This Week in Cyber: September 24 - 30, 2026
Federal grid funding moved into deployment, DOE opened another commercialization program, regulators revisited overlapping cyber requirements, water utilities trained for attacks, and GAO found major gaps in federal OT inventories.
DOE Moves $5.25 Billion in Grid Upgrades Into 31 Projects
On September 24, the Department of Energy announced 31 grid modernization projects across 26 states through its SPARK program.
The projects combine $1.9 billion in federal funding with $3.35 billion in recipient funding. Plans include more than 1,500 miles of rebuilt or reconductored transmission and grid-enhancing technologies across nearly 21,000 miles.
Why it matters: DOE opened SPARK in March. This announcement turns that funding into $5.25 billion in planned grid investment. It also follows DOE's push for Cyber-Informed Engineering, putting cybersecurity into the design of new energy infrastructure instead of adding it later.
DOE Opens $41 Million Commercialization Call With CESER and the Office of Electricity
Also on September 24, DOE opened a new $41 million Technology Commercialization Fund lab call.
CESER and the Office of Electricity are among five participating DOE offices. Companies and universities can join the teaming-partner list to work with National Laboratories pursuing projects under the program.
Why it matters: DOE has spent September opening new paths for energy security technology. SENTRY is funding work in ICS cybersecurity, cyber risk and distributed energy. AI-FORTS is focused on AI for OT visibility, detection and response. This program adds another route to move federally developed technology into commercial use.
Critical Infrastructure Operators Tell GAO Federal Cyber Reporting Requirements Still Conflict
On September 28, GAO released new findings on overlapping federal cybersecurity requirements across critical infrastructure.
Energy, financial services and healthcare representatives reported conflicting requirements around incident reporting timelines, thresholds and required information.
Why it matters: GAO identified 117 federal cybersecurity regulations in July. Eighty contained reporting requirements that could overlap with another rule. The September findings show what that means during an incident: operators can face different reporting clocks and requirements while they are still investigating and restoring systems.
Alabama Water Utilities Run Cyberattack Exercise as $19 Million Reaches Local Systems
On September 29, more than 100 people from 40 Alabama water utilities took part in a two-day cyberattack exercise focused on water infrastructure.
Alabama also has roughly $19 million in federal State and Local Cybersecurity Grant Program funding available. Public water and wastewater systems are eligible for services including monitoring and recovery support.
Why it matters: In July, attackers compromised remote monitoring and control equipment at more than 30 Minnesota water systems. Now federal cyber funding is reaching local utilities for monitoring, exercises and response. The Minnesota attacks are already changing how states prepare water systems for the next incident.
GAO Finds Most Federal Agencies Still Haven't Met OT and IoT Inventory Requirements
On September 30, GAO reported that only seven of 22 civilian agencies had fully met federal OT and IoT inventory requirements.
The first inventories were due in September 2024. Two years later, seven agencies still had not established one.
Why it matters: GAO points directly to the July Minnesota water attacks, where attackers reached technology used to remotely monitor and control physical equipment. Two years after the federal deadline, most agencies reviewed still can't fully account for their connected OT and IoT assets.
That's it for this week!
We'll be back next Thursday with the developments shaping critical infrastructure cybersecurity, operations and resilience.