Grid Transformation - Aggregation of Control

By Jason Georgoulis
CIP Cyber and Physical Security Analyst

In 2025, the Electric Reliability Organization (ERO) Enterprise continued to see a rise in inverter-based resources (IBRs) and distributed energy resources (DERs). As the grid continues its transformation and modernization, the ERO has also seen an increase in the aggregation of control and the use of third-party services to support day-to-day operations. These changes introduce new operational and cybersecurity complexities and can significantly impact how Cyber Assets are classified when performing a CIP-002 evaluation.

CIP-002-5.1a Requirement 1 requires registered entities to identify each high, medium, and low impact Bulk Electric System (BES) Cyber System and review the identifications at least once every 15 calendar months.

Understanding the risks that come from allowing a vendor to connect to your systems and the risks that come from having a vendor provide services from external systems could impact how a registered entity chooses to perform a CIP-002 evaluation and whether it is prudent to consider a vendor’s systems within the evaluation.  

By including both local and external systems in your CIP-002 evaluation, your organization will be better equipped to identify any gaps in controls necessary to meet all CIP requirements and obligations. With a wider view of the environment used to perform BES reliability functions, you may find that you want to employ best practices such as:

  • Data encryption and integrity checks that meet federal standards can prevent unauthorized disclosure.
  • Validating that third parties employ a known cybersecurity framework. SOC2 and ISO 27001 reports can provide you with a higher degree of confidence that a vendor is applying appropriate cybersecurity and physical security controls.
  • Good cyber hygiene policies such as employing strong passwords, multifactor authentication, patch management, and scheduled data backups can all help to reduce the risk of a data breach, data loss, or system availability concerns.

These are just a few control examples that may be worth considering when using third-party vendors to assist in your daily operations. For more information and further guidance on implementing best practices related to security and privacy controls, Texas RE encourages Responsible Entities to consult the National Institute of Standards and Technology (NIST) SP 800-53 Rev. 5.