Furthermore, distributed and process-aware IDS allow to further strengthen security in interconnected power grids. An IDS in a PCN can, therefore, be much more restrictive without affecting operations than in an office network, where a large number of protocols and devices might communicate with each other and unknown Internet endpoints. Within the context of interconnected power grids, remote attestation can, e.g., be used to detect compromised devices based on changes in their physical memory 93,103. Depending on the sophistication of the attack, SCADA software may be able to identify a problem through bad data detection algorithms. Different examples of disgruntled employees misusing their authority have been reported by Brdiczka .
The company lacked the visibility needed to secure the grid and meet its regulatory compliance requirements. With these benefits, however, comes a significantly increased surface area for attacks on both the utility networks as well as the power grid. Recent advances in smart energy technology have provided increased control and efficiency by enabling two-way communication between utilities and energy users. Through this combination of deep expertise, specialized facilities, technology development, and industry collaboration, PNNL is helping protect our nation’s electricity infrastructure from cyber threats today and into the future.
In 2024, Check Point Research documented 1,162 cyberattacks on utilities, a 70 percent increase compared with the same period in the prior year. Department of Energy (DOE) reported at least 175 instances of physical attacks or threats against critical grid infrastructure, including incidences of theft and vandalism. Its federal government counterparts include senior administration officials from the White House, relevant cabinet agencies, federal law enforcement, and national security organizations. The Electricity Subsector Coordinating Council (ESCC) is the main liaison organization between the federal government and the electric power industry. Energy Department to identify any vulnerabilities to cyberattacks in https://dallasrentapart.com/it-will-not-work-to-play-the-role-of-the-duck.html the nation’s electrical power grid. Baltimore Gas and Electric conducts regular drills with its employees.
- Furthermore, distributed and process-aware IDS allow to further strengthen security in interconnected power grids.
- “Other countries that are not experiencing direct conflict are experiencing increasing amounts of physical attacks on their energy infrastructure,” she says.
- As the grid evolves through digitization, IoT expansion, and increased automation, so does its exposure to cyber and physical threats.
- Once access to a machine in the office network has been gained, the attacker can passively listen for user credentials and search for, e.g., a VPN tunnel to the PCN.
- Even if PCNs are air-gapped, i.e., physically isolated from other networks, such as the office network to prevent lateral movement, attackers can still try to attack a PCN by strategically placing USB drives containing malware around a facility they are targeting.
Enjoy more free content and benefits by creating an account
While it is evident that technology alone cannot secure the grid, it must be coupled with a strong security-first culture, ongoing training, and cross-disciplinary collaboration between engineers, operators, and security teams. Ensure that only vendors with secure firmware update processes are engaged. Automated monitoring dashboards provide real-time visibility into device vulnerabilities, firmware versions, and patch status, helping utilities detect risks early and streamline remediation. Organizations should leverage automations for continuous visibility within distributed environments and rapid detection of abnormal activity such as unauthorized access, firmware tampering, or communication anomalies. Centralized dashboards consolidate visibility across sites, devices, and compliance status, supporting a Defense-in-Depth approach to grid security. Organizations should deploy asset discovery tools to build a live inventory, use platforms that integrate with SCADA to surface device status, firmware versions, and create a layered defense.
Allowing communications between PCN-connected devices and the office network might be necessary, e.g., to transfer certain information, such as environment data between office network and control room. In the attacks on Ukrainian grid operators in 2015 , attackers gained access to the PCN through lateral movement from the office network (cf. Figure 1). In the following, we discuss the most important attack vectors an attacker can exploit to access a PCN. Attackers can leverage different attack vectors to compromise the network of a transmission or distribution system operator with the goal of causing a blackout or at least considerable disturbance in the power grid.
“Defense-in-Depth” and Sector-Wide Preparation Exercises
- Since 2014, vandalism and confirmed or suspected physical attacks on electrical grid infrastructure have also been the second-largest cause of electrical disturbance events.
- In the following, we discuss the most important attack vectors an attacker can exploit to access a PCN.
- The Ukraine 2015 power grid attacks showcased how attackers can remotely control circuit breakers while disabling operator visibility and response capabilities.
- The three primary segments of the electric utility industry—public power, investor-owned, and rural electric cooperatives—have long had in place mutual aid response networks to share employees and resources to restore power after natural disasters and other emergencies.
- The bill includes a number of provisions to establish a more transparent and streamlined process by which the President, the Department of Energy, and the Federal Energy Regulatory Commission (FERC) can act to address existing or potential vulnerabilities.
- With attacks becoming more frequent and more severe, it is imperative that utilities continue to evolve and mature their cybersecurity posture to ensure operational uptime, improve situational awareness, minimize risk and promote the safety of employees and the community.
Centralized platforms support cultural transformation by offering visibility tools built for OT teams, presenting https://mamemame.info/on-my-thoughts-explained-2/ alerts, compliance drift, and access violations in language and context relevant to field personnel. Finally, CISA 2015 set up policies and procedures for voluntary sharing of cybersecurity threat information between and among the federal government and private entities (the definition of which includes public power utilities) and provides limited liability protection for these activities. While not all data is publicly available, Coe says there’s been a “tenfold” increase over the past decade in the number of reported physical attacks on the grid. This scenario, inspired by the upcoming 2026 World Cup and the 2028 Olympic Games in Los Angeles, was an exercise in studying how utilities can prevent and mitigate, among other dangers, physical attacks on power grids. The bill includes a number of provisions to establish a more transparent and streamlined process by which the President, the Department of Energy, and the Federal Energy Regulatory Commission (FERC) can act to address existing or potential vulnerabilities.
In the following, we first discuss the most important attack vectors before we present the attack scenarios enabled by these vectors. Practical cybersecurity in interconnected power grids is impacted by a diverse set of fundamental security challenges. As a result, there is a need to develop solutions which can be used by all relevant actors in interconnected power grids and are not only deployable by larger grid operators. Once an attacker gains access to an unsecured PCN, simple tools enabling communication in the specific protocol may be used to control devices crucial for grid operation. Past attacks have shown that office networks (connected to the Internet) are often not sufficiently separated from the PCN, allowing attackers lateral movement between the two .
- The Safe Haven exercise was held in Washington and Kansas, locations that were selected in coordination with DOE based on several criteria.
- Within the context of interconnected power grids, remote attestation can, e.g., be used to detect compromised devices based on changes in their physical memory 93,103.
- Pre-built models for anomaly detection, user behavior analytics, and threat classification can be customized for energy sector environments.
- Join our hazard resilience exercise to learn how we can build resilience together.
Thus, only an overall increase in the security of a country’s power grid provides an effective defense against sophisticated attacks. To provide security in interconnected power grids, we discussed a set of diverse security solutions and approaches. In this paper, we highlighted resulting fundamental security problems and attack vectors, which still have to be addressed in the coming years in order to maintain a high level of security and availability of power grids as a critical infrastructure 2,3,4,5. To be valuable for training employees of grid operators, such training environments need to closely model typical process control network as found in power grids 17,134. Consequently, grid operators need to develop and maintain actionable incident response plans and guidelines, supporting their employees with precise instructions also at the technical level on how to react to security incidents.