Wednesday, December 15, 2010

The Smart Grid Security Misinformation Network

It seems that a lot of the news we hear about Smart Grid security seems to focus on how we are all potentially doomed due to the lack of attention being given to Smart Grid security.  Bad news does seem to get a lot of attention, so I can certainly see how this may be a great way to attract readers.  I have a Google Alert set to "Smart Grid Security", and every evening I get an email with the latest headlines.  It seems to come in waves, but I get a lot of links to random postings where the author proclaims that not enough attention is being given to Smart Grid security.

I am not sure what "enough" really means in the eyes of many of these authors, but I will say that there are a lot of people paying very close attention to Smart Grid security.  I personally belong to 2 of 12 NIST Smart Grid Cyber Security Working Groups (http://collaborate.nist.gov/twiki-sggrid/bin/view/SmartGrid/WorkingGroupInfo) and these groups generally meet for 1 hour per week.  Members from every corner of the energy and security industries regularly attend these meetings, and the discussions and associated tasks are certainly focused on securing our Smart Grid.  The NIST CSWG is also where the NISTIR 7628 Security Guidelines came from, which was a collaborative effort of over 400 people from the energy, security, legal, regulatory, government, educational, and general technology industries.  Many of these same people are still quite active in the efforts of the NIST Smart Grid Interoperability Panel (SGIP) and NIST CSWG.  Besides the NIST effort, several standards development organizations have become involved in working towards developing standards for securing the smart grid.  

The US Department of Homeland Security has put together a comprehensive Industrial Control Systems Joint Working Group (ICSJWG), which is open to anyone who wants to help (http://www.us-cert.gov/control_systems/icsjwg/index.html).  I am also a member of this group, and recently attended a conference (also open to anyone who wishes to attend) in Seattle Washington.  The speakers were all excellent (okay, I was one of them), and the presentations are all freely available at http://www.us-cert.gov/control_systems/icsjwg/presentations.html .

Under the UCA International Users Group (UCAIUG) there exists the vaunted and very active Open Smart Grid (OpenSG) users group, with several active Smart Grid security groups operating under their umbrella.  Literally hundreds of people (many of the same working with the NIST groups) meet regularly to discuss security, take on tasks, and publish documentation which has been utilized by NIST to help develop their special publications (including NISTIR 7628), and by both utilities and public utility commissions to guide their security efforts and regulatory efforts.

The Federal Energy Regulatory Commission (FERC) has worked with the North American Electric Reliability Corporation (NERC), who have developed critical infrastructure protection requirements (NERC CIPS), which are used by utilities for auditing the security in bulk generation and transmission.  The US Department of Energy (DOE) has granted millions of dollars to organizations who are charged with researching and developing security methods to protect our energy infrastructure.

There are several active Smart Grid and Industrial Control Systems active mailing lists, and several LinkedIN groups focused on Smart Grid security discussions and collaboration.  Several research organizations (most notably Pike Research) have invested enormous efforts on researching and reporting on the topic of Smart Grid security, and the security product and vendor community has come out in force to address the challenges that are constantly being discovered and discussed among Smart Grid security professionals.

Of course, I must take the opportunity to also give myself a shameless plug, since I created the Smart Grid Security Summit (www.smartgridsecuritysummit.com), which took place this past Summer, and this has led to the upcoming Smart Grid Security East conference (www.smartgridsecurityeast.com), where representatives from all the above mentioned organizations (and a lot more) will be presenting on nearly every Smart Grid security topic there is to talk about.  I certainly hope some of you can make it to the event.  It will be worth your time if Smart Grid security information is what you seek.  You can also freely join and attend meetings of the NIST, DHS, and OpenSG groups.  Anyone interested in helping is welcome.

Otherwise, please continue to peruse the fear, uncertainty, and doubt (FUD) driven news headlines.  If nothing else, they are quite entertaining.

Sunday, December 5, 2010

WikiLeaks and Why "Plan B" is now more important than "Plan A"

We all understand the idea of "Plan A" and "Plan B".  Plan A is the plan we put in place that is meant to work as planned.  In security, it is the plan we hope will ensure the CIA (Confidentiality, Integrity, and Availability) triad is in place.  We put a lot of effort into Plan A, and then the more intelligent among us will put some effort into a Plan B.  This is the plan we switch over to in the event Plan A fails.

This is generally the "damage control" mode plan.  This is the plan we all hope we never have to go to, since by this point something very bad has happened.  This could be something like...say perhaps...all of our national secret and top secret information getting leaked on a website.

That can be a really bad thing...

By now we are all probably keenly aware that the masterminds behind the WikiLeaks website have decided that information must all be publicly shared no matter what.  Someone asked me my opinion about this several days ago....if I thought it was a good thing of bad thing...and my response was simple.  I do not have an opinion about it being a good thing or bad thing.  What I do know is that it is something that exists,  and we must now figure out a way to deal with it, because it is NOT going to go away...EVER!  It is like winter in Cleveland...deal with it.

I know this may sound harsh, but that is what we are facing.  We live in an age where information ebbs and flows (and overflows) like water in an ocean.  It comes to us as a gentle and calm breeze, or as a hurricane.  It drifts down like snowflakes, or comes crashing down like an avalanche.

Okay...enough analogies...you get the picture.  The truth is, we simply no longer have the control of information we once thought we had.  The very nature in which we communicate today has created an environment were massively scalable information storms can occur.  In the "good old days" we communicated by sending letters and talking.  Today we communicate by generating data that gets pumped into "The Cloud", and then BLINDLY trust that it will only get to the intended recipients and nobody else.

Isn't that cute...

The Plan A way of dealing with information has been to protect the confidentiality, integrity, and availability of the information for as long as information has been important to us (essentially forever, but perhaps more so today in the information age).  While we have created some absolutely fantastic systems for insuring both the integrity and availability of information over the last several decades, it seems that the very systems we have built have made it increasingly more difficult to insure confidentiality.  Through the application of Moore's Law we have created systems with insane amounts of processing power, and have driven down the cost of these systems to almost nothing (I say almost nothing because you can find computers for free these days...at least in the San Francisco Bay Area), meaning that anyone can get their hands on the tools needed to both obtain and distribute information.  There was a time when getting confidential information meant breaking encryption or applying brute force or dictionary attacks on systems.  While this is still true today, we now live in a world where there are so many people accessing systems throughout the world, we no longer need to break into systems to get a hold of sensitive information.  Today somebody who has authorized access to information either copies it or sends it into the cloud for all to consume.  What makes this so difficult to control is that there are so many who have access to information, and either through direct access or aggregation the information can be assembled into nice little information bombs.

In other words, confidentiality has become nearly impossible to both achieve and manage.

This makes Plan A an incredibly difficult plan to manage, and certainly makes our reliance on Plan A more and more difficult to justify from a due diligence/due care perspective.  We simply live in an age where we MUST assume compromise.  We must accept the fact that, at some point, confidentiality goes out the window.  Time to look at Plan B.

I am not sure what the US Government is doing with respect to Plan B.  I saw an article where the US Government is warning college students to not talk about WikiLeaks...or else.  I see some efforts to shut down the WikiLeaks site, and cut off funding sources.  I imagine these are all some valid steps to take...in an act of desperation.  Okay, maybe it is not desperation, but it certainly seems desperate.  I mean...c'mon...do we really believe this is going to do anything more that irritate a bunch of college students who already do not like our government to begin with, and who are perhaps infinitely more savvy about the information age?

I am fairly certain that Plan B has not been given the level of attention it should have been given.  It is very difficult for people who are intelligent AND arrogant (a bad but common combination) to consider the possibility that their best laid plans may have a fatal flaw.  Consequently, anything more than a cursory level of attention to Plan B is considered an admission that maybe they are not as smart as they think they are.  Perish the thought!

The truth is, Plan B has ALWAYS been more important than Plan A.  By the time you get to point where you need to use Plan B, things have generally gotten very bad.  This is now the time were you must not only figure out how to keep things operational, but also undo the damage that caused Plan A to fail.  This is the "do or die" moment.

We certainly need to continually focus on protecting information.  We do indeed have systems and methods available to us today that can buy us some time in the race between those who need to protect information and those who want to uncover it.  We simply need to understand that at some point the information we so dearly protected is likely to be become publicly available, and use that mentality to weather the information age.  It may take some time, but I am sure we will eventually get to a point where we can deal with this...much like I dealt with 21 years of Cleveland winters.

Thursday, November 11, 2010

Can I Steal A Vowel ? Never Mind...I Don't Need To.

The human mind is capable of some amazing feats.  The conceptual capabilities of a young child, for example, astound me.  I am a fairly good chess player, and recently my 6 year old son decided he wanted to learn chess (having seen "Wizard Chess" played in a Harry Potter movie), and I decided to indulge him.

Being a firm believer that children are far more capable of what some tend to give then credit for, I play him just as hard as I would play anyone, which meant the first few games resulted in quick checkmates.  It did not take long for him to figure out how to think ahead and use inference as a strategic method, and he has since managed to achieve stalemate.  Games now frequently last for an hour or more.  Not bad for a 6 year old.  Pappa is so proud!

What amazes me is watching him "think".  I swear I can almost feel his brain thinking, and I swear I can sense his "brain muscles" getting stronger.  I also believe that ANYONE can build those "brain muscles" if the drive exists to do so.

Let's consider an interesting story I read this morning.  It was an article on esquire.com about a Wheel of Fortune contestant who solved the puzzle with 1 letter (and a freebie apostrophe).  I read the story and realized that she was using a highly tuned level of inference in order to arrive at her conclusion.  It reminded me of a conversation I recently had with Dr. Fred Cohen (we occasionally meet at the local Peet's for coffee and conversation).  He stated that he believes that inference is impossible to prevent,  and I have to say that I tend to agree with him.

A hacker (researcher, penetration tester, whatever term you like) is presented with overwhelming amounts of information surrounding a system all the time.  In fact, the challenge is not where to find the information, but how to filter out what does not matter.  With a little mental exercise, this can be accomplished very quickly...mainly because most organizations charged with protecting information are inherently lazy, and fail to understand the power of aggregation and inference.  I have discovered countless pieces of company "confidential" information from piecing together bits of information available in various "sanitized" versions of documents.  Bear in mind, I am not a "hacker" (at least not in the modern sense of the word), but I get how hackers think...at least to some degree.

I think about this a lot when I consider Smart Grid technologies, as well as health care information technologies.  As these technologies grow we are going to see new sources of information emerge, and in our inherent somewhat lackadaisical manner of dealing with security at the decision making helm of our corporate culture, we will create plenty of early opportunities for aggregation and inference.

Things are going to get interesting....

Monday, November 8, 2010

Smart Grid Hackenomics

I recently attended (and presented at) the Department of Homeland Security Industrial Control Systems Joint Working Group (DHS ICSJWG) meeting in Seattle Washington. It was a interesting event, and STUXNET seemed to be the hot topic everyone was discussing. Most of the sessions were quite good, and many were informative.

When I attend these types of events, I often find the side conversations I have with attendees more interesting than the conference itself. I had the opportunity to chat with people who work at DHS, FBI, NRC...and just about any other 3 letter agency seeking to get a handle on cyber security issues. It does my heart good to know that our government is indeed serious about cyber security, and truly seeking knowledge.

The most interesting discussion I had, however, was on the last day. It was during a lunch break with one of the attendees, and we started a discussion on the economics of attacking the Smart Grid. Essentially, we agreed that "hobbyist" attackers and "nation-state" attacks are perhaps not the types of threats that should (or do) cause great levels of concern at the C-level's of stakeholder companies. At the highest decision making level of any organization directly affected by security threats, the only issue that consistently keeps them awake at night is money...or rather the loss of money. In fact, when we talk about security, we must constantly understand that an enterprise's chief (and arguably exclusive) security concern is in securing their ability to keep making money (and not lose money).

In other words, if security does not lead to more $$$, expect some rolling eyes. Likewise, if a lack of security leads to a loss of $$$, expect some wide eyes. This is the beginning of my Theory of Hackenomics.

In our discussion, we used the financial industry as an example of an economic model that makes a lot of sense to organized criminal enterprises. In the former Soviet Union, there are criminal enterprise organizations that provide tools and support services (for a fee) to criminals who want to make a career out of exploiting security holes in the financial industry. This is a very popular target for criminals because it is both large in size, and the direct result of a successful attack is immediate access to cash. So as part of my theory I want to state the following: The quicker an attack leads to cash for the attacker, the greater the likelihood that the attack moves from theory to reality.

This is, however, only part of the theory. The other part has to do with volume. For organized crime to get involved, the volume needs to be big enough to take the risk. Remember, organized crime is just as concerned with risk as corporations are (some will argue that corporations are the "new" organized crime anyhow). Therefore a quick path to cash that does not include a large enough volume is not necessarily a win for organized crime.

Another important issue to consider is keeping the attack as "clean" as possible, in order to make collecting and retaining the cash as easy as possible. A good example of this is how financial firms created Credit Default Swaps as a way to hedge high risk investments. This instrument allowed the potential for a large return on the chance that those who took out those crazy loans on overpriced homes (and such) would default. Well, as it turns out, those who purchased Credit Default Swaps seem to have done quite well. It was essentially a low risk method of shorting the entire financial system, and it is perfectly legal under today's laws.

So now this brings me to what became an interesting part of the lunch discussion. I postulated that if a large stakeholder in the Smart Grid ecosystem (in other words, a large publicly traded utility or AMI product vendor) was vulnerable to a major Smart Grid related attack, and an attacker held onto a 0-Day vulnerability, he could potentially sell the 0-Day vulnerability for a lot of money to a large criminal enterprise, who could then short the stock of the utility or product vendor, and then publicly announce the vulnerability. Granted, this would require some coordinated effort, but if done correctly, one could make a killing when the stock plummeted on the bad news. The news alone would probably drop the price enough to make a lot of money with a high enough volume. The news immediately followed by an actual attack would probably lead to a very big win for the criminal enterprise.

As we continue to have lunch, we discussed a few more ideas, and I thought of a few more over the last several weeks (I am not going to go into them here), and I came to the conclusion that Smart Grid Hackenomics may indeed be an interesting discipline for criminal organizations to investigate...and they probably already are.

Hopefully, the C-Level people at stakeholder organizations have thought of this as well.


Sunday, November 7, 2010

Mobile Application Insecurity

Being someone who has develops secure mobile applications, I am consistently dumbfounded at large enterprises (who should know better) that fail to secure their mobile applications. A recent article in The Wall Street Journal highlighted some findings by viaForensics which pointed out several banking applications for mobile devices that store passwords unencrypted on devices.

The banking industry is no stranger to security concerns. They are indeed one of the largest purchasers of security products and services globally. The rush to bring mobile applications to the marketplace by enterprises has not overlooked financial firms, however, and they are simply not applying basic principals of secure application development - such as build security in from the very beginning, and test the security before deploying the applications. I am absolutely floored by the number of financial applications available on the iPhone (for example) that do not require something as simple as a PIN to enter the application after storing the password (let alone encrypting the password).

It is carelessness at best, and completely irresponsible at worst. Banks, Large Enterprises, and Health Care organizations should make maximizing security a priority with any and every application that deals with ANY potentially sensitive information...and they consistently fail to do so often enough to convince me that there will be a lot more breaches before things get better.

What I also find remarkable is how a company like Apple, who scrutinizes application submissions and regularly rejects applications that use foul language, show nudity, or (God forbid) replicates Apple functionality. Yet Apple does not bother to reject applications submitted by banking and health care organizations (the latter being something I am personally well aware of) that fail to encrypt information. Is this their responsibility?

Yes it is!

Security is everyone's responsibility, and until we understand that, we will continue down the same path with every new technology, platform, and latest and greatest thing that comes down the pike.

You can bank on that.

Friday, September 10, 2010

"Smart Grids Don’t Present Any New Security Threats" (According To At Least One Man's Opinion)

I read an interesting interview on TMCnet this morning. It was an interview with Chris King, who is the Chief Strategy and Regulatory Officer at eMeter. One of the questions he was asked...well, let me just quote it directly:

Q: Don’t smart grids potentially present a major security threat?
A: Smart grids don’t present any new security threats. Utilities have controlled millions of customer-owned air conditioners, water heaters, and other devices for decades with no security breaches. In fact, the technologies being deployed today are more secure than ever.

Hmmm....

I would suggest that Chris King might consider taking a look at NISTIR 7628, Volume 3, Chapter 7.

Let me quote from that specific section:

7.1 Scope

...First, we have identified a number of evident and specific security problems in the Smart Grid that are amenable to and should have open and interoperable solutions but which are not obviously solved by existing standards, de facto standards, or best practices. This list includes only cyber security problems that have some specific relevance to or uniqueness in the Smart Grid. Thus we do not list general cyber security problems such as poor software engineering practices, key management, etc., unless these problems have some unique twist when considered in the context of the Smart Grid. We have continued to add to this list of problems as we came across problems not yet documented...

This chapter then continues on for a bit over 30 more pages (including references) to articulate the specific security issues identified in the Smart Grid (so far). You know, the ones that Chris King essentially says are not there.

Perhaps Chris King has not read NISTIR 7628, or he simply does not agree with more than 400 people who contributed to NISTIR 7628, let alone the plethora of "unofficial" discoveries made by security consultants worldwide. I would strongly suggest that he takes a good hard look at NISTIR 7628 (at least at Volume 3, Chapter 7) and then revisits his last statement.

I am sure he is a very smart person, and perhaps he was misquoted (that can happen). I would love it if he would comment on this.

Sunday, September 5, 2010

NISTIR 7628 Is Final...So Now What?

The entire Smart Grid deployment and cyber security world has been waiting for NISTIR 7628 to move from "Draft" status to "Final" status for nearly one and a half years. This magnificent effort, which included over 400 participants from many industries, government agencies, public and private groups, and just plain interested individuals, has culminated in 3 volumes that essentially read like an encyclopedia of cyber security best practices and technical jargon, complete with tables, drawings, and lots of arrows pointing all over the place. It is an impressive compendium of knowledge, and you can get your very own copy by going here.

So what does this all mean to the world of Smart Grid security? Does this make us more secure?

Well, as things stand right now, not exactly.

First of all, let's understand something about NIST and NISTIR 7628. The title is both prescient and potentially misleading. Here is the title for Volume 1:

Guidelines for Smart Grid Cyber Security: Vol. 1, Smart Grid Cyber Security Strategy, Architecture, and High-Level Requirements

Look carefully at the first word and the title and bear in mind that, for all legal intents and purposes that is all that matters. It is a "Guideline". I know it says "Requirements" at the end of the sentence, but understand that NIST does not dictate requirements to anyone who has the authority to enforce anything. The only requirements NIST has any authority over is the requirements NIST sets forth to comply with NIST standards (i.e. there are certain specific requirements that an entity must meet in order to become FIPS certified).

Why do I say this is potentially misleading? Well, because unless an authoritative body passes a rule, law, or mandate of some sort that requires the adoption of all or part of the recommendations in NISTIR 7628, it is nothing more than a magnificent exercise.

The simple existence of Smart Grid security guidelines does not make the Smart Grid more secure. The correct implementation of Smart Grid security standards, however, can.

Yet simply pointing at the NISTIR 7628 and saying "do this" will not suffice. This is because NISTIR 7628 is a collection of NIST standards and recommendations. While this may seem sufficient for some, it is still too open ended to serve as anything close to prescriptive. In fact, NISTIR 7628 is not intended to be prescriptive, and it says so in section 2.2 of Volume 1:

"This list of technologies and services is not intended to be prescriptive; rather, it is to be used as guidance."

This leads to the obvious conclusion that NISTIR 7628 is not intended to serve as "the rulebook", but to assist the rulemakers in writing "the rulebook".

So who are the rulemakers?

Well, that is a good question, and one that is not so easy to answer without first understanding that it all depends on what part of the Smart Grid we are talking about.

To try to simplify this as much as possible, and forgive me if this is oversimplified (or overly complicated as the case may be).

We can break the power Smart Grid into three categories:

1. Generation - Where the power is generated (i.e. the power plant)
2. Transmission - How the power gets from the power plant to the substations that send it to those who use it.
3. Distribution - The part of the organization that the user directly interfaces with (the ones who read your meter and send you a bill and shut off your power if you do not pay your bill).

So Generation and Transmission are generally not considered part of AMI (Advanced Metering Infrastructure). AMI is the part of the Smart Grid where smart meters live. Generation and Transmission currently fall under the jurisdiction of the Federal Government, and are therefore subject to the whims of the Federal Energy Regulatory Commission (FERC) and the North American Electric Reliability Corporation (NERC). NERC is not a Federal agency, but is given authority by FERC to conduct audits, levy fines, and all sorts of interesting stuff that tends to keep utilities in various stages of insomnia and cold sweats.

Distribution, on the other hand, falls under the jurisdiction of the individual States, and consequently the Public Utility Commission (PUC) of a given state.

So what this means is that FERC, NERC, and the State PUC's must now take a long and hard look at NISTIR 7628 (not to say they have not already been doing so) and try to synthesize some specific regulations based upon what is contained in this very verbose 3 volume set. This is no easy task, as one can imagine. Let's examine one particular section, taken from Volume 1:

4.2.1.8 Physical Security Environment
...In determining the appropriate level of physical protections required for a device, it is important to consider both the operating environment and the value and sensitivity of the data protected by the device. Therefore, the specification of cryptographic module physical protections is a management task in which both environmental hazard and data value are taken into consideration. For example, management may conclude that a module protecting low value information and deployed in an environment with physical protections and controls, such as equipment cages, locks, cameras, and security guards, etc., requires no additional physical protections and may be implemented in software executing on a general purpose computer system. However, in the same environment, cryptographic modules protecting high value or sensitive information, such as root keys, may require strong physical security...

If, for example, you are the CPUC (California Public Utility Commission) and are attempting to create a requirement based upon this section for physical protection of cryptographic modules (and the data contained within them), one must first define what "high value or sensitive information is". The root key mentioned is a good example, but what about other information stored on the device? What is the information? Is it also sensitive? Who determines if it is sensitive or not?

If the CPUC then determines that the information stored is not overly sensitive (i.e. not a root key), then it is important to ensure that the scope of the information stored on such modules does not "creep" to a point where it may indeed become sensitive. This is no easy task, because sometimes what is deemed safe today does not always remain safe going forward. A good example of this is a Social Security Number. There was a time when nobody had a problem sharing their Social Security Number with anyone. Heck! In many cases it was your ID number for school, work, military, etc. What happened, however, is that the scope of the Social Security Number expanded, and it was soon discovered that if you knew someone's number you could do all sorts of bad things with it.

If the CPUC determines that the information is indeed sensitive, then they are tasked with determining what standard for protection of such information must serve as a baseline (i.e. FIPS 140-2).

Providing they can accomplish these tasks, they must then determine if and how they are going to audit (and potentially certify) such requirements.

...but first they have to determine what is in scope and what is not in scope, and why. This in and of itself requires the PUC's (and FERC and NERC) to have an intimate understand of what parts of NISTIR 7628 (and potentially other guidelines, such as the excellent work done by the UCAIUG AMI-SEC Task Force, which is specifically credited for their contributions to NISTIR 7628 within Volume 1) apply to their purview. Looking at this at the Federal level, one might conclude that they have enough resources to tackle this task, but having listened to FERC Commissioner Philip Moeller's keynote address at my Smart Grid Cyber Security Summit last month, in which he stated "We don't have all the answers, we need all of you to help.", I am led to believe that we still have a long way to go.

...and it is even more challenging for State PUC's. The CPUC is a fairly well staffed organization, being that California is indeed a very large State. Nonetheless, the CPUC does not currently have anything close to a comprehensive understanding of cyber security. To be fair, why would they? In its many years of existence they have never had to deal with cyber security issues with respect to regulation of utilities, and up until the passage of California SB 17 it has never been their responsibility. However, being staffed with some very intelligent (and diligent) people, and now being responsible for making decisions relating to cyber security and the Smart Grid, the CPUC has indeed taken it upon themselves to rise to the occasion. I have personally attended two public hearings at the CPUC where Smart Grid security was discussed, contributed to requests for comments from the CPUC regarding cyber security, and the CPUC is planning a public hearing to specifically discuss NISTIR 7628 with the NISTIR 7628 team at the CPUC at the end of September, 2010 (currently planned for September 28th and 28th), as well as additional workshops to hash out the details of Smart Grid security.

This is all good stuff!

...but what about other PUC's? Some States (from what I have been told by members of the CPUC) have PUC's that could fit into a small room with plenty of space to spare for filing cabinets, chairs, and tables. In other words, they are woefully understaffed and underfunded. How are they going to manage cyber security?

Well, one answer is contained in one of my favorite sayings "As goes California, so goes The Nation." Their eyes are on California, and what California decides is quite likely to serve as a template for the rest of the nation. Some have also argued that Texas is also serving as a template. While this may be true, I have a sneaking suspicion that California will likely prevail as a trendsetter. Only time will tell, I imagine.

The great news is that there seems to be no shortage of people who are willing to volunteer their time in working through these challenges. It may not be entirely altruistic in nature (hey, everyone wants a piece of the Smart Grid security market pie, including yours truly), but the fact remains that we are indeed well served by some of the great minds working on the effort. PG&E has a cyber security team currently led by CISO Dave Tyson (who came from the security team of eBay) and PG&E has been dealing with Smart Grid security for longer than just about any utility in the world. The UCAIUG AMI-SEC Task Force is still working hard and growing stronger with every meeting (I try to attend and contribute as often as possible). Many AMI vendors are currently specifically dedicating resources to cyber security efforts, and are working together in a spirit of "coopetition", where they cooperatively share information with each other despite being competitors. Anyone who attended my conference is well aware of just how many organizations are involved in this effort, and the list keeps growing.

We still have a lot of work to do, but we have come a long way, and I am not even close to tired yet! NISTIR 7628 is worthy of being celebrated for finally being completed, but now the real work begins.