Securely manage and enforce compliance on all devices in a NERC CIP environment

February 04, 2026
26AB
Advanced Operations , Asset Management , Cybersecurity

This presentation will describe how a major US electric utility greatly reduced operations and maintenance expenses and significantly improved cybersecurity by unifying secure remote access, automated device management and compliance, and support for all devices regardless of connectivity. They have deployed a centralized solution for more than 50,000 Intelligent Electronic Devices (IEDs) in their operational environment. 

Initially, the utility had multiple disparate systems prior to standardizing on a single multi-vendor solution. The multiple systems were necessary to manage all their IP connected North American Electricity Reliability Corporation (NERC) Critical Infrastructure Protection (CIP) IEDs as well as their Distribution and Feeder Automation IEDs. The transition to a single, multi-vendor solution capable of supporting the fleet of IP-connected IEDs lead the utility to realize the benefits of streamlining and automating security and compliance to reduce workload supporting these devices. However, this still left a separate costly, manual, and time-consuming process for field workers to manage the remaining 20% of IEDs that were disconnected from the network. 

The next problem they addressed was these disconnected IEDs, which accounted for 80% of the work after implementing the centralized solution. By extending the device management functionality to field worker laptops, the utility now has a unified platform capable of automating the management of every Transmission and Distribution IED. Field workers now have a simplified process to change passwords, collect configuration files and event logs, document hardware, firmware, or software that is installed, and gather all evidence necessary to demonstrate compliance. Collected data is synchronized to the central solution when they return to the office. 

Too often compliance and security initiatives reduce workforce satisfaction, but this new capability automates compliance, easing their workload and allowing them to reclaim workforce efficiency. Furthermore, security teams now have end-to-end visibility of all device activity tracking work performed both remotely and locally to the entire fleet of devices. This presentation will cover the problems encountered and solutions implemented to improve human performance and efficiency, while simultaneously improving the compliance and cybersecurity posture of their Operational Technology workforce and assets.

Chairperson
Sunil Katwala
Sunil Katwala - PSEGLI