* Special note: I woke up this morning and heard about this topic while scanning my cybersecurity communication email. Having spent several decades handling communication in the cyber-security and manufacturing world, I always find the questions that are left unanswered, pose the greatest threat to clear concise understanding. This blog post differs from all of my Master Your Story creative energy and focuses on questions I believe should be asked and answered by the parties involved in this endeavor. I placed links to reference material at the end, for those who want to know more.
The announcement of a $528 million Hitachi Energy transformer-manufacturing facility in Gallman, Mississippi, has understandably generated excitement. The project promises hundreds of jobs, a major investment in Copiah County and increased domestic production of equipment the United States urgently needs.
It has also generated questions—and asking them is neither anti-business nor anti-growth. It is what responsible citizens should do whenever a private company, public incentives and critical national infrastructure intersect.
First, an important distinction: the proposed facility is not a power-generating plant, and Hitachi Energy is not being handed control of the American electrical grid. The Gallman facility will manufacture transformers, which allow electricity to move across transmission and distribution systems at appropriate voltages. Utilities, not the equipment manufacturer, will purchase, install and operate those transformers.
That distinction should reduce unnecessary alarm. It should not eliminate thoughtful oversight.
Transformers are essential to the reliability of the grid. As these machines increasingly incorporate digital sensors, communications systems and software, security depends on more than steel, copper and engineering. It also depends on code, access privileges, supply chains, maintenance agreements and public accountability.
Before equipment from this facility becomes part of America’s critical infrastructure, the public deserves clear answers to eight questions.
1. Are the digital components and software independently tested?
Manufacturers routinely test their own products, but internal testing is not the same as independent verification. Digital monitoring systems, communications modules and embedded software should be examined by qualified third parties using recognized American security standards.
Testing should look for exploitable vulnerabilities, undocumented communications, insecure default settings and unnecessary pathways into utility networks. It should also continue throughout the product’s life. A system that is secure when installed may not remain secure as new vulnerabilities emerge.
The public does not need access to sensitive technical details that could help an attacker. It should, however, be told what independent standards apply, who performs the verification and whether identified problems must be corrected before deployment.
2. Can the manufacturer access equipment remotely after installation?
Remote diagnostics can help utilities identify problems quickly, reduce outages and avoid costly site visits. But every remote connection can also become a potential avenue for misuse or attack.
Utilities should retain control over whether remote access exists at all. If it is permitted, access should be limited, encrypted, logged and activated only for a specific purpose and period. No manufacturer should have an undisclosed or permanent pathway into critical equipment.
The central question is simple: after a transformer is sold and installed, who holds the keys?
3. Are firmware updates authenticated and monitored?
Firmware is the embedded software that helps equipment perform its functions. Updates may be necessary to correct errors or security weaknesses, but a compromised update can introduce malicious code into otherwise secure equipment.
Utilities should accept only updates that are cryptographically signed and verified as authentic. Each update should be tested, approved, recorded and capable of being rolled back safely if a problem occurs. Vendors should also be required to report vulnerabilities promptly and explain how long each product will receive security support.
No update to critical infrastructure should arrive as an act of blind trust.
4. Are critical parts sourced from several suppliers?
Domestic assembly does not automatically mean that every critical component is domestically produced. A transformer made in Mississippi may still contain specialty metals, electronic components or control devices sourced elsewhere.
Global sourcing is not inherently dangerous, but dependence on a single supplier, manufacturer or country creates vulnerability. A factory disruption, geopolitical conflict, cyber incident or trade restriction could interrupt the availability of necessary parts.
Hitachi Energy and the utilities purchasing its equipment should be able to demonstrate supplier diversity, traceability and contingency planning. Policymakers should also identify which components still lack a reliable American or allied-nation source.
5. Are replacement transformers and components stockpiled?
Large transformers are not ordinary off-the-shelf products. Replacing one after a natural disaster, physical attack or catastrophic failure can take considerable time. Increasing manufacturing capacity helps, but production alone is not a complete emergency plan.
Utilities and government agencies should determine which replacement units and critical components need to be held in strategic reserves, where they should be stored and how they could be transported during a crisis. Stockpiles must also be maintained and tested; equipment that cannot be located or deployed quickly offers little protection.
The Gallman investment should become part of a broader national resilience strategy, not merely a response to current market demand.
6. Can utilities maintain the equipment without permanent dependence on the manufacturer?
A utility should not discover after purchasing critical equipment that only the original manufacturer can diagnose it, repair it or provide essential software. Long-term vendor dependence can increase costs and become a security risk if service is interrupted.
Purchase agreements should address access to manuals, diagnostic information, replacement parts, workforce training and software support. Utilities should know what happens if a product is discontinued, a contract ends or the manufacturer changes ownership.
American workers should be trained not only to build this equipment, but also to operate and maintain it safely over its full service life.
7. Are physical systems and cybersecurity systems appropriately separated?
The systems that monitor electricity should not automatically have unrestricted authority to control it. Utilities need strong separation between business networks, monitoring tools and operational technology capable of affecting physical equipment.
That requires more than a firewall. It involves segmented networks, strict access controls, multifactor authentication, continuous monitoring, incident-response plans and manual operating alternatives. A cyber incident affecting administrative systems should not be able to cascade into the physical operation of the grid.
Federal reliability standards already require covered bulk-power entities to address cybersecurity and vendor supply-chain risk. The important question is how rigorously those requirements will be applied to each installation, and whether smaller utilities outside portions of that framework will adopt equally strong protections.
8. What taxpayer incentives, environmental permits and public obligations accompany the project?
Mississippi has stated that the project will receive assistance through its MFLEX tax-incentive program, as well as support for site development and infrastructure improvements. Copiah County is also participating. Those commitments make transparency essential.
The public should be told the estimated value and duration of the incentives; what job, wage and investment targets Hitachi Energy must meet; and whether incentives can be recovered if the company falls short. Officials should also disclose the environmental and construction permits required, anticipated demands on water, transportation and public services, and how compliance will be monitored.
Economic development works best when benefits and obligations are both clearly defined. Hundreds of jobs would be meaningful for the region, but projected job numbers should eventually be measured against actual hiring, wages, contracting opportunities and long-term community impact.
Responsible questions strengthen responsible investment
Hitachi Energy has operated in the Crystal Springs area for decades, and producing more transformers inside the United States could reduce shortages and strengthen domestic supply capacity. The Gallman project may prove to be an important investment in both Mississippi and American energy resilience.
But “made in America” should describe more than the location of a factory. It should mean that the equipment is built under strong security requirements, that American utilities retain operational control, that the supply chain can withstand disruption and that public investment produces measurable public value.
These questions should not be treated as allegations that wrongdoing has occurred. Based on the information publicly announced so far, many of the detailed answers may rest with future utility purchasers rather than the Gallman factory itself. That is precisely why the questions should be asked now, while standards, contracts and oversight expectations can still be shaped.
The choice is not between welcoming investment and protecting national security. We can, and must, do both. A stronger grid begins with stronger equipment, but it endures only through transparency, independent verification and accountability.