Hiển thị các bài đăng có nhãn incentives. Hiển thị tất cả bài đăng
Hiển thị các bài đăng có nhãn incentives. Hiển thị tất cả bài đăng

Where do Today's Electric Utility CEOs come from, and what do their Origins Mean for Grid Security?


I remember once thinking, naively perhaps, that most utility CEOs must have come up through the ranks, like generals in the military, with hands-on operational engineering experience garnering them the respect of their peers and subordinates along the way.

When I shared that concept last year with a 40-year industry veteran who'd done his time in generation and T&D, he schooled me saying that while that used to be the case, it's not the norm today.  He said more often you'll find someone with a finance background, often imported from sectors outside power.

Well, I got another round of schooling on this subject this week from former state commissioner and current consumer advocate Nancy Brockway, who has made her presence known on this blog before, in: "The State of the States and Smart Grid Security." Well she's back, and whether you agree with her or not, and allowing for exceptions, I think you definitely should hear what she has to say about the origins of senior utility leadership in 2014:
Transaction-oriented finance and legal sector professionals have displaced engineers in the executive suites of most utilities. The big shift to deal-making occurred in the wake of the existential shocks of the late 20th century over cost over-runs, the end of cheap oil, and the growing recognition of the environmental costs of utilities. 
Look back a century or more to the pioneers of the utility industry and you'll see a public interest value system that could and often did accompany the build out of utility territories and even accompanied mergers and acquisitions. Read 2004's Insull: The Rise and Fall of a Billionaire Utility Tycoon by Forrest MacDonald, for more background. 
But economies of scale were pretty-well exhausted by the 1960s. Bigger was no longer better for customers. And an anti-regulation "winner takes the hindmost" political climate did not reward a utility executive's greater effort to serve the public. Rather, it rewarded ever more sophisticated schemes to funnel profits up to the executive suite.
Regulators have to push for what they see as the public interest. To do their jobs with any responsibility in these circumstances, they can no longer sit back and merely act as a brake on occasional excesses. Too often they have to define the public good and demand it from utility management.

I am not sure that a workable redefinition of the roles and responsibilities of management and regulators can happen without a wholesale cultural shift away from "Greed is Good." My opposition to pre-approval of cyber security spending comes from the sense that if the utility drags its heels or does only what it needs to satisfy regulators, that just demonstrates that utility execs do not see security as fundamentally necessary for their personal financial success.
Sort of begs the question of how Gordon Gekko would weigh security investments vs. security risk, and you know what, I don't know the answer.  But we know GG types thrive on risk and reward. 

That's not exactly what I had in my mind previously, imagining conservative, retired military, former boy or girl scouts, with steady hands on the tiller of some of the absolute most important critical infrastructure organizations in the country.

Hopefully, experience and acumen with fine tuning financial risk/reward equations will most often translate to similarly savvy understanding of and action on operational risks ... including one that's increasingly material and the raison d'etre of this blog.

Photo credit: ABC news

Motivation through Compensation: Paying Utilities to Upgrade Cyber Defenses

Now we're getting somewhere!  The long submerged topic of "who should pay" for electric utility cyber security improvements has just breached the surface and is now bobbing up and down in clear daylight.

A recent article in Bloomberg documents several large US utilities' efforts to recover current and future cyber security investments the same way they get paid for other infrastructure programs: by getting clearance from their state utility commissions to approve these expenses in their rate cases.

Actually rate payers (aka electricity customers) will pay one way or another, as they should, for the essential service that makes our modern lifestyles possible.  Possible methods of payment include:
  • Absorbing the costs to their businesses and their lives associated with brown outs or black outs or electricity quality issues stemming from successful attacks on control centers or systems
  • Paying more every month to cover some, most or all (TBD) of their utilities' cyber-protection expenses
  • Or, as Pepco CIO Doug Myers said, as cited in the Bloomberg article, allowing utilities to be reimbursed through federal grants
This concept was articulated more formally by Michael Daniel, special assistant to the President on Cybersecurity, when he included rate recovery as one of a number of cyber incentive strategies for critical infrastructure providers:
Rate Recovery for Price Regulated Industries — Agencies [DHS, Commerce, Treasury] recommended further dialogue with federal, state, and local regulators and sector specific agencies on whether the regulatory agencies that set utility rates should consider allowing utilities recovery for cybersecurity investments related to complying with the Framework and participation in the Program.
As this blog often reiterates, we have to acknowledge and accept the costs of living in a technology-enabled world, where the impulse to cyber secure important services must become every bit as natural as physically securing our more tangible valuables.

Else, I have a nice cave I'd like to show you. And no, it doesn't have wifi.

First Look at Cyber Security Incentive Ideas, Companion to NIST's Framework Work

I'll oversimplify this to keep it short, but the President kicked all of this off earlier this year in wake of failed cyber security legislation efforts in 2010 (GRID Act) and 2012 (Cybersecurity Act of 2012).

The two primary vectors on this project have included:

  1. Having NIST lead the charge to develop a new cyber security framework (i.e., pattern, roadmap, guidance) made up of references to existing guidance that seem to work well. On twitter this effort is tagged #NISTCSF
  2. A parallel initiative to develop incentives that might improve the business case for being more proactive on cyber security.
The incentive categories were just made public, and so far include :
  • Cybersecurity Insurance
  • Grants
  • Process Preference
  • Liability Limitation
  • Streamline Regulations
  • Public Recognition
  • Rate Recovery
  • Cybersecurity Research
Liability and insurance are going to be the thorniest.  And rate recovery help, if workable, sounds promising.

You ran read The Hill's coverage and the original White House text via URLs below, as well as check out the current status and next activities related to the framework.

----

URLs

The Hill

http://thehill.com/blogs/hillicon-valley/technology/315795-white-house-publishes-preliminary-list-of-cybersecurity-incentives

White House

http://www.whitehouse.gov/blog/2013/08/06/incentives-support-adoption-cybersecurity-framework

NIST CSF

http://www.nist.gov/itl/cyberframework.cfm