Showing posts with label threat. Show all posts
Showing posts with label threat. Show all posts

FERC official testifies on electromagnetic pulses and geomagnetic disturbances

Friday, March 8, 2019

Electromagnetic pulse and geomagnetic disturbance events "pose a serious threat to the electric grid and its supporting infrastructures that serve our Nation," according to testimony delivered by a federal official to the U.S. Senate Committee on Homeland Security and Governmental Affairs.

Electromagnetic pulse (EMP) and geomagnetic disturbance (GMD) events are two types of events that could affect the nation's electric grid. Generally speaking, GMD events are naturally occurring solar magnetic disturbances which periodically disrupt the earth’s magnetic field. These disruptions can induce currents on the electric grid that may simultaneously damage or destroy key transformers over a large geographic area.

On February 27, 2019, Joseph McClellan, director of the Federal Energy Regulatory Commission's Office of Energy Infrastructure Security, testified before the Senate committee. As described in his testimony, EMP events can be generated by "devices that range from small, portable, easily concealed battery-powered units all the way through missiles equipped with nuclear warheads." High-altitude nuclear detonations can generate three distinct EMP effects: "a short high energy radio-frequency-type burst called E1 that can destroy electronics; a slightly longer burst that is similar to lightning termed E2; and a final effect termed E3 that is similar in character and effect to GMD, with the potential to damage transformers and other electrical equipment."

According to Director McClellan's testimony, any of these effects could lead to "wide-area blackouts." In his testimony, he cited reports by the federal EMP Commission as finding that "a single EMP attack could seriously degrade or shut down a large part of the electric power grid," with the potential that significant parts of electric infrastructure could be “out of service for periods measured in months to a year or more."

He also cited a 2010 study by Oak Ridge National Laboratory as finding that "EMP and GMD events pose substantial risk to equipment and operation of the Nation’s electric grid and under extreme conditions could result in major long-term electrical outages," that "GMD disturbances are inevitable with only the timing and magnitude subject to variability," and that a solar storm such as occurred in 1921 "could damage or destroy over 300 bulk power system transformers interrupting service to 130 million people with some outages lasting for a period of years." Director McClellan clarified that subsequent analysis suggested that in case of such an event, "the power grid may collapse before significant damage was done to transformers; resulting in a potentially wide-spread, but relatively short, power outage."

Director McClellan also spoke to the Federal Energy Regulatory Commission's "dual-fold approach" to address these threats: employing mandatory standards to establish foundational practices while also working collaboratively with industry, the states and federal agencies to identify and promote best practices to mitigate advanced threats. According to a report released in 2018 by the U.S. Government Accountability Office, U.S. and Canadian electricity suppliers have taken steps to prepare for potential electromagnetic disruptions, but more research is needed on both geomagnetic disturbances and high-altitude electromagnetic pulses.

US warns of Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure

Thursday, March 22, 2018

The U.S. Department of Homeland Security has warned that for at least two years, Russian government cyber actors have targeted government entities and multiple U.S. critical infrastructure sectors, including the energy, nuclear, commercial facilities, water, aviation, and critical manufacturing sectors.

In a joint Technical Alert issued March 15, 2018 by the Department of Homeland Security's U.S. Computer Emergency Readiness Team (US-CERT) and the Federal Bureau of Investigation, the agencies warned of a "multi-stage intrusion campaign by Russian government cyber actors." The report follows an October 2017 alert by computer security firm Symantec of a re-emergence of a sophisticated cyber espionage group known as "Dragonfly."

According to the government agencies' report, the Russian cyber threat actors seem to have deliberately targeted specific organizations, as opposed to pursuing targets of opportunity. In an initial "staging" phase, the campaign used tools like malware, watering holes, and spear phishing to gain access to small commercial facilities' networks -- typically peripheral organizations like trusted third-party suppliers whose networks may be less secure. For example, the threat actors sent emails with malicious attachments appearing to be personnel resumes or contract documents. Clicking on links in the attachments exposed the victims to malware or data harvesting. In a subsequent phase, the threat actors made further use of the staging targets' networks as "pivot points and malware repositories" for use in targeting their final intended victims.

The report says that these Russian government cyber actors used this hacked access for network reconnaissance and collection of information pertaining to Industrial Control Systems (ICS). It describes multiple instances of threat actors accessing workstations and servers on corporate networks that contained data output from control systems within energy generation facilities.

Cyber security is now a significant concern, both domestically and abroad. A February 2018 report by the U.S. intelligence community described the targeting of national security information and proprietary information from US companies and research institutions involved with defense, energy, finance, dual-use technology, and other areas as "a persistent threat to US interests." Last month, U.S. electric grid reliability regulators imposed a $2.7 million penalty on an unidentified utility for its violations of mandatory reliability standards in connection with a data security breach -- the largest fine to date associated with U.S. utility cybersecurity regulation. In that case, a third-party contractor hired by the utility allegedly copied protected data from the utility's network to the contractor's unsecured network -- where it was accessible online without the need to enter a user ID or password, and where it was in fact accessed by one or more unknown outside entities.

In 2014, reports emerged that Russian hackers had found flaws in solar panel monitoring software that, if left unfixed, could allow malicious actors to damage the electric grid. Foreign state-sponsored cyber attacks in 2016 and 2017 against Ukraine and Saudi Arabia targeted multiple sectors across critical infrastructure, government, and commercial networks, causing disruption to Ukrainian energy distribution networks.

FERC ends DOE resilience rulemaking, opens new proceeding

Tuesday, January 9, 2018

U.S. energy regulators have terminated a fast-tracked proceeding opened last fall to consider rules proposed by the Department of Energy that would have compensated certain electric generating plants for reliability and resilience values; instead, the Federal Energy Regulatory Commission has opened a broader case to examine the resilience of the bulk power system.

On September 29, 2017, Secretary of Energy Rick Perry directed the Commission to consider a proposed rulemaking to ensure that "traditional baseload resources, such as coal and nuclear" are rewarded for their reliability and resilience attributes. As proposed, the rule would have required grid operators to set rates for compensation paid to certain "grid reliability and resiliency resources" with a 90-day fuel supply on site and capable of providing "essential energy and ancillary reliability services, including but not limited to voltage support, frequency services, operating reserves, and reactive power."

The request under Section 403 of the Department of Energy Organization Act bore an expedited timeline. The Commission solicited public comments on the proposed rulemaking, and Commission staff issued a series of questions to frame the discussion. Many comments expressed concerns that rapid changes to wholesale markets could have harmful or perverse effects, and prior to yesterday's most seated Commissioners had publicly expressed reservations.

On January 8, 2018, the Commission issued its Order Terminating Rulemaking Proceeding, Initiating New Proceeding, and Establishing Additional Procedures.  In doing so, it recognized "that we must remain vigilant with respect to resilience challenges, because affordable and reliable electricity is vital to the country’s economic and national security." The order recites a history of the evolution of the electric power industry and the Commission's efforts to help ensure bulk power system resilience, including the adoption of NERC reliability standards, reforms to capacity markets and gas-electric coordination.

But the Commission found that neither the Department of Energy's proposed rulemaking nor the record in the case satisfied a key legal standard for Commission action under Section 206 of the Federal Power Act. Specifically, it concluded that the existing tariffs had not been demonstrated to be unjust, unreasonable, unduly discriminatory or preferential.

The Commission also noted potential problems with the proposed rule. For example, it said that allowing all eligible resources to receive a cost-of -service rate regardless of need or cost to the system had not been demonstrated to be just and reasonable, and that the proposed rule's on-site 90-day fuel supply requirement hadn't been shown not to be unduly discriminatory or preferential -- but that it would exclude some resources with resilience attributes.

At the same time, the order states, "The resilience of the bulk power system will remain a priority of this Commission." It continued, "Although the Proposed Rule failed to satisfy the fundamental legal requirements of section 206 of the FPA, the Proposed Rule and the record developed to date have shed additional light on resilience more generally and on the need for further examination by the Commission and market participants of the risks that the bulk power system faces and possible ways to address those risks in the changing electric markets." Noting "a variety of economic, environmental, and policy drivers that are changing the way electricity is procured and used," the Commission said these changes "present new opportunities and challenges regarding the reliability, affordability, and environmental profile of each region’s electric system."

To address these changes, the Commission initiated a new proceeding, Docket No. AD18- 7-000, to take additional steps to explore resilience issues in organized wholesale electricity markets. According to the order, the goal of this proceeding is: "(1) to develop a common understanding among the Commission, industry, and others of what resilience of the bulk power system means and requires; (2) to understand how each RTO and ISO assesses resilience in its geographic footprint; and (3) to use this information to evaluate whether additional Commission action regarding resilience is appropriate at this time."

The Commission directed six regional transmission organizations and independent system operators to respond within 60 days with comments on the definition of resilience, plus how they assess and mitigate threats to resilience. The Commission also solicited public comment within 30 days of the grid operators' due date.