Grid cyber rules architect: squirrels outpace hackers — SkimNews

Get the Energy newsletter
Daily energy & climate — solar, EVs, oil, the policy fights and tech bets shaping the transition. Free.
- Patrick Miller helped write the original NERC Critical Infrastructure Protection cybersecurity standards for the US bulk power grid in the 2000s and became the first person with delegated federal authority to enforce them.
- US grid companies have experienced documented cybersecurity intrusions, but attackers have only pre-positioned themselves — actual blackouts from cyberattacks have occurred in Ukraine and Poland, both attributed to Russia.
- Chinese-made power electronics (inverters, transformers, controllers) dominate US grid buildouts, but the source describes fears of embedded 'kill switch' malware as 'less sinister than they sound.'
- NERC CIP standards cover the bulk power system but exclude distributed energy resources below set thresholds; regulators are pushing to lower the threshold to 20 MVA and pull more assets inside the federal perimeter.
- State utility commissioners typically arrive with extreme views — either dismissing all cyber risk or believing 'China is here to eat your children' — because they often come from legal rather than technical backgrounds.
- Data centers and AI are expanding grid attack surfaces, with the episode pointing to cyber-informed engineering and analog safeguards as emerging defensive strategies.
Why it matters: Miller's authority — having written the rules and audited utilities under federal delegation — gives regulators a rare reality check at a moment when documented US utility intrusions are mounting but no confirmed grid-damaging cyberattack has occurred on US soil. The China-inverter threat, he suggests, is more commodity-supply-chain than 'kill switch,' a distinction that matters as NERC weighs expanding its perimeter.
Ask SkimNews




