Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Government

5 Bills to Boost Energy Sector Cyber Defenses Clear House Panel

The news comes after the Department of Energy conducted its annual Liberty Eclipse cybersecurity exercise.

Power grid security

The House Subcommittee on Energy this week advanced five recently introduced bills aimed at boosting the physical and cyber security of the United States’ electric grid and other energy infrastructure.

The bills collectively aim to update Department of Energy (DOE) programs, enhance grid and pipeline protections, and prioritize cybersecurity for vulnerable sectors amid rising threats.

One of the bills is H.R. 7258, named the Energy Emergency Leadership Act, which bolsters the Department of Energy’s capabilities to perform its energy emergency functions and respond to risks and incidents. 

The second bill is H.R. 7266, the Rural and Municipal Utility Cybersecurity Act. It reauthorizes and supports a cybersecurity program through 2030, providing rural electric cooperatives, small utilities, and public power agencies with advanced cybersecurity tools, technical assistance, and grant funding.

H.R. 7257, the Securing Community Upgrades for a Resilient Grid (SECURE Grid) Act, updates and enhances programs for the physical and cyber security of the energy infrastructure. It aims to build resilience in community-level upgrades and systems. 

The Pipeline Cybersecurity Preparedness Act, H.R. 7272, improves the DOE’s coordination and technical support for securing pipelines and LNG facilities. It aims to develop programs to improve collaboration, ensure timely responses to disruptions, and enhance overall resilience in energy fuel supply systems.

Advertisement. Scroll to continue reading.

The last bill is H.R. 7305, the Energy Threat Analysis Center Act of 2026. It reauthorizes the Energy Threat Analysis Center (ETAC) to conduct preventative analysis, information sharing, and coordination on cyber threats to energy systems. 

Although the five bipartisan cybersecurity bills advanced unanimously from the House Energy Subcommittee, they still face a lengthy path ahead, including full committee approval, a House floor vote, Senate consideration, and settling any disputes.

The Department of Energy recently conducted its annual Liberty Eclipse cybersecurity exercise, which trains power companies, government officials, and industry experts to respond to potentially disruptive cyberattacks targeting electricity and natural gas infrastructure. 

Through Liberty Eclipse, the DOE develops and runs large-scale, interactive cybersecurity exercises that provide hands-on experience in defending against advanced threats.

Threat actors regularly target the global energy sector, including for espionage and destructive attacks

Related: Default ICS Credentials Exploited in Destructive Attack on Polish Energy Facilities

Related: Phishers Abuse SharePoint in New Campaign Targeting Energy Sector

Related: Bill Aims to Create National Strategy for Quantum Cybersecurity Migration

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

In cyber-physical systems (CPS), just one hour of downtime can outweigh an entire annual security budget. Learn how to master the Return on Security Investment (ROSI) to align security goals with the bottom-line priorities.

Register

Delve into big-picture strategies to reduce attack surfaces, improve patch management, conduct post-incident forensics, and tools and tricks needed in a modern organization.

Register

People on the Move

Malwarebytes has named Chung Ip as Chief Financial Officer.

Semperis has appointed John Podboy as Chief Information Security Officer.

Randy Menon has become Chief Product and Marketing Officer at One Identity.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.