US Grid Cyber Risk: Real Threats vs. Hype

Get the Energy newsletter
Daily energy & climate — solar, EVs, oil, the policy fights and tech bets shaping the transition. Free.
- Patrick Miller wrote the original NERC Critical Infrastructure Protection standards in the 2000s and became the first US official with delegated federal authority to audit utilities for compliance, later founding a nonprofit, running a DOE program, and advising regulators worldwide.
- US grid intruders have gained pre-positioned access inside utility systems without yet causing damage or a blackout domestically — a sharp contrast with Russia-linked attacks that have produced documented blackouts in Ukraine (multiple times) and recently Poland.
- Grid cybersecurity splits between IT (corporate systems, billing, email) and OT (operational technology that directly interfaces with physical equipment like breakers, transformers, and voltage sensors), and Miller says most new commissioners arrive with no technical background.
- NERC CIP standards cover the bulk power system, but distributed energy resources can fall outside the regulatory perimeter depending on registration thresholds — a gap Miller says is being narrowed as inverter-based resources come online.
- Chinese-made inverters, transformers, and controllers dominate US grid supply, yet Miller argues fears of embedded malware and kill switches are "less sinister than they sound" because commodity boards make targeted weaponization harder than the doomsday framing suggests.
- Data centers are an emerging cyber attack surface as electrification expands, and AI is reshaping both offensive and defensive capabilities in grid security, with regulators still racing to harmonize rules like CIRCIA after CISA cuts.
- Physical threats — squirrels, balloons — still cause more grid damage than hackers, per Miller, a reminder that cyber risk sits alongside a much longer list of mundane reliability hazards.
Why it matters: As US electrification pulls more Chinese-made power electronics and distributed resources onto the grid, NERC's regulatory perimeter must expand to cover assets below current thresholds and new attack surfaces like data centers. Miller's reframing — from apocalyptic kill switches to managing pre-positioned intruders and IT/OT gaps — gives state commissioners and federal regulators a more actionable target than the doomsday scenarios dominating headlines.




