Securing the U.S. Electricity Grid from Cyberattacks U.S. GAO

grid cybersecurity

The monitoring the traffic between those critical systems as they talk to each other so we can see what they’re saying to each other, and that’s the last piece. And they’re sort of unusual. Some utility companies have cybersecurity-specific practices or teams. A 2024 Thales report found that 42% of critical infrastructure companies – including energy providers – suffered data breaches during the year. Find out more about our work on electricity grid cybersecurity by checking out our recent reports linked above. https://scivast.com/articles/analysis-energy-storage-systems/ New cyber awareness strategies from PNNL and others are increasing the ability to share information about threats, vulnerabilities, and mitigation strategies with people who can put that information to work.

I mean, if they’re building systems that are 74.5 MVA, this probably indicates that they’d rather not take all this on. Large power companies, transmission- So talk a little bit about what they consist in, what they ask people to do, and how they are enforced. Like what do they require of people? We’ll get to the distribution stuff later, which is really my true interest. If this thing is required for the grid to run, you don’t just reboot it because you get a blackout.

grid cybersecurity

In this paper, we highlighted resulting fundamental security problems and attack vectors, which still have to be addressed in the coming years in order to maintain a high level of security and availability of power grids as a critical infrastructure 2,3,4,5. Consequently, grid operators need to develop and maintain actionable incident response plans and guidelines, supporting their employees with precise instructions also at the technical level on how to react to security incidents. For example, phishing experiments are valuable to raise employees’ awareness for spear-phishing at companies in the electrical power domain . Especially, workers who have direct access to vital equipment need to be aware of social engineering techniques and empowered to detect simple attacks, such as spear-phishing. With an increasing integration of novel, easily-accessible assets, such as smart meters and charging infrastructure for electronic vehicles 78,126, into the communication infrastructure of smart grids, the challenge of physical security is further exaggerated. Still, an attacker doing active reconnaissance (e.g., a port scan) could even easily be detected by a simple traditional IDS which is not specialized on industrial control systems.

Even if PCNs are air-gapped, i.e., physically isolated from other networks, such as the office network to prevent lateral movement, attackers can still try to attack a PCN by strategically placing USB drives containing malware around a facility they are targeting. Because we gotta patch stuff.” Because most of the time you can’t just, like, take these systems offline. So we are concerned about its ability to find vulnerabilities in key equipment that we’re concerned about. W-we, I mean, what we typically do now is when we buy this gear and we don’t have these assurances, we just isolate the heck out of it so that it just can’t talk to anything. To do so, GAO reviewed relevant federal and industry reports on grid cybersecurity risks and analyzed relevant DOE documents. However, even if attackers are only able to control a small fraction of the power connected to the grid, they can still leverage mechanisms inherent to today’s large power grids to cause considerable damage.

  • With more than 100 technical experts focused on cybersecurity infrastructure research and solutions, helping assure the reliability and security of the nation’s power system is a key priority for PNNL.
  • Utilities must adopt comprehensive frameworks, invest in emerging technologies like AI and blockchain, and join industry consortia, partnering with regulators and academia to address evolving risks.
  • Of the vulnerabilities disclosed in 2025, approximately 4 percent of ICS vulnerabilities were actively exploited at the time of disclosure.
  • So you can’t prevent it from happening, but you can certainly detect it.
  • While this certainly provides an extra level of security, it does not offer any protection once an attacker has gained physical access to one device in the network.

Analysis and Evaluation At-Scale

I mean, you can physically dam- Well, that’s what’s I mentioned earlier, the physical protections for big transmission in the CIP standards, there’s a specific standard for that. Like, I mean, that’s what’s- Like, how do you, how do you rate the physical threats to the grid relative to the cybersecurity stuff? I mean, we’re arguably the best in the world at cyber anything, so one would have to believe that that’s a reality. One is, and maybe this is naive to even ask it, but like, are we trying to sneak-you know, are we trying to sneak stuff into China’s systems too? We’re starting with, you know, at the asset owner level, could you do this?

  • See how Schneider Electric strengthens cybersecurity in smart grids, safeguarding critical energy systems against evolving cyber threats and ensuring grid reliability.
  • Two men with previous criminal records of thefts were arrested on January 3, with the reported motive being to cut the power to serve as part of a wider plan to burglarize several businesses in the area.
  • W-we, I mean, what we typically do now is when we buy this gear and we don’t have these assurances, we just isolate the heck out of it so that it just can’t talk to anything.
  • Dubai Electricity and Water Authority (DEWA) is a government-owned utility that provides electricity and water services in the Emirate of Dubai.
  • So there’s other forces that push the, these components around a bit, too.

NIST Staff

Naturally, the security of their systems is not as tightly controlled as those of traditional energy companies. The rise of renewable energy has empowered many individuals and companies to enter the energy sector . Data exchange between office network and PCN should only be handled through a dedicated data exchange server, where every file is checked for malware before being passed through. To this end, we motivate the need for cybersecurity when operating power grids and outline promising approaches to provide security at different levels of abstraction. This paper specifically targets the security challenges originating from the increasing interconnection of power grids, especially at the transmission and distribution level.

grid cybersecurity

Filter by Priority Level Only receive alerts of selected priority levels However, the same modernization has dramatically expanded the cyber attack surface – NERC https://the-business-mag.net/what-are-the-emerging-markets-to-watch/ reports 60 new vulnerable points per day. A cyberattack that corrupts control systems without destroying hardware is typically resolved in days to weeks.

grid cybersecurity

Defense-in-Depth Cybersecurity Strategies

One of the key issues for electric grid security is that these ongoing improvements and modernizations have created more risk to the system. Reliability and efficiency are two key drivers of the development of the smart grid. The electric utility industry in the U.S. leads several initiatives to help protect the national electric grid from threats. This program area focuses on strengthening the cybersecurity of the grid’s digital and operational systems, ensuring data and control signals can’t be manipulated or disrupted. The Office of Electricity’s Grid Cybersecurity and Communications program aims to meet these challenges by researching, developing, testing and demonstrating how to build information security into grid architecture, technologies, networks and components. Cyber incidents can interrupt the grid, damage highly specialized equipment, and threaten human health and safety.

Related NIST Projects

A high-altitude nuclear detonation or purpose-built EMP weapon would damage electronic components across a wide area. The Western Interconnection recorded 220 physical security incidents in 2024, more than double the 107 incidents in 2023, according to DOE OE-417 reporting. The attack came close to blacking out approximately 500,000 people, https://neuralooms.com/articles/climate-change-current-status-future-prospects/ according to ESET Research. The North American Electric Reliability Corporation (NERC) reports that susceptible points on the grid are increasing by approximately 60 per day as the grid expands to incorporate distributed energy resources and smart grid technology. It requires visibility across adversary behavior, vulnerabilities, asset exposure, and operational context. The report makes clear that risk grows when those pathways are poorly segmented or when supporting systems are allowed to sit too close to operational functions without sufficient boundaries.

What Is The Grid Cybersecurity Market Growth Forecast?

And this is not an easy thing to do because we buy a lot of our equipment that, you know, not from the US. So what we’re also trying to do is to actually, you know, do this at the supply chain level. You can’t make them become like cybersecure and follow these federal guidelines and get audited, for example. Is that not sort of like where this needs to go eventually?

Background – The Key Pillars of Grid Security

It integrates real-world equipment with simulation capabilities to dynamically configure many experimental and testing setups. This information is shared with voluntary utility participants that collectively deliver more than 80 percent of the nation’s electricity. With more than 100 technical experts focused on cybersecurity infrastructure research and solutions, helping assure the reliability and security of the nation’s power system is a key priority for PNNL. Cyber incidents could disrupt energy services, damage highly specialized equipment, and threaten public health and safety.

Today the utility industry is advancing cybersecurity with a series of initiatives. The modern-day electric grid system is capable of restoring equipment that is damaged by natural disasters such as tornadoes, hurricanes, ice storms, and earthquakes in a generally short period of time. Burlington Electric discovered malware code in a computer system that was not connected to the grid. In 2016, members of the Russian hacker organization “Grizzly Steppe” infiltrated the computer system of a Vermont utility company, Burlington Electric, exposing the vulnerability of the nation’s electric grid to attacks. Investor-owned utilities operate under a different authority, state public utility commissions. In a report concerning extremist threats, the Department of Homeland Security made note of a Telegram document that gave instructions for low-tech sabotage, including attacks on electrical power stations with rifles.