ARTICLE
16 March 2018

Utility Receives Massive Reliability Standards Penalty For Data Breach Involving Vendor

The North American Electric Reliability Corporation (NERC) filed a Notice of Penalty summarizing an agreement by an unidentified electric utility to pay a $2.7 million penalty ...
United States Energy and Natural Resources
To print this article, all you need is to be registered or login on Mondaq.com.

The North American Electric Reliability Corporation (NERC) filed a Notice of Penalty summarizing an agreement by an unidentified electric utility to pay a $2.7 million penalty in connection with self-reported violations of the Critical Infrastructure Protection reliability standards related to sensitive data exposure by a vendor. Although the utility did not directly cause the improper data handling—and indeed the violation resulted from vendor noncompliance with utility policies—the Western Electricity Coordinating Council nevertheless concluded that the utility failed to adequately implement its information protection program by not preventing or immediately detecting the vendor's actions and submitted the settlement to NERC. 

For more detail, read our LawFlash.

This article is provided as a general informational service and it should not be construed as imparting legal advice on any specific matter.

We operate a free-to-view policy, asking only that you register in order to read all of our content. Please login or register to view the rest of this article.

ARTICLE
16 March 2018

Utility Receives Massive Reliability Standards Penalty For Data Breach Involving Vendor

United States Energy and Natural Resources

Contributor

See More Popular Content From

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More