> ## Documentation Index
> Fetch the complete documentation index at: https://docs.reyhford.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Critical Infrastructure Targets

> Which ICS/OT sectors attackers prioritize — energy, water, fuel, manufacturing, buildings.

Critical infrastructure is defined differently by each country, but adversary interest clusters around sectors where cyber effects become **physical or geopolitical**.

## Priority sectors we see reflected in probing

| Sector                   | Typical protocols       | Why it is targeted                               |
| ------------------------ | ----------------------- | ------------------------------------------------ |
| **Electric power**       | IEC 104, S7, Modbus     | National resilience; wartime precedence          |
| **Fuel / midstream**     | Guardian AST, Modbus    | Inventory intel; pipeline/IT coupling (Colonial) |
| **Water / wastewater**   | Modbus, proprietary     | Public health; often under-resourced OT          |
| **Manufacturing**        | EtherNet/IP, S7, Modbus | IP theft + ransomware leverage                   |
| **Buildings / campuses** | BACnet                  | Physical access, HVAC, bridging to IT            |

## Why honeypot geography matters

Attackers scan globally, but **regional concentration** of certain protocols (e.g. Guardian AST intensity near SEA) reveals collection priorities. Owned capacity today is SEA (`edge-sgp-001`); the network grows with customer-enrolled sensors — compare “internet background radiation” vs region-specific campaigns as coverage expands.

## Defensive takeaway

Map your asset inventory to these protocol classes, then subscribe to Reyhford indicators filtered by protocol/confidence. Pair with [Southeast Asia landscape](/regional/southeast-asia) and [actor profiles](/regional/threat-actor-profiles).
