October is Cybersecurity Awareness Month — a time to reflect on how we can strengthen the systems we all rely on in the face of evolving threats. For the power sector, the stakes are higher than ever. In 2024, cyberattacks against critical infrastructure surged by 30%, with the U.S. power grid increasingly in the crosshairs. At the same time, ransomware complaints impacting critical infrastructure rose 9% from 2023 to 2024, with nearly half involving sectors such as energy and utilities.
These growing risks come as demand for reliable power surges — fueled by the rapid rise of artificial intelligence (AI), domestic manufacturing growth, and the electrification of vehicles and buildings. Energy-hungry data centers, factories, and communities all depend on secure, always-on access to electricity. That means protecting the grid from cyber and physical threats is not only a security priority, but also an economic and societal imperative as America seeks to win the global AI race.
Proactive Preparedness Is Essential
EPSA members are taking action before threats strike. From investing in advanced monitoring to conducting independent assessments, and participating in security exercises like GridEx VIII, competitive power suppliers are stress-testing their systems and strategies to ensure reliability.
In late November 2025, EPSA will for the first time ever host a tailored GridEx VIII tabletop exercise for its members, providing a forum to practice real-world scenarios and strengthen readiness directly tailored for the unique considerations of competitive power suppliers. Organized by the North American Electric Reliability Corporation’s (NERC) Electricity Information Sharing and Analysis Center (E-ISAC), GridEx is the premier grid security exercise in North America. Now in its eighth year, the nationwide version brings together industry, government, and other critical stakeholders to practice response and coordination in the face of evolving threats. EPSA’s tailored session gives members a unique opportunity to engage directly in realistic scenarios, test strategies, and refine preparedness measures.
Exercises like these are innovations in the field and underscore that preparedness is not optional — it is a core part of building resilience.
Flexibility Delivers Smarter Security
There is no one-size-fits-all solution to securing the grid. Different sites, terrains, and infrastructure needs demand different responses. For this reason, EPSA continues to emphasize the importance of performance-based, flexible standards that allow companies to tailor defenses in the most effective ways.
Information Sharing Is a Force Multiplier
Cyber and physical security challenges cannot be solved in silos. EPSA members actively participate in information-sharing networks such as the E-ISAC and FBI InfraGard, ensuring rapid communication of threats and vulnerabilities across the sector. Shared intelligence helps every company respond faster — and strengthens the entire grid.
Going Beyond Compliance
Meeting regulatory requirements like NERC CIP standards is only the baseline. EPSA members go further, routinely investing in voluntary measures that exceed minimum expectations — from advanced cyber compromise assessments to expanded employee training. Security is about more than compliance; it’s about commitment to reliability and public trust.
Collaboration Strengthens Resilience
Protecting critical infrastructure requires teamwork. Industry, government agencies, and independent experts all have a role to play. EPSA members are committed to building and maintaining these partnerships, knowing that strong collaboration means a safer, more resilient grid for everyone.
What the Public Can Do
While EPSA members focus on securing infrastructure, individuals also play a vital role in helping build a Cyber Strong America. Every small action contributes to grid security:
• Enable multi-factor authentication to add an extra layer of protection.
• Use strong, unique passwords and keep them updated.
• Watch out for phishing emails and report suspicious activity.
• Update devices and software regularly to close known vulnerabilities.
By taking these steps, the public helps reduce risks that ripple into critical systems.
Looking Ahead
Cybersecurity Awareness Month is an important reminder that securing the grid is a shared responsibility. EPSA members are leading with proactive measures, flexibility, information sharing, collaboration, and a commitment to go beyond compliance.
As we look ahead to our tailored GridEx VIII exercise in November, EPSA and its members remain dedicated to protecting America’s power system and working together to Build a Cyber Strong America.


