BREAK IN TRANSCRIPT
Mr. KING. Mr. President, at 3:30 in the afternoon on December 23 of last year, about a half hour before sunset, the lights started to go out in western Ukraine. The power started to go out. The operator in one of the Ukrainian powerplants noticed, to his horror, that he no longer controlled the cursor on his computer screen. The cursor moved of its own accord and started opening dialogue boxes and opening breakers.
The operator tried frantically to get back into the computer, only to find he was locked out and the password had been changed. At the same time, the call center of this utility in Ukraine was blocked by thousands of fake calls, so the utility itself could not know what was happening in the countryside. The backup generators around western Ukraine also went down. Malware was installed on the operating computers and a system called KillDisk was installed, which wiped the disks and rendered the computers useless.
As a final insult, the power in the power control system itself went off and the operators were literally left in the dark. This was the first major cyber attack of a public utility anywhere in the world. It was sophisticated, it was well planned, and it was devastating. Within a few minutes, 230,000 people in the country of Ukraine were without power.
That attack could have occurred in Kansas City, in San Jose, in New York, or here in Washington. Ever since I have served in this body as a member of the Armed Services and Intelligence Committees, I have heard repeated warnings from every public official involved with intelligence and national security that an attack on our critical infrastructure is not possible, it is likely.
How many shots across our bow, how many warning shots do we have to endure? Sony, the OPM, insurance companies, and now the nightmare scenario of an electric grid attack.
We can learn something from what happened in the Ukraine, and there is a piece of good news and a lesson for us. The attack, which left 230,000 people without power, only persisted for about 6 hours. The interesting part of the scenario of this development was that one of the reasons they were able to get the power back on so fast was because the Ukrainian grid was not up to modern--I hesitate to say ``standards''--practices in terms of its interconnectedness and its digitization. There were old-fashioned analog switches, and the most old-fashioned analog switch of all, a human being, who could actually throw breakers and get the system back online.
However, in this country we are not so lucky, and I use that in a very sort of backward way because we have the most advanced grid structure in the world. We are more digital, we are more automated, we are more interconnected, but that makes us more vulnerable. That makes us more vulnerable. We are asymmetrically vulnerable because we are asymmetrically interconnected. We keep getting these warning shots. A lot is being done by our utilities and by our government agencies to work on protecting this country from a devastating cyber attack. But I know of no one who would assert that enough is being done and that we are ahead of this threat.
I introduced a bill yesterday, along with three cosponsors: Senator Risch from Idaho, Senator Collins from Maine, and Senator Heinrich from New Mexico--all of whom, along with myself, are members of the Intelligence Committee, where we hear about these threats practically weekly. The bill is pretty straightforward. It tasks our great National Labs with working with the utilities over a 2-year period to determine, not new software patches and new complexity, but if we can protect our grid by returning to, at least at critical points in the grid, the old-fashioned analog switches or good-old Fred, who has to go and throw a breaker with his dog. It may be that going back to the future, if you will--going back to the past and simplifying some of these critical connection points may be the best protection we can have. The idea is for the Labs to put their best people on this and for the utilities to do the same on a voluntary basis.
I might add that there is nothing mandatory about this bill. We are trying to work on finding some solutions that are implementable in the short run to protect us from this grave threat. Once we get a report back, hopefully we will be able to implement this legislation across the country.
I am tired of hearing warnings. It is really time for us to act, and this is a straightforward bill that I hope can move through this body at the speed of a cyber attack so that we can then have the defense we have to have.
An attack on our critical infrastructure--particularly the electric infrastructure across this country--would, in fact, be devastating and would undoubtedly involve a loss of lives. I do not want to be here on a darkening winter afternoon and see the lights going off across America--the power to hospitals, the power to our transportation system, the power that makes our lives what they are today. This is not an abstract threat. We know from the Ukraine that the capability exists to do exactly that and take down the grid. We must act expeditiously and directly to counteract that threat. If we do not do so, we are failing our responsibility to the people of America, our constituents, and the United States.
I urge rapid consideration of this bill, and I look forward to its consideration at the Energy Committee. Three of the four sponsors are also members of the Energy Committee as well as the Intelligence Committee, and I am hoping we can move this rapidly so we can begin the process of countering what is not an abstract threat but a direct, clear, and present danger to the future of this country.
BREAK IN TRANSCRIPT