Trump Order Aims to Block Foreign Backdoors in US Power Grid Gear

President Trump’s Executive Order 14420 has been issued, declaring a national emergency to mitigate vulnerabilities in the United States’ bulk power system arising from foreign-supplied electrical equipment. The order aims to block potential backdoors and remote access points in critical infrastructure, particularly in high-voltage transmission lines.

The rapid growth of data centers, artificial intelligence, advanced manufacturing, and defense production has created new dependencies on grid reliability, making it crucial to address the risks associated with foreign supply chain disruptions or targeted attacks. The order covers electrical equipment installed at facilities operating bulk-power system transmission lines rated at 69 kilovolts or higher, excluding local electricity distribution facilities.

The targeted technologies include transformers, inverters, energy storage systems, and industrial control systems (ICS), such as remote terminal units (RTUs) and programmable logic controllers (PLCs). The order also covers associated firmware, software, and remote access capabilities. Under the new directives, any acquisition or installation of foreign-produced bulk-power equipment initiated after August 26, 2026, is prohibited if it involves designated entities.

The restrictions apply to hardware or software deemed to pose risks of sabotage, unauthorized access, malicious remote operation, or supply disruption. The order does not name any specific country, but its structure mirrors a similar Trump-era order from 2020 that targeted entities associated with China. That prohibition was later revoked after a review by the Biden administration.

While state-sponsored actors have been linked to active intrusions targeting US power grid networks, these directives signal a shift toward mitigating upstream supply chain risks and embedded hardware backdoors. For equipment installed prior to the new executive order, the Energy Department can mandate security controls, including identifying, isolating, monitoring, securing, disconnecting, or replacing certain components.

To support ongoing grid operations, energy authorities may negotiate mitigation agreements or publish an official list of pre-qualified equipment and vendors exempt from the baseline prohibitions. This approach aims to balance security concerns with operational continuity and safety requirements.

As the global cybersecurity landscape continues to evolve, this executive order highlights the importance of supply chain risk management in critical infrastructure sectors. The directive’s focus on mitigating upstream risks underscores the need for proactive measures to address vulnerabilities before they can be exploited by malicious actors. For organizations responsible for grid operations, it is essential to familiarize themselves with the new regulations and assess their equipment’s security posture to ensure compliance and minimize potential disruptions.

In light of this development, organizations involved in critical infrastructure should prioritize supply chain risk management and embedded hardware security. This includes conducting regular vulnerability assessments, implementing robust security controls, and maintaining open communication channels with vendors and stakeholders to address any concerns or requirements related to the new executive order. By taking proactive steps to mitigate risks, organizations can help ensure the resilience of their systems and maintain public trust in critical infrastructure operations.


Source: SecurityWeek — 2026-08-27