Verizon launches electric grid reliability consulting
New service designed to help utilities prep for cyberattacks, smart grid needs
Computerworld - Verizon Business today launched a set of consulting services specifically designed for electric utilities working to safeguard the reliability of the electric grid in North America.
Among the services Verizon will offer is advice on, and implementation of, security software that can be used to thwart cyberattacks on the electric grid.
The consulting services could cost from $30,000 to multiple millions of dollars, depending on the size of the utility and its needs, said Omar Khawaja, product manager at Verizon Business, a division of Verizon Communications Inc. Khawaja said the average consulting services contract would cost between $50,000 and $200,000.
Verizon already provides security consulting to hundreds of companies and has many electric utilities under contract. The new services are intended to specifically help electric utilities meet a July 1, 2010 deadline to be "auditably compliant" with the North American Electric Reliability Corp.'s Critical Instruction Protection (NERC CIP) requirements, Khawaja said in an interview. "Auditably compliant" means that electric utilities must be able to show an auditor that the utility has logs and other records indicating it has 12 months of compliance with the requirements.
NERC was empowered by the U.S. 2005 Energy Law to enforce the NERC CIP standards; NERC is overseen by the Federal Energy Regulatory Commission (FERC).
Verizon will be competing with international accounting firms that provide similar utility audits and the consulting services of IBM Corp., Khawaja said. However, Verizon's familiarity with communications networks gives it more expertise in dealing with electric networks, which could give it an edge.
In addition, smart electric grids of the future will involve two-way communications using Internet Protocol controls that are part of Verizon's expertise, Khawaja added.
The smart grid concept is designed to help utilities conserve energy and costs, partly by allowing utilities to communicate with a variety of devices on a grid about the real-time cost of electricity. For example, a dishwasher or electric car might have an automatic two-way communication with the electric utility about what time of day energy is less expensive. The car or dishwasher would shut down until a time when costs were lower, Khawaja said.
The data passed over IP could be communicated via existing wired infrastructure or even wirelessly, Khawaja said, but there is also developing technology that allows data to be carried over electric lines.
With such smart grids, utilities will need cyber security protection against fraud by homeowners and average consumers trying to keep their electric bills low, as well as against international terrorists who might want to cripple the grid as part of a larger attack, Khawaja said. "IP is a well-known protocol, so there is potential for security breaches and the amount of threats is much greater now." The CIP regulations will also protect electric utilities against accidents or natural disasters.
Verizon will offer four basic types of consulting, starting with strategy, then planning, implementation (including installation of patch management technology) and security operations.
Utilities must meet eight NERC CIP requirements, including identification of cyber assets in the grid, adequate training for personnel and the physical security of computer assets. The CIP requirements also detail how cyberattacks must be reported and lay out plans for recovery in the event of an attack or accident.
Read more about Security in Computerworld's Security Topic Center.



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Overcome Top 7 Admin Challenges of Active Directory
- As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
- Insiders Can Ruin Your Company. Take Action.
- Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
- Top Solutions and Tools to Prevent Devastating Malware
- Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
- X-Ray of the PCI Process-4 Proactive Steps
- This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into...
- Identity Governance: The Business Imperatives
- This white paper describes the business challenges and opportunities that are driving interest in Identity Governance while discussing considerations your organization should make... All Security White Papers
- Live Webcast
Playing Defense: Staying on Top of Your Disaster Recovery Game - When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing...
- Introduction to VMware vCenter Site Recovery Manager 5
- Traditional disaster recovery solutions are often too expensive, complex and unreliable to meet business requirements. As a result, IT departments are hesitant to...
- The Top Ten Secrets to Avoiding SAN Performance Problems
- Maintaining peak performance while simultaneously addressing the root cause of SAN errors is challenging. Learn the most common SAN problems and explore new...
- Deduplication Without Compromise
- Go inside Quantum's scalable, high-performance, multi-protocol new DXi deduplication appliances, designed to make backup much more effective. Discover how the new future-proof DXi6700...
- Director of Disk Products Discusses DXi6700
- Discover how the new DXi 6700 series of deduplication appliances provide investment protection and a future-proof feature set, all while delivering fast, scalable,...
- Playing Defense: Staying on Top of Your Disaster Recovery Game
- When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing... All Security Webcasts