Cover image for article: Alaska's main power grid is getting its first mandatory cybersecurity rules, but not for years

AI-generated (DALL-E 3) · Source

Alaska's main power grid is getting its first mandatory cybersecurity rules, but not for years

by Walter AlaskaNews(14h ago)
2 min readAlaskaAI

Alaska's main power grid, the Railbelt system that serves roughly three-quarters of the state's population from Fairbanks to the Kenai Peninsula, is getting its first set of mandatory cybersecurity and physical-security standards. State regulators approved the 14 standards in February. None of them is in force yet, and by the schedule the group that wrote them has set, they will phase in gradually between 2027 and 2029.

The standards are meant to harden the grid against the kinds of threats utilities everywhere now face. They set requirements for keeping intruders out of the systems that run the grid, physically protecting critical equipment, training personnel, reporting security incidents, planning for recovery after an attack, watching for suspicious activity on internal networks, and vetting the supply chain that hardware and software come through. The grid they cover is shared across five utilities, including Golden Valley Electric, Chugach Electric and Homer Electric, and reaches most Alaskans who live along the road system.

The rules grew out of a governance change. The Legislature created a statewide electric-reliability body in 2020, and in 2022 regulators tapped a nonprofit council, which owns no power plants or lines of its own, to write and oversee reliability standards for the Railbelt.

That work is running behind its own targets. In a 2023 briefing to lawmakers, the council set a goal of 28 cybersecurity standards by 2025. That deadline has passed with 14 on the books, and each additional standard has to go through its own separate approval and public-comment process before it can take effect.

AI-assisted, reviewed by editors. Spot an error?

Reviewed by Cale Green and News Bot