FERC Staff Provides “Lessons Learned” from Critical Infrastructure Protection Reliability Standard Audits

Nov 5, 2021

Reading Time : 2 min

The report is based on nonpublic audits of NERC “registered entities”1 subject to the CIP reliability standards that were conducted by FERC’s Office of Electric Reliability and Office of Enforcement, in collaboration with NERC and its regional reliability entities. In addition, while FERC’s Office of Energy Infrastructure Security (OEIS) was not involved in the audits, its Office of Electric Reliability “consulted with OEIS” in preparing the report. OEIS is responsible for “identification and implementation of best practices to address current and emerging defense and mitigation strategies for advanced cyber and physical threats to not only the Bulk-Power System but all energy infrastructure” under FERC’s jurisdiction.

This year, FERC staff “found that while most of the cybersecurity protection processes and procedures adopted by the registered entities met the mandatory requirements of the CIP Reliability Standards, there were also potential compliance infractions.” Such infractions can create significant risk and result in penalties that vary depending on the severity of the risk they present. FERC staff “also identified practices not required by the CIP Reliability Standards that could improve security.” The report includes those as “voluntary cyber security recommendations.” These recommendations are relevant not only for registered entities, but “may be generally beneficial to the utility-based cybersecurity community” to improve the security of the bulk electric system.

The report’s overview of “lessons learned” lists 14 principal recommendations, including:

  • “Enhanc[ing] policies and procedures to include evaluation of Cyber Asset misuse and degradation during asset categorization.”2
  • “Properly document[ing] and implement[ing] policies, procedures and controls for low-impact transient cyber assets.”
  • “Enhanc[ing] recovery and testing plans to include a sample of any offsite backup images in the representative sample of data used to test the restoration of bulk-electric system cyber systems.”
  • “Improv[ing] vulnerability assessments to include credential-based scans of cyber assets.”
  • “Enhanc[ing] internal compliance and controls programs to include control documentation processes and associated procedures pertaining to compliance with the CIP Reliability Standards.”

For each of its 14 recommendations, the report discusses the related audit findings and ties each recommendation to the specific CIP reliability standard(s) and requirement(s) to which it applies. The report also provides the “lessons learned” from four prior annual reports, illustrating how FERC staff’s audit findings and recommendations have evolved over time. This year’s report highlights FERC’s and NERC’s ongoing focus on registered entities’ compliance with the CIP reliability standards and should be required reading for both registered entities and other owners and operators of assets on the U.S. electric grid in connection with the development and implementation of their cybersecurity programs.


1 As FERC staff explained in the report, “[a]ll Bulk-Power System users, owners and operators are required to register with NERC and, once registered, are commonly referred to as ‘registered entities.’”

2The NERC Glossary defines “Cyber Assets” as “programmable electronic devices, including the hardware, software, and data in those devices.”

 

Share This Insight

Previous Entries

Speaking Energy

July 8, 2026

On June 18, 2026, the Federal Energy Regulatory Commission (FERC or the Commission) issued an order to ISO New England Inc. (ISO-NE) directing ISO-NE and ISO-NE participating transmission owners to show cause as to why ISO-NE’s tariff should not be found to be unjust and unreasonable (ISO New England Inc., 195 FERC ¶ 61,215 (2026) (Order)) because it fails to sufficiently:

...

Read More

Speaking Energy

July 7, 2026

On June 29, 2026, the Supreme Court granted a petition for certiorari in Leonard Hoffmann v. WBI Energy Transmission, Inc. (Hoffmann), which presents the question whether section 7 of the Natural Gas Act (NGA) requires pipeline companies using federal eminent domain authority to pay landowners’ attorney’s fees in states where landowners can recover those fees under state law. In the decision giving rise to the Supreme Court’s review, the U.S. Court of Appeals for the Eighth Circuit held that a group of ranchers were not entitled to recover their $383,300 in attorney’s fees incurred while negotiating their compensation—creating a circuit split with four other courts of appeals. Hoffmann will be heard during the Court’s October 2026 Term, and marks the second time in five years that the Court has agreed to interpret NGA section 7.

...

Read More

Speaking Energy

July 6, 2026

On June 29, 2026, the United States Supreme Court issued Trump v. Slaughter, fundamentally reshaping presidential removal authority over independent regulatory agencies. The decision overruled a 90-year-old precedent established in Humphrey’s Executor v. United States, which had upheld the constitutionality of commissioner removal protections in the Federal Trade Commission Act (FTC Act). As written, the FTC Act permits a commissioner’s removal “only for inefficiency, neglect of duty, or malfeasance in office.” In Slaughter, the Court was asked to reevaluate this standard following the President’s removal of a Democratic-appointed FTC commissioner from office in 2025 without cause. Finding for the President, the Court held that removal was permissible because the FTC Act’s for-cause removal protections for commissioners violate the separation of powers, specifically, the President’s removal power under Article II. The Court explained that the FTC exercises executive power because it promulgates binding rules, investigates and enforces those rules through administrative adjudications, and brings civil enforcement actions in federal court. It found that because it exercises these executive powers, its commissioners “must therefore be controlled by the Chief Executive, in whom such power is vested.” While previous recent cases addressing the scope of the Removal Power, Seila Law LLC v. Consumer Financial Protection Bureau and Collins v. Yellen purported to preserve some kernel of Humphrey’s, the Court made clear that “[i]f anything more is left of Humphrey’s, we overrule it.”

...

Read More

Speaking Energy

June 25, 2026

On June 18, 2026, the Federal Energy Regulatory Commission (FERC or the Commission) issued an order to the California Independent System Operator Corporation (CAISO) directing CAISO and CAISO transmission owners to show cause as to why CAISO’s tariff should not be found to be unjust and unreasonable (California Indep. Sys. Operator Corp., 195 FERC ¶ 61,214 (2026) (the Order)) because it fails to sufficiently:

...

Read More

© 2026 Akin Gump Strauss Hauer & Feld LLP. All rights reserved. Attorney advertising. This document is distributed for informational use only; it does not constitute legal advice and should not be used as such. Prior results do not guarantee a similar outcome. Akin is the practicing name of Akin Gump LLP, a New York limited liability partnership authorized and regulated by the Solicitors Regulation Authority under number 267321. A list of the partners is available for inspection at Eighth Floor, Ten Bishops Square, London E1 6EG. For more information about Akin Gump LLP, Akin Gump Strauss Hauer & Feld LLP and other associated entities under which the Akin Gump network operates worldwide, please see our Legal Notices page.