Showing posts with label Grid Security. Show all posts
Showing posts with label Grid Security. Show all posts

Saturday, August 15, 2026

Review - S 5313 Introduced – FERC Quantum Cybersecurity

Last week, Sen Coons (D,DE) introduced S 5313, the Quantum Grid Utility Assurance and Resilient Defense (Quantum-GUARD) Act of 2026. The bill would require the Federal Energy Regulatory Commission (FERC) to consider cybersecurity risks from quantum computers in any future reliability-standards setting actions. It would also require DOE to establish a PQC sandbox. No new funding is authorized by this legislation. 

Moving Forward  

Neither Coons, nor his sole cosponsor {Sen Rounds (R,SD)} are members of the Senate Energy and Natural Resources Committee to which this bill was assigned for consideration. This means that there will not likely be sufficient influence to see the bill considered by the Committee. I see nothing in the language that would engender organized opposition. I suspect that there would be some level of bipartisan support for the bill. Unfortunately, this bill is not politically significant enough to justify the time necessary to consider it under regular order, especially in the short time left in the 119th Congress. 

Commentary  

This bill is not normally something that would be considered in this blog. But, having said that, I am interested in the definition of the term ‘operational technology’ proposed in Section 2. While S 5313 is targeted at control of the electric grid, the crafters of this definition felt it necessary to specifically include “industrial control systems, building management systems, fire control systems, and physical access control mechanisms” in the definition. It is almost as if they were intending to use this bill to establish this definition in US Code for some reason. I do not think that that is likely to happen with this bill, but the definition is almost good enough to be a broadly applicable cybersecurity definition. 


For more information on the provisions of this legislation, including providing changes to the OT definintion to make it more broadly applicable, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/s-5313-introduced-ferc-quantum-cybersecurity - subscription required. A copy will be emailed to free subscribers tomorrow. 

Wednesday, July 1, 2026

Review - S 4166 Introduced – State Grid Security Plans

Back in March, Sen Cortez-Masto (D,NV) introduced S 4166, the Securing Community Upgrades for a Resilient (SECURE) Grid Act. The bill would amend 42 USC 6326 to require States to include local distribution systems in their State Energy Security Plans described in that section. No new funding is authorized by this legislation. 

This bill is very similar to HR 7257 that was passed in the House this week. Most of the differences between the two bills are editorial changes in format. The one significant change is that S 4166 lacks the definition of the term ‘State Energy Security Plan’ found in subsection 3(c) of HR 7257. 

Moving Forward  

Cortez-Masto, and one of her two cosponsors {Sen Murkowski (R,AK)} are members of the Senate Energy and Natural Resources Committee to which this bill was assigned for consideration. This means that there may be sufficient influence to see the bill considered by the Committee. As was seen in the House, I would expect that the bill would receive significant bipartisan support if it were considered. 

If this bill was brought to the floor of the Senate for consideration, probably under the unanimous consent process, it would be as substitute language for HR 7257. The language from the Senate bill could also be added to the EWR spending bill, if/when that bill makes it to the floor of the Senate. 


For more information on the provisions of this bill, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/publish/posts/detail/204440771/share-center - subscription required. 

Tuesday, June 30, 2026

HR 7257 Passed in House – State Energy Security

Yesterday, the House took up HR 7257, the Securing Community Upgrades for a Resilient (SECURE) Grid Act, under the suspension of the rules process. After nine minutes of debate, the bill passed by voice vote. The bill would amend 42 USC 6326 to require States to include local distribution systems in their State Energy Security Plans described in that section. No new funding is authorized by this legislation.

The legislation now moves to the Senate where it is unlikely to be considered under regular order. The voice vote in the House would seem to indicate that it would be a potential candidate for consideration under the Senate’s unanimous consent process. 

Tuesday, June 16, 2026

Review - HR 7696 Introduced – Grid Scale Testbed

Back in February, Resident Commissioner Hernandez (D,PR) introduced HR 7696, the AI Cyber Grid Protection Resilient Development Act of 2026. The bill would require CISA and DHS to establish a grant program to develop secure artificial intelligence (AI) cyber-physical testbeds to simulate grid-scale cyberattacks and train AI models safely. The bill would authorize $100 million per year through 2030 to fund the program. 

Moving Forward  

Hernandez is a member of the House Homeland Security Committee to which this bill was assigned for consideration. This means that there may be sufficient influence to see the bill considered by the Committee. There will be substantial opposition to the amount of new funding authorized by this bill. More importantly, the Chair of the House Energy and Commerce Committee will probably oppose this bill because it does not include that Committee in the consideration of what is at base an energy program. This is especially true since the Lawrence Livermore National Laboratory, in conjunction with DOE’s Office of Cybersecurity, Energy Security, and Emergency Response (CESER), is already funding the Mjölnir AI Testbed which is already addressing these issues. 


For more information on the provisions of this bill, including a commentary suggesting cybersecurity requirements for the cyber-physical testbeds, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/hr-7696-introduced-grid-scale-testbed - subscription required. 

Tuesday, February 17, 2026

Review – HR 7257 Introduced – State Energy Plans

Last month Rep Latta (R,OH) introduced HR 7257, the Securing Community Upgrades for a Resilient (SECURE) Grid Act. The bill would amend 42 USC 6326 to require States to include local distribution systems in their State Energy Security Plans described in that section. No new funding is authorized by this legislation.

The bill is similar to HR 9083 that was introduced by Latta in July 2024. No action was taken on that bill in the 118th Congress. While similar in intent, HR 7257 is a substantial rewrite. Some of the changes of interest include:

Modifying the proposed definition of the term ‘local distribution systems’ by increasing the maximum voltage from 35 kilovolts to 100 kilovolts,

Removing the proposed language being added to (b)(2)(B) referencing “energy supply disruptions resulting from increased demand on the electric grid, deteriorating assets [emphasis added], and physical and cybersecurity threats”, and

Removing from the proposed language revision in (b)(3) reference to “risks and liabilities posed by human error or mismanagement”.

Moving Forward

Latta and his two cosponsors are members of the House Energy and Commerce Committee to which this bill was assigned for consideration. This means that there could be sufficient influence to see this bill considered in Committee. I see nothing in this bill that would engender any organized opposition. I suspect that there will be some level of bipartisan support for this bill in Committee. Whether that support would be sufficient to see the bill considered in the Full House under the suspension of the rules remains to be seen.

 

For more information on the provisions of this bill, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/hr-7257-introduced-state-energy-plans - subscription required.

Monday, December 1, 2025

Review – Committee Hearings – Week of 11-30-25

With both the House and Senate back from their Thanksgiving break, there is a moderately busy hearing schedule. Of interest here are two fact-finding hearings on grid security and communications security. There are also two Space Geek hearings.

Grid Security

On Tuesday the Subcommittee on Energy of the House Energy and Commerce Committee will hold a hearing on “Securing America’s Energy Infrastructure: Addressing Cyber and Physical Threats to the Grid”.

Communications Security

On Tuesday the Subcommittee on Telecommunications and Media of the Senate Commerce, Science, and Transportation Committee will hold a hearing on “Signal Under Siege: Defending America’s Communications Networks”.

Space Geek Hearings

On Wednesday the Senate Commerce, Science, and Transportation Committee will hold a nomination hearing  that will bring Jared Isaacman back before the Committee for his renomination to be NASA Administrator.

On Thursday the Subcommittee on Space and Aeronautics of the House Science, Space, and Technology Committee will hold a hearing on “Strategic Trajectories: Assessing China’s Space Rise and the Risks to U.S. Leadership”.

 

For more information on these hearings, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/committee-hearings-week-of-11-30 - subscription required.

Monday, November 3, 2025

Reader Comment – Advisory Windows

This weekend a reader over on Substack, Robots and Chips,  left three comments (here, here, and here) on two of my blog posts (here and here) about CISA vulnerability advisories. They draw some interesting conclusions about how these vulnerabilities provide a window into cybersecurity problems with the energy sector. While I generally try to avoid drawing general conclusions from isolated advisories, the insights here deserve consideration and discussion.

I would, however, like to make one observation; I have seen very few of these energy sector related vulnerabilities show up in CISA’s Known Exploited Vulnerabilities catalog. That may just be a reporting anomaly (the KEV catalog is, after all, focused on problems potentially affecting federal systems), or a failure to report exploits by that sector, but I suspect that the overall cybersecurity posture of the major components of the electric grid may have something to do with that. But that is an outsider’s perspective, my knowledge of the grid does not extend much beyond being able to identify the GA Power distribution substation down at the end of my block.

Saturday, February 11, 2023

CRS Reports – Week of 2-24-23 – Grid Physical Security

This week the Congressional Research Service (CRS) published a report on “Electric Grid Physical Security: Recent Developments”. This is an update of the report originally reported on January 9th, 2023. It adds a brief mention of the February 6th arrest of “two individuals for planning to attack five electric power transmission substations around Baltimore, MD, allegedly as part of a “racially or ethnically motivated violent extremist” conspiracy.”

The new version adds a new, final sentence in the ‘Congressional Initiatives’ section of the report: “As CIP-014 implementation and other physical security initiatives proceed, Congress also may examine the power sector’s overall progress in securing its infrastructure, including organizational and structural changes supporting physical security as a corporate priority.” We can almost certainly expect congressional hearings in both the House and Senate on this topic.

Saturday, January 14, 2023

CRS Reports – 1-14-23 – Grid Security

This week the Congressional Research Service published a report on “Electric Grid Physical Security: Recent Developments”. It provides a brief overview of recent physical attacks on power distribution substations as well as a description of the current regulatory framework regarding physical security for grid facilities, specifically noting that electric distribution substations are not subject to federal regulation by FERC and NERC.

The important part of any CRS report is the discussion of options that Congress has for addressing the issues identified in the report. Here, CRS notes that:

“The 118th Congress may continue to be concerned about the state of electric grid physical security, including the security of grid infrastructure not currently subject to NERC’s existing security standards. Among many specific issues of potential interest, Congress may consider the evolving physical threat environment, oversight of physical security implementation, the relationship between federal and state grid security initiatives, and the cost-effectiveness of any future security requirements. Congress may also examine tradeoffs between investments to “harden” grid infrastructure (e.g., physical barriers) and investments to make the grid more resilient to physical attacks (e.g., additional transmission lines). As CIP-014 implementation and other physical security initiatives proceed, Congress also may be concerned about the power sector’s overall progress in securing its infrastructure, including organizational and structural changes supporting physical security as a corporate priority.”


Saturday, November 19, 2022

CRS Reports – Electric Power Transformers

This week the Congressional Research Service (CRS) published a report on “Electric Power Transformers: Supply Issues”. The report provides a relatively non-technical look at the use of electrical transformers in the bulk electric and electric distribution systems. It identifies potential shortages of both large power transformers used in the bulk power transmission system and smaller transformers used in distribution systems.

The report provides a discussion about recently passed bills that were supposed to reduce those supply impacts as well as a listing of legislation that has been introduced (but not yet passed) in the 117th Congress.

Saturday, March 12, 2022

HR 6779 Introduced – Transformer Resilience

Earlier this month, Rep Lamb (D,PA) introduced HR 6779, the Grid Resilience and Infrastructure Depot (GRID) Act of 2022. The bill would require DOE to establish a program to build a reserve of large transformers and other critical electric-grid equipment in order to be able to “restore electric grid function rapidly in the event of severe damage to the electric grid”. The bill would authorize $75 million per year through FY 2026 for the program.

Moving Forward

Neither Lamb, nor his sole cosponsor {Rep Gonzalez (R,OH)}, are members of the House Energy and Commerce Committee to which this bill was assigned for consideration. This means that the bill is unlikely to be considered in that Committee. Other than the funding, the only issue with this bill that might engender organized opposition would be the prevailing wage provisions that routinely draw significant Republican opposition. If the bill were considered in Committee, it would probably pass with some minor bipartisan support.

Saturday, November 6, 2021

CRS Reports - Evolving Electric Power Systems and Cybersecurity

This week the Congressional Research Service published “Evolving Electric Power Systems and Cybersecurity”. This report focuses on the current state of U.S. electric grid security, given recent cybersecurity events.

Topics covered in the report includes:

• Mandatory and Enforceable Critical Infrastructure Protection Standards,

• Electric Grid Threats and Vulnerabilities,

• Supply Chain Security and Risks,

• Changing Grid Technologies,

• Federal Actions and Programs to Assist Grid Security,

• Improving Cybersecurity of Distribution and Smaller Utilities,

• Additional Actions to Potentially Improve Grid Cybersecurity,

The report also briefly describes bills currently before Congress that address grid security issues.

Monday, September 13, 2021

Review - HR 5135 Introduced – GRID Act

Last month, Rep Crow (D,CO) introduced HR 5135, the Guaranteeing Resilient Installations for Defense (GRID) Act of 2021. The bill would require DOD to establish a pilot program to implement mitigating actions to address vulnerabilities assessed under 16 USC 824o-1 at critical defense facilities and their associated defense critical electric infrastructure.

Crow and one of his cosponsors {Rep Bacon (R,NE)} are both members of the House Armed Services Committee to which this bill was assigned consideration. Secondary consideration was assigned to the House Energy and Commerce Committee in which the second cosponsor {Rep Peters (D,CA)} is a member. This means that there may be adequate influence to see the bill considered in both Committees. I do not see anything in the bill that would engender any organized opposition. I suspect that there would be sufficient bipartisan support for this bill that, should it make it to the floor of the House for consideration, the bill should be considered under the suspension of the rules process.

Commentary

It is interesting that this bill requires DOD to “address vulnerabilities assessed under section 215A of the Federal Power Act (16 U.S.C. 824o–1)”. That section deals with providing DOE the authority to respond to a “grid security emergency” declared by the President. There is no language in that section that calls for an assessment of vulnerabilities, in fact, there is no use of the words ‘assessment’, ‘assess’, ‘vulnerability’ or ‘vulnerabilities’ in that section.

So, it strikes me that this bill is incomplete at best. It needs to define who is responsible for the ‘assessment of vulnerabilities’ and explain whether that assessment is solely related to a grid security emergency declared by the President.

For more details about the provisions in the bill, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/hr-4597-introduced-a93   - subscription required.

Friday, September 10, 2021

Review - HR 4939 Introduced - Grid Security Research and Development

Last month, Rep Bera (D,CA) introduced HR 4939, the Grid Security Research and Development Act. The bill would amend Title VIII, Division Z (the Energy Act of 2020) of the Consolidated Appropriations Act,  2021, inserting 9 new sections in that Title. To support the programs in those new sections the bill would authorize $371 million in FY 2022, increasing to $442 million in FY 2026. The new sections would be:

§8013. Energy sector security research, development, and demonstration program.

§8014. Grid resilience and emergency response.

§8015. Best practices and guidance documents for energy sector cybersecurity research.

§8016. Vulnerability testing and technical assistance to improve cybersecurity.

§8017. Cybersecurity education and workforce training research and standards.

§8018. Interagency coordination and strategic plan for energy sector cybersecurity research.

§8019. Report to Congress.

§8020. Critical infrastructure research and construction.

§8021. Definitions.

Bera and his single cosponsor {Rep Weber (R,TX)} are both members of the House Space, Science, and Technology Committee to which this bill was assigned for consideration. This means that there could be enough influence to see the bill considered in Committee. I suspect that there will be some level of bipartisan support for this bill, but I am not sure that it would be sufficient to allow the bill to move to the floor of the House under the suspension of the rules process. I doubt that there is enough solid support for this bill in the leadership to have the bill move to the floor under regular order.

For more detailed description of the programs outlined in this bill, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/hr-4939-introduced - subscription required.

Wednesday, May 13, 2020

Bills Introduced – 5-12-20


Yesterday with the Senate in town and the House meeting in pro forma session, there were 72 bills introduced. One of those bills will receive future coverage in this blog:

S 3688 A bill to amend the Federal Power Act to authorize the Federal Energy Regulatory Commission and the Secretary of Energy to offer assistance in securing the assets of the owners and operators of energy infrastructure against threats and increasing the security of the electric grid, and for other purposes. Sen. Murkowski, Lisa [R-AK]

I suspect that this bill may be an attempt to achieve at least a portion of what S 2657 was attempting to do in the area of grid security. That comprehensive energy security bill died on the floor of the Senate.

Sunday, May 3, 2020

EO 13920 Published – Protecting the Grid


The White House published EO 13920 in Monday’s (available online Saturday) Federal Register (85 FR 26595-26599) addressing “Securing the United States Bulk-Power System”. The EO provides the Secretary of Energy the authority to prohibit the use of foreign made electric equipment in the US bulk-power system.

To justify the authority, the EO explains that:

• The bulk-power system is a target of those seeking to commit malicious acts against the United States and its people; and
• The unrestricted acquisition or use in the United States of bulk-power system electric equipment designed, developed, manufactured, or supplied by persons owned by, controlled by, or subject to the jurisdiction or direction of foreign adversaries augments the ability of foreign adversaries to create and exploit vulnerabilities in bulk-power system electric equipment.

The President then states:

“I therefore determine that the unrestricted foreign supply of bulk-power system electric equipment constitutes an unusual and extraordinary threat to the national security, foreign policy, and economy of the United States, which has its source in whole or in substantial part outside the United States. This threat exists both in the case of individual acquisitions and when acquisitions are considered as a class. Although maintaining an open investment climate in bulk-power system electric equipment, and in the United States economy more generally, is important for the overall growth and prosperity of the United States, such openness must be balanced with the need to protect our Nation against a critical national security threat. To address this threat, additional steps are required to protect the security, integrity, and reliability of bulk-power system electric equipment used in the United States. In light of these findings, I hereby declare a national emergency with respect to the threat to the United States bulk-power system.”

Prohibitions


Section 1(a) of the EO prohibits “any acquisition, importation, transfer, or installation of any bulk-power system electric equipment” where the Secretary of Energy (in consultation with the Director of OMB) finds that “the transaction involves bulk-power system electric equipment designed, developed, manufactured, or supplied, by persons owned by, controlled by, or subject to the jurisdiction or direction of a foreign adversary” and the transaction:

• Poses an undue risk of sabotage to or subversion of the design, integrity, manufacturing, production, distribution, installation, operation, or maintenance of the bulk-power system in the United States;
• Poses an undue risk of catastrophic effects on the security or resiliency of United States critical infrastructure or the economy of the United States; or
• Otherwise poses an unacceptable risk to the national security of the United States or the security and safety of United States persons.

Designated Actions


Section 1(b) allows the Secretary to “design or negotiate measures to mitigate concerns identified under section 1(a)” and use such measures as a precondition to approvals of transactions that would otherwise be prohibited.

Section 2(a) authorizes the Secretary to:

• Direct the timing and manner of the cessation of pending and future transactions prohibited pursuant to section 1 of this order,
• Adopt appropriate rules and regulations, and
• Employing all other powers granted to the President by the International Emergency Economic Powers Act (50 USC 1701 et seq.; IEEPA) as may be necessary to implement this order.

Section 2(b) directs the Secretary to issue rules and regulations implementing this EO. Those would include rules or regulation that would:

• Determine that particular countries or persons are foreign adversaries exclusively for the purposes of this order;
• Identify persons owned by, controlled by, or subject to the jurisdiction or direction of foreign adversaries exclusively for the purposes of this order;
• Identify particular equipment or countries with respect to which transactions involving bulk-power system electric equipment warrant particular scrutiny under the provisions of this order;
• Establish procedures to license transactions otherwise prohibited pursuant to this order; and
• Identify a mechanism and relevant factors for the negotiation of agreements to mitigate concerns raised in connection with subsection 1(a) of this order.

Section 2(d)(i) directs the Secretary to “identify bulk-power system electric equipment designed, developed, manufactured, or supplied, by persons owned by, controlled by, or subject to the jurisdiction or direction of a foreign adversary that poses an undue risk of sabotage to or subversion of the design, integrity, manufacturing, production, distribution, installation, operation, or maintenance of the bulk-power system in the United States” that:

• Poses an undue risk of catastrophic effects on the security or resiliency of United States critical infrastructure or the economy of the United States, or
• Otherwise poses an unacceptable risk to the national security of the United States or the security and safety of United States persons.

Task Force Established


Section 3 establishes the Task Force on Federal Energy Infrastructure Procurement Policies Related to National Security. The Task Force will be chaired by the Secretary and include representatives from at least six listed federal agencies. The Task Force will:

• Develop a recommended consistent set of energy infrastructure procurement policies and procedures for agencies, to the extent consistent with law, to ensure that national security considerations are fully integrated across the Federal Government, and submit such recommendations to the Federal Acquisition Regulatory Council (FAR Council);
• Evaluate the methods and criteria used to incorporate national security considerations into energy security and cybersecurity policymaking;
• Consult with the Electricity Subsector Coordinating Council and the Oil and Natural Gas Subsector Coordinating Council in developing the recommendations and evaluation described in subsections (c)(i) through (ii) of this section; and
• Conduct any other studies, develop any other recommendations, and submit any such studies and recommendations to the President, as appropriate and as directed by the Secretary.

Definitions


Section 4 provides definitions for key terms used in this EO. The terms defined include:

• Bulk-power system,
• Bulk-power system electric equipment,
• Entity,
• Foreign adversary,
• Person,
• Procurement, and
• United States person

Most of these definitions are generic descriptions of standard regulatory terms. The interesting exception is the term ‘Bulk-power system electric equipment’. This definition starts off with a lengthy list of industrial power equipment that includes:

• Reactors,
• Capacitors,
• Substation transformers,
• Current coupling capacitors,
• Large generators,
• Backup generators,
• Substation voltage regulators,
• Shunt capacitor equipment,
• Automatic circuit reclosers,
• Instrument transformers,
• Coupling capacity voltage transformers,
• Protective relaying,
• Metering equipment,
• High voltage circuit breakers,
• Generation turbines,
• Industrial control systems,
• Distributed control systems, and
• Safety instrumented systems.

The definition then concludes by stating that: “Items not included in the preceding list and that have broader application of use beyond the bulk-power system are outside the scope of this order.” Thus, communications equipment, security software and access control systems, for example, could not be addressed under this Executive Order.

Commentary


It seems clear to me that this EO is primarily directed at limiting the spread of Chinese equipment in the bulk-power system; certainly the President is not concerned with US companies using equipment made in North Korea or Iran, or designed by Hezbollah. Unfortunately, failing to actually name the Chinese government as the intended foreign adversary paves the way for this EO to be used in a wide variety of trade disputes around the world.

It is particularly odd that the President is providing the Secretary of Energy with broad powers (employing all other powers granted to the President) under IEEPA. Those authorities include levying economic sanctions and taking control of foreign owned property and assets within the United States. Those authorities are typically limited to the State Department or Treasury Department. Providing blanket authority to the Secretary of Energy in this way greatly expands the reach of the Energy Department well beyond that defined by Congress.

One final oddity here, the distressing lack of discussion of cybersecurity issues. There is only a single mention of cybersecurity in the EO and that is in describing the duties of the Task Force; “evaluate the methods and criteria used to incorporate national security considerations into energy security and cybersecurity policymaking”. Certainly, a major portion of the perceived threat is via cyber attacks on components of the bulk-power systems. Failure to specifically require the Secretary to address those concerns in consultation with the Cybersecurity and Infrastructure Security Agency is a major oversight in this EO.

 
/* Use this with templates/template-twocol.html */