A report released this week by the Foundation for Defense of Democracies (FDD) examines ongoing security threats to the United States bulk-power system — the high-voltage transmission infrastructure that moves electricity from generators to local distribution networks and ultimately to homes and businesses. The FDD, a Washington-based nonpartisan policy institute that has tracked foreign interference in critical infrastructure for years, argued that existing federal rules have not kept pace with the scale of the problem.

The bulk-power system is distinct from the local distribution grid most people picture when they think of power lines. It operates at voltages typically above 100 kilovolts and includes large power transformers, high-voltage direct-current terminals, and control systems that are extraordinarily difficult and slow to replace. A 2014 Federal Energy Regulatory Commission (FERC) analysis — still widely cited in policy circles — estimated that destroying as few as nine of the roughly 2,000 high-voltage substations across the country during peak demand could cause a coast-to-coast blackout lasting 18 months or more, because domestic manufacturing capacity for the largest transformers is severely limited and lead times from overseas suppliers can run 12 to 18 months even under normal conditions.

The FDD analysis focuses specifically on the sourcing problem: a significant share of the electrical equipment installed in U.S. substations over the past two decades originates from Chinese and Russian state-linked manufacturers. Executive Order 13920, signed in May 2020, gave the Department of Energy authority to block or require removal of bulk-power equipment from foreign adversaries, but implementation has been uneven. A 2023 DOE Inspector General review found the department had not yet established a comprehensive inventory of potentially prohibited equipment already embedded in the grid, a gap the FDD report highlights as still unresolved as of its October 2026 publication.

The report also points to the expanding attack surface created by grid modernization. As utilities add digital sensors, remote monitoring, and automated switching to aging substations — often using commercial off-the-shelf networking components — the number of software-accessible entry points grows faster than utilities' cybersecurity staffing can track. The North American Electric Reliability Corporation (NERC) Critical Infrastructure Protection (CIP) standards set baseline cybersecurity requirements for bulk-power operators, but FDD argues the standards apply unevenly across utility sizes and leave some transmission owners with meaningful compliance carve-outs.

What most mainstream coverage of grid-security reports omits is the distinction between the bulk-power system and the distribution grid, and why that distinction matters for understanding actual recovery timelines. Local outages caused by storms or equipment failure typically draw on an established supply chain of standardized distribution transformers — units that weigh hundreds of pounds and can be trucked in from regional warehouses within days. Bulk-power transformers, by contrast, are custom-engineered units weighing hundreds of tons, shipped on specialized rail cars, and requiring months of on-site installation and commissioning. There is no strategic stockpile of them. The DHS-backed STEP (Spare Transformer Equipment Program) has made incremental progress in building a reserve of recovery transformers, but the program covers a fraction of the highest-criticality units on the network. That asymmetry — relatively quick recovery from distribution-level failures versus potentially multi-year recovery from bulk-power failures — is the factual backdrop against which the FDD's policy concerns should be read.