Finite StateFinite State
Finite StateFinite State
Executive Order 13920: Securing the United States Bulk-Power System
Energy & UtilitiesIoT & OTCompliance & Regulations

Executive Order 13920: Securing the United States Bulk-Power System

Finite State publishes The United States Department of Defense's Request for Information regarding Securing the United States Bulk-Power System.

Matt Wyckhouse

Matt Wyckhouse

Founder & CEO

August 26, 2020

The United States Department of Defense recently put out a Request for Information (RFI) regarding Executive Order 13920 (Securing the United States Bulk-Power System). While Finite State does not typically publish our RFI submissions, the urgency of this issue and the fact that these answers will be available to the public allow us to do so in this instance.

Among other things, the Executive Order:

“Prohibits any acquisition, importation, transfer, or installation of bulk-power system electric equipment which has a nexus with any foreign adversary and poses an undue risk to national security, the economy, or the safety and security of Americans” — energy.gov

Will prohibiting installation of equipment manufactured by foreign adversaries secure our bulk-power system?

It is our belief that simply banning equipment from foreign adversaries will not address or entirely prevent vulnerabilities within our critical infrastructure, and that it is imperative that we recognize the impact of a globalized economy on our supply chains. The reality is, if you look deeply enough every supply chain is at risk of compromise by potential adversaries.

Trying to solve this through vendor self reporting and lightweight 3rd-party risk assessments will never work. We need to move away from this trust-based model and focus on a robust, continuous, risk-based approach where every device, software application, and firmware update in the BPS is being screened for real threats and vulnerabilities.

Country of origin and geopolitical risk are but a few factors in a comprehensive supply chain risk management strategy. Supply chain security is a multi-faceted, strategic, global priority, and it requires a collaborative effort between vendors and asset owners. We’re proud to work with manufacturers and asset owners in the energy sector to ensure their firmware, devices, networks, and supply chains are safe.

Read Finite State’s Full Response:

Finite State – DOE RFI 2020-0028 Response

Tags

#regulation
Matt Wyckhouse

Matt Wyckhouse

Founder & CEO

Matt Wyckhouse is CEO of Finite State and a recognized leader in cybersecurity, with over 20 years of experience securing software supply chains, IoT, and embedded systems. Formerly the founding CTO of Battelle’s Cyber Innovations Unit, he now leads Finite State’s mission to protect connected products from supply chain threats.

Related Articles

Road to Compliance: First Steps OEMs and Suppliers Should Take Today

The Road to Compliance: First Steps OEMs and Suppliers Should Take Today

Learn how to achieve Connected Vehicle Rule compliance with six actionable steps — from SBOM & HBOM generation to supplier engagement and risk evaluat...

Oct 20, 2025
Legacy Software & CVR Compliance Carveouts Explained

Legacy Software & CVR Compliance Carveouts Explained

Learn how legacy carveouts and specific authorizations can help you comply with CVR—while time-limited, they demand proactive planning now.

Oct 16, 2025
Regulations Driving IoT Security Forward

Regulations Driving IoT Security Forward

From EU CRA to FDA 524B, IoT regulations are reshaping the market. Learn what manufacturers need for compliance—SBOMs, testing, and supply chain visib...

Sep 24, 2025

Ready to Level Up Your Security Knowledge?

Join thousands of security professionals learning from the best in the industry

Start Learning TodayStart Learning Today
Finite StateFinite State

Finite State is the Product Security Automation Platform that functions as an autonomous Product Security OS: design → verify → prove, grounded in what you ship.

Platform

Platform Overview
Ground Truth Inventory
Exploitability-Based Prioritization
Design-Time Architecture Security
Automated Evidence-Backed Compliance

Solutions

Device Manufacturers
Automotive
Medical Devices
Energy & Utilities
Government
Industrial

Resources

Blog
Resource Library
Webinars & Videos
Events
Documentation

Company

About Us
CareersHIRING
Press & Media
Contact Sales
X

Privacy PolicyTerms of UseCustomer Terms and Conditions