Melissa Swisher is chief revenue officer at SkySafe, a provider of airspace intelligence.
In recent years, drones have transformed from a hobbyist technology into sophisticated aircraft, capable of long-range flights, autonomous navigation and high-resolution imaging. For many critical infrastructure operators, drones have become indispensable tools used for tasks like transmission line inspections, pipeline surveys and rail corridor monitoring.

However, drones have also introduced new challenges that existing security systems and on-the-ground teams weren't built to address. The same capabilities that make drones operationally valuable also make them effective tools for surveillance and reconnaissance. Bad actors can use them to map facility layouts, monitor security protocols and identify vulnerabilities, often without operators knowing a drone was ever there.
As drone activity continues to proliferate, industry exercises, guidelines and regulatory developments are drawing greater attention to airspace security.
The recent GridEx VIII report highlighted the growing risks drones pose to critical infrastructure and the need for operators to improve their visibility into activity occurring around sensitive facilities. At the same time, the Federal Aviation Administration’s proposed Section 2209 rule would enable eligible fixed-site facilities in the U.S. to request restrictions on drone operations near sensitive infrastructure.
As critical infrastructure operators evaluate what Section 2209 and other industry developments mean for their security posture, there are four emerging challenges they must confront.
Physical security doesn’t extend to the airspace
Every major critical infrastructure sector has invested heavily in perimeter security. Cameras, lighting, motion sensors and access control are mature, well-understood capabilities. However, they were designed to address ground-based threats. While these measures remain essential, they provide little visibility into activity occurring above a facility.
A consumer-grade drone can operate at several hundred feet above ground and reach a top speed of 47 miles per hour. From two miles outside a facility's perimeter, a drone can cross into restricted airspace, complete a reconnaissance mission, and exit in under three minutes, all without a security team even knowing it was there.
This has created a critical visibility gap. Organizations that have spent decades securing the ground perimeter must now extend that awareness to the airspace above it.
Once organizations recognize the need for dedicated airspace security, many assume the ability to capture Remote ID is sufficient.
The FAA's Remote ID framework requires drones to broadcast identifying and location information, functioning much like a digital license plate for aircraft operating in low-altitude airspace. Remote ID is an important step toward greater visibility and accountability for drone operators and supporting the safe integration of drones into commercial applications. However, it falls well short of providing the comprehensive visibility critical infrastructure operators need.
Remote ID works when drone operators choose to comply and broadcast their information. Only about 20% of drone flights today are Remote ID compliant, and a bad actor targeting critical infrastructure will simply choose not to broadcast information announcing their presence.
Organizations need visibility into drone activity, whether operators choose to comply or not. Passive radio frequency, or RF, detection is one example of a technology that makes this possible. Rather than waiting for a drone to announce itself, RF-based systems identify the communication link between a drone and its controller from the moment of takeoff — regardless of whether Remote ID is enabled — allowing operators to identify drone activity that would otherwise go unseen.
As drone activity continues to rise and new rules, like Section 2209, bring new regulatory attention to airspace security, effective security must assume the threat won't cooperate and plan accordingly.
Detection isn't enough
Even when a technology like passive RF is put in place, detection alone rarely answers the questions security teams actually need to answer. Knowing a drone is present is useful, but understanding the broader context around that activity is what matters.
Who is operating a drone, whether a drone is authorized to be in a given area, if that same drone has appeared near the facility before, and whether it is simply transiting through an area or repeatedly hovering near sensitive assets are all important questions for understanding intent, risk and patterns of behavior that detection alone cannot answer.
A drone observed near a refinery three times in two weeks tells a very different story than a single transit flight. Security teams need historical context, behavioral patterns, operator information and forensic evidence to understand that difference.
This challenge is particularly acute for critical infrastructure operators, many of whom are responsible for vast, distributed footprints spanning substations, pipelines, rail corridors and other facilities spread across large geographic areas. The same drone may appear at multiple sites over time, revealing patterns that are nearly impossible to recognize without comprehensive historical records and analytics.
That is why historical activity, behavioral patterns and broader airspace intelligence matter. The goal should not be simply to know a drone exists, but to understand what that activity means in the context of the larger environment being protected. Capturing and logging this information will also become increasingly important as operators consider pursuing flight restrictions under FAA Section 2209, given operators will be required to submit evidence of existing drone activity and potential safety consequences.
Even the best airspace intelligence is only valuable if it leads to informed decisions and coordinated action.
When a drone appears over a refinery, substation or other sensitive facility, critical infrastructure operators should have a clear process for assessing the activity, documenting what occurred and sharing actionable information with the appropriate authorities. While the authority to investigate or mitigate unauthorized drones often resides with local law enforcement, state agencies or federal partners, operators play a critical role in providing the information those organizations need to respond effectively.
That means building relationships before an incident occurs. Organizations should establish response procedures, identify points of contact with law enforcement and government partners, and ensure drone activity can be documented and shared quickly with supporting evidence.
Effective airspace security depends on a shared operating picture. When critical infrastructure operators, local law enforcement, state agencies and federal authorities are working from the same understanding of drone activity, they can make faster decisions, coordinate more effectively, identify patterns across facilities and respond with greater confidence.
The perimeter now extends overhead
Recent industry exercises, guidelines and regulatory developments make one thing clear: Airspace is now part of the security perimeter, and critical infrastructure operators can no longer afford to leave it unmonitored or unmanaged.
Section 2209 is more than a regulatory proposal. It is a recognition that drone activity has fundamentally changed the security landscape for critical infrastructure. Organizations can no longer define their security perimeter solely by fences, gates and cameras. The airspace above their facilities has become an operational security concern that demands the same level of visibility, awareness and planning.
The organizations best positioned for this new environment will be the ones that can understand what is happening in the airspace around them, share that understanding with the right partners and respond accordingly.