The US Approach to Cybersecurity in the Energy Sector
摘要
In recent years, the US energy infrastructure has undergone rapid advancements in digitization, including the emergence of smart grid technologies and the overall deployment of information and communication technologies. However, this evolved infrastructure has coincided with the increased exploitation of technological vulnerabilities leading to a rise in cyberattacks that have grown in both occurrence and complexity. As the USA continues to implement these upgrades, malicious cyberattacks on the North American electric grids are steadily escalating. The ability of threat actors to infiltrate and harm the nation’s energy assets, such as transmission or distribution systems, through cyber methods has become a significant concern for energy utilities, particularly due to its critical role in bulk electric systems. Moreover, despite federal and state efforts to eliminate risk, there are limitations. Among the most significant challenges to promoting cybersecurity include insufficient understanding of the attacks and the absence of a swift and strategic approach to threats. This chapter outlines how the digitization of the energy sector has increased cybersecurity risks, evaluates the measures taken by both US private sector energy infrastructure owners and government entities to protect national security, and analyzes best practices for prevention and response to cyber threats and risks. In addition, this chapter specifically examines the role of California’s adoption of advanced cybersecurity initiatives as a use case for future developments. Policy recommendations include implementing well-defined security standards supplemented with ongoing audits, administering security awareness training for grid experts, allocating budgets for improving security posture, enhancing information sharing, pursuing incentives to hiring sufficient talent, applying maturity assessments, implementing financial and tax incentives, insuring operational technology (OT) systems, adjusting federal jurisdictions, sustaining industry partnerships, and participating in flexible procedures. One of the many findings conveyed here is that aligning federal, state, and private sector approaches to meet these policy recommendations is crucial in strengthening US cybersecurity readiness and resilience in the energy sector. Adopting these recommendations could strengthen cybersecurity norms and ultimately reduce the risks for energy infrastructures. Addressing vulnerabilities is crucial as the energy grid is responsible for society’s most crucial infrastructures, spanning from health to transportation to communication services. As a large part of the global economy is driven exceedingly by energy, it is critical that steps are taken to address the potential hazards faced to governments and societies.