FERC Staff Provides “Lessons Learned” from Critical Infrastructure Protection Reliability Standard Audits

Nov 5, 2021

Reading Time : 2 min

The report is based on nonpublic audits of NERC “registered entities”1 subject to the CIP reliability standards that were conducted by FERC’s Office of Electric Reliability and Office of Enforcement, in collaboration with NERC and its regional reliability entities. In addition, while FERC’s Office of Energy Infrastructure Security (OEIS) was not involved in the audits, its Office of Electric Reliability “consulted with OEIS” in preparing the report. OEIS is responsible for “identification and implementation of best practices to address current and emerging defense and mitigation strategies for advanced cyber and physical threats to not only the Bulk-Power System but all energy infrastructure” under FERC’s jurisdiction.

This year, FERC staff “found that while most of the cybersecurity protection processes and procedures adopted by the registered entities met the mandatory requirements of the CIP Reliability Standards, there were also potential compliance infractions.” Such infractions can create significant risk and result in penalties that vary depending on the severity of the risk they present. FERC staff “also identified practices not required by the CIP Reliability Standards that could improve security.” The report includes those as “voluntary cyber security recommendations.” These recommendations are relevant not only for registered entities, but “may be generally beneficial to the utility-based cybersecurity community” to improve the security of the bulk electric system.

The report’s overview of “lessons learned” lists 14 principal recommendations, including:

  • “Enhanc[ing] policies and procedures to include evaluation of Cyber Asset misuse and degradation during asset categorization.”2
  • “Properly document[ing] and implement[ing] policies, procedures and controls for low-impact transient cyber assets.”
  • “Enhanc[ing] recovery and testing plans to include a sample of any offsite backup images in the representative sample of data used to test the restoration of bulk-electric system cyber systems.”
  • “Improv[ing] vulnerability assessments to include credential-based scans of cyber assets.”
  • “Enhanc[ing] internal compliance and controls programs to include control documentation processes and associated procedures pertaining to compliance with the CIP Reliability Standards.”

For each of its 14 recommendations, the report discusses the related audit findings and ties each recommendation to the specific CIP reliability standard(s) and requirement(s) to which it applies. The report also provides the “lessons learned” from four prior annual reports, illustrating how FERC staff’s audit findings and recommendations have evolved over time. This year’s report highlights FERC’s and NERC’s ongoing focus on registered entities’ compliance with the CIP reliability standards and should be required reading for both registered entities and other owners and operators of assets on the U.S. electric grid in connection with the development and implementation of their cybersecurity programs.


1 As FERC staff explained in the report, “[a]ll Bulk-Power System users, owners and operators are required to register with NERC and, once registered, are commonly referred to as ‘registered entities.’”

2The NERC Glossary defines “Cyber Assets” as “programmable electronic devices, including the hardware, software, and data in those devices.”

 

Share This Insight

Previous Entries

Speaking Energy

March 10, 2026

Federal energy regulators are assuming expanded roles as the administration prioritizes energy dominance and infrastructure development to meet unprecedented power demand. FERC Chairman Laura Swett has vowed to expedite data center interconnections while addressing jurisdictional challenges, warning that unmet electricity demand could drive data centers abroad and create national security risks. The agency is processing pipeline applications faster than in prior years and considering blanket authorizations for certain LNG and hydroelectric projects to streamline approvals. 

Pipeline projects previously stalled by Clean Water Act permits are being revitalized, particularly in northeastern states where historically high electricity prices have increased openness to natural gas infrastructure. The Department of Energy is expanding its emergency authority to require retention of generation resources and has granted major LNG export approvals, signaling commitment to expanding U.S. export capacity under a streamlined framework that deprioritizes climate considerations.  

The Administration is bullish on the opportunities for the U.S. energy industry in Venezuela and eager to support companies willing to navigate the political risk inherent in the operations at the moment. Early meetings with President Trump and industry leaders showed the path forward may be longer and more complex than anticipated by the President. 

As permitting reforms advance and the pendulum swings toward fossil fuel favorability, the regulatory and policy landscape is fundamentally reshaping energy infrastructure development timelines and investment opportunities. 

Oil & Gas in 2026: Energy Policy & Regulation 

Delve into the complete regulatory & policy outlook at our Oil & Gas in 2026 report.

...

Read More

Speaking Energy

March 3, 2026

Macroeconomic turbulence and volatile commodity markets significantly influenced oil & gas M&A activity throughout 2025, with deals showing renewed momentum only in the year's second half.  

...

Read More

Speaking Energy

February 24, 2026

On February 19, 2026, the Federal Energy Regulatory Commission (FERC) issued an order rescinding the soft price cap for bilateral spot market energy sales in the Western Electricity Coordinating Council (WECC) region.1 As previously covered, on July 15, 2025, FERC initiated a Federal Power Act Section 206 proceeding following the D.C. Circuit’s decision finding that FERC must apply the Mobile-Sierra public interest standard before ordering refunds for above-cap bilateral sales and vacating FERC’s orders requiring refunds for certain bilateral spot market transactions in the WECC region that exceeded the $1,000 MWh soft price cap.2 FERC’s Order follows through on the proposal it made last July to eliminate the WECCs soft price cap and marks a recognition that Western wholesale markets have evolved over the past two decades to become sufficiently competitive to render the soft price cap unnecessary.  

...

Read More

Speaking Energy

February 23, 2026

The oil & gas industry is experiencing a fundamental transformation in how companies access and deploy capital in 2026. Despite strong balance sheets and robust free cash flow generation, the sector is witnessing strategic shifts in funding sources and investment priorities that signal a new era of capital allocation.

...

Read More

© 2026 Akin Gump Strauss Hauer & Feld LLP. All rights reserved. Attorney advertising. This document is distributed for informational use only; it does not constitute legal advice and should not be used as such. Prior results do not guarantee a similar outcome. Akin is the practicing name of Akin Gump LLP, a New York limited liability partnership authorized and regulated by the Solicitors Regulation Authority under number 267321. A list of the partners is available for inspection at Eighth Floor, Ten Bishops Square, London E1 6EG. For more information about Akin Gump LLP, Akin Gump Strauss Hauer & Feld LLP and other associated entities under which the Akin Gump network operates worldwide, please see our Legal Notices page.