Available logo

Federal agencies just raised the bar on power grid security

August 19, 2026
High-voltage power line illustration

The electricity system is more distributed and Internet-connected than ever — and that changes everything about securing it

Most of the operational technology running America’s grid has fallen outside the strongest tiers of federal cybersecurity coverage. And regulators are taking note. In the past few months, federal agencies have made a series of big moves to shore up cybersecurity across America's power grid. 

In March, the Federal Energy Regulatory Commission (FERC) voted unanimously to issue two final rules and approve an updated reliability standard to modernize cybersecurity protections for the bulk power system (BPS). 

The BPS is the backbone of the nation's electricity supply: the high-voltage transmission lines and large-scale power plants that move electricity across regions and power daily life. The expanded rules cover secure virtualization, baseline controls for lower-tier grid systems, and tighter definitions of which assets fall under oversight. 

Meanwhile, also earlier this year, the North American Electric Reliability Corporation (NERC) released its new Critical Infrastructure Protection (CIP) Roadmap review. It similarly identified the urgency to act.

The NERC-CIP standards focus on the other end of the system: the distribution grid that delivers electricity into cities, businesses, and homes. This includes a fast-growing category of assets called distributed energy resources (DERs): grid-connected devices like rooftop solar, behind-the-meter batteries, smart thermostats, building energy management systems, and EV charging infrastructure.

A cybersecure, reliable grid needs protection at both ends of the system, and it's the distribution end — with its explosion of connected devices — where the risk picture is changing fastest.

Distributed energy, distributed risk

The scale of what's now connected to the grid puts the urgency of federal action into perspective. Nearly 77% of US households had smart electric meters in 2023, up from 60% just five years prior, and millions of homes and businesses are adding rooftop solar, batteries, and EVs every year. And research projects the US will add another 217 gigawatts of DER capacity between 2024 and 2028 — nearly equal to the output of all US coal-fired power plants combined. 

Such explosive growth creates two distinct but related cybersecurity risks. The first is DERs as an entry (attack) vector. More endpoints on the grid means more potential points of compromise, meaning adversaries no longer need to attack a high-value target directly to inflict damage. A compromised smart meter or building energy management system can serve as a foothold, allowing attackers to move laterally through connected systems, escalate privileges, and work their way toward higher-value infrastructure. And, this risk isn't limited to clean energy technologies: any internet-connected asset — natural gas plant control systems, pipelines, transmission infrastructure — carries the same exposure.

The second risk is DERs as a primary target. As virtual power plants (VPPs) and large DER fleets take on greater roles in demand response aggregation and grid balancing, the grid itself increasingly depends on the services they deliver — generation from rooftop solar and batteries, load shifting, peak shaving. If adversaries knock whole fleets of DERs offline, it can disrupt critical services like heating, cooling, and backup power. At scale, such disruption can ripple into broader grid instability across entire communities, from darkening homes during extreme weather and grounding EV fleets, to compromising hospital power and water treatment systems. 

These aren’t hypothetical concerns. Nation-state actors have repeatedly identified energy infrastructure as a target, with advanced threat actors known to target grid infrastructure just to get inside and see how things work, mapping systems and dependencies to pre-position for future attacks. 

A multi-layer defense for critical infrastructure

Defending the grid requires a multi-layer security framework that matches the scale and sophistication of today’s fast-evolving threat.

  • Zero trust is the foundation. Built on the principle that no user, device, or system is trusted by default, a zero trust approach requires every connection to be continuously verified, every access request validated, and every device treated as a potential threat until proven otherwise. For grid-connected operational technology, this means identity-bound access, micro-segmentation, and continuous authentication enforced directly at the operational edge.
  • Quantum-resilient encryption protects data integrity. Quantum computing is advancing faster than most organizations realize. Post-quantum cryptography replaces encryption standards that quantum computers will eventually break, securing endpoints, data in transit, and cloud environments against both current and future threats. This next level of protection is increasingly urgent as state-backed hackers are embracing "harvest now, decrypt later" methods in anticipation of Q Day.
  • AI-assisted monitoring detects threats in real time. AI-powered threat detection can identify anomalies across distributed infrastructure in real time, proactively flagging threats before they escalate. It can also guard against AI poisoning and shadow AI — whether adversaries corrupting the models that monitor critical grid operations, or unsanctioned models introducing unvetted risk from within.

Grid security can’t wait

AI is enabling attackers to identify vulnerabilities and automate attacks at a scale and speed that wasn't possible even a few years ago. The multi-layer framework we've outlined here — zero trust, quantum-resilient encryption, and AI-assisted monitoring — is how grid-connected systems stay ahead of increasingly more sophisticated cyber attacks.

The federal rules covering the bulk power system and distribution grid are in place and the window for action is narrowing. Your DER systems are either part of the solution — or part of the attack surface.

SanQtum merges national security-grade zero trust protection with real-time edge computing as infrastructure gets more distributed, strengthening organizational protection and grid resilience alike. Contact us to learn more.

crossmenu