Cart Total Items (0)

Cart

Abhishek Solar

utilities grid security

And growing nearly as fast as cyber threats is a strange trend toward physical attacks on grid infrastructure. That’s especially true as the past few years have seen the rise of OT/OT convergence, wherein formerly siloed equipment that runs physical processes for critical infrastructure (operational technology, or OT) has been hooked up to the IT network and the Internet in some cases, exposing it to more cyberthreats. To this end, our theoretical contributions consolidated in this perspective paper provide the foundation for deeper practical research and experimental studies to pave the way forward to provide a high level of cybersecurity for interconnected power grids. Achieving these goals requires tight collaboration between cybersecurity experts and grid operators to develop and implement cybersecurity solutions that are tailored to the unique requirements of power grids.

utilities grid security

They simultaneously increase demand and reduce performance, pushing energy, water, transport, and communications systems toward overload and cascading failure. Join our hazard resilience exercise to learn how we can build resilience together. Whether it’s a naturally occurring phenomenon like the Carrington Event or it’s from an artificial source, an EMP can indeed happen. However, just because it’s unlikely something might happen doesn’t mean it ever will. If there is any reason why we need grid security now, it’s because of the threat of an artificial EMP.

A unified platform for monitoring digital device https://www.volumepillshelper.com/category/internet-services/ behavior, access logs, and physical tampering alerts can support this hybrid defense model, helping teams close the visibility gap across both planes. The sections that follow examine six of the most effective practices for ensuring power grid security in the modern threat landscape. Engineers and operators must think in layers of visibility, access control, resilience, and coordinated response to better protect the grid.

Analyzing the power grid security threat landscape

utilities grid security

The industry partners with the federal government, particularly the https://power-at-work.com/get-the-job-done-understanding-your-earthmoving-machinery/ National Institute of Standards and Technology, the North American Electric Reliability Corporation, and federal intelligence and law enforcement agencies.

Enjoy more free content and benefits by creating an account

To prevent disruption to the network, Sheahan and Powelson recommended national standards and collaboration between federal and state energy regulators. In his 2015 book, Ted Koppel argues that all utilities, but especially smaller ones, do not truly air-gap their operations from the internet, leaving significant attack surfaces. The system includes systems necessary for operating the interconnected grid. Since 2014, vandalism and confirmed or suspected physical attacks on electrical grid infrastructure have also been the second-largest cause of electrical disturbance events. As an example, one risk specifically comes from the integration of digital communications and computer infrastructure with the existing physical infrastructure of the power grid.

The system includes a pan-tilt-zoom camera capable of 360-degree motion mounted on top of a tripod or pole with four installed radars. “The question we get all the time is, how do you tell if it’s a bad actor, or if it’s a 12-year-old kid that got the drone for their birthday? And in 2023, a neo-Nazi leader was among two arrested in a plot to attack five substations around Baltimore with firearms, part of an increasing trend in white supremacist groups planning to attack the U.S. energy sector. “Other countries that are not experiencing direct conflict are experiencing increasing amounts of physical attacks on their energy infrastructure,” she says. Yet despite a number of recent high-profile attacks in the United States, physical attacks on the grid are happening worldwide.

utilities grid security

If an attacker already works within the energy sector or compromises an employee of a grid operator, the attacker might have direct access to the control room or field devices and could, therefore, directly control devices or introduce malware, even to air-gapped systems. Consequently, curious or helpful employees may unknowingly compromise air-gapped systems by connecting such drives to devices in company networks. Even if PCNs are air-gapped, i.e., physically isolated from other networks, such as the office network to prevent lateral movement, attackers can still try to attack a PCN by strategically placing USB drives containing malware around a facility https://californianetdaily.com/the-best-windows-10-antivirus-software/ they are targeting. Once access to a machine in the office network has been gained, the attacker can passively listen for user credentials and search for, e.g., a VPN tunnel to the PCN.

  • A unified platform for monitoring digital device behavior, access logs, and physical tampering alerts can support this hybrid defense model, helping teams close the visibility gap across both planes.
  • The ESCC serves as the principal liaison between the federal government and the electric power sector, with the mission of coordinating efforts to prepare for, and respond to, national-level disasters or threats to critical infrastructure.
  • Attackers can leverage different attack vectors to compromise the network of a transmission or distribution system operator with the goal of causing a blackout or at least considerable disturbance in the power grid.
  • A CVD is an architectural blueprint for a specific use case designed and tested by Cisco engineers with Cisco equipment.
  • Lateral movement from the office network is one of the most dangerous attack vectors for power system operators.
  • Supported by DOE’s Office of Electricity, the EIOC offers a secure and collaborative environment for tackling the nation’s most pressing energy challenges—ensuring the nations critical electrical infrastructure is reliable, secure, and affordable.
  • The utilities industry has done an excellent job of ensuring our electric reliability.
  • The industry players are working together to make sure that we’re doing things in a way that mitigates the risk as much as possible, and we take a risk-based approach.
  • While it is evident that technology alone cannot secure the grid, it must be coupled with a strong security-first culture, ongoing training, and cross-disciplinary collaboration between engineers, operators, and security teams.

The rise of renewable energy has empowered many individuals and companies to enter the energy sector . Sometimes, though, as seen in the Ukraine attacks , there are other communication channels, such as VPNs, which allow direct communication between the office network and the PCN or remote maintenance lines for vendors or contractors. Data exchange between office network and PCN should only be handled through a dedicated data exchange server, where every file is checked for malware before being passed through. A simplified view of a TSO/DSO network, separated into office network (connected to the Internet, typical data processing tasks) and process control network (SCADA traffic, connecting the control room with substations and field devices). The industry players are working together to make sure that we’re doing things in a way that mitigates the risk as much as possible, and we take a risk-based approach.

Leave a Reply

Your email address will not be published. Required fields are marked *