Utilities should align spending with FERC’s eligibility rules, focusing on investments that improve the ability to protect, detect, respond to, or recover from cyber threats. The most defensible approach is to prioritize controls that are not already mandated, document the cybersecurity outcome, and tie costs to qualifying technology, monitoring, training, or information-sharing activities. Timing also matters, since late filings can disqualify older expenditures.
How utilities should think about qualifying spend
The practical question is not whether a cyber purchase is “good security,” but whether it can be defended as a qualifying investment under the incentive framework. That means the spend should map to a cyber outcome, sit outside ordinary compliance obligations, and be documented in a way that makes the utility’s business and reliability case easy to follow. For a utility, the strongest candidates are controls that improve resilience across monitoring, response, recovery, and threat visibility.
Utilities should treat the filing package as part of the investment itself. If the record cannot show what the control does, what threat it addresses, and why the cost is incremental rather than already required, the spend is harder to defend. That is especially important in environments where cyber work is often bundled with baseline reliability, OT modernization, or general IT refresh programs.
One useful reference point is the broad security outcome model in NIST Cybersecurity Framework 2.0, which helps organize spending around govern, protect, detect, respond, and recover outcomes.
What types of cybersecurity investments are usually easiest to defend
The easiest investments to defend are the ones that clearly improve the utility’s ability to observe and control cyber conditions rather than simply keep the environment running. That often includes logging and monitoring, anomaly detection, incident response tooling, backup and recovery hardening, segmentation, access governance, and cyber-focused training or exercises. Information-sharing and threat-intelligence activities can also fit when they directly improve defensive decision-making.
In practice, utilities should be careful not to present ordinary maintenance as cyber uplift. A patching project, control-system refresh, or network replacement may still qualify if the filing shows a distinct cybersecurity increment, such as added detection coverage, hardened access paths, or better containment. The investment case should explain the cyber delta, not just the technology refresh.
For utilities operating critical infrastructure, sector guidance from CISA Industrial Control Systems is a useful companion for thinking about monitoring, segmentation, and operational resilience in OT-adjacent environments.
Why documentation and timing matter as much as the control itself
Eligibility can turn on process discipline. Late filing, weak cost attribution, or vague descriptions can undermine otherwise sensible investments, especially when expenditures predate the filing window. Utilities should build a cost ledger that separates qualifying cyber work from mandated spend, routine operations, and unrelated capital work, then retain the evidence needed to show when the decision was made and why it was necessary.
Timing also affects defensibility because cyber programs evolve quickly. If an expenditure is made after a known threat, after a control gap has been identified, or after a compliance deadline has already forced the work, the utility should expect closer scrutiny over whether the spend is truly incentive-eligible. Strong governance means the utility can show a pre-investment rationale, a clear control objective, and a direct link to the cyber outcome the spend is meant to achieve.
Risk and Threat Considerations
Utilities face a real risk of overclaiming general technology spend as qualifying cyber investment, or of under-documenting controls that are actually important to resilience. The security exposure is not just financial disallowance, but also a weaker ability to prove that the utility is funding the controls that reduce compromise, outage, and recovery risk.
Failure mechanism: The filing ties costs to broad modernization, compliance, or reliability work without isolating the cyber function, so the regulator cannot verify that the expenditure improves protection, detection, response, or recovery in a material way.
Impact: The utility can lose incentive treatment, weaken its audit trail, and miss the chance to justify cyber spending that would have been persuasive if it had been packaged around a clearly documented security outcome.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, CIS Controls v8 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV — Govern | Utilities need governance to justify qualifying cyber spend and document eligibility. |
| DE — Detect | Detection investments are central when utilities justify monitoring and alerting spend. | |
| RC — Recover | Recovery capabilities often support defensible utility cyber investments. | |
| Recommendation — Define investment approval criteria that tie spending to documented cyber outcomes. Prioritize monitored capabilities that improve cyber event detection and visibility. Fund recovery controls that measurably reduce restoration time after cyber incidents. | ||
| CIS Controls v8 | 13 — Network Monitoring and Defense | Monitoring investments are a common defensible cyber spend for utilities. |
| 17 — Incident Response Management | Response capability is a core qualifying outcome for cyber-related utility spend. | |
| Recommendation — Implement continuous monitoring to justify cyber investment in detection and response. Build and exercise incident response capability around the funded controls. | ||
| NIST Zero Trust (SP 800-207) | 3 — Zero Trust Principles | Zero trust framing helps utilities defend investments that improve segmented, bounded access. |
| Recommendation — Use zero trust principles to justify investments that limit blast radius and access. | ||
Practitioner Guidance
What to verify: Before filing, verify that each claimed item has a named control objective, a dated approval trail, and a cost breakout showing the cyber increment versus baseline operational work. If the control can be described only as “improved technology” or “better reliability,” it probably needs more evidence before it is defensible.
Decision rule: If the spend improves the utility’s ability to detect, contain, respond to, or recover from cyber events, preserve it as a cyber claim; if it mainly replaces aging equipment or satisfies a mandatory requirement, treat it as supportable only when the cyber delta is separately and clearly documented.
Practitioner takeaway: The strongest filings do not start with the invoice, they start with the security outcome, then prove that the cost is incremental, timely, and directly tied to a defensible cyber control.
Related resources from NHI Mgmt Group
- How should public companies structure cybersecurity disclosure so they can meet SEC reporting expectations without creating noise for investors?
- What breaks when rate limiting is based only on generic request counts?
- How should security teams evaluate cybersecurity investments when budgets are tight and demand is rising?
- Should students choose cybersecurity based on salary potential alone, or on longer term career fit?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 20, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org