Security
Cyber security and physical security are critical to safeguarding the bulk power system (BPS). A comprehensive security strategy that addresses the protection of cyber and physical electric infrastructure is essential to mitigate risk and ensure reliability. For the 2026 Regional Risk Assessment, ReliabilityFirst (RF)'s analysis of cyber and physical security resulted in a high risk score.
Cyber Security
Cyber security risk involves the compromise of systems, networks, programs, and data used to monitor and control the BPS. Threat actors include state-sponsored groups or insider threats that target Bulk Electric System (BES) Cyber Systems within an entity’s Electronic Security Perimeter. A successful compromise can impact the confidentiality, integrity, or availability of monitoring and control systems, resulting in loss of visibility or control, degraded operations, loss of load, or widespread customer outages.
To gain insight on cyber security risks within the RF footprint, RF evaluated violation intake of Critical Infrastructure Protection (CIP) Standards. Figure 9 illustrates CIP violations for the commonly violated standards within the RF footprint between 2020 and 2025.
CIP violation intake remained relatively flat in the RF footprint between 2020 and 2025. According to Figure 9, CIP-010 (Configuration Change Management and Vulnerability Assessments) was the most violated standard in most years. CIP-010 R1 involves establishing BES Cyber System baselines and ensuring that all changes are made in a timely manner with formal authorization, documentation, and validation prior to implementation.
RF’s outreach confirmed that Registered Entities are improving their internal controls and reporting the violations identified by CIP-010 controls. RF plans to continue compliance monitoring and outreach related to configuration and vulnerability management.
Figure 9. Violation Intake for Commonly Violated CIP Standards in RF Footprint (2020-2025)
Figure 9. Violation Intake for Commonly Violated CIP Standards in RF Footprint (2020-2025)
CIP-004 (Personnel & Training) declined in violation frequency between 2020 and 2025, while CIP-003 (Security Management Controls), CIP-007 (System Security Management), and CIP-011 (Information Protection) did not exhibit clear trends. Overall, 91% of violations were self-reported by Registered Entities, which indicates that compliance programs were proactive in identifying and correcting CIP noncompliance.
In 2025, all industry sectors, including the energy sector, experienced an uptick in attempted cyber attacks. Despite satisfactory cyber security performance in the RF footprint, an increasingly hostile threat environment may contribute to higher perceived security risk among RF stakeholders. RF is monitoring and educating industry on emerging threat patterns that could impact cyber security. Highlighted below are examples of various threats that were tracked by RF staff during the year.
Emerging threat patterns
1. More AI-Orchestrated attacks (such as the Anthropic espionage campaign in which AI was able to execute 80-90% of the tactical work such as vulnerability discovery and data exfiltration).
2. Roughly 50% of major 2025 incidents involved third party vendors and/or software (e.g., Salesloft/Drift, Palo Alto Networks, and Zscaler).
3. Adversaries are targeting lower-level software supply chain open-source and commercial software packages, development tools, and coding libraries that many commercial and open-source products use or depend on within their products. Examples include the XZ Utils backdoor discovered in 2024, which could have led to a widespread backdoor to a large percentage of Linux distributions used in critical infrastructure. Additionally, the s1ngularity attack, and Shai-Hulud 2.0 attack exposed over 400,000 developer secrets used to secure developer repositories, source code and system infrastructure for CI/CD pipelines.
4. The moment when quantum computers can break today’s public-key cryptography, known as “Q-Day,” has been projected to occur around 2030 -2045. However, Google executives have stated they are planning to implement post-quantum cryptography (PQC) algorithms in 2029.
Telecommunications and IT infrastructure incidents
1. The zero-day attacks on Ivanti and SonicWall affected VPN and Firewall products from these vendors when they were actively exploited to allow remote access to numerous corporate and governmental networks.
2. The Salt-Typhoon Campaign infiltrated multiple telecom providers such as Verizon, AT&T, Charter Communication, and Lumen. This was one of the most significant breaches in history as it allowed a foreign adversary to eavesdrop on U.S. government officials.
Energy sector incidents
1. During the Toolshell attack on Microsoft SharePoint, over 400 organizations, including the Department of Energy and the Department of Homeland Security, were compromised due to vulnerabilities within on-premises SharePoint servers.
2. The FBI and CISA warned of Iranian foreign actor positioning on U.S. targeting water utilities and healthcare systems.
Physical Security
Physical security focuses on the physical protection measures to safeguard critical infrastructure such as substations, transformers, generating facilities, and control centers from threats that could disrupt or degrade their intended function. Exploiting a physical security threat vector can result in prolonged outages including the loss of load, reduced system resilience, cascading outages, and prolonged recovery response times, thereby posing a significant risk to the overall operation of the BPS.
Figure 10 illustrates violation intake data for CIP Standards related to physical security (i.e., CIP-003, CIP-006, and CIP-014). RF evaluated the noncompliance to provide context for physical security risks within the RF footprint.
Between 2020 and 2025, CIP-006 (Physical Security of BES Cyber Systems) violations exhibited a relatively flat trendline and had the fourth highest violation count among CIP standards. This standard has requirements for the monitoring and controlling of physical access to BES cyber systems. CIP-003 (Security Management Controls), which focuses on physical security of BES cyber systems at low-impact sites, has shown a slight upward trend in violations over time.
Figure 10. Physical Security CIP Violation Intake in RF Footprint (2020-2025)
Figure 10. Physical Security CIP Violation Intake in RF Footprint (2020-2025)
Some of these violations pose an independently low risk to the reliability of the BPS, such as failing to record all required information in visitor logs. However, it is important to stay vigilant for performance drift, in which entity employees have decreased attention to and associated complacency surrounding physical security practices. As discussed in the 2024 CIP Themes and Lessons Learned Report, performance drift may lead to violations of CIP-006 and CIP-003, which may impact operation, permit exposure to vulnerabilities, and impede the ability to detect malicious activity.
CIP-014-3 (Physical Security) focuses on identifying and protecting high voltage (e.g., 500 kV) transmission substations critical to interconnection reliability, where physical damage could cause widespread outages and delay restoration. Although CIP-014-3 violation frequency has been relatively low, most issues stem from deficiencies in understanding and applying the criteria of the risk assessments that are required to identify critical substations. In 2022, FERC issued an order directing NERC to study CIP-014-3, leading to ongoing revisions intended to clarify and strengthen the risk assessment requirements.
Figure 11 categorizes various types of physical security threats within the RF footprint between 2020 and 2025. Since 2020, the RF footprint has experienced an increase across most threat categories, including higher levels of vandalism, theft, and suspicious activity at energy infrastructure sites. There have been no reported instances of sabotage since 2020.
Figure 11. Characteristics of Physical Threats in RF Footprint (2020-2024)
Figure 11. Characteristics of Physical Threats in RF Footprint (2020-2024)
The increase in physical security threats may be linked to broader societal factors such as economic stress, political extremism, crime, and social unrest. With the increase of threats across the footprint, RF will continue to monitor this risk with its Threat Intelligence program (also discussed in the Situational Awareness section of this report). In addition, RF plans to share educational materials such as the recently released NERC Security Guideline: Voluntary Physical Security Protection Best Practices at Entity Facilities.
An emerging threat related to physical security is the use of drones, also commonly referred to as Unmanned Aerial Vehicle (UAV) or Unmanned Aircraft System (UAS), near electric infrastructure. Drones are becoming more prevalent, with approximately 8% of the U.S. population, or around 26.8 million people, owning a drone. Drones are increasingly sophisticated, with the ability to take off and land vertically, carry explosives and surveillance equipment, swarm (i.e., multiple drones controlled by a single point in unison), and the potential to become autonomous when enhanced with AI technology.
The global military drone market is projected to reach $23.8 billion by 2035 and is growing at a compound annual growth rate of 6.6%. Therefore, potential threat vectors range from individual hobby enthusiasts to nation-state sponsored actors that could deploy drones to perform espionage or attack electric infrastructure.
The Electricity Information Sharing and Analysis Center (E-ISAC) has also identified unauthorized drone activity as an emerging physical security concern for the electric sector. E-ISAC reporting highlights the potential use of drones for surveillance, reconnaissance, and other suspicious activity near electric infrastructure, including substations and power plants.
E-ISAC periodically issues situational awareness bulletins when member organizations report suspicious drone activity. As a member of E-ISAC, RF monitors the E-ISAC Portal for drone news, reports, analytical products, and other resources to inform its education and outreach activities in the RF footprint.
RF will continue to monitor and communicate risks associated with drone activity to its stakeholders through its Threat Intelligence program. RF is also developing educational material for outreach purposes related to possible actions to prevent and mitigate threats from drones.
