U.S. Government agencies and major vendors are acti vely attempting to secure critical infrastructure networ ks, but those efforts depend on patching unsecure, commodit y systems, installing add-on security appliances, and applying other industry “best practices” that are ineffective against new attacks and software subver sion. This has unfortunately led to the conclusion that i t is impossible to secure critical infrastructure networ ks and even that a completely new, “alternative” Internet is needed. These conclusions disregard known and prove n techniques for building secure, high-assurance, tru sted systems – techniques developed as a result of years of research and engineering experience and systematica lly codified in the Trusted Computer System Evaluation Criteria (TCSEC) and related documents. Those techniques have not since been improved upon or adequately replaced, not even by the more recent Common Criteria for Information Technology Security Evaluation. In this paper, we sketch how the truste d systems technology codified in the TCSEC can be app lied today to create a secure infrastructure network.