Maurice Martin, Tami Reynolds, Anuj Sanghvi, Sadie Cox, James Elsworth
Stakeholder
National alternative energy Laboratory (NREL); U.S. Agency for International Development (USAID); electric utilities worldwide
This report introduces 11 cybersecurity “building blocks” for electric utilities, especially those with growing grid edge resource adoption. It outlines practical, modular guidance for developing cybersecurity programs spanning governance, risk, technical controls, incident response, and more. Includes diagrams and toolkits like DER-Cyber Framework and references tailored for under-resourced utilities.
Implementing the NIST Cybersecurity Framework: A Utility Guide
Component
Technical
Author
Developed by a SEPA Utility Peer Group (Cybersecurity Framework Working Group) – “authored by utilities” with contributions from multiple utility cybersecurity experts
Stakeholder
Smart Electric Power Alliance (SEPA) and contributing electric utilities (utility cybersecurity practitioners who authored the guide).
An abbreviated guide (case study) created “by utilities for the electric power industry” to help utilities effectively implement the National Institute of Standards and Technology (NSIT) Cybersecurity Framework (CSF). It provides nine recommended steps with key tasks, outputs, and real-world examples for building a sustainable cybersecurity risk management program aligned with NIST CSF and Cybersecurity Capability Maturity Model . The goal is to show one approach that electric utilities can use to improve their cyber resilience by leveraging these frameworks, with practical insights from utility practitioners.