Process sensor issues continue to be ignored and are placing the country at extreme risk

June 1, 2021
A recent NERC Lessons Learned event discussed a 2019 event where a combined cycle power plant in Florida suffered significant load oscillations because a sensor provided erroneous input to the steam turbine controller. The controller reacted by cycling the turbine resulting in 200MW load swings (see Max 737 plane crashes). These oscillations caused a 0.25Hz impact on the entire Eastern Interconnect and resulted in a 50 MW load swing in New England (local failure affects entire interconnected systems similar to Colonial Pipelines). Like the 2008 Florida outage, there was no mention of the event being a cyber incident. There is no cyber security, authentication, or cyber logging in the sensor. Moreover, process sensors are out-of-scope for the NERC CIPs and NERC Supply Chain issues. The lack of process sensor authentication is also key to being able to address the Chinese transformers with hardware backdoors. 

In preparing for my keynotes and panel sessions next week, July 8-9 (follow-on blog), I found a recent NERC Lessons Learned event of a combined cycle power plant in Florida that suffered significant load oscillations. In this January 2019 event, a single potential transformer (PT) sensor provided input to the steam turbine controller in the power plant. However, the sensor was providing bad data and the controller reacted accordingly by cycling the turbine resulting in 200MW load swings (see Max 737 plane crashes). These oscillations caused a 0.25Hz impact on the entire Eastern Interconnect and resulted in a 50 MW load swing in New England (local failure affects entire interconnected systems similar to Colonial Pipelines). Like the 2008 Florida outage, there was no mention of the event being a cyber incident even though it was a sensor communicating to a control system that cycled a valve with the impact affecting the interconnected grid. I don’t know if the PT sensor was analog or digital, but in either case, there is no cyber security, authentication, or cyber logging. Moreover, process sensors are out-of-scope for the NERC CIPs and NERC Supply Chain issues. The lack of process sensor authentication is also key to being able to address the Chinese transformers with hardware backdoors. There have been more than 350 control system cyber incidents in the North American electric system to date with 5 causing outages affecting at least 96,000 customers. The utility industry has work to do when it comes to treating cyber security and reliability/safety as inter-related tasks.

Sponsored Recommendations

2024 Industry Trends | Oil & Gas

We sit down with our Industry Marketing Manager, Mark Thomas to find out what is trending in Oil & Gas in 2024. Not only that, but we discuss how Endress+Hau...

Level Measurement in Water and Waste Water Lift Stations

Condensation, build up, obstructions and silt can cause difficulties in making reliable level measurements in lift station wet wells. New trends in low cost radar units solve ...

Temperature Transmitters | The Perfect Fit for Your Measuring Point

Our video introduces you to the three most important selection criteria to help you choose the right temperature transmitter for your application. We also ta...

2024 Industry Trends | Gas & LNG

We sit down with our Industry Marketing Manager, Cesar Martinez, to find out what is trending in Gas & LNG in 2024. Not only that, but we discuss how Endress...