Thursday, December 9, 2010

Pike's New Smart Grid Security Report Available


Boulder, Colorado-based Clean Tech research firm Pike Research recently released a comprehensive report on the current state and market size of the security business related to global Smart Grid initiatives. This is such a nascent market, you've got to give them credit for even attempting this project. And having seen it, I can say it's a darn good piece of work. You can see Pike's own description and the table of contents HERE as well as register to pay and get a copy (yes, it costs significant money).

If you want to get a better feel for the experience of the lead author, Bob Lockhart, THIS detailed Q&A on Smart Grid security was just posted yesterday, 8 December 2010. There's a lot of goodness in the interview, and I like this comment here on getting employees on the right (and same) page:
One area of security that gets too little attention in smart grids is employee awareness. It is critical for employees of utilities, systems integrators and other involved entities to understand what security is implemented, why it is there, and their responsibilities to support it. This requires a proactive education program. Whether we’re talking e-mails, Web courses, or stand-up instruction matters less than that the points are gotten across to the workforce.
In light of this year's biggest attacks: the one targeting IP theft at Google and dozens of other large co's, Stuxnet, and Wikileaks, it's clear that employee awareness (and it's lack) and behavior played a major role in all of them. In his big report, Bob tackles standards, business drivers and technology challenges too, and I think he describes it all with a substantial amount of mastery. Might be worth your while to check it out.

Photo credit: krytofr on flickr.com

Wednesday, December 8, 2010

Life's Rich Pageant: Smart Grid Resistance Movements


Since I've been covering their emergence, Smart Meters, the gateway drug for the Smart Grid, have been  alleged to do some or all of the following:
  • Cause confusion or brain cancer
  • Facilitate attack by foreign nations
  • Help utilities get rich by cranking up rates forever
  • Give Barack Obama control of your house
  • Signal criminals when your house is ready to be robbed
  • Reveal to the government when you're doing naughty things
  • Reduce fertility in laboratory mice
These stories pop up all over, but here's the latest from Maine and California. And lest you think this is a phenomenon unique to the USA alone, here's a vigilant gentleman chiming in from north of the border:
... these so-called 'Smart Meters' may be deliberately 'tricked' to register a higher consumption reading than is actually true. Obviously, this would produce more revenue for the greedy utilities and the greedy governments which are constantly looking for new ways to screw the people.
Well said Sir! And tell you what - if after reading these you find yourself converted, you can go HERE for all your anti-Smart Meter propaganda needs including bumper stickers and yard signs.

We're trying to update the grid for the 21st century: bringing better efficiencies, improving reliability, and enabling greatly increased use of renewables and EVs, and this is the response from some folks.

As Charlie Brown used to say, "Good grief."

Photo credit: "Radio Waves" by Thomas Anderson on Flickr.com

Tuesday, December 7, 2010

FERC and NERC Down the 2010 Cyber Security Standards Home Stretch


Been saying it all year: tension is building between those who want to tighten up security standards faster and those who was to take a gentler, but more predictable path. FERC and NERC have been the primary protagonists in this struggle, as described a few months ago HERE.

For those who are paying attention, a few items that have surfaced as the year winds down, and here's a short summary for you:

First we have the so-called "bright line" ruling in which FERC says we (especially NERC) need a new and crisper definition of the bulk electric system (BES). Here's an excerpt in their own words:
Today's final rule directs NERC to revise its definition of the term “bulk electric system” to ensure that the definition encompasses all facilities necessary for operating an interconnected electric transmission network .... FERC said the ultimate goal ... is to eliminate inconsistencies across regions, eliminate the ambiguity created by the current characterization of the 100 kilovolt (kV) threshold as a general guideline, provide a backstop review to ensure that any variations do not compromise reliability, and ensure that facilities that could significantly affect reliability are subject to mandatory rules. 
So the ball's in NERC's court on that one. A few days after that press was released, FERC Commssioner Jon Wellinghof spoke out on security and the Smart Grid for Forbes.com. Seems like he really wishes things could go a lot further and a lot faster than they have so far, and that Congress hasn't come through yet:
... there have been a number of legislative proposals put forward, none of which have been passed….
Without mentioning it by name, he also plugs the GRID Act which is still stuck half-way through Congress:
We do believe that there’s some additional authority necessary with respect to cyber-security, especially with respect to an imminent threat or vulnerability. We think FERC needs the authority to issue an order to the utilities to take a specific action. Right now we don’t have that authority. It all has to go through the National Electric Reliability Corporation…. It’s kind of a cumbersome process now, that takes a lot longer than you would want if you knew of some immediate threat or vulnerability….
Which brings us to some analysis of what's on deck for 2011 in the NERC CIP world. From NERC CIP compliance experts Abidance Consulting, here's their well informed take on which way this will likely play out in version 4 of the CIPs:
The NERC CIP Standards are being reviewed and updated by various NERC committees to include the Standards & Development Team .... The new version(s) will categorize Critical Assets and Critical Cyber Assets based on impact assessment as “High”, "Medium" and "Low". The new methodology will not use the current Critical Assets and Critical Cyber Assets. [Rather], CIP standards will be customized to each category based on their impact on the BES ....
That's a heck of a lot of change. Too much for some, though others would call it long overdue. And here's a big (and good) one:
The new version of CIP will expose several assets to CIP compliance requirements unlike today as the serial connection will no longer be able to provide immunity from compliance.
This change, if and when it takes effect, will reverse a trend that some analysts have used to argue that the CIPs actually weaken grid security.

We could go on, but this is a blog and our job is to keep these posts short and tasty. Kind of like tappas. Speaking of which, there's plenty of action on the menu for 2011 for utility security pro's and everyone in the community who wants to see them succeed. Looking forward to it!

Photo credit: Erik Fitzpatrick on Flickr.com

Monday, December 6, 2010

Get Ready, Grid - First Wave of Volts Being Born


Lovingly hand-assembled one at a time like a Phantom?  Uhhh, no.  The Volt manufacturing process seems to draw more from Tron than from Rolls Royce. Check it great video HERE.

So GM has invested big time in being able to create a large number of Volts fast. Good thing, because GE recently committed to buying 12,000 Volts next year, and sales are just beginning in New York, New Jersey, Connecticut, California, Texas, Washington, D.C., and Michigan.

I've always felt that the huge efforts to accelerate the arrival of the Smart Grid at residences was a case of too much spending for too little benefit, and that the prospect of trimming 5-15% off their home electric bill would not be a sufficient motivator for the majority of Americans to change their behaviors

But electric vehicles (EVs) like the Tesla Model S and Nissan Leaf, and plug-in hybrid electric vehicles (PHEVs) like the Chevy Volt, depending on their rate of adoption, may have me revising that opinion. You see, while they are charging, each of these cars draws the electricity of another entire house (or more). That's enough electricity use to make savings more desirable, and enough additional demand to prompt utilities to closely monitor which neighborhoods are adding EVs the fastest, so as to avoid overloading local transformers through preemptive, targeted upgrades.

Let the good times roll. Oh, and this just in via a sharp-eyed colleague and worth your time: Why Electric Cars will Drive the Smart Grid.

Photo credit: Betsy Weber on Flickr.com

Tuesday, November 30, 2010

Smart Grid Security Lessons from WikiLeaks?


UPDATE: Brilliant IBM colleague Jeff Jonas post on WikiLeaks implications and some potential first steps forward for sensitive-data intensive orgs. Click HERE to read it.
-----------------------------------------------------------------
We talked about this today a little on day one of the 2nd Annual Canadian Smart Grid Summit in Toronto. Not sure how the other participants felt, but for me, in the early days of designing and deploying world class security and privacy controls for the electrical utility industry in the wake of WikiLeaks makes me want to stop and reassess. Everything.

From an information security point of view WikiLeaks founder Julian Assange is a villain as dangerous as any penned by Stan Lee. And in Army Private Brad Manning, we've got the perfect lackey ... a worst-case scenario inside threat and substantially misguided youth who may not live to fully appreciate the damage he's caused his country and its allies.

Manning is no Megamind; far from it. The security flaws he overcame were policy shortcomings, not technical exposures.

While no organization is bullet proof, other sectors often point to the US DoD as an exemplar of security best practices. And who knows, maybe DoD has the best policy in DIACAP, the best internal and external guidance in the world, and the best tools and security controls money can buy. But you know what? Nothing prepares you for the thing you didn't see coming.

As North American utilities work to achieve and maintain rudimentary security via NERC CIP compliance, implement best practice cyber and physical security controls in IT and OT, and wrestle with how to best combat future threats as powerful as Stuxnet, WikiLeaks lessons should have them question every foundational assumption about what they're seeking to protect, how they're going to protect it, and from whom.

This Atlantic article, How the Pentagon Hopes to Prevent More WikiLeaks Embarrassments" tries to shine some early light on potential ways out of this morass for the Pentagon and State Department. But for me, pondering enormous Smart Grid data flows, in organizations that never had to segment and store anything like this before, has me wanting to call a time out.

We've all got a lot to learn from Stuxnet and now WikiLeaks. It's much too much in too short a period of time to assimilate. But we've got to try. We've got some big decisions to make in 2011 and we'd better get most, if not all of them right.

Photo credit: Michael Vroegop on Flickr.com

Monday, November 29, 2010

Enernex's Kevin Brown on Intersection of Physical and Cyber Security Challenges in Smart Grid Devices

Thanks to Erich Gunther for promulgating this excellent video Q&A featuring his security-minded colleague, Kevin Brown.

As a cyber guy, I've not imagined physical security as being much more than perimeter fences, surveillance cameras and good locks. Brown's discussions on battery life expectancies, how high you should mount pole-mounted devices, and how easy is to become king of reclosers were all eye openers for me.

Visually, there's not a lot more going on than in My Dinner with Andre. But the content, which truly bridges the physical and cyber worlds, is utterly compelling, fascinating stuff. It's over 20 minutes long, so make sure you find an open spot in your schedule. You won't want to multi-task through this one or you'll miss a lot.


Physical and Cyber Security for a Smart Grid from Erich Gunther on Vimeo.

Stuxnet Visualized

As one often hear's a picture is worth a thousand words, and at 30 frames per second, a good video is worth that much more. Here's Symantec's Liam O Murchu, the same engineer who presented to us at the IEEE Smart Grid Survivability Workshop last month (see post HERE), in a nicely crafted presentation showing how Stuxnet works its (black) magic.

The balloon pop at the end is a good metaphor for what is happening to industry's recently burst beliefs that control systems are safe from cyber attack.

Still looking, BTW, for a nice video, white paper, or even a scribbled note on a cocktail napkin for best practices to defend against future Stuxnets beyond banning USB drives.