

Cyber Readiness
How Prepared Is Florida Critical Infrastructure for Iranian-Style Cyber Activity?
Statewide Readiness Snapshot
Eligible assessments
Overall preparedness Method
NIST CSF control readiness
Bottom line. Florida critical infrastructure shows moderate overall preparedness, with stronger performance in Detect and Protect controls but materially weaker performance in Govern and Recover. The most important statewide readiness issues are leadership oversight, risk management strategy, incident analysis, and recovery plan execution.
Threat lens used in this report: Iranian cyber activity is commonly associated with credential attacks, phishing, abuse of valid accounts, and exploitation of internet-facing weaknesses. This report maps Florida Cyber Risk Assessment evidence to those defensive themes rather than claiming attribution of any specific incident.
Executive Summary
• The analysis includes 488 Florida critical infrastructure assessments that were more than 80% complete. Using the FCRA requirement-level NIST CSF response data, statewide weighted preparedness measures 58.5%, with a median organization at 62.0%.
• At the function level, Detect (79.0%) and Protect (71.3%) are the strongest areas. Govern (48.2%) and Recover (47.7%) are the weakest.
• The most consequential statewide weaknesses are concentrated in governance and response management themes: oversight, organizational roles and authorities, risk management strategy, incident analysis, and recovery plan execution.
• Among major sectors with at least 10 eligible assessments, Water and Wastewater Systems (50.8%) and Transportation Systems (52.2%) scored lowest, while Healthcare and Public Health (70.9%) and Financial Services (69.9%) scored highest.
• Organizational structure matters. Entities without a CISO averaged 52.1% preparedness versus 64.9% for entities with a full-time CISO. Entities without a cyber training program averaged 52.4% versus 63.8% where training exists.
Threat Lens Used for This Cyber Florida Version
This report is intentionally threat-informed. It uses a practical Iranian-style cyber activity lens drawn from recent U.S. government and MITRE reporting: credential compromise, brute force and password spraying, phishing and social engineering, misuse of valid accounts, exploitation of unpatched or internet-facing systems, and reliance on legitimate administrative pathways after access is obtained.
The purpose is not to prove whether a given sector has faced Iranian targeting. Instead, the purpose is to answer a more useful leadership question: if an adversary used those common tradecraft patterns against Florida critical infrastructure, where does the statewide data suggest defenses are stronger or weaker today?
Florida Statewide Snapshot
Preparedness by NIST CSF 2.0 Function | Elgible assessments (>80% complete, n=488)

Preparedness Score (%)
Interpretation. Florida organizations appear comparatively stronger in monitoring, detection, access control, backups, and technical protection basics. Performance drops more sharply where cybersecurity must be institutionalized through leadership oversight, formal risk strategy, consistent role ownership, incident analysis discipline, and recovery decision-making.
Sector Observations
Preparedness by Major Critical Infrastructure Sector | Shown for sectors with at least 10 eligible assessments

Preparedness score (%)
Readout. The statewide pattern is not uniform. Water and wastewater and transportation stand out as the lowest-performing larger sectors, and both show pronounced weakness in governance or recovery-oriented controls. Government Facilities has the largest footprint in the sample and also posts the weakest governance score among the larger groups. Sector results with fewer than 10 eligible assessments were not emphasized because those samples are too small for confident statewide conclusions.
Structural Readiness Factors
Preparedness improves with dedicated leadership and training
Preparedness score (%)

Dedicated governance capacity correlates with better performance. Organizations without a CISO lag materially behind organizations with a full-time CISO.
Cyber training capacity also tracks with stronger readiness. That matters because phishing, credential theft, and abuse of valid accounts remain central features of the Iranian-style threat lens used in this report.
The staffing-size relationship is directionally positive as well: larger organizations generally score higher than smaller and mid-sized organizations, although sector mix and sample size also affect those comparisons.
What Leadership Should Do Next
• Use Govern and Recover as the first statewide improvement priorities. Technical controls alone will not close the largest gaps visible in this dataset.
• Target under-resourced agencies first, especially water/wastewater, transportation, and governance-heavy local government environments.
• Treat leadership accountability, documented risk strategy, and recovery criteria as reportable management actions, not just cybersecurity team tasks.
• Prioritize incident analysis, recovery execution, and role clarity with Cyber Florida’s assistance and resources.

Methodology and Important Limitations
Eligibility rule: only assessments with greater than 80% completion were included. This produced a final analysis population of 488 assessments spanning all Florida critical infrastructure sectors.
Data quality note: some assessments contained inconsistent answers. The analysis normalized the requirement-level records using score-based parsing and aggregation. Findings should therefore be read as directional statewide preparedness indicators, not audited compliance determinations.
Threat note: this report does not claim active Iranian compromise of the included organizations. It evaluates how current control patterns align against commonly reported Iranian-style tactics and techniques.
References
• RealClearDefense, “How Prepared Is the Defense Industrial Base for Iranian Cyber Attacks?” published March 24, 2026. https://www.realcleardefense.com/articles/2026/03/24/how_prepared_is_the_defense_industrial_base_for_iranian_cyber_attacks_1172226.html
• CISA / FBI / DC3 / NSA joint statement and related advisories on Iranian-affiliated cyber activity against vulnerable U.S. networks.
https://www.ic3.gov/CSA/2025/250630.pdf
https://www.cisa.gov/sites/default/files/2024-10/aa24-290a-iranian-cyber-actors-conduct-brute-force-andcredential-access-activity.pdf
• MITRE ATT&CK group profiles for MuddyWater and OilRig.
https://attack.mitre.org/groups/G0069/
https://attack.mitre.org/groups/G0049/
