Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Critical Infrastructure Cybersecurity topic
No spam. Unsubscribe anytime.
NSA-funded study flags cyber vulnerabilities in Oregon electric grid; researchers call for secure briefing and systemwide approach
Summary
Presenters summarized a multi-state NSA-funded study showing critical vulnerabilities in the power grid, urged interdisciplinary mitigation, and asked the governor's office to host a secure briefing for elected officials and infrastructure leaders because detailed findings are controlled unclassified information.
Get email alerts on the Critical Infrastructure Cybersecurity topic
No spam. Unsubscribe anytime.
Researchers who led an NSA-funded, multi-state study on power-grid cybersecurity briefed the Joint Legislative Committee on Information Management and Technology Feb. 28 and urged a systems approach to address gaps in infrastructure, workforce and incident response.
Birro Yashileda, founding director of the Oregon Cybersecurity Center of Excellence, and Turul Daim, professor of engineering and technology management at Portland State University, told the committee the study examined physical and cyber interdependencies across the grid and is classified as controlled unclassified information (CUI), so they cannot release detailed technical findings in a public hearing. Yashileda said the multi-state project took two years to complete, covered five states and produced a detailed technical report; he described the public summary and asked the governor’s office to convene a secure briefing for committee members, agency directors and industry partners.
The presenters described a set of high-priority gaps and threats: aging infrastructure that is costly to replace, vulnerabilities at substations and distribution points, social-engineering and insider-threat risks, and supply-chain concerns such as components with embedded malware. "We identified substation vulnerabilities and points where an adversary can move from a local utility into broader grid systems," Yashileda said. The presenters also discussed the accelerating role of artificial intelligence: while AI can help detect anomalous network traffic and improve response, it can also enable more adaptive attacks and data-poisoning techniques.
The researchers highlighted the strategic threat environment they assessed: their presentation discussed nation-state actors that have probed or infected critical infrastructure and warned that both information warfare and physical attacks across networks require coordinated technological and policy responses. Because much of the study’s granular evidence is CUI, the team requested a secure session to present findings and recommended increased tabletop exercises, shared monitoring of key network traffic, and investment in workforce and interoperable incident response capabilities.
Committee members asked whether utilities coordinate on cybersecurity. Presenters said cooperation exists through industry associations and regional structures, but investments and capacities vary by utility type (investor-owned, public, co-op) and many public or small utilities lack the funds to underwrite large R&D or resilience investments. The presenters said federal funds and public–private partnerships will be needed to address the most costly infrastructure gaps.
The presenters offered to provide committee members a secure briefing with the governor’s office and to follow up with a non-classified summary of high-level recommendations suitable for public circulation.
