Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Protecting the Smart Grid From Cyber Threats
Articles

Protecting the Smart Grid From Cyber Threats

ISBuzz TeamBy ISBuzz TeamAugust 15, 2014Updated:July 3, 20245 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

In October 2008, an assassination attempt against exiled former Pakistani Prime Minister Benazir Bhutto was carried out by al-Qaeda operatives in the form of a roadside bombing of her caravan. The first sign that an attack was about to occur, according to witnesses, was the sudden switching off of public streetlights along the roadway. That attack claimed the lives of nearly 140 people and serves as a morbid example of how modern terrorists are taking a much more sophisticated approach. Now more than ever, the public infrastructures of nations are at greater risk to be penetrated, infiltrated and controlled by unsanctioned individuals or groups looking to do harm.

Some might look at the example of a Pakistani terrorist attack and dismiss it as a regional anomaly – that could never happen in the United States, right? Consider this: in March 2014, the North American Electric Reliability Corporation (NERC) released the results of its GridEx II exercise, carried out in November 2013. The report revealed that nearly all the 2,000-plus utilities that participated in a two-day drill testing the preparedness to withstand cyber and physical attacks were deemed “insufficient.” This included utilities in North America, Canada and Mexico. And in May 2014, the Department of Homeland Security (DHS) confirmed that there had been a cyberattack attempted against an undisclosed U.S. public utility that succeeded in compromising its control system network.

Just as companies are required to protect their networks from internal and external security threats, the smart grid must be secured from rogue forces seeking to disrupt the safe distribution of power. This is where the NERC’s Critical Infrastructure Protection (CIP) rules fit in.

NERC’s CIP standard specifically focuses on the security of the power supply, which can include the grid infrastructure itself and power generation facilities like wind farms, nuclear power plants, and more. The NERC CIP standard is important because it was designed to reduce cyber threats by proactively managing the technology of the smart grid. It outlines six key requirements for transmission stations, transmission substations and their associated primary control centers.

1.) Risk assessments must be performed on a periodic basis to identify critical transmission stations and substations, as well as the primary control center for each.

2.) An unaffiliated third party must verify that risk assessment.

3.) Transmission owners must give notice of its identification and obligations to a transmission operator that controls a primary control center.

4.) Transmission owners and operators must conduct an evaluation of the potential threats and vulnerabilities of a physical attack to each identified critical facility.

5.) Transmission owners and operators must develop and implement a documented physical security plan that covers each of its identified critical facilities.

6.) An unaffiliated third party must review the physical security plan developed by the owner and operator.

When looking at these six key requirements, companies seeking to do business with smart grid utilities, transmission owners, operators and any technology partners might be wondering who is required to take precautions. Currently, NERC is focused on the “big guys,” such as the bulk power system owners, operators and users. However, we see several specific areas where NERC will eventually need to provide additional guidance for cyber and physical security.

First, the electricity providers have to follow best cybersecurity practices. In other words, they need to know who has been granted access to systems that install, upgrade, and manage the smart grid technology. They also need to check regularly to ensure the networks controlling these devices are not breached, and they must select high-quality technology with built-in protections. There are benefits and risks to rolling out systems that can automatically and seamlessly communicate with each other. The benefit is that it creates a smoothly operating grid. But remember that smart grids are digital, and if best practices aren’t followed for things like password protection, weak points in the grid can cause far-reaching problems.

Secondly, the energy industry uses contractors heavily, both for office work and for installation, upgrades, and maintenance to the infrastructure itself. As numerous data breaches in the enterprise and government sectors have demonstrated, contractors can often be a weak security link. Contractors need to be properly vetted and trained and must adhere to the same security practices with controls in place to make sure they do not have too much access. Most importantly, their access to network architecture and systems must be removed immediately when their work or contract period is finished.

Third, buildings and businesses that sign up for digital regulators from their power companies should also have a backup plan. Keep in mind that if a utility has the ability to turn power off remotely, it is possible that someone could intercept the connection and cause havoc.

In 2013, the Industrial Control Systems Cyber Emergency Response Team (ICS-CERT), a division of DHS, responded to a total of 256 cyber incident reports against federal systems. More than half of these attacks were aimed at assets in the energy sector. That is nearly double the agency’s 2012 caseload. While there was not a single incident that caused a major disruption with the smart grid, there is clearly a trend at work among cyber criminals, and the law of averages suggests that the more attempts are made, the more likely one of them will succeed. The energy sector will need to rely on IT security best practices to decrease those odds and keep the positive energy flowing.

By Kevin Jones, Information Security Architect, Thycotic Software

About Thycotic Software

thycotic_logoThycotic deploys smart, reliable, IT security solutions that empower companies to control and monitor privileged account credentials and identity access for administrators and end-users. An Inc. 5000 company, Thycotic is recognized as the fastest growing privileged management vendor in IT security and one of the top 30 fastest growing companies headquartered in Washington, DC.

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

The Real Cost of Inconsistent Third-Party Access

December 18, 20255 Mins Read

What Happens When Devices Cross Borders? The Role of Geofencing in Global IT

August 7, 20256 Mins Read

The Evolving Importance of Identity Governance in FinTech

July 10, 20258 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}