The U.S. Department of Homeland Security (DHS) issued a warning on Monday that Russian-backed hackers have penetrated the control rooms of electric utilities and gained the ability to "operate switches," potentially causing blackouts, with the operation allegedly affecting "hundreds" of targets. The news sent shockwaves through the electric power industry, as security concerns were already a top priority for industry leaders.

However, some grid security experts have questioned DHS's characterization, especially claims that hackers could trigger blackouts on a large scale. Robert Lee, CEO of cybersecurity firm Dragos, said in an emailed statement: "The language around 'operating switches' and 'causing blackouts' is misleading about the impact of this attack. What was observed is indeed concerning, but the picture of an imminent blackout does not match reality."

"The possibility of localized action does exist, but the grid will not collapse tomorrow, next year, or in the near future."

— Joe Slowik, Threat Hunter at Dragos

Experts point out that DHS's findings, first shared with electric industry leaders a year ago, indicate that attackers are monitoring power systems and could cause localized disruptions, but cannot yet trigger widespread blackouts. Joe Slowik, a threat hunter at Dragos, said: "The current activity suggests reconnaissance and environment preparation—information needed to execute some future action. The possibility of localized action does exist, but the grid will not collapse tomorrow, next year, or in the near future."

In Washington, the Trump administration has used security concerns to push for retaining uneconomical coal and nuclear power capacity, claiming that threats to gas pipelines constitute a grid emergency. However, utilities say there is no imminent blackout threat based on cybersecurity concerns. Scott Aaronson, vice president of security and preparedness at the Edison Electric Institute (EEI), said: "Grid operators have been working closely with the government over the past year to address this threat. So there is no emergency today; we are well aware of these threats and have been working to mitigate them since being briefed."

Threat Analysis

Monday's DHS briefing was part of raising awareness of cyber threats to energy infrastructure, but Slowik said that since the initial disclosure in July 2017, "not much has changed." The difference lies in the agency's characterization of the threat, especially claims that attackers could operate power switches and that the attack affected hundreds of victims.

Slowik said: "When you combine these two, it sounds very scary—there are hundreds of places where malicious actors could operate switches to cause blackouts, but that's not the case. Based on the attack methods and the adversary, these operations are very manual and require human intervention." Causing a widespread blackout would require simultaneously disrupting multiple critical power facilities, which might require automated attacks of a sophistication not yet observed among hackers.

Experts believe that if adversaries move from reconnaissance to direct attack, they might briefly disrupt power in a single city, but are unlikely to affect an entire region. Alexander Heid, chief research and development officer at SecurityScorecard, said: "Being able to access the grid and operate switches is indeed a real threat. But if it happens, it will affect a localized area and will not cause a nationwide blackout."

Such an attack might resemble the 2015 Russian-backed hackers' attack on Ukraine, which cut power to parts of Kyiv for hours, rather than the 2003 weather-related blackout in the Northeast, which left multiple states and Canadian provinces without power for days. Slowik said: "In the Ukraine attack, everything before deploying the malware was manual, so it couldn't be scaled in a country as large as Ukraine, let alone the United States."

The Grid's "Inherent" Defenses

Although experts agree that even a brief blackout in a major city would have serious consequences, the complexity of the large grid and individual energy assets makes problems naturally difficult to spread. Slowik said: "The grid is a system of systems, where components interoperate but are also isolated from each other. To cause a cascading blackout, the near-term risk is minimal because the grid is designed to handle natural disasters, lightning strikes, and so on."

Individual power assets also provide natural protection due to their unique operating systems, known as industrial control systems. Aaronson said: "Industrial control systems are the most important assets of the grid, but also the most unique, so their configuration and deployment have inherent security." To operate enough switches to cause a cascading blackout, hackers would need to design unique exploits for each target system. Slowik said: "In that case, I think it would be cheaper to drop a bomb directly."

In Washington, the Trump administration has paid particular attention to natural gas pipeline control systems, which a leaked spring memo described as "increasingly vulnerable to cyber and physical attacks." As a result, the White House in March directed the Energy Department to prepare to retain retired coal and nuclear power capacity, arguing that their on-site fuel supplies are safer than gas plants relying on pipelines. But cyber experts point out that every type of energy infrastructure has threats. Coal plants have fuel but rely on cooling systems that could be hacked, need transmission lines, and are large, centralized targets.

Slowik said: "Every form of power generation has weaknesses. As long as someone has the motivation to find them. Thinking coal or nuclear power is unhackable and reliable ignores the real pain points of these generation types." Heid noted that upgrades to existing assets could increase internet connectivity, bringing new threats. He said: "These large critical infrastructures previously had no internet connection; now they're being 'upgraded,' meaning they're more accessible and usable, which is a double-edged sword for users and attackers alike." Sometimes upgrades can expose critical infrastructure to the internet without operators knowing. Heid mentioned that SecurityScorecard once found an IP address where pressing a button could open an entire hydroelectric dam, with no password, and the company was unaware.

Security and Human Nature

Mike Legatt, CEO of Resilient Grid (who holds doctorates in neuropsychology and power systems engineering), warns that the greatest risk from cyber threats may come from our reactions, not adversary activity. He said: "The risk of reacting to perceived risk is higher than the perceived risk itself." Legatt worries that panic over Russian hackers could lead policymakers to design hasty solutions, such as subsidizing aging power plants. He said: "Our people care deeply about system security, so they tend to react quickly, creating anything we think can get us out of danger."

"The point of critical infrastructure is that it is always under attack."

— Mike Legatt, CEO of Resilient Grid

Some experts believe this may already be happening. Earlier this month, the Federal Energy Regulatory Commission (FERC) issued new rules expanding the scope of cyber threat reporting for utilities and their suppliers, requiring reports of attempted attacks, not just successful ones. Slowik worries that if the rule is finalized, it will "flood" FERC and the North American Electric Reliability Corporation (NERC) with information on minor hacking attempts, making it harder to identify real threats. He said: "This desire to control threats leads to decisions that may do more harm than good, because of information overload and the inability to focus on the right information." FERC directed NERC to revise the reporting requirements within six months, which Slowik believes gives entities time to narrow the scope of investigations. He said: "Unless someone seriously thinks about what constitutes an intrusion attempt, this rule will produce more noise than value."

Legatt urges utility leaders and policymakers not to change proven technologies for ensuring reliability just because the threat comes from hackers rather than hurricanes or wildfires. He said: "The point of critical infrastructure is that it is always under attack. The grid always keeps the lights on by responding to severe storms. When you focus on maintaining system reliability, you anticipate, think about, and isolate future attacks. In that sense, I think this fits the same paradigm."