Skip to main content
Geopolitics & DefenseNational Security

Trump Signs Order to Mitigate Foreign Cyber Risks in US Energy Infrastructure

High-voltage power transmission tower stands against blue sky with clouds, with blurred electrical equipment in foreground.

China supplies 85% of solar supply chain production capacity, according to the International Atomic Energy Agency.

The move: a national emergency to protect the bulk-power system

President Donald Trump signed an executive order that "declares a national emergency to secure the U.S. bulk-power system" and aims to bar certain foreign-produced equipment, software and systems from U.S. energy infrastructure. The order responds explicitly to "malicious cyber activities" and says it forbids "any acquisition, importation, transfer, or installation" of foreign-produced bulk-power system electric equipment if it is determined to pose a significant national security risk.

What the order says it will block

The White House fact sheet accompanying the order explains the prohibition in more detail: "The Order, among other things, generally prohibits certain foreign-produced bulk-power system electric equipment, including associated critical software and digital capabilities that could pose cybersecurity or operational risks, from being purchased or installed in the United States, or appropriately conditions such purchases and installations to address those risks." The order frames the restriction as aimed at equipment that could contain "digital backdoors" or other vulnerabilities that would allow a foreign country remote access to systems that operate the bulk-power system.

Cyber context cited by the order and intelligence testimony

The executive order ties the policy choice to cyber threats. It cites "malicious cyber activities" as an impetus for declaring the emergency and restricting equipment. The White House fact sheet warns that "minimal restrictions on acquisition or operation in the United States of foreign-produced bulk-power system electric equipment augment the ability of some foreign entities to create and exploit vulnerabilities in such equipment." The order pairs that concern with a concrete intelligence reference: in 2024, then-FBI Director Christopehr Wray told Congress that hackers prepositioning themselves in small office and home routers had the electricity grid as one of their targets should China and the United States go to war.

Regulatory lineage and the implementation timetable

The new order continues earlier Trump administration efforts to limit foreign-made bulk-power equipment. Near the end of the president's first term he signed an executive order with similar aims; the Biden administration later suspended that order and "revoked and replaced a related Energy Department order," according to the source material. Utilities experienced compliance challenges under the 2020 order, the source notes. Under the new directive, the Energy Department has 120 days to develop implementing rules, doing so "in consultation with other key departments."

What this means for technologists, utilities, and policymakers

  • Technologists and security teams: Expect rulemaking to specify what counts as a disallowed foreign-produced component, and to highlight associated critical software and digital capabilities that regulators view as risks. The order's mention of "digital backdoors" and the cited prepositioning of access in routers underscore the signal that regulators will be looking for remote-access vectors tied to equipment and firmware.
  • Utilities and procurement leaders: The source notes that "some utilities found compliance with the 2020 executive order difficult." That history — combined with the scale of foreign participation in supply chains (including China's large share of solar production and its role in transformer manufacturing) — suggests practical challenges ahead for sourcing, inventorying, and replacing covered equipment if the Energy Department's rules are strict.
  • Policymakers and regulators: The Energy Department must produce rules within 120 days and coordinate with other departments. They will need to translate the executive order's national-security language into implementable procurement and certification standards while addressing the operational realities utilities flagged under the prior order.

The executive order restates a clear policy posture: use national emergency authorities to limit acquisition and installation of foreign-produced bulk-power equipment deemed a security risk. The immediate, concrete step is now the Energy Department's 120-day rulemaking clock — a deadline that will determine how rapidly the administration turns broad national-security concerns and cited cyber-threat examples into specific controls on procurement and operation. How those rules address supply concentrations (including the IAEA-cited share of solar capacity) and the practical problems utilities previously described will shape whether the measure strengthens grid resilience or creates new operational headaches.

Source: CyberScoop