North Carolina's biggest threat

Published 5:35 p.m. today

By Tom Campbell

Our state’s greatest threat likely won’t come from storms, although we all know the damage hurricanes, floods, and ice storms can create. It won’t come from political upheavals or a revolution, although we acknowledge the turmoil that could result. And it’s hard to conceive of a widespread epidemic wiping large numbers of us out, although COVID gave us a scare.

North Carolina’s most likely threat come from one or more cyberattacks - deliberate, malicious attempts to destroy or disrupt our water supplies, natural gas pipelines, supply chains, or our power grid.

Remember December of 2022, when unknown attackers shot out the transformers of two large electric substations in Moore County? More than 45,000 residences and businesses were without power for four days. We still don’t know who did it or why they perpetrated these attacks.

Another example. On August 4th, our ports in Wilmington, Morehead City and the Charlotte Inland Port were victims of cyberattacks that disrupted their Information Technology systems, forcing them to revert to old-fashioned manual operations, delaying valuable cargo processing. Fortunately, they had cybersecurity contingency plans that prevented the attack from being a major event; there is no evidence that sensitive data was compromised. But the Wilmington port is located within 700 miles of 70% of the nation’s industrial base and could have disrupted supply chains.

In June, the Shipping Association of New York and New Jersey, the authority for moving cargo through one of our nation’s busiest ports had a ransomware breach.

The most common types of cyberattacks are phishing, ransomware, malware, denial of service and supply chain attacks. Phishing attacks are fake emails or messages that look like they come from real sources, but don’t. Ransomware invasions attempt to extract payment for personal files and malware is the insertion of malicious software like viruses or spyware into your accounts.

If you have mobile phones, the Internet or other electronic devices you have likely small scale cyberattack experience with spam phone calls, emails, texts or even mailings that invade your privacy and attempt to get your money.

Water systems in at least 12 states have been involved in what appears to be a wave of cyber invasions. In Minnesota, more than 30 community water systems were victimized. In New Jersey several water utility systems experienced automated system outages. Federal authorities recently announced they suspect Iranian hackers were behind some or all the disruptions.

North Carolina doesn’t have a single statewide water grid, but instead has some 7,600 public water systems and thousands of miles of water lines managed by cities, counties and even private companies. About 80 percent of us get our water from these sources and authorities, already worried about the increased demands our rapid growth is placing on these sources, also worry about attacks poisoning some or all the feeder lakes, acquifers or river basins sourcing water to us.

But the largest biggest threat to North Carolina is our power grid. Again, growth is placing rapidly increasing the demand and we are fortunate not to have had brownouts. But cyberattacks could result in massive blackouts, wreaking havoc.

How real are these threats?

We have three major power grids in the U.S. – the Western, Eastern, and Texas interconnections. Within each there are thousands of utilities generate and distribute power, managed by 101 “balancing authorities.”

The Federal Energy Regulatory Commission conducted an analysis of what would happen if some of the substations in each of the three grids were disabled. Their study concluded that if you knocked out nine total important substations within the three grids the whole country would be blacked out.

And restoring power to them is problematic. These substations depend on large power transformers, many uniquely designed, and the wait time to get a new one, if no backup is available, is 128 weeks…almost half a year. The news gets worse: Many of those massive transformers now in service are aging and need replacing.

While there has been much national discussion about how to prevent or respond to a national electric cyberattack there is no formal plan in place.

As a side note, Siemens Energy is in the process of building a large transformer manufacturing facility in North Carolina.

But the point is made. A disruption of water, electric, transportation or other supply chains in North Carolina could affect our lives immediately and perhaps for a long period.

Let us suggest that it is past time for real leaders of North Carolina to put aside their petty political ruminations and focus instead on real issues and threats to our state. Not only do we need to assess those threats but we need solutions and plans to avoid or react to potential cyberattacks.

The clock is ticking.

Please understand my purpose in this column was not to frighten or alarm you, but to inform you of the potential problems and dangers, hoping you will urge our leaders to act.

Tom Campbell is a Hall of Fame North Carolina broadcaster and columnist who has covered North Carolina public policy issues since 1965.  Contact him at tomcamp@ncspin.com