Join our Newsletter — 33% off our NHI Course
Home FAQ Cyber Security How should electric utilities structure cybersecurity investments to…
Cyber Security

How should electric utilities structure cybersecurity investments to qualify for incentive-based rate treatment?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 20, 2026 Domain: Cyber Security

Utilities should align spending with FERC’s eligibility rules, focusing on investments that improve the ability to protect, detect, respond to, or recover from cyber threats. The most defensible approach is to prioritize controls that are not already mandated, document the cybersecurity outcome, and tie costs to qualifying technology, monitoring, training, or information-sharing activities. Timing also matters, since late filings can disqualify older expenditures.

How utilities should think about qualifying spend

The practical question is not whether a cyber purchase is “good security,” but whether it can be defended as a qualifying investment under the incentive framework. That means the spend should map to a cyber outcome, sit outside ordinary compliance obligations, and be documented in a way that makes the utility’s business and reliability case easy to follow. For a utility, the strongest candidates are controls that improve resilience across monitoring, response, recovery, and threat visibility.

Utilities should treat the filing package as part of the investment itself. If the record cannot show what the control does, what threat it addresses, and why the cost is incremental rather than already required, the spend is harder to defend. That is especially important in environments where cyber work is often bundled with baseline reliability, OT modernization, or general IT refresh programs.

One useful reference point is the broad security outcome model in NIST Cybersecurity Framework 2.0, which helps organize spending around govern, protect, detect, respond, and recover outcomes.

What types of cybersecurity investments are usually easiest to defend

The easiest investments to defend are the ones that clearly improve the utility’s ability to observe and control cyber conditions rather than simply keep the environment running. That often includes logging and monitoring, anomaly detection, incident response tooling, backup and recovery hardening, segmentation, access governance, and cyber-focused training or exercises. Information-sharing and threat-intelligence activities can also fit when they directly improve defensive decision-making.

In practice, utilities should be careful not to present ordinary maintenance as cyber uplift. A patching project, control-system refresh, or network replacement may still qualify if the filing shows a distinct cybersecurity increment, such as added detection coverage, hardened access paths, or better containment. The investment case should explain the cyber delta, not just the technology refresh.

For utilities operating critical infrastructure, sector guidance from CISA Industrial Control Systems is a useful companion for thinking about monitoring, segmentation, and operational resilience in OT-adjacent environments.

Why documentation and timing matter as much as the control itself

Eligibility can turn on process discipline. Late filing, weak cost attribution, or vague descriptions can undermine otherwise sensible investments, especially when expenditures predate the filing window. Utilities should build a cost ledger that separates qualifying cyber work from mandated spend, routine operations, and unrelated capital work, then retain the evidence needed to show when the decision was made and why it was necessary.

Timing also affects defensibility because cyber programs evolve quickly. If an expenditure is made after a known threat, after a control gap has been identified, or after a compliance deadline has already forced the work, the utility should expect closer scrutiny over whether the spend is truly incentive-eligible. Strong governance means the utility can show a pre-investment rationale, a clear control objective, and a direct link to the cyber outcome the spend is meant to achieve.

Risk and Threat Considerations

Utilities face a real risk of overclaiming general technology spend as qualifying cyber investment, or of under-documenting controls that are actually important to resilience. The security exposure is not just financial disallowance, but also a weaker ability to prove that the utility is funding the controls that reduce compromise, outage, and recovery risk.

Failure mechanism: The filing ties costs to broad modernization, compliance, or reliability work without isolating the cyber function, so the regulator cannot verify that the expenditure improves protection, detection, response, or recovery in a material way.

Impact: The utility can lose incentive treatment, weaken its audit trail, and miss the chance to justify cyber spending that would have been persuasive if it had been packaged around a clearly documented security outcome.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, CIS Controls v8 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV — GovernUtilities need governance to justify qualifying cyber spend and document eligibility.
DE — DetectDetection investments are central when utilities justify monitoring and alerting spend.
RC — RecoverRecovery capabilities often support defensible utility cyber investments.
Recommendation — Define investment approval criteria that tie spending to documented cyber outcomes. Prioritize monitored capabilities that improve cyber event detection and visibility. Fund recovery controls that measurably reduce restoration time after cyber incidents.
CIS Controls v813 — Network Monitoring and DefenseMonitoring investments are a common defensible cyber spend for utilities.
17 — Incident Response ManagementResponse capability is a core qualifying outcome for cyber-related utility spend.
Recommendation — Implement continuous monitoring to justify cyber investment in detection and response. Build and exercise incident response capability around the funded controls.
NIST Zero Trust (SP 800-207)3 — Zero Trust PrinciplesZero trust framing helps utilities defend investments that improve segmented, bounded access.
Recommendation — Use zero trust principles to justify investments that limit blast radius and access.

Practitioner Guidance

What to verify: Before filing, verify that each claimed item has a named control objective, a dated approval trail, and a cost breakout showing the cyber increment versus baseline operational work. If the control can be described only as “improved technology” or “better reliability,” it probably needs more evidence before it is defensible.

Decision rule: If the spend improves the utility’s ability to detect, contain, respond to, or recover from cyber events, preserve it as a cyber claim; if it mainly replaces aging equipment or satisfies a mandatory requirement, treat it as supportable only when the cyber delta is separately and clearly documented.

Practitioner takeaway: The strongest filings do not start with the invoice, they start with the security outcome, then prove that the cost is incremental, timely, and directly tied to a defensible cyber control.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 20, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org