- Wednesday, September 23, 2026

America needs to build more power infrastructure than it has in generations, and that infrastructure must be secure. Threats are coming from many directions.

In April 2026, federal agencies including the Department of Energy (DOE), the Cybersecurity and Infrastructure Security Agency and the National Security Agency warned that Iranian-affiliated hackers were inside American critical infrastructure, manipulating the industrial controllers that run plant equipment and falsifying what operators saw on their screens. Three months earlier, Winter Storm Fern cut power to more than a million customers across the South and Mid-Atlantic as ice downed lines. Meanwhile, at PJM, the nation’s largest grid operator, roughly 20 gigawatts of generation went offline as extreme cold shut down critical energy infrastructure. In December 2022, unidentified attackers opened fire on two Duke Energy substations in North Carolina, cutting power to over 45,000 customers for nearly five days during freezing winter temperatures. One was a cyberattack, another was an extreme weather event and the last was a physical attack coinciding with cold weather.

America is entering the largest buildout of its electric grid in generations, and with it comes a real opportunity for Congress to secure lasting authority for the grid’s defenders. DOE’s Office of Cybersecurity, Energy Security and Emergency Response (CESER), the federal office charged with protecting this system, stands ready for that mandate. Congress can seize this moment, and there’s never been a better time to act.



In 2025, the North American Electric Reliability Corporation’s information sharing center logged more than 3,500 physical security incidents on the grid, up from 2,800 two years earlier. On the cyber side, ransomware attacks on industrial organizations rose 64% from 2024 to 2025, hitting 3,300 organizations worldwide, with at least one new intrusion group discovered during an incident response at U.S. electric and water utilities.

None of this is an argument against building our electric grid; it’s an argument for building security, both physical and cyber, into it from the start.

American electricity demand has broken out of a long plateau. After 15 flat years, consumption has grown 2.1% annually over the last five, and the U.S. Energy Information Administration (EIA) expects it to climb from a record 4,195 billion kilowatt-hours in 2025 to 4,391 billion by 2027. Data centers and advanced manufacturing are the engines of this economic growth, creating jobs in communities across the country and positioning the U.S. to be a more secure global leader in the next generation of technologies and industries like Artificial Intelligence.

We should want this. AI leadership reshored manufacturing and electrification are national assets that foster long-term economic growth. The right response is to build here: clean, firm generation; transmission; and new technologies that keep power affordable and reliable. American innovation has already made clean energy deployable. Now the mission is leading the world to adopt it, because that’s the only path to cutting global emissions. But the grid we are building differs in kind, not just size. Meeting it means adding millions of networked devices — advanced transmission technologies, battery controllers, EV chargers and the 130 million smart meters already covering nearly 80% of American meters — to a grid that predates the internet. Digitization makes a modern grid smarter, unlocking capacity and making it more efficient, But defending it will require new tools and greater coordination.

That work has a federal home. DOE’s CESER Office carries out the Department’s role as Sector Risk Management Agency for the Energy Sector. It collects the disturbance reports utilities must file after major incidents, stewards critical RD&D, and leads the federal energy response when the lights go out — whether due to ransomware, hurricanes, intrusion or wildfire. It also co-runs the threat intelligence partnership covering utilities serving more than 75% of American customers. President Donald Trump’s 2017 cybersecurity executive order directed DOE to assess the nation’s ability to prepare for and respond to cyberattacks on the electric grid and in 2018, DOE created CESER to lead its work on cybersecurity, energy security, and emergency response. Congress has given DOE and the Secretary of Energy important energy security authorities, but today, many are exercised by CESER only through departmental delegation. That means without a full authorization, CESER’s specific role could easily be changed by future administrations.

Advertisement
Advertisement

Authorization would not expand the federal footprint or impose new mandates, and it shouldn’t. The private sector owns more than 80% of American energy infrastructure and knows those systems better than Washington does. The federal advantage lies elsewhere: the expertise of the National Laboratories, classified threat intelligence no utility can reach alone, testbeds no single company could justify building for itself and the ability to coordinate across states, companies and agencies when a major disruption occurs. Congress does not need to invent a new agency or launch another federal program. It simply needs to make permanent the energy security mission the government is already carrying out.

America will build an extraordinary amount of energy infrastructure this decade. But it will be hard to measure the success of an energy system that leads the world in clean technology but sits at the mercy of its adversaries. Comprehensively authorizing CESER is overdue and has long enjoyed bipartisan support. It costs almost nothing against the price of finding out what happens without it.

Jeremy Harrell is the chief executive officer of ClearPath Action.

Copyright © 2026 The Washington Times, LLC. Click here for reprint permission.

Please read our comment policy before commenting.