Remote location if necessary. Cybersecurity and awareness is a critical part of our operational preparedness. Though we are a small utility, we strive to follow industry best practices such as the use of network scanning and intrusion detection programs in protecting our Operational Data as well as our business and member information. We practice but in the Pennsylvania Department of Homeland Securitys task force on cybersecurity. Our preparedness in the field is tested throughout the year during localized outages caused by weather events and other conditions. Lessons learned through experience, along with the coordination with our national, statewide and local networks would form the basis of our response to a national or cyber event. Again i thank you for the opportunity to testify today on our emergency preparations and recovery efforts. Thank you for your testimony. I will now begin our first round of questioning. This question is to all. Im going to ask you the same question i asked our first panel. What is the planning scenarios that state and local governments should be using for a cyber attack on the electric grid . Will power be out out for days or weeks or months . Considering both a cyber attack and a physical attack, the worst case scenario. How widespread the outage be . Mr. Cauley, nerc runs and exercise on the failure of the grid. What scenario do you use . I will let you begin. Thank you mr. Chairman, for the question. As i mentioned in my presentation we do probably post estimated that is 10 times beyond any sort of realistic expectation in terms of the magnitude which is to test and shake us out and see what we can do. I think the difficulty in understanding the question is that theres many kinds of hazards that can cause outages. In fact, if you look at, we do a lot of data and analysis about what causes blackouts. Thats one of our jobs. Since 2011, so four years running in our data, the weather has been a top 10 causes of all major outages in north america. So we have that sort of a slowing. So the question for me, i phrase it as what kinds of things can cause outages from a few hours up to two to three days . Theres a lot of things that can contribute toward that, and what kind of response capability we have. So could the storms come to be equipment failure, could be a number of things. I think as we get to the kaiser things were talking about in terms of cyber and physical attacks, i think its reasonable to ask, and severe storms, i storms, hurricanes. It is reasonable to ask the question how are we taking care of people in a one to two week outage . And may not be everywhere but it might be in some local areas. It might be some cities that could reasonably be facing a one to two week outage. I would hate for us to say its a cyber event will its a storm. Really a Public Safety issue is very similar. The major difference would be to me the major difference would be, we know that some kind of security concern, Law Enforcement would be involved but still the same fundamental without electricity you need to take care people, give them fuel, food and water. The one scenario i think that is the exception i think was appropriate the committee participated in the legislation around their equipment, the one scenario i think realistically concerns me longer than the one to two week timeframe is damaged their equipment. And particularly the transformers, that could happen from bomb blasts, shootings, other gmt storms. The question is not what caused but the question is what are you going to do if you loose transformers. I guess what im getting at, i want to get this done, connect the dots down to the local and state. I feel pretty confident that getting to that point weve got all ducks in order. Im just concerned that theres a missing link to what should that states and local governments be preparing for or planning for any length of time . Because they need to do the same thing you are doing. They need to know the scenario of worst case, what do we need to prepare for . Spirit right. Ive been doing reliability for 35 years. I think there are two levels. Theres normal expected to see a number of times the year is the one to three days is a normal kind of scenario that everyone should be prepared for. I think they wanted to make scenario is a scenario that if you are prudent, i would be talking with the mayors and City Councils about what you can do to be ready for one to two week outage in the extreme case of hurricanes and earthquakes in those kinds of things. My only exception is spare equipment and damage may be more challenging. It really is independent of the cost, whether its cyber attack, i cant imagine a cyber attack that is going to damaged equipment to the outage within hours or days. I would agree with mr. Cauley. I think the prudent thing would be the same as what we are doing today for devastating storms which is will a one to two week outage preparation. There are a lot of resources that are currently available to local communities, both at the state and local Community Level that are really great resources that afford to i dont think all the towns and communities take full advantage of. A lot of really good best practices that have been used by towns and cities that have been more experience with devastating storms. So, for example, the state of florida has a lot of experiences and Lessons Learned that are available to towns and communities. I think the other thing and this was mentioned by the representative of fema earlier, it really boils down to in many cases the probability of the event happening that risk of the event and willingness to put in place and spend the money for backup generation or other backstops that would be necessary for one to two week events. I think thats where i would direct the towns and communities to be aware of what is available. Utilize that fold and then make the critical investments that they need to survive a one to two week period. Im going to connect the dots. Do you think its the federal governments responsibility or the state governments responsibility to make sure that the local government is doing all that . Iges consumer going to everybody pointing fingers where i thought you said, i think you did, nobody did. Whose responsibility should it be that we make sure that the local governments are prepared . Today is the first time im hearing a length of time, and in my own mind again im going to put the mayors back on, im beginning to think, if its a week or two weeks, theres a lot of things i need to be prepared for and were probably not. Which means that most cities are probably not prepared and i think thats what this is about is really to raise a red flag today that we are not prepared in the event of something drastic, major, unlikely but could be spent a couple comments. First i would say, and you probably would not want it is necessary but i think it is the shared responsibility between local government and the federal government. And i really do believe that because you are just not going to have federal boots on the ground in all these local communities to get the committees back up and running. Secondly, i would say theres things the local utilities do have at their disposal to up with local communities in terms of communication and even backup generators that we can deploy to high Priority Areas to make sure that when we need to restore the system and we cant do it in a timely fashion, at least for some basic level of service we can provide. I think in an extended period of outage you will still have power to certain areas, have a backbone the power to him in a big discount or that down by the think collectively there will be ways to get resources able to the local towns and communities. To be quite frank i was skeptical when they started this electric subsector core dating council and whether the cub was going to get help us as an industry to store power quicker but i think presently surprised the last level of cooperation and collaboration that has gone on in the last three to four years. There are simple things like providing fuel that we needed during Hurricane Sandy to restore towns and communities in new jersey and pennsylvania. Theres other things like providing dads for crews were coming from out of state. We were able to access a barracks at the department of defense facilities, access portable generators. Would able to access experts in emergency response. So the are some things the federal government can be very, very helpful for, and i think now that we have a playbook that dictates who does what when, which was always my concern in a major event, who do i call . Are they going to be ready for that call . I can say that from what ive seen so far i believe we are more ready than weve ever been in the past and we have a very good system and a playbook that we can go right down the light and have access, in this case, we are talking about with this committee to cyber resources at the highest level of the federal government. Thank you. I agree with my fellow panelists on the shared responsibility. I would also like to emphasize to the subcommittee the importance of communications during crisis periods. My experience has been sometimes its not the length of the outage but simply knowing how long its going to be a with the expectation is. It can help both residential consumers as well as townships and towns understand how they need to plan. I would also like to add one thing weve seen in our rural areas of, especially since Hurricane Sandy, and that is a focus on individual preparedness. Im seeing our local county Emergency Management agencies doing a great job in trying to educate the public on being prepared. We tried to do the same thing. Of course, we are in a rural area. We are subject to many weather events so i think our consumers are relatively prepared to im not suggesting we cant rely on that but i think that is an element in all of this. Thank you. The chair recognizes Ranking Member carson. Thank you, chairman barletta. Ms. Kilmer, you mentioned that copyright rural is not connected to the bulk power system but you receive services from the lack. What does it mean for cooperative in the event of a nationwide cyber attack on the grid . In the event that was a cyber attack that took down the grid we would be affected by that. The Transmission System was perfected empower was disrupted to a substation. Would also be out of power. Mr. Spence or whoever. It was a newspaper article yesterday that indicated that the fbi and department of Homeland Security have been warning that our industry over the last month about a potential cyber attack. What role as electricity information sharing and Analysis Center, what role might they play and distribute this kind of information . Thank you, congressman. That is exactly really what the information sharing and Analysis Center does. In fact, im not aware of that particular one. We do dozens of these a day. We get information posted industry. We have thousand participants and industry who received those notices every day. I yield back, mr. Chairman. Thank you. The chair recognizes mr. Meadows. Thank you, mr. Chairman. Mr. Cauley, did i hear you correctly, you said that in in e event of a cyber attack, the longest period of time that people would be without power, and our . Is that what you said . Thank you for allowing me to follow up on my, on whatever i said. My point spitters sometimes vital hit record but i wanted to give you a chance. The point i was trying to get to but i rushed was, its a very difficult form of attack to go from a cyber attack. Its easier to steal information or disrupt electronics. Its technically challenging to go from an electronic cyber attack to causing physical damage to equipment. Even in the ukraine attack there was no damage to equipment. The breakers were operating to basically shut down the theater still going to customers but there was no damage. So that once they realized what was happening, they basically a defeat the computers and that people go to the station manually and flip the switch and put the power back on. So my point, and i would love to continue working on this and getting some actual data to support that come is its very hard to transform from a cyber attack into longterm damage that would be measured in weeks. Because jeff hirt equipment to do that. Thats really my focus, is not turning a switch off your order or tripping the breaker or making the jack will out. Thats minor. I guess the type of Cyber Attacks that we are seeing and hearing about in classified settings is not directly related to the electric utility business. So being able to come in. I assume going into a generating capacity. Lets say you have a generator. Theres all kinds of controls and switches to make sure that you dont run into problems with the electrons. Lets put it that way. So all of a sudden somebody coming in with nefarious, not just turning a switch off, and scramble it in such a way that it would create unbelievable damage, certainly from the standpoint of generating capacity. I dont want to talk about it in an open forum like this, but i guess my concern, are you not having those kinds of conversations which are more than just turning the power switch off as happened in the ukraine, but really causing longterm damage either to generation capacity or transmission capacity . Yes, congressman. I had the privilege of going to similar classified briefings as well. But also 35 years of experience working in substations with equipment. I understand the threats of black energy or aurora are stuxnet or things like that but its difficult to transform an action that the predominant behavior were seeing today is surveillance type behavior. To transform that into an action that destroys a piece of equipment thats comforting to know. Thats a real comforting because what im going to do is, i will followup with both you and mr. Spence as relates to this, because again is one of the number one questions that i get is just a real concern. Its about getting the grid, and most people dont understand the interconnectivity between utilities. A lot of that its blown way out of proportion, but at the same time your confidence level, if there were a cyber attack on an investor owned utility somewhere in the midwest, the damage they could cause come in your opinion, would be minimal . The damage on the information systems, that would be their business risk. On the grid its very difficult. Its very unlikely to put the grid out for one to two weeks. I think what you are saying is mass outages for multiple weeks or days, in your opinion, is going to be a weatherrelated event . Or the other thing is a physical attack which is shooting and explosive device at the substation, are two things i think and get into that wanted to reach and beyond. Those are a lot easier to anticipate and plan for. Gets very complicated g20 sites at once with a physical attack with the current Law Enforcement we have. I think that risk is mitigated as well. The one i worry about the most is a physical attack. I will followup with all of you. I just want to say thank you as a member of my local rea. I have great affinity for my reas. Thank you very much. I yield back. I just have one more question, mr. Spence. My colleague from pennsylvania highlighted that to me coal power plants have closed. Are you concerned having fewer generation facilities online makes the grid as a whole more vulnerable . I am not. In fact, mr. Cauley and his team are also responsible as part of their duties to evaluate with very detailed modeling region by region the impact of retirements of any sort on the grid of major power stations. They have evaluated this multiple times in fact and i found that we continue to maintain an adequate reserve of capacity, should we see more retirements that actually forecast. So even with a forecast of retirements, which are many, particularly on the cold side, we have adequate capacity to meet all of our projected needs for power. Thank you. I look forward to working with each and every one of you and welcome your input as we move forward on this initiative. I thank you all for your testimony. Your comments had been helpful to todays discussion. If there are no further questions i would ask unanimous consent that the record of todays hearing remain open until such time as our witnesses have provided answers to any questions that need submitted to them in writing. Unanimous consent the record remain open for 15 days for any additional comments and information submitted by members or witnesses to be included in the record of todays hearings. Without objections order. I would like to thank our witnesses again for the testimony. If there are no further questions to add, the subcommittee stands adjourned. [inaudible conversations] [inaudible conversations] [inaudible conversations] [inaudible conversations] [inaudible conversations] [inaudible conversations] our live coverage of the president ial race continues tonight for the new york state primary. Choice at nine eastern for election results, candidate speeches and viewer reaction. Taking you on the road to the white house on cspan, cspan radio and cspan. Org. The senate is about to start its session. They will have a final passage vote on providing just over 33 billion to fund the faa in till september 30 of next year and will recess for party lunches following the vote. Back at 2 15 p. M. And work on an Energy Modernization bill which would modernize the nations electric grid and approve Energy Standards for buildings. Senators will also debate a number of amendments with votes on those and final passage later today. The president pro tempore the senate will come to order. The chaplain, dr. Barry black, will lead the senate in prayer. The chaplain let us pray. Eternal spirit, the splendor of your presence delights us. You have been our help in ages