The study of energy sector security is in flux. A traditional focus on exploring the nexus
between terrorism and physical energy infrastructure has given way to a new and
specific emphasis on cyber attacks targeting electrical power grids. A noticeable gap
in the literature exists in terms of presenting a more comprehensive assessment of the
general threat environment. Our paper, and the larger project from which it stems,
intends to fill this void and prompt more nuanced and empirically driven research on the
topic that informs Canadian security policy. Our findings are informed by interviews
conducted with American and Canadian energy sector officials, and a questionnaire
carried out with energy sector companies. By examining a broader suite of disruptive
threats to the energy sector, we paint a more inclusive picture of the many gateways
through which the energy sector could be targeted.
Energy security, cyber security, counterterrorism, Canada–US relations, Canadian
national security, critical infrastructure protection
On 29 January 2019, US Director of Intelligence Daniel R. Coats presented the
Worldwide Threat Assessment of the US Intelligence Community to the Senate
Select Committee on Intelligence. In addition to highlighting expected concerns of
America’s national security community such as terrorism, organized crime, weap-
ons of mass destruction, and electoral interference, the report also emphasized
threats to an area which receives comparatively little attention—the energy
sector. With a standalone section dedicated specif‌ically to economics and energy,
the report provides a glimpse into the increased attention America’s national secur-
ity community is paying not only to the potential risks of changing international
energy markets, production, and demand, but to kinetic threats facing critical
energy infrastructure in the US. Similarly, other countries around the world have
signalled their intent to pay greater attention to this issue. Canada, for example,
specif‌ically mentions the energy sector in its National Cross Sector Forum
2018–2020 Action Plan for Critical Infrastructure and its 2018 National Cyber
Security Strategy, while the UK, New Zealand, Australia, and others are pursuing
a mix of regulatory, information-sharing, and governance changes to better address
their respective threat environments.
While many of these disparate initiatives are described as being ref‌lective of ‘‘all
hazards’’ (e.g. focusing on a wide range of threats and challenges to critical infra-
structure), there is a clear prioritization of cyber attacks, particularly those target-
ing the electrical grid. The US, for example, in the aforementioned report, discusses
its concern about Russia having the ‘‘ability to execute cyber attacks in the United
States that generate localized, temporary disruptive ef‌fects on critical infrastruc-
ture—such as disrupting an electrical distribution network for at least a few
Former Department of Homeland Security Secretary Kirstjen Nielsen
has echoed this challenge, stating: ‘‘An attack on a single tech company, for
instance, can rapidly spiral into a crisis af‌fecting the energy grid.’’
And US
President Donald Trump signed Executive Order (EO) 13800 in May 2017, order-
ing the federal government to prepare for cyber attacks targeting America’s
power grid.
The energy sector’s emphasis on grid security and defence against digitized
attacks is entirely expected, appropriate, and justif‌ied given the recent surge in
of‌fensive cyber operations and other forms of cyber attack conducted by state
and non-state actors targeting power grids and other critical infrastructure, but
