If an attacker already works within the energy sector or compromises an employee of a grid operator, the attacker might have direct access to the control room or field devices and could, therefore, directly control devices or introduce malware, even to air-gapped systems. Consequently, curious or helpful employees may unknowingly compromise air-gapped systems by connecting such drives to devices in company networks. Even if PCNs are air-gapped, i.e., physically isolated from other networks, such as the office network to prevent lateral movement, attackers can still try to attack a PCN by strategically placing USB drives containing malware around a facility they are targeting. Once access to a machine in the office network has been gained, the attacker can passively listen for user credentials and search for, e.g., a VPN tunnel to the PCN.
A unified platform for monitoring digital device behavior, access logs, and physical tampering alerts can support this hybrid defense model, helping teams close the visibility gap across both planes. The sections that follow examine six of the most effective practices for ensuring power grid security in the modern threat landscape. Engineers and operators must think in layers of visibility, access control, resilience, and coordinated response to better protect the grid.
Building off the success of GridEx, APPA hosted its first ever cyber mutual aid exercise, Safe Haven, in fall 2025, funded by DOE. Electric utilities plan and regularly exercise for a variety of emergency situations that could impact their ability to provide electricity. APPA and public power utilities play a leadership role on the ESCC, which includes utility CEOs and trade association leaders representing all segments of the industry. The ESCC serves as the principal liaison between the federal government and the electric power sector, with the mission of coordinating efforts to prepare for, and respond to, national-level disasters or threats to critical infrastructure. One important venue for this collaboration is the Electricity Subsector Coordinating Council (ESCC). The electric power industry works closely with the federal government, including NERC, FERC, DOE, and DHS, on matters of critical infrastructure protection.
Building a security-first culture: Awareness, training & visibility
And growing nearly as fast as cyber threats is a strange trend toward physical attacks on grid infrastructure. That’s especially true as the past few years have seen the rise of OT/OT convergence, wherein formerly siloed equipment that runs physical processes for critical infrastructure (operational technology, or OT) has been hooked up to the IT network and the Internet in some cases, exposing https://alstatenews.com/what-are-wood-pellets-how-are-they-made.html it to more cyberthreats. To this end, our theoretical contributions consolidated in this perspective paper provide the foundation for deeper practical research and experimental studies to pave the way forward to provide a high level of cybersecurity for interconnected power grids. Achieving these goals requires tight collaboration between cybersecurity experts and grid operators to develop and implement cybersecurity solutions that are tailored to the unique requirements of power grids.
How to Build Software that Empowers a Modern Military
In collaboration with industry, PNNL is creating systems with built-in resiliency and cybersecurity controls that enable energy delivery systems to keep working regardless of threats. PNNL plays a lead role in CRISP, which uses advanced sensors and data analysis to identify new and ongoing cyber threats. The federal government and its national laboratories complement these efforts as part of their mission to protect national and economic security. With attacks becoming more frequent and more severe, it is imperative that utilities continue to evolve and mature their cybersecurity posture to ensure operational uptime, improve situational awareness, minimize risk and promote the safety of employees and the community. Leidos helps clients answer this question by enhancing the visibility and the status of an organization’s key safety systems (i.e., the barriers used to control the hazards within its operations). Pre-built models for anomaly detection, user behavior analytics, and threat classification can be customized for energy sector environments.
How Secure Is America’s Power Grid? Are We Doing Enough to Protect It Against an Attack?
- A simplified view of a TSO/DSO network, separated into office network (connected to the Internet, typical data processing tasks) and process control network (SCADA traffic, connecting the control room with substations and field devices).
- Yet despite a number of recent high-profile attacks in the United States, physical attacks on the grid are happening worldwide.
- Past attacks have shown that office networks (connected to the Internet) are often not sufficiently separated from the PCN, allowing attackers lateral movement between the two .
- As a foundation to overcome these challenges and, thus, provide security for distribution and transmission systems, we now identify attack vectors and attack scenarios that result from the fundamental security challenges.
- As an example, one risk specifically comes from the integration of digital communications and computer infrastructure with the existing physical infrastructure of the power grid.
Fortunately, digital technology can aid in better utilizing the existing grid, leading to an increased deployment of digital technology to control, monitor, and maintain transmission and distribution of power 2,11. The Grid Security Design Guide is designed for utility companies implementing a holistic security architecture that includes Cisco Cyber Vision and Cisco networking hardware. With a focus on safeguarding Critical National Infrastructure, find out how our integrated and intelligent approach to OT security allows organisations to gain an initial overview and understanding of the existing OT security posture in order to identify key priority areas for improvement. While there she worked extensively on various efforts, including energy resilience exercises, energy project planning tools, government partnerships, defense critical electric infrastructure, and more. By combining these tools with strong processes and people, the backbone of our modern society can remain reliable, resilient, and protected regardless of how the threat landscape evolves.
As preparations get underway for the ninth GridEx, in 2027, Ball says participation in the exercises alone isn’t enough to bolster grid security. An AI model processes the results and can classify events based on patterns in the optical signal as a result of perturbations happening around the fiber cable. A file-cabinet-size unit plugs into a substation and sends light pulses down existing fiber optic cables 30 miles in each direction. Already, a number of utilities https://angliannews.com/ukraine-s-energy-sector-investment-opportunities-in-renewable-energy.html in the United States are using AI integrations in their security and monitoring processes.
The system includes a pan-tilt-zoom camera capable of 360-degree motion mounted on top of a tripod or pole with four installed radars. “The question we get all the time is, how do you tell if it’s a bad actor, or if it’s a 12-year-old kid that got the drone for their birthday? And in 2023, a neo-Nazi leader was among two arrested in a plot to attack five substations around Baltimore with firearms, part of an increasing trend in white supremacist groups planning to attack the U.S. energy sector. “Other countries that are not experiencing direct conflict are experiencing increasing amounts of physical attacks on their energy infrastructure,” she says. Yet despite a number of recent high-profile attacks in the United States, physical attacks on the grid are happening worldwide.
- Centralized dashboards consolidate visibility across sites, devices, and compliance status, supporting a Defense-in-Depth approach to grid security.
- Department of Energy (DOE) reported at least 175 instances of physical attacks or threats against critical grid infrastructure, including incidences of theft and vandalism.
- Already, a number of utilities in the United States are using AI integrations in their security and monitoring processes.
- Energy Department to identify any vulnerabilities to cyberattacks in the nation’s electrical power grid.
- Depending on the sophistication of the attack, SCADA software may be able to identify a problem through bad data detection algorithms.
The industry partners with the federal government, particularly the National Institute of Standards and Technology, the North American Electric Reliability Corporation, and federal intelligence and law enforcement agencies.
