What's Happening?
The Joseph Rainey Center for Public Policy has released a new policy brief titled 'Securing the Grid While Growing the Grid,' which argues that the security of the U.S. electric grid should be determined by rigorous cybersecurity standards rather than
solely by the country of origin of its equipment. Sarah E. Hunt, President and CEO of the Joseph Rainey Center, stated that while the origin of equipment is a risk signal, the critical factors are who can access it, who controls its software and updates, and the trustworthiness of its communications. The brief suggests that existing frameworks from organizations like NERC, NIST, IEEE, UL, and IEC already provide measurable standards for supply-chain security, operational technology, software integrity, access controls, and industrial control systems. The Center recommends that federal policymakers prioritize verified software, U.S.-controlled operations, independent testing, and protected operational data, while preserving exclusion as a tool for equipment that cannot meet these standards or presents unmitigable risks. This policy discussion comes as U.S. electricity demand is projected to increase significantly, with NERC forecasting a 24% rise in summer peak demand over the next decade, and a substantial portion of critical grid components, such as large transformers and power inverters, being imported.
Why It's Important?
This policy brief is important because it challenges the prevailing focus on country of origin in U.S. critical infrastructure security, particularly for the electric grid. By advocating for a standards-based approach, the Rainey Center suggests a method that could enhance national security without hindering the necessary infrastructure investments to meet rising electricity demand. The U.S. relies heavily on imported components for its grid, with 80% of large transformers and over 90% of power inverters installed in the last decade being imported. An origin-based exclusion policy could severely impact the availability and cost of these essential components, potentially delaying grid modernization and expansion efforts. Conversely, a robust standards-based approach could ensure that all equipment, regardless of its manufacturing location, adheres to strict security protocols, thereby mitigating risks from insecure remote access, compromised software, or untrustworthy communications. This shift could benefit U.S. industries by fostering a more competitive market for grid components, as long as manufacturers meet the specified security benchmarks. It also aims to protect consumers from potential service disruptions and economic losses that could result from cyberattacks on critical infrastructure.
What's Next?
Federal policymakers will likely consider the recommendations put forth by the Joseph Rainey Center for Public Policy as they continue to develop strategies for securing the U.S. electric grid. The brief's emphasis on verifiable standards, U.S.-controlled operations, and independent testing could influence future legislation and regulatory guidelines concerning critical infrastructure procurement and deployment. Stakeholders, including grid operators, equipment manufacturers, and cybersecurity firms, will need to adapt to any potential shifts in policy. Manufacturers, both domestic and international, may face increased pressure to demonstrate compliance with stringent security standards, potentially leading to investments in more secure design and testing processes. The debate over the Defense Ministry's role in civilian network defense, as seen in other countries, could also intensify in the U.S. as the threat-hunting program scales, with privacy and civil liberties groups potentially pressing for clearer oversight rules. The ongoing increase in U.S. electricity demand will further underscore the urgency of finding a balance between security and the need for reliable, affordable grid expansion.
Beyond the Headlines
The Rainey Center's brief delves into the deeper implications of cybersecurity policy, highlighting the ethical and practical challenges of securing critical infrastructure in a globalized economy. The argument that 'domestic production is not, by itself, a cybersecurity standard' underscores a fundamental shift in thinking from nationalistic protectionism to a more nuanced, technical assessment of risk. This approach acknowledges that a domestically assembled device with insecure remote access can pose as significant a threat as a foreign-made one, emphasizing the importance of intrinsic security features over geographical origin. The brief also touches upon the long-term shift towards greater scrutiny of software integrity, access controls, and data handling, which could trigger a broader re-evaluation of supply chain security across various sectors. The public polling data cited, indicating that voters prioritize how equipment is built, tested, and controlled over where it is made, suggests a potential for public support for such a standards-based framework, moving beyond simplistic 'buy American' mandates to a more sophisticated understanding of cybersecurity in an interconnected world.













