Episode #21 of Power Players by Origis® features Origis Services Managing Director Michael Eyman and Henry Sienkiewicz, senior information technology executive and Georgetown University professor.
In Episode 21 of Power Players by Origis®, host Michael Eyman discusses cybersecurity in renewable energy and best practices for improving it with Henry Sienkiewicz, senior information technology executive and Georgetown University professor.
Henry J. Sienkiewicz had a distinguished career as the former Chief Information Officer (CIO) at the Defense Information Systems Agency (DISA) and corporate officer for multiple technology companies. At DISA, he played a pivotal role in shaping the U.S. Department of Defense’s information technology and cybersecurity strategies. His tenure at DISA is noted for innovative approaches to securing information systems and advancing the department’s technological infrastructure. He currently sits on a number of boards and is a faculty member at Georgetown University.
With twenty years of leadership and operations experience, Managing Director Michael Eyman ensures that Origis Energy Services’ rapidly growing solar and energy storage portfolio performs as projected for owners and communities.
Eyman and Sienkiewicz discussed the general state of cybersecurity across industries and how to define critical infrastructure and protect it.
“The way I talk about it with my students at the very first session of class is, ‘Tell me what you believe is a good life.’ And as the instructor, I get to go first,” said Sienkiewicz. “And I say it’s the ability to take a long shower at the temperature of my choice because it implies so many other things. It implies security across the entire critical infrastructure. It implies that we have secure water. It implies that you have secure power. It implies that you have secure sewage treatment plants. It implies so many things.”
Sienkiewicz clarified that Department of Homeland Security and CISA, the Cybersecurity Infrastructure Security Agency, along with the EU and other countries like Japan have very specific definitions of critical infrastructure. Categorizations include systems that are not obvious when they are working well like traffic management systems and the electrical grid.
Eyman agreed. “I think that’s a perfect example because it also implies physical security, right? There’s a whole bunch of things to your point. When you turn on a light switch, what are all the things that had to go right for that simple act to work? And so, cybersecurity in this space is something people don’t think a lot about.”
While there will always be room for improvement, Sienkiewicz said he was fairly confident in the security of the electric grid. However, because nothing is ever completely secure once it’s connected virtually, asset owners and operators as well as grid operators need to employ best practices to prevent, detect and respond to attacks.
Sienkiewicz broke down the best practices for a secure and resilient environment.
Device security – solar assets and operators need hardware that is tamper proof, including secure firmware for data security.
Network security – ensuring there is role-based access control that isn’t overly cumbersome to increase compliance.
Response plan – know how you will respond before there is a breach. Include legal, financial, communications and even the local FBI field office in the plan.
“There’s a good possibility you will be breached at some point in time,” said Sienkiewicz. “But as you’re having this breach and you need to have a response, the worst time to put the team together is as it’s happening. You as the provider, your information technology people, your information security people need to put together a game plan.”
Eyman pointed out the explosion of connected devices across every industry.
“Everybody’s refrigerator is talking to the Internet these days,” he said. “It’s crazy. And that is happening everywhere across every industry, right? And so, thinking about from a future perspective, from an OT future perspective, how do we keep these things secure going forward? Because this is terrain that’s constantly changing.”
Sienkiewicz suggested the future of security and resiliency in the grid could be helped with artificial intelligence, blockchain technology and creating a digital twin to model a more secure environment.
“Using artificial intelligence or permutation of the ability to look at and use algorithms to make better decisions on investments, better decisions on placement of assets, better decisions on where to have additional resiliency built in, these are wonderful things,” Sienkiewicz said.
Sienkiewicz wrapped up the conversation an optimistic note, “It’s not all doom and gloom. There’s a lot of good things going on. I think the industry, as long as they’re looking out for it, they’ll be able to succeed in a marvelous fashion.”
During their conversation, Sienkiewicz and Eyman discussed securing solar assets from cyber-attacks. Three key takeaways:
We’d like to thank our Power Players expert guest Henry Sienkiewicz and host Michael Eyman, for their insightful conversation, giving context and perspective to the future of secure renewable energy assets.
Critical thinking to move decarbonization solutions forward. Stay informed. Sign up for our newsletter.