RSS Amplifier

Marco's Substack · Jul 31, 2026

The Grid Has No Moat

0
Sign in to vote or save

Marco Polo · Marco's Substack

Energy abundance is incomplete if the system cannot be defended and restored. The commercial grid was built to serve customers, not to withstand coordinated physical and cyber stress. In a dangerous world, compliance must become readiness.

The Most Important Machine Is Also Exposed

The American electric grid has no moat.

It crosses mountains, farms, forests, rivers, highways, suburbs, cities, and back roads. Its substations sit behind fences. Its transformers are heavy, specialized, and difficult to replace quickly. Its control rooms depend on operators, software, sensors, telecommunications, vendors, contractors, and judgment exercised under pressure. Its fuel systems depend on pipelines, rail lines, ports, roads, storage sites, compressors, water systems, and electricity from the grid itself.

For most of the modern era, this openness was treated as a practical necessity. The grid had to be everywhere because electricity had to be everywhere. The public learned to treat power as invisible infrastructure. Utilities learned to plan around reliability, maintenance, weather, load growth, and cost. Regulators learned to ask whether a proposed investment was prudent, necessary, and affordable.

Those questions still matter. But they are no longer enough.

A more dangerous world has changed the meaning of energy policy. Cyber intrusion, physical sabotage, drones, domestic extremism, hostile states, ransomware, supply-chain manipulation, fuel disruption, telecom failure, and coordinated misinformation can all touch the energy system. None of these risks is purely theoretical. None can be dismissed as the plot of a movie. Yet none should be used to frighten the public into helplessness.

The correct response is not panic. It is seriousness.

The uncomfortable truth is that a system can be reliable in ordinary conditions and still be underprepared for abnormal intent. It can pass required exercises and still lack the reserves, training, equipment, communications, and institutional confidence needed for a major event. It can comply with standards and still discover, under stress, that compliance was not the same thing as readiness.

That distinction belongs near the center of any serious discussion about the Independence of Power.

The Headlines Have Already Happened

Readers do not need a classified briefing to see the pattern. The public record already contains enough examples to move energy security from imagination to governance.

• Metcalf, California, 2013: a major transmission substation was attacked and critical equipment was damaged. The incident did not cause a large outage, but it revealed how much consequence can be concentrated in remote high-voltage assets.

• Moore County, North Carolina, 2022: gunfire attacks on substations cut power to more than 45,000 customers for several days.

• Pierce County, Washington, 2022: four substations were attacked over the Christmas holiday, causing millions of dollars in damage and leaving thousands without power.

• Baltimore, Maryland, 2023: federal authorities announced the disruption of an alleged extremist plot to attack electrical substations around the city.

• Colonial Pipeline, 2021: a ransomware attack forced the shutdown of a major fuel pipeline network that carries nearly half of East Coast fuel supplies.

• Volt Typhoon, 2024: federal agencies said a China-linked actor had compromised networks across multiple U.S. critical-infrastructure sectors, including energy.

These events are not identical. Some were criminal, some ideological, some cyber, some physical, some domestic, and some tied to foreign state capability. That variety is precisely the point. Energy security is not a single-risk problem.

The lesson is also not that the grid is doomed. Several events were contained. Some plots were disrupted. Some attacks caused local outages but not cascading regional failure. The right conclusion is that preparedness works when it is real, practiced, funded, and connected across agencies and sectors.

Compliance Is Not Readiness

Compliance is necessary. It creates minimum expectations, auditable requirements, documented procedures, and accountability. Without compliance, the energy system would be more uneven and more dangerous. Standards matter.

But compliance is not a fortress. It is a floor.

A utility can complete a tabletop exercise, document a drill, satisfy a checklist, and still wonder whether the organization could perform under a coordinated physical and cyber event that unfolds during extreme weather, with public communications strained, field crews stretched, fuel logistics uncertain, and replacement equipment unavailable. The people closest to field security often understand this difference better than the people reading the after-action reports.

That is not an accusation that commercial utilities are careless. Many are serious. Many invest heavily in security. Many participate in information-sharing organizations, exercises, mutual-aid structures, and emergency planning. The issue is structural. The commercial grid is vast, dispersed, cost-regulated, owned by many entities, governed through overlapping jurisdictions, and judged heavily by affordability and service restoration. It was not built like a military installation.

The result is an uncomfortable gap between routine reliability and adversarial resilience.

Routine reliability asks: Can the system serve load under expected conditions and recover from ordinary failures? Adversarial resilience asks: Can the system keep critical functions alive and recover quickly when someone is deliberately trying to make recovery harder?

Those are different questions. They require different planning assumptions. They also require different regulatory incentives. A utility cannot be expected to build true resilience if prudent security investments are treated as optional overhead, if spare equipment is difficult to justify in a rate case, if exercises are evaluated more for completion than consequence, or if distribution-system risks fall between state and federal lines of responsibility.

The grid does not need fewer rules. It needs rules that distinguish paper readiness from operational readiness.

What Nuclear Security Reveals

Nuclear security offers a useful comparison - not because nuclear is perfect, and not because the wider grid can or should be turned into a nuclear plant perimeter, but because nuclear has long operated under high-consequence adversarial assumptions.

Commercial nuclear plants are governed by a security culture that assumes some threats must be confronted directly. Facilities operate under physical protection requirements, access controls, armed security, intrusion detection, barriers, emergency planning, cyber protections, and exercises tied to defined adversary characteristics. The Nuclear Regulatory Commission has used force-on-force inspections to test physical protection against a design basis threat. These exercises are not merely paperwork; they are intended to probe whether a protective strategy can actually defend key equipment from realistic attack scenarios.

That kind of posture shapes behavior. It teaches an organization to think in terms of adversaries, not just equipment failures. It forces attention to access, response time, communications, coordination, training, command structure, and the consequences of a successful breach. It creates a different expectation: readiness must be demonstrated, not merely described.

The broader commercial energy system is different. A transmission substation in a rural area, a distribution control system, a pipeline compressor station, a telecom relay, a transformer yard, or a water treatment plant connected to grid operations may be critical to public life without being protected by the same culture of high-consequence security.

That difference is not necessarily irrational. Not every asset deserves the same protection. Risk-based security is essential. The country cannot put a paramilitary guard force around every pole, wire, pump, and transformer. But risk-based security must still be honest about consequences. Some assets that do not meet a federal definition of bulk-system criticality may still be critical to a city, hospital region, military installation, data-center cluster, water system, or emergency-services network.

The lesson from nuclear is not that every energy asset must look nuclear. The lesson is that security culture matters. The question is whether commercial energy has a culture strong enough for the world now emerging.

The Bulk Grid Is Not the Whole Grid

The United States often discusses grid reliability as though the bulk power system were the whole story. That is understandable. High-voltage transmission, large generators, balancing authorities, wholesale markets, and reliability coordinators are central to keeping power moving across regions. They deserve strong federal standards.

But the customer does not live on the bulk power system. The customer lives at the end of the distribution system.

Distribution networks carry electricity to homes, schools, factories, data centers, hospitals, water systems, fuel stations, communications facilities, and public-safety operations. They increasingly host distributed energy resources, batteries, demand-response controls, electric-vehicle charging, smart meters, aggregators, and automated management systems. They are becoming more digital, more interactive, and more operationally important.

Yet distribution is largely regulated by states, and many distribution utilities are generally not subject to the same mandatory federal cybersecurity standards that apply to the bulk system. The Government Accountability Office has warned that distribution systems are becoming more vulnerable to cyberattacks as remote access and business-network connections expand, while federal planning has historically focused more on generation and transmission.

This is a jurisdictional problem with practical consequences.

An adversary does not care whether an asset is regulated by FERC, a state commission, a municipal board, a cooperative, a private vendor, or no one with a complete view of the system. The adversary cares whether disruption produces leverage. The public cares whether the hospital has power, the water system functions, the fuel pumps operate, emergency communications remain available, and the lights come back on.

The Independence of Power therefore cannot stop at generation and transmission. It must include distribution resilience, local restoration, critical-load protection, and the ability to operate essential services when the wider system is impaired.

The Software-Defined Grid

The grid is becoming more intelligent. That is good. It needs to become more intelligent.

Advanced sensors, automated controls, grid-enhancing technologies, inverter-based resources, batteries, distributed energy resources, cloud platforms, AI-enabled forecasting, flexible data-center loads, and demand response can all help the system operate with more precision. They can reduce waste, relieve congestion, improve visibility, and allow loads and resources to respond to real conditions.

But intelligence creates dependence. Dependence creates attack surface.

A grid that relies on software, communications, cloud services, remote access, vendor updates, automated aggregators, machine-learning tools, and connected devices must treat those systems as part of the grid itself. A control path is not just a business system. A demand-response platform is not just a customer-service tool. A DER aggregator is not just a market participant. When remote instructions can affect electrical behavior, the communication and control system becomes energy infrastructure.

NERC has identified the convergence of information technology and operational technology, reliance on cloud-based technology, emerging AI tools, distributed management systems, Internet-of-Things devices, outage-management systems, and automation as factors increasing the cyber attack surface. It has also warned that the use of common technologies, protocols, and network connections across many distribution resources could expand the scale of potential cyber impact.

This does not mean modernization should stop. It means modernization must be secure by design.

The international warning has already been written. In 2015, Russian state-sponsored actors conducted cyber operations against Ukrainian energy distribution companies that led to unplanned outages. In 2024, U.S. agencies warned that Volt Typhoon activity had compromised critical-infrastructure networks in the United States, including energy-sector organizations. The lesson is not to fear software. The lesson is to treat control paths, vendors, credentials, communications, cloud dependence, and manual fallback as part of the energy system itself.

A flexible grid that cannot be trusted is not resilient. It is merely more complicated. Flexibility must be contractual, measurable, dispatchable, tested, and secured. Large loads that promise flexibility should also demonstrate secure control, ride-through behavior, fallback procedures, and coordination with system operators. Distributed resources that provide grid value should be governed by cyber and operational rules proportionate to the role they play.

The next grid will be cyber-physical. Its security must be cyber-physical as well.

The Recovery Problem

No security strategy can promise to prevent every failure. It should not pretend otherwise.

The real measure of resilience is what happens after disruption begins. Can operators see what is happening? Can they communicate when normal systems are degraded? Can they isolate damage? Can they reroute power? Can they keep critical loads alive? Can they move field crews safely? Can law enforcement secure damaged sites? Can replacement equipment be deployed? Can a black-start sequence proceed? Can public officials speak with confidence? Can the public trust the instructions it receives?

For many energy assets, the limiting factor is not only prevention. It is recovery time.

Large transformers illustrate the point. They are not ordinary spare parts. They can weigh hundreds of tons, be custom-made for specific applications, require specialized transportation, and involve long procurement timelines. A sophisticated attack that damages critical transformers is not the same thing as a storm knocking out a neighborhood feeder. It can become a logistics and manufacturing problem, not merely a repair problem.

That is why resilience requires more than cameras and fences. It requires spare-equipment strategies, mobile substations, standardization where practical, protected communications, black-start capability, fuel assurance, mutual-aid agreements, trained operators, manual fallback procedures, and exercises that test the restoration chain from the control room to the field.

The Metcalf attack is often discussed as a resilience success because electric service was not interrupted. That should not make the event comfortable. It should make the lesson clearer: the boundary between contained damage and a wider crisis can depend on redundancy, operator action, equipment availability, restoration planning, and luck. Moore County showed the other side of the same lesson. A small number of damaged sites can leave ordinary communities without power, close schools, interrupt businesses, strain public safety, and force residents to learn infrastructure dependence the hard way.

Recovery is where the difference between compliance and readiness becomes visible. A plan can look adequate in a binder and fail in the field because the radio path is down, the spare is incompatible, the access road is blocked, the needed contractor is unavailable, the cyber team cannot trust the telemetry, or the local police do not know which asset must be secured first.

Energy security is not merely the prevention of attack. It is the ability to continue serving the public while absorbing the attack.

Interdependence Is a Security Issue

The electric grid is not alone. It is intertwined with nearly every other system that keeps modern life functioning.

Electricity powers water treatment, wastewater systems, fuel pumps, communications, emergency operations, hospitals, traffic control, banking, grocery logistics, refrigeration, public safety, and increasingly transportation. Natural-gas systems rely on electricity for compression and controls, while many gas plants rely on pipelines and gas deliverability during extreme weather. Telecommunications support grid operations, but telecom sites also depend on electricity and backup fuel. Data centers depend on the grid, while the grid increasingly depends on data, cloud platforms, and communications services.

This interdependence creates efficiency in normal times and complexity in crisis.

An event that begins in one sector can cascade into others. A power outage can impair water pressure or communications. A telecom failure can reduce operational visibility. A cyberattack on a vendor can create uncertainty about equipment status. A fuel disruption can limit generation or backup power. A public communications failure can turn a difficult outage into a public-order problem.

Colonial Pipeline was not an electric-grid outage, but it belongs in this chapter because it revealed how quickly cyber risk in one energy system can become a public problem in another. Fuel logistics, emergency generators, utility field operations, hospitals, transportation, and public confidence do not exist in separate worlds. The energy system is a web, and a failure in one strand can tighten the whole net.

The old mental model of the grid as a standalone electric machine is no longer sufficient. The grid is now part of a larger operating organism. Security planning must therefore include water, telecom, fuel, hospitals, emergency management, law enforcement, local governments, data-center operators, and critical industrial customers.

The public does not need to know every operational detail. But the public does need to know that these dependencies exist and that readiness means practicing across them.

Data Centers Change the Security Equation

Large data centers are usually discussed in terms of load growth, cost allocation, interconnection, water use, local tax revenue, and generation supply. Those questions remain essential. But data centers also change the security discussion.

A single large campus can represent hundreds of megawatts of demand. A cluster can reshape a regional load profile. If designed well, some computing loads may provide flexibility by delaying noncritical work, using on-site storage, shifting tasks, or supporting demand-response arrangements. If designed poorly, concentrated load can increase dependence on specific substations, corridors, generation resources, water systems, telecom routes, and control platforms.

This makes data centers both a challenge and an opportunity.

They should not be treated as ordinary commercial customers when their scale creates system consequences. Large-load interconnection should require credible security and resilience planning: secure controls, emergency coordination, ride-through expectations where appropriate, clear curtailment rules, on-site backup responsibilities, cyber-risk management, and contribution to the infrastructure their demand requires.

The goal is not to keep AI or cloud infrastructure from growing. The goal is to ensure that the digital economy strengthens national capacity rather than concentrates risk. A data center that consumes city-scale power should be expected to behave like a serious participant in the energy system, not merely a customer with a large meter.

Energy abundance and digital ambition must be matched by security discipline.

The False Comfort of Imports

When a region lacks sufficient power, the easiest political answer is often to import more. Build a line. Reach farther. Draw from another region. Move the burden somewhere else.

Transmission can be necessary and valuable. It can improve resilience, unlock productive generation, connect regions with complementary conditions, and help recover from local events. The previous chapter argued for a broad transmission toolbox precisely because wires are part of a serious energy architecture.

But importing power is not the same as securing power.

If the supply at the other end is also tight, transmission simply moves scarcity more efficiently. If a region becomes dependent on a small number of import corridors, those corridors become higher-value targets. If imported power depends on external fuel, external regulation, external politics, or distant equipment, the receiving region may have shifted its vulnerability rather than reduced it.

This is especially important in an era when energy supply chains themselves are strategic. Transformers, control systems, inverters, turbines, enriched uranium, reactor components, critical minerals, software, sensors, semiconductors, and specialized labor all determine whether energy infrastructure can be built and restored. Energy independence does not mean isolation from allies. It means the country has enough domestic and allied industrial depth to avoid being coerced by suppliers that do not share its interests.

That is why the Rosatom example matters in the nuclear discussion. Russia has treated nuclear power as an end-to-end strategic enterprise: design, construction, fuel, financing, service, training, export relationships, maritime nuclear capability, and emerging SMRs. The lesson is not that America should imitate Russia’s state model. The lesson is that other powers understand nuclear energy as strategy, not merely as electricity.

The same principle applies to the grid. A country that cannot make, replace, secure, and govern the equipment that carries its power has not achieved energy independence. It has rented it.

A National Energy Security Readiness Standard

America needs a practical security agenda that moves beyond fear and beyond slogans. The purpose should not be to federalize every local utility decision or impose identical requirements on every asset. The grid is too varied for that. The purpose should be to establish a national expectation: critical energy systems must be able to withstand, operate through, and recover from high-consequence disruption.

That expectation should become part of the rules of abundance.

A National Energy Security Readiness Standard would not reveal sensitive details to the public. It would establish the categories of readiness that regulators, utilities, emergency managers, and major customers must be able to demonstrate.

The standard should include:

The public-facing list of vulnerabilities is now familiar enough to be taught without theatrics: extreme weather, aging infrastructure, cybersecurity lapses, physical attacks, insider or extremist threats, and rising demand. Each has a corresponding remedy. The purpose of naming them is not to produce fear. It is to turn fear into a practical work program.

Security Readiness Agenda

• Risk-based hardening of high-consequence substations, transformers, control centers, telecommunications dependencies, and fuel-linked assets.

• Distribution-level cyber and physical security planning, with state and federal coordination where local failure would create regional or critical-service consequences.

• Mandatory recovery-time objectives for critical loads such as hospitals, water systems, emergency operations, military facilities, communications, and fuel infrastructure.

• Strategic transformer reserves, mobile substations, component standardization where practical, and transport plans for damaged or replacement equipment.

• Secure communications fallback for grid operations, including degraded-mode procedures when ordinary data paths cannot be trusted.

• Regular joint exercises involving utilities, law enforcement, emergency management, water utilities, telecom providers, hospitals, fuel suppliers, large loads, and state and federal partners.

• Clear cost-recovery mechanisms for prudent security and resilience investments, so utilities are not penalized for preparing for risks the public depends on them to manage.

• Security requirements for large loads whose sudden loss, manipulation, or restoration needs could affect system operation.

• Supply-chain security for inverters, relays, transformers, control software, firmware, cloud services, sensors, communications equipment, and other grid-critical components.

• Workforce pipelines for operational technology security, field protection, substation engineering, system restoration, cyber incident response, and command coordination.

From Fear to Agency

The purpose of a chapter like this is not to leave readers afraid. It is to move them past the most dangerous form of fear: the fear that begins with, “I did not know that,” and ends with helplessness.

The vulnerabilities are real. They are also addressable.

Physical hardening can reduce easy targets. Better surveillance and law-enforcement relationships can improve deterrence and response. Cyber hygiene can close common paths of compromise. Secure-by-design engineering can reduce dependence on fragile controls. Spare equipment and standardization can shorten recovery. Microgrids can keep critical services operating. Black-start capability can restore larger systems. Mutual-aid agreements can move crews and equipment. Training can reveal weak assumptions before a crisis reveals them publicly. Domestic manufacturing can reduce dependence on distant suppliers. Clear cost recovery can turn resilience from discretionary expense into public infrastructure.

This is the constructive point: energy security is not a mystery. It is a choice.

America knows how to build disciplined security cultures where consequences are high. It has done so in nuclear facilities, military systems, defense logistics, aviation, intelligence, and other critical sectors. The question is whether the country will now apply enough of that seriousness to the commercial energy systems on which every other ambition depends.

The answer should be yes.

Security Is Part of Abundance

Energy abundance is usually discussed in terms of production: more generation, more transmission, more fuel, more factories, more reactors, more storage, more capacity. That is necessary. A country facing large new loads and industrial ambition cannot manage scarcity forever.

But abundance without security is fragile. A power plant that cannot be fueled, a transformer that cannot be replaced, a control system that cannot be trusted, a distribution network that cannot be restored, and a critical service that cannot island during crisis all expose the public to the same uncomfortable truth: prosperity depends on continuity.

This is why stewardship belongs in the security discussion. Good stewardship is not only about using fewer resources or building cleaner power. It is about preserving the public’s ability to live, work, communicate, heal, produce, defend, and recover when the world is not calm.

The Independence of Power therefore means more than freedom from imported fuel. It means freedom from energy fragility. It means domestic and allied industrial capability. It means hardened and recoverable infrastructure. It means utilities, regulators, customers, and communities sharing a realistic understanding of risk. It means a grid that is not merely efficient on a spreadsheet, but resilient under pressure.

The next energy crisis may not begin with a shortage. It may begin with a switch, a substation, a software exploit, a ship lane, a transformer order, a fuel route, or a supplier that no longer answers the phone.

A serious nation does not wait for that moment to discover whether it was ready.

It prepares while the lights are on.

Source Notes

The factual context in this essay draws principally from the following current public sources. The essay avoids operational details that could aid malicious actors and treats security as a governance, readiness, and resilience issue rather than a tactical manual.

1. North American Electric Reliability Corporation, 2025 ERO Reliability Risk Priorities Report, approved July 22, 2025 and accepted August 14, 2025. Used for the critical risk profiles of grid transformation, resilience to extreme events, critical infrastructure interdependencies, security, and energy policy; for simultaneous changes in resource, grid, and load; and for NERC statements on cyber/physical security complexity, supply-chain challenges, AI, cloud, telecommunications dependence, DER aggregators, and physical-security incident categories. Link: NERC 2025 RISC Report

2. Federal Energy Regulatory Commission, “Presentation | Evaluation of the Physical Security Reliability Standard and Physical Attacks to the Bulk-Power System,” April 20, 2023. Used for the discussion of CIP-014 as a baseline requirement; E-ISAC-reported physical security incidents; the Moore County substation attack; the Baltimore-area extremist plot; the challenge of minimum protections; risk-based hardening; cost recovery; mobile substations; standardization; and law-enforcement relationships. Link: FERC physical-security presentation

3. U.S. Government Accountability Office, Electricity Grid Cybersecurity: DOE Needs to Ensure Its Plans Fully Address Risks to Distribution Systems, GAO-21-81, March 18, 2021, with recommendation status updated through March 2026. Used for distribution-system cyber risk, state/federal jurisdiction issues, remote access and business-network connections, supply-chain vulnerabilities, and the open recommendation that DOE more fully address distribution-system risks. Link: GAO-21-81

4. U.S. Department of Energy, Office of Cybersecurity, Energy Security, and Emergency Response (CESER), About the Office of Cybersecurity, Energy Security, and Emergency Response; Energy Sector Cybersecurity Preparedness; and Infrastructure Hardening and Technology Development pages, accessed July 2026. Used for DOE descriptions of physical, cyber, economic, and geopolitical threats; integrated cyber and physical security; cross-sector dependencies; CRISP; C2M2; CyTRICS; Cyber-Informed Engineering; and RMUC utility hardening and workforce support. Links: DOE CESER overview; Energy Sector Cybersecurity Preparedness; Infrastructure Hardening and Technology Development

5. U.S. Nuclear Regulatory Commission, Backgrounder on Force-on-Force Security Inspections, updated October 7, 2024. Used for the nuclear-security contrast: force-on-force inspections, design basis threat, tactical exercises, mock adversary forces, Special Operations Command advisors, plant security forces, barriers, detection, surveillance, and access controls. The essay uses this comparison to discuss security culture, not to suggest the broader grid can be protected in the same manner. Link: NRC Force-on-Force Security Inspections

6. Utility Dive, Michelle J. Howard, “America’s aging grid threatens national security. Here are some steps to fix it,” January 24, 2024. Used for national-security framing around aging transmission infrastructure, weather impacts, direct physical attacks, Colonial Pipeline as an energy-infrastructure cyber example, the national-security role of transmission, and the argument for stronger planning and cost allocation. Link: Utility Dive article

7. Quartz, Jack Shaw, “The 6 biggest vulnerabilities in the power grid,” updated October 13, 2025. Used as a public-facing vulnerability framework covering extreme weather, outdated infrastructure, cybersecurity lapses, physical infrastructure attacks, insider threats, and rising electricity demand. The essay treats it as illustrative rather than primary authority. Link: Quartz article

8. Congressional Research Service, Physical Security of the U.S. Power Grid: High-Voltage Transformer Substations, R43604. Used for high-voltage transformer exposure, the Metcalf attack, the difficulty of transformer replacement and transport, and the distinction between preventing attacks and limiting consequences. Link: CRS R43604

9. Associated Press, “Gunfire damages North Carolina substation, no outage caused,” January 2023. Used for the follow-on North Carolina incident and for AP’s summary that the earlier Moore County gunfire attacks knocked out power to more than 45,000 customers for several days. Link: AP North Carolina substation article

10. U.S. Department of Justice, Western District of Washington, “Two charged with attacks on four Pierce County power substations,” January 3, 2023. Used for the Pierce County Christmas 2022 attacks, the $3 million damage estimate, and the law-enforcement framing of attacks on energy facilities. Link: DOJ Pierce County substations

11. Associated Press, “Woman plotted with neo-Nazi to attack power grid, feds say,” February 2023. Used for the Baltimore-area extremist plot and the larger point that power-grid targeting has entered domestic extremist planning. Link: AP Baltimore grid plot article

12. Reuters/Voice of America, “Cyberattack Shuts Down Top US Fuel Pipeline Network,” May 8, 2021. Used for Colonial Pipeline, ransomware, the temporary shutdown of a network carrying nearly half of East Coast fuel supplies, and the interdependence of fuel logistics, public confidence, and energy security. Link: VOA / Reuters Colonial Pipeline article

13. CISA and partner agency advisories on Volt Typhoon and Russian state-sponsored cyber threats. Used for critical-infrastructure cyber warnings, reported compromises in energy-sector networks, and the 2015 Ukrainian distribution-company outages attributed to Russian state-sponsored activity. Links: CISA Volt Typhoon advisory; CISA Russian cyber threats advisory

14. U.S. Department of Energy, Addressing Security and Reliability Concerns of Large Power Transformers; Transformer Resilience and Advanced Components Program; and related July 2024 Large Power Transformer Resilience materials. Used for transformer customization, cost, transportation difficulty, long procurement timelines, strategic transformer-reserve concepts, and the importance of transformer standardization and resilience. Links: DOE large power transformers; DOE TRAC Program; DOE Large Power Transformer Resilience report

15. U.S. Government Accountability Office, Electricity Grid: DOE Could Better Support Industry Efforts to Ensure Adequate Transformer Reserves, GAO-23-106180, April 2023, with 2026 status notes. Used for the adequacy of transformer reserves, supply-chain constraints, manufacturing lead times, limited capacity, labor/material shortages, and DOE support for common transformer configurations. Link: GAO-23-106180

16. CISA, Cross-Sector Cybersecurity Performance Goals, and energy-sector cybersecurity baseline materials. Used for the broader point that critical-infrastructure security increasingly requires practical baseline cyber hygiene for both information technology and operational technology owners and operators. Link: CISA Cross-Sector Cybersecurity Performance Goals

17. NERC GridEx materials and 2025 RISC report references to GridEx. Used for the fact that the electric sector conducts major distributed cyber/physical exercises, while the essay distinguishes participation in exercises from demonstrated readiness under high-consequence field conditions. Links: NERC E-ISAC / GridEx; GridEx VIII Lessons Learned Report

18. Prior Independence of Power series framing and user-provided source set, including articles on heat-driven substation stress, PJM demand warnings, data-center cost allocation, and transmission opposition. Used for continuity with the series argument that security must be integrated with generation, grid modernization, large-load policy, consumer protection, and national energy abundance. Links: Evening Sun / Littlestown substations; U.S. News / Reuters PJM demand warnings; The Conversation data-center cost allocation; Delmarva Farmer transmission-line opposition; Utility Dive grid flexibility / PJM governance

No posts

Read the original on reimaginingbroadcast.substack.com

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.