Grid Vulnerability Warnings Continue
Just over a year ago I summarized a Scientific American article that pointed out how at risk the U.S. power grids are, regardless of what the Sun might do:
- Every facet of the modern electrical grid is controlled by computers. It is our greatest example of physical infrastructure interlinked with electronics.
- The Stuxnet virus that infected Iran’s nuclear program showed just how vulnerable machines could be to a well-crafted electronic virus.
- The grid shares many of the vulnerabilities that Stuxnet exposed; being larger, its vulnerabilities are, if anything, more numerous.
- A sophisticated attack could bring down a large chunk of the U.S. electrical grid.
A lot easier to achieve than most terrorist activities, and something that has already been used against Iraq.
Now we have a report from the U.S. Government Accountability Office, pointing out the very same, and noting that the government has ignored their previous recommendations.
Varying types of threats from numerous sources can adversely affect computers, software, networks, organizations, entire industries, and the Internet itself. These include both unintentional and intentional threats, and may come in the form of targeted or untargeted attacks from criminal groups, hackers, disgruntled employees, nations, or terrorists. The interconnectivity between information systems, the Internet, and other infrastructures can amplify the impact of these threats, potentially affecting the operations of critical infrastructures, the security of sensitive information, and the flow of commerce. Moreover, the electricity grid’s reliance on IT systems and networks exposes it to potential and known cybersecurity vulnerabilities, which could be exploited by attackers.
As GAO previously reported, there were a number of ongoing challenges to securing electricity systems and networks. These include:
- A lack of a coordinated approach to monitor industry compliance with voluntary standards.
- Aspects of the current regulatory environment made it difficult to ensure the cybersecurity of smart grid systems.
- A focus by utilities on regulatory compliance instead of comprehensive security.
- A lack of security features consistently built into smart grid systems.
What GAO Recommends
In a prior report, GAO has made recommendations related to electricity grid modernization efforts, including developing an approach to monitor compliance with voluntary standards. These recommendations have not yet been implemented.

