Articles By This Author

Test methods with map features selected

Methodologies

Test methods with map features selected

Lorem Ipsum is simply dummy text of the printing and typesetting industry. Lorem Ipsum has been the industry's standard dummy text ever since the 1500s, when an unknown printer took a galley of type and scrambled it to make a type specimen book. It has survived not only five centuries, but also the leap into electronic typesetting, remaining essentially unchanged. It was popularised in the 1960s with the release of Letraset sheets containing Lorem Ipsum passages, and more recently with desktop publishing software like Aldus PageMaker including versions of Lorem Ipsum.
Test methods no map

Climate Change

Test methods no map

Lorem Ipsum is simply dummy text of the printing and typesetting industry. Lorem Ipsum has been the industry's standard dummy text ever since the 1500s, when an unknown printer took a galley of type and scrambled it to make a type specimen book. It has survived not only five centuries, but also the leap into electronic typesetting, remaining essentially unchanged. It was popularised in the 1960s with the release of Letraset sheets containing Lorem Ipsum passages, and more recently with desktop publishing software like Aldus PageMaker including versions of Lorem Ipsum.
Test methods with map features selected1

Methodologies

Test methods with map features selected1

This article provides a structured assessment of the potential malign use of Geographic Information Systems (GIS) by threat actors of varying technical sophistication to target U.S. cities and critical infrastructure. Using a newly constructed critical infrastructure facility in the United States as the operational test case, the use cases explore how open-source geospatial tools can be used to identify, model, and potentially exploit critical infrastructure vulnerabilities. The facility was selected for its emergent relevance to regional and national supply chains, logistical novelty, and its appearance in both regional and national public discourse surrounding immigration and rural industrial development.

The assessment includes four discrete use case examples corresponding to escalating levels of threat actor capability: Tier 1 (one without and one with AI augmentation), Tier 2, and Tier 3 (see Figure 1). Each scenario demonstrates how openly accessible data and commercially available GIS and AI tools can be operationalized to perform tasks such as infrastructure targeting, route planning, emergency response delay modeling, reconnaissance staging, among others. This framework assists in evaluating adversarial capabilities, mapping threat vectors, and anticipating how generative AI may further reduce the technical barriers to high consequence targeting.

Threat actors across varying skill levels can effectively identify and exploit vulnerabilities in critical infrastructure using open-source geospatial data. Even Tier 1 actors, when augmented by generative AI like ChatGPT, Claude, or Google Gemini, can analyze site access, infer vulnerabilities, and devise attack strategies including physical sabotage, low-level cyber tactics, and disinformation campaigns. More sophisticated actors leverage advanced GIS platforms to model supply chains, critical dependencies, and emergency response scenarios, with the ability to closely mimic professional geospatial intelligence processes. Crucially, generative AI can compress traditional skill barriers[1] and enable non-experts to rapidly convert reconnaissance into actionable attack plans, significantly increasing the risk profile and challenging the reliability of existing infrastructure security paradigms.

Testing with new categories and regions

Climate Change

Testing with new categories and regions

Lorem Ipsum is simply dummy text of the printing and typesetting industry. Lorem Ipsum has been the industry's standard dummy text ever since the 1500s, when an unknown printer took a galley of type and scrambled it to make a type specimen book. It has survived not only five centuries, but also the leap into electronic typesetting, remaining essentially unchanged. It was popularised in the 1960s with the release of Letraset sheets containing Lorem Ipsum passages, and more recently with desktop publishing software like Aldus PageMaker including versions of Lorem Ipsum.