Utilities News – Preet Kahai https://kahai.com/preetblog Photographer Wed, 16 Sep 2026 12:20:23 +0000 en-US hourly 1 https://wordpress.org/?v=4.8.25 Power Grid Vulnerability https://kahai.com/preetblog/?p=26599 https://kahai.com/preetblog/?p=26599#respond Mon, 10 Jul 2023 13:04:06 +0000 http://kahai.com/preetblog/?p=26599 grid cybersecurity

GAO launched its WatchBlog in January, 2014, as part of its continuing effort to reach its audiences—Congress and the American people—where they are currently looking for information. GAO’s mission is to provide Congress with fact-based, nonpartisan information that can help improve federal government performance and ensure accountability for the benefit of the American people. The Federal Energy Regulatory Commission (FERC)—which regulates the interstate transmission of electricity—has approved mandatory grid cybersecurity standards. However, we found that DOE’s plans do not fully incorporate the key characteristics of an effective national strategy. For National Cybersecurity Awareness Month (October), today’s WatchBlog post looks at two of our recent reports on cybersecurity risks to the U.S. electric grid and federal efforts to address them.

The countries covered in this market report are Australia, Brazil, China, France, Germany, India, Indonesia, Japan, Taiwan, Russia, South Korea, UK, USA, Canada, Italy, Spain. https://master-your-business.com/what-are-the-latest-trends-in-innovation/ The regions covered in this market report are Asia-Pacific, South East Asia, Western Europe, Eastern Europe, North America, South America, Middle East, Africa. North America was the largest region in the grid cybersecurity market in 2025.

Energy sectors worldwide are undergoing transformation – renewable sources, smart grids, transport electrification. “A robust and resilient electricity grid is the foundation for a low carbon future, managing the cyber risks is key to that and it’s a challenge that must be tackled together. We are proud to work alongside those organisations that are key to delivering electricity, to find a better way forward in addressing these risks globally.” “This initiative provides a forum for global electric companies and premiere industry partners to take the lead in driving increased maturity and capability to address cyber threats all nations are facing.” Securing the modern power grid with hybrid deep learning against cyber threats in renewable-integrated smart grids Control systemsCritical infrastructureCritical infrastructure protectionCritical infrastructure vulnerabilitiesCyber attacksCybersecurityElectricityElectricity gridsEnergy resourcesEnergy sectorsFederal agenciesGlobal positioning systemHomeland securityNational laboratoriesPublic utilities

grid cybersecurity

Identify and assess

  • At the same time, we’re using AI to patch those vulnerabilities.
  • Investor-owned utilities operate under a different authority, state public utility commissions.
  • The North American Electric Reliability Corporation (NERC) reports that susceptible points on the grid are increasing by approximately 60 per day as the grid expands to incorporate distributed energy resources and smart grid technology.
  • They can typically stabilize these things.
  • This allows an attacker, e.g., to control switches in substations which disconnect entire power lines or power plants from the grid, possibly leading to an immediate loss of the energy supply to consumers.
  • And they’re sort of unusual.

In the attack on Ukraine in 2015, 225,000 consumers were disconnected from the grid, as attackers were able to control switches in multiple substations . If an attacker already works within the energy sector or compromises an employee of a grid operator, the attacker might have direct access to the control room or field devices and could, therefore, directly control devices or introduce malware, even to air-gapped systems. Such an attack would likely be local in scope with a medium impact, as attackers could only execute previously determined attacks. Hence, such a theft could be used as camouflage by cyber attackers to deter grid operators from even looking for traces of a cyber attack. While this certainly provides an extra level of security, it does not offer any protection once an attacker has gained physical access to one device in the network.

El Apagón—The Blackout. Puerto Rico’s Continuing Struggle for Stable Electricity

This is an illustrative chart; the full report provides a complete and accurate competitive analysis. This chart maps companies by product innovation and brand strength, with bubble size indicating relative revenue, helping identify market leaders, challengers, and niche players. The grid cybersecurity market size is expected to see rapid growth in the next few years. Utilities must adopt comprehensive frameworks, invest in emerging technologies like AI and blockchain, https://pluginhighway.ca/blog/how-to-choose-the-best-battery-for-your-tesla-electric-vehicle-and-maximize-its-performance and join industry consortia, partnering with regulators and academia to address evolving risks. Securing smart grids and substations is essential to sustaining reliable and sustainable energy infrastructure.

grid cybersecurity

grid cybersecurity

In 2016, members of the Russian hacker organization Grizzly Steppe infiltrated the computer system of a Vermont utility company, Burlington Electric, but did not disrupt the state’s electric grid. The attack, in which gunmen fired on 17 electrical transformers, resulted in more than $15 million worth of equipment damage, but it had little impact on the station’s electrical power supply. Its mission is to coordinate efforts to prepare for, and respond to, national-level disasters or threats to critical infrastructure. In May 2020, he issued an executive order that bans the use of grid equipment manufactured by a foreign adversary. Energy Department to identify any vulnerabilities to cyberattacks in the nation’s electrical power grid.

  • Find out more about our work on electricity grid cybersecurity by checking out our recent reports linked above.
  • Assuming a vulnerability in a large number of, e.g., solar installations is found, attackers may control the power fed into the grid.
  • Once access to a machine in the office network has been gained, the attacker can passively listen for user credentials and search for, e.g., a VPN tunnel to the PCN.
  • A high-altitude nuclear detonation or purpose-built EMP weapon would damage electronic components across a wide area.
  • In addition, the Shield suite provides compliance readiness reporting, vulnerability risk prioritization, and assessment capabilities to help utilities reduce exposure and pass audits confidently.

In the following, we briefly discuss the three most important methods an attacker with access to the PCN can employ. We assume an attacker accessing a PCN to aim at disrupting the power grid and do not specifically consider pure passive attacks, such as industrial espionage. An insider attack can have a high impact on the grid, especially since insiders typically have decent knowledge of the inner workings of grids and potential security measures in place, thus being able to carefully pick their target. Different examples of disgruntled employees misusing their authority have been reported by Brdiczka .

]]>
https://kahai.com/preetblog/?feed=rss2&p=26599 0
Electric Grid Cybersecurity: 2026 OT Threat Insights https://kahai.com/preetblog/?p=26597 https://kahai.com/preetblog/?p=26597#respond Thu, 06 Jul 2023 15:39:34 +0000 http://kahai.com/preetblog/?p=26597 grid cybersecurity

So could they do key points and cause regional problems? They’ll wanna do typically like a 1B investigation, especially if it causes a blackout, they send in a blackout investigation team, and those are some solid engineers that go do that work. Like if you caused a problem where my insurance company is trying to prove that it wasn’t us, but it was somebody else, they’re likely gonna send in some forensics teams to go figure out what happened. Like who’s typically, who are you gonna find that was at fault if you, if something goes wrong? So there’s other forces that push the, these components around a bit, too.

grid cybersecurity

As you know, where the federal regulations don’t reach, it’s pretty much left to the states, and in a lot of cases, you can end up with like, you know, 50 different directions. So I’m curious, sort of like, what’s the first thing you kinda tell them to get grounded, and what sort of misconceptions are they carrying around with them? It’s an unusually broad range of experience and it has made him a prized voice in the field, a level head in an area filled with uncertainty and fear. There was no major damage to the facility, and no service disruptions were reported after the incident, which authorities investigated as a terrorism-related event. Two men with previous criminal records of thefts were arrested on January 3, with the reported motive being to cut the power to serve as part of a wider plan to burglarize several businesses in the area.

grid cybersecurity

APPA and public power utilities play a leadership role on the ESCC, which includes utility CEOs and trade association leaders representing all segments of the industry. The ESCC serves as the principal liaison between the federal government and the electric power sector, with the mission of coordinating efforts to prepare for, and respond to, national-level disasters or threats to critical infrastructure. Moreover, there https://pagemakers.net/building-a-sustainable-home-eco-friendly-design-and-construction/ is robust electric utility industry participation in information sharing organizations known as the Electricity Information Sharing and Analysis Center (E-ISAC) and the Multi-State Information Sharing and Analysis Center. The electric sector is unique in that it has long been subject to cyber incident reporting mandates to the Department of Energy (DOE) via an Electricity Emergency Incident and Disturbance Report (OE-417) and NERC/FERC. To this end, our theoretical contributions consolidated in this perspective paper provide the foundation for deeper practical research and experimental studies to pave the way forward to provide a high level of cybersecurity for interconnected power grids.

The Electric Grid You Defend Has Changed According to OT Threat Intelligence

Is the utility the one doing that? Is that at the device level, or is that at the system level? Yeah, that, that’s a concern, but nationwide or continent-scale blackouts are just not a realistic thing.

  • Yeah, because they’re, I mean, that’s, it’s a bigger threat.
  • The countries covered in this market report are Australia, Brazil, China, France, Germany, India, Indonesia, Japan, Taiwan, Russia, South Korea, UK, USA, Canada, Italy, Spain.
  • Cyber incidents could disrupt energy services, damage highly specialized equipment, and threaten public health and safety.
  • Consequently, an attacker can do considerable damage even when controlling only a comparably small amount of energy by exploiting cascading effects (see above) .
  • The attack, in which gunmen fired on 17 electrical transformers, resulted in more than $15 million worth of equipment damage, but it had little impact on the station’s electrical power supply.

More sophisticated physical security may not only deter attackers but also act as a part of a general IDS. For example, a motivated attacker could break into a substation and infect local devices with malware or otherwise tamper with the available access to the PCN. Intrusion detection systems (IDS) are used in most company networks to detect attackers through suspicious network activities 113,114. In future attacks, similar methods could, e.g., allow attackers to overload power lines even if these are secured by protection devices, potentially leading to physical damage. Even if attackers neither have full access to the PCN nor can inject (false) information, they may still be able to manipulate certain devices and effectively render them non-functional to launch a denial of service attack against parts of the power grid .

Like, is there– do we have evidence, not just sort of vague suspicions, but do we have evidence that they are– want to do or trying to get away with something? You just can’t prevent everything. So you can’t prevent it from happening, but you can certainly detect it. It would break, and you’d have to go buy new stuff. They actually make quality stuff.

grid cybersecurity

Related NIST Projects

In August 2019, GAO reported that the generation and transmission systems—which are federally regulated for reliability—are increasingly vulnerable to cyberattacks. For example, DOE’s plans do not address distribution systems’ vulnerabilities related to supply chains. The industry is expanding equipment sharing programs—like the Spare Transformer Equipment Program, SpareConnect, and Grid Assurance—to improve grid resiliency. Finally, electric utilities regularly share transformers and other equipment through long-existing bilateral and multilateral sharing arrangements and agreements. The ESCC used the concept of traditional mutual assistance networks to develop the Cyber Mutual Assistance Program that can help electric and natural gas companies, public power utilities, and/or electric cooperatives restore critical computer systems following significant cyber incidents. The three primary segments of the electric utility industry—public power, investor-owned, and electric cooperatives—have long had in place mutual aid response networks to share employees and resources to restore power after natural disasters and other emergencies.

grid cybersecurity

  • Is that not sort of like where this needs to go eventually?
  • In August 2019, GAO reported that the generation and transmission systems—which are federally regulated for reliability—are increasingly vulnerable to cyberattacks.
  • The 2025 Poland attack demonstrated that distributed energy targets are vulnerable at scale, and the growing number of internet-connected grid components continues to expand the attack surface.
  • The electric utility industry in the U.S. leads several initiatives to help protect the national electric grid from threats.
  • In a report concerning extremist threats, the Department of Homeland Security made note of a Telegram document that gave instructions for low-tech sabotage, including attacks on electrical power stations with rifles.

Act swiftly to contain, mitigate, and communicate during grid cybersecurity incidents, minimizing https://britainrental.com/pin-din-1471-conical-with-a-line-a-reliable-element-in-mechanical-engineering.html impact and disruption In an interconnected grid, small, unnoticed vulnerabilities can escalate rapidly. See how Schneider Electric strengthens cybersecurity in smart grids, safeguarding critical energy systems against evolving cyber threats and ensuring grid reliability. The market research report delivers a complete perspective of everything you need, with an in-depth analysis of the current and future state of the industry.

Public Inquiries

At the same time, we’re using AI to patch those vulnerabilities. AI is really good at finding vulnerabilities. I’ll keep it to the two key things. So yeah, they’re– I think most of them are realizing this is just a good business decision, too.

]]>
https://kahai.com/preetblog/?feed=rss2&p=26597 0