The Grid We're About to Build Is Not the Grid We Know How to Defend
- edminyard6
- 2 days ago
- 5 min read
DOE says America needs more transmission. It's right. The harder question is what kind — and we have until September 8 to put that question on the record.
On July 9, the Department of Energy's Office of Electricity released the draft 2026 National Transmission Needs Study. The finding is blunt: the United States has a pressing need for more electric transmission infrastructure, driven by hyperscale data centers, domestic manufacturing, large industrial loads, and electrification. DOE also elevates interregional transmission — stronger ties between regions — as a reliability and resilience play.
The engineering case is sound. I don't dispute a line of it.
The security case is unfinished.
More transmission is not the same as more of the same grid
The buildout now underway changes the character of the system, not just its size.
Interregional ties don't only move electrons. Every new seam tie is a new trust relationship between two operating entities with different vendors, different patch cadences, different detection maturity. The reliability benefit is real. So is the corollary: an adversary who compromises the less mature of two coupled entities inherits partial reach into the more mature one.
The capacity being added inside existing corridors is software-defined. HVDC converter stations, FACTS devices, phase-shifting transformers, dynamic line rating, advanced conductors with embedded sensing — these technologies expand throughput by adding control intelligence. That's an underappreciated shift in failure mode. A conventional alternating-current line fails in physics, in ways engineers have modeled for a century. A converter station fails in firmware.
And the load growth driving the whole study arrives with its own control surface. Large flexible load is a genuine reliability tool, but wherever a curtailment signal exists, a remotely actuated multi-hundred-megawatt switch exists with it — and that control path frequently runs over commercial IT that was never engineered or assessed as reliability-critical.
The threat environment moved while we were planning
A portfolio approved in 2026 will energize assets that operate into the 2060s. So the relevant question isn't what the threat looks like today. It's the trend line. The 2025 record is not ambiguous.
For years the dominant concern was persistence — state-aligned actors quietly establishing footholds and waiting. That concern hasn't gone away; it's been superseded. Industry reporting on 2025 describes adversaries moving past access into active operational understanding: mapping control loops, identifying where commands originate and how they propagate, probing what causes a process to stop. The actor most associated with U.S. utilities was observed manipulating engineering workstations to dump configuration files and alarm data.
That is not espionage tradecraft. That is target development.
Three new operational technology threat groups were identified in a single year, and what's notable is the division of labor — an access broker weaponizing enterprise vulnerabilities and handing footholds to a more capable state-aligned operator. In December, distributed energy resources were attacked at scale in Poland for the first time, and the target wasn't a substation. It was the management platform. Ransomware groups with reach into OT rose roughly 49 percent year over year, and incidents are routinely misclassified as "IT" when the compromised box is the SCADA host.
Underneath all of it is the visibility gap. In most environments, compromise becomes apparent only after the process behaves abnormally. That is exactly how a small Massachusetts municipal utility ended up hosting an intruder for more than 300 days.
The window nobody is defending
Here's the part that keeps me up at night, and it's the argument I haven't seen anyone else make in this context.
During construction and commissioning, all of the following are normal and temporarily acceptable: contractor laptops on project networks, integrator remote access for tuning, default and shared credentials during acceptance testing, incomplete segmentation, logging that isn't forwarded anywhere yet, and heavy personnel turnover across multiple firms.
Meanwhile, most compliance obligation attaches when the asset enters service as a bulk electric system Cyber Asset.
The result is a multi-year interval in which the asset is physically real, increasingly connected, and only lightly governed. Supply chain and social engineering tradecraft targets exactly this seam. And on a historically large national portfolio, that seam is now open across hundreds of simultaneous projects.
We are preparing to deploy the largest transmission capital in American history under a regime that mostly evaluates security after the asset is already carrying load.
What to do about it
None of the fixes require new legislation. All of them can be specified contractually — by a utility, a transmission developer, an RTO, or a federal funding instrument.
Specify ISA/IEC 62443 for suppliers and integrators in EPC contracts. Require SBOMs and firmware provenance, with a right to reject unsupported components. Prohibit persistent vendor-managed remote access as a default architecture and price brokered, session-recorded access into the bid. Make logging and monitoring interfaces design deliverables rather than post-energization change orders. Govern the construction network as a production OT network from day one. Deliver an asset inventory as a commissioning artifact — if the integrator can't produce it, the asset isn't ready for service. Bring monitoring live before energization, not in the following budget year.
And fund the OT security staffing in the same capital request as the steel. The binding constraint has always been people, not products.
The lever is open until September 8
DOE is taking comment on the draft study through midnight EST on September 8, 2026. Comments are most effective when they ask for something specific and within the agency's authority. Four candidates:
Add visibility as a category of need. The study identifies where the grid is constrained in capacity. It should also identify where operators cannot detect an OT compromise before physical impact. That is a transmission need in every sense that matters.
Model cyber-caused correlated outage in interregional benefit cases. If ties are justified partly on resilience grounds, the analysis should include the failure mode most likely to affect multiple elements at once.
Attach lifecycle security requirements at procurement for federally supported and corridor-designated projects. DOE doesn't need to regulate to do this; it can condition the instruments it already controls.
Track OT monitoring coverage as a reported metric. We count transmission miles, transformer inventories, and interconnection queues nationally. We do not count the percentage of new transmission assets under continuous monitoring. We should.
Build it in now
Requirements written into a specification cost a paragraph. The same requirements retrofitted into an energized converter station cost an outage, a change order, and a regulatory filing. The requirements never written at all get paid for during restoration — in the one currency no planner controls.
Larger, more interconnected, more inverter-dense, more software-defined: more capability and more attack surface, arriving on the same trucks. These aren't competing objectives requiring a tradeoff. They're the same project. Treating them as separate is how the security cost gets deferred into the operations budget at five to ten times the price.
The construction window now opening is the last inexpensive opportunity to get this right at national scale.
The full white paper — Building at Scale, Building Exposed: Cyber Risk in America's Transmission Expansion — covers all six expansion-exposure intersections, the governance gap across NERC CIP and ISA/IEC 62443, and a phase-by-phase set of lifecycle security requirements for planning, procurement, construction, and operations. [Reach out via the Contact link for a free copy.]
Eddie Minyard, CISM, CCP, CMMC-RP, CBCP, CHTI, has spent four decades in crisis management and critical infrastructure resilience. He is the author of the cybersecurity thriller Gridfall: The Long Dark.


Comments