Hiển thị các bài đăng có nhãn Smart Grid. Hiển thị tất cả bài đăng
Hiển thị các bài đăng có nhãn Smart Grid. Hiển thị tất cả bài đăng

It's Hard for Utilities to Improve Security when Their Business Models are Increasingly Insecure


This one's not about security, unless you consider the well-being of the utilities who own and operate most of the grid to be security related.  In which case this post is completely about security!

Greentech Media (GTM) has just written a short piece highlighting some of the take-aways of a new Edison Electric Institute (EEI) report called "Can the Utility Industry Survive the Energy Transition?" and I'd say both the GTM article and the full EEI report are well worth your attention.

Here are a couple of GTM excerpts for you ... the first on what EEI identifies as a "vicious cycle," where:
... the industry's decline will make it harder to pass on the costs of providing service, because customer rates are tied to usage. As usage declines, the costs of new investment must be passed on to a shrinking pool of customer demand, which in turn forces per-unit prices higher still. As those prices rise, investment in efficiency and renewables becomes even more cost-effective, which shrinks usage further. Ultimately, these dynamics could leave a small number of customers supporting the costs of a large chunk of grid infrastructure, leaving utilities with "stranded investments."
And then a potentially ominous ripple effect:
It could become very difficult for [Investor Owned Utilities], IOUs to remain profitable, which will test the loyalty of investors. Brokerage firms are forecasting earnings per share of 4 percent to 7 percent for IOUs, EEI notes, but if the utilities aren't able to meet these investor expectations, "a wholesale reevaluation of the sector is likely to occur."
Keep this in mind as the NERC CIPs, the Executive Order on Critical Infrastructure Cybersecurity, and other initiatives seek to find ways to incentivize more spending on security.  This is not a stable playing field; the ground is shifting beneath utilities' feet.

You can see the GTM piece HERE and reach the full EEI report HERE.

Conference Alert: AGRION Energy & Sustainability

On Feb 19, one of the year's best energy and sustainability conferences will be kicking off in NYC. It's organized  by a great org I've become familiar with recently: AGRION, a global business network for energy, cleantech and corporate sustainability.

On the second day, following a morning keynote by PSE&G CEO Ralph Izzo, I'll be moderating a panel of experts on the topic "Smart Grid Market: Scope and Scale":
  • Kevin Genieser, Managing Director & Head of Clean Energy & Renewables, Morgan Stanley
  • Joe Callis, Sr. Applied Solutions Engineer, PJM Interconnection
  • David Groarke, Smart Grid Senior Analyst, Greentech Media
To be sure, I'll work in an appropriate amount of security substance. After all, you can't deploy a Smart Grid that's easy to disrupt, right?

You can see the full agenda, list of speakers and venue details HERE. Hope some SGSB readers can make it.

ENISA Again: 3rd Time's the Charm re European Grid and Smart Grid Security Policy

8/29 Update:

You still have a few days to register and get your plane or train tickets to Amsterdam. In one fell swoop, the existence of this 10/15 workshop, in itself, fully refutes charges of lack of US-European cooperation, as well as claims that control system security is ignored. Go HERE to learn more and register.

---------------------------------------

While of monologues many great political speech or play are constructed, it's through dialogue we reach understanding and consensus. Wait, who said that?

This blog first posted on the European Network and Information Security Agency (ENISA) and its recent recommendations for EU energy sector security earlier this month.





Since then I've received a good deal of reader feedback, some of it supporting statements made in that post and some refuting. The most definitive and best of the latter, I believe, comes from the organization
itself.

Here then, are 2 of the original critiques, followed by ENISA's detailed responses, just in:

1. "It contains no call for cooperation with US-CERT, FERC or equivalent body on problems that are clearly of interest to both sides. Compare with various DHS initiatives (such as DHS ICSJWG) which have included foreign participants."
ENISA responds: On moves towards EU-US cooperation, and concerns that the report does not explicitly call for this, to allay any concerns, we would point out that the European Union, including ENISA, is already working closely with the US government on cyber security issues through the Joint EU-US Working Group on Cyber-Security and Cyber-Crime (EU-US WG). As such, not only does it encourage but also promotes cooperation between the US bodies and the relevant European ones. 
Looking specifically at smart grids, an example of this cooperation is ENISA's support for the forthcoming Joint EU-US Open Workshop on the Cyber Security of ICS and Smart Grids. Our smart grids security report reflects the views of the experts who participated in the study, and while there is support for closer cooperation and sharing of information, there is not as yet a consensus on how a workable framework could be established.  (For details of the survey process, go HERE.)

2. "ENISA reports do not adequately address control systems."
ENISA responds: We'd like to set the record straight by pointing your readers towards an ENISA report published last year that is exclusively about control systems. This gives recommendations on ICS security for the European Union Member States and bodies. The report can be found HERE.
I am satisfied. Actually more than satisfied and happy to have seen this discussion all the way through, and I've added ENISA to the "Key Players - Gov" group on the blog's right side bar.

However, if you remain peeved or perturbed, then by all means please contact ENISA yourself with your certain-to-be-constructive comments and criticisms.

Mr. Graeme Cooper is the man you want to speak with and his sig block looks like this:

Graeme Cooper
Head of Public Affairs Unit
European Network and Information Security Agency (ENISA)
email: graeme.cooper@enisa.europa.eu

OK?  Gut. Bueno. Bien. Etc.

Perhaps Better Fettered: 2nd Thoughts on ENISA's Cybersecurity Report from this Side of the Pond

Had a number of reader responses to this week's post on the European information security organization's proclamation of intent and recommendations for the electric sector and Smart Grid. 

My post welcomed the attention to the issue by the EU, but expressed, hopefully in a mainly professional way, that this feels, to invoke a common American idiom, a day late and a dollar short.

Here are two additional observations I got:
1. One US respondent says "It contains no call for cooperation with US-CERT, FERC or equivalent body on problems that are clearly of interest to both sides. Compare with various DHS initiatives (such as DHS ICSJWG) which have included foreign participants."
Concur. References to SANS, NIST and DHS in the bibliography notwithstanding, it does appear that explicit calls for trans Atlantic, interagency cooperation are missing, and that this should be rectified in a next version.
2. Another true blue American notes "ENISA reports do not adequately address control systems."
While the bibliography is littered with entries for SCADA and Control Systems-related texts, it doesn't seem like much of that research made it into the final document. Still, while most of the 10 recommendations involve getting ready to get ready to do something, and control system security seems to be largely glossed over, there is, in requirement 6, language that might point to operational systems at some point:
Recommendation 6. Both the EC and the MS competent authorities should promote the development of security certification schemes for components, products and organisational security.
So I'll leave it at that for now. Would welcome an ENISA response. I always try to not be too hard on 1.0 documents because there's always the chance, if not the likelihood, that we'll see them improve in subsequent versions.

I know it doesn't want to be a fetterer, but my sense is that Europe will come to see the wisdom of getting a bit more explicit and comprehensive in these matters.  I know from experience that some of its utilities are looking for more guidance. OK? Back to the Olympics!