Energy Central EnergyPulse Home
Home Subscribe Login Contribute to Energy Pulse Advertise on Energy Pulse About Energy Pulse Feedback to Energy Pulse
Search Articles:   
  You are here: Home > Grid Operations > Article Display


Free Newsletter
Sign up today for your free subscription to the EnergyPulse Weekly Update - delivered directly to your e-mail box.
e-mail:


 

Communicating Smart Meter Value

Sep 9 2010 - 2010-01-01 12:00:00 - Your City

If you are involved in Management or Customer Service and are responsible for communicating the value of smart meters to your utility customers, you don’t want to miss this online discussion - Communicating Smart Meter Value.  more...

Social Media: The new frontier in recruiting, communications and marketing

Sep 13 2010 - 2010-01-01 12:00:00 - Your City

Join social media mavens Matthew Burks and Amanda Shewmake as they provide an insider's perspective on how HR, communications and marketing professionals in energy companies can harness the power of social media to be more effective and productive. more...

Eliminating Obstacles and Delivering the Benefits of the Smart Grid - IBM's Optimized Energy Value Chain (OEVC)

Sep 14 2010 - 2010-01-01 12:00:00 - Your City

The convergence of power and information technologies in the smart grid has created opportunities for finer grained and broader controls of energy flows. These opportunities can improve electric service in multiple dimensions: lower cost, greater reliability, greater customer satisfaction, and more...

Achieving Operational Excellence - What to Consider Before Implementing or Upgrading Your Distribution Management Solutions

Sep 16 2010 - 2010-01-01 12:00:00 - Your City

Significant cost over runs. Changing business requirements. A well thought out plan is essential. Attend this free webcast discussion to hear inside hear three experts in utility operations discuss what utilities need to evaluate when they are considering upgrading or more...

Outsmarting the Smart Grid: IT, Security and Communication Infrastructure  Challenges & Opportunities for Utilities

Sep 21 2010 - 2010-01-01 12:00:00 - Your City

The smart grid is shifting the playing field for utilities. And when the game changes, it pays to be prepared. A nimble solutions partner can help you design the solutions that keep operations on track, even as new challenges come more...

1st CSP Today Concentrated Solar Thermal Power Summit India

Sep 7 2010 - Sep 8 2010 - New Delhi India

Deliver a profitable, productive and commercially successful large scale CSP business in India. Building on the success of past events in USA, Europe & MENA, CSP Today brings to New Delhi the most relevant international experience for the concentrated solar more...

Offshore Wind Energy in North America's Great Lakes Conference

Sep 9 2010 - Sep 10 2010 - Toronto

Two day conference that tackles the most important challenges. A blend of European knowledge from the companies who have been installing offshore wind turbines for the last decade alongside local state governing bodies and leading project developers. Permitting, securing long more...

Autovation 2010

Sep 12 2010 - Sep 15 2010 - Austin, TX - USA

Autovation 2010 is a not-to-miss educational forum that will attract utility executives from around the world looking for new ways to optimize their operations through automation technologies. more...

Global Sustainable Bioenergy North American Convention

Sep 14 2010 - Sep 16 2010 - Minneapolis, MN - USA

The North American convention provides a remarkable opportunity to play a part in guiding renewable energy policy for the 21st century. Attendees will create a resolution that, along with similar resolutions already drafted on four other continents, will help set more...

GridWise Global Forum

Sep 21 2010 - Sep 23 2010 - Washington, DC - USA

Hosted by the GridWise(R) Alliance and the U.S. Department of Energy, the GridWise Global Forum will convene thought leaders from the highest levels of government, business, NGOS, and academia from around the world to discuss the ultimate enabling potential of more...

1. Intro to Nat Gas Trading & Hedging 2. Option Applications in Energy

Sep 20 2010 - Sep 23 2010 - Houston, TX - USA

Introduction to Natural Gas Trading & Hedging - This program provides a comprehensive understanding of the structures that underlie Natural Gas trading. Beyond Essentials: Option Applications in Energy - This course provides a solid practical and conceptual (non-quantitative) understanding of more...

Electric Business Understanding Seminar

Sep 20 2010 - Sep 21 2010 - Houston, TX - USA

Electric Business Understanding provides a comprehensive overview of the electric industry. Position yourself for career advancement by gaining a solid understanding of how the electric business works including key physical, market, and regulatory aspects and how market participants navigate this more...

Electric Market Dynamics Seminar

Sep 22 2010 - Sep 23 2010 - Houston, TX - USA

Electric Market Dynamics offers participants an in-depth understanding of North American electric markets and how they function. Enhance your career by furthering your knowledge of market structures, pricing mechanisms, services offered in markets, and how various participants use the markets more...

Gas and Electric Business Understanding Seminar

Oct 5 2010 - Oct 6 2010 - Los Angeles, CA - USA

Gas and Electric Business Understanding provides a comprehensive overview of the natural gas and electric industries. Position yourself for career success by gaining a solid understanding of how each business works, including key physical, market and regulatory aspects, as well more...

Energy Central
Power Network




Grid Operations


We know you have something to say!
There is an immediate need for articles on the hot topics in the Power Industry! EnergyPulse, like no other publication, also provides a means for our readers to immediately interact with experts like you.
 
Contribute Today!
Please view our Author Guidelines and send submissions to the editor.

Click For More Articles on Grid Operations
 
Cyber Security for a Smarter Grid
9.23.09   Russ Holder, Vice President of System Engineering & Integration, Intergraph
Tom Babst, Program Manager, Intergraph

Article Viewed 5701 Times
2 Comments
E-mail Article Printer Friendly
 
  • Comment On Article
  • About The Author
  • More Articles By This Author

  • Email This Author
  • Comment On Article
  • About The Author
  • More Articles By This Author
    Long gone are the days when cyber attackers were teenagers in their basements writing viruses and sending them out across the World Wide Web for entertainment and notoriety. Today's cyber attacks are sophisticated, targeted and have insidious motives such as profit/extortion and terrorism. Attackers are going after organizations that cannot afford to experience any downtime, such as ecommerce sites, banks, telecommunications providers and utilities, and demanding money in exchange for restoring or not disturbing their networks. Additionally, evidence suggests the use of cyber attacks against the U.S. by foreign powers as a form of warfare, i.e., cyber terrorism or cyberwarfare.

    Critical infrastructure including power plants and utilities has become an increasing target of cyber attack over the past five years or so. In fact, the CIA has linked at least one widespread power outage affecting multiple cities outside of the United States to cyber attack.

    While attacks by criminals and terrorists are most alarming, threats can also come from other groups such as disgruntled employees or competitors. Cyber incidents can also occur by accident without the involvement of third parties. For example, last summer, a botched software update on a single computer caused a power plant in Georgia to shut down for two days, strongly revealing the need for airtight security policies and employee training for all utilities.

    At the same time that criminals and terrorists begin to hone in on utilities as targets of sophisticated cyber attacks, utility networks are becoming more open and connected to the Internet to achieve self-healing smart grids. Smart grid can be defined as an intelligent system of automated devices and advanced sensors that create a self-healing network and allow for the incorporation of alternative energy sources into the grid to provide more sustainable energy for the future. A large component of smart grid is the use of Supervisory Control and Data Acquisition (SCADA) technology, which allows for the remote control of systems via the Internet. While most systems in the IT world are now more secure and prepared to handle the evolving threat landscape, control systems were not built with these types of sophisticated attacks in mind and therefore do not contain the same safeguards as other systems. Connecting them to open business systems makes them very vulnerable to intrusions. In other words, the smart grid is unfortunately not yet smart enough to resist cyber attacks.

    Additional factors contributing to the severe danger of cyber incidents on utilities include the fact that cyber attacks are often not easily recognized, and can therefore be difficult to identify and remediate, as well as the fact that utilities like water and electricity are vital to our daily lives, and their disruption can cause significant equipment and environmental impacts including death.

    In addition to dealing with evolving threats, utilities are now forced to take a closer look at cyber security due to impending legislation that will make it a requirement. Government agencies such as the Federal Energy Regulatory Commission (FERC), self-regulatory organizations like the North American Electric Reliability Corporation (NERC), and state public utility and service commissions currently regulate and enforce reliability standards and policies for electricity generation and transmission. All of these organizations are in the process of investigating and developing more advanced cyber security and critical infrastructure protection (CIP) policies, as well as potentially moving into the regulation of electricity distribution.

    All of these factors, combined with the Obama administration's heightened focus on critical infrastructure protection, of which cyber security will play a major role, are creating a perfect storm for utilities operators in terms of cyber security. It is simply a facet of doing business for utilities that can no longer be ignored or downplayed.

    Key steps in developing security plans include:

    • identifying critical assets and assessing the risk of each asset to attack;
    • developing security management controls such as proactive risk mitigation, enforcement of security policies, change management, centralized control of the security infrastructure, access management, Intrusion Prevention Systems (IPS), Network Access Controls (NAC), Network Access Protection (NAP), application whitelisting, etc.;
    • conducting vulnerability tests and remediating weaknesses with tools such as firewall and intrusion prevention technology;
    • incorporating security into the product development cycle;
    • developing plans, policies, processes and procedures for continued protection;
    • developing and executing recurring cyber security awareness and training programs;
    • implementing physical security plans for the protection of critical cyber assets;
    • developing a standard plan for recording and responding to incidents.
    While this may seem like a lot of steps, they are all intertwined and required for achieving a more impenetrable network. For instance, without first methodically identifying all critical assets and determining their respective risks, it would be impossible to develop a sound security plan. Additionally, protecting critical assets from cyber intrusions, for example, would be pointless if they were not also physically secured.

    A comprehensive, multi-pronged security approach not only provides utilities with robust protection against attacks and other incidents, but also enables organizations to achieve compliance with necessary government and industry mandates. It is expected that such cyber security mandates and requirements will continue to expand in the coming years, making the development of a comprehensive security plan at the present time even more crucial for all utilities.

    Overall, the main message to utilities is that the time to develop, revamp or re-evaluate your cyber security plan is now. As both cyber attackers and utility grids become smarter, security is evolving as a crucial piece of the puzzle. Without a comprehensive security plan, the resiliency and self-healing aspects of the smart grid become obsolete, leaving us with a grid that is not only very porous and unintelligent, but also quite dangerous.

    For information on purchasing reprints of this article, contact Tim Tobeck ttobeck@energycentral.com.
    Copyright 2010 CyberTech, Inc.
     
    E-mail Article Printer Friendly
     
  • Click Here For More Articles on Grid Operations


  • Click Here For More Articles By Russ Holder
  • Do you agree or disagree with this article? Send in your own article.

     

    Readers Comments

    Date Comment
    Don Hirschberg
    9.30.09
    A bit off topic, but there was a brief period when we hanged horse thieves while some killers might go free. As a judge explained, “I’ve known men who needed killing but I never knew a horse that need stealing.” The point of course is that a lone man, no matter how diligent, in most cases cannot prevent his horse from being stolen. Perhaps cyber criminals ought to be treated like horse thieves of yore?

    Len Gould
    10.1.09
    Agreed, Don, much more severe penalties should be implemented for such. However, its likely to be very difficult to track down then extradite such attackers from eg. remote corners of Russia, China, India or Africa etc.

    BTW, I was told as a child that the reason horse-thieves were hung was that stealing a man's horse while he was out rounding up cattle alone was effectively killing him (eg. easy to get too far from life support to walk out).

    Add your comments:
    Please log in to leave a comment!

    Top

        Home | Register | Subscribe | Contribute | Advertise | About Us | Feedback
       Copyright © 2002-2010, CyberTech, Inc. - All rights reserved. Read our Terms of Service.