Operational Integrity Enhancement Energy Industry Analysis
Total Page:16
File Type:pdf, Size:1020Kb
Operational Integrity CENTER for Enhancement REGULATORY STRATEGY Energy Industry Analysis AMERICAS Operational Integrity Enhancement | Energy Industry Analysis Energy Physical infrastructure and (c) the transition of customers from Operational integrity in the energy industry Much of our nation’s underlying energy deregulation, which froze rates and for many is a broad and complex issue that includes infrastructure has exceeded its useful life years insulated consumers from natural key physical infrastructure components— and needs to be replaced. For example, in marketdriven rate increases that would have such as power plants, oil rigs, power some places, the underground pipes that occurred in smaller increments. lines, and underground pipes—not just carry natural gas have deteriorated to a information and control systems. The point where the gas is essentially traveling The need to fix big-dollar problems in aging complexity is amplified by the fact that through tunnels of dirt—creating a infrastructure—combined with an inability some parts of the energy industry are highly significant risk of leaks and explosions. to generate sufficient revenue due to market regulated and subject to explicit regulatory To address this issue, many regulators conditions, as well as increased pressure requirements about all aspects of their are responding by requiring utilities to on regulators to mitigate the “sticker shock” business, while other parts are much less implement long-term infrastructure to consumers in deregulated territories— regulated and most of their regulatory replacement programs. increases the burden of proof for utilities requirements focus only on safety. Also, when proposing rate recovery for day-to-day while some energy industry sectors are The business of a utility is to provide and long-term operations. All of this leads regulated nationally or globally, many others safe, reliable, and cost-effective service to to numerous levels and forms of risk in are regulated at the state or local level. customers, while also generating sufficient both operations and financial planning. The For example, utility companies typically fall revenue to ensure a reasonable rate of increased burden of proof is being enforced under the purview of state regulators and return. Since the services being provided in a variety of ways, including: more specific are often subject to detailed requirements are “necessary,” regulators (generally in regulation; the use of more sophisticated about everything from maintenance, the form of commissions) are designated analysis tools and resources by commissions inspection, and reliability to how much they at the state and federal levels to manage in rate cases; government initiatives with a can charge and how much profit they can and protect these interests. “Keeping the focus on infrastructure management; and make. In contrast, oil pipelines are much less lights on” or “keeping the gas and water imposition of “recommendations” (guidance regulated, although some attention is given flowing” is the number one objective, and that is labeled as voluntary but in reality is to safety and environmental impacts. capital investment in infrastructure is vital to mandatory). meeting this objective. Because of this breadth and complexity, All utilities are vulnerable to change. the industry’s drive to improve operational While infrastructure planning and However, some types of utilities are more integrity is scattered across countless management has always been an area likely to be targets for change. For example, rules and regulations that vary by sector of scrutiny in any rate case or utility the gas utility sector is likely the highest and jurisdiction—and thus cannot be fully management audit, commissions have priority for regulators looking to drive captured simply by describing a handful of begun imposing more sophisticated financial widespread infrastructure improvement key emerging regulations. However, and risk assessment requirements as part because reliability failures in the sector generally speaking, it would be fair to say of the associated justifications in order to pose the greatest safety risks. Other that the energy industry recognizes the clear the approval processes. This is likely sectors may be vulnerable to more targeted importance of operational integrity and that attributable to a few key factors: (a) aging enforcement of regulatory change. This various regulatory bodies in the industry are infrastructure and the lack of sufficient includes, for example, utilities that for a actively working to address the issue. longterm plans to address the rapidly variety of reasons—relationships, bad actor increasing risk of major failures, particularly reputation, poor filings—have historically Regulatory requirements and guidance in gas and water infrastructure; (b) market not been very successful in rate recovery or related operational integrity in energy conditions that have driven prices down, other regulatory proceedings. generally fall into four major categories: creating a “do more with less” environment; 02 Operational Integrity Enhancement | Energy Industry Analysis to protect those systems from abuse. concerns, such as cost allocation regulations Cybersecurity1 Headlines and perceived major failures, for shared assets and services. The energy sector is seeing a rise in risks, and threats will drive increased cyber threats—particularly against critical legislative focus. This will likely spur support Additional complexity exists for entities that infrastructure—and regulators are working from regulators for the development and are regulated for some cyber assets and not hard to increase and improve cybersecurity implementation of rules that allow for better for others. Many organizations think they and compliance controls to address those monitoring, tracking, and enforcement already have robust processes and are in threats. Publicized threats, such as of specific cybersecurity controls and compliance. But assessments of controls Dragonfly and Black Energy, target industrial compliance obligations similar to the NERC for unregulated assets often reveal that control systems (ICS) and other energy CIP requirements. the controls are not being implemented as assets, while quieter threats and the intended. Utilization of different processes, expanded use of cyber assets in day-to-day Recent versions of NERC’s CIP framework controls, and frameworks while leveraging operations add to the need to transform expanded the scope of cyber assets that the same resources, assets, and controls cybersecurity programs. power and utility companies must monitor can create confusion and cause many of the —an increase for some utilities of more than gaps or implementation failures. Complicating all of this is the use of different 1,000 percent. The effect of these changes frameworks (i.e., Critical Infrastructure applies unevenly. For example, a challenge Cybersecurity efforts in energy are focusing Protection (CIP), NIST) by many entities, for small and mid-sized companies is that on non-ICS cyber assets as well. The CFTC as well as inconsistent implementation of the expected vigilance and compliance recently approved the NFA’s cybersecurity processes and controls depending on the infrastructure of the expanded CIP guidance that will require members nature of the assets to be protected. Finally, regulations is not scalable. They face the to adopt—and enforce—policies and lack of focus on assurance activities to verify need to implement the same changes as procedures to secure customer data and the proper execution and effectiveness of larger companies, but with smaller budgets protect their electronic systems. The CFTC is existing controls—and to identify areas for and staffs. Larger companies, however, may also considering some proposals to ensure improvement or remediation—increases the face significant expansion of the number that the major exchanges, clearinghouses, risk of a major failure. of assets requiring protection and the and swap data repositories are doing challenge of managing compliance programs adequate evaluation and testing of their As the Smart Grid grows and evolves and and resources that are spread across a own cybersecurity and operational risk energy companies increase their use of much larger organization (or even separate protections. ICS, there will likely be a mounting need entities). This could trigger other regulatory 03 Operational Integrity Enhancement | Energy Industry Analysis Operational integrity related to • Swap data repositories. Tracking swap the Bureau of Safety and Environmental energy trading transactions and resolving problems Enforcement (BSEE) develop and adopt Regulatory scrutiny and guidance related to before the transactions are reported to a probability-based approach to risk energy trading have increased significantly regulators. management. The idea is to shift the focus in the wake of the financial downturn and from subjective/qualitative risk factors • Price data reporting. Updating FERC’s other headline-grabbing problems. This is an to objective/quantitative risk factors (i.e., price data reporting guidelines (which area where specific regulations have been setting standards based on probability were originally issued in 2003/2004) to introduced, and where enforcement actions percentages—for example, requiring a capitalize on the latest technologies. are increasingly common. Here are some of project to achieve expected reliability of 99.9 the key focus