New England utility regulators have gathered in Maine for the 71st annual symposium of the New England Conference of Public Utilities Commissioners.
NECPUC is a non-profit corporation which provides regional regulatory assistance on matters of common concern to public utilities commissions of the six New England states. Its board of directors is composed of public utilities commissioners from the six New England states. NECPUC meets regularly throughout the year and sponsors an annual symposium on regulatory issues.
NECPUC holds its 71st annual symposium in Cape Neddick, Maine, from May 20-23, 2018. The agenda for the 2018 NECPUC event includes programs focused on topics affecting the New England utility landscape. For the energy sector, these include a plenary session on wholesale markets and how consumers are impacted by "reliability-centric market challenges," as well as a panel on advancing electric vehicle infrastructure in New England. Another set of panels focuses on how to analyze, regulate, and manage risks of high-impact, low-frequency events like cybersecurity attacks or extreme weather. Other panels cover water, telecommunications, and natural gas topics.
Speakers scheduled to appear include Maine Governor Paul LePage and Federal Energy Regulatory Commission Commissioner Robert Powelson, as well as commissioners from numerous state public utilities commissions.
Showing posts with label cybersecurity. Show all posts
Showing posts with label cybersecurity. Show all posts
NECPUC 2018 energy symposium
Monday, May 21, 2018
Labels:
customer,
cybersecurity,
electric vehicle,
FERC,
infrastructure,
LePage,
Maine,
NECPUC,
reliability,
risk,
wholesale
US warns of Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure
Thursday, March 22, 2018
The U.S. Department of Homeland Security has warned that for at least two years, Russian government cyber actors have targeted government entities and multiple U.S. critical infrastructure sectors, including the energy, nuclear, commercial
facilities, water, aviation, and critical manufacturing sectors.
In a joint Technical Alert issued March 15, 2018 by the Department of Homeland Security's U.S. Computer Emergency Readiness Team (US-CERT) and the Federal Bureau of Investigation, the agencies warned of a "multi-stage intrusion campaign by Russian government cyber actors." The report follows an October 2017 alert by computer security firm Symantec of a re-emergence of a sophisticated cyber espionage group known as "Dragonfly."
According to the government agencies' report, the Russian cyber threat actors seem to have deliberately targeted specific organizations, as opposed to pursuing targets of opportunity. In an initial "staging" phase, the campaign used tools like malware, watering holes, and spear phishing to gain access to small commercial facilities' networks -- typically peripheral organizations like trusted third-party suppliers whose networks may be less secure. For example, the threat actors sent emails with malicious attachments appearing to be personnel resumes or contract documents. Clicking on links in the attachments exposed the victims to malware or data harvesting. In a subsequent phase, the threat actors made further use of the staging targets' networks as "pivot points and malware repositories" for use in targeting their final intended victims.
The report says that these Russian government cyber actors used this hacked access for network reconnaissance and collection of information pertaining to Industrial Control Systems (ICS). It describes multiple instances of threat actors accessing workstations and servers on corporate networks that contained data output from control systems within energy generation facilities.
Cyber security is now a significant concern, both domestically and abroad. A February 2018 report by the U.S. intelligence community described the targeting of national security information and proprietary information from US companies and research institutions involved with defense, energy, finance, dual-use technology, and other areas as "a persistent threat to US interests." Last month, U.S. electric grid reliability regulators imposed a $2.7 million penalty on an unidentified utility for its violations of mandatory reliability standards in connection with a data security breach -- the largest fine to date associated with U.S. utility cybersecurity regulation. In that case, a third-party contractor hired by the utility allegedly copied protected data from the utility's network to the contractor's unsecured network -- where it was accessible online without the need to enter a user ID or password, and where it was in fact accessed by one or more unknown outside entities.
In 2014, reports emerged that Russian hackers had found flaws in solar panel monitoring software that, if left unfixed, could allow malicious actors to damage the electric grid. Foreign state-sponsored cyber attacks in 2016 and 2017 against Ukraine and Saudi Arabia targeted multiple sectors across critical infrastructure, government, and commercial networks, causing disruption to Ukrainian energy distribution networks.
In a joint Technical Alert issued March 15, 2018 by the Department of Homeland Security's U.S. Computer Emergency Readiness Team (US-CERT) and the Federal Bureau of Investigation, the agencies warned of a "multi-stage intrusion campaign by Russian government cyber actors." The report follows an October 2017 alert by computer security firm Symantec of a re-emergence of a sophisticated cyber espionage group known as "Dragonfly."
According to the government agencies' report, the Russian cyber threat actors seem to have deliberately targeted specific organizations, as opposed to pursuing targets of opportunity. In an initial "staging" phase, the campaign used tools like malware, watering holes, and spear phishing to gain access to small commercial facilities' networks -- typically peripheral organizations like trusted third-party suppliers whose networks may be less secure. For example, the threat actors sent emails with malicious attachments appearing to be personnel resumes or contract documents. Clicking on links in the attachments exposed the victims to malware or data harvesting. In a subsequent phase, the threat actors made further use of the staging targets' networks as "pivot points and malware repositories" for use in targeting their final intended victims.
The report says that these Russian government cyber actors used this hacked access for network reconnaissance and collection of information pertaining to Industrial Control Systems (ICS). It describes multiple instances of threat actors accessing workstations and servers on corporate networks that contained data output from control systems within energy generation facilities.
Cyber security is now a significant concern, both domestically and abroad. A February 2018 report by the U.S. intelligence community described the targeting of national security information and proprietary information from US companies and research institutions involved with defense, energy, finance, dual-use technology, and other areas as "a persistent threat to US interests." Last month, U.S. electric grid reliability regulators imposed a $2.7 million penalty on an unidentified utility for its violations of mandatory reliability standards in connection with a data security breach -- the largest fine to date associated with U.S. utility cybersecurity regulation. In that case, a third-party contractor hired by the utility allegedly copied protected data from the utility's network to the contractor's unsecured network -- where it was accessible online without the need to enter a user ID or password, and where it was in fact accessed by one or more unknown outside entities.
In 2014, reports emerged that Russian hackers had found flaws in solar panel monitoring software that, if left unfixed, could allow malicious actors to damage the electric grid. Foreign state-sponsored cyber attacks in 2016 and 2017 against Ukraine and Saudi Arabia targeted multiple sectors across critical infrastructure, government, and commercial networks, causing disruption to Ukrainian energy distribution networks.
Labels:
control,
cyber,
cybersecurity,
Department of Homeland Security,
generation,
hacker,
industrial,
NERC,
penalty,
Russia,
SCADA,
security,
threat,
US-CERT,
utility
Energy dept adopts grid emergency order rule
Wednesday, January 17, 2018
U.S. energy regulators have issued a final rule governing the procedures through which the Secretary of Energy may issue an emergency order under the Federal
Power Act to respond to an electric grid security emergency.
Under the Fixing America's Surface Transportation Act of 2015, Congress authorized the Secretary of Energy to order emergency measures after the President declares a grid security emergency. Such an emergency could occur as the result of a physical attack, a cyber-attack using electronic communication, an electromagnetic pulse (EMP), or a geomagnetic storm event. The FAST Act added these powers to the Federal Power Act, which contained additional language authorizing the Secretary to order temporary emergency measures as needed to serve the public interest.
On January 10, the U.S. Department of Energy published its final rule governing grid security emergency orders. According to the Department, the procedures established by this final rule "will ensure the expeditious issuance of emergency orders under the Federal Power Act." It says the final rule establishes a "consistent yet flexible set of procedures" for regulatory engagement with impacted parties as the Department issues emergency orders. The Department says it "expects that these emergency orders would be issued rarely," but emphasized its need for flexibility in tailoring a response to the particular circumstances of any grid disruption.
The new final rule is codified in 18 C.F.R. section 205.380 et seq.
Under the Fixing America's Surface Transportation Act of 2015, Congress authorized the Secretary of Energy to order emergency measures after the President declares a grid security emergency. Such an emergency could occur as the result of a physical attack, a cyber-attack using electronic communication, an electromagnetic pulse (EMP), or a geomagnetic storm event. The FAST Act added these powers to the Federal Power Act, which contained additional language authorizing the Secretary to order temporary emergency measures as needed to serve the public interest.
On January 10, the U.S. Department of Energy published its final rule governing grid security emergency orders. According to the Department, the procedures established by this final rule "will ensure the expeditious issuance of emergency orders under the Federal Power Act." It says the final rule establishes a "consistent yet flexible set of procedures" for regulatory engagement with impacted parties as the Department issues emergency orders. The Department says it "expects that these emergency orders would be issued rarely," but emphasized its need for flexibility in tailoring a response to the particular circumstances of any grid disruption.
The new final rule is codified in 18 C.F.R. section 205.380 et seq.
FERC's approach to EMP and GMD threats
Friday, June 2, 2017
Federal energy regulators have used both regulatory and more informal collaborative approaches to address the threat to the electric grid posed by electromagnetic pulses and geomagnetic disturbances, according to testimony delivered on May 4, 2017, to the U.S. Senate Committee on Energy and Natural Resources.
Last month, Federal Energy Regulatory Commission acting chairman Cheryl LaFleur spoke to the Senate committee on the Commission's work in protecting the reliability of the U.S. grid against naturally-occurring and manmade threats. In her testimony, she noted the Commission's role in approving mandatory reliability standards developed by the North American Electric Reliability Corporation (NERC), as well as its support for grid security through voluntary and collaborative efforts like sharing best practices, participating in grid reliability exercises, and briefing state policymakers.
Acting chairman LaFleur's testimony focused on the threats posed by man-made electromagnetic pulses (EMP) and naturally-occurring geomagnetic disturbances (GMD). As she categorized it, EMP are bursts of energy designed to disrupt, damage or destroy electronics such as those found in control systems on the electric grid. GMD are naturally occurring solar magnetic disturbances which periodically disrupt the earth’s magnetic field; these disturbances can induce currents on the electric grid that may simultaneously damage or destroy key transformers over a large geographic area. According to Commissioner LaFleur, a severe EMP or GMD event "has the potential to cause voltage problems and instability on the electric grid, which could lead to wide-area blackouts."
She next noted FERC's actions to address EMP threats, including both regulatory and informal approaches. Regulatory actions include FERC's direction and approval of NERC's two-stage GMD reliability standards, which require responsible entities to develop and implement operational procedures to mitigate the effects of GMDs and to conduct initial and on-going assessments of the potential impact of a benchmark GMD event on bulk-power system equipment and the bulk-power system as a whole and to mitigate any assessed vulnerabilities.
She also pointed to FERC's approval of NERC's physical reliability standard, which requires responsible entities to mitigate assessed vulnerabilities to critical transmission facilities through resiliency or security measures designed collectively to deter, detect, delay, assess, communicate, and respond to potential physical threats and vulnerabilities, as helping to address the use of small, portable EMP devices that require close proximity to their intended target. However, as she noted, "FERC has not directed NERC to develop a standard specifically targeting EMP."
Acting chair LaFleur also noted collaborative efforts, including coordination and information-sharing with the Department of Energy, Department of Homeland Security, Department of Defense, interagency task forces, and foreign governments.
Last month, Federal Energy Regulatory Commission acting chairman Cheryl LaFleur spoke to the Senate committee on the Commission's work in protecting the reliability of the U.S. grid against naturally-occurring and manmade threats. In her testimony, she noted the Commission's role in approving mandatory reliability standards developed by the North American Electric Reliability Corporation (NERC), as well as its support for grid security through voluntary and collaborative efforts like sharing best practices, participating in grid reliability exercises, and briefing state policymakers.
Acting chairman LaFleur's testimony focused on the threats posed by man-made electromagnetic pulses (EMP) and naturally-occurring geomagnetic disturbances (GMD). As she categorized it, EMP are bursts of energy designed to disrupt, damage or destroy electronics such as those found in control systems on the electric grid. GMD are naturally occurring solar magnetic disturbances which periodically disrupt the earth’s magnetic field; these disturbances can induce currents on the electric grid that may simultaneously damage or destroy key transformers over a large geographic area. According to Commissioner LaFleur, a severe EMP or GMD event "has the potential to cause voltage problems and instability on the electric grid, which could lead to wide-area blackouts."
She next noted FERC's actions to address EMP threats, including both regulatory and informal approaches. Regulatory actions include FERC's direction and approval of NERC's two-stage GMD reliability standards, which require responsible entities to develop and implement operational procedures to mitigate the effects of GMDs and to conduct initial and on-going assessments of the potential impact of a benchmark GMD event on bulk-power system equipment and the bulk-power system as a whole and to mitigate any assessed vulnerabilities.
She also pointed to FERC's approval of NERC's physical reliability standard, which requires responsible entities to mitigate assessed vulnerabilities to critical transmission facilities through resiliency or security measures designed collectively to deter, detect, delay, assess, communicate, and respond to potential physical threats and vulnerabilities, as helping to address the use of small, portable EMP devices that require close proximity to their intended target. However, as she noted, "FERC has not directed NERC to develop a standard specifically targeting EMP."
Acting chair LaFleur also noted collaborative efforts, including coordination and information-sharing with the Department of Energy, Department of Homeland Security, Department of Defense, interagency task forces, and foreign governments.
Labels:
cybersecurity,
EMP,
FERC,
GMD,
LaFleur,
NERC,
physical reliability,
reliability,
resilience,
security,
Senate,
standard
Substation security and the Garkane shooting
Tuesday, October 11, 2016
As the U.S. strengthens protections for its electricity grid, much of the discussion focuses on cybersecurity -- but physical security is also important, as shown by an attack on a Utah utility's substation. On September 25, an unknown gunman fired at least 3 shots into a distribution system substation, damaging a transformer and causing power outages. The incident may place renewed pressure on utilities to secure their infrastructure against vandalism and terrorism.
As reported by the Deseret News, the damage occurred at a substation owned by Garkane Energy Cooperative. An assailant reportedly shot the main transformer's oil-cooled radiator system, causing the transformer to overheat and fail. About 13,000 customers lost power across most of Kane and Garfield counties. A spokesman for the cooperative said damage to the transformer could reach $1 million; repairs could take 6 to 12 months. The utility has offered an unusually high reward -- $50,000 -- for information leading to the arrest of the shooter.
This is not the first time someone has used firearms to damage utility infrastructure. Some incidents, such as the 2012 shotgunning of 167 insulating discs on Vermont's transmission system, may be considered vandalism. Others, like the 2013 sniper shooting of a PG&E substation in San Jose, California, are considered terrorism. That attack led the Federal Energy Regulatory Commission to implement new physical security protections for utility infrastructure known as CIP-014, through its Order No. 802.
The Garkane incident remains under investigation. More broadly, it may strengthen calls for further hardening of the utility system against physical attack. Meanwhile, efforts continue to strengthen cybersecurity protections for the grid.
As reported by the Deseret News, the damage occurred at a substation owned by Garkane Energy Cooperative. An assailant reportedly shot the main transformer's oil-cooled radiator system, causing the transformer to overheat and fail. About 13,000 customers lost power across most of Kane and Garfield counties. A spokesman for the cooperative said damage to the transformer could reach $1 million; repairs could take 6 to 12 months. The utility has offered an unusually high reward -- $50,000 -- for information leading to the arrest of the shooter.
This is not the first time someone has used firearms to damage utility infrastructure. Some incidents, such as the 2012 shotgunning of 167 insulating discs on Vermont's transmission system, may be considered vandalism. Others, like the 2013 sniper shooting of a PG&E substation in San Jose, California, are considered terrorism. That attack led the Federal Energy Regulatory Commission to implement new physical security protections for utility infrastructure known as CIP-014, through its Order No. 802.
The Garkane incident remains under investigation. More broadly, it may strengthen calls for further hardening of the utility system against physical attack. Meanwhile, efforts continue to strengthen cybersecurity protections for the grid.
Labels:
California,
cybersecurity,
distribution,
FERC,
Garkane,
infrastructure,
outage,
PG&E,
physical security,
security,
shooting,
substation,
terrorism,
Utah,
vandalism,
Vermont
Subscribe to:
Posts (Atom)
