Center for Grid Security SAFE
Given the number of organizations present, GridEx estimates that more than 28,000 individual players participated, including utility workers and government partners, an all-time high since the exercise began. Called GridEx, the exercise was hosted by the Electricity Information Sharing and Analysis Center (E-ISAC) from 18 to 20 November 2025, and was described in a report released on 2 March. Aspects include emergency exercises, such as NERC’s biannual GridEx program. The Electricity Subsector Coordinating Council (ESCC) is the liaison between the electric power industry and the federal government, and it is responsible for preparing for and responding to threats and disasters.
Devices capable of subjecting transformers and other critical infrastructure to localized, but destructive, levels of EMP can be built from readily available equipment from local electronics stores and instructions from the internet. The utilities industry has done an excellent job of ensuring our electric reliability. Last year, when the Department of Energy announced $45 million of funding for energy sector security, it chose to distribute a chunk of that money to a research project focused on preventing cyber-physical threats to distributed energy resources (DER) using zero-trust authentication. Bramson tells Dark Reading that “the gap comes from having more than one team owning cybersecurity, and the potential opportunity for assumptions of ‘the other side’ covering some aspect of the system.” IT and OT might involve different machinery, but ever since cyber-physical attacks rose to prominence in the late 2000s and 2010s, the considerations of each have affected both. On the physical attack front, in February 2023, the Electricity Information Sharing and Analysis Center (E-ISAC) disclosed that physical attacks on the power grid had risen a full 71% in 2022 (and 20% over 2020 numbers).
As the grid evolves through digitization, IoT expansion, and increased automation, so does its exposure to cyber and physical threats. The Ukraine 2015 power grid attacks showcased how attackers can remotely control circuit breakers while disabling operator visibility and response capabilities. It includes an interconnected network of substations, transmission lines, https://orwell.ru/test/web/ control systems, and intelligent devices that work together to keep electricity flowing reliably. The power grid has become one of the most complex systems and infrastructures ever designed.
Centralized platforms support cultural transformation by offering visibility tools built for OT teams, presenting alerts, compliance drift, and access violations in language and context relevant to field personnel. Finally, CISA 2015 set up policies and procedures for voluntary sharing of cybersecurity threat information between and among the federal government and private entities (the definition of which includes public power utilities) and provides limited liability protection for these activities. While not all data is publicly available, Coe says there’s been a “tenfold” increase over the past decade in the number of reported physical attacks on the grid. This scenario, inspired by the upcoming 2026 World Cup and the 2028 Olympic Games in Los Angeles, was an exercise in studying how utilities can prevent and mitigate, among other dangers, physical attacks on power grids. The bill includes a number of provisions to establish a more transparent and streamlined process by which the President, the Department of Energy, and the Federal Energy Regulatory Commission (FERC) can act to address existing or potential vulnerabilities.
How Secure Is America’s Power Grid? Are We Doing Enough to Protect It Against an Attack?
While it is evident that technology alone cannot secure the grid, it must be coupled with a strong security-first culture, ongoing training, https://www.softcourier.com/list.php?cat=System%20Utilities%3A%3ASystem%20Maintenance&page=58 and cross-disciplinary collaboration between engineers, operators, and security teams. Ensure that only vendors with secure firmware update processes are engaged. Automated monitoring dashboards provide real-time visibility into device vulnerabilities, firmware versions, and patch status, helping utilities detect risks early and streamline remediation. Organizations should leverage automations for continuous visibility within distributed environments and rapid detection of abnormal activity such as unauthorized access, firmware tampering, or communication anomalies. Centralized dashboards consolidate visibility across sites, devices, and compliance status, supporting a Defense-in-Depth approach to grid security. Organizations should deploy asset discovery tools to build a live inventory, use platforms that integrate with SCADA to surface device status, firmware versions, and create a layered defense.
Power grid exposure points and threat landscape
The company lacked the visibility needed to secure the grid and meet its regulatory compliance requirements. With these benefits, however, comes a significantly increased surface area for attacks on both the utility networks as well as the power grid. Recent advances in smart energy technology have provided increased control and efficiency by enabling two-way communication between utilities and energy users. Through this combination of deep expertise, specialized facilities, technology development, and industry collaboration, PNNL is helping protect our nation’s electricity infrastructure from cyber threats today and into the future.
- “The question we get all the time is, how do you tell if it’s a bad actor, or if it’s a 12-year-old kid that got the drone for their birthday?
- This visibility also gave the OT organization valuable insights into industrial processes, reduced the organization’s regulatory risk, and enhanced IT/OT collaboration.
- A private cloud foundation gives you the control, segmentation and visibility required to integrate OT and IT without increasing outage or safety risk as the grid becomes more intelligent and distributed.
- As noted above, CISA 2015 set up policies and procedures for the voluntary sharing of cybersecurity threat information between and among the federal government and private entities and provided limited liability protection for these activities.
- If an attacker already works within the energy sector or compromises an employee of a grid operator, the attacker might have direct access to the control room or field devices and could, therefore, directly control devices or introduce malware, even to air-gapped systems.
- Recent advances in smart energy technology have provided increased control and efficiency by enabling two-way communication between utilities and energy users.
For example, phishing experiments are valuable to raise employees’ awareness for spear-phishing at companies in the electrical power domain . Moreover, as traffic in PCNs is well defined, a network-based IDS can detect further suspicious network activity, e.g., an increase in the number of packets sent from a network node or communication between network nodes that have not communicated beforehand. Most of the communication in a PCN in the energy sector is conducted between the control room and substations or field devices. In the following, we discuss the different approaches for IDS and their application to the energy sector.
Solutions developed here are shared across the energy sector, helping build a more reliable, affordable, secure, and resilient grid for the future. Developed with input from utilities, vendors, and researchers, the EIOC brings together live grid data feeds, advanced analytics, and industry-grade software in a flexible space where new tools can be tested and refined. Supported by DOE’s Office of Electricity, the EIOC offers a secure and collaborative environment for tackling the nation’s most pressing energy challenges—ensuring the nations critical electrical infrastructure is reliable, secure, and affordable. By quickly identifying trends and relationships that may reveal a potential threat, grid operators and automated protection systems can rapidly take action to protect the grid. Other examples include data resilience tools like blockchain and adaptive control systems, which adjust in real time based on system conditions.
Her previous experience also includes supporting energy security programs for the U.S. Current permitting processes delay essential energy infrastructure, compromising national defense, economic stability, and America’s competitive edge—with essential projects taking up to years to build. SAFE’s Center for Grid Security provides policy analysis and recommendations to build out the national power grid – ensuring America’s energy and national security. Modern platforms that provide unified visibility, automation, and device lifecycle management can play an important role in helping utilities proactively address vulnerabilities and embrace innovation.
Build a resilient private cloud foundation for utilities and OT/IT convergence
In 2024, Check Point Research documented 1,162 cyberattacks on utilities, a 70 percent increase compared with the same period in the prior year. Department of Energy (DOE) reported at least 175 instances of physical attacks or threats against critical grid infrastructure, including incidences of theft and vandalism. Its federal government counterparts include senior administration officials from the White House, relevant cabinet agencies, federal law enforcement, and national security organizations. The Electricity Subsector Coordinating Council (ESCC) is the main liaison organization between the federal government and the electric power industry. Energy Department to identify any vulnerabilities to cyberattacks in the nation’s electrical power grid. Baltimore Gas and Electric conducts regular drills with its employees.
New Research from AXIS Communications Reveals Video Surveillance AI Perspectives
Along with all the responsibilities that come with navigating the organization toward increased success and reduced risk, how leaders interact with others sets the tone for the rest of the company. With these events on the rise, it’s time to reassess the resilience of your organization’s infrastructure. With visibility and the ability to detect cyberattacks, the power utility gained confidence in https://www.yaldex.com/Bestsoft/Utilities.htm its security posture at the edge and throughout the network. The IT security organization was able to identify those devices and where they were connected, and quickly address the security vulnerabilities that were creating a risk exposure. A CVD is an architectural blueprint for a specific use case designed and tested by Cisco engineers with Cisco equipment. The sensors are embedded into industrial switches, making it easy to deploy at scale throughout the production, transmission, and distribution networks, enabling the power company to obtain visibility into all the traffic.
Our goals include:
In the following, we first discuss the most important attack vectors before we present the attack scenarios enabled by these vectors. Practical cybersecurity in interconnected power grids is impacted by a diverse set of fundamental security challenges. As a result, there is a need to develop solutions which can be used by all relevant actors in interconnected power grids and are not only deployable by larger grid operators. Once an attacker gains access to an unsecured PCN, simple tools enabling communication in the specific protocol may be used to control devices crucial for grid operation. Past attacks have shown that office networks (connected to the Internet) are often not sufficiently separated from the PCN, allowing attackers lateral movement between the two .


Leave a Reply
Want to join the discussion?Feel free to contribute!