Cybersecurity Policy Report, Bills to Boost Electric Grid’s Cyber Defenses Clear House, (Jun 30, 2026)

Legislation that would elevate the Department of Energy’s cybersecurity office and require it to be led by a Senate-confirmed assistant secretary was among four bills passed yesterday by the House to improve the energy sector’s cyber defenses.
The Energy Emergency Leadership Act (HR 7258), the Securing Community Upgrades for a Resilient Grid (SECURE Grid) Act (HR 7257), the Rural and Municipal Utility Cybersecurity Act (HR 7266), and the Energy Threat Analysis Center Act (HR 7305) cleared the House by voice vote.
HR 7258. The Energy Emergency Leadership Act, introduced by Rep. Laurel Lee (R., Fla.), would amend the Department of Energy Organization Act by codifying DoE’s Office of Cybersecurity, Energy Security, and Emergency Response (CESER) under the leadership of a Senate-confirmed assistant secretary.
The office, established under the first Trump administration, originally had a Senate-confirmed leader, but under the Biden administration the leadership position was downgraded to a “director,” for whom DoE didn’t seek Senate confirmation.
Rep. Lee’s bill would require the position to be Senate-confirmed and would give CESER a central role in addressing cyber and physical threats to the energy sector and “emergency planning and preparedness, coordination, response, and restoration,” according to the bill’s text.
“State-sponsored actors like Volt Typhoon are actively targeting American critical infrastructure. Physical attacks on grid infrastructure are also on the rise,” Rep. Lee said on the House floor. “HR 7258 addresses this directly. It ensures that the Department of Energy’s emergency and cybersecurity responsibilities are led by a Senate-confirmed assistant secretary, a clear, accountable leader whose role is codified in statute, not left to chance.”
HR 7257. The SECURE Grid Act, introduced by Reps. Bob Latta (R., Ohio), chairman of the House Energy and Commerce Committee’s energy subcommittee, and Doris Matsui (D., Calif.), would require states to include more granular data in the security plans they submit to the DoE to qualify for federal funds from the department’s State Energy Program.
“State energy security plans, or SESPs, provide states with an opportunity to identify threats and vulnerabilities in their respective energy networks. This collaborative process ensures that states can stay on the cutting edge of an evolving threat landscape,” Rep. Latta said on the House floor.
“While the initial exercise of SESPs has meaningfully assisted States in managing their energy systems, there is room for improvement to enhance visibility and threat detection and to holistically consider disparate vulnerabilities across the sector,” he said.
Additional information that would be included in SESPs under the bill include potential threats to local distribution facilities and the role of vendors in maintaining a secure energy distribution system.
HR 7266. The Rural and Municipal Utility Cybersecurity Act, introduced by Reps. Mariannette Miller-Meeks (R., Iowa) and Jennifer McClellan (D., Va.), would renew an expired cybersecurity grant program originally created by the 2021 Infrastructure Investment and Jobs Act. The grant program, administered by DoE, would provide $250 million through 2030 to electric cooperatives, municipal electric utilities, and small investor-owned electric utilities.
“Just this spring, national security experts warned that hostile nation-states are shifting from isolated cyber incidents to sustained campaigns against U.S. critical infrastructure, including the energy sector. Yet, many small and rural utilities lack the capacity and expertise to act on this information,” Rep. Miller-Meeks said on the House floor.
“At a time when cyber attacks on our critical infrastructure are escalating, small and rural utilities need the resources to defend against nation-state actors and sophisticated threats. This bill provides that support,” she added.
HR 7305. The Energy Threat Analysis Center Act, introduced by Rep. Kathy Castor (D., Fla.), the energy subcommittee’s ranking member, would reauthorize DoE’s Energy Sector Operational Support for Cyberresilience Program, a public-private cyber threat information-sharing center for the energy sector.
“In 2023, the Department of Energy launched the Energy Threat Analysis Center. We call it ETAC. ETAC brings together the classified intelligence community with private energy sector operational professionals in real time. It produces sector-specific threat analysis and mitigation advisories,” Rep. Castor explained on the House floor.
“80% of U.S. energy infrastructure is owned by the private sector, so we need to make sure that they are working with the federal government and our intelligence community to confront the risks,” she said.
Rep. Brett Guthrie (R., Ky.), chairman of the House Energy and Commerce Committee, celebrated the passage of the four bills, which cleared the committee in March (CPR, March 5).
“As threats to our nation’s energy infrastructure grow more frequent and more complex, it’s essential that we strengthen our grid’s security in order to keep our communities safe,” Rep. Guthrie said in a news release.
“These four bills provide critical solutions to help us meet the challenges we face,” he said. “By strengthening our security planning, ensuring the Department of Energy has the leadership necessary to confront threats, providing utilities with the tools necessary to protect the grid, and supporting increased collaboration between grid operators and the federal government, we can stay ahead of adversaries and ensure reliable, secure energy for American families and businesses.”
MainStory: TopStory FederalLegislation DataSecurity