Showing posts with label physical. Show all posts
Showing posts with label physical. Show all posts

FERC, DOE to hold Security Investments for Energy Infrastructure Technical Conference

Tuesday, March 5, 2019

The Federal Energy Regulatory Commission and the United States Department of Energy have scheduled a joint technical conference to discuss current cyber and physical security practices used to protect energy infrastructure and possible federal and state incentives for related security investments.

According to a notice issued on February 4, the Security Investments for Energy Infrastructure Technical Conference will be led by one or more FERC Commissioners and DOE senior officials. Its agenda addresses two high-level topics: types of current and emerging cyber and physical security threats, and how federal and state authorities can facilitate investments to improve the cyber and physical security of energy infrastructure.

In a supplemental notice issued on March 1, the agencies noted that the Commission has adopted a "well-developed set of mandatory and enforceable reliability standards that set baseline protections for both cyber and physical security of the bulk electric system" as well as "policies that allow for the recovery of prudently incurred costs to comply with those mandatory reliability standards." The supplemental notice describes the technical conference as aimed at better understanding:
  1. the need for security investments that go beyond those measures already required by mandatory reliability standards, including in infrastructure not subject to those standards (e.g., natural gas pipelines);
  2. how the costs of such investments are or could be recovered; and
  3. whether additional incentives for making such investments are needed, and if so, how those incentives should be designed.
The supplemental notice describes two panels, the first of which will discuss types of cyber and physical security threats to energy infrastructure, particularly electric transmission, generation, and natural gas pipelines, as well as best practices for cyber and physical security mitigation beyond those measures already required by mandatory reliability standards and industry and government engagement needed to address these matters. The second panel will explore how federal and state authorities can provide incentives and cost recovery for security investments in energy infrastructure, particularly electric transmission, generation, and natural gas pipeline infrastructure

The federal agencies' Security Investments for Energy Infrastructure Technical Conference has been scheduled for on March 28, 2019.

Report on US electric grid physical security

Wednesday, March 28, 2018

Since a 2013 rifle attack on a critical electric power substation in California, the U.S. electric power sector has generally moved toward greater physical security for critical assets, according to a report published by the Congressional Research Service. But the report says bulk power security "remains a work in progress," and suggests further investment -- and policy reforms -- may follow.

The report published on March 19, 2018 -- NERC Standards for Bulk Power Physical Security: Is the Grid More Secure? -- begins with the premise that securing the electric power grid is among the nation's highest priorities for critical infrastructure protection. It notes that a 2013 rifle attack on an electric transmission substation in California which caused widespread power outages also broadened policy attention from cybersecurity to encompass the physical security of assets critical to the power grid.

In response, Congress enacted legislation to strengthen power grid physical security and to facilitate its recovery from disruption. Section 1104 of the Fixing America’s Surface Transportation (FAST) Act contains provisions to protect or restore the reliability of critical electric infrastructure or defense of critical electric infrastructure during a grid security emergency. The Federal Energy Regulatory Commission (FERC) and the nation's electric reliability organization NERC also took action to develop new reliability standards for the physical security of bulk power critical infrastructure.

But physical security risks may persist. The report references a September 2016 rifle attack on a Garkane Energy Cooperative transformer substation in Utah as illustrating this persistence. The report notes that while it is probably accurate to conclude that the grid is more physically secure than it was in 2013, "it has not necessarily reached the level of physical security needed based on the sector's own assessments of risk.

The report notes Congress's continued concern about the physical security of the electric grid. It identifies possible areas for further policy focus as including "security implementation oversight, cost recovery, hardening vs. resilience, and the quality of threat information."

Meanwhile, cybersecurity has remained a priority. An October 2017 FERC report describing the results of its audits of regulated companies' cybersecurity protection processes and procedures noted that most met the applicable mandatory standards. But earlier this month, NERC fined an anonymous utility $2.7 million for alleged violations of reliability standards in connection with a data security breach, and the U.S. Department of Homeland Security issued warnings about Russian hackers targeting computer systems controlling energy and other critical infrastructure.

Interest in shoring up the security of energy infrastructure and systems -- both from physical attacks as well as cyber threats -- appears poised to drive continued discussions, regulation, and investment.

NERC fines utility $2.7 million for cyber breach

Friday, March 9, 2018

The electric reliability organization responsible for the grid spanning much of North America has penalized an unidentified utility $2.7 million for its violations of mandatory reliability standards in connection with a data security breach. The penalty may be the largest fine to date associated with U.S. utility cybersecurity regulation.

NERC, or the North American Electric Reliability Corporation, is charged by U.S. law with ensuring the reliability of the nation's bulk power system. NERC establishes reliability standards for the bulk electric system, which are approved by the Federal Energy Regulatory Commission, and takes action to monitor and enforce compliance with its reliability standards.

On February 28, 2018, NERC filed with the Commission a Notice of Penalty regarding what it described as noncompliance by an "Unidentified Registered Entity (URE)", following a settlement between the anonymous utility and regional reliability group Western Electricity Coordinating Council (WECC).

Some of the details of the underlying fact pattern are protected from public disclosure as Critical Energy Infrastructure Information or CEII. But NERC's public filing says the settlement arose from WECC's determination and findings that the anonymous utility violated two of NERC's Critical Infrastructure Protection or CIP cybersecurity standards. According to NERC's report, the utility received a report that an outside "white hat security researcher" had found data publicly available online which appeared to be protected information associated with the utility.

Following this tipoff, an investigation by the utility and regional reliability group WECC revealed that a third-party contractor hired by the utility had copied data from the utility's network environment to the contractor's network environment, where it was no longer subject to the utility's visibility or control -- in violation of the contractor's authority. While the data was on the contractor's network, a subset of live utility data including over 30,000 records was accessible online without the need to enter a user ID or password for a period of 70 days. These records included some associated with the utility's Critical Cyber Assets, such as servers storing user data, systems controlling physical access within the utility's control centers and substations, and supervisory control and data acquisition or SCADA systems. System logs showed unauthorized access to this data set by both the white hat researcher and unidentified IP addresses.

According to the Settlement Agreement, the anonymous utility neither admitted nor denied the violations, but agreed to pay a $2,700,000 penalty and take other compliance actions. This may represent the largest fine to date for violations of NERC's CIP standards. While federal penalty policy encourages self-reporting of violations and having an internal compliance program in place -- as the anonymous utility did -- the settlement notes that the utility "was not fully transparent and forthcoming with all pertinent information detailing the data exposed in the incident." In particular, the settlement says the utility did not initially provide WECC with all the data fields exposed in the incident. These factors, combined with a finding that the violations posed a serious and substantial risk to the reliability of the bulk power system, led WECC to set the penalty amount at $2.7 million, which NERC subsequently approved.

By federal rule, the penalty will be effective upon expiration of the 30-day period following the penalty notice's filing with the Federal Energy Regulatory Commission or, if FERC decides to review the penalty, upon final determination by FERC.

FERC considers Physical Security Reliability Standard

Thursday, November 13, 2014

Federal energy regulators are considering a new national standard for protecting the physical security of the U.S. electric grid.  Given the importance of electric reliability and concern over terrorist attacks and sabotage, electric reliability organization NERC has proposed a Physical Security Reliability Standard known as CIP-014-1.  If adopted by the Federal Energy Regulatory Commission (FERC), the standard would become enforceable against transmission owners and operators.

Under U.S. law, the FERC has jurisdiction over the network of wires and transformers that make up the nation's bulk transmission system.  The Energy Policy Act of 2005 expanded the Commission's authority to impose mandatory reliability standards on the bulk transmission system.  Working with the nation's chief electric reliability organization (North American Electric Reliability Corporation, or NERC), the Commission has adopted a series of reliability standards covering matters including communications among utilities, cybersecurity, and interconnections.

On July 17, 2014, the FERC issued a notice of proposed rulemaking proposing to approve NERC’s proposed Physical Security Reliability Standard (CIP-014-1).  NERC has described this standard as designed to enhance physical security measures for the most critical Bulk-Power System facilities and thereby to lessen the overall vulnerability of the Bulk-Power System to physical attacks.  The standard requires owners and operators of transmission facilities to identify and protect critical transmission stations, substations, and control centers whose damage through physical attack could result in spreading outages or other reliability problems.

The proposed physical security reliability standard also includes provisions protecting sensitive or confidential information from public disclosure, calling for third party verification and periodic reevaluation of critical facility identification, threats assessment, and security plans.

The FERC solicited public comment on the proposed physical security reliability standard through September 8, 2014.  Over 30 parties filed comments, with additional reply comments filed by September 22.

With the proposed Physical Security Reliability Standard now pending before the FERC, we may soon see its adoption.  The FERC has scheduled the matter for its November 20 deliberations.  Assuming CIP-014-1 is adopted, owners and operators of regulated facilities will need to comply with the new standard, and to plan for further tightening up of the physical security of the electric grid in the coming years.

FERC directs standards requiring utility hardening against physical threat

Monday, March 17, 2014

In the wake of last year's sniper assault on a California electrical substation, federal regulators have initiated a process to require utilities to demonstrate that they have hardened their power plants, transmission lines, and other infrastructure against physical attacks.  Last week the Federal Energy Regulatory Commission ordered the North American Electric Reliability Corporation, or NERC, to develop reliability standards requiring utilities to address risks due to physical security threats and vulnerabilities.  If NERC adopts reliability standards to protect against physical threats, will the standards improve electric reliability -- and if so, at what cost?

Stacks from a power plant subject to NERC standards rise above a cove in Salem, Massachusetts.

NERC, a not-for-profit entity whose mission is to ensure the reliability of the bulk power system in North America, has been designated as the United States' electric reliability organization.  To carry out this mission, NERC develops and enforces reliability standards for owners and operators of critical electrical infrastructure.  NERC's existing standards span 1,778 pages, and cover issues ranging from personnel training and emergency preparedness to protection against hacking and cyberterrorism. 

Following the April 16, 2013, destruction by intense gunfire of a PG&E Corp. substation in San Jose, California, much attention has fallen on the protection of the U.S. electrical grid against physical threats.  At the federal regulatory level, this attention led the FERC to issue an order on March 7, 2014, directing NERC to adopt additional standards for physical security.  That order prescribes the creation of new standards requiring owners and operators of the so-called Bulk-Power System to take at least three steps to protect physical security:

  • First, owners and operators must perform a risk assessment of their system to identify their "critical facilities".  Critical facilities are defined as those that, if rendered inoperable or damaged, could have a critical impact on the operation of the interconnection through instability, uncontrolled separation, or cascading failures of the Bulk-Power System.

  • Second, owners and operators of critical facilities must evaluate potential threats and vulnerabilities to those facilities.

  • Third, owners and operators must develop and implement a security plan to address potential threats and vulnerabilities.

The order directing physical protections standards has prompted at least two sets of questions in the utility industry.  First, will these standards lead to improved reliability?  While the efficacy of the standards will likely only be proven in retrospect, if at all, fears brought to life by the California attack and others have convinced a majority of the Commission that the standards are necessary.

Other questions have arisen about the cost of implementing the standards.  While some defenses against physical threats may be adopted relatively inexpensively -- for example, opaque fencing around critical facilities -- others may prove expensive.  When the possible scope and extent of critical facilities are taken into account, some estimates of the potential cost -- including that of concurring FERC Commissioner John Norris -- rise into the billions.

Under the Commission's order, NERC has until June 5, 2014, to prepare and submit its proposed new reliability standards.