Updated: Secrecy Reigns as NERC Fines Utilities $10M citing Serious Cyber Risks
ID: dc343a01-f344-51ee-bb30-04d6d68dec67
STIX ID: report--dc343a01-f344-51ee-bb30-04d6d68dec67
Feed Name: Security Ledger
NERC issued its largest-ever penalty — $10 million across undisclosed entities within a Regional Entity — for 127 violations of Critical Infrastructure Protection (CIP) standards, including 13 rated as serious risks and 62 as moderate. The public notice is heavily redacted, but describes systemic failures such as absent/insufficient electronic access controls, weak change-control practices, and poor management oversight; the report requires the fined companies to undertake governance, documentation, and technical remediation. The article situates the enforcement in the context of growing concern about nation-state actors (notably Russia, China, and Iran) targeting North American critical infrastructure, but does not provide indicators of compromise or evidence of an active cyber intrusion.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
