Skip to main content
Background

Secure the Grid: What Executive Order 14421 Means for Zero Trust

October 05, 2026 by Erin Verna

Share

Key takeaways

On August 26, 2026, the President of the United States declared a national emergency under the International Emergency Economic Powers Act (IEEPA) to address foreign-sourced vulnerabilities in the U.S. bulk-power system, citing risks of remote sabotage by foreign actors, unauthorized access, and supply chain compromise.

Executive Order 14421 gives the Department of Energy sweeping authority to restrict, isolate, or require replacement of foreign-supplied grid equipment, including the software, firmware, and remote-access capabilities tied to it.

For utilities, grid operators, and the state agencies that oversee them, the mandate is really an architecture mandate: Assume targeted components already exist inside the environment and design accordingly.

Zero Trust network segmentation, application access, and API security together form the practical playbook for meeting that mandate without waiting years for hardware replacement cycles to finish.

U.S. federal action on grid cybersecurity has typically moved at the pace of procurement cycles, but that changed recently. By declaring a national emergency to protect the bulk-power system, the administration signaled that certain foreign-origin equipment — including reactors, transformers, industrial control systems, protective relaying, and the remote-access channels wired into them — should be treated as a standing national security threat, not a theoretical one.

For utility and grid-operator security teams, the order supports a mentality recommended by threat intelligence experts for years: Adversaries don't need to breach the perimeter if the vulnerability is already built into the equipment on the substation floor.

For state energy regulators and federal agencies, the order raises the bar on what “secure”  means for every interconnected system that touches bulk-power infrastructure — everything from generation to transmission and the industrial control systems in between.

The emerging risk of AI in grid operations

This security challenge is growing as AI becomes more involved in grid operations. AI-driven forecasting, optimization, and other automated processes can introduce more machine-to-machine interactions across IT, OT, and cloud environments. 

These additional interactions introduce another set of connections that security teams need to understand and control.

What happens when the threat is already inside the environment?

The order doesn't just restrict future purchases of foreign-produced bulk-power equipment tied to a “Covered Foreign Entity.” The Department of Energy can also impose conditions on equipment already in use, including requirements to identify, isolate, monitor, secure, disconnect, replace, or remove it. 

The order's own language is clear: Foreign-produced equipment “might have digital backdoors built into their systems that allow a foreign country to access that equipment remotely.” Addressing this is a textbook Zero Trust threat use case.  

Continue to mature your Zero Trust architectural approach by ensuring Least Permissive Trust to all apps (modern and legacy). You should apply this same approach to all the APIs that serve as the connective tissue among applications. And, by adopting network segmentation under the assumption that a malicious actor is already inside the network, you can help prevent lateral movement.

How can existing security controls help contain a compromise?

Executive Order 14421 makes clear that defense in depth is no longer optional — security teams must be able to isolate threats at a moment's notice. Rather than ripping and replacing complex operational technology, you can apply three core Zero Trust disciplines to contain exposure, restrict lateral movement, and satisfy federal compliance requirements without disrupting active power generation, including:

  • Network segmentation

  • Zero Trust application access 

  • API monitoring and security

Network segmentation

Flat OT/IT networks are precisely what allow one compromised remote terminal unit or transformer controller to turn into a grid-wide incident. 

Microsegmentation delivered by Akamai Guardicore Segmentation lets operators isolate substations, control rooms, and generation assets from one another — and from corporate IT — so that a compromised or foreign-flagged component can be contained, monitored, or disconnected without taking down the broader system. This is also what makes the order's “isolate” and “disconnect” mandate operationally achievable instead of requiring a full network shutdown.

That level of control is especially important in environments where simply taking systems offline may not be practical. Microsegmentation gives security teams a more granular way to isolate affected assets while maintaining necessary communications across the rest of the environment.

Zero Trust application access

Remote-access capabilities that are called out explicitly in the order as attack surfaces —including vendor maintenance links, remote diagnostics, and third-party support tools — are exactly the kind of “remote-access capability associated with such equipment” that the order targets. 

Replacing flat VPN access to ICS and SCADA environments with an Identity-Aware Proxy like Akamai Enterprise Application Access closes off the broad network reach that legacy remote access grants by default, whether the vendor is trusted today or is designated a risk tomorrow.

API monitoring and security

As grid operations increasingly depend on data centers, AI-driven load forecasting, and interconnected utility platforms — a dependency the order specifically flags as raising the stakes of a successful attack — the APIs tying these systems together become a growing, often undermonitored, attack surface. 

Discovering, testing, and continuously monitoring every API call with a platform like Akamai API Security is what turns a compliance requirement into real-time protection against remote exploitation.

CapabilitySecurity outcome

Network segmentation

Microsegmentation and breach detection across data centers, cloud, and hybrid OT environments shut down lateral movement.

Zero Trust application access 

Deploying an identity-aware proxy closes all inbound firewall ports and hides applications from the internet, granting access only to authorized users and devices, never the network itself.

API monitoring and security 

Continuous discovery, risk assessment, automated testing, and runtime protection across an organization's full API estate, including APIs tied to AI and large language model integrations, address one of the fastest-growing attack surfaces. 

How Zero Trust architecture addresses the executive order mandate

Securing AI agents and machine-to-machine traffic

The challenge grows as utilities adopt AI-driven workflows and explore AI agents for functions such as grid balancing, forecasting, and predictive maintenance. These systems can create more machine-to-machine API traffic across IT, OT, and cloud boundaries, making it important to know which APIs are communicating with one another, what they can access, and whether their behavior changes unexpectedly.

Extending API discovery, testing, and runtime monitoring to these AI-driven connections can help security teams identify unmanaged APIs, vulnerabilities, and abnormal behavior before those pathways create additional exposure. It applies the same Zero Trust principles already used at the network and application layers to the machine-to-machine interactions that are connecting increasingly automated systems.

How does Zero Trust strengthen infrastructure-wide security?

While this executive order applies specifically to the bulk-power system, the same security principles can extend to other critical infrastructure environments. Network segmentation, application access, and API security aren't parallel initiatives, but the same Zero Trust principles enforced at three points in the stack: the network, the application access layer, and the data exchange. 

Zero Trust principles, built on continuous verification and least privilege, help teams respond to a fast-moving federal mandate.

Find out more

To learn more about how Akamai solutions can help you support this shift, request a demo today.

About the Author(s)

Erin Verna

Erin Verna

Erin Verna is a Principal Product Marketing Manager for Zero Trust Architectures at Akamai. With a career spanning more than 15 years across technology firms, including F5 and Microsoft, Erin specializes in messaging strategy, product positioning, and go-to-market execution for complex cybersecurity and hardware solutions. Erin holds a Bachelor’s degree in Journalism from Gonzaga University and actively serves as a business mentor in the Seattle area.