Dramatic change is sweeping over the sector. For instance, so-called smart meters are being added to bring more online control to the electrical grid. And more and more households are adding solar systems to their rooftops, providing new connecting points. A “rapidly evolving system” is in major need of modernization and upgrades to keep pace, the report says.
“There’s the weak-link issue for the whole system,” Energy Secretary Ernest Moniz said in an interview to highlight the report. “The reality is, for a lot of rural, smaller utilities, it’s a very difficult job to have the kind of expertise that will be needed in terms of cyber, so we suggest for example, grant programs to help with training, to help with analytical capacity in these situations.”
“The economy would just take an enormous hit” from a successful grid attack, he said.
The document is the second installment of the Quadrennial Energy Review, a series of wide-ranging reports surveying the entire U.S. energy system that the department began after President Obama announced new climate change policies in 2013. The first installment dealt broadly with the entirety of the nation’s energy infrastructure, which goes far beyond electricity to encompass natural gas and oil pipelines, storage infrastructure, and other facets. This one zooms in on electricity.
It highlights not only cyberattacks on electric infrastructure in Ukraine in late December of 2015 — in which three Ukrainian utilities were hit by synchronized cyberattacks, leading to power losses for 225,000 customers — but also the Oct. 21, 2016, event that used in-home Internet-connected devices, collectively, to lead a large denial-of-service attack.
“We know that this is not just a theoretical concern,” Moniz said.
The report calls for utilities to take engage in “deliberate risk management activities” as the electric power sector becomes increasingly interconnected with global communications networks.
“The threat environment is also changing — decision makers must make the case for investments that mitigate catastrophic, high-impact, low-probability events,” the report notes.
Cyberthreats are not the only challenge facing the grid. The report warns that extreme weather events triggered by human-caused climate change also makes the system vulnerable.
On grid security, the report contains myriad recommendations, including amending the Federal Power Act to give the Energy Department the ability to issue a “grid-security emergency order,” and also giving the Federal Energy Regulatory Commission new powers to bolster reliability standards that affect electricity-sector operators “if it finds that expeditious action is needed to protect national security in the face of fast-developing new threats to the grid.”
In the interview, Moniz said he hoped that under the next administration, the Quadrennial Energy Review process would continue, noting that the last installment of the report has already triggered major action. Of its 63 recommendations, the DOE has found, 21 are already “fully or partially reflected in Federal law.”
“We think that the second volume hopefully is going to have the same kind of track record,” Moniz said. “That’s the basis upon which I certainly hope, and will certainly recommend, presumably to [Energy secretary nominee Rick Perry], that the new administration take ownership of this, and keep it going.”