“There is no effing way the NSA is not all over their security. This is not some group of high school kids.”
I assure you the NSA was not involved, at least until yesterday. This is the realm of FBI and DHS/CISA.
While there are specific regulations for critical infrastructure, they are really not seriously enforced. There is no lawful way to do that, though folks may want to consider it given the importance.
I was involved with an incident where a major defense contractor and manufacturer was compromised entirely.
Of course that was China.
But it happens all the time with major corporations. Most of them you never hear about.
I worked in telecom for a bank. The bank regulators took this stuff very, very seriously. It was tedious how serious it was. I imagine in the years since I have been retired I imagine it’s gotten even more serious.