Proving the Business Case for the Internet of Things

AEP, Fortress JV to protect US grid

William Payne
November 14, 2019



Electricity producer and operator American Electric Power has formed a joint venture with industrial cybersecurity firm Fortress Information Security to better protect the US power grid from cyber threats. The Asset to Vendor Network for Power Utilities (A2V) venture will help promote collaboration among North American electricity companies and help reduce the costs associated with cybersecurity regulatory compliance in an effort to cope with budgetary limitations.

Power utilities share many of the same supply chain vendors for equipment, software and services for their Bulk Electric Systems (BES), an industry trait that has been identified by malicious actors and is resulting in an increasing number of attacks on the power grid.

To address emerging supply chain risks to the power grid, the Federal Energy Regulatory Commission (FERC) has issued new rules that require utilities to develop a plan for managing cyber risk related to their supply chain. The plan includes procedures for prioritising vendors based on risk and requirements for completing standardised risk assessments on each vendor, as well as verifying the authenticity of software manufacturers and the integrity of software updates.

The deadline for completion of the plan is currently June 2020. Utilities that fail to meet this deadline can face various levels of penalties, ranging as high as $1,000,000 per day.

The volume of supply chain vendors providing equipment, software, and services to power utilities makes the completion of this goal challenging and costly for individual companies, and ultimately their customers, as well as potentially burdensome for the vendors.

Fortress is launching A2V to share technology and information to support security efforts for these vendors. The technology and data basis for A2V were developed in collaboration with AEP and include a substantial library of completed vendor risk assessments that comply with the new regulations. Fortress will operate the A2V platform.

Power companies who join A2V will be able to purchase vendor assessments for much less than it would cost for them to conduct the assessment themselves. Participating utilities also will be able to contribute their own completed assessments for purchase by the network and receive a portion of the proceeds. This will help them recover some of their investments in vendor assessments and help reduce overall operating and maintenance (O&M) costs associated with cyber security compliance.

"Building the A2V Network is consistent with Fortress' mission to secure critical infrastructure," according to Alex Santos, the CEO of Fortress. "Our team is looking forward to working with AEP and other electric energy companies in taking this next step to secure the North American grid."

Stephen Swick, Director of Cybersecurity Intelligence and Defence for AEP, said, "Power utilities need to work together to accomplish our shared goal of a secure power grid. A2V offers the opportunity for companies to collaborate and help mitigate the significant costs of protecting the grid."