When a section of the network goes dark, the top priority is usually getting it back online quickly: deploy crews to the site, reestablish service and minimize the outage window. That urgency is critical for customers depending on the network, but it can destroy valuable evidence when the damage wasn’t an accident.
In 2025 alone, more than 18,300 documented incidents of a vandalism and theft targeted communications networks, disrupting service for nearly 11.8 million customers. Compared with 2024, outage incidents jumped 59%, requiring a rapid response to restore service in each case. Twenty-eight states now treat network vandalism as a felony, including Colorado, Connecticut, Oregon and Virginia, which added protections this year, and federal legislation (H.R. 2784) is pending in Congress.
But those emergency responses can also compromise the evidence law enforcement needs to build a case, especially since documentation practices can vary across regions, contractors, shifts and functions. To address this problem, the industry needs a shared standard for preserving evidence and providing authorities with a clear, indexed package that non-specialists can understand.
STRIKE (Strategic Threat Response & Infrastructure Knowledge Exchange) is an industry coalition co-led by SCTE and NCTA to coordinate responses to the rise in network attacks, treating them as a national security crisis. It aims to share intelligence, advocate for stronger laws and align industry and government efforts to protect critical communications infrastructure.
In conjunction with STRIKE, SCTE recently established a Critical Infrastructure Protection Subcommittee (CIPS). CIPS will bring together operator participants from across the broadband industry, supporting the overall mission of infrastructure protection by developing response standards and operational practices.
STRIKE: Shared Concern to Shared Vision
In 2025, STRIKE was formed to address the industry leaders’ concerns about rising theft, intentional attacks and vandalism aimed at broadband networks in the U.S. Today, in cooperation with the SCTE Standards Program, it’s a working, cross-operator effort producing a formal evidence-collection standard investigators and prosecutors can use to hold offenders accountable.
STRIKE focuses on three main areas:
- Stronger enforcement and policy alignment. STRIKE advocates for treating network vandalism as a national security priority backed by real enforcement resources, not just the patchwork of state laws that already exist.
- Sharing threat intelligence and operational protocols across operators. Shared standards will enable the industry to respond and recover faster when incidents happen.
- Raising visibility for critical infrastructure. Broadband network attacks impact critical public safety infrastructure, including 911 access, hospitals, schools, emergency responders and other public services.
STRIKE gives operators a shared platform to coordinate threat intelligence and response. It also enables lessons learned from one company’s incident to help protect the next, instead of everyone learning the hard way on their own.
CIPS: Establishing Consensus
Functioning alongside STRIKE, CIPS is a newly established subcommittee in the ANSI-accredited SCTE Standards Program. The team will consist of representatives from across the broadband industry, including AT&T, Comcast, Lumen, Midco, Mediacom, Optimum, Spectrum, T-Mobile, Verizon and Zayo. It will be chaired by Chris Snyder, a Regional Vice President of Field Operations at Spectrum.
“Protecting critical communications infrastructure is bigger than any one company. CIPS brings together operators, suppliers, law enforcement and government officials to share what we see in the field and develop solutions that can improve incident response and ultimately make our networks more resilient.”
The subcommittee’s charter centers on four objectives:
- Developing voluntary consensus standards, operational practices and technical guidance. These guidelines aim to strengthen the protection, resilience and recovery of broadband infrastructure before, during and after intentional damage incidents.
- Establishing common frameworks. Common frameworks ensure consistent handling of incident classification, forensic readiness, evidence preservation and coordinated response.
- Promoting collaboration. The subcommittee’s work supports consistent practices and knowledge sharing among operators, equipment manufacturers, government agencies and law enforcement.
- Advancing the industry’s response to intentional infrastructure damage. Practical, interoperable standards will improve the industry’s ability to deter, investigate and recover from intentional infrastructure damage.
What a Consistent Standard Will Achieve
A consistent ANSI standard for forensic readiness and evidence collection should give operators and contractors a consistent, repeatable method for documenting and preserving evidence at the scene of vandalism or theft incident. The goal is to ensure that all evidence collected holds up in court and helps investigators build a case, no matter which operator responds.
The response lifecycle includes five stages:
- Ready: Preparation before an incident occurs, including defined roles, evidence kits and training.
- Control: Addresses the scene itself, defining safety procedures and scene preservation as restoration begins.
- Document: Captures the record with photos, measurements and written details.
- Preserve: Governs the evidence itself, including labeling and chain of custody.
- Handoff: Produces a structured evidence package for authorities.
The standard should integrate with workflows that already exist (outage response, safety, security, legal and restoration), rather than introducing a separate process alongside them. The goal is a consistent record of what happened at a damage site, not a mandate on how operators secure their networks or repair them.
How the Broadband Industry Benefits
A repeatable evidence standard for operators and for the broader critical infrastructure players ensures that evidence is captured without slowing down restoration. Benefits include:
- Less evidence lost: A minimum photo set, labeling conventions and preservation steps applied consistently reduce the risk that a fast repair erases critical evidence.
- Less rework: A consistent evidence register and chain-of-custody record hold up better under scrutiny than ad hoc documentation assembled after the fact.
- Faster handoff: A structured package with a brief, timeline, exhibits and contacts gives investigators what they need as quickly as possible.
- Better readiness: Evidence kits are already in hand and ready to go, operatives have been trained in how to approach evidence gathering, and they know exactly what to do before an incident occurs.
When evidence is captured the same way across operators and regions, cross-incident learning can inform risk-reduction efforts for the whole industry, rather than each operator learning the same lessons independently. A well-documented case is also more likely to result in prosecution, giving the industry’s push for stronger enforcement a concrete outcome.
Beyond the standard itself, training and certification can be developed for field teams so that they are equipped with the tools and methodologies to effectively gather the evidence. Through the SCTE Chapters program, outreach can extend to local law enforcement agencies to keep them apprised of both the threat posed by network vandalism and the evidence collection methods that can help lead to arrests and prosecution of those responsible.
None of this replaces the physical security investments operators are already making, but it adds a consistent way to document and act when prevention isn’t enough.
How to Get Involved
Infrastructure protection is an industry-wide challenge, and it calls for an all-in response. Whether your expertise is in network operations, field restoration, security, legal, public safety or infrastructure engineering, there’s a role for you in the Critical Infrastructure Protection Subcommittee (CIPS). Meetings begin Oct. 13 to focus on the development of the evidence collection standard and identify other areas of need.
To learn more or get involved, reach out to [email protected].