Showing posts with label cyber-security. Show all posts
Showing posts with label cyber-security. Show all posts

House subcommittee considers reliability draft

Tuesday, May 19, 2015

A congressional committee is considering legislation to assure reliability and security of the U.S. electricity grid.  The House Subcommittee on Energy and Power's discussion draft includes a series of provisions designed to harden the grid against disturbance.

To understand the discussion draft, you must first understand its context.  2015 is a time of great change for the U.S. electricity system.  The grid continues to shift away from coal-fired generation and towards use of natural gas and renewable energy sources.  New environmental regulations affecting power plants are taking effect.  Smart grid technology now enables real-time communication and coordination between supply and demand for electricity, but creates millions of potential access points for hackers to target the grid.  Meanwhile utilities plan to invest more than $60 billion in transmission infrastructure over the next decade. 

Faced with these shifts, the House Subcommittee on Energy and Power held a hearing today on a "discussion draft" of proposed measures to strengthen grid reliability, security and readiness to survive disturbance.  The discussion draft includes measures that would:
  • Resolve conflicts between choosing whether to comply with an emergency order from the Department of Energy or violate environmental obligations;
  • Require the Federal Energy Regulatory Commission to complete an independent reliability analysis of any proposed or final major federal rule that affects electric generating units;
  • Direct the Secretary of Energy to develop and adopt procedures to enhance communication and coordination between governmental entities and the private sector to improve emergency response and recovery;
  • Give the Secretary of Energy powers to address grid security emergencies, and facilitate information sharing;
  • Require the Energy Department to submit a plan to Congress evaluating the feasibility of establishing a Strategic Transformer Reserve for the storage, in strategically-located facilities, of spare large power transformers in sufficient numbers to temporarily replace critically damaged large power transformers;
  • Direct DOE to create a voluntary Cyber Sense program to identify cyber-secure products and technologies intended for use in the bulk-power system, like controls and SCADA systems;
  • Directs state public utility commissions and utilities to improve grid resilience and promote investments in energy analytics technology to increase efficiencies and lower costs for ratepayers while strengthening reliability and security; and
  • Require FERC to work with each regional transmission organization to encourage a diverse generation portfolio, long-term reliability and price certainty for customers, and enhanced performance assurance during peak period.
As noted in the opening statements of Chairmen Ed Whitfield and Fred Upton, elements from this discussion draft may be included in a bipartisan energy bill expected to emerge from the House committee later this session.

FERC considers Physical Security Reliability Standard

Thursday, November 13, 2014

Federal energy regulators are considering a new national standard for protecting the physical security of the U.S. electric grid.  Given the importance of electric reliability and concern over terrorist attacks and sabotage, electric reliability organization NERC has proposed a Physical Security Reliability Standard known as CIP-014-1.  If adopted by the Federal Energy Regulatory Commission (FERC), the standard would become enforceable against transmission owners and operators.

Under U.S. law, the FERC has jurisdiction over the network of wires and transformers that make up the nation's bulk transmission system.  The Energy Policy Act of 2005 expanded the Commission's authority to impose mandatory reliability standards on the bulk transmission system.  Working with the nation's chief electric reliability organization (North American Electric Reliability Corporation, or NERC), the Commission has adopted a series of reliability standards covering matters including communications among utilities, cybersecurity, and interconnections.

On July 17, 2014, the FERC issued a notice of proposed rulemaking proposing to approve NERC’s proposed Physical Security Reliability Standard (CIP-014-1).  NERC has described this standard as designed to enhance physical security measures for the most critical Bulk-Power System facilities and thereby to lessen the overall vulnerability of the Bulk-Power System to physical attacks.  The standard requires owners and operators of transmission facilities to identify and protect critical transmission stations, substations, and control centers whose damage through physical attack could result in spreading outages or other reliability problems.

The proposed physical security reliability standard also includes provisions protecting sensitive or confidential information from public disclosure, calling for third party verification and periodic reevaluation of critical facility identification, threats assessment, and security plans.

The FERC solicited public comment on the proposed physical security reliability standard through September 8, 2014.  Over 30 parties filed comments, with additional reply comments filed by September 22.

With the proposed Physical Security Reliability Standard now pending before the FERC, we may soon see its adoption.  The FERC has scheduled the matter for its November 20 deliberations.  Assuming CIP-014-1 is adopted, owners and operators of regulated facilities will need to comply with the new standard, and to plan for further tightening up of the physical security of the electric grid in the coming years.

FERC testifies on EPA carbon regulations and electric reliability

Wednesday, July 30, 2014

The U.S. Environmental Protection Agency's proposed Clean Power Plan rule is projected to limit carbon dioxide emissions from power plants, improve human health and save money -- but will it jeopardize the reliability of the nation's electricity grid?

Poorly implemented carbon regulations could increase the risk of widespread power outages, but this risk can be managed, according to testimony offered by the Commissioners of the Federal Energy Regulatory Commission to the House Energy & Commerce Subcommittee on Energy & Power earlier this week.

In her written testimony, Acting Chairman Cheryl LaFleur acknowledged concerns that EPA's carbon rule may have an "adverse impact on the overall reliability of the bulk power system."  Noting that EPA's plan leaves much of the implementation to individual states, she suggested that the FERC work closely with states to consider how state implementation plans will affect the operation of the grid. 

Commissioner Philip Moeller's testimony was more critical of EPA's proposed rule, which he described as infringing upon the FERC's jurisdiction over electric system reliability.  Noting that electricity markets are interstate in nature, Commissioner Moeller warned that "the proposal’s state-by-state approach results in an enforcement regime that would be awkward at best, and potentially very inefficient and expensive."  He also expressed skepticism at the plan's inclusion of increased use of existing natural gas-fired generation as one "building block" states may use to reduce their power sector's carbon intensity.  Commissioner Moeller also pointed to EPA's Mercury and Air Toxics Standards (MATS) rule as giving him reliability concerns.  On the positive side, he urged state regulators to speed adoption of real-time pricing at the retail level, so consumers can feel price signals that could reduce the overall cost of energy.  Commissioner Moeller concluded with a plea that FERC be given a formal role in EPA's regulation of the electric power sector.

Commissioner John Norris testified that EPA's proposed rule is "an important first step that addresses climate change by appropriately seeking to reduce carbon emitted by our nation’s electric power system."  While he acknowledges that transitioning to a low-carbon economy is challenging, he expressed confidence that "we as a nation should be well positioned to meet those challenges."  Commissioner Norris cited the MATS standards as an example of our readiness: while EPA's MATS rule led to the retirement of many older, inefficient coal-fired power plants, the grid has generally responded in a way that will maintain reliability.  Commissioner Norris urged cooperation with electric reliability organization North American Electric Reliability Corporation (NERC) and states, and to be flexible in making market rule changes to enable states, regional transmission organizations and other system planners to meet resource adequacy requirements.

Commissioner Tony Clark testified that while the grid is more reliable than before, it remains vulnerable to cyberattack, physical security threats, and geomagnetic disturbances.  He also described environmental regulations as another source of risk, and warned of the "seismic" shift in EPA authority over the energy sector embodied in the rule.  Commissioner Clark described the Clean Power Plan as the most comprehensive reordering he has seen of the jurisdictional relationship between the federal government and states as it relates to the regulation of public utilities and energy development.  He painted a picture of states forced to choose between surrendering their authority over power plants willingly or losing it to federal supremacy.

Current FERC enforcement director Norman Bay also testified, noting that he was confirmed by the Senate as a Commissioner on July 15, but that he has not yet been sworn in.  His brief testimony focused on the need for cooperation between FERC, EPA, NERC, states, and regional transmission organizations to ensure reliability.

What happens next remains to be seen.  As expressed in the opening statements of Energy and Power Subcommittee Chairman Ed Whitfield and Energy and Commerce Committee Chairman Fred Upton, many remain concerned about what they perceive as an effort by EPA to assert control and new regulatory authorities over states’ electricity decision-making.  Will EPA's Clean Power Plan ultimately come into effect -- and if so, what path will it take?

Cybersecurity, solar energy and the electric grid

Monday, May 12, 2014

A group of Russian hackers claims to have identified security gaps in widely-used solar panel monitoring software.  The monitoring platform's developer is said to be fixing the gaps -- but can hackers damage the electric grid?

Solar panels supporting Goblin Valley State Park, Utah.
German company Solare Datensysteme GmbH makes a series of devices to track and monitor solar panel performance.  Its "Solar-Log" product line monitors the performance of solar photovoltaic systems and uses an internet connection and software to offer users additional management tools.  According to the company's website, Solar-Log systems manage roughly 229,300 solar plants that producing an aggregate average of 5.66 terawatt-hours (TWh) per day.

According to an article on tech website The Register, a Russian hacking firm known as Positive Security has warned that the previous Solar-Log software was vulnerable to malicious cyberattacks that could cause power grid reconfiguration and cascading blackouts.  The article claims that attackers could download and modify Solar-Log configuration files without needing propert authentication.  Files could be compromised to change user passwords and run code provided by the attacker.  The article suggests that malicious hackers could manipulate "specific power-generation related values", letting users could overstate the amount of power pumped back into grids by their solar installations.

The exact details of the weaknesses identified by Positive Security is being kept secret until the Solar-Log maker can distribute a patch shoring up system security.  As with past bugs, it is likely that Solare Datensysteme and other product makers will continue to plug holes in their cybersecurity, as new flaws are exposed and as systems evolve.  But solar panel monitoring systems are not the only energy-related infrastructure vulnerable to hacking; items ranging from utility smart meters to utility-scale power generator controls may be at risk of compromise from outside forces.

A series of regulations are designed to protect the grid against these threats.  The Federal Energy Regulatory Commission has approved mandatory cybersecurity reliability standards for the U.S. bulk power system.  Acting under its authority pursuant to the Energy Policy Act of 2005, through Order No. 706 the Commission has approved a series of Critical Infrastructure Protection (CIP) cyber security reliability standards proposed by electric reliability organization North American Electric Reliability Corporation (NERC).  Both NERC and the Commission continue to evaluate further changes to those standards, along with other standards bolstering the physical security of the electric grid.

New cybersecurity threats crop up regularly, prompting product developers, service providers, and regulators to engage in a continual effort to identify, block, and protect against threats to the electric power system.  For developers of energy technologies or projects, compliance with key regulations is a critical element of this protection, as is taking a proactive view to ensure safe and reliable operations.  While it is hard to predict the next front in this war, count on it to be ever shifting.

Utilities face smart meter hacking threat

Tuesday, April 10, 2012

Electric utilities are converting traditional electric meters to modern, remotely-readable smart meters - but some may be facing a new twist on electricity theft: hacking smart meters.

The term "smart meters" encompasses a variety of devices used by electric utilities to measure how much electric energy their customers consume.  In general, smart meters can eliminate the need for a meter reader to physically visit the customer's premises, relying instead on wireless radio frequency communication to tell the central office about the customer's consumption.  Many smart meters can also allow real-time tracking of customers' use of electricity, a precursor to time-of-use rates and other "smart grid" applications.  Federal and state regulators promote their installation, citing improved customer service, enhanced storm restoration efforts, and reduced costs for both ratepayers and utilities.

Cybersecurity blog KrebsOnSecurity has released part of a document that appears to be a bulletin by the Federal Bureau of Investigation noting a new threat: hacking smart meters.  According to the blog, a Puerto Rican utility may have lost "hundreds of millions of dollars annually" as a result of smart meter hacking.  Apparently some smart meter models are relatively vulnerable to being reprogrammed (or simply subverted) such that they underreport how much electricity the consumer is using.

Theft of electricity is not new, as people have likely attempted to bypass utility meters since their inception in the 19th century.  As society and the electric power industry have become increasingly digital, it may be inevitable that this trend would continue.  As utilities and regulators respond to the new threat, cybersecurity may play an important and increasing role.

January 7, 2011 - data center power demands

Friday, January 7, 2011

As the volume of digital data we create and consume increases, how much electricity is required to store, manage and analyze this information?  Smart grid technology has been described as relying on the "internet of things", a vision becoming real of constant real-time data communications between interconnected devices like home appliances, heating systems, and vehicles and the overall power grid.  This will represent a multifold increase in the volume of data being produced - and for those entities interested in analyzing that data, a likely increase in the volume of energy required to do so.

Even now, when smart grid communications are still a relatively small portion of the total volume of data flying around the country, it can take a surprisingly large amount of electricity to run a data storage and analysis center.  In Utah, the National Security Agency has just broken ground for its Utah Data Center, a complex enclosing about 1 million square feet of space, 100,000 square feet of which will be devoted to computer hardware.  Sen. Orrin Hatch has been quoted as describing the data center as creating 100 to 200 jobs for information technology specialists and engineers.  The NSA describes the data center as a component of the Comprehensive National Cyber-security Initiative designed to help the intelligence community meet domestic cyber-security requirements.

So how much power will the Utah Data Center consume?  Apparently up to 65 megawatts.  Indeed, the availability and cost of that much power was one factor behind the siting of the facility in Utah.  In 2006, the agency reportedly nearly consumed the entire free electric capacity of the Baltimore, Maryland power grid, causing the agency to look elsewhere for the installation of this new computing capacity.  The relatively low cost of energy in Utah may also have been attractive; the EIA reports that the September 2010 average all-sector electricity price in Utah was just 7.42 cents per kWh, significantly below the U.S. average of 10.24 cents per kWh for that time period, let alone costlier markets like Washington, D.C. (13.74 cents/kWh), California (15.27 cents/kWh), or Connecticut (17.26 cents/kWh).

As society generates more and more data, can we expect to see more and more data centers?  Will they consume more and more electricity?  Because data can be directed to any geographic location, does this place areas with less expensive power at a relative advantage for the economic development opportunities posed by data centers?