FERC and NERC Publish Whitepaper on SolarWinds and Related Supply Chain Compromise

Jul 7, 2021

Reading Time : 3 min

On July 6, 2021, the staff of the Federal Energy Regulatory Commission (FERC) and the North American Electric Reliability Corporation (NERC) Electricity Information Sharing and Analysis Center (E-ISAC) issued a whitepaper entitled “SolarWinds and Related Supply Chain Compromise – Lessons for the North American Electricity Industry.” The whitepaper “describes these major supply chain-related cyber security events and the key actions to take to secure systems”1 and is “intended for electric industry stakeholders and vendors as they consider their next steps in continued response to the SolarWinds cyberattack”2 and “other recently identified cybersecurity vulnerabilities [that] have the potential to compromise electric industry cybersecurity.”3 The whitepaper:

  • “primarily focuses on the significant and ongoing cyber event related to the SolarWinds Orion platform and the related Microsoft 365/Azure Cloud compromise, [and] also addresses vulnerabilities in products such as Pulse Connect Secure, Microsoft’s on-premise Exchange servers, and F5’s BIG-IP;”4
  • “offers key actions to take and key questions to ask to ensure the electricity industry is taking all necessary steps to mitigate compromises related to these incidents and vulnerabilities;”5 and
  • “highlights the need for continued vigilance by the electricity industry related to supply chain compromises and incidents, identifies key elements of adversary tradecraft, highlights specific malwares and tools to remediate, and recommends actions to ensure the reliability and security of the [bulk-power system].”6

With regard to the SolarWinds attack specifically, “[c]onsidering the sophistication, breadth, and persistence” of that attack,7 the whitepaper recommends “electric industry stakeholders fully consider the available diagnostics and mitigation measures to [e]ffectively address the software compromise,” including considering the recommendations in the U.S. Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA) Emergency Directive 21-01 (directed toward federal agencies) and CISA Alert AA20-352A (directed toward the private sector).8 Such recommendations include “disconnecting affected systems, conducting deep forensics, performing risk analyses, and consulting with CISA before reconnecting [or rebuilding] affected systems.”9 The whitepaper also includes its own specific recommended industry actions, which are extensive and detailed.10

Of particular note, the whitepaper states that “[b]ecause of SolarWinds’ wide use and the adversarial tactics used, even entities that did not install SolarWinds on their networks could still be impacted. For example, the indicators of compromise (IOCs) have been found on networks without SolarWinds. In addition, although SolarWinds may not have been used by entities, their key suppliers may use the product. Should the suppliers be compromised, the supplier in turn could compromise their customers, including those without SolarWinds. In fact, there is evidence technology firms were targeted for this reason.”11 Accordingly, electricity industry participants should carefully review the recommended actions in the whitepaper and the alerts it references and consider implementing those that apply to them.

The whitepaper also notes that “[t]he E-ISAC is working closely with its members, FERC, and other partners in the Canadian and United States governments to produce timely, actionable, and useful defense information for all segments of the electric industry.”12 Going forward, the E-ISAC “anticipates supplementing its current information sharing with new [Cybersecurity Risk Information Sharing Program] capabilities, enhanced cross-border sharing, and collaboration with the U.S. Department of Energy’s office of Cybersecurity, Energy Security and Emergency Response,” and FERC staff “stands ready to assist in the dissemination of actionable information that supports the electric industry in proactively responding to cyber attacks and other cyber vulnerabilities.” The whitepaper is available here. Stay tuned.


1 Whitepaper at 17.

2 Id. at 6.

3 Id. at 13.

4 Id. at 6.

5 Id.

6 Id.

7 Id. at 4.

8 Id. at 4-5.

9 Id. at 5, 9.

10 Id. at 5, 10-18.

11 Id. at 4 (emphasis added).

12 Id. at 17.

Share This Insight

Previous Entries

Speaking Energy

August 07, 2024

*Thank you to JaKell Larson, 2024 Akin Summer Associate, for her valuable collaboration on this article.

...

Read More

Speaking Energy

July 31, 2024

Interstate oil, liquid and refined products pipelines regulated by the Federal Energy Regulatory Commission (FERC) will soon be able to raise their transportation rates (provided they were set using FERC’s popular Index rate methodology) in the wake of a significant new decision by the District of Columbia Circuit (the D.C. Circuit) in Liquid Energy Pipeline Association v. FERC (LEPA).

...

Read More

Speaking Energy

July 29, 2024

On Wednesday, July 24, 2024, the U.S. House of Representative Committee on Energy and Commerce held a Subcommittee on Energy, Climate, and Grid Security hearing to review the Federal Energy Regulatory Commission (FERC or Commission) Fiscal Year 2025 Budget Request. Members of the Subcommittee had the opportunity to hear testimony from all five Commissioners, including FERC Chairman Willie Phillips and Commissioner Mark Christie, as well as the three recently confirmed commissioners, David Rosner, Lindsay See and Judy Chang. In addition to their prepared remarks, the five commissioners answered questions on FERC’s mandate to provide affordable and reliable electricity and natural gas services nationwide, while also ensuring it fulfills its primary mission of maintaining just and reasonable rates.

...

Read More

Speaking Energy

July 29, 2024

On July 9, 2024, the U.S. Court of the Appeals for the D.C. Circuit held that the Federal Energy Regulatory Commission (FERC or the Commission) erred in ordering refunds for certain bilateral spot market transactions in the Western Energy Coordinating Council (WECC) region that exceeded the $1,000/megawatt-hour (MWh) “soft” price cap for such sales.1 Finding FERC failed to conduct a “Mobile-Sierra public-interest analysis” before “altering” those contracts by ordering refunds, the court vacated FERC’s orders and remanded the case to FERC for further proceedings.2

...

Read More

Speaking Energy

July 8, 2024

On June 28, 2024, in Loper Bright Enterprises v. Raimondo, the U.S. Supreme Court overruled Chevron U.S.A. Inc. v. Natural Resources Defense Council, Inc., which for 40 years required court deference to reasonable agency interpretations of federal statutes in certain circumstances, even when the reviewing court would read the statute differently. The Court ended “Chevron deference” and held that courts “must exercise their independent judgment in deciding whether an agency has acted within its statutory authority.” In doing so, the Court upended a longstanding principle of administrative law that is likely to make agency decisions more susceptible to challenge in the courts.

...

Read More

Speaking Energy

July 3, 2024

We are pleased to share a recording of Akin and ICF’s recently presented “Powering Progress: Decoding FERC Order No. 1920” webinar, along with the program materials.

...

Read More

Speaking Energy

June 12, 2024

Join projects & energy transition partner Ben Reiter at Infocast's Transmission & Interconnection Summit, where he will moderate the “Dealing with the Impacts of Increased Interconnection Request Requirements and Costs” panel.

...

Read More

Speaking Energy

June 4, 2024

Join projects & energy transition partners Hayden Harms and Vanessa Wilson at Infocast's RNG & SAF Capital Markets Summit, where Hayden will moderate the "Investor Perspectives: Private Equity, Infrastructure Funds, & Strategies" panel, and Vanessa will moderate the "Opportunities in Other Biogas/Fuels Markets" panel.

...

Read More

© 2024 Akin Gump Strauss Hauer & Feld LLP. All rights reserved. Attorney advertising. This document is distributed for informational use only; it does not constitute legal advice and should not be used as such. Prior results do not guarantee a similar outcome. Akin is the practicing name of Akin Gump LLP, a New York limited liability partnership authorized and regulated by the Solicitors Regulation Authority under number 267321. A list of the partners is available for inspection at Eighth Floor, Ten Bishops Square, London E1 6EG. For more information about Akin Gump LLP, Akin Gump Strauss Hauer & Feld LLP and other associated entities under which the Akin Gump network operates worldwide, please see our Legal Notices page.