The difficulty of the three steps required to hack power grids explains why actual disruptions are so rare
IN 2017, IT can sometimes seem like power grids are practically crawling with digital intruders. Over just the last four months, news has emerged that Russian hackers penetrated …
Context & Ripple Effects
The related coverage sets up a puzzle: intrusions are everywhere but blackouts are not. Hackers have already crossed the line once — the unprecedented hack of Ukraine's power grid produced actual outages — and Symantec later found the Dragonfly group inside the operational networks of multiple US and European energy companies. Yet repeated attacks on Ukraine read less like a campaign of disruption than Russia testing offensive cyber capabilities, accumulating access without triggering mass failures.
This piece supplies the missing explanation: turning network access into physical disruption requires three difficult steps, and most intruders stall before completing them. That reframes the threat picture — the danger is measured by how far an attacker gets through those steps, not by how many networks are breached.
First-order effects
- Dragonfly's presence inside energy companies' operational networks is revealed as an intermediate stage, not a prelude to imminent blackouts — access to control systems does not yet mean the ability to manipulate them.
Second-order effects
- Defenders shift focus from perimeter breaches to the final, hardest step of the kill chain, which pushes utilities and vendors of grid-control hardware — such as the makers of the industrial Ethernet switches found vulnerable in dams and nuclear plants — to harden the control layer itself rather than just enterprise IT.
Third-order effects
- If the pattern holds, nation-state activity will keep concentrating on supply chains and contractor networks — the route the reconstructed US grid attack from 2016 to 2018 followed — because that is where attackers can quietly gather what the three steps require, making third-party vendors the structural weak point of grid security.
The trend: State-sponsored hackers are penetrating power grids faster than they can convert access into disruption, so the industry's defense race moves from keeping intruders out to blocking the final control-system step.