FERC Directs NERC to Propose Mandatory Reliability Standards Regarding Physical Security Risks to the Bulk-Power System

Mar 10, 2014

Reading Time : 4 min

Three-Step Approach

The FERC did not impose a “one size fits all” approach to protecting physical security, but directed NERC to include in the Reliability Standards a three-step approach to addressing physical security risks.

Step One:  Risk Assessment and Identification of “Critical Facilities”

First, the FERC directed that the Reliability Standards “should require owners or operators of the Bulk-Power System to perform a risk assessment” to identify their “critical facilities,” i.e., those which, “if rendered inoperable or damaged, could have a critical impact on the operation of the interconnection through instability, uncontrolled separation or cascading failures.”  The FERC did not require a specific type of risk assessment, but stated that the methodologies used to determine “critical facilities” should be “based on objective analysis, technical expertise, and experienced judgment.”  In addition, the Reliability Standards “should allow owners or operators to consider resilience of the grid in the risk assessment when identifying critical facilities, and the elements that make up those facilities, such as transformers that typically require significant time to repair or replace.”

Step Two:  Threat and Vulnerability Evaluation

Second, the FERC directed that the Reliability Standards should require owners or operators of “critical facilities” to evaluate potential threats and vulnerabilities to those facilities based on factors such as location, size, function, existing protections, and “attractiveness as a target.”  Thus, the FERC stated, the Reliability Standards should require owners or operators to tailor their threat and vulnerability evaluation “to the unique characteristics of the identified critical facilities and the type of attacks that can be realistically contemplated.”

Step Three:  Security Plans

Third, the FERC directed that the Reliability Standards should require owners or operators of critical facilities to develop, validate, and implement security plans “designed to protect against attacks to those . . . facilities based on the assessment of the potential threats and vulnerabilities to their physical security.”  The Reliability Standards “need not dictate specific steps an entity must take to protect against attacks,” but must require owners and operators of critical facilities to have plan that provides “an adequate level of protection against the potential physical threats and vulnerabilities they face.”

Confidentiality, Independent and Periodic Review, and Implementation

Because of the sensitive nature of the information related to all three steps, the FERC also required NERC to include in the proposed Reliability Standards a procedure to “ensure confidential treatment of sensitive or confidential information but still allow for the [FERC], NERC and the Regional Entities to review and inspect any information that is needed to ensure compliance with the Reliability Standards.”

In addition, the FERC noted that the risk assessments, threat and vulnerability evaluations, and security plans should be independently reviewed by an entity other than the owner or operator, such as the FERC, NERC, a Regional Entity, Reliability Coordinator, or other entity with appropriate expertise, and that the proposed Reliability Standards should require that all three “be periodically reevaluated and revised to ensure their continued effectiveness.”

The FERC did not impose an implementation timeline for the Reliability Standards, but required NERC to “develop an implementation plan that requires owners or operators of the Bulk-Power System to implement the Reliability Standards in a timely fashion, balancing the importance of protecting the Bulk-Power System from harm while giving the owners or operators adequate time to meaningfully implement the requirements.”

Commissioner Norris’s Concurrence and Concerns

In a separate statement, Commissioner Norris expressed support for the order, but noted several areas of concern.  First, Commissioner Norris noted that the procedural approach the FERC selected, which, due to the its ex parte rules, will limit communication and engagement between industry and the FERC, as well as the “uniquely expedited nature” of the standards development process, could weaken that process.  To mitigate these issues, Commissioner Norris encouraged broad participation in the NERC standards development process and the forthcoming FERC rulemaking proceeding.  Commissioner Norris also cautioned parties to “be mindful of the Commission’s expectation that the number of critical facilities identified will be relatively small compared to the number of facilities that comprise the Bulk-Power System and [to] strive for balance between the measures related to physical security and the costs for consumers.”

Second, Commissioner Norris expressed his concern regarding the sensitivity of information regarding the physical vulnerabilities of the power grid and urged Congress to expeditiously create a clearly-defined Freedom of Information Act exemption to facilitate the exchange of information important to the Reliability Standards development process among industry, the FERC, and NERC without fear of disclosure.

Third, Commissioner Norris expressed his concern that recent efforts to protect reliability have focused too narrowly on physical security.  Instead, Commissioner Norris argued, equal focus on and dedication of resources to other threats, including cyber-attacks, geomagnetic disturbances, electromagnetic pulses, and natural disasters, are necessary.

Finally, Commissioner Norris cautioned against overreaction to the widely-reported April 2013 attack on PG&E’s Metcalf Substation, which has received significant attention in recent months from legislators and regulators (as we discussed in prior posts available here, and here).  Specifically, Commissioner Norris noted that he remains concerned that “recent momentum will result in the electricity sector potentially spending billions of dollars erecting physical barriers to protect our grid infrastructure,” with “most if not all of those costs . . . passed through to ratepayers.”  Instead, Commissioner Norris believes that “the more prudent approach is to focus on building a smarter and more agile grid, incorporating better communication and coordination, to mitigate against the multiple forms of risks that we face,” as well as to “more readily integrate intermittent resources, increase demand-side management capabilities, enhance the competitiveness of the wholesale energy market and more.”

Potential Implications

Ultimately, the effect of the FERC’s order will depend on the outcomes of the NERC standards development process and FERC rulemaking proceeding.  For owners and operators of facilities that are part of the Bulk-Power System that already have assessed the risks to and vulnerabilities of their critical facilities and implemented protective measures, the Reliability Standards, as ultimately adopted, might not require significant further action or costs.  For other entities, the costs of compliance with the new Reliability Standards could be significant.  Either way, because of the expedited timeline for NERC to develop and propose the standards, NERC-registered entities should be sure to voice their concerns in the NERC and FERC proceedings.

Share This Insight

Previous Entries

Speaking Energy

October 24, 2025

On October 21, 2025, the U.S. Department of Energy (DOE) issued a final order (DOE/FECM Order No. 5264-A1) granting Venture Global CP2 LNG, LLC long-term authorization to export up to 1,446 billion cubic feet per year of domestically produced liquefied natural gas (LNG) from its Louisiana facility to countries without a free trade agreement with the United States (Non-FTA Countries). The final order follows a March 2025 Conditional Order,2 which issued while DOE was still completing its review of the agency’s 2024 LNG Export Study.3 The final order confirms that the project’s export volume and term authorization (through December 31, 2050) are unchanged, but provides for a three-year “make-up period” to allow export of any approved volume not shipped during the original term.

...

Read More

Speaking Energy

October 9, 2025

On October 1, 2025, the Federal Energy Regulatory Commission (FERC or the Commission) issued Order No. 914 amending certain Commission regulations to incorporate a conditional sunset date in compliance with the Trump administration’s April 2025 Executive Order, “Zero-Based Regulatory Budgeting to Unleash American Energy” (the EO).

...

Read More

Speaking Energy

October 8, 2025

Akin is pleased to serve as a gold sponsor for Infocast’s Energy Independence Summit in Houston, October 21-23. Energy partner Charlie Ofner will moderate the Macroeconomics of Domestic Energy Independence panel, projects & energy transition partner Shariff Barakat will lead Opportunities in US Manufacturing: How Big, How Fast, How FEOC?, and counsel Taha Qureshi will guide the discussion on Cornerstones for Energy Independence: Investing in Grid Security & Cybersecurity.

...

Read More

Speaking Energy

October 6, 2025

As of October 6, 2025, the Federal Energy Regulatory Commission (FERC) continues to operate despite the lapse in appropriations that resulted in a government shutdown on October 1, 2025. While FERC receives appropriations from Congress, it primarily is self-funded through fees and charges obtained from the industries it regulates, offsetting its total costs. Hence, during prior government shutdowns in 2018 and 2013, the agency was able to continue operations. However, FERC published a plan for operating in the event of a lapse in appropriations on September 30, 2025, available here

...

Read More

Speaking Energy

September 8, 2025

On September 4, 2025, the Senate Energy and Natural Resources Committee convened a hearing to consider the nominations of Laura Swett and David LaCerte to serve as commissioners at the Federal Energy Regulatory Commission (FERC or Commission). Swett is a former FERC Staff that served as legal and policy advisor to former FERC Chairman Kevin McIntyre and Commission Bernard McNamee. LaCerte is an attorney in private practice that previously held positions at the Chemical Safety and Hazard Investigation Board and the Louisiana Department of Veterans Affairs.

...

Read More

Speaking Energy

September 9, 2025

On August 29, 2025, Christopher Wright, the Secretary of the U.S. Department of Energy (DOE) submitted a proposal to the Federal Energy Regulatory Commission (FERC) under section 403 of the Department of Energy Organization Act (DOE Organization Act), asking that FERC terminate its long-running proceeding in Docket No. PL18-1, which addresses proposed updates to its policy statement on the Certification of New Interstate Natural Gas Facilities. The docket resulted in a draft policy statement that has never been finalized, nor relied upon by FERC in a published order, but would require FERC to consider environmental impacts and potential mitigation prior to making a public interest determination under the Natural Gas Act (NGA). The Secretary asks FERC to rescind the draft policy statement in its entirety to remove any uncertainty in gas infrastructure development. Rescission would require FERC to initiate a new docket and develop a new record should it want to reinitiate similar policy changes in the future.

...

Read More

Speaking Energy

August 15, 2025

On August 8, 2025, the Federal Energy Regulatory Commission (FERC) issued an enforcement order in Skye MS, LLC (Skye) and levied a $45,000 civil penalty on an intrastate pipeline operator in Mississippi, resolving an investigation into the operator’s violations of section 311 (Section 311) of the Natural Gas Policy Act (NGPA). FERC faulted the operator for providing a Section 311 transportation service without timely filing a Statement of Operating Conditions (SOC) and obtaining FERC’s approval for the transportation rates. Section 311 permits intrastate pipelines to transport interstate gas “on behalf of” interstate pipelines without becoming subject to FERC’s more extensive Natural Gas Act (NGA) jurisdiction, but requires the intrastate pipeline to have an SOC stating the rates and terms and conditions of service on file with FERC within 30 days of providing the interstate service. Under the NGPA, Section 311 rates must be “fair and equitable” and approved by FERC. In Skye, FERC stated that the operator began providing Section 311 service on certain pipeline segments in Mississippi in May 2023, following their acquisition from another Section 311 operator, but did not file an SOC with FERC until April 2025. The order ties the penalty to the approximately two-year delay between commencement of the Section 311 service and the SOC filing date. The pipeline operator was also ordered to provide an annual compliance report and to abide by additional verification requirements related to the filing of its FERC Form No. 549D, the Quarterly Transportation & Storage Report for Intrastate Natural Gas and Hinshaw Pipelines.

...

Read More

Speaking Energy

August 6, 2025

In Sierra Club v. FERC, No. 24-1199 (D.C. Cir. Aug. 1, 2025), the U.S. Court of Appeals for the District of Columbia Circuit (D.C. Circuit) upheld the Federal Energy Regulatory Commission’s (FERC) approval of a 1,000-foot natural gas pipeline segment crossing the United States-Mexico border (the Border Pipeline) under section 3 of the Natural Gas Act (NGA), rejecting environmental groups’ challenges that FERC improperly limited its analysis under both the NGA and the National Environmental Policy Act (NEPA), as related to a 155-mile intrastate “Connector Pipeline” constructed upstream of the Border Pipeline in Texas.

...

Read More

© 2025 Akin Gump Strauss Hauer & Feld LLP. All rights reserved. Attorney advertising. This document is distributed for informational use only; it does not constitute legal advice and should not be used as such. Prior results do not guarantee a similar outcome. Akin is the practicing name of Akin Gump LLP, a New York limited liability partnership authorized and regulated by the Solicitors Regulation Authority under number 267321. A list of the partners is available for inspection at Eighth Floor, Ten Bishops Square, London E1 6EG. For more information about Akin Gump LLP, Akin Gump Strauss Hauer & Feld LLP and other associated entities under which the Akin Gump network operates worldwide, please see our Legal Notices page.