RSS Amplifier

Risk Factor - Dr. Andrew G. Huff · Aug 11, 2026

A Failure to Investigate

0
Sign in to vote or save

Dr. Andrew G. Huff · Risk Factor - Dr. Andrew G. Huff

By Dr. Andrew G. Huff

Epidemiologist. Security engineer. Former Q-cleared scientist, Sandia National Laboratories. Ph.D. in Environmental Health Science, Emerging Infectious Disease and Epidemiology, DHS Center of Excellence Research Fellow. Former U.S. Army infantryman.

In November 2021 a government-derived, rank-ordered criticality target list of American food and agriculture infrastructure was stolen from a locked safe in my home. I reported the theft to eight bodies: the FBI, USDA, DHS, FDA, and DOE at the federal level, and the Michigan State Police, the Marquette County Sheriff’s Department, and the Michigan Intelligence Operations Center at the state and local level. Not one of them opened an investigation. Not one collected the physical evidence I preserved and offered. That is the story, and it is documented.

Everything else that gets argued about this is a way of not discussing that. The most common substitute is a debate about whether food-plant fires are occurring at a statistically abnormal rate. I did not raise that question, I have never argued from fire frequency, and it is not how national security risk is managed. Anyone who reframes the theft of a critical infrastructure target list as an actuarial question about fire counts is doing one of three things: a limited hangout, conceding a small true point to bury a larger one; a non-starter, answering a question nobody serious asked; or wordsmithing, playing with the frame instead of the substance. None of the three touches the finding.

Seven judgments, each with my confidence on a 0 to 100 scale.

1. A non-public, government-derived CI/KR criticality target list was stolen from my home in November 2021, reported to eight federal, state, and local bodies, and investigated by none. Documented, high confidence, 92.

2. That failure to investigate is the material national security failure here, and it stands whole regardless of who took the drive or what they intended. High confidence, 90.

3. The DHS risk management framework is a continuous, evidence-driven process for managing risk across the CI/KR enterprise. The compromise of a criticality product is precisely the input it exists to act on, and no action followed. Assessed, 85.

4. The frequency framing, that food-plant fires are statistically normal, is a deflection and not a rebuttal. I never made a frequency argument, and you do not manage a national security risk by counting fires. High confidence, 88.

5. The list was real, non-public, and not re-constructable from public data, because it was produced by Delphi elicitation of state expert panels informed by DHS national security meetings, and none of this information was public. Assessed, 88.

6. The exposure this framework exists to manage is real and demonstrated, concentration plus digital dependency, proven in public when a ransomware crew halted roughly a fifth of American beef processing from a keyboard in 2021. High confidence, 92.

7. Biometric evidence, network logs, and photographs I preserved and offered were never collected by any agency. High confidence on the offer and the silence, 85.

The single line to carry out of this piece: you do not solve a national security problem by arguing about fire statistics. You run the process. The process was not run, the evidence was left on my shelf, and four and a half years later that is still true.

Start with the part that requires no inference, because it is where the weight belongs.

A criticality target list is not an ordinary document. It is a ranked map of which nodes in the American food and agriculture system matter most, the product of years of federally funded work, treated inside government as sensitive for exactly the reason you would expect: in the wrong hands it is a targeting aid. Mine was taken from a locked safe. I did what a person is supposed to do. I reported it, in sequence, to the five federal agencies with equities in food and infrastructure security, to the Michigan State Police, to the sheriff of the county I live in, and to the state’s homeland security fusion center. Eight separate bodies, each with a mandate that this report falls squarely inside.

Eight bodies, zero investigations. No case number that reached me. No forensic collection. No interview that went anywhere. I had preserved physical and digital evidence, biometric prints from a related break-in, router and network logs, photographs, and I offered all of it. None of it was ever collected. When the federal channels produced nothing, I put the matter in writing to seven cabinet-level and agency-head officials in March 2025, and to every member of Congress and 108 Michigan state legislators in September 2025. The letters are attached to this series, unedited. Read them and hold them against the response, which remains nothing.

That silence is the crime. Not a metaphor for a crime. The failure to investigate a reported compromise of a critical infrastructure targeting product is itself the national security failure, and it is complete on its own terms, before anyone argues about attribution, motive, or what happened to the facilities afterward. Strip out every contested claim in this piece and that one remains, dated and documented, and it is enough.

Now the maneuver that has kept that silence comfortable, because naming it is half the point of this part.

When this subject comes up, it is almost always redirected into a single question: are American food plants burning at an abnormal rate. Fact-checkers examined that question and answered it, correctly, in the negative. Fires and accidents at food facilities are common, and the frequency is not anomalous. I have never argued otherwise, and here is the point that matters I never posed the question. It was posed for me, and then answered, so that the answering could stand in for a response to what I reported.

This is a category error, and when it is done deliberately it is a technique. A national security risk is not an actuarial quantity you settle by counting events and comparing to a baseline. Fire frequency is a question for an insurance underwriter. The compromise of a ranked targeting product is a question for a counterintelligence and risk-management process. Answering the first to avoid the second is a limited hangout: you concede the small, true, safe point, that fires happen at a normal rate, precisely to bury the large, uncomfortable one, that a targeting list was stolen and nobody investigated it. A person who does this on purpose is running interference. A person who does it by reflex is a non-starter, arguing past the issue. A person who does it with careful language is a wordsmith, and the care is the tell.

So, I am not going to litigate fire statistics, because to do so is to accept the substitution. The frequency of fires is not the subject. The fact that the destroyed facilities matched the stolen criticality list beyond a statistical probability is a subtopic within the subject. The subject is a documented failure to execute a process that exists precisely to prevent the frequency of anything from ever becoming the question.

Here is the process, and why its absence is the real finding underneath the specific one.

The United States runs critical infrastructure protection as a continuous risk-management cycle, not a filing cabinet. Under Homeland Security Presidential Directive 7 and the National Infrastructure Protection Plan, the framework is explicit and it is a loop: set security goals, identify the critical assets and systems, assess and analyze the risk to them using the best available information and science, prioritize, implement protective and risk-reduction activities, then measure effectiveness and feed the result back into the next cycle. It is meant to be evidence-driven, repeatable, and accountable to measurable outcomes, and it is meant to run across the entire CI/KR enterprise without stopping. FASCAT, the tool that produced the list that was stolen, exists inside that framework. Its whole purpose is to feed the assess-and-prioritize step with a defensible ranking of what matters most.

Now apply the framework to the event. A compromise of a criticality and vulnerability product is not a footnote to the process; it is one of the highest-value risk inputs the process can receive. It changes the threat picture for every asset on the list at once, because it means an adversary may now hold the same prioritized map the defender built. A functioning risk-management cycle ingests that input and acts: reassess the risk to the listed assets, notify the owners and operators, adjust protective posture, and open the law-enforcement and counterintelligence threads that a theft demands. That is not optional and it is not exotic. It is the framework doing the one thing it is for.

None of it happened. The input arrived, reported eight times through the correct channels, and the cycle did not turn. No reassessment, no notification, no measurable action, no investigation. That is the systemic finding, and it is larger than my case. If the framework will not process a compromise this clean, reported this thoroughly, by a person with this standing, then the framework is not running. It is a document, not a process. And a risk-management enterprise that has quietly become a document is a national security exposure, because everyone downstream is relying on a loop that has stopped turning.

A discipline note first, and it is load bearing. What follows describes the existence, provenance, and handling of a dataset. It does not describe its contents, its ranking criteria, or any facility on it, by name, category, or region, and it never will in this publication. There is a version of this section that is a targeting aid, and I am not writing it.

Between 2007 and 2012 the federal government funded the Food and Agriculture Sector Criticality Assessment Tool, FASCAT, through a DHS Center of Excellence, to determine which food and agriculture systems were most critical to the nation. I was the scientist who collected and analyzed the FASCAT data, and the evaluation of the tool was published under my name in Risk Analysis in 2015. Only de-identified, generalized statistics were ever published. The facility-level data and the rank ordering were not, and only four people outside DHS held the underlying data. I was one of them.

How the ranking was produced is the fact that defeats the easy dismissal, so hold it. The rankings were not a formula run on public capacity figures. They were generated by the Delphi method: iterative, anonymized elicitation of expert panels in each state, informed by the experts who briefed state-level DHS national security meetings. Delphi is chosen precisely for problems where the answer is not reducible to observable numbers, where the value is in extracting and converging the distributed, tacit judgment of people who know things that appear in no public dataset. The output is therefore dependent on who sat on those panels and what they knew, which is why an outsider does not reconstruct it from a spreadsheet. This matters here for one reason only: it establishes that the stolen artifact was a genuine, non-public, high-value risk product, not a hobbyist’s list and not something already sitting in the open. It was exactly the kind of input the framework in Section III is built to protect and to act on, which makes the failure to act on its theft the more damning, not the less.

One more thing the framework exists to manage, on the record, so that no one can pretend the risk is hypothetical.

On 30 May 2021, over the Memorial Day weekend, a ransomware crew encrypted the systems of JBS, the largest meat processor in the world. The company shut down all its United States beef plants, roughly a fifth of national capacity, for several days, and paid a ransom of about eleven million dollars. Nobody set anything on fire. Nobody entered a plant. A criminal group with no state sponsorship removed a substantial fraction of national beef processing from a keyboard, because the cattle keep arriving and the schedule has no slack. That is the exposure in one event: concentration, so that a few nodes matter nationally, meeting digital dependency, so that those nodes can be reached without a fence ever being crossed.

The exposure is wider than beef and wider than ransomware. A modern combine is a networked data platform on a seasonal calendar an adversary can read, where an outage in February is an inconvenience and the same outage at harvest is a lost crop. The cold chain between plant and plate is a continuous temperature obligation monitored by the same class of controller this series has tracked throughout, where altering a setpoint, or altering what the monitor reports, spoils product or, worse, does not, and nobody catches it. And when a genuine agroterrorism signal does surface, as it did in the June 2025 smuggling case, the detection happens by luck at a border rather than by any process designed to catch it. Every one of these is a live input the risk-management framework is supposed to be ingesting and managing. The point of this part is that the framework is not running, so it ingests none of them.

There is a question about whether the stolen list was subsequently used, and it is a real question with a real answer available. I raise it here not to settle it, but to show that the tools to settle it existed and were declined, which is the failure to investigate stated in operational terms.

A competent investigation had at least three threads to pull, none of which required my cooperation beyond what I offered. The physical evidence, the prints and logs and photographs I preserved, could have been collected and examined; it never was. The provenance could have been established, who held the data, how the safe was reached, whether the network intrusion I documented connected to the theft; it never was. And the analytic question could have been tested directly: did the incidents that followed track the specific, non-public, non-re-constructable ranking, including the non-obvious entries that only the Delphi panels surfaced, and did the rate of incidents on the list step up after the theft rather than before. Those two tests, rank sensitivity and post-theft timing, are exactly the analysis a government with subpoena power and the underlying data could have run in weeks. They are how you distinguish an adversary working from the stolen list from coincidence or independent guessing, and they are decisive in either direction.

Nobody ran them. That is the whole point. This was never a hard problem starved of method. It was a straightforward problem starved of will. The refusal to collect the evidence and run the tests is not a gap in the science. It is the failure to investigate, described precisely, and it is why the attribution question remains open: not because it is unanswerable, but because the one party positioned to answer it declined to look.

The strongest objections to what I have argued, and my answers.

“You are dressing up a personal grievance as a national security failure.” The grievance and the failure are separable, and I have kept them separate. Whatever you think of my case, the general finding stands: there is no reliable pathway to investigate the theft or compromise of a critical infrastructure criticality product held outside federal networks by cleared academic and contractor personnel. Mine is the worked example. The hole is the finding.

“The fires really are statistically normal, so there is nothing here.” You have just performed the exact substitution this piece is about. The fire rate is normal and irrelevant. I never claimed otherwise and the subject is not fires. The subject is a reported theft of a targeting product and eight agencies that did not investigate it. Answer that, or concede that you are changing the question.

“You cannot prove the theft. You are an interested party.” Correct on both, and I have not asked you to take my word. The reports are dated, the letters are published, and the physical evidence was offered and refused. The theft is my account; the reporting and the refusal to collect evidence are matters of record. Those are different standards and I have not blurred them.

“If the framework failed everywhere, why single out DHS.” I am not singling out an agency; I am naming a process. HSPD-7 and the National Infrastructure Protection Plan define a continuous, measurable risk-management cycle across the CI/KR enterprise, and the compromise of a criticality product is precisely what that cycle exists to act on. The failure is that the cycle did not turn. That is a structural finding, and it will repeat, with someone else’s list, until it is fixed.

“Publishing this is a targeting aid.” Which is why this piece describes the existence and provenance of the list and never its contents and never will. If you came for the facilities, you came to the wrong author.

Part V, “When the Hospital Goes Dark.” The series turns to the place where the harm can finally be measured. What the peer-reviewed evidence now shows about mortality inside a hospital under ransomware, what happens to the hospitals next door, and why the deaths from a cyberattack are never counted as deaths from a cyberattack.

[1] Homeland Security Presidential Directive 7 (HSPD-7), “Critical Infrastructure Identification, Prioritization, and Protection,” 2003. https://www.cisa.gov/homeland-security-presidential-directive-7

[2] Department of Homeland Security, National Infrastructure Protection Plan and the CI/KR risk management framework. https://www.cisa.gov/resources-tools/resources/national-infrastructure-protection-plan

[3] Huff AG, Hodges C, et al., “Evaluation of the Food and Agriculture Sector Criticality Assessment Tool (FASCAT) and the Collected Data,” Risk Analysis, 2015. https://onlinelibrary.wiley.com/doi/10.1111/risa.12377

[4] Dalkey N, Helmer O, “An Experimental Application of the Delphi Method to the Use of Experts,” Management Science, 1963. https://doi.org/10.1287/mnsc.9.3.458

[5] Letters from Dr. Andrew G. Huff to the Attorney General, the Director of National Intelligence, and the Secretaries of Homeland Security, Defense, and Agriculture, and to the FBI, 23 March 2025, and the distribution to Congress, 17 September 2025. Attached to this series.

[6] CISA and contemporaneous federal reporting on the May 2021 JBS ransomware incident. https://www.cisa.gov/news-events/news/ransomware-attack-jbs

[7] United States Attorney’s Office, Eastern District of Michigan, “Chinese Nationals Charged with Conspiracy and Smuggling a Dangerous Biological Pathogen into the U.S.,” June 2025. https://www.justice.gov/usao-edmi/pr/chinese-nationals-charged-conspiracy-and-smuggling-dangerous-biological-pathogen-us

[8] USDA Economic Research Service, structure and concentration of US meat packing. https://www.ers.usda.gov/

[9] Joint Cybersecurity Advisory AA24-038A, PRC state-sponsored actors and US critical infrastructure, 7 February 2024. https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-038a

DHS has attempted to scrub this from the Internet it appears. Strange.

No posts

Read the original on aghuff.substack.com

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.