NRG Energy Opposes Joint Utilities' Petition to Strengthen Data Security Agreement

NRG Energy, a leading integrated energy and home services company, has submitted comments in response to the Joint Utilities' petition to modify the Data Security Agreement Self-Attestation Requirements and Implement a Governance Review Process for Regular Self-Attestation Updates. NRG argues that the proposed changes would impose overly burdensome cybersecurity requirements on energy service entities (ESEs) and customers, rather than striking a balance between protecting utility IT systems and customer information. The company urges the New York Public Service Commission to deny the petition as filed, citing three main reasons: the JU's proposal lacks a risk-based approach to cybersecurity, the Governance Committee proposed by the JU does not provide ESEs like NRG a voice in future cybersecurity matters, and the JU Petition fails to provide ESEs a buffer period to assess their internal systems against new requirements.

Key Takeaways:

  • NRG Energy is a leading integrated energy and home services company that provides products and services to over 6 million customers in the US.
  • The Joint Utilities' petition aims to modify the Data Security Agreement Self-Attestation Requirements and Implement a Governance Review Process for Regular Self-Attestation Updates, which NRG opposes due to its overly burdensome nature.
  • The proposed changes would require energy service entities (ESEs) to implement NIST standards, which NRG argues are not appropriate for communicating retail customer data used in accordance with customer consent.
  • NRG believes that the Commission has already recognized the need to strike a balance between protecting utility IT systems and customer information, and that the JU's proposal would undermine this balance.
  • The company argues that ESEs like NRG need to be involved in future cybersecurity discussions and should have a voice in the proposed Governance Committee.
  • NRG requests that the Commission deny the JU petition as proposed and provide a phased-in compliance period for ESEs to implement necessary changes.

Statistics:

  • NRG Energy serves over 6 million customers in the US.
  • The company has 7,300 employees and provides a range of products and services, including demand response and energy efficiency, 100% renewable energy, and energy plans bundled with energy efficiency technology.
  • The Joint Utilities' petition proposes the implementation of NIST standards for cybersecurity, which NRG argues are not suitable for communicating retail customer data.

Sources:

  • NRG Energy: "Comments of NRG Energy, Inc. in Response to the Joint Utilities' Petition to Modify the Data Security Agreement Self-Attestation Requirements and Implement a Governance Review Process for Regular Self-Attestation Updates" (Case 20-M-0082)
  • New York Public Service Commission: "Order Establishing Minimum Cyber Security and Privacy Protections and Making Other Findings" (Case 18-M-0376)
  • New York General Business Law: Section 899-bb (Data Security Protections)