SlideShare a Scribd company logo
1 of 4
Modernizing Physical Security and Incorporating Best Practices Into New Assets
 Interview with David Grubbs, Director, Regulatory Affairs and Compliance at City of Garland,
                                                                TX




                                As the Department of Homeland Security has reported, cyber
                                security threats to the utility industry are increasing in number
                                and sophistication. Because of this challenge, the North
                                American Reliability Corporation (NERC) is increasing the
                                Critical Infrastructure Protection (CIP) regulatory requirements to
                                ensure organizations and facilities are meeting basic standards
                                in this area.


marcus evans had the privilege to hear from David Grubbs before the upcoming Utility Cyber
Security & CIP Compliance Conference, January 15-17, 2013 in Atlanta, GA. Below he shares
with us his perspective on how CIP standards are affecting cyber security within electric utilities.
The responses below strictly reflect the views and beliefs of David Grubbs, and not necessarily
those of City of Garland, TX.




What are some of the newer efforts being utilized to protect the physical assets
of utilities?


David Grubbs: Electric utilities continue to improve both physical and cyber security efforts to
counter known and unknown threats. In physical security, many upgraded security features
have been added including: card access at many locations, electronic padlocks that require the
regular reauthorization of keys and can be set to ignore keys identified as lost, video monitoring,
fence tamper detection and motion sensors. The most important aspect of improving security is
properly training personnel and achieving a security mindset within the industry. The CIP
Standards make a start at this, but only include personnel with access the CIP Critical Cyber
Assets.


Can you elaborate on the benefits of applying CIP standards to non-critical
assets?


DG: The CIP standards are a good starting point for any security system. They are however,
inadequate to fully protect any asset. Security is achieved by a defense in depth. Much as an
onion has numerous layers, good security systems should have numerous layers of which the
CIP standards are only a few of the layers. Frequently, the best defenses are those no one
knows about. Unfortunately, at least through version 4, the CIP Standards are somewhat
prescriptive. Many of the security aspects of a facility, and even which facilities have security,
can be guessed because of the CIP standards. Beginning with version 5 of the CIP standards
the industry will have more flexibility to install the appropriate security for a facility rather than
specific security practices.


Why should utilities consider organizational security to be just as important as
safety?


DG: Security systems are inherently designed to keep the “bad guys” out. Excellent security
systems can easily be defeated when someone inadvertently leaves a door open or invites the
“bad guys” in. The most common ways of entering a system are by social engineering. Asking
innocent sounding questions, a hyperlink in an email that appears to be from your boss, or
getting someone to plug in a USB drive or CD are the easiest way to get into a secure system.
A second source of lost information is a lost laptop or the USB drive that contains sensitive
information.


The following article from Intelligent Utility,
http://www.intelligentutility.com/article/12/10/cyber-risk-conversation , explores
the potential motivation behind cyber attacks aimed at utilities in the format of a
hypothetical conversation between utility executives. If you had a chance to join
the conversation, what comments/counterarguments would you give?


DG: I have had several very similar conversations with industry executives across North
America. Different entities have differing risk profiles to the various threats identified in the
discussion. Certain companies may be more of a target to certain organizations, such as
environmental extremists, while others might be less so. There is some risk for all of these
threats to each of us. Some organizations, because of their small size, might believe they are
immune to such activities because no one knows they are there and theorize that someone
would not be interested in attacking them. By the same logic, an attacker might go after a
smaller organization believing their security is less organized than at a larger entity and easier
to penetrate, thus making a smaller entity a more attractive target. None of these is true in all
circumstances, but are potential considerations when designing a security system.


As someone who has attended marcus evans events in the past, what do you
think attendees can take away from this conference?


DG: There are three primary takeaways from a marcus evans conference. First is the
educational aspect. Attendees learn how other comparable companies are coping with the
issues; from compliance, to security, to organizational structure, to budgeting. Second, are the
relationships you build with the speakers and fellow participants. Being able to discuss ideas
with others, both during the conference and afterward, can give significant insight into issues.
Third, and perhaps most important, it gives you a chance to break out of a rut and do something
different. We are all guilty of continuing to do what we have been doing and as long as nothing
jolts us, we just keep on doing it. A conference, such as this, gives us the opportunity to review
our own programs in the light of the best practices of others. It allows us to refocus on the needs
of our organization and gives us a new enthusiasm for pursuing the ideas we developed at the
seminar.


Mr. Grubbs joined the City of Garland in 2002 and has held numerous positions within the City.
He is currently serving as the Director of Regulatory Affairs and Compliance reporting directly to
the Managing Director of the Electric Utility on Regulatory, Compliance and Transmission
Planning Issues. Immediate prior to joining Garland, Mr. Grubbs worked as a consultant
developing wind energy and compressed air energy storage generation units.


For more information, please contact Michele Westergaard, Senior Marketing Manager at 312-
540-3000 ext. 6625 or Michelew@marcusevansch.com.


About the Utility Cyber Security & CIP Compliance Conference
This unique event will take place in Atlanta, GA from January 15-17, 2013. Industry leaders
attending this event will benefit from a dynamic presentation format consisting of workshops,
panel discussions and case studies. Attendees will experience highly interactive conference
sessions, 10-15 minutes of Q&A time after each presentation, 4+ hours of networking and
exclusive online access to materials post-event.


About marcus evans
marcus evans conferences annually produce over 2,000 high quality events designed to
provide key strategic business information, best practice and networking opportunities for senior
industry decision-makers. Our global reach is utilized to attract over 30,000 speakers annually;
ensuring niche focused subject matter presented directly by practitioners and a diversity of
information to assist our clients in adopting best practice in all business disciplines.

More Related Content

Recently uploaded

Annual General Meeting Presentation Slides
Annual General Meeting Presentation SlidesAnnual General Meeting Presentation Slides
Annual General Meeting Presentation SlidesKeppelCorporation
 
8447779800, Low rate Call girls in New Ashok Nagar Delhi NCR
8447779800, Low rate Call girls in New Ashok Nagar Delhi NCR8447779800, Low rate Call girls in New Ashok Nagar Delhi NCR
8447779800, Low rate Call girls in New Ashok Nagar Delhi NCRashishs7044
 
8447779800, Low rate Call girls in Shivaji Enclave Delhi NCR
8447779800, Low rate Call girls in Shivaji Enclave Delhi NCR8447779800, Low rate Call girls in Shivaji Enclave Delhi NCR
8447779800, Low rate Call girls in Shivaji Enclave Delhi NCRashishs7044
 
Cybersecurity Awareness Training Presentation v2024.03
Cybersecurity Awareness Training Presentation v2024.03Cybersecurity Awareness Training Presentation v2024.03
Cybersecurity Awareness Training Presentation v2024.03DallasHaselhorst
 
Islamabad Escorts | Call 03070433345 | Escort Service in Islamabad
Islamabad Escorts | Call 03070433345 | Escort Service in IslamabadIslamabad Escorts | Call 03070433345 | Escort Service in Islamabad
Islamabad Escorts | Call 03070433345 | Escort Service in IslamabadAyesha Khan
 
(Best) ENJOY Call Girls in Faridabad Ex | 8377087607
(Best) ENJOY Call Girls in Faridabad Ex | 8377087607(Best) ENJOY Call Girls in Faridabad Ex | 8377087607
(Best) ENJOY Call Girls in Faridabad Ex | 8377087607dollysharma2066
 
MAHA Global and IPR: Do Actions Speak Louder Than Words?
MAHA Global and IPR: Do Actions Speak Louder Than Words?MAHA Global and IPR: Do Actions Speak Louder Than Words?
MAHA Global and IPR: Do Actions Speak Louder Than Words?Olivia Kresic
 
Flow Your Strategy at Flight Levels Day 2024
Flow Your Strategy at Flight Levels Day 2024Flow Your Strategy at Flight Levels Day 2024
Flow Your Strategy at Flight Levels Day 2024Kirill Klimov
 
Pitch Deck Teardown: Geodesic.Life's $500k Pre-seed deck
Pitch Deck Teardown: Geodesic.Life's $500k Pre-seed deckPitch Deck Teardown: Geodesic.Life's $500k Pre-seed deck
Pitch Deck Teardown: Geodesic.Life's $500k Pre-seed deckHajeJanKamps
 
Ten Organizational Design Models to align structure and operations to busines...
Ten Organizational Design Models to align structure and operations to busines...Ten Organizational Design Models to align structure and operations to busines...
Ten Organizational Design Models to align structure and operations to busines...Seta Wicaksana
 
Global Scenario On Sustainable and Resilient Coconut Industry by Dr. Jelfina...
Global Scenario On Sustainable  and Resilient Coconut Industry by Dr. Jelfina...Global Scenario On Sustainable  and Resilient Coconut Industry by Dr. Jelfina...
Global Scenario On Sustainable and Resilient Coconut Industry by Dr. Jelfina...ictsugar
 
Call Girls In Radisson Blu Hotel New Delhi Paschim Vihar ❤️8860477959 Escorts...
Call Girls In Radisson Blu Hotel New Delhi Paschim Vihar ❤️8860477959 Escorts...Call Girls In Radisson Blu Hotel New Delhi Paschim Vihar ❤️8860477959 Escorts...
Call Girls In Radisson Blu Hotel New Delhi Paschim Vihar ❤️8860477959 Escorts...lizamodels9
 
The CMO Survey - Highlights and Insights Report - Spring 2024
The CMO Survey - Highlights and Insights Report - Spring 2024The CMO Survey - Highlights and Insights Report - Spring 2024
The CMO Survey - Highlights and Insights Report - Spring 2024christinemoorman
 
International Business Environments and Operations 16th Global Edition test b...
International Business Environments and Operations 16th Global Edition test b...International Business Environments and Operations 16th Global Edition test b...
International Business Environments and Operations 16th Global Edition test b...ssuserf63bd7
 
Call US-88OO1O2216 Call Girls In Mahipalpur Female Escort Service
Call US-88OO1O2216 Call Girls In Mahipalpur Female Escort ServiceCall US-88OO1O2216 Call Girls In Mahipalpur Female Escort Service
Call US-88OO1O2216 Call Girls In Mahipalpur Female Escort Servicecallgirls2057
 
Keppel Ltd. 1Q 2024 Business Update Presentation Slides
Keppel Ltd. 1Q 2024 Business Update  Presentation SlidesKeppel Ltd. 1Q 2024 Business Update  Presentation Slides
Keppel Ltd. 1Q 2024 Business Update Presentation SlidesKeppelCorporation
 
8447779800, Low rate Call girls in Tughlakabad Delhi NCR
8447779800, Low rate Call girls in Tughlakabad Delhi NCR8447779800, Low rate Call girls in Tughlakabad Delhi NCR
8447779800, Low rate Call girls in Tughlakabad Delhi NCRashishs7044
 
Organizational Structure Running A Successful Business
Organizational Structure Running A Successful BusinessOrganizational Structure Running A Successful Business
Organizational Structure Running A Successful BusinessSeta Wicaksana
 
APRIL2024_UKRAINE_xml_0000000000000 .pdf
APRIL2024_UKRAINE_xml_0000000000000 .pdfAPRIL2024_UKRAINE_xml_0000000000000 .pdf
APRIL2024_UKRAINE_xml_0000000000000 .pdfRbc Rbcua
 

Recently uploaded (20)

Annual General Meeting Presentation Slides
Annual General Meeting Presentation SlidesAnnual General Meeting Presentation Slides
Annual General Meeting Presentation Slides
 
8447779800, Low rate Call girls in New Ashok Nagar Delhi NCR
8447779800, Low rate Call girls in New Ashok Nagar Delhi NCR8447779800, Low rate Call girls in New Ashok Nagar Delhi NCR
8447779800, Low rate Call girls in New Ashok Nagar Delhi NCR
 
8447779800, Low rate Call girls in Shivaji Enclave Delhi NCR
8447779800, Low rate Call girls in Shivaji Enclave Delhi NCR8447779800, Low rate Call girls in Shivaji Enclave Delhi NCR
8447779800, Low rate Call girls in Shivaji Enclave Delhi NCR
 
Cybersecurity Awareness Training Presentation v2024.03
Cybersecurity Awareness Training Presentation v2024.03Cybersecurity Awareness Training Presentation v2024.03
Cybersecurity Awareness Training Presentation v2024.03
 
Islamabad Escorts | Call 03070433345 | Escort Service in Islamabad
Islamabad Escorts | Call 03070433345 | Escort Service in IslamabadIslamabad Escorts | Call 03070433345 | Escort Service in Islamabad
Islamabad Escorts | Call 03070433345 | Escort Service in Islamabad
 
(Best) ENJOY Call Girls in Faridabad Ex | 8377087607
(Best) ENJOY Call Girls in Faridabad Ex | 8377087607(Best) ENJOY Call Girls in Faridabad Ex | 8377087607
(Best) ENJOY Call Girls in Faridabad Ex | 8377087607
 
MAHA Global and IPR: Do Actions Speak Louder Than Words?
MAHA Global and IPR: Do Actions Speak Louder Than Words?MAHA Global and IPR: Do Actions Speak Louder Than Words?
MAHA Global and IPR: Do Actions Speak Louder Than Words?
 
Corporate Profile 47Billion Information Technology
Corporate Profile 47Billion Information TechnologyCorporate Profile 47Billion Information Technology
Corporate Profile 47Billion Information Technology
 
Flow Your Strategy at Flight Levels Day 2024
Flow Your Strategy at Flight Levels Day 2024Flow Your Strategy at Flight Levels Day 2024
Flow Your Strategy at Flight Levels Day 2024
 
Pitch Deck Teardown: Geodesic.Life's $500k Pre-seed deck
Pitch Deck Teardown: Geodesic.Life's $500k Pre-seed deckPitch Deck Teardown: Geodesic.Life's $500k Pre-seed deck
Pitch Deck Teardown: Geodesic.Life's $500k Pre-seed deck
 
Ten Organizational Design Models to align structure and operations to busines...
Ten Organizational Design Models to align structure and operations to busines...Ten Organizational Design Models to align structure and operations to busines...
Ten Organizational Design Models to align structure and operations to busines...
 
Global Scenario On Sustainable and Resilient Coconut Industry by Dr. Jelfina...
Global Scenario On Sustainable  and Resilient Coconut Industry by Dr. Jelfina...Global Scenario On Sustainable  and Resilient Coconut Industry by Dr. Jelfina...
Global Scenario On Sustainable and Resilient Coconut Industry by Dr. Jelfina...
 
Call Girls In Radisson Blu Hotel New Delhi Paschim Vihar ❤️8860477959 Escorts...
Call Girls In Radisson Blu Hotel New Delhi Paschim Vihar ❤️8860477959 Escorts...Call Girls In Radisson Blu Hotel New Delhi Paschim Vihar ❤️8860477959 Escorts...
Call Girls In Radisson Blu Hotel New Delhi Paschim Vihar ❤️8860477959 Escorts...
 
The CMO Survey - Highlights and Insights Report - Spring 2024
The CMO Survey - Highlights and Insights Report - Spring 2024The CMO Survey - Highlights and Insights Report - Spring 2024
The CMO Survey - Highlights and Insights Report - Spring 2024
 
International Business Environments and Operations 16th Global Edition test b...
International Business Environments and Operations 16th Global Edition test b...International Business Environments and Operations 16th Global Edition test b...
International Business Environments and Operations 16th Global Edition test b...
 
Call US-88OO1O2216 Call Girls In Mahipalpur Female Escort Service
Call US-88OO1O2216 Call Girls In Mahipalpur Female Escort ServiceCall US-88OO1O2216 Call Girls In Mahipalpur Female Escort Service
Call US-88OO1O2216 Call Girls In Mahipalpur Female Escort Service
 
Keppel Ltd. 1Q 2024 Business Update Presentation Slides
Keppel Ltd. 1Q 2024 Business Update  Presentation SlidesKeppel Ltd. 1Q 2024 Business Update  Presentation Slides
Keppel Ltd. 1Q 2024 Business Update Presentation Slides
 
8447779800, Low rate Call girls in Tughlakabad Delhi NCR
8447779800, Low rate Call girls in Tughlakabad Delhi NCR8447779800, Low rate Call girls in Tughlakabad Delhi NCR
8447779800, Low rate Call girls in Tughlakabad Delhi NCR
 
Organizational Structure Running A Successful Business
Organizational Structure Running A Successful BusinessOrganizational Structure Running A Successful Business
Organizational Structure Running A Successful Business
 
APRIL2024_UKRAINE_xml_0000000000000 .pdf
APRIL2024_UKRAINE_xml_0000000000000 .pdfAPRIL2024_UKRAINE_xml_0000000000000 .pdf
APRIL2024_UKRAINE_xml_0000000000000 .pdf
 

Featured

2024 State of Marketing Report – by Hubspot
2024 State of Marketing Report – by Hubspot2024 State of Marketing Report – by Hubspot
2024 State of Marketing Report – by HubspotMarius Sescu
 
Everything You Need To Know About ChatGPT
Everything You Need To Know About ChatGPTEverything You Need To Know About ChatGPT
Everything You Need To Know About ChatGPTExpeed Software
 
Product Design Trends in 2024 | Teenage Engineerings
Product Design Trends in 2024 | Teenage EngineeringsProduct Design Trends in 2024 | Teenage Engineerings
Product Design Trends in 2024 | Teenage EngineeringsPixeldarts
 
How Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental HealthHow Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental HealthThinkNow
 
AI Trends in Creative Operations 2024 by Artwork Flow.pdf
AI Trends in Creative Operations 2024 by Artwork Flow.pdfAI Trends in Creative Operations 2024 by Artwork Flow.pdf
AI Trends in Creative Operations 2024 by Artwork Flow.pdfmarketingartwork
 
PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024Neil Kimberley
 
Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)contently
 
How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024Albert Qian
 
Social Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsSocial Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsKurio // The Social Media Age(ncy)
 
Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024Search Engine Journal
 
5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summarySpeakerHub
 
ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd Clark Boyd
 
Getting into the tech field. what next
Getting into the tech field. what next Getting into the tech field. what next
Getting into the tech field. what next Tessa Mero
 
Google's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search IntentGoogle's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search IntentLily Ray
 
Time Management & Productivity - Best Practices
Time Management & Productivity -  Best PracticesTime Management & Productivity -  Best Practices
Time Management & Productivity - Best PracticesVit Horky
 
The six step guide to practical project management
The six step guide to practical project managementThe six step guide to practical project management
The six step guide to practical project managementMindGenius
 
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...RachelPearson36
 

Featured (20)

2024 State of Marketing Report – by Hubspot
2024 State of Marketing Report – by Hubspot2024 State of Marketing Report – by Hubspot
2024 State of Marketing Report – by Hubspot
 
Everything You Need To Know About ChatGPT
Everything You Need To Know About ChatGPTEverything You Need To Know About ChatGPT
Everything You Need To Know About ChatGPT
 
Product Design Trends in 2024 | Teenage Engineerings
Product Design Trends in 2024 | Teenage EngineeringsProduct Design Trends in 2024 | Teenage Engineerings
Product Design Trends in 2024 | Teenage Engineerings
 
How Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental HealthHow Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental Health
 
AI Trends in Creative Operations 2024 by Artwork Flow.pdf
AI Trends in Creative Operations 2024 by Artwork Flow.pdfAI Trends in Creative Operations 2024 by Artwork Flow.pdf
AI Trends in Creative Operations 2024 by Artwork Flow.pdf
 
Skeleton Culture Code
Skeleton Culture CodeSkeleton Culture Code
Skeleton Culture Code
 
PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024
 
Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)
 
How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024
 
Social Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsSocial Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie Insights
 
Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024
 
5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary
 
ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd
 
Getting into the tech field. what next
Getting into the tech field. what next Getting into the tech field. what next
Getting into the tech field. what next
 
Google's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search IntentGoogle's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search Intent
 
How to have difficult conversations
How to have difficult conversations How to have difficult conversations
How to have difficult conversations
 
Introduction to Data Science
Introduction to Data ScienceIntroduction to Data Science
Introduction to Data Science
 
Time Management & Productivity - Best Practices
Time Management & Productivity -  Best PracticesTime Management & Productivity -  Best Practices
Time Management & Productivity - Best Practices
 
The six step guide to practical project management
The six step guide to practical project managementThe six step guide to practical project management
The six step guide to practical project management
 
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
 

Modernizing Physical Security and Incorporating Best Practices Into New Assets

  • 1. Modernizing Physical Security and Incorporating Best Practices Into New Assets Interview with David Grubbs, Director, Regulatory Affairs and Compliance at City of Garland, TX As the Department of Homeland Security has reported, cyber security threats to the utility industry are increasing in number and sophistication. Because of this challenge, the North American Reliability Corporation (NERC) is increasing the Critical Infrastructure Protection (CIP) regulatory requirements to ensure organizations and facilities are meeting basic standards in this area. marcus evans had the privilege to hear from David Grubbs before the upcoming Utility Cyber Security & CIP Compliance Conference, January 15-17, 2013 in Atlanta, GA. Below he shares with us his perspective on how CIP standards are affecting cyber security within electric utilities. The responses below strictly reflect the views and beliefs of David Grubbs, and not necessarily those of City of Garland, TX. What are some of the newer efforts being utilized to protect the physical assets of utilities? David Grubbs: Electric utilities continue to improve both physical and cyber security efforts to counter known and unknown threats. In physical security, many upgraded security features have been added including: card access at many locations, electronic padlocks that require the regular reauthorization of keys and can be set to ignore keys identified as lost, video monitoring, fence tamper detection and motion sensors. The most important aspect of improving security is properly training personnel and achieving a security mindset within the industry. The CIP
  • 2. Standards make a start at this, but only include personnel with access the CIP Critical Cyber Assets. Can you elaborate on the benefits of applying CIP standards to non-critical assets? DG: The CIP standards are a good starting point for any security system. They are however, inadequate to fully protect any asset. Security is achieved by a defense in depth. Much as an onion has numerous layers, good security systems should have numerous layers of which the CIP standards are only a few of the layers. Frequently, the best defenses are those no one knows about. Unfortunately, at least through version 4, the CIP Standards are somewhat prescriptive. Many of the security aspects of a facility, and even which facilities have security, can be guessed because of the CIP standards. Beginning with version 5 of the CIP standards the industry will have more flexibility to install the appropriate security for a facility rather than specific security practices. Why should utilities consider organizational security to be just as important as safety? DG: Security systems are inherently designed to keep the “bad guys” out. Excellent security systems can easily be defeated when someone inadvertently leaves a door open or invites the “bad guys” in. The most common ways of entering a system are by social engineering. Asking innocent sounding questions, a hyperlink in an email that appears to be from your boss, or getting someone to plug in a USB drive or CD are the easiest way to get into a secure system. A second source of lost information is a lost laptop or the USB drive that contains sensitive information. The following article from Intelligent Utility, http://www.intelligentutility.com/article/12/10/cyber-risk-conversation , explores the potential motivation behind cyber attacks aimed at utilities in the format of a
  • 3. hypothetical conversation between utility executives. If you had a chance to join the conversation, what comments/counterarguments would you give? DG: I have had several very similar conversations with industry executives across North America. Different entities have differing risk profiles to the various threats identified in the discussion. Certain companies may be more of a target to certain organizations, such as environmental extremists, while others might be less so. There is some risk for all of these threats to each of us. Some organizations, because of their small size, might believe they are immune to such activities because no one knows they are there and theorize that someone would not be interested in attacking them. By the same logic, an attacker might go after a smaller organization believing their security is less organized than at a larger entity and easier to penetrate, thus making a smaller entity a more attractive target. None of these is true in all circumstances, but are potential considerations when designing a security system. As someone who has attended marcus evans events in the past, what do you think attendees can take away from this conference? DG: There are three primary takeaways from a marcus evans conference. First is the educational aspect. Attendees learn how other comparable companies are coping with the issues; from compliance, to security, to organizational structure, to budgeting. Second, are the relationships you build with the speakers and fellow participants. Being able to discuss ideas with others, both during the conference and afterward, can give significant insight into issues. Third, and perhaps most important, it gives you a chance to break out of a rut and do something different. We are all guilty of continuing to do what we have been doing and as long as nothing jolts us, we just keep on doing it. A conference, such as this, gives us the opportunity to review our own programs in the light of the best practices of others. It allows us to refocus on the needs of our organization and gives us a new enthusiasm for pursuing the ideas we developed at the seminar. Mr. Grubbs joined the City of Garland in 2002 and has held numerous positions within the City. He is currently serving as the Director of Regulatory Affairs and Compliance reporting directly to
  • 4. the Managing Director of the Electric Utility on Regulatory, Compliance and Transmission Planning Issues. Immediate prior to joining Garland, Mr. Grubbs worked as a consultant developing wind energy and compressed air energy storage generation units. For more information, please contact Michele Westergaard, Senior Marketing Manager at 312- 540-3000 ext. 6625 or Michelew@marcusevansch.com. About the Utility Cyber Security & CIP Compliance Conference This unique event will take place in Atlanta, GA from January 15-17, 2013. Industry leaders attending this event will benefit from a dynamic presentation format consisting of workshops, panel discussions and case studies. Attendees will experience highly interactive conference sessions, 10-15 minutes of Q&A time after each presentation, 4+ hours of networking and exclusive online access to materials post-event. About marcus evans marcus evans conferences annually produce over 2,000 high quality events designed to provide key strategic business information, best practice and networking opportunities for senior industry decision-makers. Our global reach is utilized to attract over 30,000 speakers annually; ensuring niche focused subject matter presented directly by practitioners and a diversity of information to assist our clients in adopting best practice in all business disciplines.