T&D World article on Battery Energy Storage Systems (BESS) cyber issues

Networked Battery Energy Storage Systems (BESS) introduce cyber and physical vulnerabilities, and not enough attention is paid to training, design and operation. As a follow-up to my February 14, 2025 Unfettered blog, “Cyber vulnerable battery systems are catching fire and communicate directly to China”, T&D World published the update “How Vulnerable to Cyber Attacks are […]

OT and Engineering are not the same and are creating dangerous conditions

A recent job solicitation from a medium-size water utility seeking engineers included knowledge of associated industrial communications and networking equipment. However, the engineers were not responsible for cybersecurity of those networks and there was no mention of the term OT nor any consideration of with working with the network security organization. Another recent job solicitation […]

Cyber vulnerable battery systems are catching fire and communicate directly to China

Battery energy storage systems (BESS) are cyber vulnerable. There have been numerous cases where intentional and/or unintentional control system cyber incidents have caused or contributed to thermal runaway fires. There have been other cases where BESS systems have been cyber-compromised. Yet there appears to be minimal attention being paid to cybersecurity in the design, operation, […]

Will the next administration finally address control system cyber security?

Addressing critical infrastructure (control system) cyber security started with the issuance of PDD 63 by President Bill Clinton in 1998. According to PDD63, the critical infrastructures were to be cyber secure within five years of issuance of the PDD – 2003. Yet control system cyber security still has not been adequately addressed by the intervening […]

Critical infrastructures cannot be secured because network security and engineering won’t work together

There continues to be a gap between the engineering organizations in end-users and control system suppliers responsible for reliability, functionality, and safety on the one hand, and the network security organizations responsible for network security on the other. Control systems are neither just engineering nor network security but a combination of both: modern networking technologies […]

The need to identify control system incidents as being cyber-related

Control system cyber incidents are different from network cyber incidents because you can’t hide their impact: plane, trains, and ships crash, pipeline rupture, power and water are lost, etc. What is not identified is that many of these incidents have been cyber-related, and this failure to recognize them is because of a lack of appropriate […]

Ford recall on a control system cyber issue

These, and other types of “subtle” control system cyber issues that do not involve Internet Protocol networks demonstrate that identifying control system incidents as being cyber-related often is not obvious. NHTSA recalled 144,500 Ford Mavericks over concerns that the rearview camera display could show frozen images while backing up. November 14, 2024, NHTSA announced that […]