The Alliance for Critical Infrastructure is an industry-led coalition aimed at strengthening national resilience.
Protecting our critical infrastructure is a strategic necessity. Enhancing domestic resilience will support deterrence efforts and minimize the impact of attacks on the communities we serve.
The private sector operates over 85% of critical infrastructure and is uniquely positioned to lead cross-sector collaboration while working with government entities to safeguard these essential systems.
The Alliance for Critical Infrastructure (ACI) represents a strategic shift towards an industry-led model of national resilience planning, leveraging the expertise and capabilities of the private sector to protect our nation's most critical assets. Through collaboration, we can build infrastructure that not only withstands adversarial threats but also deters them through demonstrated resilience.
“When that bad day happens… it is not the time to phone a friend.”
— Tom Fanning, Chairman, Executive Committee
ACI Board Members Tom Fanning, Jeff Baumgartner, and Sharla Artz discuss ACI origins and strategic pillars at the McCrary Institute for Cyber and Critical Infrastructure Security
Don’t wire foreign enemies into America’s power grid
— by Jim Langevin and Tom Fanning [ published in The Hill ]
The U.S. is racing to build infrastructure that will power artificial intelligence, advanced manufacturing and the next generation of economic growth. Electricity demand is surging for the first time in decades, and utilities are scrambling to keep up. But in the rush to modernize the grid, policymakers risk overlooking a simple question: Are we building new vulnerabilities into the very systems America will depend on most?
Between the two of us, we have spent decades working on these issues from different perspectives. One of us served in Congress and helped build many of the cybersecurity institutions the federal government now relies on to protect critical infrastructure. The other spent years leading one of America’s largest energy companies and helping coordinate the electric sector’s response to cyber and physical threats.
Over that time, we have seen the same mistake play out again and again: America focuses on cost and convenience until dependence on foreign technology suddenly becomes a national security problem. By then, fixing it is far more difficult than preventing it in the first place. After years of allowing the purchase of cheap Chinese telecommunications devices, for example, the Federal Communications Commission estimated it would cost more than $5 billion to remove and replace them with more secure equipment.
The electric grid is becoming more digital than most Americans realize. The systems being installed now do more than move electricity; they communicate with one another, process data and help utilities manage power across entire regions in real time. Those features make the grid more efficient, but they also create new points of vulnerability.
Many Americans also may not know that Chinese government-linked hackers are already burrowing inside U.S. critical infrastructure, including power systems. U.S. officials have warned that these intrusions appear designed to give Beijing options to disrupt vital services during a future crisis. That should raise an obvious question: If China is already trying to gain access to critical systems from the outside, why would we make it easier by relying on Chinese-linked technology in the systems that help control the grid from the inside?
Of course, that doesn’t mean every Chinese-made component poses the same risk. A screw, a solar panel and a battery cell — components that simply perform a particular function — present a very different challenge from the software and control systems that determine how electricity is generated, stored and routed.
That distinction should guide U.S. policy. Too often, Washington treats every component as if it poses the same threat. The greatest scrutiny should fall on the software, firmware and control systems that act as the grid’s command center. These technologies can communicate remotely, receive updates and influence how electricity flows across large parts of the country. They present a fundamentally different risk from commodity hardware.
The U.S. cannot replace every foreign-made control system overnight. But failing to prioritize carries risks of its own. As a recent paper from two leading cyber research institutions explains, we can and must assess technologies based on their systemic importance, impact and level of digital sophistication, domestically sourcing the most important while relying on cheap global supplies for the least consequential.
America has already spent years trying to unwind vulnerabilities in industries such as semiconductors and telecommunications after strategic concerns took a back seat to short-term economic considerations. We should not make the same mistake with the systems that will power the next generation of American innovation.
Neither government nor industry can solve this challenge alone. Most of America’s critical infrastructure is owned by the private sector, yet companies cannot be expected to independently determine which technologies pose the greatest national security concerns. Washington should provide clearer guidance about which systems deserve the closest scrutiny and share threat information more aggressively with the companies responsible for deploying them. Industry, in turn, should use that data to make smarter sourcing and procurement decisions before vulnerable technologies become deeply embedded across the grid.
The decisions being made today will shape our nation’s energy security for decades. If we focus on the technologies that matter most, we can modernize the grid while reducing risk. If we fail to do so, we may discover too late that we built avoidable vulnerabilities into one of the country’s most important systems.
Most Americans rarely think about the electric grid, because from an outside viewpoint, it just works. Our leaders should do everything possible to keep it that way.