Title: New Opportunities for Boosting Grid Security
Speakers: Jennifer Panahi and Miles Kiger
Jennifer Panahi (00:07):
Good morning, Miles. Thanks for sitting down with me to talk about cybersecurity issues at FERC.
Miles Kiger (00:12):
Thanks so much, Jennifer. I’m energized to be here to talk about FERC’s recent cybersecurity rate incentives rule. But before we get there, would you mind telling us a little bit about why cybersecurity is an important policy priority at the commission right now?
Jennifer Panahi (00:26):
Sure. As you know, in recent years, cybersecurity threats against the electric grid have been increasing. And in 2020, SolarWinds Orion experienced a cyber attack, which was quite disruptive to the grid. Chairman Phillips has made cybersecurity a primary policy goal as part of an overall reliability effort. And to that end, this year the commission has issued directives to NERC to develop new cybersecurity standards regarding internal network security monitoring and supply chain risk monitoring as well. So can you tell me a little bit more about the final rule?
Miles Kiger (01:03):
Thanks, Jennifer, for that background on the importance of cybersecurity to the commission right now. So one way that the commission wants to incentivize utilities to take a more enhanced cybersecurity posture is to provide rate incentives for specific investments that a utility would make in advanced cybersecurity technology. That’s the basic gist of the rate incentives final rule — FERC wants to incentivize utilities to enhance their cybersecurity posture. And it’s willing to give utilities a little bit more of a return on some of those expenses, assuming that those utilities comply with FERC’s eligibility requirements in order to move the ball forward in terms of cybersecurity protection.
Jennifer Panahi (01:47):
Great. So can you explain a little bit more exactly what the final rule says?
Miles Kiger (01:52):
So what FERC is proposing to do is to offer public utilities and non-public utilities alike rate incentives for investments in advanced cybersecurity technology and participation in threat information sharing programs.
Jennifer Panahi (02:06):
What’s the primary incentive that FERC has adopted?
Miles Kiger (02:09):
So in its proposed rule, FERC had considered a return on equity adder, a regulatory asset incentive, and other performance-based rate-making treatments as proposed incentives, but in its final rule, it landed only on the regulatory asset incentive and declined to adopt the ROE adder and the performance-based rates. And what that means is essentially eligible cybersecurity expenses can be capitalized by the utility and they can then earn a return on those eligible and approved expenses.
Jennifer Panahi (02:39):
So how do utilities take advantage of these rate incentives?
Miles Kiger (02:42):
In order to take advantage of these rate incentives, public utilities will have to come and make a filing before the commission, either to modify their formula rates or to make a single issue rate filing if they are stated rates.
Jennifer Panahi (02:56):
Got it. And I heard that there was a sunsetting provision in the final rule, is that right?
Miles Kiger (03:01):
Yes, that is correct. So a utility that comes in to seek a regulatory asset incentive, and assuming it is approved by the commission, they would only be able to defer and then amortize those eligible cybersecurity investments over five years. But there’s one critical exception to that, and that’s for the participation in threat information sharing programs. I had mentioned before about the Department of Energy’s CRISP program. So FERC wants utilities to participate in that program so much so that it’s not going to create a sunsetting provision associated with participation in that program. So the eligible expenses associated with DOE CRISP could be capitalized and a return could be earned on it in perpetuity, or until FERC changes its mind.
Jennifer Panahi (03:46):
Great. And I think the final rule made a big deal about these investments having to be voluntary. Is that right?
Miles Kiger (03:52):
Yes, that’s a great and critical point. In order to satisfy FERC’s eligibility criteria, these investments must be voluntary. And what that really means in practice is that if a reliability standard is already mandatory, then the cybersecurity expenses associated with those reliability programs would not be eligible for rate incentive treatment. And that makes sense because an incentive is meant to try and incentivize a utility to do something — in this case, to make voluntary investments in eligible cybersecurity investments to improve cybersecurity generally.
Jennifer Panahi (04:26):
Great. What happens with those investments made in support of a cybersecurity rule that has been approved but hasn’t become enforceable yet?
Miles Kiger (04:35):
That’s another great point. As I mentioned before, there are two areas of low-hanging fruit here with respect to this new final rule. The first being the gap period between the time that a new reliability standard gets approved by the commission and the time in which it becomes mandatory and enforceable. FERC expects utilities to file after that rule is approved for regulatory asset incentive treatment. And then the utility would be able to capitalize those eligible expenses until the time that that reliability standard becomes mandatory. Once it’s no longer voluntary, then the incentive treatment would no longer be permitted.
Jennifer Panahi (05:15):
Great. Well, it sounds like the final rule can offer a lot of opportunities for electric utilities to take advantage of these rate treatments. These might seem like small dollar numbers in isolation, but when you think about the rate at which FERC is requiring new cybersecurity standards to be issued by NERC, this could really add up.
Miles Kiger (05:33):
I completely agree, Jennifer. And one important thing to note for utilities: while the final rule is wonky and a little bit complicated and has lots of details and different mechanics, there is an opportunity for them to come to the commission and get rate incentive treatment for investments in cybersecurity technology that they’re already making and may have to make as a result of new cybersecurity rules that have either been approved recently by the commission or will be approved in the near future.
Jennifer Panahi (06:03):
Great. Well, it’s a lot of exciting stuff happening at FERC. Thanks for meeting with me today.
Miles Kiger (06:08):
Thanks so much, Jennifer. It’s great talking about cybersecurity rate incentives with you.
Jennifer Panahi (06:11):
Great.
Copyright, Troutman Pepper Locke LLP. These recorded materials are designed for educational purposes only. This video is not legal advice and does not create an attorney-client relationship. The views and opinions expressed in this podcast are solely those of the individual participants. Troutman does not make any representations or warranties, express or implied, regarding the contents of this podcast. Information on previous case results does not guarantee a similar future result. Users of this video may save and use the video only for personal or other non-commercial, educational purposes. No other use, including, without limitation, reproduction, retransmission or editing of this video may be made without the prior written permission of Troutman Pepper Locke. If you have any questions, please contact us at troutman.com.
DISCLAIMER: This transcript was generated using artificial intelligence technology and may contain inaccuracies or errors. The transcript is provided “as is,” with no warranty as to the accuracy or reliability. Please listen to the video for complete and accurate content. You may contact us to ask questions or to provide feedback if you believe that something is inaccurately transcribed.