FERC Issues Notice of Proposed Rulemaking Aimed at Expanding Data Breach Reporting Obligations
Time 2 Minute Read

On December 21, 2017, the Federal Energy Regulatory Commission (“FERC”) issued a Notice of Proposed Rulemaking (“NOPR”) aimed at expanding mandatory reporting obligations in relation to cybersecurity incidents. In particular, FERC’s NOPR would direct the North American Electric Reliability Corporation (“NERC”) to develop modifications to certain Critical Infrastructure Protection (“CIP”) Reliability Standards so that those standards require mandatory reporting of cybersecurity incidents that compromise or attempt to compromise a responsible entity’s Electronic Security Perimeter (“ESP”) or associated Electronic Access Control or Monitoring Systems.

Currently, the CIP Reliability Standards require cybersecurity incidents to be reported only if they have actually disrupted one or more reliability tasks, so unsuccessful attempts to penetrate an ESP— or successful attempts that do not disrupt reliability tasks—would not need to be reported. FERC’s staff noted in the presentation of the NOPR that the existing reporting threshold for cybersecurity incidents “may understate the true scope of cyber-related threats facing the bulk electric system,” citing the fact that there were zero reported cybersecurity incidents in either 2015 or 2016 under the current reporting requirements. This lack of reported cybersecurity incidents stands in contrast with the 59 cybersecurity incidents within the Energy Sector to which the Department of Homeland Security responded in 2016 alone.

In addition to broadening the scope of the mandatory reporting requirements, the NOPR also seeks to improve the quality of the reports themselves by specifying the information that is required to be included in cybersecurity incident reports in an effort to facilitate comparative analysis. NERC would also be required to file with FERC an anonymized, aggregated annual public summary of the reports.

Comments on the NOPR must be filed with FERC within 60 days after it is published in the Federal Register.

You May Also Be Interested In

Time 3 Minute Read

Immediately prior to the lapse in funding on October 1, Department of Veterans Affairs (VA) and the Department of Homeland Security (DHS) released information on their contingency plans during the impending government shutdown, providing guidance to federal contractors.

Time 8 Minute Read

On October 23, 2025, the Secretary of Energy, pursuant to his authority under section 403 of the Department of Energy Organization Act, directed the Federal Energy Regulatory Commission to initiate rulemaking procedures and consider an advance notice of proposed rulemaking that sets forth potential reforms to expedite and facilitate the interconnection of “large loads,” notably data centers, to the interstate transmission system.

Time 9 Minute Read

On September 30, 2025, the U.S. Court of Appeals for the D.C. Circuit (D.C. Circuit) issued Sierra Club v. FERC, which upheld the Federal Energy Regulatory Commission’s (FERC) authorization of a 32-mile pipeline that will supply natural gas to a Tennessee Valley Authority (TVA) project at which TVA is replacing a coal-fired power unit with a natural gas turbine. The opinion is significant because the D.C. Circuit recognized, for the first time, that its controversial Sabal Trail opinion was abrogated by the Supreme Court’s recent decision in Seven County Infrastructure Coalition v. Eagle County, Colorado.

Time 3 Minute Read

On October 1, 2025, the Federal Energy Regulatory Commission issued a direct final rule inserting a conditional sunset date into certain regulations in response to Executive Order 14270, “Zero-Based Regulatory Budgeting to Unleash American Energy.”

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page