overlooks.”

TOPGEAR continuously collects data from sources including U.S. Securities and Exchange Commission filings and the Energy Information Administration. When needed, third‑party proprietary sources supplement public data to refine timelines and clarify risk patterns.

TOPGEAR structures this information into three layers of an adversarial socio‑technical network:

  1. Social layer: capturing business ties, leadership roles and organizational influence
  2. Infrastructure layer: representing physical and digital assets
  3. Cross‑layer influence: edges that show how a person or organization can affect a specific asset and vice versa

The novelty lies in the third layer. It enables analysts to trace influence paths from a human actor to a physical asset, such as a substation or data center, in a way no single system previously supported.

A TOPGEAR user interface showing statewide generator owners and operators in 2024. Node colors indicate companies and generator types (such as natural gas or hydroelectric), while edge colors depict relationships like ownership, operation and parent-company links.

The team is developing algorithms to examine these networks for suspicious or emerging patterns, update risk profiles, and highlight concentrations of concern within regions or sectors. TOPGEAR’s visualizations, including detailed maps and influence reports, help decision‑makers understand the extent of regional dependencies on companies and how those companies connect.

A tool born from collaboration

TOPGEAR was refined in collaboration with the Naval Postgraduate School, where Weaver and professor Daniel Eisenberg applied socio-technical network analysis from an adversarial perspective, a feature that set the tool apart.

It was initially funded through INL’s Laboratory Directed Research and Development program, which empowers national labs to pursue high-risk, high-reward research.

The project brought together expertise in cybersecurity, data science, and national security. Its impact has extended beyond INL, drawing support from multiple offices across the U.S. Department of Energy (DOE) — including the Office of Cybersecurity, Energy Security, and Emergency Response (CESER) and the Office of Electricity (OE) — as well as the Department of Homeland Security, helping ensure the work translates into real-world operations. OE is sponsoring TOPGEAR’s technical assistance engagements with state energy offices.

Last year, the TOPGEAR team joined DOE’s Energy I‑Corps program, completing 76 market analyses to understand industry needs and accelerate technology transfer. Today, state energy offices already use TOPGEAR, and its commercial potential continues to grow.

A new era of infrastructure security

As global supply chains grow more interconnected and artificial intelligence accelerates business decision‑making, the need to understand hidden influence within critical infrastructure has never been greater. TOPGEAR offers a way to align economic growth with national resilience, ensuring progress doesn’t come at the expense of security.

“You can’t defend what you can’t see,” Weaver says. “We’re working to illuminate a broader variety of potential threats to the nation’s critical infrastructure.”

About Idaho National Laboratory

Battelle Energy Alliance manages INL for the U.S. Department of Energy’s Office of Nuclear Energy. INL is the nation’s center for nuclear energy research and development, and also performs research in each of DOE’s strategic goal areas: energy, national security, science and the environment. For more information, visit www.inl.gov.

Follow us on social media:

INL News | Related Stories