This Week in Cyber - Sept 10–16, 2026
Cyber resilience moved from policy to practice this week across energy, utilities, maritime infrastructure and local government.
Here’s what operators need to know.
DOE expands its push for energy resilience
On September 14, 2026, DOE CESER announced its latest SENTRY award recipients, funding technologies focused on energy risk quantification, ICS cybersecurity, decentralized asset security and counter-drone capabilities.
Why it matters: SENTRY adds to a much broader DOE push on energy resilience. CESER is simultaneously investing in AI-enabled defense through AI-FORTS, hardening the energy supply chain through Energy Cyber Sense and CyTRICS, and tightening bulk-power security against foreign-adversary risk. DOE is moving quickly across technology, infrastructure hardening and response readiness rather than treating cyber as a single program.
CenterPoint confirms customer data was stolen
On September 14, 2026, CenterPoint Energy disclosed that an unauthorized third party obtained personal information belonging to some customers through an external-facing system. Electric and gas delivery remained operational and undisrupted.
Why it matters: The breach comes as CenterPoint's 2026–2028 resiliency plan puts new money into IT/OT cybersecurity monitoring, network security and vulnerability management, and cloud and product security. Texas is also running a statewide Cybersecurity Monitor Program for electric utilities, while FERC and NERC continue tightening grid cybersecurity and incident-response requirements. Utilities are putting more resources behind cyber resilience as the attack surface keeps expanding.
Congress pushes further into maritime cybersecurity
On September 15, 2026, the House Transportation and Infrastructure Committee approved the MTS CYBER Act of 2026 , which would examine whether the Coast Guard has the resources, workforce and capabilities needed to carry out its maritime cybersecurity mission.
Why it matters: The MTS CYBER Act comes as the Coast Guard is already expanding its maritime cyber mission. New cybersecurity requirements for vessels and facilities are being phased in, the Coast Guard established a dedicated Office of Maritime Cybersecurity Policy on August 31, and federal teams are already investigating suspected compromises aboard operating vessels. Maritime cyber is moving from guidance into regulation, dedicated federal capacity and active response.
Massachusetts municipalities face another week of cyber disruption
On September 16, 2026, the Town of Sutton disclosed a cybersecurity incident affecting portions of its town and public-school networks. Springfield was dealing with confirmation that student and staff data had been breached following its recent cyberattack, while Everett City Hall remained closed into a second week of recovery.
Why it matters: The incidents are landing as Massachusetts expands a broader municipal cyber push. The state is already funding Cybersecurity Health Checks, a new $1 million remediation grant program, and a 60-day pilot giving towns and schools access to EDR, MDR and continuous vulnerability scanning. Sutton itself received $42,840 in remediation funding this year. The state is putting more resources into assessment, remediation and monitoring, while incidents in Sutton, Springfield and Everett show how quickly local governments are still getting tested.
Also worth watching: suspected cyberattack aboard oil tanker
On September 15, 2026, Reuters reported that the Coast Guard and FBI had boarded a Texas-bound oil tanker to investigate a suspected cyberattack on its onboard network. The boarding occurred on August 21, but the investigation became public this week.
The disclosure came the same day Congress advanced the MTS CYBER Act, putting a real-world incident next to the broader federal push to expand maritime cybersecurity capability.
That’s it for this week.
We’ll be back next Thursday with the next Weekly Roundup.