Hiển thị các bài đăng có nhãn distribution. Hiển thị tất cả bài đăng
Hiển thị các bài đăng có nhãn distribution. Hiển thị tất cả bài đăng

New England (and Connecticut in Particular) Showing PUC Leadership on Security

NARUC has been issuing cybersecurity guidance to the 50 US public utility commissions (PUCs) since 2010. And NASEO's been guiding other state government orgs.  California's PUC has been very active, showing leadership with its multiple publications on security and privacy. Until recently, PUC Texas had a true cybersecurity pro on staff.

But now I'm going to tell you about my part of the world: New England.  Last fall the organization that brings the six northeastern PUCs together, NECPUC, put out an RFP for security consulting for the six and some of their utilities. Won by EnergySec, I've heard only positive news about what that six month engagement has produced. In addition, the Massachusetts AG recently released an RFP seeking 3rd part evaluations of cybersecurity preparedness of the distribution companies serving the state.

Now comes this comprehensive, 30-page report this from Connecticut's Public Utilities Regulatory Authority (PURA): "Cybersecurity and Connecticut's Public Utilities," released earlier this week.  While giving credit to the two regulated electric utilities in its jurisdiction for doing a good job on cybersecurity so far, it also tackles head on key challenges and next steps, including:
  • Setting performance criteria (hmmm, sounds like measurement maybe)
  • Seeking concurrence regarding the role of regulators
  • Establishing consistent regulation
  • Identifying reporting goals and standards
  • Sharing information and best practices
  • Maintaining confidentiality of sensitive cyber information
  • Rethinking procedures for ensuring personnel security
  • Defining appropriate cost thresholds and cost recovery guidelines
  • Identifying effective training and situational exercises
  • Integrating public utility cyber issues into Connecticut's emergency management operations. 
All good stuff.  However, the report notes that municipal utilities, while providing essential services, are not regulated by PURA. This is true across all 50 states and presents a massive power sector security regulatory blindspot.

Before the report wraps up, it presents regulators and other stakeholders with a few questions (in third person) to be asked about utility cyber preparations:
  • Do the leaders in the public utilities serving Connecticut and their boards pay appropriate attention to risk management in general and cyber as part of that challenge? 
  • Do they have skilled personnel and necessary hardware and software? Are their budgets for cybersecurity adequate? 
  • Do they train and keep up with the constantly evolving set of threats? 
  • Do they run mock drills with outside assistance to test the strength of their deterrence? 
  • Do they have access to outside consultants and experts to stay up to date and to fill in gaps not covered by their own personnel? 
  • Are they active participants in trade association activities geared toward sharing best practices? 
There's more to say, but you're better off reading the report in full when you have a chance.

You'll find it HERE.


Security at the Edge of the Grid


We used to be very concerned about traveling too close to the edge of the world, remember?  Then some smart math and science guys figured out, surprisingly, Earth has no edge, so we were free to move about about the globe.

Now as we approach the end of the beginning of the Smart Grid era, what began as an initiative to add visibility, flexibility, and yes, smarts all over the grid is now seeing change accelerate close to the points of consumption.

Of course, amid all the excitement about innovation in distributed generation, distribution automation, energy efficiency, demand management, microgrids, storage, etc., one could forget that there's some basic housekeeping to attend to in the categories of power regulation and security.

The former, which includes maintaining the quality of electricity and keeping dangerous phenomena like harmonics in check, has been the province of utilities and ISO/RTOs and that's not going to change.  Ever increasing percentages of distributed generation are, in anything, going to make utilities' capabilities in this area even more essential to safe and reliable power delivery.

The other housekeeping item, now that it's 2013/2014 and not 1963/1964, is that all the new edge devices have several attributes in common:

  • They send, receive and store data
  • They constrain access to their data and/or services to certain other systems
  • They receive control signals, sometimes from humans (think: iPhone apps) and sometimes from other systems (think: Nest thermostats)

Of course this is an oversimplification, but astute readers will notice that the integrity of all of these activities depends entirely on capabilities from the security domain.  My job as part of Greentech Media's new Grid Edge Executive Council (see my humble logo above nestled among the titans) is to ensure less-than-sexy security attributes are baked into the functional requirements of all the new products that plan to participate in this edgy arena.

That way, when 2023/2024 arrives, we'll be powering our homes, businesses and country with power we can depend upon.