Back to Feed
PolicyAug 27, 2026

Trump Order Aims to Block Foreign Backdoors in US Power Grid Gear

Trump order targets foreign-supplied electrical equipment for US power grid.

Summary

President Trump has issued Executive Order 14420, declaring a national emergency to address vulnerabilities in the US bulk power system stemming from foreign-supplied electrical equipment. The order prohibits the acquisition, import, transfer, or installation of foreign-produced bulk-power equipment from designated entities after August 26, 2026, if it poses risks of sabotage or unauthorized access. It covers critical infrastructure transmission lines and specific industrial control systems, signaling a shift towards mitigating upstream supply chain risks and embedded hardware backdoors.

Full text

President Trump issued Executive Order 14420 on Wednesday, declaring a national emergency to mitigate vulnerabilities in the United States’ bulk power system arising from foreign-supplied electrical equipment. The order attributes the heightened emergency status to rapid growth across data centers, AI, advanced manufacturing, and defense production. Officials noted that dependence on grid reliability magnifies the impact of foreign supply chain disruptions or targeted attacks that exploit built-in backdoors for remote access. The order covers critical infrastructure operating bulk-power system transmission lines rated at 69 kilovolts or higher, while explicitly excluding local electricity distribution facilities. Targeted technologies include transformers, inverters, energy storage systems, and industrial control systems (ICS), such as remote terminal units (RTUs), programmable logic controllers (PLCs), and safety systems. The order also covers associated firmware, software, and remote access capabilities. Under the new directives, any acquisition, import, transfer, or installation of foreign-produced bulk-power equipment initiated after August 26, 2026, is prohibited if the transaction involves designated entities. Restrictions apply to hardware or software deemed to pose risks of sabotage, unauthorized access, malicious remote operation, or supply disruption. The order does not name any country. However, its structure closely mirrors a 2020 Trump-era bulk-power order that led to a DOE prohibition order explicitly targeting entities associated with China — though that prohibition was later revoked following a Biden administration review.Advertisement. Scroll to continue reading. While the focus is often on state-sponsored Chinese actors targeting US power grid networks through active intrusions, these directives signal a shift toward mitigating upstream supply chain risks and embedded hardware backdoors. For equipment installed prior to the new executive order, the Energy Department can mandate security controls. Following consultation with defense and intelligence leaders, it can require grid operators to identify, isolate, monitor, secure, disconnect, or replace certain components to neutralize operational threats, while ensuring service continuity and safety. To support ongoing grid operations, energy authorities may negotiate mitigation agreements or publish an official list of pre-qualified equipment and vendors exempt from the baseline prohibitions. Related: Novel Private APN Pivot Let Hackers Sabotage Second Polish Energy Facility Related: Origin Energy Data Breach Affects 900,000 Australians Related: New Wiper Malware Targeted Venezuelan Energy Sector Prior to US Intervention Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Eduard Kovacs Recent Citrix NetScaler Vulnerability Exploited in the WildAI Speeds Up Malware Development, Not Its Success Rate: AnalysisAdobe and Nvidia Patch Dozens of VulnerabilitiesCISA: Over 100 Internet-Exposed Water Systems Targeted in July CyberattacksChrome 152 Patches Over 300 VulnerabilitiesSensitive Information Exposed in Nutex Health Data BreachCISA Warns of Exploited Gitea VulnerabilityLinux Foundation to Govern TRACE, an Open Standard for AI Runtime Attestation Latest News Australia Arrests 2 Alleged TeamPCP HackersOpenAI Agents Coordinated via Makeshift Message Board Ahead of Hugging Face HackOkta Shares Surge on Strong Earnings, Growing Demand for AI Identity SecurityCISO Conversations: Chris Wheeler – Trust Is the Job, From the Navy to the C-SuiteCyberattack Causes Global Disruption at Boston ScientificThe Future of AI-Driven Security Depends on Complete DataUS Disrupts Chinese Hacking Platform Used in Military and Critical Infrastructure AttacksPro-Russian Hackers Claim Responsibility for Major Cyberattack on Norway’s Public Digital Services Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Scaling AI Security August 26, 2026 Join this live webinar for a practical framework for evolving your AI security program from a single application to an enterprise AI ecosystem and autonomous agents. Register Webinar: Minimum Viable Business: Can You Prove Your Organization Would Recover? September 2, 2026 In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk. Register People on the MoveNaveen Bhateja has been appointed Chief People Officer at HackerOne.The Department of War has appointed Sonu Shankar as Principal Deputy Chief Information Officer.Trellix has named David Pieterse as Chief Operating Officer GTM and David Soto as Chief Information Security Officer.More People On The MoveExpert Insights The Future of AI-Driven Security Depends on Complete Data For twenty-five years, "data" in security meant logs and events. But logs are a lossy representation of reality. (Danelle Au) The MFA Identity Trap: When Authentication Creates a False Sense of Security Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop. (Torsten George) Silent Patches Don’t Stop Attackers – They Blind Defenders Silent patches can become exploit intelligence for attackers while leaving defenders without the context needed to prioritize risk. (Tod Beardsley) Hired for One Job, Judged on Another: The CISO’s Real Problem The skills that get a CISO hired are rarely the skills they are judged on later. Most security leaders are stuck in that gap. Closing it is the real job. (Sravish Sridhar) Rethinking Application Security for the AI Era As AI dramatically shortens the time from vulnerability disclosure to exploitation, enterprises must look beyond patching to reduce application risk. (Joshua Goldfarb) Flipboard Reddit Whatsapp Whatsapp Email

Entities

industrial control systems (product)remote terminal units (product)programmable logic controllers (product)safety systems (product)transformers (product)inverters (product)