NRG Energy Opposes Joint Utilities' Petition to Strengthen Data Security Agreement
NRG Energy, a leading integrated energy and home services company, has submitted comments in response to the Joint Utilities' petition to modify the Data Security Agreement Self-Attestation Requirements and Implement a Governance Review Process for Regular Self-Attestation Updates. NRG argues that the proposed changes would impose overly burdensome cybersecurity requirements on energy service entities (ESEs) and customers, rather than striking a balance between protecting utility IT systems and customer information. The company urges the New York Public Service Commission to deny the petition as filed, citing three main reasons: the JU's proposal lacks a risk-based approach to cybersecurity, the Governance Committee proposed by the JU does not provide ESEs like NRG a voice in future cybersecurity matters, and the JU Petition fails to provide ESEs a buffer period to assess their internal systems against new requirements.
Key Takeaways:
- NRG Energy is a leading integrated energy and home services company that provides products and services to over 6 million customers in the US.
- The Joint Utilities' petition aims to modify the Data Security Agreement Self-Attestation Requirements and Implement a Governance Review Process for Regular Self-Attestation Updates, which NRG opposes due to its overly burdensome nature.
- The proposed changes would require energy service entities (ESEs) to implement NIST standards, which NRG argues are not appropriate for communicating retail customer data used in accordance with customer consent.
- NRG believes that the Commission has already recognized the need to strike a balance between protecting utility IT systems and customer information, and that the JU's proposal would undermine this balance.
- The company argues that ESEs like NRG need to be involved in future cybersecurity discussions and should have a voice in the proposed Governance Committee.
- NRG requests that the Commission deny the JU petition as proposed and provide a phased-in compliance period for ESEs to implement necessary changes.
Statistics:
- NRG Energy serves over 6 million customers in the US.
- The company has 7,300 employees and provides a range of products and services, including demand response and energy efficiency, 100% renewable energy, and energy plans bundled with energy efficiency technology.
- The Joint Utilities' petition proposes the implementation of NIST standards for cybersecurity, which NRG argues are not suitable for communicating retail customer data.
Sources:
- NRG Energy: "Comments of NRG Energy, Inc. in Response to the Joint Utilities' Petition to Modify the Data Security Agreement Self-Attestation Requirements and Implement a Governance Review Process for Regular Self-Attestation Updates" (Case 20-M-0082)
- New York Public Service Commission: "Order Establishing Minimum Cyber Security and Privacy Protections and Making Other Findings" (Case 18-M-0376)
- New York General Business Law: Section 899-bb (Data Security Protections)