Justice League Blog

Smart Grid equals Dumb Security?

I recently had the pleasure of giving a keynote at the NRECA annual conference in Atlanta. The conference brings together senior management and Board members from rural electric cooperatives throughout the country. Some coops are large in terms of the number of subscribers, and some are large in terms of geographic area covered (those numbers often run opposite to each other). My job as keynoter was to introduce some thinking about computer security to business people who operate power grids for a living. This is a big challenge for a geek like me.

Of course I ended up touching on software security, especially the fact that power meters for the “smart grid” are little IP-enabled computers hung on the outside of your house. Given known attacks against this new breed of meters, the question is how many rooted smart grid meters in a botnet could cause a really serious problem?

Here is my talk in its entirety. Your feedback is welcome.

Download audio [mp3]
Download presentation [pdf]

I’m pleased that Cigital is directly involved in working to make smart grid security a reality. We’re working directly with NRECA to bring electric cooperatives up to speed with cyber risk management.

This entry was posted in Software Security. Bookmark the permalink.
« »
  • http://www.cigital.com/~gem gem

    After thinking some more about this problem, I wrote my monbthly informIT column about smart grid risk as well.

    The Smart (Electric) Grid and Dumb Cybersecurity
    http://www.informit.com/articles/article.aspx?p=1577441

    gem

  • http://www.cigital.com/justiceleague/2010/05/06/is-cyber-war-inevitable/ Justice League » Blog Archive » Is Cyber War Inevitable?

    [...] even when they’re not. Turns out that taking down the power grid with a cyber attack is not outside the realm of possibility. I’ve been told by people who actually engineer and run the grid for a living that inflicting [...]