Show Filters

Top Results

NERC CIP Program Recovery

Full Program Turnaround

Achieved zero regulatory findings during follow-up NERC CIP audit

Comprehensive Workforce Development

Trained and engaged more than 120 employees across compliance, engineering, cybersecurity, and operations to create a more sustainable program

Program Durability

Enabled self-sustaining compliance readiness by embedding recurring tasks into a work management tool and deploying structured job plans and training across the organization

Challenge

A large electric utility received an unfavorable audit that pointed to a significant programmatic breakdown and a lack of cultural understanding of NERC CIP compliance standards. Significant gaps existed in the organization’s roles and responsibilities to provide governance and oversight for the standards; procedures were not well maintained or did not exist; and the organization relied on manual methods to document and collect evidence. Operating and technical groups did not understand the NERC CIP standards, requirements, or the implications of non-compliance. Enterprise and business unit leadership were facing tight timelines to respond to audit findings and a situation where repeat issues would not be tolerated by the regulator or the board.

Process

  • Established an operating model and organization for NERC CIP compliance​
  • Developed and updated NERC CIP documentation, including seven technical program documents, 11 new CIP procedures, and more than seven updated procedures​
  • Developed more than 25 PMs and entered them into the Maximo work management tool for recurring CIP requirements; allowed management visibility to oversee ongoing CIP tasks​
  • Developed eight template job plans with work instructions​
  • Prepared and issued computer-based awareness training for more than 800 workers, totaling more than 1,200 courses completed​
  • Delivered CIP technical instructor-led training at medium-impact facilities, providing direct training to more than 350 workers​
  • Provided initial training to compliance managers and compliance analysts​
  • Worked with operational leaders to self-certify that they knew how to execute work

Result

  • The next NERC CIP regulatory audit contained zero findings for the business unit​
  • Developed the program in a way that engaged more than 120 employees, and the entire organization (compliance, engineering, cybersecurity, and operations) was able to self-sustain the program

Related Insights

Let’s Work Together

We don’t solve problems with canned methodologies; we help you solve the right problem in the right way. Our experience ensures that the solution works for you.