U.S. Energy Secretary Steven Chu has announced an initiative to further protect the electrical grid from cyber attacks. The â€śElectric Sector Cybersecurity Risk Management Maturityâ€ť project, a White House initiative led by the Department of Energy in partnership with the Department of Homeland Security (DHS), will leverage the insight of private industry and public sector experts to build on existing cybersecurity measures and strategies to create a more comprehensive and consistent approach to protecting the nationâ€™s energy delivery system.
â€śThis initiative is another important step forward in improving the security of the nationâ€™s energy infrastructure and ensuring that the countryâ€™s electrical systems remain secure, reliable and resilient,â€ť said Secretary Chu. â€śEstablishing a comprehensive cybersecurity approach will give utility companies and grid operators another important tool to improve the gridâ€™s ability to respond to cybersecurity risks.â€ť
â€śThis effort will be focused on performance-based strategies and concrete steps to measure progress of cybersecurity in the electric sector,â€ť said White House Cybersecurity Coordinator Howard A. Schmidt. â€śIt is important to understand the sectorâ€™s strengths and remaining gaps across the grid to inform investment planning and research and development, and enhance our public-private partnership efforts.â€ť
This newest initiative will develop a â€śmaturity modelâ€ť that allows utility companies and grid operators to measure their current capabilities and analyze gaps in their cyber defenses. Maturity models, which rely on best practices to identify an organizationâ€™s strengths and weaknesses, are widely used by other sectors to improve performance, efficiency and quality.
To launch the initiative, officials from the Energy Department, the White House and DHS met with more than two dozen senior leaders from across the electric sector. Over the next several months, the Department will host a series of workshops with the private sector to draft a maturity model that can be used throughout the electric sector.
More than a dozen electric utilities and grid operators are expected to participate in the pilot program to test the maturity model, assess its effectiveness and validate results. This public-private partnership and pilot program will help develop a risk management maturity model that is expected to be made available to the electric sector later this summer.
As cyber threats to the nationâ€™s electrical grid become increasingly sophisticated and dynamic, the Department of Energy is continuing to work closely with DHS, other government agencies, and industry to reduce the risk of energy disruptions due to cyber incidents. For example, in September, the Department released both the Roadmap to Achieve Energy Delivery Systems Cybersecurity and a Cybersecurity Risk Management Process Guideline that establish frameworks and processes to help the electricity sector manage cybersecurity risk.