# The Backdoor That's Already There: Trump's Grid Security Order Arrives Late to a Problem Years in the Making
The concern isn't hypothetical. Since at least 2021, U.S. intelligence agencies have tracked a Chinese state-sponsored group — known in the threat intelligence community as Volt Typhoon — methodically pre-positioning inside American critical infrastructure. Not stealing data. Not disrupting operations. Waiting. The kind of waiting that only makes sense if the goal is to have a switch to flip when the moment comes.
Against that backdrop, Executive Order 14420, signed this week, widening federal scrutiny of industrial control systems in the power grid to address cyber sabotage risks, reads less like a bold new initiative and more like Washington finally catching up to a threat the private sector has been screaming about for years.
## A Second Term Continuation, Not a New Direction
Trump's first term produced Executive Order 13920 in May 2020, which blocked certain transactions involving bulk power system equipment from foreign adversaries — primarily targeting Chinese-manufactured components for high-voltage transformers and transmission gear. That order was suspended by Biden almost immediately after taking office for review, then quietly reinstated in modified form. The Biden administration added its own layer: a 2023 Commerce Department rule tightening review of connected software in critical infrastructure.
EO 14420 builds on that architecture. The new order expands the aperture beyond bulk power equipment to industrial control systems more broadly — the SCADA platforms, programmable logic controllers, and distributed control systems that actually run generation facilities, substations, and transmission networks. The shift matters because the threat has evolved. It's no longer just about a compromised transformer sitting in a substation. It's about the software layer on top of it.
## The Inverter Problem Nobody Wants to Talk About
Here's what the executive order doesn't fix: the equipment that's already in the ground.
The U.S. grid has absorbed years of Chinese-manufactured solar inverters — the devices that convert DC power from solar panels into AC power for the grid. Estimates suggest Chinese-made inverters account for a substantial share of utility-scale solar installations across the country. These aren't passive components. Modern inverters are network-connected, remotely manageable, and embedded with firmware that rarely gets audited.
In early 2024, the Department of Energy quietly flagged the inverter supply chain as a significant vulnerability. Chinese manufacturers dominate the market for a straightforward reason: they're cheaper, often by 20-30%, than Western alternatives. Utilities operating on thin margins made rational procurement decisions that, in aggregate, created a systemic risk.
Scrutinizing new purchases doesn't touch what's already deployed. The order, from what's publicly disclosed, doesn't include a remediation mandate for existing hardware.
## What the ICS Threat Landscape Actually Looks Like
The industrial control systems securing U.S. power infrastructure were designed for reliability and longevity, not security. Many legacy PLCs and SCADA systems running substations were engineered in the 1990s, intended to last 30-40 years, with network connectivity bolted on as an afterthought. Authentication is often weak or nonexistent. Patches are applied irregularly — sometimes not at all — because taking a substation offline to update firmware carries real operational risk.
The Volt Typhoon intrusions documented by CISA and NSA weren't exploiting zero-days in cutting-edge systems. They were leveraging living-off-the-land techniques inside legacy infrastructure, using built-in tools to avoid detection. The sophistication wasn't in the malware — it was in the patience and the targeting.
That pattern has a precedent with sharper edges. In 2015 and 2016, Sandworm — Russia's GRU Unit 74455 — cut power to portions of Ukraine's grid twice. The second attack, which deployed the INDUSTROYER malware, targeted the protocol layer of substation control systems directly. It wasn't a proof of concept. It was a demonstration.
## Who Bears the Operational Burden
The scrutiny mechanism under EO 14420 flows through the Department of Energy and the Department of Homeland Security, with CISA playing its standard role in ICS guidance. Utilities will face expanded review processes for procurement involving foreign-manufactured ICS components.
For the largest investor-owned utilities, this is manageable friction — more paperwork, longer procurement timelines, higher costs passed through rate cases. For smaller municipal utilities and rural electric cooperatives, which collectively serve millions of customers and operate with far leaner compliance budgets, the burden is proportionally much heavier. These are often the least-hardened links in the grid, and the ones least equipped to absorb new regulatory overhead.
The order doesn't appear to include funding mechanisms or technical assistance for smaller operators. That's a gap.
---
## HackWire Analysis
The framing around this executive order — "blocking foreign backdoors" — implies a future-tense problem that can be addressed at the procurement gate. The actual threat is considerably messier.
Volt Typhoon's documented behavior suggests the pre-positioning campaign has been underway for years. The group favors compromising network edge devices — routers, VPNs, small-office appliances — to establish persistent, hard-to-detect footholds rather than leaving obvious malware signatures. CISA's advisory from February 2024 was explicit: the goal appears to be capability staging for disruption in the event of a major geopolitical conflict, particularly over Taiwan.
That's not a supply chain problem you solve with a procurement review board. It's an active intrusion problem that requires continuous monitoring, network segmentation between IT and OT environments, and aggressive threat hunting inside operational technology networks — capabilities most utilities aren't fully equipped to execute.
The executive order is a necessary step in the right direction on a discrete slice of the problem. But it shouldn't be mistaken for a grid security strategy. The harder conversation — what to do about the equipment already deployed, how to fund hardening for smaller operators, and what a credible deterrence posture looks like — isn't being held publicly at the pace the threat demands.
Worth watching: whether the order triggers a broader push to certify domestic ICS alternatives, or whether it primarily produces compliance theater while the underlying supply chain dependency on Chinese manufacturers remains structurally unaddressed.
— HackWire Editorial
---
## Related Coverage