The Federal Energy Regulatory Commission has approved two consequential grid decisions: a tightened NERC cybersecurity standard that closes long-standing gaps in physical access controls, and a cost-recovery green light for MISO’s 765-kV transmission backbone that will cross into PJM territory — while rejecting calls to subject those cross-border lines to competitive bidding. Together, the rulings signal FERC’s willingness to harden the grid’s digital defenses even as it navigates the messy politics of inter-regional transmission development.
The CIP-015-2 update targets the operational technology that hackers have learned to exploit: authentication servers, badge readers, and visitor management systems. These components sit at the intersection of physical and cyber security, often overlooked because they don’t fit neatly into either domain. As cybersecurity expert Kristine Martz noted, the expansion addresses a critical gap adversaries have actively exploited. The standard now requires entities to inventory, monitor, and protect these systems with the same rigor applied to critical cyber assets — a recognition that a compromised badge reader can be as dangerous as a breached firewall.
On the transmission side, MISO’s planned backbone represents a rare attempt at large-scale inter-regional infrastructure. The 765-kV lines would strengthen reliability across the Midwest while dipping into PJM’s footprint, creating a natural friction point over who builds and who pays. Industry groups argued that MISO’s competitive bidding process should extend to the PJM segments, but FERC sided with incumbent utilities ComEd and Duke Energy Ohio, allowing them to construct the lines under traditional cost-of-service regulation. The decision preserves the status quo for transmission ownership but raises questions about whether the current regulatory framework can efficiently deliver the inter-regional capacity the energy transition demands.
Both rulings reflect a grid under pressure from converging threats: sophisticated cyber adversaries probing physical access points, and a generation fleet in transition that requires new transmission pathways. FERC’s cybersecurity move is surgical and overdue; its transmission decision is pragmatic but may defer harder questions about competitive market design across RTO boundaries. The common thread is a regulator trying to secure today’s grid while the architecture of tomorrow’s remains unsettled.
Read the full report at Energy Central.