Blog
/
/
November 22, 2023

70 million in Cybersecurity Funding for Electric Cooperatives & Utilities

Default blog imageDefault blog imageDefault blog imageDefault blog imageDefault blog imageDefault blog image
22
Nov 2023
Discover how the Bipartisan Infrastructure Law and its $250M Rural and Municipal Utility Cybersecurity Program empower electric cooperatives and municipalities to strengthen cybersecurity. Learn how innovative tools like anomaly detection, IT/OT integration, and AI-driven solutions enhance resilience against modern threats.

What is the Bipartisan Infrastructure Deal?

The Bipartisan Infrastructure Law passed by congress in 2021 aimed to upgrade power and infrastructure to deliver clean, reliable energy across the US to achieve zero-emissions. To date, the largest investment in clean energy, the deal will fund new programs to support the development and deployment of clean energy technology.

Why is it relevant to electric municipalities?

Section 40124 of the Bipartisan Infrastructure Law allocates $250 million over a 5-year period to create the Rural and Municipal Utility Cybersecurity (RMUC) Program to help electric cooperative, municipal, and small investor-owned utilities protect against, detect, respond to, and recover from cybersecurity threats.1 This act illuminates the value behind a full life-cycle approach to cyber security. Thus, finding a cyber security solution that can provide all aspects of security in one integrated platform would enhance the overall security posture and ease many of the challenges that arise with adopting multiple point solutions.

On November 16, 2023 the Office of Cybersecurity, Energy Security, and Emergency Response (CESER) released the Advanced Cybersecurity Technology (ACT) for electric utilities offering a $70 million funding opportunity that aims to enhance the cybersecurity posture of electric cooperative, municipal, and small investor-owned utilities.

Funding Details

10 projects will be funded with application submissions due November 29, 2023, 5:00 pm ET with $200,000 each in cash prizes in the following areas:

  1. Direct support for eligible utilities to make investments in cybersecurity technologies, tools, training, and improvements in utility processes and procedures;
  2. Funding to strengthen the peer-to-peer and not-for-profit cybersecurity technical assistance ecosystem currently serving eligible electric utilities; and
  3. Increasing access to cybersecurity technical assistance and training for eligible utilities with limited cybersecurity resources. 2

To submit for this award visit: https://www.herox.com/ACT1Prize

How can electric municipalities utilize the funding?

While the adoption of hybrid working patterns increase cloud and SaaS usage, the number of industrial IoT devices also continues to rise. The result is decrease in visibility for security teams and new entry points for attackers. Particularly for energy and utility organizations.

Electric cooperatives seeking to enhance their cyber security posture can aim to invest in cyber security tools that provide the following:

Compliance support: Consider finding an OT security solution that maps out how its solutions and features help your organization comply with relevant compliance mandates such as NIST, ISA, FERC, TSA, HIPAA, CIS Controls, and more.

Anomaly based detection: Siloed security solutions also fail to detect attacks that span
the entire organization. Anomaly-based detection enhances an organization’s cyber security posture by proactively defending against potential attacks and maintaining a comprehensive view of their attack surface.

Integration capabilities: Implementation of several point solutions that complete individual tasks runs the risk of increasing workloads for operators and creates additional challenges with compliance, budgeting, and technical support. Look for cyber security tools that integrate with your existing technologies.

Passive and active asset tracking: Active Identification offers accurate enumeration, real time updates, vulnerability assessment, asset validation while Passive Identification eliminates the risk of operational disruption, minimizes risk, does not generate additional network traffic. It would be ideal to find a security solution that can do both.

Can secure both IT and OT in unison: Given that most OT cyber-attacks actually start in IT networks before pivoting into OT, a mature security posture for critical infrastructure would include a single solution for both IT and OT. Separate solutions for IT and OT present challenges when defending network boundaries and detecting incidents when an attacker pivots from IT to OT. These independent solutions also significantly increase operator workload and materially diminish risk mitigation efforts.

Darktrace / OT for Electric Cooperatives and Utilities

For smaller teams with just one or two dedicated employees, Darktrace’s Cyber AI Analyst and Investigation features allow end users to spend less time in the platform as it compiles critical incidents into comprehensive actionable event reports. AI Analyst brings all the information into a centralized view with incident reporting in natural language summaries and can be generated for compliance reports specific to regulatory requirements.  

For larger teams, Darktrace alerts can be forwarded to 3rd party platforms such as a SIEM, where security team decision making is augmented. Additionally, executive reports and autonomous response reduce the alert fatigue generally associated with legacy tools. Most importantly, Darktrace’s unique understanding of normal allows security teams to detect zero-days and signatureless attacks regardless of the size of the organization and how alerts are consumed.

Key Benefits of Darktrace / OT

Figure 1: Darktrace/OT stops threats moving from IT to OT by providing a unified view across both systems

References

1. https://www.whitehouse.gov/briefing-room/statements-releases/2021/11/06/fact-sheet-the-bipartisan-infrastructure-deal/

2. https://www.energy.gov/ceser/rural-and-municipal-utility-advanced-cybersecurity-grant-and-technical-assistance-rmuc

Inside the SOC
Darktrace cyber analysts are world-class experts in threat intelligence, threat hunting and incident response, and provide 24/7 SOC support to thousands of Darktrace customers around the globe. Inside the SOC is exclusively authored by these experts, providing analysis of cyber incidents and threat trends, based on real-world experience in the field.
Author
Jeff Cornelius
EVP, Cyber-Physical Security

Jeff Cornelius joined Darktrace in February of 2015 as Executive Vice President and oversees Darktrace’s Cyber-Physical Security solutions while serving as a subject matter expert around Darktrace’s solutions for OT/ICS environments. Jeff has been the featured/keynote speaker at numerous international events and conferences and regularly shares insights at global events. Prior to joining, Darktrace, Jeff held a several C-level and Executive Commercial positions delivering subject matter expertise in the security, compliance and governance sectors. Jeff holds advanced degrees in Experimental Psychology (Social, Cognition, Perception) and Experimental Statistics and previously taught at the University of Texas and New Mexico State University where he held adjunct positions.

Book a 1-1 meeting with one of our experts
Share this article

More in this series

No items found.

Blog

/

Cloud

/

April 2, 2025

Fusing Vulnerability and Threat Data: Enhancing the Depth of Attack Analysis

Default blog imageDefault blog image

Cado Security, recently acquired by Darktrace, is excited to announce a significant enhancement to its data collection capabilities, with the addition of a vulnerability discovery feature for Linux-based cloud resources. According to Darktrace’s Annual Threat Report 2024, the most significant campaigns observed in 2024 involved the ongoing exploitation of significant vulnerabilities in internet-facing systems. Cado’s new vulnerability discovery capability further deepens its ability to provide extensive context to security teams, enabling them to make informed decisions about threats, faster than ever.

Deep context to accelerate understanding and remediation

Context is critical when understanding the circumstances surrounding a threat. It can also take many forms – alert data, telemetry, file content, business context (for example asset criticality, core function of the resource), and risk context, such as open vulnerabilities.

When performing an investigation, it is common practice to understand the risk profile of the resource impacted, specifically determining open vulnerabilities and how they may relate to the threat. For example, if an analyst is triaging an alert related to an internet-facing Webserver running Apache, it would greatly benefit the analyst to understand open vulnerabilities in the Apache version that is running, if any of them are exploitable, whether a fix is available, etc. This dataset also serves as an invaluable source when developing a remediation plan, identifying specific vulnerabilities to be prioritised for patching.

Data acquisition in Cado

Cado is the only platform with the ability to perform full forensic captures as well as utilize instant triage collection methods, which is why fusing host-based artifact data with vulnerability data is such an exciting and compelling development.

The vulnerability discovery feature can be run as part of an acquisition – full or triage – as well as independently using a fast ‘Scan only’ mode.

Figure 1: A fast vulnerability scan being performed on the acquired evidence

Once the acquisition has completed, the user will have access to a ‘Vulnerabilities’ table within their investigation, where they are able to view and filter open vulnerabilities (by Severity, CVE ID, Resource, and other properties), as well as pivot to the full Event Timeline. In the Event Timeline, the user will be able to identify whether there is any malicious, suspicious or other interesting activity surrounding the vulnerable package, given the unified timeline presents a complete chronological dataset of all evidence and context collected.

Figure 2: Vulnerabilities discovered on the acquired evidence
Figure 3: Pivot from the Vulnerabilities table to the Event Timeline provides an in-depth view of file and process data associated with the vulnerable package selected. In this example, Apache2.

Future work

In the coming months, we’ll be releasing initial versions of highly anticipated integrations between Cado and Darktrace, including the ability to ingest Darktrace / CLOUD alerts which will automatically trigger a forensic capture (as well as a vulnerability discovery) of the impacted assets.

To learn more about how Cado and Darktrace will combine forces, request a demo today.

Continue reading
About the author
Paul Bottomley
Director of Product Management, Cado

Blog

/

OT

/

March 28, 2025

Darktrace Recognized as the Only Visionary in the 2025 Gartner® Magic Quadrant™ for CPS Protection Platforms

Default blog imageDefault blog image

We are thrilled to announce that Darktrace has been named the only Visionary in the inaugural Gartner® Magic Quadrant™ for Cyber-Physical Systems (CPS) Protection Platforms. We feel This recognition highlights Darktrace’s AI-driven approach to securing industrial environments, where conventional security solutions struggle to keep pace with increasing cyber threats.

A milestone for CPS security

It's our opinion that the first-ever Gartner Magic Quadrant for CPS Protection Platforms reflects a growing industry shift toward purpose-built security solutions for critical infrastructure. As organizations integrate IT, OT, and cloud-connected systems, the cyber risk landscape continues to expand. Gartner evaluated 17 vendors based on their Ability to Execute and Completeness of Vision, establishing a benchmark for security leaders looking to enhance cyber resilience in industrial environments.

We believe the Gartner recognition of Darktrace as the only Visionary reaffirms the platform’s ability to proactively defend against cyber risks through AI-driven anomaly detection, autonomous response, and risk-based security strategies. With increasingly sophisticated attacks targeting industrial control systems, organizations need a solution that continuously evolves to defend against both known and unknown threats.

AI-driven security for CPS environments

Securing CPS environments requires an approach that adapts to the dynamic nature of industrial operations. Traditional security tools rely on static signatures and predefined rules, leaving gaps in protection against novel and sophisticated threats. Darktrace / OT takes a different approach, leveraging Self-Learning AI to detect and neutralize threats in real time, even in air-gapped or highly regulated environments.

Darktrace / OT continuously analyzes network behaviors to establish a deep understanding of what is “normal” for each industrial environment. This enables it to autonomously identify deviations that signal potential cyber threats, providing early warning and proactive defense before attacks can disrupt operations. Unlike rule-based security models that require constant manual updates, Darktrace / OT improves with the environment, ensuring long-term resilience against emerging cyber risks.

Bridging the IT-OT security gap

A major challenge for organizations protecting CPS environments is the disconnect between IT and OT security. While IT security has traditionally focused on data

protection and compliance, OT security is driven by operational uptime and safety, leading to siloed security programs that leave critical gaps in visibility and response.

Darktrace / OT eliminates these silos by providing unified visibility across IT, OT, and IoT assets, ensuring that security teams have a complete picture of their attack surface. Its AI-driven approach enables cross-domain threat detection, recognizing risks that move laterally between IT and OT environments. By seamlessly integrating with existing security architectures, Darktrace / OT helps organizations close security gaps without disrupting industrial processes.

Proactive OT risk management and resilience

Beyond detection and response, Darktrace / OT strengthens organizations’ ability to manage cyber risk proactively. By mapping vulnerabilities to real-world attack paths, it prioritizes remediation actions based on actual exploitability and business impact, rather than relying on isolated CVE scores. This risk-based approach enables security teams to focus resources where they matter most, reducing overall exposure to cyber threats.

With autonomous threat response capabilities, Darktrace / OT not only identifies risks but also contains them in real time, preventing attackers from escalating intrusions. Whether mitigating ransomware, insider threats, or sophisticated nation-state attacks, Darktrace / OT ensures that industrial environments remain secure, operational, and resilient, no matter how threats evolve.

AI-powered incident response and SOC automation

Security teams are facing an overwhelming volume of alerts, making it difficult to prioritize threats and respond effectively. Darktrace / OT’s Cyber AI Analyst acts as a force multiplier for security teams by automating threat investigation, alert triage, and response actions. By mimicking the workflow of a human SOC analyst, Cyber AI Analyst provides contextual insights that accelerate incident response and reduce the manual workload on security teams.

With 24/7 autonomous monitoring, Darktrace / OT ensures that threats are continuously detected and investigated in real time. Whether facing ransomware, insider threats, or sophisticated nation-state attacks, organizations can rely on AI-driven security to contain threats before they disrupt operations.

Trusted by customers: Darktrace / OT recognized in Gartner Peer Insights

Source: Gartner Peer Insights (Oct 28th)

Beyond our recognition in the Gartner Magic Quadrant, we feel Darktrace / OT is one of the highest-rated CPS security solutions on Gartner Peer Insights, reflecting strong customer trust and validation. With a 4.9/5 overall rating and the highest "Willingness to Recommend" score among CPS vendors, organizations across critical infrastructure and industrial sectors recognize the impact of our AI-driven security approach. Source: Gartner Peer Insights (Oct 28th)

This strong customer endorsement underscores why leading enterprises trust Darktrace / OT to secure their CPS environments today and in the future.

Redefining the future of CPS security

It's our view that Darktrace’s recognition as the only Visionary in the Gartner Magic Quadrant for CPS Protection Platforms validates its leadership in next-generation industrial security. As cyber threats targeting critical infrastructure continue to rise, organizations must adopt AI-driven security solutions that can adapt, respond, and mitigate risks in real time.

We believe this recognition reinforces our commitment to innovation and our mission to secure the world’s most essential systems. This recognition reinforces our commitment to innovation and our mission to secure the world’s most essential systems.

® Download the full Gartner Magic Quadrant for CPS Protection Platforms

® Request a demo to see Darktrace OT in action.

Gartner, Magic Quadrant for CPS Protection Platforms , Katell Thielemann, Wam Voster, Ruggero Contu 12 February 2025

Gartner does not endorse any vendor, product or service depicted in its research publications and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner research publications consist of the opinions of Gartner’s research organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose.

GARTNER is a registered trademark and service mark of Gartner and Magic Quadrant and Peer Insights are a registered trademark, of Gartner, Inc. and/or its affiliates in the U.S. and internationally and are used herein with permission. All rights reserved. Gartner Peer Insights content consists of the opinions of individual end users based on their own experiences with the vendors listed on the platform, should not be construed as statements of fact, nor do they represent the views of Gartner or its affiliates. Gartner does not endorse any vendor, product or service depicted in this content nor makes any warranties, expressed or implied, with respect to this content, about its accuracy or completeness, including any warranties of merchantability or fitness for a particular purpose.

Continue reading
About the author
Pallavi Singh
Product Marketing Manager, OT Security & Compliance
Your data. Our AI.
Elevate your network security with Darktrace AI