Stanley Sigman and the 1996 Grid Failure Risk
By Miriam Adler ·
A 1996 risk assessment documented the fragility of the American power grid against electronic intrusion, though the specific nodes and state actors were kept out of the unclassified record.
A total blackout does not just kill the lights; it kills the ventilators in the ICU and the pumps in the city's water mains. In 1996, the people responsible for the American power grid were told that their systems were open to electronic intrusion, but they were not told exactly where the doors were unlocked.
This account is drawn from an archival description of the record, rather than the full pages of the report. The record is the "Electric Power Information Assurance Risk Assessment," dated December 1996 and produced by the President's National Security Telecommunications Advisory Committee. This committee, the body tasked with bridging the gap between White House security imperatives and the private companies that owned the wires, conducted the study to evaluate how an adversary could turn the lights off across the continent.
Control Centers and Substations
The record establishes that the assessment focused on the specific points where the physical world meets the digital one. It provided an "overview of power generation and distribution" and specifically analyzed "vulnerabilities (to control centers, substations, and communications links)" (Electric Power Information Assurance Risk Assessment, 1996). This was not a theoretical exercise in software bugs; it was a map of the physical architecture of American survival. The report looked at "the threat (both physical and electronic)," treating a bomb at a transformer and a line of code in a control center as two versions of the same catastrophe.
To mitigate these risks, the record says the study provided "protection measures" and "recommendations" (Electric Power Information Assurance Risk Assessment, 1996). But the record is a summary of a risk assessment, and a risk assessment that is marked "Unclassified" is a document designed for a specific kind of audience. It tells the reader that a problem exists without telling the reader how to exploit it. The record lists the categories of vulnerability, but it does not list the specific coordinates of the compromised nodes.
Document imagery from nsarchive.gwu.edu From the files: nsarchive.gwu.edu
Stanley Sigman
The committee that produced this assessment relied on the cooperation of the men who ran the infrastructure. Among them was Stanley T. Sigman, who led Cingular Wireless at AT&T during the explosion of mobile connectivity. Sigman brought the perspective of the nation's largest wireless provider to a table where the government was trying to figure out how to harden a grid that was increasingly reliant on the very telecommunications networks Sigman managed.
The public record places Sigman at the intersection of corporate expansion and national security. By 1996, the divide between "government systems" and "private systems" had effectively vanished. The power grid was not a government asset; it was a patchwork of private utilities. The President's National Security Telecommunications Advisory Committee existed because the White House could not simply order the grid to be secure; it had to persuade the CEOs and the engineers to spend their own capital on security measures that offered no immediate return on investment.
The April 1 Warfare Strategy
There is a chronological collision in the record that reveals the government's true priorities in 1996. Eight months before the Advisory Committee released its risk assessment for the power grid, the Air Force was polishing its own sword. On April 1, 1996, Air University—the professional military education arm of the Air Force—produced a document titled "The Need for a USAF Information Warfare Strategy for Military Operations Other than War."
While the Advisory Committee was assessing the "risk of disruption of electric power from electronic intrusion" to protect American soil, the Air Force was drafting the blueprint for how to project that same disruption abroad. The public record shows a government operating in two parallel tracks: one track of defensive advisory committees and another of offensive warfare strategies. The Air Force was studying how to disable an enemy's essential services while the Advisory Committee was gently suggesting to people like Stanley Sigman that their control centers might be vulnerable.
The Unclassified Mask
The record mentions "protection measures" and "recommendations" for the grid, but it is silent on the tools required to implement them. This gap is not an accident of the archival description; it is a reflection of a political war. In March 1997, just months after the grid assessment, the House Judiciary Subcommittee on Courts and Intellectual Property held hearings on the Security and Freedom Through Encryption (SAFE) Act. The public record shows Ira Rubinstein, a senior corporate attorney at Microsoft who represented the Business Software Alliance, and Philip Karn, a staff engineer at Qualcomm, testifying on the legalities of encryption.
The government was fighting a battle over who could hold the keys to encrypted data. If the laziest, most vulnerable parts of the power grid were to be secured, they would have required the very encryption standards that the government was attempting to restrict or backdoor via the SAFE Act. The "protection measures" mentioned in the risk assessment were likely hollowed out by this legal conflict. The government could not recommend a security standard that it was simultaneously trying to outlaw or compromise in the halls of Congress.
If this file is shaped the way it looks, the "Unclassified" status of the risk assessment served as a convenient veil. The desk's reading is that the report identified the threat in general terms to satisfy the public record of "due diligence" while withholding the identity of specific state actors in a classified annex. By reporting the vulnerabilities as general categories rather than a specific inventory of compromised nodes, the government avoided providing a roadmap for adversaries while simultaneously avoiding a public admission of how far the intrusion had already progressed.
The pattern suggests a calculated omission regarding the friction between federal security mandates and private ownership. The Advisory Committee's role as a liaison between the White House and industry leaders like Sigman ensured that the final report would not alienate the private utilities. The recommendations likely omitted the staggering cost of the necessary upgrades and the jurisdictional nightmare of forcing private companies to adhere to federal security protocols they didn't want to pay for.
The desk's reading is that the 1996 risk assessment was a performance of security, not a plan for it. The government knew exactly how the grid could be broken because they were drafting the manual for breaking grids at Air University. They withheld the specifics of the vulnerability to prevent a panic and to protect their own offensive capabilities. The real cost of this secrecy was borne by the utilities and the public, who were left with a general sense of risk but no specific roadmap for defense. A full release of the classified annexes would likely show that the "electronic intrusions" were not hypothetical threats but active probes by state actors—probes that the government chose to monitor rather than stop, treating the American power grid as a live laboratory for the coming age of cyber warfare.
Sources
- President's National Security Telecommunications Advisory Committee,Electric Power Information Assurance Risk Assessment, December 1996. Unclassified. — National Security Archive (GWU)
- Document PDF (President's National Security Telecommunications Advisory Committee,Electric Power Information Assurance Risk Assessment, December 1996. Unclassified.)
- Background: Stan Sigman — Wikipedia