Toronto Hydro online accounts hacked

By Toronto Star


Substation Relay Protection Training

Our customized live online or in‑person group training can be delivered to your staff at your location.

  • Live Online
  • 12 hours Instructor-led
  • Group Training Available
Regular Price:
$699
Coupon Price:
$599
Reserve Your Seat Today
Toronto police have launched an investigation after as many as 179,000 Toronto Hydro customer account numbers were illegally accessed in the company's electronic billing system.

Toronto Hydro says it contacted police after detecting atypical activity in its e-billing system. "We saw some unusual activity on our systems, and whenever there is more than the normal use of our system, the system shuts down and notifies IT staff," said David O'Brien, president and CEO of Toronto Hydro.

"What was being accessed was the file that contained the customer account number, their name and address. We're very confident it doesn't go deeper than that, no financial information was obtained," said O'Brien, who noted Hydro was concerned the information might be used to obtain credit card or personal information from customers.

"It's a total outrage when the provincial government has been paying lip service to fighting identity theft and a major public utility has exposed close to 200,000 people to that very sort of thing," said Peter Kormos, NDP consumer protection critic.

Ontario's Information and Privacy Commissioner Ann Cavoukian was notified of the breach and is investigating as well.

"The last bill(s) to 179,000 customers were accessed online," said Bob Spence, spokesman for the office of the Information and Privacy Commissioner. "Any time a privacy investigation is launched, we look at what happened and how it might be prevented."

O'Brien says Toronto Hydro will be sending a letter to each of its 685,000 customers, explaining about the privacy breach. It will not be telling customers if their account information was among those accessed, however.

"We're aware of the situation, and we'll be monitoring developments," said Eric Pelletier, a spokesman for the Ministry of Energy and Infrastructure.

Related News

Worker injured after GE turbine collapse

GE Wind Turbine Collapse Brazil raises safety concerns at Omega Energia's Delta VI wind farm in Maranhe3o, with GE Renewable Energy probing root-cause of turbine failure after a worker injury and similar incidents in 2024.

 

Key Points

An SEO focus on the Brazil GE turbine collapse, its causes, safety investigation, and related 2024 incidents.

✅ Incident at Omega Energia's Delta VI, Maranhao; one worker injured

✅ GE Renewable Energy conducts root-cause investigation and containment

✅ Fifth GE turbine collapse in 2024 across Brazil and the United States

 

A GE Renewable Energy turbine collapsed at a wind farm in north-east Brazil, injuring a worker and sparking a probe into the fifth such incident this year, the manufacturer confirmed.

One of the manufacturer’s GE 2.72-116 turbines collapsed at Omega Energia’s Delta VI project in Maranhão, which was commissioned in 2018.

Three GE employees were on site at the time of the collapse on Tuesday (3 September), the US manufacturer confirmed, even as U.S. offshore wind developers signal growing competitiveness with gas. 

One worker was injured and is currently receiving medical treatment, GE added.

"We are working to determine the root cause of this incident and to provide proper support as needed," it said

The turbine collapse in Brazil is the fifth such incident involving GE turbines this year, even as the UK's biggest offshore windfarm begins power supply this week, underscoring broader sector momentum.

On 16 February, a turbine collapsed at NextEra Energy Resources’ Casa Mesa wind farm in New Mexico, US, while giant wind components were being transported to a project in Saskatchewan, Canada. The site uses GE’s 2.3-116 and 2.5-127 models.

The New Mexico incident was followed by another collapse in the US — as a Scottish North Sea wind farm resumed construction after Covid-19 — this time a GE 2.4-107 unit at Tradewind Energy’s Chisholm View 2 project in Oklahoma on 21 May.

Two GE turbines then collapsed at projects in July: a 2.5-116 unit at Invenergy’s Upstreamwind farm in Nebraska on 5 July, followed by a 1.7-103 model at the Actis Group-owned Ventos de São Clemente complex in Pernambuco, north-eastern Brazil, even as tidal power in Scotland generated enough electricity to power nearly 4,000 homes.

No employees were injured in the first four turbine collapses of the year, in contrast with concerns at a Hawaii geothermal plant over potential meltdown risk.

In response to the latest incident, GE Renewable Energy added: "It is too early to speculate about the root cause of this week’s turbine collapse.

"Based on our learnings from the previous turbine collapses, we have teams in place focused on containing and resolving these issues quickly, to ensure the safe and reliable operation of our turbines."

 

Related News

View more

"Everything Electric" Returns to Vancouver

Everything Electric Vancouver spotlights EV innovation, electric vehicles, charging infrastructure, battery technology, autonomous driving, and sustainability, with test drives, consumer education, and incentives accelerating mainstream adoption and shaping the future of clean transportation.

 

Key Points

Everything Electric Vancouver is a premier EV expo for vehicles, charging tech, and clean mobility solutions.

✅ New EV models: better range, battery tech, autonomous features

✅ Focus on charging networks: ultra-fast and home solutions

✅ Consumer education: test drives, incentives, ownership costs

 

Vancouver has once again become the epicenter of electric vehicle (EV) innovation with the return of the "Everything Electric" event. This prominent showcase, as reported by Driving.ca, highlights the accelerating shift towards electric mobility, echoing momentum seen at the Quebec Electric Vehicle Show and the growing role of EVs in shaping the future of transportation. The event, held at the Vancouver Convention Centre, provided a comprehensive look at the latest advancements in electric vehicles, infrastructure, and technologies, drawing attention from industry experts, enthusiasts, and consumers alike.

A Showcase of Electric Mobility

"Everything Electric" has established itself as a key platform for unveiling new electric vehicles and technologies. This year’s event was no exception, featuring a diverse range of electric vehicles from leading manufacturers. Attendees had the opportunity to explore a wide array of models, from sleek sports cars and luxury sedans to practical SUVs and compact city cars. The showcase underscored the significant progress in EV design, performance, and affordability, reflecting a broader trend towards mainstream adoption of electric mobility.

One of the highlights of this year’s event was the unveiling of several cutting-edge electric models. Automakers used the platform to debut their latest innovations, including enhanced battery technologies, improved range capabilities, and advanced autonomous driving features. This not only demonstrated the rapid evolution of electric vehicles but also underscored the commitment of the automotive industry to addressing environmental concerns and meeting consumer demands for sustainable transportation solutions.

Expanding Charging Infrastructure

Beyond showcasing vehicles, "Everything Electric" also emphasized the critical role of charging infrastructure in supporting the growth of electric mobility. The event featured exhibits on the latest developments in charging technology, including ultra-fast chargers, innovative home charging solutions, and corridor networks such as B.C.'s Electric Highway that connect communities. With the increasing number of electric vehicles on the road, expanding and improving charging infrastructure is essential for ensuring convenience and reducing range anxiety among EV owners.

Industry experts and policymakers discussed strategies for accelerating the deployment of charging stations and integrating them into urban planning, while considering the B.C. Hydro bottleneck projections as demand grows. The event highlighted initiatives aimed at expanding public charging networks, particularly in underserved areas, and improving the overall user experience. As electric vehicles become more prevalent, the development of a robust and accessible charging infrastructure will be crucial for supporting their widespread adoption.

Driving Innovation and Sustainability

"Everything Electric" also served as a platform for discussions on the broader impact of electric vehicles on sustainability and innovation. Panels and presentations explored topics such as the environmental benefits of reducing greenhouse gas emissions, the role of renewable energy in powering EVs, insights from the evolution of U.S. EV charging infrastructure, and advancements in battery recycling and second-life applications. The event underscored the interconnected nature of electric mobility and sustainability, highlighting how innovations in one area can drive progress in others.

The emphasis on sustainability was evident throughout the event, with many exhibitors showcasing eco-friendly technologies and practices. From energy-efficient manufacturing processes to sustainable materials used in vehicle interiors, the event highlighted the automotive industry's efforts to reduce its environmental footprint and contribute to a more sustainable future.

Consumer Engagement and Education

A key aspect of "Everything Electric" was its focus on consumer engagement and education. The event offered test drives and interactive demonstrations, mirroring interest at the Regina EV event as well, allowing attendees to experience firsthand the benefits and performance of electric vehicles. This hands-on approach helped demystify electric mobility for many consumers and provided valuable insights into the practical aspects of owning and operating an EV.

In addition to vehicle demonstrations, the event featured workshops and informational sessions on topics such as EV financing, government incentives, and the benefits of transitioning to electric vehicles, reflecting how EVs in southern Alberta are a growing topic today. These educational opportunities were designed to empower consumers with the knowledge they need to make informed decisions about adopting electric mobility.

Looking Ahead

The successful return of "Everything Electric" to Vancouver highlights the growing importance of electric vehicles in the automotive landscape. As the event demonstrated, the electric vehicle market is rapidly evolving, with new technologies and innovations driving progress towards a more sustainable future. The increased focus on charging infrastructure, sustainability, and consumer education reflects a comprehensive approach to supporting the transition to electric mobility, exemplified by B.C.'s charging expansion across the province.

As Canada continues to advance its climate goals and promote sustainable transportation, events like "Everything Electric" play a crucial role in showcasing the possibilities and driving forward the adoption of electric vehicles. With ongoing advancements and increased consumer interest, the future of electric mobility in Vancouver and beyond looks increasingly promising.

 

Related News

View more

New England Emergency fuel stock to cost millions

Inventoried Energy Program pays ISO-NE generators for fuel security to boost winter reliability, with FERC approval, covering fossil, nuclear, hydropower, and batteries, complementing capacity markets to enhance grid resilience during severe cold snaps.

 

Key Points

ISO-NE program paying generators to hold fuel or energy reserves for emergencies, boosting winter reliability.

✅ FERC-approved stopgap for 2023 and 2024 winter seasons

✅ Pays for on-site fuel or stored energy during cold-trigger events

✅ Open to fossil, nuclear, hydro, batteries; limited gas participation

 

Electricity ratepayers in New England will pay tens of millions of dollars to fossil fuel and nuclear power plants later this decade under a program that proponents say is needed to keep the lights on during severe winters but which critics call a subsidy with little benefit to consumers or the grid, even as Connecticut is pushing a market overhaul across the region.

Last week the Federal Energy Regulatory Commission said ISO-New England, which runs the six-state power grid, can create what it calls the Inventoried Energy Program or IEP. This basically will pay certain power plants to stockpile of fuel for use in emergencies during two upcoming winters as longer-term solutions are developed.

The federal commission called it a reasonable short-term solution to avoid brownouts which doesn’t favor any given technology.

Not all agree, however, including FERC Commissioner Richard Glick, who wrote a fiery dissent to the other three commissioners.

“The program will hand out tens of millions of dollars to nuclear, coal and hydropower generators without any indication that those payments will cause the slightest change in those generators’ behavior,” Glick wrote. “Handing out money for nothing is a windfall, not a just and reasonable rate.”

The program is the latest reaction by ISO-NE to the winter of 2013-14 when New England almost saw brownouts because of a shortage of natural gas to create electricity during a pair of week-long deep freezes.

ISO-New England says the situation is more critical now because of the possible retirement of the gas-fired Mystic Generating Station in Massachusetts. As with closed nuclear plants such as Vermont Yankee and Pilgrim in Massachusetts, power plant owners say lower electricity prices, partly due to cheap renewables and partly to stagnant demand, means they can’t be profitable just by selling power.

Programs like the IEP are meant to subsidize such plants – “incentivize” is the industry term – even though some argue there is no need to subsidize nuclear in deregulated markets so they’ll stay open if they are needed.

The IEP approved last week will be applied to the winters of 2023 and 2024, after a different subsidy program expires. It sets prices, despite warnings about rushing pricing changes from industry groups, for stocking certain amounts of fuel and payments during any “trigger” event, defined as a day when the average of high and low temperatures at Bradley International Airport in Connecticut is no more than 17 degrees Fahrenheit.

These payments will be made on top of a complex system of grid auctions used to decide how much various plants get paid for generating electricity at which times.

ISO-NE estimates the new program will cost between $102 million and $148 million each winter, depending on weather and market conditions.

It says the payments are open to plants that burn oil, coal, nuclear fuel, wood chips or trash; utility-scale battery storage facilities; and hydropower dams “that store water in a pond or reservoir.” Natural gas plants can participate if they guarantee to have fuel available, but that seems less likely because of winter heating contracts.

A major complaint and groups that filed petitions opposing the project is that ISO-NE presented little supporting evidence of how prices, amount and overall cost were determined. ISO-NE argued that there wasn’t time for such analysis before the Mystic shutdown, and FERC agreed.

“The proposal is a step in the right direction … while ISO-NE finishes developing a long-term market solution,” the commission said in its ruling.

The program is the latest example of complexities facing the nation’s electricity system evolves in the face of solar and wind power, which produce electricity so cheaply that they can render traditional power uneconomic but which can’t always produce power on demand, prompting discussions of Texas grid improvements among policymakers. Another major factor is climate change, which has increased the pressure to support renewable alternatives to plants that burn fossil fuels, as well as stagnant electricity demand caused by increased efficiency.

Opponents, including many environmental groups, say electricity utilities and regulators are too quick to prop up existing systems, as the 145-mile Maine transmission line debate shows, built when electricity was sent one way from a few big plants to many customers. They argue that to combat climate change as well as limit cost, the emphasis must be on developing “non-wire alternatives” such as smart systems for controlling demand, in order to take advantage of the current system in which electricity goes two ways, such as from rooftop solar back into the grid.

 

Related News

View more

Bruce Power awards $914 million in manufacturing contracts

Bruce Power Major Component Replacement secures Ontario-made nuclear components via $914M contracts, supporting refurbishment, clean energy, low-cost electricity, and advanced manufacturing, extending reactor life to 2064 while boosting jobs, supply chain growth, and economy.

 

Key Points

A refurbishment program investing $914M in advanced manufacturing to extend reactors and deliver low-cost, clean power.

✅ $914M Ontario-made components for steam generators, tubes, fittings

✅ Extends reactor life to 2064; clean, low-cost electricity for Ontario

✅ Supports 22,000 jobs annually; boosts supply chain and economy

 

Today, Bruce Power signed $914 million in advanced manufacturing contracts for its Major Component Replacement, which gets underway in 2020, as the reactor refurbishment begins across the site and will allow the site to provide low-cost, carbon-free electricity to Ontario through 2064.

The Major Component Replacement (MCR) Project agreements include:

  • $642 million to BWXT Canada Inc. for the manufacturing of 32 steam generators to be produced at BWXT’s Cambridge facility.
  • $144 million to Laker Energy Products for end fittings, liners and flow elements, which will be manufactured at its Oakville location.
  • $62 million to Cameco Fuel Manufacturing, in Cobourg, for calandria tubes and annulus spacers for all six MCRs.
  • $66 million for Nu-Tech Precision Metals, in Arnprior, for the production of zirconium alloy pressure tubes for Units 6 and 3.

 

Bruce Power’s Life-Extension Program, which started in January 2016 with Asset Management Program investments and includes the MCRs on Units 3-8, remains on time and on budget.”

#google#

By signing these contracts today, we have secured ‘Made in Ontario‘ solutions for the components we will need to successfully complete our MCR Projects, extending the life of our site to 2064,” said Mike Rencheck, Bruce Power’s President and CEO.

“Today’s announcements represent a $914 million investment in Ontario’s highly skilled workforce, which will create untold economic opportunities for the communities in which they operate for many years to come.”We look forward to growing our already excellent relationships with these supplier partners and unions as we work toward our common goal, supported by an operating record, of continuing to keep Canada’s largest infrastructure project on time and on budget."

By extending the life of Bruce Power’s reactors to 2064, the company will create and sustain 22,000 jobs annually, both directly and indirectly, across Ontario, while investing $4 billion a year into the province’s economy, underscoring the economic benefits of nuclear development across Canada.

At the same time, Bruce Power will produce 30 per cent of Ontario’s electricity at 30 per cent less than the average cost to generate residential power, while also producing zero carbon emissions, aligning with Pickering NGS life extensions across the province.The Hon. Glenn Thibeault, Minister of Energy, said today’s announcement is good news for the people of Ontario.”

Bruce Power’s Life-Extension Program makes sense for Ontario, and the announcements made today will create good jobs and benefit our economy for decades to come,” Minister Thibeault said.

“Moving forward with the refurbishment project is part of our government’s plan to support care and opportunity, while producing affordable, reliable and clean energy for the people of Ontario.”Kim Rudd, Parliamentary Secretary to the Minister of Natural Resources and MP for Northumberland-Peterborough South, offered her support and congratulations.”

Related planning includes Bruce C project exploration funding that supports long-term nuclear options in Ontario.

Canada’s nuclear industry, including its advanced manufacturing capability, is respected internationally,” Rudd said. “Bruce Power’s announcement today related to the advanced manufacturing of key components throughout Ontario as part of its Life-Extension Program will allow these suppliers to have a secure base to not only meet Canada’s needs, but export internationally.”

 

Related News

View more

How waves could power a clean energy future

Wave Energy Converters can deliver marine power to the grid, with DOE-backed PacWave enabling offshore testing, robust designs, and renewable electricity from oscillating waves to decarbonize coastal communities and replace diesel in remote regions.

 

Key Points

Wave energy converters are devices that transform waves' oscillatory motion into electricity for the grid or loads.

✅ DOE's PacWave enables full-scale, grid-connected offshore testing.

✅ Multiple designs convert oscillating motion into torque and power.

✅ Ideal for islands, microgrids, and replacing diesel generation.

 

Waves off the coast of the U.S. could generate 2.64 trillion kilowatt hours of electricity per year — that’s about 64% of last year’s total utility-scale electricity generation in the U.S. We won’t need that much, but one day experts do hope that wave energy will comprise about 10-20% of our electricity mix, alongside other marine energy technologies under development today.

“Wave power is really the last missing piece to help us to transition to 100% renewables, ” said Marcus Lehmann, co-founder and CEO of CalWave Power Technologies, one of a number of promising startups focused on building wave energy converters.

But while scientists have long understood the power of waves, it’s proven difficult to build machines that can harness that energy, due to the violent movement and corrosive nature of the ocean, combined with the complex motion of waves themselves, even as a recent wave and tidal market analysis highlights steady advances.

″Winds and currents, they go in one direction. It’s very easy to spin a turbine or a windmill when you’ve got linear movement. The waves really aren’t linear. They’re oscillating. And so we have to be able to turn this oscillatory energy into some sort of catchable form,” said Burke Hales, professor of cceanography at Oregon State University and chief scientist at PacWave, a Department of Energy-funded wave energy test site off the Oregon Coast. Currently under construction, PacWave is set to become the nation’s first full-scale, grid-connected test facility for these technologies, a milestone that parallels U.K. wind power lessons on scaling new industries, when it comes online in the next few years.

“PacWave really represents for us an opportunity to address one of the most critical barriers to enabling wave energy, and that’s getting devices into the open ocean,” said Jennifer Garson, Director of the Water Power Technologies Office at the U.S. Department of Energy.

At the beginning of the year, the DOE announced $25 million in funding for eight wave energy projects to test their technology at PacWave, as offshore wind forecasts underscore the growing investor interest in ocean-based energy. We spoke with a number of these companies, which all have different approaches to turning the oscillatory motion of the waves into electrical power.

Different approaches
Of the eight projects, Bay Area-based CalWave received the largest amount, $7.5 million. 

″The device we’re testing at PacWave will be a larger version of this,” said Lehmann. The x800, our megawatt-class system, produces enough power to power about 3,000 households.”

CalWave’s device operates completely below the surface of the water, and as waves rise and fall, surge forward and backward, and the water moves in a circular motion, the device moves too. Dampers inside the device slow down that motion and convert it into torque, which drives a generator to produce electricity, a principle mirrored in some wind energy kite systems as they harvest aerodynamic forces.

“And so the waves move the system up and down. And every time it moves down, we can generate power, and then the waves bring it back up. And so that oscillating motion, we can turn into electricity just like a wind turbine,” said Lehmann.

Another approach is being piloted by Seattle-based Oscilla Power, which was awarded $1.8 million from the DOE, and is getting ready to deploy its wave energy converter off the coast of Hawaii, at the U.S. Navy Wave Energy Test site.

Oscilla Power’s device is composed of two parts. One part floats on the surface and moves with the waves in all directions — up and down, side to side and rotationally. This float is connected to a large, ring-shaped structure which hangs below the surface, and is designed to stay relatively steady, much like how underwater kites leverage a stable reference to generate power. The difference in motion between the float and the ring generates force on the connecting lines, which is used to rotate a gearbox to drive a generator.

″The system that we’re deploying in Hawaii is what we call the Triton-C. This is a community-scale system,” said Balky Nair, CEO of Oscilla Power. “It’s about a third of the size of our flagship product. It’s designed to be 100 kilowatt rated, and it’s designed for islands and small communities.”

Nair is excited by wave energy’s potential to generate electricity in remote regions, which currently rely on expensive and polluting diesel imports to meet their energy needs when other renewables aren’t available, and similar tidal energy for remote communities efforts in Canada point to viable models. Before wave energy is adopted at-scale, many believe we’ll see wave energy replacing diesel generators in off-the-grid communities.

A third company, C-Power, based in Charlottesville, Virginia, was awarded more than $4 million to test its grid-scale wave energy converter at PacWave. But first, the company wants to commercialize its smaller scale system, the SeaRAY, which is designed for lower-power applications. 

″Think about sensors in the ocean, research, metocean data gathering, maybe it’s monitoring or inspection,” said C-Power CEO Reenst Lesemann on the initial applications of his device.

The SeaRAY consists of two floats and a central body, the nacelle, which contains the drivetrain. As waves pass by, the floats bob up and down, rotating about the nacelle and turning their own respective gearboxes which power the electric generators.

Eventually, C-Power plans to scale up its SeaRAY so that it’s capable of satellite communications and deep water deployments, before building a larger system, called the StingRAY, for terrestrial electricity generation.

Meanwhile, one Swedish company, Eco Wave Power, is taking another approach completely, eschewing offshore technologies in favor of simpler wave power devices that can be installed on breakwaters, piers, and jetties.

“All the expensive conversion machinery, instead of being inside the floaters like in the competing technologies, is on land just like a regular power station. So basically this enables a very low installation, operation, and maintenance cost,” explained CEO Inna Braverman.

 

Related News

View more

Purdue: As Ransomware Attacks Increase, New Algorithm May Help Prevent Power Blackouts

Infrastructure Security Algorithm prioritizes cyber defense for power grids and critical infrastructure, mitigating ransomware, blackout risks, and cascading failures by guiding utilities, regulators, and cyber insurers on optimal security investment allocation.

 

Key Points

An algorithm that optimizes security spending to cut ransomware and blackout risks across critical infrastructure.

✅ Guides utilities on optimal security allocation

✅ Uses incentives to correct human risk biases

✅ Prioritizes assets to prevent cascading outages

 

Millions of people could suddenly lose electricity if a ransomware attack just slightly tweaked energy flow onto the U.S. power grid, as past US utility intrusions have shown.

No single power utility company has enough resources to protect the entire grid, but maybe all 3,000 of the grid's utilities could fill in the most crucial security gaps if there were a map showing where to prioritize their security investments.

Purdue University researchers have developed an algorithm to create that map. Using this tool, regulatory authorities or cyber insurance companies could establish a framework for protecting the U.S. power grid that guides the security investments of power utility companies to parts of the grid at greatest risk of causing a blackout if hacked.

Power grids are a type of critical infrastructure, which is any network - whether physical like water systems or virtual like health care record keeping - considered essential to a country's function and safety. The biggest ransomware attacks in history have happened in the past year, affecting most sectors of critical infrastructure in the U.S. such as grain distribution systems in the food and agriculture sector and the Colonial Pipeline, which carries fuel throughout the East Coast, prompting increased military preparation for grid hacks in the U.S.

With this trend in mind, Purdue researchers evaluated the algorithm in the context of various types of critical infrastructure in addition to the power sector, including electricity-sector IoT devices that interface with grid operations. The goal is that the algorithm would help secure any large and complex infrastructure system against cyberattacks.

"Multiple companies own different parts of infrastructure. When ransomware hits, it affects lots of different pieces of technology owned by different providers, so that's what makes ransomware a problem at the state, national and even global level," said Saurabh Bagchi, a professor in the Elmore Family School of Electrical and Computer Engineering and Center for Education and Research in Information Assurance and Security at Purdue. "When you are investing security money on large-scale infrastructures, bad investment decisions can mean your power grid goes out, or your telecommunications network goes out for a few days."

Protecting infrastructure from hacks by improving security investment decisions

The researchers tested the algorithm in simulations of previously reported hacks to four infrastructure systems: a smart grid, industrial control system, e-commerce platform and web-based telecommunications network. They found that use of this algorithm results in the most optimal allocation of security investments for reducing the impact of a cyberattack.

The team's findings appear in a paper presented at this year's IEEE Symposium on Security and Privacy, the premier conference in the area of computer security. The team comprises Purdue professors Shreyas Sundaram and Timothy Cason and former PhD students Mustafa Abdallah and Daniel Woods.

"No one has an infinite security budget. You must decide how much to invest in each of your assets so that you gain a bump in the security of the overall system," Bagchi said.

The power grid, for example, is so interconnected that the security decisions of one power utility company can greatly impact the operations of other electrical plants. If the computers controlling one area's generators don't have adequate security protection, as seen when Russian hackers accessed control rooms at U.S. utilities, then a hack to those computers would disrupt energy flow to another area's generators, forcing them to shut down.

Since not all of the grid's utilities have the same security budget, it can be hard to ensure that critical points of entry to the grid's controls get the most investment in security protection.

The algorithm that Purdue researchers developed would incentivize each security decision maker to allocate security investments in a way that limits the cumulative damage a ransomware attack could cause. An attack on a single generator, for instance, would have less impact than an attack on the controls for a network of generators, which sophisticated grid-disruption malware can target at scale, rather than for the protection of a single generator.

Building an algorithm that considers the effects of human behavior

Bagchi's research shows how to increase cybersecurity in ways that address the interconnected nature of critical infrastructure but don't require an overhaul of the entire infrastructure system to be implemented.

As director of Purdue's Center for Resilient Infrastructures, Systems, and Processes, Bagchi has worked with the U.S. Department of Defense, Northrop Grumman Corp., Intel Corp., Adobe Inc., Google LLC and IBM Corp. on adopting solutions from his research. Bagchi's work has revealed the advantages of establishing an automatic response to attacks, and analyses like Symantec's Dragonfly report highlight energy-sector risks, leading to key innovations against ransomware threats, such as more effective ways to make decisions about backing up data.

There's a compelling reason why incentivizing good security decisions would work, Bagchi said. He and his team designed the algorithm based on findings from the field of behavioral economics, which studies how people make decisions with money.

"Before our work, not much computer security research had been done on how behaviors and biases affect the best defense mechanisms in a system. That's partly because humans are terrible at evaluating risk and an algorithm doesn't have any human biases," Bagchi said. "But for any system of reasonable complexity, decisions about security investments are almost always made with humans in the loop. For our algorithm, we explicitly consider the fact that different participants in an infrastructure system have different biases."

To develop the algorithm, Bagchi's team started by playing a game. They ran a series of experiments analyzing how groups of students chose to protect fake assets with fake investments. As in past studies in behavioral economics, they found that most study participants guessed poorly which assets were the most valuable and should be protected from security attacks. Most study participants also tended to spread out their investments instead of allocating them to one asset even when they were told which asset is the most vulnerable to an attack.

Using these findings, the researchers designed an algorithm that could work two ways: Either security decision makers pay a tax or fine when they make decisions that are less than optimal for the overall security of the system, or security decision makers receive a payment for investing in the most optimal manner.

"Right now, fines are levied as a reactive measure if there is a security incident. Fines or taxes don't have any relationship to the security investments or data of the different operators in critical infrastructure," Bagchi said.

In the researchers' simulations of real-world infrastructure systems, the algorithm successfully minimized the likelihood of losing assets to an attack that would decrease the overall security of the infrastructure system.

Bagchi's research group is working to make the algorithm more scalable and able to adapt to an attacker who may make multiple attempts to hack into a system. The researchers' work on the algorithm is funded by the National Science Foundation, the Wabash Heartland Innovation Network and the Army Research Lab.

Cybersecurity is an area of focus through Purdue's Next Moves, a set of initiatives that works to address some of the greatest technology challenges facing the U.S. Purdue's cybersecurity experts offer insights and assistance to improve the protection of power plants, electrical grids and other critical infrastructure.

 

Related News

View more

Sign Up for Electricity Forum’s Newsletter

Stay informed with our FREE Newsletter — get the latest news, breakthrough technologies, and expert insights, delivered straight to your inbox.

Electricity Today T&D Magazine Subscribe for FREE

Stay informed with the latest T&D policies and technologies.
  • Timely insights from industry experts
  • Practical solutions T&D engineers
  • Free access to every issue

Download the 2025 Electrical Training Catalog

Explore 50+ live, expert-led electrical training courses –

  • Interactive
  • Flexible
  • CEU-cerified