Hiển thị các bài đăng có nhãn regulation. Hiển thị tất cả bài đăng
Hiển thị các bài đăng có nhãn regulation. Hiển thị tất cả bài đăng

New England (and Connecticut in Particular) Showing PUC Leadership on Security

NARUC has been issuing cybersecurity guidance to the 50 US public utility commissions (PUCs) since 2010. And NASEO's been guiding other state government orgs.  California's PUC has been very active, showing leadership with its multiple publications on security and privacy. Until recently, PUC Texas had a true cybersecurity pro on staff.

But now I'm going to tell you about my part of the world: New England.  Last fall the organization that brings the six northeastern PUCs together, NECPUC, put out an RFP for security consulting for the six and some of their utilities. Won by EnergySec, I've heard only positive news about what that six month engagement has produced. In addition, the Massachusetts AG recently released an RFP seeking 3rd part evaluations of cybersecurity preparedness of the distribution companies serving the state.

Now comes this comprehensive, 30-page report this from Connecticut's Public Utilities Regulatory Authority (PURA): "Cybersecurity and Connecticut's Public Utilities," released earlier this week.  While giving credit to the two regulated electric utilities in its jurisdiction for doing a good job on cybersecurity so far, it also tackles head on key challenges and next steps, including:
  • Setting performance criteria (hmmm, sounds like measurement maybe)
  • Seeking concurrence regarding the role of regulators
  • Establishing consistent regulation
  • Identifying reporting goals and standards
  • Sharing information and best practices
  • Maintaining confidentiality of sensitive cyber information
  • Rethinking procedures for ensuring personnel security
  • Defining appropriate cost thresholds and cost recovery guidelines
  • Identifying effective training and situational exercises
  • Integrating public utility cyber issues into Connecticut's emergency management operations. 
All good stuff.  However, the report notes that municipal utilities, while providing essential services, are not regulated by PURA. This is true across all 50 states and presents a massive power sector security regulatory blindspot.

Before the report wraps up, it presents regulators and other stakeholders with a few questions (in third person) to be asked about utility cyber preparations:
  • Do the leaders in the public utilities serving Connecticut and their boards pay appropriate attention to risk management in general and cyber as part of that challenge? 
  • Do they have skilled personnel and necessary hardware and software? Are their budgets for cybersecurity adequate? 
  • Do they train and keep up with the constantly evolving set of threats? 
  • Do they run mock drills with outside assistance to test the strength of their deterrence? 
  • Do they have access to outside consultants and experts to stay up to date and to fill in gaps not covered by their own personnel? 
  • Are they active participants in trade association activities geared toward sharing best practices? 
There's more to say, but you're better off reading the report in full when you have a chance.

You'll find it HERE.


Where do Today's Electric Utility CEOs come from, and what do their Origins Mean for Grid Security?


I remember once thinking, naively perhaps, that most utility CEOs must have come up through the ranks, like generals in the military, with hands-on operational engineering experience garnering them the respect of their peers and subordinates along the way.

When I shared that concept last year with a 40-year industry veteran who'd done his time in generation and T&D, he schooled me saying that while that used to be the case, it's not the norm today.  He said more often you'll find someone with a finance background, often imported from sectors outside power.

Well, I got another round of schooling on this subject this week from former state commissioner and current consumer advocate Nancy Brockway, who has made her presence known on this blog before, in: "The State of the States and Smart Grid Security." Well she's back, and whether you agree with her or not, and allowing for exceptions, I think you definitely should hear what she has to say about the origins of senior utility leadership in 2014:
Transaction-oriented finance and legal sector professionals have displaced engineers in the executive suites of most utilities. The big shift to deal-making occurred in the wake of the existential shocks of the late 20th century over cost over-runs, the end of cheap oil, and the growing recognition of the environmental costs of utilities. 
Look back a century or more to the pioneers of the utility industry and you'll see a public interest value system that could and often did accompany the build out of utility territories and even accompanied mergers and acquisitions. Read 2004's Insull: The Rise and Fall of a Billionaire Utility Tycoon by Forrest MacDonald, for more background. 
But economies of scale were pretty-well exhausted by the 1960s. Bigger was no longer better for customers. And an anti-regulation "winner takes the hindmost" political climate did not reward a utility executive's greater effort to serve the public. Rather, it rewarded ever more sophisticated schemes to funnel profits up to the executive suite.
Regulators have to push for what they see as the public interest. To do their jobs with any responsibility in these circumstances, they can no longer sit back and merely act as a brake on occasional excesses. Too often they have to define the public good and demand it from utility management.

I am not sure that a workable redefinition of the roles and responsibilities of management and regulators can happen without a wholesale cultural shift away from "Greed is Good." My opposition to pre-approval of cyber security spending comes from the sense that if the utility drags its heels or does only what it needs to satisfy regulators, that just demonstrates that utility execs do not see security as fundamentally necessary for their personal financial success.
Sort of begs the question of how Gordon Gekko would weigh security investments vs. security risk, and you know what, I don't know the answer.  But we know GG types thrive on risk and reward. 

That's not exactly what I had in my mind previously, imagining conservative, retired military, former boy or girl scouts, with steady hands on the tiller of some of the absolute most important critical infrastructure organizations in the country.

Hopefully, experience and acumen with fine tuning financial risk/reward equations will most often translate to similarly savvy understanding of and action on operational risks ... including one that's increasingly material and the raison d'etre of this blog.

Photo credit: ABC news

Motivation through Compensation: Paying Utilities to Upgrade Cyber Defenses

Now we're getting somewhere!  The long submerged topic of "who should pay" for electric utility cyber security improvements has just breached the surface and is now bobbing up and down in clear daylight.

A recent article in Bloomberg documents several large US utilities' efforts to recover current and future cyber security investments the same way they get paid for other infrastructure programs: by getting clearance from their state utility commissions to approve these expenses in their rate cases.

Actually rate payers (aka electricity customers) will pay one way or another, as they should, for the essential service that makes our modern lifestyles possible.  Possible methods of payment include:
  • Absorbing the costs to their businesses and their lives associated with brown outs or black outs or electricity quality issues stemming from successful attacks on control centers or systems
  • Paying more every month to cover some, most or all (TBD) of their utilities' cyber-protection expenses
  • Or, as Pepco CIO Doug Myers said, as cited in the Bloomberg article, allowing utilities to be reimbursed through federal grants
This concept was articulated more formally by Michael Daniel, special assistant to the President on Cybersecurity, when he included rate recovery as one of a number of cyber incentive strategies for critical infrastructure providers:
Rate Recovery for Price Regulated Industries — Agencies [DHS, Commerce, Treasury] recommended further dialogue with federal, state, and local regulators and sector specific agencies on whether the regulatory agencies that set utility rates should consider allowing utilities recovery for cybersecurity investments related to complying with the Framework and participation in the Program.
As this blog often reiterates, we have to acknowledge and accept the costs of living in a technology-enabled world, where the impulse to cyber secure important services must become every bit as natural as physically securing our more tangible valuables.

Else, I have a nice cave I'd like to show you. And no, it doesn't have wifi.

RFP Alert: Security Advisor Sought for New England Utility Commissions

No sooner had I posted on the need for more state utility commissions to ensure access to quality cyber security guidance, when an RFP with this exact goal in mind came across my desk (figuratively speaking). So without further delay, your attention please:

The region of 6 northeastern US states collectively referred to as "New England" and boasting the highest per-capita concentration of Dunkin Donuts is seeking one very well qualified energy and cyber security professional to help guide them for a six month period commencing in mid September.

The New England Conference of Public Utilities Commissioners, Inc. (NECPUC) has issued an RFP for which responses are due NLT 5 pm August 8, 2013. I provide the URL to the RFP below but to save you an unnecessary trip, here are the qualifications required if you or your small firm want to even be considered for the job:
  • Background and knowledge of utility sector industrial control system and business operations
  • Knowledge and expertise in computer systems security and related physical security issues
  • Certified Information Systems Security Professional or similar computer security management certification preferred
  • U.S. Government security clearance of “Secret” or higher preferred
  • Engineering and/or information technology degree and training preferred
  • Knowledge of NERC CIP standards
  • Certified Information Systems Security Professional, Certified Information Security Manager or similar computer security management certification preferred
  • Ability to drive throughout New England visiting public utility commissions and utilities will be required (ab add: must be a confident driver in snow)
Does that sound like you?  If so, recommend you get started on your proposal. The New England state commissions are eager to get started!

(If not, but you think you know a qualified candidate, pleasure forward this on to them stat - thanks.)

------------------------------------

URL for NECPUC RFP:

http://www.aesp.org/associations/5980/files/RFP%20for%20Cyber%20Security%20Consultant%20FINAL.pdf

URL for previous SGSB post on PUCs and cyber security:

http://smartgridsecurity.blogspot.com/2013/07/to-secure-your-state-grid-first-know.html

House of Reps Report Reams Utilities on Cybersecurity

Was trying to capture spirit of Jesse Berst's headline on the same subject:
Utilities to FERC: Take your security measures and shove it
That's not very nice, is it?  I think they toned it down with a later change, but this headline was what was in my inbox in this morning's SmartGridNews.com newsletter. The subject is a recent report published by the House of Representatives that's highly critical of electric utilities behavior to date re: grid cybersecurity.

Moving on! The Wall Street Journal's Rachel King did a fine write-up of recent testimony from the CEO of the American Gas Association (AGA), Dave McCurdy. King began by noting that:
The oil and gas sector faces many of the same cyber security challenges as the electric industry. Yet, there’s one major difference between the industries, both of which need to secure software-based industrial control systems from intruders. There are no regulations governing cyber security among the oil and gas companies.
She also heard McCurdy say that no regulations were needed and that the sector’s voluntary approach is working just fine, and:
AGA remains concerned that prescriptive cyber security regulations will have little practical impact on cyber security and, in fact, will hinder implementation of robust cyber security programs.
If you know this subject pretty well, you're aware that there is some interesting psychology and rhetoric going on here. Most agree that mandatory, prescriptive cybersecurity rules are painful to implement and audit, and too slow to adapt to new types of attack. So in a major sense, the AGA CEO's quote is dead on. 

But the rub is that "robust cyber security programs," loosely defined, are not commonplace in the natgas distribution sector, and it's hard to imagine that market forces alone will drive companies to move of the schneid.  And the same dynamic largely holds true for the electric power sector.

The language is getting a little saucy. What's going to give?

URLs for the above, below:

House Report on Electric Grid Cyber Vulnerability

http://markey.house.gov/sites/markey.house.gov/files/documents/Markey%20Grid%20Report_05.21.13.pdf

SmartGridNews.com on Utilities' Unhappiness with Cybersecurity Regulation

http://www.smartgridnews.com/artman/publish/Technologies_Security/Utilities-to-FERC-Take-your-security-measures-and-shove-it-5778.html/?fpt#.UZ4dcSt4ZyE

WSJ: Oil and Gas Lobby Resists Regulation Despite Cyber Risk

http://blogs.wsj.com/cio/2013/05/22/oil-and-gas-lobby-resists-regulation-despite-cyber-risk/

NARUC Releases a Timely Cybersecurity Guide

I didn't like the tone of my original piece on this so have made a few mods. Content is essentially the same.

Here's a LINK to the National Association of Regulatory Utility Commissioners (NARUC)'s new Cybersecurity for State Regulators

Before I begin to comment on and critique some of the contents, I just want to say I have no ax to grind against NARUC. From my interaction with its members, including several of the folks named as authors of this document, these folks do a fantastic job, state by state by state, keeping the gigantic and sprawling US grid, reliably and economically up and running.

And let's continue with a little more praise. Very few state regulators have hands-on experience with cybersecurity. Giving them a guide that both teaches them, at an intro level, and arms them with good starting-point questions, is a wonderful and necessary thing. Major kudos for that.

However, this paraphrase from an article introducing the guide gave me initial pause:
NARUC advised state commissioners to work with utilities to increase their investment in cybersecurity protections for the smart grid.
This statement makes it sound like someone knows what the right amount of spending is. And that would suggest that that same someone knows a lot about the evolving threats, as well as the requirements for the right types of correctly deployed and configured technical and human protections, and has converted them to USDs (money). These are all things the energy sector security community is working on, but quantifying down to the right level of dollars spent is beyond us still, I think.

Now here's a direct quote from the guide:
Regulators have to determine whether the amount being invested is insufficient or excessive and whether it is allocated appropriately.
I know it's their job in general, but also think that specific to cybersecurity, this is a burden (on the regulators themselves) too far. Determining appropriate allocation is definitely a worthy pursuit, and the matter has great import for all stakeholder including customers. But man, without some commonly agreed frameworks or metrics to measure against, it's a tough one.

Now I'll do a quick pass at a couple of the proposed questions in the appendix.The first one is about budget:
Q26. Is cybersecurity budgeted for? What is the current budget for cybersecurity activities relative to the overall security spending?
Good stuff generally, and really core when it comes time to rate case justification. But I'd also want to know how is the budget arrived at? Like an elementary school teacher, I want you to step up to the board and show me the math. And not sure the second question is all that relevant ... is there a correct or helpful answer to that one?
Q27. Are individuals specifically assigned cybersecurity responsibility? Do you have a Chief Security Officer and do they have explicit cybersecurity responsibilities?
I hope that in even the smallest utilities (and some are mighty small) the answer to the first question is yes. And I know that in even the largest utilities, the answer to the second question is almost always no.

Now here are a couple of other questions I might have suggested." In addition to Q27, I would have liked to see questions that poke into other governance issues, like:
  • QAB1: Related to applications: How many applications do you have? What are the top 10 most important ones? Who owns them? Who developed them? Who patches them? How are they secured? When was the last time they were tested and how did they do? Who tested them?
  • QAB2: Related to data: Have you inventoried your data assets? Developed a classification scheme? Identified data owners? Developed data lifecycle and protection policies? Practiced responding to a data breach? Who owns Privacy?
  • QAB3: Related to money (again): Beyond pen testing, how do you evaluate the effectiveness of your cybersecurity policies and programs? Related to Q26, what methods do you use for prioritizing your cybersecurity expenditures?
OK, I'll leave off there. This is simply going too long. But would like to end by saying that this was a document that could never fully please everyone, and if we remember it's a 1.0 version, then in that context it's an ambitious and excellent start. Let's start providing feedback now so that 2.0 can be even better.