E-ISAC's Michael Ball: GridEx and Building Resilience by Testing to the Point of Failure
GridEx VIII promises to be another major step forward in advancing industry-wide preparedness and resilience against evolving cyber and physical security threats.

As the new leader of the Electricity Information Sharing Analysis Center (E-ISAC), I come into the role with a sense of enthusiasm and energy. Not only do I get to continue the mission, vision, and focus I had in my previous role at Berkshire Hathaway Energy (BHE), I also get to work with another exceptional and highly respected team. I see nothing but potential as we build on the E-ISAC’s historic successes—one of which is GridEx, the largest grid security exercise in North America.
Hosted every two years by the North American Electric Reliability Corporation and the E-ISAC, GridEx was launched in 2011. Hundreds of organizations and thousands of individuals have participated. GridEx simulates the response and recovery from a coordinated attack on critical infrastructure and is designed as a decentralized, distributed play exercise. Organizations that take part can scale their own participation up or down to meet their unique objectives while coordinating their response with external partners. This year, GridEx VIII (to be held November 18-19) promises to be another major step forward in advancing industry-wide preparedness and resilience against evolving cyber and physical security threats.
Although I have been with the E-ISAC for a relatively short time, I already am struck by the scale and scope of the exercise and the level of industry and government planning, collaboration, and coordination that goes into staging this important event.
In my previous role, I participated in all seven exercises. I always saw them as an opportunity to exercise at scale and to test and continually strengthen our resilience. While GridEx is only one of many exercises that entities take part in, its unique flexibility is an asset and provides a broader view across industry, government, and stakeholder perspectives.
And, importantly, it serves as a call to action to engage and build relationships across those groups before a real event occurs. Planning and engagement include working with federal government partners, such as the U.S. Department of Energy, the Cybersecurity and Infrastructure Security Agency, the U.S. Department of Defense, and the Canadian Centre for Cybersecurity—organizations that would be instrumental in responding to a national-level crisis.
Of course, the real impacts of any attack are realized in local communities, making strong relationships among the investor-owned electric companies, electric cooperatives, public power entities and municipalities, local government, and emergency services vital to recovery efforts. GridEx promotes bringing these organizations together to build and strengthen relationships, as participants work together to enhance our collective resilience.
I firmly believe that the E-ISAC’s role in building and coordinating this exercise is about continuously advancing the resilience of our industry. Every exercise should move the needle forward, challenging our plans and capabilities and identifying opportunities to strengthen and improve, because that is the real benefit. At the end of the day, we cannot prevent everything, but we can reduce the likelihood and impact of physical and cyber attacks—and we can ensure that the partnerships and processes are in place to effectively respond and recover.
Participating with BHE in the past provided a valuable perspective and shaped my thinking on how participants should approach the exercise. I believe the aim should be to challenge existing plans, degrade resources, and test assumptions to the point of failure—it is at the point of failure where the lessons are really learned. Effective exercises using challenging scenarios and the resulting lessons learned are what lead to measurable improvement for each participating organization.
The E-ISAC publishes its own Lessons Learned Report following each GridEx, which is posted on the E-ISAC website. A major outcome of the 2023 exercise was the need for the electric sector to improve the resilience of its communications systems. Through document reviews and interviews with subject matter experts, the E-ISAC developed a full report with extensive recommendations for the Electricity Subsector Coordinating Council.
The E-ISAC also developed two communications references: an in-depth case study on the unique communications challenges encountered during Hurricane Helene in North Carolina; and a Resilient Communications Technical Crosswalk document, which serves as a quick reference for comparing different resilient communications technologies currently in use across the grid. These references, which are available on the E-ISAC website, are provided to help members as they improve their crisis communications plans and elevate their communications technologies.
Enhanced accessibility was another recommendation identified during GridEx 2023. As a direct result, the E-ISAC has expanded participation options for the upcoming exercise to make it even easier for smaller organizations and first-time participants to get involved. To facilitate their participation, two new formats have been introduced this year:
- GridEx in a Box: A streamlined version designed as a functional exercise, ideal for smaller planning teams or organizations with limited resources.
- GridEx Tabletop: A flexible, discussion-based format designed to be “plug and play” with a slide deck and a facilitator guide.
With more than 300 organizations already registered, GridEx VIII is an opportunity to strengthen internal response capabilities, build relationships across the industry and with other sectors, and help enhance the overall resilience of the bulk power system. More information and registration details are available on the E-ISAC website.
Michael Ball is senior vice president at the North American Electric Reliability Corporation and CEO of the Electricity Information Sharing Analysis Center.