Power grid growing more vulnerable to cyber attacks, report finds


CSA Z462 Arc Flash Training – Electrical Safety Compliance Course

Our customized live online or in‑person group training can be delivered to your staff at your location.

  • Live Online
  • 6 hours Instructor-led
  • Group Training Available
Regular Price:
$249
Coupon Price:
$199
Reserve Your Seat Today

Power Grid Cybersecurity faces rising vulnerabilities as smart grid devices expand attack vectors, challenging FERC, NERC, DHS, and DOE standards; millions of connected meters and sensors heighten risk to critical infrastructure resilience.

 

Understanding the Story

Controls that protect electric generation, transmission, and distribution systems from evolving cyber threats.

  • Smart meters and sensors expand attack vectors at scale
  • Complexity grows with multi-vendor hardware and software
  • Standards by FERC, NERC, NIST, DHS, DOE still fragment
  • Prevention alone is insufficient; resilience is vital

 

America's electricity grid is a big, juicy target for cyberattacks – and it's getting more vulnerable as interactive \"smart grid\" features and other Internet-based connections are grafted onto an old, insecure system, a major new study reports.

 

Despite development of new cybersecurity standards, the electric utility industry is creating more new vulnerabilities than it is patching and, thus, losing ground to attackers, the Massachusetts Institute of Technology "Future of the Electric Grid" study found.

"Millions of new communicating electronic devices ... will introduce attack vectors – paths that attackers can use to gain access to computer systems or other communicating equipment," the report states. "That increase[s] the risk of intentional and accidental communications disruptions," including "loss of control over grid devices, loss of communications between grid entities or control centers, or blackouts."

Every new "smart meter," as well as new sensors and major equipment at generating plants, will soon be connected to communications modules – resulting in millions of components from hundreds of manufacturers and software from many developers and raising privacy and security risks for agencies.

The presence of "so many interfaced components increases system complexity as well as the number of potential cyber vulnerabilities," the study found.

Shoring up cybersecurity for the power grid would cost about $3.7 billion, a relatively small amount compared with the $476 billion that a "smart grid" upgrade could cost, according to a report earlier this year by the Electric Power Research Institute.

Even so, it is "difficult to make the business case" for cybersecurity investments because the probability of a devastating attack is so low. One problem: Regulations that mandate action often end up as a mere checklist for utilities – without actually improving security, because cyberthreats keep evolving.

Cybersecurity for the power grid is of concern to many. The Federal Energy Regulatory Commission FERC and North American Electric Reliability Corp. jointly oversee development of cybersecurity standards for power companies in the bulk power system. The National Institute of Standards and Technology is working on another set of standards. The Department of Homeland Security DHS and the Department of Energy DOE are weighing in, too.

In May, the White House offered its plan to put the grid in DHS hands. In July, a Senate bill proposed putting oversight authority with FERC and DOE after industry testimony underscored the need for greater cybersecurity legislation. Action could come in the Senate as soon as January.

None of these portend a single body with national regulatory oversight of cybersecurity standards – and not just for bulk power that is transmitted long distances over high-voltage lines, but also for local distribution systems, the MIT report notes.

"The federal government should designate a single agency to have responsibility for working with industry and to have appropriate regulatory authority to enhance cybersecurity preparedness, response, and recovery across the electric power sector, including bulk power and distribution systems," the study recommended.

The report regards cyberattacks as inevitable. Therefore, the US needs another specialized entity to conduct forensic investigations – something akin to the National Transportation Safety Board NTSB that, in the transportation world, swoops in to analyze the causes of accidents and recommends action, the study says.

Other experts endorse the findings.

"The report correctly concludes that the complexity and diversity of communications will make prevention an impossible task," writes Michael Assante, former chief security officer for NERC, in an e-mail. "It will be very important that the industry is able to learn from mistakes and near misses in order to best manage operational risk to the system. I fully support the concept of establishing a NTSB-like function with industry involvement that spans the entire system from Generation to Distribution."

 

Related News

Related News

FPL Proposes Significant Rate Hikes Over Four Years

FPL Rate Increase Proposal 2026-2029 outlines $9B base-rate hikes as Florida grows, citing residential demand,…
View more

Tunisia moves ahead with smart electricity grid

Tunisia Smart Grid Project advances with an AFD loan as STEG deploys smart meters in…
View more

Amazon launches new clean energy projects in US, UK

Amazon Renewable Energy Projects advance net zero goals with a Scotland wind farm PPA and…
View more

Peterborough Distribution sold to Hydro One for $105 million.

Peterborough Distribution Inc. Sale to Hydro One delivers a $105 million deal pending Ontario Energy…
View more

Sudbury Hydro crews aim to reconnect service after storm

Sudbury Microburst Power Outage strains hydro crews after straight-line winds; New Sudbury faces downed power…
View more

Diesel Prices Return to Pre-Ukrainian Conflict Levels

France Diesel Prices at Pre-Ukraine Levels reflect energy market stabilization as supply chains adapt and…
View more

Sign Up for Electricity Forum’s Newsletter

Stay informed with our FREE Newsletter — get the latest news, breakthrough technologies, and expert insights, delivered straight to your inbox.

Electricity Today T&D Magazine Subscribe for FREE

Stay informed with the latest T&D policies and technologies.
  • Timely insights from industry experts
  • Practical solutions T&D engineers
  • Free access to every issue

Live Online & In-person Group Training

Advantages To Instructor-Led Training – Instructor-Led Course, Customized Training, Multiple Locations, Economical, CEU Credits, Course Discounts.

Request For Quotation

Whether you would prefer Live Online or In-Person instruction, our electrical training courses can be tailored to meet your company's specific requirements and delivered to your employees in one location or at various locations.