Cybersecurity vulnerabilities result from system integrity


NFPA 70E Training

Our customized live online or in‑person group training can be delivered to your staff at your location.

  • Live Online
  • 6 hours Instructor-led
  • Group Training Available
Regular Price:
$199
Coupon Price:
$149
Reserve Your Seat Today
Cybersecurity is a major threat to utilities' operations, said John Shaw, a senior vice president with Industrial Defender, at the Utilities Telecom Council's annual conference.

As a result, it is essential to protect the nation's electrical grid as rogue forces could use it as a weapon of mass destruction. However, Shaw doesn't believe that most security threats against the electrical grid stems from outside the nation. Instead, security breaches happen at a more practical level.

"It's about basic system integrity, malware coming in over the internet and getting on to a PC that's connected to a [utility's] control system," he said. "There's also just basic mistakes and human error."

In fact, Shaw said cybersecurity strategies should focus on deploying best practices and putting in efficient change control procedures to improve reliability, including adhering to the mandated NERC Standards CIP-002 through CIP-009 that provides a cybersecurity framework for the identification and protection of critical cyber assets.

"That's what security is about," he said. "Every time someone opens a connection they need to close it. It's also about keeping software and operating systems up to date. So we get into issues of data integrity when talking about cybersecurity."

In addition, wireless does not, in itself, make utilities more vulnerable to issues of cybersecurity, Shaw said. Although wireless does create some extent of openness, intrusion detection software protects networks. He said such defense-of-depth strategies are crucial and the use of layered security defenses in an application can reduce the chance of a successful attack. In addition, incorporating redundant security mechanisms requires an attacker to circumvent each mechanism to gain access to a digital asset. For example, a software system with authentication checks may prevent an attacker that has subverted a firewall.

Shaw said defending an application with multiple layers can prevent a single point of failure that compromises the security of the application.

"I don't think wireless by itself or decreases the threat but it does show the critical importance of having multiple layers of security," Shaw said. "In fact, just because [cyber attackers] can get through the physical access layer of wireless, and maybe get through that first encryption layer to a connection point, that should not give them very much power by itself."

Related News

Ontario Breaks Ground on First Small Modular Nuclear Reactor

Ontario SMR BWRX-300 leads Canada in next-gen nuclear energy at Darlington, with GE Vernova and…
View more

Hydro One: No cut in peak hydro rates yet for self-isolating customers

Hydro One COVID-19 Rate Relief responds to time-of-use pricing, peak rates, and Ontario Energy Board…
View more

Manitoba Hydro seeks unpaid days off to trim costs during pandemic

Manitoba Hydro unpaid leave plan offers unpaid days off to curb workforce costs amid COVID-19,…
View more

Hydro One, Avista to ask U.S. regulator to reconsider order against acquisition

Hydro One Avista Takeover faces Washington UTC scrutiny as regulators deny approval; companies plan a…
View more

No public details for Newfoundland electricity rate mitigation talks

Muskrat Falls rate mitigation progresses as Newfoundland and Labrador and Ottawa align under the updated…
View more

Britain breaks record for coal-free power generation - but what does this mean for your energy bills?

UK Coal-Free Electricity Record highlights rapid growth in renewables as National Grid phases out coal;…
View more

Sign Up for Electricity Forum’s Newsletter

Stay informed with our FREE Newsletter — get the latest news, breakthrough technologies, and expert insights, delivered straight to your inbox.

Electricity Today T&D Magazine Subscribe for FREE

Stay informed with the latest T&D policies and technologies.
  • Timely insights from industry experts
  • Practical solutions T&D engineers
  • Free access to every issue

Download the 2026 Electrical Training Catalog

Explore 50+ live, expert-led electrical training courses –

  • Interactive
  • Flexible
  • CEU-cerified