▶ 0:11:01We'd be more informed about the most consequential risk and to better plan and protect our grid. Energy and commerce has led on enactment of several laws over the past decade to ensure appropriate national attention to cyber and physical attacks and our nation's critical energy infrastructure. This work ranged from clarifying government authorities and the federal power act to authorizing several technical assistance and information sharing programs to assist utilities of all sizes.
▶ 0:11:31The hearing today should inform us as we seek to update and reauthorize various provisions that aim to make the nation more secure. And at this time, I'll yield back the balance of my time. And I recognize the gentlelady from florida's 14th district, the subcommittee ranking member, for an opening statement. >> well, thank you, Mr. chairman. Thank you to our witnesses for being here today. Energy infrastructure and an electric grid that meets the needs of the 21st century.
▶ 0:12:00That means a modern, reliable and resilient grid and tools for our power providers to guard against malign attacks and extreme events. Unfortunately, the trump administration is taking us backwards, keeping us wedded to outdated technologies that are insufficient to meet modern threats or power. Innovations like artificial intelligence.
▶ 0:12:22For example, the current department of energy terminated billions of dollars for projects meant to reduce the frequency and duration of blackouts and help utilities restore power faster. One energy expert, who previously consulted for the department, recently criticized the administration for arbitrarily ending projects that sought to make the grid more reliable and able to withstand storms, hackers, accidents and other problems.
▶ 0:12:51Some of the canceled projects under the grid resilience and innovation partnerships program would have upgraded grid management, including improved sensing of real time voltage and frequency changes in the electricity sent to homes and businesses.
▶ 0:13:04The trump administration also slashed efforts to automate grid operations and allow faster response to outages or changes in output from power plants and developed microgrids, localized systems that can operate independently during outages, which really hit home for me last year when many businesses and neighbors went without power for days after hurricanes helene and milton cancel.
▶ 0:13:31Cancel grid modernization projects are estimated to total over $700 million across 24 states. For example, a $20 million project in the upper midwest would have installed smart sensors and software to detect overloaded power lines or equipment failures, helping people respond faster to outages and prevent blackouts.
▶ 0:13:53A $50 million project in california would have boosted the capacity of existing subtransmission lines, improving power stability and grid flexibility by installing a smart substation without needing new transmission corridors and microgrid projects in new york and hawaii and new mexico would have kept essential services running during disasters, cyber attacks or planned outages.
▶ 0:14:18Now, this committee could play a constructive role to get back on track, especially as it is focused a lot of attention on the power needs of ai, electricity, the technologies that produce it cheaply and efficiently, and the grid that can deliver it where needed will determine the future of ai in. In 2008, china and the united states were roughly on par in the deployment of emerging energy technologies. But not today.
▶ 0:14:46China dominates this sector. They are electrifying. While america recently has taken an off ramp, electrification in the us is stuck at just over 20%. China is electrifying. At ten percentage points a decade, they're now at 30% and heading for 35%. And as a result, they're reaping the geopolitical benefits of being able to sell these technologies abroad.
▶ 0:15:10In august, china exported $20 billion in clean technology exports, and for comparison, the us exported about 1.3 billion in lng that month. We cannot win the ai race of the 21st century while limiting ourselves to a 20 20th century playbook, we need to rapidly deploy grid enhancing technologies, scale energy efficiency and support virtual power plants.
▶ 0:15:35And while doing so, we can make our grid more flexible and resilient, both to physical dangers and to malicious cyber threats. Traditionally, our grid was established with a few large, large scale fossil based energy generators pushing out energy to customers. But that is changing to a much, much more flexible and interconnected model of distributed generation, where electricity is moving in both directions across wires all the time.
▶ 0:16:02The clean energy transition and broader energy expansion to meet ai electricity demand is an opportunity to counter cybersecurity threats, and if done properly, we can replace our outdated energy systems with software enabled clean energy technologies.
▶ 0:16:18Modern tools that allow the grid to recover more readily when harmed by a hurricane, or a hacker that takes down a portion of the grid, we can use smart inverters, grid forming technologies, and batteries to restabilize or, if necessary, quarantine a part of the grid. Securing our electric grid should be a bipartisan national security imperative. Uh, congress can do this. We did it in the bipartisan infrastructure law.
▶ 0:16:47It's imperative that we strengthen what we did there. So let's get back on track, get back into the electrification race for the sake of our technological advancement, and to put downward pressure on electric bills for consumers. I look forward to hearing from the witnesses today, and I yield back. Thank you. >> the gentleman yields back, and the chair now recognizes the chairman of the full committee, the gentleman from kentucky, for five minutes for questions. >> thank you. Thank you for chairman latta for having this hearing.
▶ 0:17:17And thank for all of our witnesses being here. And there's one specific one I'll point out just a few minutes. And I also want to publicly thank chairman jordan for the opportunity to use this room today. While our second room is being renovated. Um, so throughout our nation's history, the affordable, reliable and abundant supply of energy has underpinned our prosperity and security. Today's world is no different.
▶ 0:17:38A complex web of interwoven energy systems and networks of linear infrastructure power the facilities and technologies that americans rely on to for work, health care, financial services, modern communications and myriad of everyday necessities.
▶ 0:17:54Our society's ubiquitous reliance on digital systems to power all of these applications also makes us makes the underlying energy systems a target for nefarious actors, such as state sponsored attacks from china, russia and iran, the committee has noted throughout this congress that we are on the precipice of great technological advancements and could reshape the next generation economy.
▶ 0:18:20But as these developments take root, our reliance on energy will continue to grow into surface, and the surface area for potential threats will widen, potentially even equipping bad actors with sophisticated tools to cause harm and sow chaos in the lives of everyday americans.
▶ 0:18:35Ten years after russia conducted the world's first large scale cyber attack in ukraine that shut down the grid for 200,000 residents, we witnessed the first documented large scale ai driven cyber attack against governments, financial institutions and businesses around the globe last month. This attack served as a test case, demonstrating the capability of advanced computing models, conduct wide ranging attacks with minimal human intervention.
▶ 0:19:04But ai can also be deployed to promote security and resiliency on the cyberspace battlefield and equip operators with the tools they need to protect against attacks and respond. In the case of disaster. The witnesses before us today are on the front line, protecting critical energy infrastructure in the efforts to address an evolving threat landscape.
▶ 0:19:27One witness that I would particularly like to welcome is a friend of mine and in my for my area, tim lindahl, president and ceo of energy electric, electric cooperative that serves several counties across western kentucky. I believe you serve 14 counties in six of your 14 counties are among the best in the world. That's what I understand. They happen to also be in the second district of kentucky. Thank you for for your service to them.
▶ 0:19:54Place like owensboro, hallsville, uh, mclean county. I thank you, muhlenberg and breckinridge. I think I've hopefully got them all. Uh, davis is in hancock are the counties for those cities I mentioned. So cooperatives, like energy are a key partner in these efforts to protect reliability and security of the electric sector and our rural communities. And it's just a note that I'm glad you're here because we have, uh, you know, big, large scale, uh, investor utilities.
▶ 0:20:21We have cooperatives that are there to serve the members of their co-op and, and have the same requirement that you have to have protection and security and whatever scale you operate in. And that is a daunting task. I know you take it seriously. I know you take I know the co-ops and all of our friends take it seriously. And we really appreciate you being here. And in this discussion, as you said, as I said, we I was thinking, chairman jordan, for this real estate because there's two another meeting going on.
▶ 0:20:49I'm going to be back and forth, but I look forward to hearing as much testimony as I possibly can and engaging in this. And, Mr. chairman, I really appreciate you having this hearing and I will yield back. >> thank you very much. The gentleman yields back the balance of his time. The chair now recognizes the gentleman from new jersey, the ranking member of the full committee for five minutes for questions. >> thank you, chairman latta. I'm pleased the subcommittee is holding this important hearing today, as cyber security is a critical issue that can impact energy affordability and reliability.
▶ 0:21:19This is also the first energy subcommittee hearing, this congress that was put together in a bipartisan way. And it's december. We should be having hearings like this regularly rather than just annually, and securing our nation's energy infrastructure from cyber and physical threats should be something we can all agree on.
▶ 0:21:37After all, threats to our energy system are only growing, whether it be from nation state actors such as russia or china, or domestic terrorists here at home, whose capabilities are being enhanced every day by increasingly effective artificial intelligence tools, and soon attacks that would have required the resources of a sophisticated opponent will be able to be carried out by a single person, and our adversaries with resources will be able to sow chaos on a much larger scale than we ever anticipated.
▶ 0:22:07So these threats are not hypothetical. Earlier this year, we discovered that hackers associated with the chinese government unleashed an attack that compromised the systems of a massachusetts utility for nearly a year. And I don't have to tell anyone the disaster that this could cause, both for the reliability of energy systems and for our mission to keep utility bills low.
▶ 0:22:29And that's why today's hearing is so important, and why we have discussed the many threats facing energy reliability this year, from president trump's attack on clean, cheap energy to threats brought by extreme climate fueled weather events, to challenges from data centers consuming enormous amounts of electricity, cyber threats to the grid involve an adversary who will seek to overcome any barriers that we can raise against them. So we have to be in a state of constant evolution.
▶ 0:22:58Now, the interconnected nature of our energy systems means that any one threat cannot be viewed in isolation. Threats to a gas pipeline can quickly cascade into a threat to electric reliability, and because of this interconnectivity, we must ensure that experts from the department of energy play a key role in our energies in our government. Cybersecurity defenses for the energy sector. And while agencies under the department of homeland security can play an important convening role.
▶ 0:23:24It's the doe, the department of energy, not homeland security, that has the critical relationships with all the relevant actors in the industry and has the expertise necessary to view threats in a holistic manner. And we saw this in the aftermath of the colonial pipeline cyberattack, when department of energy took the lead on the federal response. I look forward to hearing about some of the work the doe is doing in bringing together the energy industry to talk about threats that impact everyone.
▶ 0:23:50However, none of this work at the department of energy, uh, it's not going to work essentially, unless doe, uh, is the agency that's properly staffed and has the resources to fulfill its mission. Do you lost more than 3500 staff this year as a result of secretary, right. And doj's reckless and relentless attacks on federal workers? We need to ensure that we have sufficient staff working on the issue of cybersecurity and that they get the resources that doe and the funding that they need.
▶ 0:24:21Now, I was the chair of this, uh, committee in 2021, and then we passed a law establishing a number of cybersecurity programs at the department of energy and the federal energy regulatory commission, and many of those programs are now coming up for reauthorization and are ripe for examination to see what worked, what didn't work, and lessons we should all learn as we look to potential legislative action.
▶ 0:24:44So finally, I hope we can also discuss the security not only of our energy infrastructure, but of the supply chain that creates that infrastructure. During the last ten months, the trump administration has hobbled our efforts to reassure manufacturing in america, increasing tariffs, slashing tax credits that were designed to make american manufacturing competitive. And as a result, we're more dependent than ever on foreign sources for critical infrastructure components.
▶ 0:25:09And that's a vulnerability that could turn into a devastating weakness if we don't work to reverse it. So I hope to hear our ideas on how we can turn this around today from all of you. And again, I thank you, chairman, and I yield back the balance of my time. Thank you. >> well, thank you very much. The gentleman yields back the balance of his time. And this now concludes member opening statements. The chair will remind members that pursuant to the rules, all members opening statements will be made part of the record.
▶ 0:25:38Again, we want to thank our witnesses for being with us today and taking time to testify before the subcommittee. Each witness will have the opportunity to give an opening statement, followed by a round of questions from our members. Our witnesses for today are Mr. michael ball, ceo of the electricity information sharing and analysis center and senior vice president of the north american electric reliability corporation. Miss charlotte's security and reliance.
▶ 0:26:06Pardon me, security and resilience policy area vice president at xcel energy, Mr. tim lindell, the president and ceo of kenergy corp. Mr. harry cray, the director of studies for the carnegie mellon for institute for strategy and technology. And Mr.
▶ 0:26:26Zach tudor, the the associate laboratory director at the office of the national and homeland security at the idaho national laboratory. We appreciate you all. Appreciate you all being here today. Before I recognize Mr. ball for your five minutes, let me just mention, uh, if you would pull the mics up close to you and, uh, press that button to make sure that that light has come on, uh, so we can hear you loud and clear.
▶ 0:26:53And at one minute, you'll see the green light go to yellow. So you have one minute left in your opening statement and then goes red. We'd like you to finish your opening statement. So thank you again for being with us today. Mr. ball, you are recognized for five minutes to give your opening statement. Thank you. >> all right. Well, thank you, chairman and ranking members and members of the subcommittee for inviting me and convening this important discussion, uh, regarding threats to north america's electric grid.
▶ 0:27:20My name is michael ball, and I serve as the ceo of the electricity information sharing and analysis center, or isac. The isac is a clearinghouse for security information for the electricity industry of north america. It is operated under the organization designated by ferc as the electric reliability organization for the united states.
▶ 0:27:42Our mission is to reduce cyber and physical security risk to the electricity industry by providing unique insights, leadership, and collaboration across the united states and canada. We accomplish our mission by gathering, curating, and disseminating threat information in a timely and actionable manner. We do this with asset owners and operators to help mitigate the complex, evolving threats of the grid.
▶ 0:28:10The isac operates a 24 over seven watch operation, develops analysis of ongoing incidents, and provides a suite of analytical products and services accessible to over 1900 member organizations. Isac membership represents more than 85% of the meters in north america, and includes a range of utilities of all sizes and types, some of which are represented here with us today.
▶ 0:28:37The isac promotes cross-sector coordination and information sharing as well. This includes natural gas, communications, water and finance. We work closely with our government partners such as the department of energy, um, dhs, cisa, ferc, and the intelligence community.
▶ 0:28:56We maintain similar relationships with industry and government partners in canada to support the connective tissue between the private sector and the government, and the isac are members of the industry's electricity subsector coordinating council. The esc, led by industry ceos in partnership with senior government officials, seeks to operationalize security initiatives and coordinate around events that threaten grid reliability.
▶ 0:29:24We do this because the threat landscape is complex. It includes continuously evolving threats from sophisticated and very capable adversaries. Among the most advanced are nation states, uh, the state actors and which are very well funded. And numerous public reports underscore how these adversaries focus on the electric sector. China, russia, iran and korea are monitored closely.
▶ 0:29:49Currently, chinese cyber activities pose one of the most dynamic threats to our critical infrastructure. The sheer scale and persistence of chinese cyber activities are demonstrated in the various typhoon, uh campaigns that are widely reported on, and lends credence to their ambition to target north american critical infrastructure. In addition to nation state threat actors, the isac monitors domestic and international hacktivist and criminal activities.
▶ 0:30:16Cyber criminals have access to a wide array of tools and techniques, supported by a stunning dark web ecosystem that fuels ransomware and and other extortion campaigns that we see today. And unfortunately, activists and extremists see destructive acts against critical infrastructure and targets as an opportunity to create impact in a way that draws attention to their ideologies and beliefs.
▶ 0:30:44The isac helps our industry counter these threats by fostering an active community of industry and government partners. A secure portal allows members to exchange and receive industry recognized bulletin and alerts, regardless regarding a relevant cyber and physical threats to the industry. Through this portal, isac provides analytical products with actionable content to support industry security teams.
▶ 0:31:10In partnership with the department of energy, the isac operates crisp, the cybersecurity risk information sharing program. Crisp is a monitoring system that provides cyber threat intelligence and helps detect malicious activity and inform defensive measures. We also partner with doe on the itac, the energy threat analysis center.
▶ 0:31:33The etac is a collaboration between industry and government through scissors joint, cyber defense collaborative and itac partners work together to analyze threats, provide industry contexts and recommendations back to the sector, and an important example of how private sector is working with government to bolster the defense of critical infrastructure. The isac also plays an important role in convening industry.
▶ 0:31:58We host grid satcon, an annual grid security conference which brings together nearly 1000 security professionals for training, education and collaboration across industry. And just two weeks ago, we conducted the eighth iteration of grid x, the largest grid security exercise in north america. And this is to tackle critical issues and identify ways to enhance our industry's readiness to respond to large scale attacks.
▶ 0:32:23And in conclusion, these are examples of how the isac operates around the clock to do our part to enable reliable, reliable, resilient and secure industry. I look forward to today's discussion. >> thank you. Thank you. Um, you are recognized for five minutes for your opening statement. >> thank you. Chairman. Distinguished members of the subcommittee, thank you for holding this hearing. I am chala arts and I serve as xcel energy security and resilience policy area vice president.
▶ 0:32:52My testimony today is on behalf of xcel energy and the edison electric institute, or eei. Xcel energy is a member of eei, which represents all U.S. investor owned electric companies. Aei's members provide electricity for nearly 250 million americans and operate in all 50 states and the district of columbia.
▶ 0:33:13Xcel energy is a large investor owned utility operating in eight western and midwestern states, serving 3.9 million electric customers and 2.2 million natural gas customers for xcel energy and ese member companies. Securing energy systems from all hazards, including cyber and physical threats, is a top priority. As you just heard from Mr. ball, the threat we face from nation state adversaries is real.
▶ 0:33:40It is advanced and it is persistent as the front line defenders of the nation's energy infrastructure, the private sector must be supported by the government to address national security risks. An essential component of that support is the timely sharing of actionable intelligence about our adversaries tactics and their motivations.
▶ 0:34:00Armed with this intelligence, private sector experts can proactively architect security into their systems, hunt for adversarial activity, and mitigate the risks from these threats. An important example of this information sharing support and partnership is the energy threat analysis center, or etac, that Mr.
▶ 0:34:19Ball just described, first piloted in 2023 and now consisting of 17 private sector entities, etac is an operational collaborative that convenes experts from our sector risk management agency, which is the department of energy and private sector companies to identify, analyze and mitigate cyber threats in real time.
▶ 0:34:38The uniqueness of etac is bidirectional exchange of information, private sector operational expertise combined with government intelligence that creates products that are specifically targeted to assist energy companies throughout the country. Reduce risk. Etac also facilitates collaboration with other federal agency partners. Excuse me, including dhs, the military, and federal law enforcement agencies.
▶ 0:35:05Expanding cross-agency information sharing with the private sector. Thousands of energy entities have access etac products, evidence of its important to industry risk reduction efforts. In addition to initiatives like etac, industry and government are strategically assessing threats and prioritizing risk reduction at the executive level.
▶ 0:35:28The electricity subsector coordinating council, or esc, consists of ceos who represent all segments of the electric sector and serves as the primary interface between government and industry to address national security issues. Importantly, this convening mechanism exemplified by the us, the esc unifies government and industry action on reducing systemic risk.
▶ 0:35:50A prime example of the effectiveness of the esc is the prioritization of industry efforts to support critical military installations and their energy resilience needs during a time of increasing geopolitical conflicts at all levels of our industry. The commitment to countering nation state adversaries is active, and it must be supported by congress and our government partners to bolster this national security collaborative efforts. We ask congress to do the following.
▶ 0:36:19First, congress should authorize etac so that it can adapt to address evolving threats, allowing for the strategic advice from private sector partners. Explicit recognition of this program allows industry partners and doe to jointly shape sector risk reduction priorities. Second, congress should continue to provide resources for etac so that private sector partners are armed with actionable information to defend their systems. Assured resources provide certainty for the private sector investment in this capability.
▶ 0:36:48Third, continued recognition of the importance of the sector risk management agencies for risk reduction as essential. The energy system expertise contained within doe and the national lab complex assures that risk assessment is informed by system operational understanding. Having doe lead interagency engagement minimizes duplicate, duplicative, or conflicting initiatives that tax private sector resources. The security of energy infrastructure is essential to national security.
▶ 0:37:18Government and private industry both have roles to play, and we are committed to reducing national security risks. Thank you again for including me in the hearing. I look forward to the questions. >> well, thank you very much for your testimony today. And, Mr. lindahl, you are recognized for five minutes for an opening statement. >> thank you. And good morning. Chairman and ranking member castor and other members of the committee, thank you for the opportunity to discuss how electric cooperatives are working to secure the grid against the evolving cyber threats.
▶ 0:37:45My name is tim lindahl and I serve as president and ceo of energy corp, a distribution utility in western kentucky. I'm testifying today on behalf of the national rural electric cooperatives, otherwise known as nreca, which represent nearly 900 cooperatives nationwide. At energy, we serve about 60,000 homes and businesses across 14 counties.
▶ 0:38:05We also support a robust industrial base and have built over 3500 miles of fiber infrastructure to help provide to help evolve our grid and provide broadband to our rural economies. Every day, america's electric grid faces thousands of cyber intrusion attempts for rural electric cooperatives. These threats are not abstract. They're real, they're sophisticated, and they're growing. Electric cooperatives are unique. We are private, independent businesses owned by the people we serve.
▶ 0:38:35We operate without profit. Incentive. We power over 42 million america's americans, including critical infrastructure such as hospitals, data centers and more than 150 military installations. However, securing this infrastructure presents distinct challenges. We operate in rural areas with lower population densities and fewer resources than many urban utilities. We must secure lines and isolated substations that may be hours apart because we have no shareholders.
▶ 0:39:03These costly investments are borne by our member consumers, many of whom live with modest incomes. Despite these constraints, co-ops are rising to the occasion. We apply a risk based, layered defense strategy to protect against all hazards, whether they serve are from severe storms or cyber attacks. Our approach is built on the principle of cooperation. Because we are independent, we can innovate locally, but we can also pool our resources and gain strength in our collective defense.
▶ 0:39:32But technology alone is not enough. The most critical piece of a security culture is the teams that work tirelessly, day in and day out to ensure that when the switch is flipped, the light comes on. Countless unsung heroes work quietly and anonymously in the background, monitoring and evolving our security. We never see the event that never happened, or we never hear about the attack that never occurred.
▶ 0:39:56To support these teams, we leverage cutting edge tools and resources that are being developed through nreca cybersecurity program, like the threat analysis center, a platform that helps co-ops identify, analyze, and communicate threats while reducing alert fatigue so our teams can focus on high impact risks for the cooperative cyber goals program, which also provides a structured framework designed specifically for cooperatives to advance cyber hygiene, regardless of the regardless of the utility's cyber maturity.
▶ 0:40:25While cooperatives are doing their part, we cannot do this alone. Strong federal partnerships are essential to closing this resource gap. Electric cooperatives utilize resources from various federal agencies and departments, including the csa, dhs, dod, and the state intelligence fusion centers. These all help co-ops better understand vulnerabilities, vulnerabilities, emerging threats, and mitigation efforts.
▶ 0:40:52The rule and municipal utility cybersecurity program, otherwise known as rmcc, is one example of these partnerships. Rmcc represents the most significant opportunity for co-ops to bolster their readiness by providing $250 million to help us invest in the people, processes, and technologies needed to secure the grid. However, we need your help to maximize its impact. While 80 million in the rmcc funding has been announced, much of the funding has yet to be released.
▶ 0:41:21We urge the department of energy to distribute these funds quickly so co-ops can put them into action. With an estimated 160 million remaining in less than a year left in authorization, nreca strongly urges congress to reauthorize the rmcc program. This is critical to ensuring rural communities are not left behind. Protecting the grid is a top priority for the nation's electric co-ops. We are making smart investments, training our workforce, and sharing threat intelligence to keep the lights on.
▶ 0:41:50With continued partnership and targeted federal investment, we can strengthen our defenses and ensure the security of the energy infrastructure that powers our nation. The electric grid is too critical to our existence. For it to fail. We must get it right each time, every time. All the time. Thank you for your leadership and I look forward to your questions. >> and thank you very much for your opening statement today, Mr.
▶ 0:42:18Chris, who you are recognized for five minutes for an opening statement. >> thank you. Chairman, ranking member castor and members of the committee for the opportunity to testify today. My name is harry and I'm the director of studies at the carnegie mellon institute for strategy and technology. My work focuses on us-china competition and the national security implications of emerging technologies.
▶ 0:42:39I previously worked in both the trump administration at the pentagon, working on military doctrine for offensive cyber operations, and in the biden administration at the white house, helping lead the development of the national cyber strategy. In both of these roles, I was confronted with wide ranging efforts by the people's republic of china to hold our critical infrastructure at risk. Beijing is preparing for conflict over taiwan, potentially in the very near term. Its theory of victory depends on preventing the united states from mounting a successful rescue mission.
▶ 0:43:07In response, both public and private sector cyber threat intelligence analysts have concluded that this strategy likely has two parts first, to disrupt defense infrastructure to slow our ability to mobilize personnel and equipment, and second, to target civilian infrastructure to sow panic and chaos among the public at large. Our aging infrastructure makes these threats easier, including in our energy ecosystem. Today's electricity grid is too often a hodgepodge of digital tools.
▶ 0:43:37Sitting atop an analog foundation, creating seams where adversaries can slip in. Many cybersecurity specialists used to argue that the best way to handle this kind of challenge was to separate operational technologies from modern networks. In practice, we now know that is nearly impossible.
▶ 0:43:54Digitization has swept our world so thoroughly that even national security networks that are believed to be airgapped often are found to have accidental and unknown internet connections during regular security sweeps, and efforts to ensure their ongoing defensibility from adversaries abroad. The only way around this challenge will be through it embracing modernization from top to bottom.
▶ 0:44:15As we've heard from many of the witnesses here today, to achieve that defense in depth that we need for our grid, grid security and defensibility america's ai build out reindustrialisation and broader electrification are, in fact, already demonstrating the benefits of such an approach.
▶ 0:44:30The energy technologies powering this transition from onsite generation and battery storage to smart inverters and virtual power plants were designed from the ground up, with software at their core enabling modern cybersecurity features and the ability to update and evolve in response to emerging threats. They are also enabling a smarter, more distributed grid architecture, one that is more defensible, resilient, and even self-healing, capable of quarantining disruptions and preventing cascading blackouts.
▶ 0:44:58These modern technologies are also opening a new frontier in energy security, nuclear power, geothermal wells and inverter based resources and battery storage require little to no refueling, making them defensible against fuel disruptions, but also insulating homes and businesses from swings in commodity prices. This transformation would be a valuable asset in any indo-pacific crisis as well.
▶ 0:45:22Our allies and partners in the region, upon whom our forward deployed forces rely for electricity and other infrastructure needs, are heavily dependent on maritime fuel shipments for their electricity. Modern, digitally native energy systems can not only be more defensible against cyberattacks, but they can also be more defensible against the naval risks that fuel tankers will likely face in any such conflict. But of course, there is a catch.
▶ 0:45:45Even as we modernize to many components that make these systems possible power electronics, precision magnets, batteries, and other building blocks that some refer to in aggregate as electro tech are made in china. Beijing's dominance of the very technologies that can make our grid more secure and resilient, and that are defining the future of innovation around the world as we speak, is a strategic and competitive threat.
▶ 0:46:08We should treat these modern energy technologies the way we now treat semiconductors as critical industries requiring greater visibility, investment and control by the united states and our allies. I urge congress to support more streamlined coordination between energy and national security stakeholders. Procurement frameworks that reward secure by design systems and sustained r&d and breakthrough technologies. I also urge you to build on the manufacturing reshoring progress begun by the energy tax credits and the inflation reduction act and retained in the one big beautiful bill act.
▶ 0:46:38Doing so will ensure we have an energy system that is both more competitive and secure if we do it right, if we do, the kinds of efforts described by my distinguished co witnesses here today, we could pour a new foundation for our electrical grid that delivers on the energy expansion that we are working through today, and guarantee american security and industrial leadership for the next 50 years. Thank you for the opportunity to testify today, and I look forward to your questions. >> well, thank you very much for your testimony today. And, Mr.
▶ 0:47:06Tudor, you are recognized for five minutes for your opening statement. >> chairman, ranking member castor and members of the committee, thank you for the opportunity to testify. I'm zach tudor, associate laboratory director for national and homeland security at idaho national laboratory, where I lead nearly 900 experts protecting us critical infrastructure, including the power grid, from cyber and physical threats. As has been mentioned more than once, america faces unprecedented cyber threats to our critical infrastructure.
▶ 0:47:33The 2025 annual threat assessment of the intelligence community confirms adversarial states, or pre-positioning, in us networks, to disrupt critical services at a time of their choosing. China is the most persistent threat through volt typhoon, salt typhoon flex typhoon. The chinese communist party has embedded itself in our energy, communications and water systems to set conditions for destructive attacks during a pacific conflict over taiwan. They're willing.
▶ 0:47:59They're winning without fighting, attempting to undermine our infrastructure and will to respond. Russia continues aggressive operations despite constraints from the war in ukraine. From 2015, black energy attacks on ukraine's grid and to the 2021 colonial pipeline ransomware, russian affiliated actors have proven they can disrupt energy systems at will. Recently, russian hackers targeted water systems in norway and poland and caused a texas water treatment tank to overflow.
▶ 0:48:28Iran has targeted our water, energy and manufacturing sectors, forcing a pennsylvania water utility to shut down portions of its system in 2023. North korea uses cybercrime to fund its regime, stealing over $1.3 billion in 2024, but has proven critical infrastructure capabilities through ransomware attacks that have disrupted hospitals, manufacturers and energy companies worldwide.
▶ 0:48:52The united states faces significant risks as our adversaries exploit fundamental vulnerabilities. Our infrastructure systems are interconnected. Disruption in one sector cascades across others. We operate vast, digitized, privately owned infrastructure that's aging and under-resourced against evolving cyber threats. The electric grid is indispensable and a prime target. Russia and china are advancing capabilities to disable grid segments during a crisis.
▶ 0:49:19China's volt typhoon has infiltrated us utility networks with intent for long term disruption. Oil and gas infrastructure remains vulnerable. Colonial pipeline showed how a ransomware intrusion in an ot network in an it network can trigger fuel shortages and panic buying nationwide. Iranian and russian groups continue probing pipeline control systems. Telecommunication networks are critical infrastructures. Nervous system china has embedded hardware vulnerabilities in routers and switches.
▶ 0:49:49In september, the secret service dismantled devices in new york capable of disabling cell towers and the critical infrastructure dependent on real time communication. Water systems are particularly under-resourced. Epa warns that over 70% of us water systems fail basic cybersecurity best practices. Many lack full time cyber personnel or continuous monitoring, making water infrastructure vulnerable and high stakes.
▶ 0:50:14Addressing these threats requires specialized capabilities that the department of energy's national laboratories can and have provided for many years. Doe operates 17 national laboratories to advance national economic and energy security, while supporting other federal agencies. Security missions defended critical infrastructure for over two decades. Our 890 square mile site provides unique capabilities to test threats and solutions at scale.
▶ 0:50:42We lead national control systems security efforts through programs including cyber informed engineering that integrates cyber security into the design of infrastructure. Our consequence driven, cyber informed engineering program strengthens system resilience through hands on assessments and the cyber testing for resilient industrial control systems or sites program is supported by six national laboratories to test energy sector supply chain components in coordination with the private sector.
▶ 0:51:07Additionally, inl's test ranges offer unmatched infrastructure testing capabilities. We operate a utility scale electric grid, test bed and wireless communications test range. We maintain over 150,000ft of control system lab space to safely test cyber and physical threats at full scale. We work alongside doe, dhs, and the department of war to support testing, training, and large scale exercises.
▶ 0:51:30Our new special activities office was established to bring coordinated focus across the lab complex and with our partners towards this critical mission. In summary, america's adversaries are not waiting. They're already embedded in our systems. The threat is no longer hypothetical. It's a daily reality. Congress must act decisively. We need to accelerate public private partnerships to secure infrastructure. We should extend and expand the state and local cybersecurity grant program.
▶ 0:51:59Passage of the pillar act was a positive step. We should expand national laboratory investments to advance operational technology security. At inl, we're concerned more than ever before. We face a defining test of resilience and national security. If we act decisively, we can safeguard the systems that power america's economy and protect our way of life. Thank you, and I look forward to your questions. >> well, thank you very much for your testimony. And that will conclude our testimony, our our opening statements from our witnesses.
▶ 0:52:28And we'll move into the question and answer portion of the hearing. And it's very sobering, which you've all been bringing before the committee. And with that, I'm going to recognize myself for five minutes for questions. Uh, if I could start, um, Mr. ball with you, uh, you made some interesting statements, especially when you're talking about the recommendations for congress and you talk about on the the threat, uh, uh, that's out there.
▶ 0:52:57You talk about the support for crisp from northern ohio with our when I look at our utilities, uh, you know, the question is, are we getting the information we need out there at our utilities? Are the utilities getting the information from the federal government on existing threats that are occurring or what's happening right now? >> so it's a it's a very good question. I would always err on the side that it's never enough. I would start with that.
▶ 0:53:24But I think what we are focused on is building a strong ecosystem of information sharing, and that that part is built on relationships, and it's something that, uh, is built into, whether it be from an isac perspective, the members that we, uh, engage with that actually are recipients of all of the information that we push out.
▶ 0:53:46Uh, we serve as a conduit for that, uh, programs like crisp actually are are programs that are, um, you know, start out with a member funded, uh, program where they actually participate and that that information that goes from that actually is also shared with our government partners and department of energy and the national lab work, uh, framework. And what's important about that is it starts to bring together, uh, uh, uh, our government and our industry.
▶ 0:54:16Um, I think also references to the itac is another great example of being able to provide information sharing. I think I would I can't footstomp that enough is bringing the awareness that our government partners have, uh, around threats, but the contextual understanding of what those threats represent to the industry become a really important part of that dialog that is happening. But we need more of that.
▶ 0:54:44So I think anything that we can do to encourage engagement, information sharing will actually help us drive towards a greater and more resilient grid. And certainly from a national security perspective, make us much more secure and resilient. >> well, thank you. Uh, miss, uh, we've heard about the communist party and what they're doing out there in the united states. And to what threats are you mentioned?
▶ 0:55:09Uh, defense in depth, because we've got to protect ourselves. And so would you want to explain a little bit on what we should be doing on the defense in depth? Because if they've already infiltrated, how are we going to protect ourselves? >> excellent question. Thank you for it. Um, we take a multi-layered approach to securing our systems. First, we are, as an industry, subject to mandatory cybersecurity regulations.
▶ 0:55:36Those are a part of the security controls that we implement, but we also really heavily rely on those partnerships that I described in my testimony and opening statement, so that we can ingest, um, the intelligence our government partners have at the federal level.
▶ 0:55:53We also work very closely with our state and local partners as well, to understand threats in those local areas, um, so that we can proactively implement security controls that will address those trends that we are seeing from these advanced persistent threats. Finally, really critical component of defense in depth is being prepared. Um, Mr.
▶ 0:56:15Ball mentioned the grid x exercise, but we also participate in exercises held by the department of energy with our military partners at the state and local level, so that we can respond to and recover from very quickly the incidents when they do occur. >> thank you, Mr. lindell. I probably have, uh, more electric co-ops in my district than any other congressional district in ohio.
▶ 0:56:36And when I go out and meet with them all the time, you know, I see what they've been investing just to make sure on the cyber side that they're protecting not only, you know, their system, but also all their consumers out there, that they want to make sure that the power is always on, you know, a question, you know, do they have the enough the information? Do they have, you know, the time, the money, what's happening out there? Unfortunately, I have about 44 seconds left. >> uh, we can always use more resources as cooperatives.
▶ 0:57:06Every dollar we spend is a dollar that goes into our rates and our members end up paying, um, so every resource we need, if we can partner and pull together our resources with, with the federal government, with state governments, with our other utility partners, with other cooperatives, we can, um, help solve this problem without significant cost to the individual members. Um, there's always, um, a need to evolve and, and to have the tools we need. You know, we can't do this alone.
▶ 0:57:35We've we've got to do it together. >> well, thank you. And with my remaining about five seconds, I have additional questions I'll submit for you all, because these are really important questions that we've got to get resolved and make sure we protect the grid. And with that, I yield back and recognize the gentleman from california 50th district for five minutes for questions. Thank you, chair. >> for holding this important hearing. You know, I just want to say that what you've told us is very alarming.
▶ 0:58:04And I really appreciate you taking the time to come down here and tell us that. And I'd say to the chairman that, um, american people will note someday that we've been warned today about this. They will have expected us to work on this, and I hope we make that a priority, that we make this a priority in this committee. I also just say parenthetically that I saw the, you know, don't pay attention to this, but the congressional schedule this year, again, came out. I believe it has us on the plane more days and it has us in dc.
▶ 0:58:31Um, I think that that really inhibits the ability of all committees, but including this committee, to work on important issues like this. And, um, I was sorry to see again, despite our protests, that we could we could do better, that the committee schedule itself will inhibit us from having enough meeting days to deal with important issues like this that's above our heads. Um, but we see it again and again, and it's a frustration for me. And I know for a lot of members, um, I do want to talk about one physical threat to the grid.
▶ 0:58:59Uh, that's a particular interest to me. And in san diego, uh, where catastrophic wildfires, the biggest physical threat to both our energy grid and energy affordability in california, wildfire related costs, including proactive investments in post-disaster recovery, now represent 40% of california's utility rate increases. 40% is wildfires. So it's clear we need to do a lot more than, uh, in that bucket in terms of upfront mitigation.
▶ 0:59:26Um, the the utility in my area, san diego gas and electric, they're headquartered in my district. They've really done a, I think, commendable job. They've invested nearly $6 billion in wildfire preparedness, and they're innovators in wildfire mitigation and grid safety. Uh, they have, um, monitoring technologies to detect fire risk and respond to bury transmission lines underground to minimize the risk of ignition, and conduct extensive vegetation management to protect power lines from hazardous trees.
▶ 0:59:54But this kind of investment is rare and it's expensive. And a lot of our power grid is vulnerable to falling trees, catastrophic wildfire and other threats. So there's a lot more that the federal government that we here could do to improve coordination and information sharing between federal agencies and state partners, which would unlock the full potential of wildfire mitigation and investments. Um, the fix our forest act, or fofa, which we hope will pass the senate. This congress take strong steps to address this. The house version of the bill called it the fireside center.
▶ 1:00:25The senate version calls it the wildfire intelligence center. But the goal is the same. It's a one stop shop for wildfire intelligence coordination and response would be empowered to work with states, utilities and communities to mitigate fire risks. Uh, consolidating real time information on wildfires and wildfire risk through this federal hub will improve preparedness, real time decision making, and wildfire response, especially for utility infrastructure in fire prone areas.
▶ 1:00:49Now, miss arts excel um energy has a robust wildfire mitigation plan. Obviously, you work closely with many others to maintain the physical security of the grill grid. Can you talk about the threat the catastrophic wildfire poses to the grid, and how increased communication and coordination among federal government, utilities, and states could be helpful to mitigate those threats? >> thank you for the question, congressman.
▶ 1:01:13Uh, we take a comprehensive approach to wildfire mitigation risks to all risks, physical hazards that we face. We operate in eight states. And like in california, we've seen increased catastrophic wildfires across all of our service territory. Our wildfire mitigation planning is comprehensive. It includes advanced technologies. It includes improved operations and maintenance activity, all designed to mitigate that wildfire risk.
▶ 1:01:39Importantly, because of this threat, the electricity subsector coordinating council has a wildfire mitigation task force that is working very closely with our government partners in the us forest service, with department of energy, with the bureau of land management to improve upon the consistency of the permits that are needed to conduct vegetation management and other wildfire mitigation risk to improve the information sharing and the resource allocation to those coordinated efforts.
▶ 1:02:09The last thing that I will say about that effort is, um, and Mr. lindahl and I were talking prior to the hearing, the benefit of, um, this industry is the amount of information sharing we do with each other to expand understanding of best practices so that we are all working collectively to mitigate these risks. So thank you for the question. >> Mr. ball. Quickly, I know isac works with industry to respond to threats. Um, how can congress help that effort better in 20s.
▶ 1:02:39>> yes. So, um, from the isac perspective, the wildfire threats aren't specifically within the domain, however, as as miss arts. References. The electricity subsector coordinating council is very focused on this issue. And then speaking from the side of the house, you know, ferc has asked nurc to conduct a study. Um, they're in the process of bringing together stakeholders to produce a report in may next year.
▶ 1:03:10>> thanks. We'll look for that. And I yield back. >> the gentleman's time has expired and yields back. The chair now recognizes the gentleman from kentucky, the chairman of the full committee for five minutes for questions. >> thank you. And I. >> want to ask the gentleman from kentucky a question here. Mr. linda, thank you for being here and appreciate you making the trip up. Um, so let your cooperatives serve over 42 million americans across the country, including many service territories that are seeing significant energy demand due to ai data centers.
▶ 1:03:36Now, that's in our our area, very interested in ai data centers with the ohio river of the water and the and access to electricity that we have in kentucky. And energy is is very particularly in part of the middle of that. And you have the large industrial loads like in hancock county and other places. Um, and they're important to economic drivers to our west kentucky communities in the era of skyrocketing demand growth. Can you discuss ways in which cooperatives like energy are creatively addressing cyber threats to the system? >> yeah.
▶ 1:04:06One of the concerns we have as we as we run the grid closer and closer to the edge is that it becomes more and more critical to not have interruptions before, you know, we could have a small event and and it wouldn't have an impact, you know, on on the reliability of the grid. But as we push the grid to the limit, um, with new load, data center load or any kind of load, it just puts a microscope on any hiccup in the system that could happen. So things we're doing, you know, we do a layered approach as well.
▶ 1:04:34And you know, we're in all of the above cooperative. You know, we we like to diversify our resources, diversify how we serve things, diversify. Um, even the economics around how we serve things. So that's one way we get around it, um, how we insight into our grid so we can manage our grid much more efficiently and effectively by better management.
▶ 1:04:55So part of the reason we've invested in our fiber is to be able to have insight down within our distribution system, and we can leverage new tools and new innovations to help thwart physical and cyber attacks that might, might come and help keep the lights on. >> so, so you mentioned getting close to the the level of our grid support. And my county has a well have municipal utility. But our I have a family business as a co-op and their power comes from tva.
▶ 1:05:22You know, tva took out a coal plant in three years ago during the polar vortex. We had blackouts in kentucky. Believe it or not, the energy rich state. We had blackouts because of decisions to take out power. And so I know that we have increasing demand for power and an incredible increased demand if these ai data centers. But just increase demand anyway, because we're growing again in industrializing again and taking energy offline.
▶ 1:05:45And I know that's got to be a concern that I think big rivers is where you get is some of the demands that they're having to look at maybe taking power offline, because some of the requirements that have come down from washington, is there any comment on that? >> yeah. You know, we're in all of the above. We need to keep the resources we have. And then we also need to develop, you know, new resources and new ways to bring electricity in so that we can keep the grid alive. So, so and then we need fuel security.
▶ 1:06:12You know, a lot of our, our, our plants rely on, on, you know, natural gas for instance. So we're, we're in deeply tied to the cybersecurity of the natural gas industry. Uh, we roll our trucks with diesel fuel. We're heavily, you know, reliant on that network working so cyber can have a cascading effect on utility, even if it doesn't directly impact us. But but we want the all of the above. >> thanks. I agree with you on all the above. Um, all the above person as well. Thank you for that. So, Mr.
▶ 1:06:39Tudor, um, we recently witnessed the first documented ai, a large scale cyber attack using ai agents with minimal human intervention. Ai innovation will create tools to protect critical infrastructure, but bad actors can use them. Uh, as we saw with china and russia. Or could see with china, russia. How might ai widen the attack landscape on our critical infrastructure, and how is it working to foster innovation in ai development to address these risks? So what's the risk of ai and what are you doing to counter with ai? >> yeah.
▶ 1:07:09Thank you for the question, congressman. And yeah, the, uh, the risk of this, um, really pervasive new tool, um, hasn't been lost on us. And I will say that that ai, in its various forms has been used in critical infrastructure, you know, defense in operations for quite a long time. The onset of generative ai has really called all of us, um, as we go forward. Um, but this new tool does, um, you know, allow adversaries to, to, you know, leverage the existing manpower they have. And, and china among those adversaries has a lot of manpower.
▶ 1:07:36It can also enable, um, the defenders at the idaho national lab and with other partners such as oak ridge, pacific northwest, uh, we've, um, uh, developed something that we call tiger, the test bed for ai grid resilience. I mentioned all of the infrastructure that we have. So understanding what adversaries can actually do with ai and how we can defend it is, uh, is very important.
▶ 1:07:58We're also building on our cyber testing for resilience and control systems program to make sure that we understand what it means when a control system, a vendor provided system, has ai in it, and what critical vulnerabilities might be included in that and how we can mitigate them. So we at inl are doing a lot, and so are the other national labs working with, uh, caesar and doe and others. >> thank you. >> thank you, thank you for that. Mr.
▶ 1:08:22Ball and miss arts, um, we've discussed at length in the committee and in committee this congress about how demand growth, electricity presents new risks to be managed by everyone. Um, and so how is the industry approaching risk posed by an attack that causes a sudden loss of demand, such as from data centers and and what is what will that. So you're looking at the overall grid stability and risk of this. What how are y'all managing. How are you guys mitigating risk? I'll start with Mr.
▶ 1:08:50Ball and miss arts. >> okay. Uh, well, thank you for the question. And in fact, it's, uh, it's a pretty significant. >> I'm sorry, I just noticed I'm already negative on time. Maybe we can get the answer in a. >> you know, uh, go ahead and finish up quickly. >> okay. Uh, just just to say that, um, you know, we take that threat very seriously. Uh, and in many ways, we have to explain the impacts of scenarios like that. And that is why we really focus on the ability to read and react to events and various scenarios.
▶ 1:09:22So very important topic. >> well thank you. The gentleman yields back and the chair now recognizes the gentleman from new jersey, the ranking member of the full committee for five minutes for questions. >> thank you. Chairman latta. We often hear about the importance of a diversified grid and of not discriminating against any single resource type. Unfortunately, that's not the approach we've seen from the trump administration and from congressional republicans. And that I think that leaves us with real risk. I my question initially of Mr.
▶ 1:09:51Uh, I was struck by your written testimony which said it was crucial that the united states not fall behind china in next generation technologies like batteries, smart inverters for resources like wind and solar and virtual power plants. But could you talk a bit about that importance, and do efforts to shut down the research and deployment of wind and solar technologies, for example, help or hurt the security of our energy system, if you will?
▶ 1:10:22>> absolutely. Congressman, the, uh, basket of technologies that many are beginning to refer to as electro tech or electro industrial equipment are increasingly forming the foundation of our economy today and are going to infuse every part of it tomorrow.
▶ 1:10:37Uh, technologies that generate and store electricity, that manipulate and move it, uh, that range from batteries to advanced compute to advanced sensors, autonomous vehicles, these are the technologies that are going to define the pace of industrial competition in the future. And they're critical not only to our electrical grid, but for many sources of innovation that we see on the horizon.
▶ 1:11:03And it is indeed very troubling that, uh, the people's republic of china has quite the head start on manufacturing many of these technologies. Uh, but the simple reason for that is that, uh, prc had a head start on manufacturing smartphones and computers. Uh, many of these key pieces of electro tech machinery are downstream of those initial industrial investments.
▶ 1:11:27And so, uh, the bad news is we are quite behind now on a variety of critical strategic technologies. But the good news is that if we can make progress in some of them, we'll have we'll enjoy spillover benefits in other competitive areas. Because the truth is that a smartphone, a robotaxi or a fusion reactor are all very different technologies, but are, uh, fundamentally made up of many of the same components.
▶ 1:11:57>> all right. Thank you. I want to turn to Mr. ball. I wanted to turn to the network of organizations that help keep our energy system secure, including electricity information sharing analysis center, the electricity subsector coordinating council. Many of these entities are focused primarily on the utilities that handle the transmission and distribution of electricity. And that's important. But in many parts of the country, including new jersey, the actual generation of power is handled by different companies separate from the utilities.
▶ 1:12:26But those companies are just as much an integral part of the power sector as any load serving utility that owns, wires or sells power to consumers. So, Mr. ball, could you talk about the efforts by newark or that newark has made to include independent power producers in the electricity information sharing and analysis center, and how can we ensure that those entities are getting the support they need to keep their systems secure and online? I'm about a minute because I want one more question to go.
▶ 1:12:55>> so, uh, just just to try to answer that very good question. One of the things we look at is the information sharing fabric that we work with. It's a neural network of resources. I talked about different isacs. I talked about our membership. You know, one of the things we don't from the isac perspective, all of uh, entities have the ability to participate with the isac.
▶ 1:13:16In fact, we work with a lot of entities, um, even with nreca, who are in fact distribution organizations, and we channel information through to them as well. So we are not bound by necessarily those, those, those areas. But I think we can always do better. Um, and it's certainly an area that we're continuing to see growth, um, and not only in terms of engagement and information sharing, but actually engagement.
▶ 1:13:40We had in last grid exercise, we saw a 70% growth in small, uh, utilities participating. And that represents a lot of distribution as well. So I think we're seeing progress there. More to do. >> all right. Thank you. Let me just reiterate what reiterate what I said in my opening statement, which is that the department of energy plays a vital role in cybersecurity.
▶ 1:14:04Its expertise must be represented in any governmental conversations about the cybersecurity of the energy industry. And I could just go down the line and ask if everyone here agrees quickly, miss arts. >> yes, we heavily rely on the department of energy's expertise to enhance our national security efforts. >> Mr. ball, quickly. >> the answer is yes, and we are heavily engaged with them. >> Mr. christian. >> yes. >> mister lindell? >> yes. >> Mr. tudor?
▶ 1:14:35>> absolutely. >> all right. Thank you. And thank you, Mr. chairman. >> thank you very much. The gentleman yield back, and the chair now recognizes the gentleman from alabama's sixth district for five minutes for questions. >> thank you.
▶ 1:14:47Um, I want to talk a little bit about the energy policies of the past administration and the emphasis on, uh, green and reliable and affordable, which I was just looking at some of the increases in energy costs just from 2021 to 2024, 2025 is up 34%.
▶ 1:15:13Um, and I think it's a lot of it has to do with what nurk reported as, as the number one threat to the grid. Uh, the the change in the fuel mix. But what doesn't often get reported is how much it's costing uh residential consumers and that that uh percentage that I quoted 34% increase is in residential energy costs. So it's created an enormous problem for a lot of families around the country because of the investments that are made.
▶ 1:15:44And I'm like, chairman guthrie, I'm and the rest of my colleagues, I'm for all the above. But there's a hard truth that needs to to be acknowledged that that this transition is extremely expensive and it gets passed on to the consumers. Um, what we saw in europe, uh, should be instructive to us.
▶ 1:16:04The economist magazine, nobody's idea of a right wing publication, uh, reported that in the winter of 2023, uh, the about 68,000 excess winter deaths, this was not people freezing to death. This was people who simply could not afford to adequately heat their homes. It's particularly problematic for people with respiratory illnesses, cardiovascular illnesses.
▶ 1:16:33But 68,000 excess winter deaths, that's more than died from covid. So when you take a look at at these investments, and in particularly in areas of the country where, um, they have shut down so much hydrocarbon power generation, it's created, um, I think a hazardous environment for a lot of people who simply can't afford to adequately heat their homes.
▶ 1:16:59It's also, in my opinion, and I think the opinion of many created, uh, an economic security issue and a national security issue. Uh, we're in an arms race for artificial intelligence with with china. Uh, we're going to have to build massive data centers that cannot be powered with renewables because they're they're intermittent power. You have to have a consistently high base load to meet the demands of the data centers for us to be competitive.
▶ 1:17:28Uh, when I talk about this arms race and artificial intelligence and quantum computing, whoever wins, that's not going to be a superpower. They will be the superpower. If you want to talk about power. Okay. So, um, I just, uh, Mr. ball, in your experience at newark, uh, would you care to comment on this?
▶ 1:17:51>> what I can say is, um, that is a, you know, it's a very, uh, big concern about the growth and the demand and trying to balance and balance out outcomes with that. Uh, I cannot speak expertly on that. However, I'm always happy to come back with a feedback. But, uh, I can tell you that newark is very engaged. >> um, one of the things that I think we've got to address is supply chain issues.
▶ 1:18:15We're not going to be able to build out renewable power, uh, until we, uh, as long as we're dependent on china for, uh, refined rare earth elements and critical minerals. Uh, that that's a huge issue for us right now, securing our own supply chain domestically and collaboratively with allies in the western hemisphere. Uh, but it's also critical for us to to build these data centers.
▶ 1:18:43It's it's one of the things that drives up cost is, uh, uh, supply chain issues. Um, would you be interested in commenting on that? Mr. lindell. >> supply chain is a huge concern. You know, our our system is built on three legs when we make decisions on resource generation, resource delivery, uh, we balance affordability, reliability and safety. So every decision we make, uh, has to balance between those three.
▶ 1:19:11And in some cases, renewables work. In some cases they don't in some cases. Um, and that's why we say all the above. Because, you know, we we look at it all independently every, every single time. And you can't play economic affordability against reliability or reliability against affordability. >> well, since you brought up affordability, I want to touch on that very briefly. My colleagues across the aisle keep talking about that. But they created this problem with the legislation that they passed.
▶ 1:19:40And when you combine that with the supply chain issues, we not only have an affordability crisis that's really hurting american families. I contend, sincerely that this is an economic crisis and a national security crisis. Mr. chairman, thank you for the opportunity I yield back. >> the gentleman yields back. The chair now, the gentlelady from florida, the ranking member of the subcommittee for five minutes for questions. >> well, thank you, Mr. chairman. Mr.
▶ 1:20:06Kresha, in your testimony, you talk about virtual power plants as a linchpin technology that could be easier to secure against cybersecurity threats. Um, let's start with the basics. What what is a virtual power plant? >> thank you. Congresswoman.
▶ 1:20:20Uh, virtual power plant is essentially a network of small energy assets that have been stitched together by sophisticated software to function as though it is a single, large, dispatchable asset that the grid can turn up or down. Think in terms of home batteries, uh uh, smart thermostats, even flexible industrial loads that can be aggregated together to function as though it were a dispatchable power plant.
▶ 1:20:49>> that's a little bit different than the old time power, uh, production. That was like a single power plant with distributed systems. Uh, how was this technology developed? >> uh, yes, ma'am.
▶ 1:21:02It's a benefit of a digitally native approach to a grid architecture, uh, which provides both flexibility but also security and resilience benefits, uh, for a robust grid architecture, you probably want a combination of both, uh, centralized baseload resources and flexible grid forming distributed resources that can be orchestrated with sophistication so that they can play to each other's strengths and, uh, hedge against
▶ 1:21:32Different kinds of risks. >> and then how can, uh, vrp help with grid security? >> absolutely. Can, uh, provide a, an instantaneous and flexible response to forms of disruption. They enable models, uh, like, uh, we call them graceful failovers into islanding and microgrids.
▶ 1:21:50When certain parts of the grid gets disrupted, uh, with this network of sensors and smaller energy assets, you have more flexibility to flow electricity to where it's needed and to quarantine, uh, disruptions from becoming cascading blackouts. >> and is the us leading in this technology, or are there other countries that are are in the lead on this?
▶ 1:22:15>> um, it is early days and uh, I think that, uh, like in many advanced modern electricity generation, storage and orchestration technologies, we are in a race with china to define what right looks like and to develop secure supply chains, both in the software and hardware side. >> so is there anything that the congress can do on the regulatory side or through legislation to support and assist with the deployment of. >> uh, yes, ma'am.
▶ 1:22:39I believe that, uh, supply chain security considerations, whether we're writing them into hardware sourcing or procurement guidelines, should take into consideration the systemic impact of certain components of our electricity grid and things like. >> specific when you're talking about supply chains, uh, what should this committee focus on, on supply chains to, to bolster vrp technology and cybersecurity at the same time? >> absolutely.
▶ 1:23:08I think when when writing foreign entity of concern legislation, uh, or regulatory guidance, uh, it should incorporate prioritization about what kinds of technologies have the most systemic impact, most high consequence. So virtual power plants are systemically influential and highly, uh, and can have high consequence. Uh, the contrast would be to, uh, commodity, uh, equipment like a vanilla photovoltaic, uh, which is low consequence.
▶ 1:23:35And so you'd want to focus your efforts toward the systemically influential side rather than commodity, uh, less consequence side. >> and, uh, how does xl manage sourcing and procurement? Uh, for some of these more cybersecurity sensitive components? >> yeah. Thank you for the question.
▶ 1:23:55So xl energy is a regulated entity has to adhere to the nrc's critical infrastructure protection regulations that require us to manage, um, the our supply chain risk. Um, we have a very robust process that we utilize that includes assessing, um, during the rfp process, equipment manufactured in those countries of concern.
▶ 1:24:20Importantly, we continue to urge our government partners to share specific intelligence information on manufacturers and or specific components, uh, that we should be targeting in our assessment. Finally, we are looking at remediating, uh, risk through, um, removing equipment that is legacy in nature that might have been deployed prior to our understanding of some of these threats. The last thing I will say, because I want to emphasize what Mr.
▶ 1:24:49Tudor shared about the citrix program, the department of energy does idaho national lab, where they are going in and looking at vulnerabilities in equipment, hardware, software, but importantly providing risk mitigations that industry can implement. Um, in the utilization of these technologies. >> thank you very much. I yield back. >> gentlelady yields back. The chair now recognizes gentlelady from tennessee for at least five minutes.
▶ 1:25:19>> at least five minutes. Thank you, Mr. chairman. And thank you to the witnesses for being here today. Um, Mr. tudor, I'll start with you. Um, as you highlighted, our grid is a linchpin for multiple other dependent and interdependent sectors, including natural gas and communications. A physical or cyber incident impacting one of these interdependent sectors can have downstream impacts on the grid system.
▶ 1:25:43And I guess my question, because I represent east tennessee, we have ornl right down, you know, at oak ridge, of course, we have tva. How are you identifying and collaborating with interdependent sectors to further harden, um, the electricity sector? >> yeah. Thank you for that question. Very good question.
▶ 1:26:04So, so number one, yes, working with our partners like oak ridge national lab and some of the, uh, um, utilities that are government operated, um, gives us access to a lot of information that we can use for our research. But also, you know, as I was taking notes, um, all of the different, um, sector councils, the electric sector coordinating council, newark itech program, crisp. These are all ways to get information. You know, one thing I did want to point back to is that, you know, we talk about information sharing.
▶ 1:26:31Um, I would say that every, every four and sometimes every two years as an executive order that talks about critical infrastructure, security and information sharing is always one of the top three things. And you would think that we'd gotten well, I think we've gotten better at it. Um, but not so much that presidents would have to keep talking about it. So information sharing, actionable intelligence, context, all of these things are important.
▶ 1:26:51The national labs work with utilities, organizations and others to try and get that context and that that actual intelligence, but also use that to do research for mitigations, for current threats and hopefully mitigate upcoming threats. Um, so I guess what I want to say is that partnership amongst all of us is key. Working with caesar, uh, the office of electricity, the grid deployment office, our other agencies keeps us kind of at the forefront. And the relationships really do matter. >> yeah, they certainly do.
▶ 1:27:22Thank you. Sir. Mr. ball, I appreciate you highlighting the significance of grid x in the vendor affiliate program to strengthen the grid resilience. Do you happen to know if either program has ever been used to plan and protect against, um, emp attack on the grid?
▶ 1:27:43>> so with regards to grid x, um, in terms of the exercise, uh, I'm not aware of a specific, uh, scenario with that with regards to that particular exercise. >> well, if you haven't done it, what would be required to incorporate, um, emp scenarios into future grid? Um, exercises? >> well, I would say and certainly grid x isn't the only mechanism by which we would do that.
▶ 1:28:10But I think by understanding the nature of the kinetic impacts of emp to the systems, obviously there's been tremendous analysis done that. Epa has done a great body of work in partnership with industry on those and really leveraging those, um, the understanding that's been developed out of that analysis to apply those scenarios and then explore the consequences of that and then mitigation. So I believe that is a mechanism by which, um.
▶ 1:28:37>> I always ask when I go visit tva, what are you doing to emp proof that and even its nuclear facilities and things are doing, they have new techniques and new things that they're doing to do that. Um, and I guess this question will be for Mr. lindell and Mr. ball and miss arts. Uh, the federal government relies on the private sector to provide not only mandatory, but also voluntary reporting of suspicious activity and minor incidents to improve overall analysis.
▶ 1:29:06Additionally, the government depends upon industry through sector based information sharing and analysis centers to identify threats, tactics and provide material support for law enforcement investigations. For its part, the private sector relies on the federal government's intelligence to sector um to properly secure their assets from attacks. So from your perspective, what are the intelligence gaps in the public and private sector? And, Mr. ball, we'll start with you.
▶ 1:29:38>> so I'm sure there are gaps that we can, uh, can can focus on. However, I would say that there's actually a lot of dialog occurring today. We've referenced programs that identify, uh, mitigations, like for for citrix, for example, um, are conduits of information gathering that start to be able to be, um, shared with our industry and to actually be able to deploy techniques to help mitigate the risks on that.
▶ 1:30:04Uh, the other thing I think is, is really important is, um, to recognize that, you know, our vendor community is a fundamental part of that, uh, ecosystem of information regarding threats. We find that industry that suppliers that provide industry, uh, technologies oftentimes become aware of a vulnerability or something is produced.
▶ 1:30:26We want to make sure that we are collecting that information, whether it is through government sources or not, but we want to be able to aggregate that, collate that and get that out in actionable ways. That's an objective. >> I am out of time. So you two will not get to answer my question, but you can give it to me in writing. Okay. Thank you all I yield back. >> gentleman yields back. Chair recognizes gentleman. Mr. menendez for five minutes. >> thank you. Chairman.
▶ 1:30:50Um, to all the panelists, are you familiar with president trump's march 19th executive order titled achieving efficiency through state and local preparedness? Just show of hands. Most of you are okay. I'll read section one to you. Common sense approaches and investments by state and local governments across american infrastructure will enhance national security and create a more resilient nation.
▶ 1:31:14Federal policy must rightly recognize that preparedness is most effectively owned and managed by the state, local and even individual levels, supported by a competent, accessible and efficient federal government. I'm sorry that this administration has failed on the competency part. Uh, but I want to just highlight two things from an article titled five ways the trump administration is increasing the risk of blackouts.
▶ 1:31:37Um, states that in october, the administration canceled more than $2 billion worth of funding allocated to communities to harden their energy infrastructure against extreme weather threats through the grid resilience and innovation partnership program, administered by the us department of energy's grid deployment office. Are you familiar with that program? Yeah.
▶ 1:32:01Uh, these cancellations included 26 grants across 25 states, and another 19 grants may also be canceled, according to an internal doe list shared by politico. In addition to the cuts for doe projects, the administration ended a major fema program for disaster resilience called the building resilient infrastructure and communities program.
▶ 1:32:22Brick provided funding to communities to reduce the risk of climate disasters and other natural hazards from damaging public infrastructure such as energy, water, and wastewater infrastructure. The elimination of the program revoked more than $3.6 billion in funding that was allocated for community projects across the country, including projects to upgrade upgrade the grid. Are you familiar with brick? Okay, um, Mr.
▶ 1:32:48Lindell, in response to a question by chairman latta, you said, quote, you can always use more resources. Is that correct? That's correct. Does anybody disagree with that? Okay. So I am going to have you answer yes or no. Are these over $5.6 billion in cuts by the trump administration to these two vital programs helpful to states, municipalities and utilities? Yes or no? >> no.
▶ 1:33:19>> the cuts are the funds. >> the cuts to the funds? No. Yes. >> depends. >> depends on. As you said, you need more resources. Correct. We do. So 5.6 billion is significant amount of resources. >> it is a significant amount. But you know we're going to continue to innovate and run the grid. >> I know you'll do what you need to do, but you need us to be good partners. That's right. Executive order is supported and that includes financial resources, including $5.6 billion in grants. Yes or no? >> no.
▶ 1:33:52>> yeah. So it's difficult to sit here in this committee room and have this conversation when republican colleagues are silent, when $5.6 billion are being cut from these essential programs and literally undermining the president's own executive order of supporting all of you, but it just doesn't stop there. The administration is also fired over a thousand cybersecurity and infrastructure agency staff.
▶ 1:34:19Does that make our country safer and more able to respond to these increasing cybersecurity attacks? Yes or no. We'll go down the line again. >> no. >> no no. >> yeah. So you understand the challenge that we feel here on this side. Right. Because we can diagnose the problem at nauseam.
▶ 1:34:42But we have colleagues who refuse to to lift their voices when the trump administration is cutting $5.6 billion in funds, when they're cutting cisa, which is largely a vendetta, according to project 2025, about what they think cisa did in the 2016 election. Crazy. They're also moving cisa staff to other agencies like ice, which has no, uh, connectivity to what their work has been.
▶ 1:35:10So this administration is weakening our communities. They're weakening the work that you need to do. They're weakening our cybersecurity capabilities. And the last thing I'll say is Mr. um, you talk about china's awareness of our vulnerabilities and modernizing our grid for increased ai adoption can and should take future cyber threats into consideration, right?
▶ 1:35:33Like ai is becoming more of an issue, both from an offensive capability of our adversaries and needs to be a defensive capability. We had our first ai hearing in this committee on february 5th. All that they've done is try to roll back ai state laws. There's no federal framework. There's no federal approach to cybersecurity, to ai, and we're all weaker and more vulnerable because of it. I look forward to our colleagues across the aisle actually doing the work and stepping up for our communities.
▶ 1:36:04I yield back. >> gentleman yields back. To recognize the gentleman from georgia for no more than five minutes. I thank the. >> chair, and I thank chair for holding this important hearing, uh, securing our energy infrastructure. I thank the witnesses for being here to testify, uh, protecting our critical infrastructure, I think we all agree is paramount to our national security, especially from attacks from our adversaries.
▶ 1:36:26Electrical grid must be secured so that we can protect it from evolving threats and ensure reliable power can be dispatched as part of securing our grids. Cybersecurity plays a critical role in grid resiliency. I'm fortunate that adjacent to my district is the savannah river site, located in south carolina. Look at it. Srs is the savannah river national lab.
▶ 1:36:51Researchers from idaho national laboratory and savannah river national laboratory participated through the southeastern regional center for cyber security collaboration, led by auburn university and oak ridge national laboratory, in a first of its kind lab demonstration of some of the challenges faced by electric utility companies and the hardware suppliers to these utilities, a utility provided a scenario to demonstrate resiliency in the
▶ 1:37:21Face of cyber attack on a substation. To successfully show resilience test grids at inl and srnl were virtually connected to each other. An attack was perpetrated on a substation emulated at srnl, with resilient control falling back to control system at inl.
▶ 1:37:40This scenario demonstrated the challenges faced by utilities, a possible mitigation of this particular threat, and overcoming the technical challenges of long distance command and control for grid equipment. Mr. tudor often, often commercial industry threats. The cyber treats the cyber threat as an it issue when it really is a problem for ot systems.
▶ 1:38:03How can national labs be leveraged to use their trained cyber operators to enhance security operating technologies? >> thank you for your question, congressman allen. Um, very happy to answer that. Uh, we have been partnering successfully with savannah river national lab since they have joined, kind of joined the the family, um, as well as oak ridge and the southeast regional, um, center.
▶ 1:38:25Uh, that is one of the things as we talk about the kind of, you know, shift in philosophy towards more regional preparedness, uh, with with government response. We think that the cert three is a great model, um, along with things like the cyber command, cyber florida and others.
▶ 1:38:40Um, so the national labs for a long time have worked to help people understand the meaning of convergence in it and ot, uh, through both workforce development training programs, demonstrations, uh, appearances at conferences and talks like this. Um, I think that, um, there is the constant tension between it and ot as the operational technologies becoming more and more computerized, the vulnerabilities from it systems become more apparent.
▶ 1:39:07And our critical infrastructure, um, I think that we're helping to grow, um, a next generation of engineers, places like auburn, georgia tech and others that are working with us, um, to help spread that cyber informed engineering that built in resilience in programs. Um, and I'll stop there. >> thank you. Okay. >> uh, just a follow up. What what does idaho national laboratory doing to, uh, train utilities to identify and address risks to operation technology systems?
▶ 1:39:39>> yeah, thank you for that. I was one of the leaders in in training critical infrastructure security to what? Utilities and others that we work with. Um, our university partners, utility partners. Uh, we have a large scale, um, training program that has been ongoing for the last 17 years. It's it's called the red blue training. But people from across the industry, around the world come to learn about the, uh, the threats and vulnerabilities against critical infrastructure and how to go about mitigating them and growing their capabilities.
▶ 1:40:08Uh, the workforce is a very big issue for us. We know the places like nreca and others may be under-resourced and and larger companies, larger organizations, things once again, look for the excels of the nation, help to develop some of the capabilities that can then be, um, given to the rest of the industry so they don't have to spend that kind of research dollar. >> thank you. Uh, Mr. lindahl, uh, rural electric cooperatives play a huge role in my district in georgia.
▶ 1:40:37You mentioned in your testimony the industrial control system, rural electric cooperative initiative that helps with cyber monitoring. Uh, we've got 25 seconds. Can you share how this has been impactful on helping rural communities protect critical infrastructure and enhance their cyber defense capabilities? >> yeah. The more we understand about how our systems operate and the more we can, um, kind of put protections in place to control them, the better we can respond to incidents out in the system. >> great, great, perfect.
▶ 1:41:05Uh, Mr. chairman, I'm two seconds early, and I yield back. >> uh, the braggadocious gentleman yields back, and the chair now recognizes the gentlelady from virginia for at least five minutes. >> thank you, Mr. chair. And I want to thank ranking member, uh, the chair and ranking member for holding this very important hearing.
▶ 1:41:28And while this is not a hearing on clean energy or data centers, uh, representing virginia, which is both the clean energy capital of the south and the data center capital of the globe, I can't let Mr. palmer's false claims that clean energy doesn't power and can't power data centers go unanswered.
▶ 1:41:46And I would invite the gentleman from alabama, and as a matter of fact, the entire subcommittee or the full committee, even to come to virginia to come to henrico county, sandston, specifically to tour the metadata center, which I toured during one of our many recesses. Uh, the henrico data center is supplied with 100% renewable energy from new sources, from new projects specifically built to support the data centers operations.
▶ 1:42:16That and new solar projects that add more than 500mw of reliable energy to virginia's grid. And that's because the data centers campus itself was designed to be energy efficient, and they focused on both energy efficiency and clean and renewable sources. Uh, two things that the trump administration, with the help of our republican colleagues, are trying to gut. It's not just meta, though.
▶ 1:42:41Amazon states that its data centers are powered by clean energy, with 100% of the electricity consumed by its operations, including its data centers, matched with renewable energy in 2023. So if anybody would like to come to virginia and tour this 100% clean energy power, solar power data center, uh, just let me know.
▶ 1:43:02I am happy to arrange a tour, but let me get back to what we're supposed to be talking about today, which is, uh, grid security. Now, as chair guthrie mentioned earlier, we've seen nation states use ai to enhance and automate cyber attacks against american corporations and entities. Uh, Mr.
▶ 1:43:20Crazy, with the explosion of availability of ai chatbots and large language models like the one we saw used in the attack that anthropic revealed last month, how should we be preparing for the eventuality that an increasing number of non-state actors, including for terrorist organizations, will seek to leverage these now widely available technologies to target america's critical energy infrastructure?
▶ 1:43:48And how can we increase our adaptability to this threat? >> thank you. Congresswoman. Indeed, uh, the explosion of ai technologies are lowering the bar for how many how much resources and expertise you need to mount a malicious cyber campaign. And as a result, we're going to need to take defense more seriously, uh, across the digital ecosystem and in particular in our critical infrastructure.
▶ 1:44:15And I think the answer is going to be modernization from top to bottom. >> uh, thank you. Um, and as a follow up, to what extent have we established a whole of government approach that ensures that government agencies and interagency entities are working with utilities and other private partners to monitor, prevent and react to cyber threats to the grid. And to what extent, if at all, should we be looking to better leverage the resources of interagency efforts to bolster the security of the grid? And again, Mr.
▶ 1:44:47Chris, this one's for you. >> I think we are standing on a strong foundation built from the last few decades of hard won lessons in defending our infrastructure from physical and cyber attacks. But it needs to continue to evolve, uh, to be flexible to the modern realities facing us in the years ahead. Uh, the, uh, who who makes up the energy stakeholder ecosystem is changing.
▶ 1:45:11We are getting more entrepreneurs, more diffuse and diverse sources of dynamic, new inventive technologies that need to be folded into our existing information sharing and threat response ecosystem. >> and in your testimony and in your your response to one of my questions, you note that america's electric, uh, current electric grid is a hodgepodge of outdated analog technology and more recent digital tools and components that create seams through which bad actors can gain access, compromise,
▶ 1:45:42And attack the grid. Um, and so I think we both agree we need to modernize and improve the grid. And I would argue one of the reasons for high electric costs is the fact that we have failed to invest in modernizing and expanding our grid for too long. And so in 25 seconds or less, how would you recommend we in the federal government seek to steer the modernization of the grid to address both short term vulnerabilities and create a grid that is both technologically advanced, secure and reliable?
▶ 1:46:12>> thank you. Ma'am, the, uh, ai driven build out of our energy ecosystem is a golden opportunity to focus the level of investment needed for that transformation to our electricity ecosystem that no other critical infrastructure sector allows. And so I think it will be ensuring that the, uh, hyperscalers, the various utilities and energy deployers of the country all have a similar idea of what right looks like.
▶ 1:46:37And we seize this moment to distribute that understanding as far and wide as we can. >> thank you. I yield back. >> gentlelady yields back. Chair now recognizes gentleman from texas for five minutes. >> thank you, Mr. chairman. I think this is a really important topic. I serve on homeland security as well.
▶ 1:46:53And so that the intersection of the grid, of the threats that we're facing, the things that, uh, that y'all are doing, how the government can help, uh, what what we need to be doing to help the intelligence that you need, the sharing of information and those those types of things are really important. Uh, before I get into the questions, I want to submit a letter for, uh, for the record, Mr. chairman, um, uh, that we sent to the department of commerce, uh, to secretary lutnick that Mr. balderson and I wrote.
▶ 1:47:22>> without objection, so ordered. >> um, and it has to do with the chinese manufactured inverters. Um, and just the, uh, the critical grid components that we're very concerned about. So, um, we'll, uh, we'll get that for the record, but I'll just jump right into questions. Mr. ball, in your testimony, you indicated that the prc campaigns like assault, typhoon and volt typhoon represent the most persistent and adaptive, um, threats that are targeting our infrastructure.
▶ 1:47:47Uh, we know that the chinese communist party is actively seeking, um, to to do damage and gather intelligence. But can you describe an operational level, the, uh, what utilities are doing differently today? Um, than, than has been done to detect and to stop these campaigns and then what gaps still exist that we need to be worried about.
▶ 1:48:11>> so I think the, the best way to describe that is I think, uh, we see an industry that is evolving in its capabilities and it's based on awareness. I think, you know, we have seen a significant awakening. Uh, and I'm not saying it's enough, but we have seen a significant awakening to the threat with our industry.
▶ 1:48:30And, you know, when it boils down to it, despite this, the sophisticated capabilities that threat actors like the prc has, um, a lot of the things that make us resilient still boil down to basic practices and making yourself and our utilities. And we need to continue to bolster that capability or, um, our, our industry, whether it's large ious or down to the municipals and cooperatives.
▶ 1:48:55I think you're hearing even today how they are the these this industry is awake to that. And I think we need to continue to empower them to be able to build a more resilient system. >> are you seeing that there are other state actors that are seeking to exploit the chinese made, uh, inverters? >> you know, it's a good question.
▶ 1:49:19Um, I think that, uh, we don't see any, you know, from my perspective, my purview, I necessarily can't comment or see any perspective, any different threat actors utilizing the same core technologies to exploit it. Um, but I would say that threat actors of all sorts, if there is a vulnerability in a technology, they will seek to exploit it. And that can range from sophisticated threat actors all the way down to criminals, folks that want to monetize vulnerability by attacking.
▶ 1:49:50>> Mr. lindell and miss arts. I'll get to you a question here in a second, but, uh, same same thing for you. We have a lot of rural cooperatives in my district. I think I overlapped with something close to 15 or so. Um, the gentleman behind you could probably answer that question, uh, for me, but, um, what kind of threats or vulnerabilities or gaps are you seeing? Um, specifically in the rural cooperative. >> we see the same threats, I think, that every other utility sees.
▶ 1:50:16I don't think, you know, a threat actor doesn't differentiate between a small cooperative and a large utility, like an excel energy. Um, and we put the layers in place, and we don't necessarily care where the threat comes from. We care that we have things in place to prevent it from happening and be able to respond to it once it does happen. However, with information sharing, we do need the tools so we understand what the threats are and we can develop the tools to mitigate them.
▶ 1:50:44>> are you getting what you need in the form of intelligence, information sharing and an awareness of the threat as our intelligence community sees it? Are you getting that at a in a timely manner? >> uh, it's a good foundation. I think it's working and it's working now, but we can always evolve and improve. >> I'll take that for we need to improve. Um, miss arts, you mentioned your testimony that the chinese state sponsored actors have already compromised multiple us critical, um, infrastructure providers with the intent to disrupt operational controls.
▶ 1:51:13Um, how has how have the cybersecurity practices changed in response to these, these threats and these nation states? >> yeah. Thank you for the question. I would say the information that we've received, um, particularly on volt, typhoon and typhoon, resulted in the energy threat analysis center, which I mentioned, really honing in on that threat and developing, uh, capabilities. Capabilities is maybe not quite the right word.
▶ 1:51:44So that, um, small, medium, large electric utilities could look for, um, evidence of those cyber actors in their systems, those threat hunt memo guides that were produced by itac are an example of us as industry taking that intelligence, innovating and getting, um, quick risk reduction, um, priorities into the hands of those that need to use them to mitigate the risk. >> thank you. My time is expired. Yield back. >> gentleman yields back.
▶ 1:52:11The gentlelady from colorado is recognized for at least five minutes. >> thank you, Mr. chairman. Um, I, um, I first I want to talk about sort of this this principle. I always keep hearing my republican colleagues talk about every time we have an energy subcommittee hearing. And Mr. palmer talked about it today, which is he said, quote, um, we all believe we should have an all of the above energy strategy.
▶ 1:52:40Um, I guess I just want to go down the panel and starting with you, Mr. uh, do you believe we should have an all of the above energy strategy and each person can just answer yes or no? >> absolutely. You can see the complexity. >> yeah. >> yes. >> linda. >> yes, yes. >> Mr. >> yes, yes. >> okay. So everybody thinks we should have an all of the above energy policy. Uh, Mr.
▶ 1:53:03Chris, I want to ask you, we, my staff and I tried to make an exhaustive list of what and all of the above energy policy sources would, would contain. And here's what we came up with. Crude oil, natural gas, coal, solar, wind, nuclear, hydro, biofuels, geothermal, hydrogen. Does that sound about right? >> that sounds about right.
▶ 1:53:27>> and and so here's my concern is when we have these hearings, um, they say they support an all of the above energy policy, but then they completely all the policies they advocate for completely only talk about those top three crude oil, natural gas and oil.
▶ 1:53:43And I just want to ask all of you folks here who represent industry and others, is are any of your industries or your businesses associated with you moving away from these other sources of energy to just go to these three because of cybersecurity issues? >> no. >> no, no. >> you're yeah. Okay. So so I want to ask you, Mr.
▶ 1:54:11Chris, um, in terms of cybersecurity, is it inherently more dangerous to have an all of the above energy approach and use these other things? >> thank you. Congresswoman. No, it's, uh, it isn't, I'd say, more secure and resilient to have in all of the above. >> it's more secure and resilient to have an all of the above strategy. And so so when we're talking about security with batteries and so on, it's not like these things are going to go away.
▶ 1:54:39We have to figure out how to make these sources more secure. Is that right? >> yes, ma'am. >> now, in these lines, yesterday, doe announced that the national renewable energy lab, which is just across the border from my district, will, quote, effectively be called the national laboratory of the rockies, which I'm happy to have my beloved rocky mountains recognized. But I don't really know what this means.
▶ 1:55:04Does this mean that the administration doesn't want to have the iconic nrel, which was established by president george w bush senior in 1991, move away from renewable energy research. So thanks to the to the help of ai, I went online and I looked at their report for 2023.
▶ 1:55:27And they're talking about research finds opportunities for breakthrough battery designs, hydrogen blending as a pathway towards us decarbonization, full steam ahead, unearthing the power of geothermal. And it goes on. You get my drift.
▶ 1:55:44What I want to know is in this performative action by the administration yesterday of renaming the lab, are they now planning to move away from research, research that will actually help us make our grids more secure in the long run? And that's the problem I have with what's going on with the trump administration and with my colleagues across the aisle. Now.
▶ 1:56:10Now, miss arts, I do have to ask you a question because, um, xcel energy, of course, is my local energy company. And I really do appreciate your testimony here today, given the presence of critical national security entities in the state like norad and space force, and also, of course, of of, uh, what's it called now? The national laboratory of the rockies.
▶ 1:56:34I wonder if you can talk to me briefly about how excel supports the security organizations and how, uh, the energy threat analysis center can facilitate those relationships. >> yeah. Thank you for the question. Xcel energy collaborates very regularly with the national security partners we serve in the state to ensure that we're meeting their energy resilience needs.
▶ 1:56:59We recently hosted norad and northern command at itac to exchange intelligence information. Um, that complements the efforts we conduct in other venues with them. Um, we look forward to continuing to that collaboration on response and recovery efforts as well. >> thank you. And so the collaboration is really what's important here, Mr. chairman, I yield back. >> gentlelady yields back. The chair now recognizes the gentleman from new york for five minutes. >> Mr.
▶ 1:57:28Chairman, our witnesses know better than anyone how frequently adversaries test our defenses and target the operators who keep power flowing. Uh, but as we consider these vulnerabilities, we must also recognize the broader point. Cyber and physical threats don't just expose weaknesses in the electrical system. They highlight the danger of relying on a single source of energy. When states or cities adopt policies that eliminate natural gas or restrict access to other fuels, they don't just limit consumer choice, they reduce resiliency.
▶ 1:57:59Electricity is essential, but it only works when the grid is functioning. If a cyber attack or a physical incident takes the grid offline, everything that depends on electricity stops. Natural gas and propane, however, can be delivered directly to the home or facility and continue to operate independently off the electrical grid. They provide heat, hot water, cooking capabilities, and even fuel for backup generators during an outage.
▶ 1:58:24These fuels don't replace electricity, but they give families, hospitals and emergency services a critical lifeline when the grid is down. Removing these options leaves communities with only one energy source to rely on in one point of failure. If that system is disrupted. Mr. tudor.
▶ 1:58:43If a cyber or physical attack takes down electrical service, what are the practical impacts on hospitals, water systems, emergency responders and other critical services, particularly in areas without natural gas or other backup fuels? >> well thank you, congressman. You know, obviously, you know, electricity is the lifeblood of almost all of these critical sectors. And so anything that takes down the electric capacity in a region would definitely have a devastating effect. To all those things you mentioned.
▶ 1:59:13>> these aren't abstract concerns. In my home state of new york, policymakers are moving aggressively towards an all electric mandate in rapidly increasing electric load without adding generation or transmission needed to support it. The new york independent system operator has repeatedly warned that the grid is already strained during winter peaks in electrifying uh, with electrifying for heat and transportation. Without backup options, it's creating serious reliability risks.
▶ 1:59:41And these are technical assessments, not political arguments. Uh, mister lindell, when a cyber or physical incident knocks out electrical service, what does that mean for the hardworking families that you serve, especially those living paycheck to paycheck who can't afford long outages and don't have alternate heating or cooking options? >> yeah, there's a significant cost to outages. And the longer term cost is to our general economy.
▶ 2:00:06If we have a negative impact on the reliability of our grid, that's going to force people to make decisions to go elsewhere. And it would be the same with affordability as well. And so we've got to get it right, because we can't afford to lose what we have, and we can't afford to let our folks go cold in the wintertime or hot in the summertime. Uh, those are life and death matters. >> thank you very much, Mr. lindell. And when you combine a stress grid with increasing cyber threats, the risk comes even clearer.
▶ 2:00:33Uh, if electrical demand keeps rising while natural gas is phased out, a single attack on a transmission line or a control center doesn't just cause inconvenience. It threatens entire communities, hospitals without heat, seniors at risk from freezing temperatures, manufacturers forced offline, and emergency responders left without any kind of safety net. No redundancy.
▶ 2:00:58Uh, true resilience requires multiple energy pathways electricity, natural gas, propane, backup generation and distributed resources so that a single disruption cannot shut down a community. And with that, Mr. chairman, I yield back. >> gentleman yields back. Gentleman from california for at least five minutes. >> thank you very much, Mr. chairman. And I want to thank the witnesses for being here today. Um, Mr.
▶ 2:01:21Krasa, as ranking member of the communications and technology subcommittee, I've led efforts to rip and replace insecure huawei and zte equipment from us telecom networks. However, I'm really concerned that we're facing a similar problem with chinese made grid equipment. It doesn't matter how strong our cyber defenses are. If the chinese military have direct backdoors into chinese made inverters, transformers, battery systems across the us electric grid. Mr.
▶ 2:01:51Krasa, how big of a problem is this? >> thank you for that question, congresswoman, and thank you for your efforts to secure our telecom infrastructure. Uh, this is indeed a big problem, but it's bigger than an electrical equipment problem. It's bigger than a telecom equipment problem. It's a modern society problem. Any piece of equipment that has a computer in it likely has a major chinese dependency. >> so we can't just carry out a replace program for chinese made equipment.
▶ 2:02:20Um, so let's say this not everything made in china is spyware. Um, Mr. krishna, how do we identify with certainty what chinese made grid equipment poses a risk? >> uh, it is going to require a risk and consequence prioritization framework.
▶ 2:02:40Uh, we need to consider what kinds of electrical equipment has systemic impact, has the most digital exposure, and focus our scrutiny on their first. >> okay. Now, Mr. tudor, how are the national labs helping to identify potential backdoors or other vulnerabilities in chinese made grid equipment? >> yeah, thank you for that question, ma'am.
▶ 2:03:03And, you know, we have been, you know, mentioning that that prc manufacturers, um, a majority of our power electronics, battery technology, control equipments, um, at least 70% of the manufacturers from the prc and probably 90% of our critical components have at least one critical component from china. So it is a major problem. Uh, they have had a systemic, um, 20 year strategy to, to make these things happen.
▶ 2:03:28Um, you know, we work with, uh, the department of energy, caesar, and the doe grid deployment office to provide technical assistance to asset owners. Um, the the the threat hunting and incident response has already been mentioned. Um, we've worked with the integrators and other businesses that work to develop these different infrastructures to help them provide secure designs through cyber informed engineering.
▶ 2:03:49And one of our similar programs, consequence driven, cyber informed engineering, helps utilities and others identify what the highest risk areas and highest risk components may be to be mitigated. Um, I wrote down, you know, you you asked Mr. um, you know, how do we determine these things with certainty? Um, and I don't know that I would ever, you know, be certain of these things until we could watch the manufacture happen either in, in us, uh, areas or in partner areas. But reducing risk is what we are all working out and being able to identify.
▶ 2:04:20>> and we have a lot of work to do here. Then ultimately, we should reshore manufacturing for key components of our energy supply chain. And that's why the democrats included incentives in the inflation reduction act to manufacture inverters, batteries and other grid equipment in the us. And it was an incredible success, with dozens of new factories planned here in this country. But the republicans bill derailed that momentum. Mr.
▶ 2:04:44Chris, are you concerned that without a concerted government effort to boost us manufacturing of key grid equipment, we can lessen our dependance on competitors like china? >> yes, ma'am. Thank you. Uh, I'm very concerned, but I think that the, uh, our experience in securing our telecom infrastructure demonstrates that we need two primary tools to do so.
▶ 2:05:06A scalpel and a shovel, uh, a scalpel to excise those high consequence, high risk pieces of technology and a shovel to build those factories so they can produce their replacements. >> okay. Thank you. Um, I want to shift to talk about cyber threats to our local distribution system, the low voltage local transmission system that delivers power during the last mile to our homes and businesses. The local distribution system is vulnerable to cyber attacks, and it often receives less attention. Mr.
▶ 2:05:34Chris, are you concerned that we're not paying enough attention to the local distribution system? >> yes, ma'am. Uh, it's estimated that 10 to 20% of the bulk power system is under direct federal oversight. But that's why we need the fantastic efforts of my co witnesses here today, uh, to help make sure that those efforts, uh, get down to where they need to go. >> absolutely. Mr. ball, do you share Mr. chris's concerns and looking forward.
▶ 2:06:02>> I do, I do, and we are very focused on trying to fill any gaps, thereby really channeling information in actionable ways to the local companies that are running distribution systems. >> realizing, of course, a lot of the states are more involved in that process, right? >> yeah, absolutely. >> okay. I've run out of time. I thank you very much I yield back. >> gentleman yields back. Chair recognizes the gentleman from south carolina for five minutes. >> thank you, Mr. chairman.
▶ 2:06:30And thank you to our witnesses for for being here today. If the power goes out and everything stops, hospitals, water systems, communications network, everything. I think it's incredibly alarming. Some of the testimony I heard today about malign actors, state, nation states and also others china, russia, iran, north korea becoming more aggressive and sophisticated.
▶ 2:06:50I think reading me personally, preparing for this hearing, reading about china's preparations, if there was a conflict on how to target our grid, that's really alarming, right? Like that's that's incredible stuff, uh, that we have to grapple with. And I'm glad that this committee, I think, is taking a holistic and serious approach to identifying ways in which we can be more resilient, right, that we can withstand these type of cyber attacks. Mr.
▶ 2:07:18Ball, to you, what role do you think the eia plays in identifying and sharing threats coming from the pipeline sector that could affect power generation and power delivery? >> thank you. It's a very good question. And I would have to say, uh, you characterized, um, the productive paranoia that I think all of us operate under.
▶ 2:07:43And we to that point with our particularly with the natural gas sector, we've actually had partnership from an isac perspective that goes way back. We worked actually with the downstream natural gas isac. What is now the one? Isac this is a network of information sharing that happens every day.
▶ 2:08:03We believe that the trades, uh, also work very closely together, meaning, you know, ag inga and our electric trades actually do work very closely together and worry about the complex interdependencies between, uh, those different systems.
▶ 2:08:20>> do you do you think, uh, in that same vein, though, that you have sufficient visibility into pipeline sector threats, uh, or are there any blind spots that congress should consider, uh, for today's, uh, for today's hearing? >> well, I think we certainly have lots of insights into the threats that are that are part of it.
▶ 2:08:40I think what is particularly challenging is that the dynamics of those systems, uh, when it comes to natural gas and the operational realities of, of those assets, when and need to supply the electric sector, there's a lot of good. In fact, there was an excellent exercise at eei facilitated that actually brought leaders together to tackle some of those issues, like how do we deal with these complexities, uh, when a very bad day happens? >> what about congress? Are there blind spots that congress needs to be aware of?
▶ 2:09:12>> you know, it's hard to speak to that. I actually, you know, I have to believe we do not have perfect visibility. None of us should be able to claim that. And I think there's always an opportunity to improve there. >> so thank you, miss. Miss arts, from the perspective of investor owned utilities, do you think that the utilities are receiving actionable intelligence quick enough to prepare for threats or could, um, that could move between sectors like gas and electricity? >> thank you for the question. Uh, as one of my colleagues stated earlier, we can always do better.
▶ 2:09:41Um, we are doing a lot of that improvement on sharing actionable intelligence out to the entire industry via the energy threat analysis center and the regular information sharing that occurs between the isac and the downstream natural gas isac. We are very collaborative as an industry because we are interconnected and we understand that. So sharing this information to all of our peers throughout the country, across the industry, is incredibly important to guarding against the threat.
▶ 2:10:12>> thank you for that, Mr. lindell. Rural electric cooperatives are, uh, serve large geographic areas, less people, less resources. Oftentimes. Does cross sector information sharing provide sufficient visibility, uh, for rural systems? Or are there gaps that make that job much harder to manage for smaller utilities? >> it helps, um, you know, there's always gaps because we don't know what we don't know. And, you know, we can always improve on that.
▶ 2:10:41Um, but the information we get, we react and we have the same processes in place that like the information that an excel energy would get, we use utilize the same tools, the same resources, the same opportunities. >> do you find that it's harder to manage from a rural electric perspective? >> it is because our resources are sometimes very trite. It's hard to find the team, the staff that wants to live in rural america, that has the expertise to do what we need to do.
▶ 2:11:07So that's why we we come together as cooperatives with like nreca and create programs like the rmu that we can actually bridge the gap and act like a larger entity, even though we're 900 smaller entities. >> great. So you're taking I mean, you're taking sufficient steps then to, to to bridge that gap. That's right. What's your term. Yeah. Because that was always my concern was investor owned utilities, big things a lot of money maybe a lot of customers too. But the rural folks, uh, they're kind of left. They're kind of left on the sideline. But you're you're taking, I'd say proactive steps to. >> yeah.
▶ 2:11:37One of the benefits we have, I think, in the cyber threat is, is we're many and we're diversified. But yet we cooperate among cooperatives and other utilities, and we come together to solve big problems. >> thank you for that. Guess what guys? I had questions for you too, but I'm off. You're off the hook. Especially you, Mr. tudor. I had a really challenging one about our ability of congress to understand these threats. You're damned either way. You answered that, quite frankly. But anyway, Mr. chairman, I yield back. >> the gentleman is also off the hook. His time has expired.
▶ 2:12:07Chair now recognizes the gentleman from new york for five minutes. >> thank you, Mr. chair. I fully acknowledge that cyber attacks pose a real and serious threat to our energy system. But I also know that our constituents are dealing with major energy affordability challenges. And every investment a utility makes, whether there's that's in generation, transmission, distribution or security will ultimately be paid for by the ratepayers.
▶ 2:12:32What concerns me is there seems to be no limit to the amount of money that could be invested in well meaning cybersecurity upgrades, without ever being able to guarantee that our system is 100% secure. Again, I don't want to downplay the risks we face from cyber threats, but I'd like to understand the thought process that goes into evaluating whether a cybersecurity investment is a worthwhile use of ratepayers money. So, Mr.
▶ 2:12:58Lindahl, I know co-ops are conscientious of cost increases on their members. How do you think not for profit utilities or even regulators who work on rate cases for other utility business models should think about these issues? >> yeah, from our perspective, how how how we look at it is we try and do things as efficient as we absolutely can. So a lot of times it makes no sense for maybe 900 of us to have a security expert on staff.
▶ 2:13:23But if we can pull together and hire one security expert to share amongst all 900 and leverage other tools like rmq or other things to develop the innovation and the tools needed to fight this, that's a better use of the same dollar and less dollars used to achieve a bigger benefit. >> and how can they best balance the need for cybersecurity investments, while also being mindful of that impact on people's rising utility bills?
▶ 2:13:51>> you know, we look at it from a risk perspective. You know, you have the probability of something happen, the impact that it has. And we focus on those high impact, high probability events first, kind of the low hanging fruit. And then we keep moving back. And we evaluate every, every risk that of that decreasing return to determine what's the impact or what's the probability of that happening. And we evaluate again back to the three legs I talked about earlier the affordability, reliability and safety of our system. That all has to be in balance.
▶ 2:14:19We can't put reliability at the expense of affordability. >> well I thank you for that. And miss arts how is excel thinking about finding this balance between, on one hand, protecting your customers from outages and other cyber related disruptions, and on the other, the effects those investments will have on bills? >> thank you for the question. Similar to my colleague, um, Mr. lindahl, we take a very similar whole risk assessment approach.
▶ 2:14:48Prioritize what we can get the most bang for our buck in terms of that risk reduction. But I want to emphasize, um, a point I made in my testimony that is vitally important, which is the timely and actionable sharing of intelligence so that we can build security in proactively versus bolting it on after the fact. Bolting it on after the fact is much more costly. Building it in at the front end is very cost effective.
▶ 2:15:14And that's why programs developed by idaho national labs department of energy, such as the cyber informed engineering, really help us think through the architecture of our systems to achieve that cost effectiveness and maintain affordability. >> so to Mr. lindahl or miss arts, are there simple low cost interventions or best practices that utilities could adapt to improve cyber security without adding a lot of costs to their customers?
▶ 2:15:42>> yeah, we have a cyber goals program that we implement across all of our utilities that are the basic level cyber hygiene type practices and physical for that matter too. And those are low cost, um, high impact programs. And, you know, kind of the base level goals that everybody should, should, should abide by. >> um, another program that we implement is the training and situational awareness of the threat landscape for all of our employees.
▶ 2:16:10We recognize that our employee base is our best defense. And so on a monthly basis, our security team provides situational awareness on the threat landscape. Um, we also test our employees to so that they are better able to detect phishing attempts. Um, they are our best line of defense. >> thank you.
▶ 2:16:28In april of 2023, ferc issued order 893 to establish an incentive based approach for qualified cybersecurity investments and participation in cybersecurity threat information sharing programs. But my understanding is that utilities aren't really taking advantage of this incentive. So, Mr. ball, are you familiar with this ferc order? >> I am. >> and do you have any insights as to why it hasn't proven to be as effective as the commission may have hoped?
▶ 2:16:58>> uh, you know, from my my current role, I do not um, however, in my prior work, um, you know, certainly, uh, understood those programs to be available, but there is even a cost to try to gain, uh, funding. So, um, it can be prohibitive. >> well, with that, I ran out of time, but I'll have a question that I'm sending your way in writing. And, um, again, Mr. chair, I yield back. And thank you. >> gentleman yields back. The chair now recognizes the gentlelady from iowa.
▶ 2:17:27Good doctor. For at least five minutes. >> uh, thank you, chair weber and ranking member castor for holding this hearing on cyber and physical security of the grid. The threat landscape we face today is unrecognizable compared to even five years ago. Our adversaries, specifically the chinese communist party, are actively seeking vulnerabilities and are critical infrastructure. As we know, russian hackers are doing so as well.
▶ 2:17:52Grid security is national security, and it's the difference between keeping the lights on during a winter storm or facing catastrophic failure. Iowa is leading both research and manufacturing. The department of energy selected iowa state university to lead sidearms, a regional cyber security center focused on securing distributed energy resources. As more renewables are brought online, we're introducing millions of new devices to our grid. Every connection point is a potential vulnerability.
▶ 2:18:22Syndromes is developing ai and machine learning tools to detect attacks in real time, while training the workforce needed to defend these systems, particularly for rural utilities that lack resources. We must also address hardware. We cannot secure our grid if the components we use are compromised by adversaries. The reliance on chinese technology in our supply chain is a glaring vulnerability. We must replace these components while being realistic about replacement speed and alternative availability.
▶ 2:18:51This requires enhancing domestic manufacturing. If we want american companies to build the critical critical transformers and inverters we need, we must make it viable. My bill the limiting liability for critical infrastructure manufacturers act provides domestic manufacturers legal certainty so they can invest in hiring american workers and expanding facilities, rather than hedging against frivolous legal risks. Finally, I want to highlight the energy threat analysis center at nrel.
▶ 2:19:20Etac solves the translation problem converting classified intelligence into tactical operational guidance that utilities can actually use the tools to secure our grid exist. It's our job to ensure that they have the resources and authority to succeed. Mr. ball. The risk environment is intensifying.
▶ 2:19:42We're adding technology to the grid, expanding it to meet surging demand, modernizing aging infrastructure while geopolitical tensions are rising, we need coordination between the private sector and the federal government. Doe, cisa, ferc, the white house and others to move quickly and securely. Can you speak to how the coordination is working today and where you see gaps that need to be addressed? >> so it's a very, very, very good question and certainly a very important apparatus.
▶ 2:20:10Uh, speaking from the perspective of the isac, we see ourselves and we are positioned to be a conduit of information sharing. So with these, our government partners, with our industry partners, we serve as as a pathway and a bidirectional multidirectional pathway for that information sharing. So as curators of that information, we need to see that thriving.
▶ 2:20:36And so we certainly appreciate a great deal of engagement that we see today. But there's absolutely opportunity to empower that. I think we need to see greater, um, you know, encouragement of information sharing and protection of of information sharing from our members as they see incidents. So these are areas we need to see improvement on. >> thank you. Mr. lindell. Iowa has rural utilities that are already resource strapped.
▶ 2:21:01When we tell them they need to replace outdated equipment and integrate new ai systems, what does that actually cost and who's going to pay for it in that context? Can you explain how, c ce sers rural and municipal utility advances, cybersecurity grant and technical assistance program support co-ops and strengthening their cyber security posture? >> yeah, for for the specific costs, I can't necessarily address that for every co-op.
▶ 2:21:30But, uh, you know, when we make investments in any tool, you know, we do a return on investment analysis, just like any good business would do. And we we look at what it's going to provide us and what it costs us and make sure we get back out of it, uh, by pooling our resources together through programs like the, um, we can develop these things collaboratively. So instead of, again, 900 of us developing an ai tool, let's say for an example, we can come together and develop one tool that that works for all of us.
▶ 2:21:58And those those are the ways we kind of have been working together to, to solve that, that, that problem. >> thank you. Mr. tudor. You mentioned that citrix conducts rigorous testing of hardware and software components in the energy supply chain. Given that you've identified china's embedding of hardware vulnerabilities as a major structural risk, how effective are these testing programs? And I know this is terrible, but I'm going to ask you to respond in writing because I'm running out of time.
▶ 2:22:27Uh, but how effective are the testing programs that detecting backdoors or vulnerabilities built into chinese manufactured equipment? And can these programs scale to address the volume of chinese components currently in our infrastructure? So if you'd respond in writing to us, that would be greatly appreciated. And with that, I yield. >> gentlelady yields back. I recognize the gentlelady from washington for at least five minutes. >> oh, I won't go over. Thank you, Mr. chairman. And thank you very much to our witnesses today.
▶ 2:22:56Uh, I'm going to first talk about ai, because the new ai frontier has brought new vulnerabilities and benefits to the grid, um, and also to our broader society, both because of reliance on ai by virtually every industry out there and because ai can be used to foster resiliency in our grid. But it could also be used to sabotage our grid by bad actors. Um, Mr.
▶ 2:23:24Ball, uh, newark responded to the department of energy's request for information on the previous administration's executive order on the safe, secure and trustworthy development of ai, and newark noted that it was committed to identifying and monitoring the risks in implementing ai. Things are moving quickly.
▶ 2:23:45It's a moving target, and I was just wondering if you could quickly talk about what your observations are on the current risks associated with ai, on the bulk power system? >> well, I think, um, it's a great and actually very broad question, but I would say that, you know, I think you characterize it very well that it is a prolific, um, factor in, you know, managing information technology and certainly is within, uh, you know, the
▶ 2:24:16Energy sector. Um, I think that, um, you know, we are certainly learning how it can be, um, misused. Uh, I think we saw heard a discussion a little bit about, you know, the recent demonstration of, of, uh, exploiting, uh, ai tool, um, that was, uh, for, for large scale attack. So I think we're seeing that emerge out. I don't think we're ready yet. Uh, to to really to really handle all of the issues.
▶ 2:24:45I mean, it's an emerging and continually evolving problem. We are monitoring it. In fact, when that threat I just referenced from an ai perspective, which I can speak very discreetly, you know, we were sharing information about that threat and actually things that you can do to help mitigate that risk. Uh, so that I think is the best way I can describe what we're seeing and how we are trying to tackle it. >> thank you. I appreciate that. It feels like we're going to just have to keep keep pace with this.
▶ 2:25:12I'm wondering, do you think that we should just have a fresh evaluation of nrc's critical infrastructure protection standards in light of ai and the new threats and the quick evolution of those threats? >> yeah.
▶ 2:25:26>> so what I can say is that, um, you know, while that's a specific threat area that actually newark is actively looking for ways to advance and renew the, um, the, the critical protection standards, in fact, there's an active, uh, effort underway today to try to find actionable ways to improve that. So, in other words, um, you know, there are opportunities and newark is actually working on. >> great. It's already happening. That's good to know.
▶ 2:25:53Um, I'm going to pivot a little bit to, uh, actually to our infrastructure and transformers in particular, many of you in your testimonies, uh, described or referenced the 2022 substation attacks in washington state. Unfortunately, thousands of those affected were actually in my district.
▶ 2:26:12And while those christmas day attacks luckily only interrupted access to power for a few days, uh, the large power transformers that were damaged in the incident were projected to take months to repair, and I've been talking with utilities about what it takes to replace a transformer. And it's like finding a used one, making some modifications. It's it is not the way our grid should be functioning.
▶ 2:26:39And, um, miss arts question for you is representing a large utility. What is, uh, excels energy's current capability to replace transformers and other critical electrical grid components that might be damaged in a physical or cyber security attack. >> yeah. >> thank you for the question. So we are very aware of the physical threats that are posed to our critical infrastructure.
▶ 2:27:11We have a very robust procurement process that assesses long lead times for important equipment, so that we are prepared to have that equipment in hand. Importantly, as an industry, we have taken on a couple of initiatives to, um, better, uh, provide availability of this critical equipment. One example is the electricity subsector coordinating council.
▶ 2:27:34Um, because of delays in equipment lead times, um, based on the pandemic, looked at the opportunity to reduce the number of specifications for individual transformers, thereby increasing the availability of that critical equipment. Finally, we also have a spare transformer program that can be tapped into when there are emergencies. >> thank you. I am over five minutes. Uh, just thank you for pointing that out, because I think miss miller-meeks pointed to this, too.
▶ 2:28:04We rely on china long lead time too much, uh, individualization in what kinds of transformers can be used. And so it's really hard to have a national stockpile. I think that's something this committee is going to need to help figure out. Thank you. And I yield back. >> gentleman yields back. Chair recognizes the gentleman from florida for at least five minutes. >> thank you, Mr. chairman. And to our witnesses. Cyber security is national security.
▶ 2:28:32And we must remain vigilant in maintaining the security of our grid and all of our critical infrastructure. As cyber and physical threats continue to grow in scope and sophistication, it is essential that we evolve with the threat landscape and that we continue to leverage our public private partnerships, foster information sharing, and build our cybersecurity workforce to be prepared to meet these challenges.
▶ 2:29:00So I appreciate all of our witnesses here today, uh, sharing your substantial expertise and insight about the ways in which we can best strengthen the security of our energy infrastructure and proactively mitigate threats from adversaries and malicious actors. Uh, Mr. tudor, I'd like to start with you.
▶ 2:29:20In your written testimony, you noted the threat that chinese state sponsored cyber threats like volt typhoon posed to our electric grid. I was pleased that a few weeks ago, the house passed the strengthening cyber resilience against state sponsored threats act to establish an interagency task force addressing these cybersecurity threats.
▶ 2:29:43Can you describe for us how volt typhoon and similar actors attempt to infiltrate and disrupt our critical energy infrastructure, or have the potential to lay dormant and do so at a future point? >> thank you, miss lee, for your question. And it was encouraging to to see that different coordination at the federal level being prescribed. Um, I think we are very concerned about the chinese actors in particular.
▶ 2:30:10I mean, we note that russian affiliated actors tend to be very active. They don't lay dormant. They they go for the jugular in many different ways. Um, volt. Typhoon. Typhoon. All of the things that we have designated there, um, have not been imminent threats per se, to our infrastructure, but they are, as you said, lying dormant, waiting for appropriate times to be activated.
▶ 2:30:31Um, across the interagency, the national labs, caesar and others are working on threat and incident response capabilities to be able to work with, um, other utilities to identify those threats and mitigate them where necessary and where possible. Um, and I think we're also developing tools that can be applied across the industry to help with those hunt and threat activities, understanding where the the adversary may be, um, is critical.
▶ 2:30:58One of the things that we also work on is something called consequence driven, cyber informed engineering to try to understand not just, you know, what might happen, but what are the most important, impactful things that might happen and help the government understand where they might invest to mitigate those. >> Mr. ball, on the subject of information sharing and incident sharing within the isac, uh, you mentioned just a moment ago protection for members.
▶ 2:31:24Would you elaborate on whether there are obstacles or reticence that might exist for private partners sharing information about specific, specific suspicious activity or incidents within the isac? Uh, if so, how can we overcome those? Or do you feel at this point that there is, in fact, a very open sharing of incident information within the isac? >> so, uh, it's a very good question. Certainly.
▶ 2:31:50Um, information sharing, we see a tremendous this industry is exceptional at sharing information. And I think we can continue to leverage that. Um, you know, one thing we we see concerns about, you know, you saw the, uh, some of the liability protections that was insisted in 2015, it was issued out, um, you know, with that expiring but subsequently being extended for a period, a little bit period, a small period of time.
▶ 2:32:18Those those provide some confidence to members to say, I can share when we start to see erosion of that protection, then we I'm worried about the atrophy of it. What I need is to see the opposite. We need to see increased sharing information we need to. And the speed in which we do that needs to be based on trust and confidence. And that's something we, I think have a challenge for.
▶ 2:32:44Um, but the good news is we have a tremendous base of capability right now that is working well. We just needed to work better and faster. >> and arts, you just mentioned something that is so important. It had to do with internal employee education. Would you elaborate on why training about things like phishing and social engineering is both critical to cybersecurity and also low cost in many cases? >> thank you for the question. As I said, our employees are our best line of defense.
▶ 2:33:14Um, we are being targeted, um, because we provide essential energy services, both natural gas and electricity. We need our employees to understand that they will be targeted, and therefore we provide them briefs on the threat landscape so they can understand how china and others are targeting us, that they are aware of how clever, um, bad actors are in their attempts to steal credentials that would then allow them to access our systems. So I mentioned the phishing training that we do. So the the testing that we do.
▶ 2:33:45So if you see it, you report it and don't click on it. Um, robust training practices to help them protect our infrastructure. >> thank you, Mr. chairman. I yield back. >> gentleman yields back. Chair now recognizes the gentlelady from our beloved texas for at least five minutes. >> well, thank you so much, Mr. chairman. And thank you to all of our witnesses today for your testimony. Um, it has been alarming and very important.
▶ 2:34:11And as we've heard today, um, the cyber security threats to our energy infrastructure are becoming more and more common and more and more dangerous every year. Um, someone said earlier in this hearing that this year looks different than even five years ago. I think that might be the understatement of the year.
▶ 2:34:28Um, on all fronts, what is happening is really unrecognizable to many of us who were here five years ago, and it really is absolutely essential that congress assert its authority and work to address the challenges that we face.
▶ 2:34:44Um, especially now, um, we know, for example, uh, just in 2023, texans were shocked to learn that, uh, hackers that were backed by the chinese government attempted to access the computer systems used to maintain our power grid in texas. And fortunately, there's no evidence that those hackers gained entry.
▶ 2:35:05But if successful attacks like these could be devastating, causing rolling blackouts for people who live across the state, um, and obviously across the country and other systems, um, as well as cutting off power for emergency services, something we are all too familiar with in our, um, in our region along the gulf coast and some place where long term grid stability is absolutely a priority and a deep concern.
▶ 2:35:33So as grid operators work to expand our energy infrastructure in response to growing demand from ai development, which we've also covered a little bit today, we really have to expand our ability to address these cybersecurity threats. Um, it is crucial that congress takes up transmission, permitting reform so that operators can expand and modernize the grid on pace with demand.
▶ 2:35:55And while we talk about permitting reform, and I am hopeful that we're going to see some coming out of our committee and out of this congress, I really hope that this committee can come together to find solutions to this problem and to address transmission. Um, when I hear from our independent grid operator, ercot, about security issues, uh, chris stands out as an exemplary partnership that's driving real results.
▶ 2:36:19And so I want to acknowledge that, um, and everyone here knows, of course, that, um, it facilitates information sharing among asset owners and operators about cybersecurity threats and leverages the national labs expertise to analyze the threats and provide program participants with information that they need.
▶ 2:36:36I think a lot of people who aren't in this space don't necessarily know and understand the importance of this partnership, um, but I think it is really critical that we are sharing with the people that we represent and people across the country, these examples of these successful partnerships, um, between the government, industry, academia, research institutions, that is something that, um, when Mr.
▶ 2:37:02Weber and I served on the, uh, science, space and technology committee, I was always struck by how well and effective these collaborative partnerships are. Um, and so I think it's just really important to point that out and to emphasize that, uh, when we work together, we can work to get things done and to address challenges like these. Um, but as many of us know, things are not working very well in washington these days.
▶ 2:37:26And I hope that congress will, um, take your testimony to heart, um, and will move quickly on several of the recommendations that you've made. Um, I do have a couple of questions to ask before my time is up. And, um, uh, Mr. chris, you mentioned the need for information sharing and analysis organizations, um, like issac, to ensure that membership includes a broad set of energy stakeholders.
▶ 2:37:54Um, what can congress do to help expand access and utilization of programs like crisp? Give energy stakeholders greater insight into the threat environment? Um, and obviously always a question do do we need additional funding from congress to ensure adequate participation? >> thank you.
▶ 2:38:13Congresswoman, I think that, uh, we've talked a lot about the itac today and its efforts at figuring out new models of turning threat intelligence into practical, uh, helpful advice for different kinds of consumers.
▶ 2:38:27And I think whether it's ensuring that, uh, itac has the authorities and funding it needs or if we need, uh, different variants of it for different subsectors along the way, I think that's something that would be very impactful, especially as our energy ecosystem moves toward one that's more diverse, diffuse and distributed and has more different kinds of actors in it.
▶ 2:38:50>> and just as a quick follow up to that, because this is an issue we've dealt with in this committee, in this congress, can you speak to the importance of adequately funding and staffing the national labs to analyze this data and help keep our community safe? >> absolutely. The national labs are jewels of this nation's ability to do the kinds of technical research, forensic analysis, uh, that gives us the information we need to make risk informed prioritization decisions. >> great. Thank you so much. And, Mr. chairman, I see I've gone over my time.
▶ 2:39:18I appreciate it, and I will yield back. >> thank you. Lady yields back. The gentlelady now from north dakota is recognized for at least five minutes. >> excellent. Thank you, Mr. chairman. Thank you, panel, for your time here today and for sharing your expertise with us on this really important subject matter. I want to focus in on the utilities. Uh, no shock there. Former utility regulator, uh, starting with xcel.
▶ 2:39:46You mentioned that excels coordination with rtos and isos and participation in the regional planning and resource sharing arrangements. Um, can you briefly kind of, in an overview, describe how these relationships address, not necessarily the prevention, but the restoration of power in the event that we do have a cyber attack? Yeah. >> thank you for the question. Um, we recently just hosted the eighth annual grid x, um, exercise.
▶ 2:40:16Xcel energy had 316 participants this year. 64 of those were external stakeholders that are critical to looking at how we quickly respond and recover from really bad days.
▶ 2:40:28Um, the the scenarios that we infuse into the exercise are pretty extreme to get us really thinking about what if we're not able to rely on our traditional tools, the importance of the collaboration in advance of the incidents, and then making sure that we are exercising the actual execution of those response capabilities.
▶ 2:40:52>> and can you share with me what is different about responding to a cyber attack versus like a bad snowstorm or weather related blackouts and impacts? >> so I think there are two things. First, a cyber attack probably is not going to be forecasted, right? We might get some intelligence from our government partners that there are imminent attacks, but likely the actual occurrence of the attack is not going to be forecasted for us.
▶ 2:41:18Secondly, the cyber attack can render the destruction of equipment similarly to a storm. But then it means that we are not maybe able to, uh, trust the device once we get it back into operational mode. Um, that is why we need, um, information and assistance on ensuring the backups of our systems, um, that we have access to equipment.
▶ 2:41:47And then I'll just note that we, as a company and industry are really looking more and more at zero trust types of environments, knowing that we have to be maybe suspicious of the device, um, the communication that's coming from it so that we are operating in a mode or manner that allows us to continue to provide those reliable services. >> and then how does excel prioritize baseload units in emergency response drills?
▶ 2:42:16>> uh, congresswoman, I would probably have to get back to you on the exact answer for that question. But we do include all of our energy sources in our security drills. >> okay. No worries. Um, are there emerging ai related vulnerabilities? And how are you using ai to both detect and recover, and what other vulnerabilities are being created by ai? Both you and Mr. lindell, if you could address that.
▶ 2:42:45>> so we are working with the national lab complex, with the department of energy on understanding the threats that are posed by ai. We are utilizing ai in our business environments to create efficiencies. But as with any new technology in the actual operational environments, we are slow to implement because we want to understand the impact on reliability. Um, from these new technologies.
▶ 2:43:12>> and the only thing I will add is, is, you know, we're working with vendors independently, but we're also working together with folks like neca to develop the ai tools to to enhance our grid. >> okay. Very good. With the one minute, um, well, 30s remaining, Mr. tudor, um, can you talk about how adversaries, adversaries are using trusted vendors or software, updated channels to gain access to critical systems in 20s? >> yeah, thank you for that question.
▶ 2:43:42>> yes. So, um, the software update process, some of the various ways that technologies can be improved can also be another vector, um, for, for malicious actors. Um, I believe some of our programs, such as citrix, that will identify those update paths and make sure that they are more secure themselves.
▶ 2:43:57Also, several of the different, as I mentioned before, hunt and incident response type capabilities that the national labs bring together can also look for some suspicious or malicious update sites and try to take them off and once again provide the information to many of the people that are represented here. >> excellent. Uh, thank you all, Mr. chairman, I yield back. >> gentleman yields back. Chairman, I recognize the gentleman from california for five minutes. >> thank you, Mr. chair. And thank you to our witnesses for your testimony today.
▶ 2:44:24Our electric grid is at a moment of generational transformation. After decades of stable energy usage, the rapid growth of data centers and adoption of electric vehicles and appliances are driving a sharp increase in energy demand. We need to expand our energy infrastructure while ensuring it remains resilient and secure. This moment presents both an enormous opportunity and a significant national security challenge. I believe american innovation can help us seize the opportunity and mitigate the risks.
▶ 2:44:53As digital technologies become more embedded in the grid, it is also exposing our aging infrastructure to increasingly sophisticated threats, such as china's typhoon campaign, which many of you have discussed today. Congress anticipated these challenges when it created the grid resilience and innovation partnerships, or grip, at the department of energy and the bipartisan infrastructure law. Yet, the current administration has said it would cut more than $2 billion, disproportionately targeting democratic states.
▶ 2:45:21At the same time, it proposed a 15% budget cut to the cybersecurity and infrastructure security agency, undermining our collective goal of achieving a more secure and more resilient grid. With these constraints, we need to ensure faster returns on our investments in research and development. Our national labs are leading groundbreaking work to identify and mitigate security risks in the energy system.
▶ 2:45:46My staff has seen these projects firsthand at idaho and lawrence berkeley national labs in the bay area, but too often there is a gap between lab innovation and commercial deployment on the grid. So, Mr. tudor, based on your experience at the idaho national lab, what are the most significant barriers preventing grid security innovations from moving quickly from the lab into commercial use by utilities and manufacturers? >> thank you. >> for that question.
▶ 2:46:14I've worked a very long time on some of the different commercialization aspects and the the valley of death that we all experience. Um, I think that it's, it's hard for, for national laboratories whose primary missions, um, focus around research, but also those partnerships to be able to do the marketing necessary, uh, to, to make commercialization possible. But we do work with some of the new programs within the department of energy, the technology transition programs, etc.
▶ 2:46:41Who are providing grants to help those technologies move forward. We also bring partners in, like the nreca members, other utilities, to come help us beta test these programs and see for themselves. So when we have an advocate that has seen the benefit of one of these programs, um, right now, one of the tools that we have developed called malcolm, which is an intrusion detection and monitoring and analysis capability that is open source, has been tested and sponsored by many of the utilities.
▶ 2:47:10And so we've been able to get that out and make a big impact, I think. Um, so we have to practice more about how we can do transition, uh, the department, but also we have to, you know, work with our partners to make sure they understand the capabilities we might be able to give them. >> appreciate that, Mr. tudor. Uh, my next question is, uh, Mr.
▶ 2:47:30Chris, much of your testimony outlines how china's dominance in manufacturing and components like smart inverters and batteries poses a national security risk to build long term american industrial leadership. How should congress prioritize and sequence its efforts between the near term need to onshore existing components and the longer term investments in next generation energy technologies? >> thank you for that question, congressman.
▶ 2:47:56That's, uh, I think the key question underpinning a lot of this, uh, I think it's instructive to take a look at the the case of the f-35, which does not have zero chinese made components. Uh, the defense industrial base instead makes a risk informed prioritization decision about where the cut line is for, uh, components sourced from anywhere you can get it, or from, uh, the united states, from our allies and partners.
▶ 2:48:22And I think congress could play an important role in helping catalyze that kind of prioritization among the broader electricity equipment and electro tech field and advanced manufacturing more generally, to help us focus on what the highest consequence, highest risk priorities should be that need that urgent scrutiny and what kinds of sustained industrial investments are going to be necessary to patch those risks. >> appreciate that. Thank you. And thank you all for your testimony. And, Mr. chairman, I yield back. >> gentleman yields back.
▶ 2:48:51The chair now recognizes the gentleman from colorado for five. The gentleman from ohio for five minutes. >> thank you, Mr. chairman. Uh, thank you all for being here today. Uh, and how we can secure our critical energy infrastructure. So appreciate your time here. Two weeks ago, the us-china economic and security review commission released their 2025 report to congress.
▶ 2:49:17In this report, the commission stated the extensive use of chinese components in the us grid creates risks for cyber espionage and sabotage. As our nation looks to increase grid resiliency and reliability in the face of historic electricity demand growth. Congress, in all relevant energy stakeholders must work to reduce our reliance on foreign adversaries, such as china, to meet our energy needs. My first question is for Mr. tudor.
▶ 2:49:46Um, in regards to china, russia, iran and north korea and north korea. You note, although the united states is not the only nation in the crosshairs of these advanced persistent cyber actors, the unique makeup of our critical infrastructure and key resources make us particularly vulnerable. Can you discuss why the united states is uniquely vulnerable to cyber attacks on our grid? >> thank you for. >> that question, congressman.
▶ 2:50:16I think the first thing is that, um, one of the first major countries to have an electric grid like this, and we sometimes say that it is the most complex and complete, um, machine in the world has been built up over decades and decades, you know, almost a century.
▶ 2:50:32And so as we keep adding new components, um, and keeping old components, those interfaces, as have been mentioned before, sometimes become vectors for attack, understanding how to and where to update some of these equipments with new technologies which help digitize and provide different benefits, but also may contain some of those components that we are concerned about, also puts us at risk. Um, I think that we are the leader in understanding cyber risks, um, internationally.
▶ 2:51:02And I think that is the other aspect that makes us more of a target and also as the number one economy in the world, obviously, we are, uh, a, a rich adversary to, to go after, um, you know, because of the infrastructure, you know, not being owned by the federal government by any one entity, but being owned across different types of asset owners, different asset types also provides a little bit higher risk. And we all work on protecting all of those different types of assets.
▶ 2:51:32>> okay. Thank you for that answer, Mr. tudor. Um, you also mentioned that the emergence of ai has shown promise in the ability to enhance grid operations and defend and defend the grid from cyber attacks, but it also introduces risks that could be exploited by cyber attacks. Can you expand on some of those risks? And how is the idaho national lab working with ai stakeholders to address those risks? >> yeah. >> thank you again.
▶ 2:51:58Um, ai is, uh, is not the worst thing that we've seen happen, but it is a powerful new tool for both malicious actors, but also for defenders. Um, as mentioned before, adopting some of the new technologies, um, you know, is not without risk itself. And so we are working with utilities to understand what actually ai enabled defensive capabilities that come from vendors may actually do and how they might be subverted.
▶ 2:52:24Um, looking at how ai enabled offensive tools might identify risks in our critical infrastructure is something that we and other national labs work on as well. Um, we can't necessarily defend something that we don't understand or don't know where it's coming from. So we are looking at all of the capabilities of our adversaries to see where they might apply ai. And it's a continuous battle.
▶ 2:52:47Uh, you know, we work on developing, you know, understanding of the adversary as well as developing new technologies to work to defend the grid and to reduce risk. >> thank you. Well done. Uh, my last question, uh, is for Mr. liddell, uh, as you mentioned, rural electric cooperatives face unique challenges as your infrastructure often covers thousands of square miles with few customers per mile.
▶ 2:53:12Can you discuss the difficulties co-ops might face protecting your rural and remote infrastructure? And how can congress and relevant federal agency support your efforts to protect against physical and cyber attacks to your infrastructure's 30s, sir, please. Thank you. >> yeah, it's a difficult challenge because we're so spread out. Um, but how congress can help is to continue to fund things that allow the innovation to address these challenges.
▶ 2:53:39Uh, so, like the rmcc program and other programs like that, uh, you know, congress can fund those and come together and allow the industry to identify the unique challenges they face and work together to solve those problems. >> the gentleman yields back. The chair now recognizes the good doctor from pennsylvania for know for colorado. Uh, for five minutes, doctor or not, we recognize you. >> thank you. Thank you, Mr.
▶ 2:54:09Chair. I'm glad to be upgraded to doctor, even though I'm not, of course, the ranking member. And then, thanks to our witnesses, um, for taking the time today. Um, my first question will be to Mr. kresha. Did I say that right? >> just crazy, sir. Thank you. >> tracy. Got it. Um, you talk about in your testimony how important it is to organize the disparate modern energy and national security stakeholders across public and private sectors. And so I think we've talked about a couple of different facets of that.
▶ 2:54:35Um, so far in the testimony, one thing that I wanted to hone in on a little bit, um, in a previous life, I spent 12 years in the us army, in colorado army national guard as a helicopter pilot fighting wildfires. Uh, and so we know that wildfire risk, especially in states like colorado, which is one of the most at risk states, has a direct impact on critical infrastructure like energy distribution systems.
▶ 2:54:59And so, um, I would just love to hear your thoughts on things that the federal government can do to bring together some of those different actors that are in the, um, the immediate response to natural disasters and then the long term follow up, uh, specifically when entities may be facing lawsuits or any other sort of liability that potentially has the capacity to bankrupt, for instance, a rural electric provider. >> thank you, congressman, and thank you for your service. Uh, I think that's a very important question.
▶ 2:55:28Uh, the, uh, I like to think about how our the steps we can take, where it's technology, resources, information sharing to ensure the security and resilience of our infrastructure often looks very similar, whether we're talking about a hurricane, a hacker, or a wildfire.
▶ 2:55:44And that's ensuring that we are practicing how to respond, how to anticipate, with the right stakeholders at the federal, state and local level all along the way, and the critical role that, uh, institutions like the isac and itac, uh, and that their sector risk management agencies at department of energy, cisa and elsewhere play in convening all those stakeholders can't be overstated. Uh, this is a complex. As Mr.
▶ 2:56:14Stewart has said, this is one of the most complex and complete machines in the world that's manned and, uh, and operated by just many, many thousands of people with all different kinds of resources, all different kinds of backgrounds and level of expertise, and the convening power and national leadership function that the federal government plays is absolutely critical just in terms of information, but also resourcing and information sharing. >> thank you. Same, same question to Mr. lindell.
▶ 2:56:42I know you represent some of these rural electric co-ops, um, natural disasters, immediate response. And then longer term, specifically with thought to like some of the insurance and liability questions that emerge in this space. >> yeah. You know, we deal with, uh, equipment. You know, it took us over, you know, nearly 100 years or 80 years in our case to build our grid. You know, we can't afford to rebuild it overnight. Um, so we adapt and prepare. And like Mr.
▶ 2:57:10Krishna said, you know, it it really makes no difference what the threat is. Um, we need to respond the same. Whether it's a wildfire, cyber security, physical security incident. So part of it is we prepare and we have things ready and in place to go should something like that happen. But then the second part is, you know, we really identify how can we get ahead of it? How can you know, how can we learn from the past and really, uh, learn how to mitigate these costs in the future? So we don't have those significant costs.
▶ 2:57:40>> great. So along kind of similar lines, being able to have that pre-planning, um, to be able to mitigate any sort of major disasters, um, we just talked about it. I want to switch a little bit to supply chains. Now, how can we make sure, as you said, the grid is, you know, 80 to 100 years old? How can we make sure that we're prioritizing, um, either new components or new technology? And we also have the supply chain to be able to roll those things out, specifically focusing on things like permitting reform.
▶ 2:58:08That's been a big emphasis of mine to make sure that we just have the manufacturing capacity to be able to do things like get newer, modern transformers, um, generating turbines, things of those natures. Can you can you speak to the supply chain component of this and what congress should be focusing on? Um, to do that, that triaging and prioritization that we previously discussed in the context of f-35s 35 seconds. >> yeah.
▶ 2:58:31One of the things we're doing as cooperatives, as we partner together, uh, like we do with many things, and we have our own suppliers and we self source a lot of our stuff that that we actually utilize and that keeps it in the family. It allows us to have the full control over it. Uh, as far as, uh, you know, the government helping us is really vetting, you know, those components that are coming in.
▶ 2:58:50We don't have the the ability to to really understand the threats that are coming in from overseas or the threats, even from within our own walls, you know, how can you how can congress put into place through the national labs and other partners to do that vetting on our behalf, because we don't have the ability to do that ourselves. >> thank you. Yield back. >> gentleman yields back. Now, the chair recognizes the good doctor from pennsylvania for five minutes. >> thank you, Mr. chairman. And thank you for holding this important hearing today.
▶ 2:59:18>> this year, our committee has discussed at length how critical an affordable and reliable. Grid actually is. Much of this conversation has been focused on how we can improve the generation, transmission and distribution of electricity to support all of america's energy needs and to spur the economic and technological growth necessary to compete with our adversaries. As electricity and demand for it continues to grow.
▶ 2:59:46And as we build out more infrastructure to support this demand, securing the grid against both cyber and physical threats. These will both become even more challenging. Building up necessary energy infrastructure is the first step in reliability, but keeping it operational in spite of numerous state and criminal actors who see our electrical grid as a target, will be a continuous and an ongoing challenge.
▶ 3:00:15Each technological advancement used to enhance the grid or new piece of infrastructure that is brought online, represents a new vulnerability for threat actors to target the political or financial gain that might be achieved. I represent an incredibly beautiful rural area in pennsylvania, which provides unique challenges to both cyber and physical grid security. Mr.
▶ 3:00:42Lindell, how can we ensure that we are utilizing the more limited resources in rural areas to identify and secure the infrastructure which is most vulnerable to attack and most critical to keep online? >> I think through partnerships, you know, one of the things we do well is cooperatives is is we, you know, we proactively take a look at what we can do to solve it, but then we also have the reactive approach.
▶ 3:01:08Um, so we work and it's quite evident when you see a hurricane come through florida. Let's say, you know, we have a mutual aid system set up that we send folks down and help restore power in florida. We have similar things set up with a lot of our equipment manufacturers and transformers and things like that nature. So that helps us mitigate when stuff does happen.
▶ 3:01:28>> in central pennsylvania, we see that cooperation with our rural electric co-ops, they're incredibly interactive and incredibly cooperative, whether in face of emergency or in the day to day activities that they provide. How can the coordination and information sharing that you talk about between rural electric co-ops like yours, help those with limited resources to function more effectively?
▶ 3:01:52>> so one of the things that that we've talked about and I talked about in my testimony was, you know, funding programs like the rural municipal cybersecurity program, because that helps us develop collectively the tools that we can, um, and we can share the the knowledge and information from the larger cooperatives down to the smaller cooperatives. And it really allows us to share those resources among no matter your size.
▶ 3:02:15>> do you feel that any regulatory or knowledge barriers currently exist that make proactive coordination that you're talking about in advance of threats more difficult? And is there action at this committee specifically, or congress in general, should take to remedy such barriers? >> you know, my caution would be is as as we develop regulatory, the regulatory environment, especially around physical and cyber, uh, you know, that we don't stifle the innovation to, to, uh, address the.
▶ 3:02:44>> I am so glad you teed up innovation because I think that is so important. So I'm going to move my questioning to Mr. tudor. In your testimony, you referred to unmanned aerial systems and the testing of that at johnstown airport in pennsylvania. In my district, doctor larry knowlton, through his group arium, is working to grow us uas pilot workforce and advance uas innovation. You and I recognize how important that can be.
▶ 3:03:12Can you elaborate on how you see uas integration as a way to improve grid security, and how the training of uas workforce can prepare individuals for these security applications, as is currently going on right now in johnstown, pennsylvania. >> thank you for your. >> question, congressman joyce.
▶ 3:03:34Um, so, you know, training in all of these critical areas is something that's near and dear to my heart as well as innovation, as you mentioned, um, we have a uas and uas capability at the idaho national lab and that 890 square mile, working with programs such as those, uh, to help look at specific use cases. And one of those is the ability to look at different critical infrastructures, whether it's for overgrown vegetation or concentrations.
▶ 3:03:58So having those capabilities, using those uas, um, to help protect critical infrastructure is one of the early use cases. And I think it will continue to be a use case for that. >> securing our electrical grid against threats we all recognize is critical, and we need to explore that even further. I look forward to working with this committee to ensure that america maintains the most reliable grid, the safest grid that is possible. Thank you, Mr.
▶ 3:04:26Chairman, and I yield. >> the gentleman yields back and the chair now recognizes himself for for at least five minutes. Thank you all for being here. Uh, moore county, north carolina attack in december of 22. Y'all are familiar with that? We were out there with the committee. Uh, we saw 27 shell casings on the ground. You're talking about, uh, a high powered rifle. We watched very. We looked at it very carefully. Very closely.
▶ 3:04:54Every single round was put in this far down from the transformer so they could drain the oil. Then they had an oil tank that held, I don't know what the 250 gallons had two rounds put in it. They knew exactly what they were doing. They didn't go there and just start shooting the place up. So when we talk about hardening the grid, are we talking about higher walls? Are we talking about getting that facility off away from the beaten path, as the poet once wrote, or are we talking about having security there?
▶ 3:05:2224 seven ideas on protection to protect these substations. Mr. ball, we'll start with you. >> well, thank you for that question. And certainly that concern has plagued us for many years. Our industry has seen it even with, um, you know, uh, you know, uh, vandalism, for that matter.
▶ 3:05:40But just all the way back to the metcalf substation attack, where there was a very purposeful and knowledgeable, uh, attack on a physical attack on on a substation, which had some significant implications. And I think we saw that flare up. Um, I think what we need to. I don't think you can build a wall tall enough. I don't think we can afford the cost necessary to harden that infrastructure to prevent against ballistic attacks.
▶ 3:06:07When there are other attacks, scenarios such as, um, you know, drones, you know. >> you can shoot those down if you have the experts there. >> if you have the expert and the authority. >> you can get those experts from texas, by the way. >> yeah, yeah, yeah, uh, I couldn't footstomp enough, but I think we just there's a lot of different threats to physical, uh, physical threats to a substation. And, uh, you know, again, you know, while you have ballistic attacks is a legitimate concern.
▶ 3:06:34You know, it also, um, you know, drones are, uh, do pose a real, real concern for industry. Um, and I think that's another area where we need to put some focus on, which is, um, you know, unlocking the capabilities. >> sure. Well, Mr. linda sánchez, you're in the business. You're in what say you? >> yeah. So I think there's a lot of low hanging fruit that we can do before we, you know, build walls to actually stop everything. And a wall won't stop absolutely everything either.
▶ 3:07:02Um, you know, things we're looking at from a, from policy perspective, you know, really not putting our infrastructure out there, uh, where people can easily access what it is and where it is and what it does. Um, those are some simple things we can do, uh, to what we're doing at kinergy is part of the reason we're building our fiber network is so that we have better insight, better monitoring of our system, and we can have quicker and more accurate response and maybe hopefully catch things sooner than later.
▶ 3:07:28>> last I heard, there was a move for a different kind of transformer that were in very, very short supply. Is that still the case? Were there using were the were the government is mandating different transformers or was that just under biden? >> um. >> not ringing a bell. >> yeah. There was a you know, there was a push to use a different type of steel that was going to kind of struggle for us to keep up with manufacturing on the smaller transformers in particular.
▶ 3:07:57Um, for the ones that take the actual time, you know, we're talking about the big substation transformers. Um, you know, those I don't believe were in that bill, but. >> but smaller transformers still all good. >> still. >> we're okay. >> we're good. >> good. Couple of things that we've been talking about. When Mr. peters was here doing his five minutes, he talked about wildfire risks. So I'm going to come to you is wildfire. It's not can't be just in california. There's got to be other areas. How how widespread is that.
▶ 3:08:27>> so we are seeing increased risk from wildfire across our entire service territory. Um, being here in washington, D.C. we saw the smoke from the canadian wildfires, right, a couple summers ago. So it is something that all utilities are working collectively on risk mitigation best practices, sharing that information. We're investing in technologies to better detect when fires are ignited.
▶ 3:08:52And then we're actively working with our government partners on access to, um, the rights of way to do the vegetation management we need to do to minimize those risks. >> thank you. Now, the next question I have is about data centers. Has anybody come up with a concise guesstimate of how much power is going to be needed? I'll start with you. Mr. is it say your last name. >> kray, sir. >> that's what I would have said. >> um, it's a very large amount.
▶ 3:09:22Uh, I think there are some question about precisely how much, but we're going to need more power than we have now and more flexibility than our grid currently provides. >> okay. And then I'm going to go one more place. With that, I yield to the gentleman from michigan in just a minute. And that is this. Is anybody calculating what the united states population is going to look like in 4 to 5 years, when all this stuff comes to fruition? Anybody do we know what the population is going to be?
▶ 3:09:52Is there any guesstimates that have been kind of mixed in with this discussion? Mr. ball? >> I can't say that I have, um. >> there's time, miss hours. >> we work very closely as a regulated utility with our state regulators and other stakeholders, and inject a lot of information and thinking through that resource planning that we need to do. But I don't know, off the top of my head if it includes population. >> lyndal. >> I don't have that information.
▶ 3:10:22>> jason I can speculate that probably not vastly different in five years, but potentially more after that. >> I think you're on to something there. It's going to be a lot more. Mr. tudor. >> you know, I don't believe, um, you know, that I don't know that number, but I know that in a lot of the calculations and the answer, a very large number, um, the growing population is also interesting. >> thought popped up in my head listening to all this, all the discussion we're having. Thank you all for being here. Now, the gentleman from michigan is recognized for five minutes. >> thank you, Mr. chairman.
▶ 3:10:52Michigan families are already paying the price for an energy policy that is based more on fantasy than on physics. Reserve margins are tightening, reliability warnings are increasing, and we are watching generational assets that were scheduled for retirement get pulled back into service because democrats were more focused on solar and wind than nuclear and natural gas, the system cannot absorb the loss. The campbell plant in michigan is a perfect example. It was slated to shut down, but americans could not afford to lose that reliable, dispatchable power.
▶ 3:11:21Now, ferc is reviewing whether michigan ratepayers should be compensated for the burdens of cost created by keeping this plant open and avoiding unavoidable brownouts for the rest of the region. We are continuing to work with those organizations here to make sure michiganders do not shoulder that burden alone. That tells us something very clear. Despite these facts, we are not transitioning from strength. We are backfilling reliability gaps created by policy decisions that were ignored.
▶ 3:11:48The operational realities of the grid. Yet governor gretchen whitmer continues to push aggressive net zero mandates that force early retirement of dependable baseload generation, increased dependance on weather driven imports, and accelerate deployment of complex digital systems that add new vulnerabilities without strengthening the backbone of the grid.
▶ 3:12:09At the same time, the technologies being deployed under these mandates solar inverters, ev chargers, battery systems are far more digitally connected than traditional generation. They increase the number of access points adversaries like the prc can exploit, and they expand the cyber attack surface. At the moment when the threat environment is becoming ever more aggressive, not less so.
▶ 3:12:35My concern today is straightforward michigan's being pushed into high cost, high risk energy future before the grid is ready, before cybersecurity standards have caught up and before consumers have real protections in place, we need clear answers on reliability, impact, the cyber vulnerability and the financial burden being placed on families. Mr. ball, in your view, are these rushed net zero policies creating both higher costs for families and greater cyber exposure for the grid? And at the at the very moment that we are changing course?
▶ 3:13:07>> uh, to be candid, I don't have enough contextual understanding to be able to give a affirmative or negative answer to that, but I admit that it is a very significant issue. >> okay. Well then net zero technology such as solar inverters, ev chargers, battery systems and similar technologies, um, does accelerated deployment of these devices expand the attack surface for adversaries such as prc? >> absolutely.
▶ 3:13:34>> and, uh, based on current threat levels, are today's, uh, newark cep standards sufficient to manage this increased digital exposure, or are we adding technology faster than we can secure it? >> well, I can say that, um, you can't look at the regulation or the standards to be completely comprehensive, but I can say that, you know, newark on that that side of the house is is actively looking for more agile and adaptive, uh, standards, writing to adapt to the changes that are happening.
▶ 3:14:04So, uh, I know there's attention to that, but I would have to provide additional detail at a later time on, on what they're doing. >> thank you. Continuing to strive toward a greater, more sustainable and affordable energy future is in all of our best interest, but we must remain focused on the reality at hand while we strive toward a brighter future. Mr. chairman, that I see the balance of my time. >> gentleman yields back. I'd like to thank all of the witnesses for being here today.
▶ 3:14:34Members may have additional written questions for you all. That's a texas term. I'll remind members that they have ten business days to submit additional questions for the record, and I ask that the witnesses please do your best to submit responses within ten business days. Upon receipt of the questions. So I ask unanimous consent to insert in the record the documents, including on the staff hearing documents lists without objection, so ordered that objection. The subcommittee is adjourned.