Reports

New study examines current state of grid cybersecurity efforts

A new study by the Vermont Law School’s Institute for Energy and the Environment lays out the challenges of protecting the electric grid from cyberattacks and provides some methods that may hold the keys to future success.

The “Improving the Cybersecurity of the Electric Distribution Grid” study, funded by Florida-based nonprofit Protect Our Power, includes case studies of several states that detail ongoing challenges while also examining best practices for how state electric utility commissions and their regulated utilities can increase investments to enhance grid security.

“It is clear that action is needed to reduce the likelihood and impact of a cyberattack on the nation’s distribution grid, and this report provides concrete steps towards ensuring a more resilient grid,” said Mark James, project lead and assistant professor with the Vermont Law School. “Our research identifies pathways for utilities and utilities commissions to reduce existing barriers to investment and increase system resilience.”

The legally complex area of sharing sensitive data about cyber security between government, regulators and the utilities is also examined. The case studies include efforts underway in California, Connecticut, Michigan, Florida, New York, Kentucky, Illinois and Delaware. Regulatory and technological obstacles are also explored.

Some of the key findings include:

California
Pacific Gas and Electric Co. (PG&E), San Diego Gas & Electric Co. (SDG&E), and Southern California Edison formed a partnership with Lawrence Livermore National Laboratory (LLNL) and Idaho National Laboratory for a project focused on modeling and simulating cyber threats and possible responses. The program also sought to create physical test bed sites to evaluate the impacts of cyber threats on substation equipment.

Politics and budgeting narrowed the scope of the project that primarily focused its research on a Machine-to-Machine Automated Threat Response system. Much of the data that was generated was considered classified and inaccessible to the commission and its staff without security clearances.

Connecticut
Part of the state’s Comprehensive Energy Strategy includes the major utilities meeting with the Connecticut Public Utilities Regulatory Authority every year. The utilities are expected to report on their cyber defense programs, registered attacks on their systems, and corrective measures they will undertake in the following year.

The utilities chose a Department of Homeland Security-style Cybersecurity Capability Maturity Model reporting methodology. The utilities prefer this method to enhance communication over legislation, executive order, or regulatory mandate. To protect this information, the content of the meetings are confidential, with limited note taking and the information included in the annual report curated to reduce utility exposure.

Michigan
Cybersecurity was of keen interest to former Michigan Gov. Rick Snyder and his policies brought representatives from the utilities together in informal meetings. In 2014 the Michigan Public Service Commission (MPSC) instructed the two largest investor-owned utilities (IOUs) in the state, Consumers Energy and DTE Electric, to provide MPSC staff with annual reports addressing the utilities’ cybersecurity programs and attack prevention.

Following this move, the MPSC opened cases to address statewide annual reporting. From those cases, the Commission updated the Technical Standards for Electric Service to require annual written or oral reports from all IOUs and electric co-ops.

The reports must include details on cybersecurity operations and management, as well as an “overview of major investments in cybersecurity during the previous calendar year and plans and rationale for major investments in cybersecurity anticipated for the next calendar year.

Scott Sowers

Recent Posts

NERC makes recommendations for proactively meeting power challenges this summer

The power industry and policymakers should consider implementing several recommendations now to meet expected supply shortfalls prior to the start…

1 day ago

National Renewable Energy Lab uses robots to aid wind turbine blade manufacturing

Looking to cut down on the difficult nature of the work for humans and improve consistency of the outcome, the…

2 days ago

Switch to LED streetlights could save Sylvania, Ohio nearly $77,000 annually

Toledo Edison this month began a massive streetlight conversion project through Sylvania, Ohio, installing the first of 1,650 LED replacements.…

2 days ago

Southern Nuclear names new CEO and chairman

Peter Sena III has been named the new chairman and CEO of Southern Nuclear, a subsidiary of the Southern Company.…

2 days ago

Argonne National Lab to build R&D facility to test large-scale fuel cell systems

The U.S. Department of Energy’s (DOE) Argonne National Laboratory (ANL) is con structing a research and development (R&D) facility to…

2 days ago

Program that offers tax credits for wind and solar in low-income communities to launch soon

A program that provides a 10 or 20-percentage point boost to the investment tax credit for qualified solar or wind…

3 days ago

This website uses cookies.