I expect after a few major crises involving mass casualties or major economic losses the federal government will mandate that private industry completely disconnect certain critical infrastructure control systems from the public Internet. Basically the same approach used by SIPRNet.