AGP Picks
View all

Rainey Center: Grid Security Should Be Measured by Standards, Not Country of Origin Alone

New policy brief finds existing cybersecurity frameworks can protect the U.S. grid while preserving the equipment needed to meet rising electricity demand

WASHINGTON, DC, UNITED STATES, October 10, 2026 /EINPresswire.com/ -- The Joseph Rainey Center for Public Policy today released a new policy brief, Securing the Grid While Growing the Grid, examining how the federal government can protect the U.S. electric grid from foreign threats while maintaining the reliability and infrastructure investment needed to meet rapidly growing electricity demand.

The brief argues that meeting rigorous security standards should matter more than country of origin alone when determining whether grid equipment can be trusted.

“Where equipment is made matters, but it is not the same thing as knowing whether that equipment is secure,” said Sarah E. Hunt, President and CEO of the Joseph Rainey Center for Public Policy. “The stronger test is whether the equipment can meet demanding, independently verified standards governing who can access it, who controls its software and updates, and whether its communications can be trusted.”

The brief concludes that the federal government does not need to invent a new cybersecurity framework from scratch. NERC, NIST, IEEE, UL, and IEC already provide measurable standards governing supply-chain security, operational technology, software integrity, access controls, and industrial control systems.

Rainey Center recommends that federal policymakers:
Judge equipment by whether it meets rigorous security standards, not simply by where it was made. Country of origin is an important risk signal, but security ultimately depends on access, software integrity, communications, and control.
Require U.S.-controlled operation. Remote access and control should be disabled by default and remain under the asset owner’s control.

Require verified software. Firmware should be signed, updates should be subject to owner review, and software integrity should be independently verifiable.

Require independent testing. Equipment should undergo penetration testing and hardware review by accredited U.S. laboratories.

Keep operational data protected. Grid-related operational data should remain in the United States, with vendor access limited and logged.

Mitigate risk before removing installed equipment. Network segmentation, monitoring, access restrictions, and controlled software updates should be used where they can address the risk without unnecessarily disrupting grid operations.

Preserve exclusion as a tool. Equipment that cannot meet the standard, cannot be verified, or presents an unmitigable risk should not be allowed on the grid.

The brief argues that an origin-based rule does not test the actual pathways through which cyber risk reaches the grid. A domestically assembled device with insecure remote access may still present a serious vulnerability, while a verifiable standard can evaluate remote access, software integrity, data handling, and control regardless of where equipment was manufactured.

Rainey Center polling suggests voters share that view. In the Center’s September Policy Survey, 81 percent of registered voters said they were concerned that grid equipment could be remotely accessed or controlled by a foreign government or company. By 69 percent to 19 percent, voters said how equipment is built, tested, and controlled matters more than where it was made. Voters ranked preventing remote access from outside the United States and independent U.S. testing as the two most important elements of a federal security standard.

The policy debate comes as U.S. electricity demand is accelerating. NERC projects summer peak demand will increase by 224 gigawatts, or 24 percent, over the next decade, while about 80 percent of large transformers and more than 90 percent of power inverters installed over the past decade have been imported.

“America should build more energy infrastructure at home, and we should continue strengthening domestic supply chains,” Hunt said. “But domestic production is not, by itself, a cybersecurity standard. Every device connected to critical infrastructure should have to prove that its controls can be trusted.”

The brief concludes that a verifiable standard can strengthen national security while preserving the competition, reliability, and infrastructure investment needed to meet rising U.S. electricity demand.

About the Joseph Rainey Center for Public Policy
The Joseph Rainey Center for Public Policy advances market-oriented public policy solutions through research, public-opinion analysis, and engagement with policymakers.

Megan Sibley
Rainey Center Freedom Project
megan.sibley@raineycenter.org
Visit us on social media:
LinkedIn
Instagram
Facebook

Legal Disclaimer:

EIN Presswire provides this news content "as is" without warranty of any kind. We do not accept any responsibility or liability for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this article. If you have any complaints or copyright issues related to this article, kindly contact the author above.

Share this page:

Advanced Search Options

Search for:

Search scope:

Type:

Search in:

Date range:

The last

Sort by:

Sign up for:

US National Times

The daily local news briefing you can trust. Every day. Subscribe now.

By signing up, you agree to our Terms & Conditions.