Notice: You are viewing a detailed profile of an entity in our US Agency Mapping resource, in which we have compiled all information relevant for the regulation of advanced AI technologies in the US. To see an overview of all entities, return to the entity overview page.
Index
Department of Commerce (DoC)
International Trade Administration (ITA)
US Patent and Trade Administration (USPTO)
Bureau of Industry and Security (BIS)
National Institute of Standards and Technology (NIST)
US AI Safety Institute (USAISI)
National Telecommunication and Information Administration (NTIA)
Department of Energy (DoE)
Office of Cybersecurity, Energy Security, and Emergency Response (CESER)
Advanced Scientific Computing Research (ASCR)
Office of Critical and Emerging Technology (OCET)
Department of Homeland Security (DoHS)
Cybersecurity and & Infrastructure Security Agency (CISA)
Office of Cyber, Infrastructure, Risk, and Resilience (CIRR)
Department of Energy (DoE)
Office of Cybersecurity, Energy Security, and Emergency Response (CESER)
The Office of Cybersecurity, Energy Security, and Emergency Response (CESER) strengthens the security and resilience of U.S. energy infrastructure. It focuses on mitigating cybersecurity, physical, supply chain, and climate-based threats, while assisting with response and restoration. CESER leads national efforts to enhance the preparedness, resiliency, and recovery of U.S. energy systems.
Puesh M. Kumar - Director, Office of Cybersecurity, Energy Security, and Emergency Response
Roles and Authority
Authority Type | Name | Description |
---|---|---|
Presidential Policy Directives | PPD-8 | Strengthens security and resilience through preparation for high-risk threats |
PPD-21 | Unifies national efforts to strengthen critical infrastructure; grants CESER authority in these objectives | |
PPD-41 | Designates DOE as Sector-Specific Agency for securing critical energy infrastructure | |
Legislative Authorities | Energy Independence and Security Act of 2007 | Establishes policy for grid modernization to maintain reliable and secure electricity infrastructure |
FAST Act | Codifies DOE’s role as Energy Sector Specific Agency for cybersecurity | |
NDAA FY 2020 | Established two-year pilot program to identify new energy sector security vulnerabilities | |
Agency Rules, Frameworks, and Strategies | National Response Framework | Outlines DOE’s responsibility for delivery of energy as essential community lifeline |
Emergency Support Function #12 | Grants CESER authority to coordinate and respond in energy sector emergencies | |
National Cybersecurity Strategy | Defines DOE’s role in defending national energy infrastructure | |
National Infrastructure Protection Plan | Provides risk management framework for protecting critical infrastructure | |
Grid Security Emergency Final Rule | Establishes DOE’s responses to grid security emergencies |
Programs
FY 2025 Budget focus
- Strengthen U.S. energy sector security and resilience through advanced risk analysis using the analytical capabilities of DOE’s National Laboratories and partnerships with industry and SLTT governments.
- Integrate cybersecurity and resilience into the energy sector industrial base through partnerships with manufacturers, technology companies, standards organizations, and academia.
- Reduce risks to the electricity, oil, and natural gas systems through threat-informed research, development, and demonstration (RD&D) of next generation tools and technologies providing U.S. energy companies cutting-edge protection, monitoring, detection, response, containment, forensics, and recovery capabilities.
- Build security and resiliency capacity across industry and SLTT entities through exercises, training, technical assistance, and workforce development initiatives.
- Strengthen emergency preparedness and response capabilities by enhancing CESER’s ability to address all hazards impacting or potentially impacting the energy sector, by reducing impacts at the regional and State levels, in coordination with industry partners.
Divisions
- Policy, Preparedness, and Risk Analysis (PPRA): The PPRA division, operating under CESER’s authority as the Sector Risk Management Agency for energy, assesses risks to the U.S. energy sector and leads efforts in policy development, risk management, and capacity building. It serves as the main contact for state, local, tribal, and territorial governments and private sector partners on energy critical infrastructure protection. PPRA works to strengthen energy infrastructure security and resilience through risk assessments, technical assistance, training, and educational resources. The division supports post-disaster recovery, contributes to national security via its Defense Critical Energy Infrastructure program, and represents the Department in cybersecurity and infrastructure resilience discussions.
- The Risk Management Tools and Technologies: The RMT division, under CESER, addresses energy sector challenges through RD&D. RMT focuses on cybersecurity, physical, electromagnetic, geomagnetic, and climate-based risks, creating tools to monitor and protect critical energy assets. Its functions include advancing cybersecurity tools, managing supply chain risks, addressing threats to distributed energy resources and electric vehicle infrastructure, and conducting risk assessments. RMT integrates ‘cybersecurity by design’ across DOE’s efforts and coordinates cyber RD&D among offices. The division implements the Cyber Testing for Resilient Industrial Control Systems (CyTRICS) program and the Cyber-Informed Engineering (CIE) strategy.
- Response and Restoration: This division leads emergency response efforts, coordinates situational awareness, and manages the deployment of trained responders to disaster sites. They conduct damage assessments, assist with restoration planning, and provide technical expertise during energy emergencies. The team coordinates responses to cybersecurity incidents in the energy sector and leads the Energy Threat Analysis Center (ETAC) to address cyber threats. They maintain regional response teams, provide continuous energy sector monitoring, and operate the EAGLE-I situational awareness platform.
References
Index
Department of Commerce (DoC)
International Trade Administration (ITA)
US Patent and Trade Administration (USPTO)
Bureau of Industry and Security (BIS)
National Institute of Standards and Technology (NIST)
US AI Safety Institute (USAISI)
National Telecommunication and Information Administration (NTIA)
Department of Energy (DoE)
Office of Cybersecurity, Energy Security, and Emergency Response (CESER)
Advanced Scientific Computing Research (ASCR)
Office of Critical and Emerging Technology (OCET)
Department of Homeland Security (DoHS)
Cybersecurity and & Infrastructure Security Agency (CISA)
Office of Cyber, Infrastructure, Risk, and Resilience (CIRR)