The North American Electric Reliability Corporation (NERC) has developed a new set of cybersecurity standards designed to help power and utility (P&U) companies limit their exposure to third-party cyber risks and preserve the reliability of bulk electric systems (BES).
The Federal Energy Regulatory Commission approved the NERC standards in the fall of 2018.
NERC CIP-013-1 Effective Date
This critical infrastructure protection (CIP) standard will be enforceable starting on July 1, 2020. Affected companies will need to be able to prove that they’re compliant within 18 months of the NERC CIP-013-1 effective date in order to avoid penalties.
What’s included?
The new NERC CIP-013-1 standard proactively addresses specific supply chain cyber risks with the aim of improving BES reliability.
According to NERC, “The security objective [of these rules] is to ensure entities consider cyber security risks to the BES from vendor products or services.” CIP-013-1 includes regulations for vendor procurement, permissions, and monitoring.
The new standards will help utility companies protect bulk electric systems by limiting their exposure to malware, tampering, and other cyber risks that can originate with vendors.
Why now?
NERC CIP-013-1 comes at a time when many industry regulators are implementing regulations for third-party risk management. Other, broader regulations like GDPR also focus on third-party risk.
These regulations follow a long history of third-party data breaches across industries. Research has shown that breaches originating at third parties are among the costliest cyber attacks.
These attacks have caused downtime in major network infrastructure and derailed the physical operations of global companies like FedEx and Maersk. An attack of this nature that affects American power grids could potentially be catastrophic.