Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Grid Cybersecurity topic
No spam. Unsubscribe anytime.
Vermont utilities describe layered cybersecurity programs; DPS outlines annual review process
Summary
State utilities told the House Energy and Digital Infrastructure Committee on May 13 that they maintain layered cybersecurity programs, private communications infrastructure and regular audits, while the Department of Public Service described a PUC-approved annual meeting and reporting process for cyber incidents.
Get email alerts on the Grid Cybersecurity topic
No spam. Unsubscribe anytime.
The House Energy and Digital Infrastructure Committee heard an overview of grid cybersecurity on May 13, 2025, as the Vermont Department of Public Service and representatives from Vermont Electric Power Company (VELCO), Green Mountain Power and Burlington Electric Department explained how they run and oversee cybersecurity programs and how they report incidents to state agencies.
Bill Jordan, director of engineering at the Vermont Department of Public Service, told the committee that a Public Utility Commission order issued Dec. 11, 2019, established a process for the Department to convene annual, in-person meetings with electric utilities to discuss cybersecurity programs and coordination. "This order…provides a final order approving a statement of principles relative to cybersecurity for electric utilities," Jordan said, and described the order’s requirements that each utility maintain a cybersecurity program, offer briefings to the Department on request, and report certain incidents to the commissioner.
The nut graf: the meeting combined a description of the formal process the Department follows under the PUC order with utility-level summaries of security practices — including private fiber and data centers, separation of business and control systems, external audits and employee training — and a discussion of how and when utilities notify state and federal agencies about cyber events.
VELCO’s chief technology officer, Dan Nelson, told the committee the transmission operator keeps its control infrastructure on private fiber and in private data centers and separates business and control systems. "We have our own private data center," Nelson said, adding that VELCO operates two data centers and that "one of them is built to sustain an electromagnetic pulse." He said VELCO is audited regularly by regional and federal regulators and that a Federal Energy Regulatory Commission audit last year produced no significant findings in preliminary remarks.
Representatives of distribution utilities described similar multi-layered approaches. Mark Vincheco, chief technology executive at Green Mountain Power, said GMP relies on external frameworks and audits, is building a security operations center, and emphasizes employee training as a key defense. "Mostly gone are the tactics that you used to see…Most everything in the last few years has transitioned over to phishing attacks," he said.
Erica Furlan, director of IT at Burlington Electric Department, described recent investments in people and technology and a program of frequent phishing tests. "We're sending this to 500,000 emails…now we're seeing the level of sophistication where phishing emails are targeted," Furlan said. She also told the committee that BED retired its traditional VPN in February in favor of a zero-trust solution after seeing "6 requests a second hitting that VPN, many of them with known users." Burlington also hosted Department of Energy-funded operational technology training provided by Idaho National Labs, Furlan said.
Jordan summarized the PUC order’s reporting thresholds: utilities must notify the Department of Public Service if a cyber incident results in release of confidential customer information or a compromise of grid reliability. He explained that paragraph 5 of the order also provides for an annual Department briefing to the PUC after the Department’s meetings with utilities. "Paragraph 4 requires that the utility report to the commissioner of Department of Public Service if the attack results in the release of confidential customer information or a compromise of grid reliability," Jordan said.
Committee members asked about public disclosure and legislative notification. Utility witnesses described multi-agency notification protocols — including federal and state entities such as the Department of Homeland Security, FBI and sector information-sharing organizations — and said publicity decisions are guided by crisis-communications plans and the nature of the incident. Nelson said VELCO typically notifies federal information-sharing channels (EISAC) and partner agencies; he noted an instance in which VELCO notified state authorities "out of an abundance of caution" despite no evidence of data release.
Committee members also asked about supply-chain vetting and equipment security. Nelson said the applicable standard requires product evaluation and vendor vetting and characterized the process as ongoing. "SIP 13…requires us to go through an evaluation of the products that we purchased," he said (as stated in testimony).
Throughout the hearing the utilities and the Department emphasized routine collaboration and continuous improvement — annual in-person briefings under the PUC order, external audits (including NERC/FERC/NPCC oversight for transmission-level entities), third‑party penetration testing and expanded employee training. Several witnesses said they have seen rising volumes of probing activity but no recent successful intrusions that compromised grid operations in Vermont. "There have been attempts continuously…it's kind of like how many raindrops does your roof see," Nelson said.
The committee did not take formal action. Jordan said the Department expects to convene the 2025 annual cybersecurity meeting with utilities possibly in late summer or early fall and will offer its oral briefing to the PUC after that meeting as the order requires.
Ending: The hearing documented the procedures and practices Vermont utilities use to protect the grid and the formal, PUC-approved process the Department of Public Service uses to review utility cybersecurity annually. Committee members indicated interest in clearer public-notification triggers and in continued oversight as the cyber threat landscape evolves.

