against human error automatically raises the barrier against malicious attack.

•   Investment in process and personnel must be a priority. There has been a serious lack of investment in power system infrastructure in recent years, and market-based priorities are unlikely to support strategically increasing security in power systems. Cyber security, like the reliability of the grid, probably has to be mandated by the FERC/ERO process, which usually means that the mandatory standard (i.e., the minimum required) will lag behind best practices. Because cyber security weaknesses tend to provide highly opportunistic windows for would-be attackers, and mandatory standards processes tend to be slow, the industry must continue to look for ways to facilitate rapid and the reliable implementation of security upgrades and patches and to ensure that its personnel are well trained and applying best practices. Simply conforming to the last round of standards will often not be sufficient to provide adequate protection.


