Building a secure resilient nationwide EV charging network
Harry Krejsa, Sarah Hipel
DEF CON 32 Creator Stage · Day 1 · Creator Stage
Overview
This talk, delivered by Harry Krejsa from the White House Office of the National Cyber Director (ONCD) and Sarah Hipel from the Joint Office of Energy and Transportation, addresses the critical intersection of the nation's ambitious clean energy transition and its inherent cybersecurity challenges. The speakers highlight how the rapid deployment of clean energy technologies, particularly in the electric vehicle (EV) charging sector, is fundamentally transforming the digital ecosystem and creating new attack surfaces that demand proactive, integrated security measures. Their presentation underscores the government's commitment to building a secure, resilient, and equitable clean energy future, recognizing that decarbonization is digitization and that new energy systems are inherently more cyber-sophisticated and interconnected than their fossil-fuel predecessors.

Key moments
- 0:00 Introduction to clean energy transition and digital ecosystem vision
- 1:10 Clean energy technologies are cyber-sophisticated; decarbonization is digitization
- 2:20 New stakeholders and rapid deployment create unique challenges
- 3:40 Once-in-a-generation opportunity to modernize critical infrastructure
- 5:05 Joint Office of Energy and Transportation mission for EV infrastructure
- 6:05 Interdependencies and complexity of the EV charging ecosystem
- 6:50 Government's approach to EV security, interoperability, and reliability
- 7:35 Addressing unique challenges and improving EV charging reliability
Building a secure resilient nationwide EV charging network
Speakers: Harry Krejsa, Office of the National Cyber Director; Sarah Hipel, Joint Office of Energy and Transportation
Conference: DEF CON 32
YouTube: https://www.youtube.com/watch?v=UmBNgn_9-zY
Overview
This talk, delivered by Harry Krejsa from the White House Office of the National Cyber Director (ONCD) and Sarah Hipel from the Joint Office of Energy and Transportation, addresses the critical intersection of the nation's ambitious clean energy transition and its inherent cybersecurity challenges. The speakers highlight how the rapid deployment of clean energy technologies, particularly in the electric vehicle (EV) charging sector, is fundamentally transforming the digital ecosystem and creating new attack surfaces that demand proactive, integrated security measures. Their presentation underscores the government's commitment to building a secure, resilient, and equitable clean energy future, recognizing that decarbonization is digitization and that new energy systems are inherently more cyber-sophisticated and interconnected than their fossil-fuel predecessors.
The core message of the talk revolves around the idea that the EV charging network serves as a crucial microcosm and learning ground for the broader clean energy transition. It presents a "once in a generation opportunity" to embed security and resilience into the very foundations of critical infrastructure, rather than retrofitting it later. The speakers emphasize the need for collaboration between government, industry, and the hacking community to identify vulnerabilities, develop robust standards, and ensure the long-term reliability and security of these vital systems. This proactive approach is deemed essential not only for national security but also for realizing the full potential of a future powered by clean, abundant energy.
Background
▶ Watch: Introduction to clean energy transition and digital ecosystem vision (0:00)
The United States is currently undergoing a period of unprecedented investment in its infrastructure and advanced manufacturing capabilities, largely spurred by legislative initiatives such as the Bipartisan Infrastructure Law, the Inflation Reduction Act, and the CHIPS and Science Acts. These generational investments are driving a rapid deployment of clean energy technologies, bringing with them a paradigm shift: decarbonization is digitization. Unlike traditional fossil-based energy systems, clean energy technologies are inherently more cyber-sophisticated, deeply interconnected, and involve significantly more complex supply chains. This transformation introduces a new array of cybersecurity challenges that must be addressed concurrently with deployment.
A significant hurdle in this transition stems from the nature of the clean energy ecosystem itself. It features a multitude of new stakeholders and entrants, including smaller, dynamic organizations that, while innovative, often lack the decades of experience in threat modeling, regulatory navigation, and inter-organizational relationships that characterize traditional infrastructure sectors. These established sectors are accustomed to dealing with threats from state actors and criminals and have well-developed public-private partnerships and regulatory frameworks. The nascent clean energy sector, however, is developing at a pace that often outstrips traditional government and industry standards-building processes, creating potential gaps in security posture.
Furthermore, the nation is experiencing a broad wave of physical-digital convergence across all critical infrastructure. Many components of existing infrastructure, which historically benefited from an "accidental air gap," are now being connected to the internet, necessitating a modernization of their technology and a fundamental rethinking of their cybersecurity. The transportation sector, specifically, is a primary focus for decarbonization, as it is the leading source of greenhouse gas emissions, with light duty vehicles and medium and heavy duty vehicles being major contributors. The federal government, through departments like Energy and Transportation and the White House, is "fundamentally and valuationally committed" to eliminating these emissions, driving the rapid adoption and infrastructure build-out for electric vehicles.
The Joint Office of Energy and Transportation was established as a direct outcome of the Bipartisan Infrastructure Law to serve as the technical lead for this infrastructure build-out. Described as a "startup of government," the Joint Office aims to operate with greater nimbleness and dynamism than traditional government entities, focusing on ensuring EV charging infrastructure is affordable, reliable, convenient, equitable, and safe. Sarah Hipel, as the Lead of Engineering for Standards, Reliability, and Cybersecurity, highlights the office's mission to be the "center of gravity" for cyber-physical security around charging infrastructure and to foster a web of interconnectedness among diverse stakeholders. This includes auto manufacturers, EV charging station manufacturers, network operators, application developers, security operational security providers, and the utility grid, all operating within a complex "layer cake" of city, state, municipal, tribal, and federal government oversight. The rapid expansion and inherent complexity of this new ecosystem underscore the urgent need for a cohesive and robust cybersecurity strategy from the ground up.
Key Findings
▶ Watch: New stakeholders and rapid deployment create unique challenges (2:20)
The talk elucidates several key findings regarding the secure development of the nationwide EV charging network and its implications for the broader clean energy transition. Foremost among these is the recognition that the shift to clean energy is inextricably linked to digital transformation, where decarbonization is digitization. This means that future energy systems will be characterized by capabilities such as near zero marginal cost electricity, software-defined grid management, and the proliferation of virtual power plants, offering a more resilient and flexible future. However, this advanced functionality comes with a commensurate increase in cyber complexity and potential attack surface.
A critical observation is the inherent tension between the rapid pace of clean energy deployment and the slower, more traditional mechanisms for regulatory oversight, standards development, and industry collaboration. The influx of new stakeholders, many without the deep, decades-long experience in cybersecurity and critical infrastructure operations common in legacy sectors, creates a dynamic environment ripe for innovation but also for systemic vulnerabilities if not properly managed. This highlights a fundamental need for agile, adaptive approaches to security that can keep pace with technological advancement.
The EV ecosystem itself is identified as a prime example of these dynamics, serving as a critical proving ground for the larger clean energy transition. Its multiplicity of interdependencies—spanning vehicle manufacturers, charging station producers, network operators, software developers, and the utility grid—mirrors the complexity expected across the entire future energy landscape. The government's role, particularly through the Joint Office of Energy and Transportation, is to act as a "center of gravity" for cyber-physical security, driving interoperability, reliability, and crucially, security by design across this fragmented landscape. The ambitious goal of achieving 97% uptime for EV charging infrastructure, mandated by law, underscores the reliability challenge, which is deeply intertwined with cybersecurity.
In response to these challenges and opportunities, the Biden-Harris Administration has announced five linchpin technologies critical for the success of the clean energy transition, many of which are directly relevant to EVs and EV charging: batteries and battery management systems, inverter controls, distributed control systems (like virtual power plants), building management systems, and EVs and EV supply security. The concentration of EV-related technologies within this list highlights the strategic importance of securing this sector. The speakers explicitly call upon the Defcon community to scrutinize these technologies, particularly their underlying open source software stacks, to uncover and address vulnerabilities proactively, thereby mitigating systemic risk before it becomes entrenched.
Technical Deep Dive
▶ Watch: Joint Office of Energy and Transportation mission for EV infrastructure (5:05)
The technical foundation of the secure EV charging network, as outlined by the speakers, is characterized by its inherent complexity, extensive interdependencies, and reliance on increasingly sophisticated digital systems. The EV charging ecosystem is not a monolithic entity but a layered architecture involving multiple distinct components and actors. At the core are the auto manufacturers producing the electric vehicles, which integrate deeply with the charging infrastructure. This infrastructure itself comprises EV charging station manufacturers, who design and build the physical charging units, and network operators who manage the aggregated charging stations, often through cloud-based platforms. These platforms are further enhanced by application developers creating user-facing interfaces and backend services. Overarching these operational layers is the crucial element of security operational security, encompassing the practices and technologies deployed to protect the entire system. Finally, the entire ecosystem is inextricably linked to the utility grid, which supplies the power and must manage demand fluctuations introduced by widespread EV adoption.
The talk highlights the "multiplicity of interdependencies" within this ecosystem. For instance, a single charging session involves communication between the vehicle's battery management system, the charging station's internal controls, the network operator's software, and potentially the utility grid for smart charging or demand response. This intricate web of interactions necessitates robust protocols and secure communication channels to prevent unauthorized access, data manipulation, or service disruption. The mention of distributed control systems, such as virtual power plants, is particularly significant. These systems aggregate distributed energy resources, including EV charging loads and vehicle-to-grid (V2G) capabilities, to provide services to the grid. Their software-defined nature, while offering flexibility and efficiency, also introduces complex attack surfaces, as compromise could lead to grid instability or widespread service outages.
The government's strategic focus on five linchpin technologies underscores specific technical areas requiring heightened security attention. Batteries and battery management systems are critical due to their role in vehicle performance, safety, and longevity. Compromise here could lead to vehicle malfunction, safety hazards, or even grid instability if V2G capabilities are exploited. Inverter controls are essential for converting DC power from batteries or solar panels to AC power for the grid, and vice-versa for charging. Secure inverter controls are vital for grid stability, power quality, and preventing malicious injection of false data or disruptive power signals. Distributed control systems and building management systems represent the intelligent infrastructure that manages energy flow, demand, and environmental conditions across various scales, from individual buildings to regional grids. Securing these systems is paramount to preventing coordinated attacks that could impact energy availability or critical services. Finally, EVs and EV supply security encompasses the entire lifecycle of the vehicle and its charging infrastructure, from manufacturing integrity to ongoing operational security.
A key technical vulnerability identified is the reliance on open source software stacks that underpin many of these technologies. While open-source software offers benefits in terms of transparency and collaborative development, it also requires diligent security auditing and contribution from a broad community to identify and patch vulnerabilities effectively. The rapid pace of deployment means that many of these components may not have undergone the rigorous security scrutiny typically associated with critical infrastructure, creating a fertile ground for exploitation. The call to the Defcon community to "tear these things apart" directly targets this technical challenge, aiming to leverage collective expertise to harden these foundational software components and systems against evolving threats.
Demo / Proof of Concept
▶ Watch: Interdependencies and complexity of the EV charging ecosystem (6:05)
The talk focused on policy, strategy, and a call to action regarding the cybersecurity of the EV charging network and broader clean energy infrastructure. As such, the speakers did not present any specific technical demonstrations or proofs of concept during their presentation. Their emphasis was on outlining the problem space, the government's initiatives, and the critical need for external community engagement to identify and mitigate vulnerabilities.
Defensive Implications
▶ Watch: Addressing unique challenges and improving EV charging reliability (7:35)
The insights presented by Harry Krejsa and Sarah Hipel carry significant defensive implications for cybersecurity professionals, critical infrastructure operators, and policy makers. The core message is that the nation is facing a "once in a generation opportunity" to embed security from the ground up in its evolving energy infrastructure, rather than applying it as an afterthought.
First, defenders must recognize that decarbonization is digitization. This means that traditional operational technology (OT) security paradigms, often reliant on air gaps, are rapidly becoming obsolete. New clean energy systems, including EV charging, are inherently interconnected, internet-facing, and software-defined. This necessitates a shift towards comprehensive, converged IT/OT security strategies that account for the unique characteristics of industrial control systems, real-time operations, and safety-critical functions.
Second, the call to action for the Defcon community to "tear these things apart" highlights the urgent need for proactive vulnerability research and penetration testing across the clean energy ecosystem. Defenders should actively engage with ethical hackers and security researchers to identify weaknesses in EVs and EV supply security, EV charging ecosystem components, and the five linchpin technologies: batteries and battery management systems, inverter controls, distributed control systems (like virtual power plants), and building management systems. Particular emphasis should be placed on scrutinizing the open source software stacks that form the backbone of these systems, as these often receive less dedicated security auditing compared to proprietary solutions.
Third, operators of EV charging infrastructure and other clean energy assets must prioritize security by design. This principle should guide every stage of development, from procurement and manufacturing to deployment and operation. This includes implementing robust authentication and authorization mechanisms, secure communication protocols (e.g., strong encryption for data in transit and at rest), secure boot processes, and regular software/firmware updates. Given the target of 97% uptime for EV chargers, resilience and incident response capabilities are equally critical. Defenders must develop comprehensive playbooks for detecting, responding to, and recovering from cyberattacks that could impact service availability or safety.
Fourth, the challenges posed by new stakeholders lacking traditional infrastructure experience mean that robust security guidance, standards, and training are vital. Defenders, especially those within government and established critical infrastructure sectors, have a responsibility to share knowledge and best practices. This includes developing clear, actionable security requirements for new entrants and fostering stakeholder groups that facilitate information sharing and coordinated defensive efforts. The need for more "nimble" standards and guidance processes implies a move away from slow, bureaucratic cycles towards adaptive frameworks that can quickly address emerging threats and technologies.
Finally, the broader implication of physical-digital convergence means that defenders must prepare for a future where virtually all critical infrastructure, previously considered air-gapped, will have some form of digital connectivity. Lessons learned from securing the EV charging network—regarding supply chain integrity, software assurance, and the management of interconnected systems—will be directly applicable to other sectors undergoing similar transformations. Proactive engagement with research, anticipating future technological developments, and continuously mitigating systemic risk are paramount to building a truly secure and resilient national infrastructure.
Key Takeaways
- Decarbonization is Digitization: The transition to clean energy inherently involves advanced digital technologies, creating a more interconnected and cyber-sophisticated infrastructure that introduces new and complex attack surfaces.
- EV Charging as a Critical Testbed: The rapid deployment and inherent complexity of the EV charging network serve as a vital proving ground for addressing cybersecurity challenges that will apply across the broader clean energy ecosystem.
- Government's Proactive Security Stance: The U.S. government, through entities like the ONCD and the Joint Office of Energy and Transportation, is actively working to embed "security by design" and establish the necessary frameworks for cyber-physical security in this nascent sector.
- Focus on Linchpin Technologies and Open Source: Specific attention is being directed towards securing five critical technology areas—batteries and battery management systems, inverter controls, distributed control systems, building management systems, and EVs and EV supply security—with a particular emphasis on auditing underlying open source software stacks.
- Call for Community Collaboration: The Defcon community and ethical hackers are explicitly invited and encouraged to engage in vulnerability research and penetration testing to identify and help mitigate systemic risks in clean energy infrastructure.
- Urgency for Agile Security Development: The rapid pace of clean energy deployment necessitates agile approaches to standards development, stakeholder collaboration, and vulnerability mitigation to keep pace with technological advancements and prevent the entrenchment of insecure practices.
About the Speaker(s)
Harry Krejsa is affiliated with the White House Office of the National Cyber Director (ONCD). In this role, he is involved in shaping national cybersecurity strategy and policy, particularly as it pertains to critical infrastructure and emerging technologies like clean energy. His participation highlights the strategic importance the White House places on securing the digital underpinnings of the nation's infrastructure transformation.
Sarah Hipel serves as the Lead of Engineering for Standards, Reliability, and Cybersecurity at the Joint Office of Energy and Transportation. She brings a background from the private sector, including experience with startups, to her government role. Her responsibilities involve spearheading efforts to ensure the EV charging infrastructure is not only reliable (aiming for 97% uptime) and interoperable but also fundamentally secure by design. She emphasizes bringing private sector principles and expertise into federal government initiatives, drawing talent from both industry and National Labs to address complex challenges in cyber-physical security.