Security Self-Assessments

Securing the grid's future starts with proactive defense

ReliabilityFirst offers a suite of three security self-assessments:

  • Cyber Resilience Assessment
  • Insider Threat Assessment
  • Incident Response Tabletops

These cyber and physical security assessments are carefully tailored to reveal risks and knowledge gaps outside of compliance. Learn more about each of the RF assessments below and submit the form if you are interested in getting access. You can also reach out to RF’s Entity Engagement team via the dropdown on our Contact Us page if you have any questions. 

If you’ve already been granted access to the self-assessments, you can access them on the RF Extranet here.

Request Access to Security Assessments & Scenarios

This field is for validation purposes and should be left unchanged.
Please do not submit any confidential or sen​sitive information ​(including CEII, BCSI) using this form or via email. By filling out this form, you gain access to our Entity Resource Center with these resources.
Name(Required)
Which resource(s) are you interested in?
ReliabilityFirst offers these self-assessments as part of our commitment and mission to ensure and improve grid reliability.

How it works

Use CSET software or simplified Excel sheet

These assessments are available using open-source software from the Cybersecurity and Infrastructure Security Agency (CISA) called the Cyber Security Evaluation Tool (CSET). CSET is a free, qualitative self-evaluation software that will generate an extensive report identifying areas of improvement for BPS operators.

Not interested in downloading software? We have also made simplified Excel sheets to reflect the assessments as an alternative. 

Get access

Entities can download our free custom assessments after applying through the form below, which will grant access to a series of questions related to your organization’s operational resilience. Import the RF assessments into CSET, read the descriptions, and submit your answers to evaluate your organization’s posture on different focuses. 

After evaluating operational readiness, you can work with the RF Entity Engagement department’s subject matter experts to review and evaluate your results.

RF will not have access to entity data

CSET is locally stored desktop software and RF will not have access to any information you submit. This tool was created by CISA, which is the operational lead for federal cyber security and the national coordinator for critical infrastructure security and resilience in the U.S.

Registered entities across ERO Enterprise are eligible

Any registered entity within the Electric Reliability Organization (ERO) Enterprise that is involved with ensuring the security, reliability, resilience and operations of the BPS is eligible to use these assessments.

What to expect

Based on the pilot participants, the Cyber Resilience and Insider Threat Assessments may take a few hours to complete. You may pause the assessment at any point, the responses will be automatically saved, and you can resume at a later time. The time may vary based on your program/size/knowledge and the number of people involved. 

The Incident Response Tabletop scenarios are modeled after real-world threats to the BPS and can be customized to meet your organization’s goals in testing and drilling incident response, procedures and capabilities. Some scenarios are large campaigns that can be spread out over several days with multiple departments. Some scenarios are smaller and focus on a specific type of risk. It can be a company-wide engagement or a small group. The scenarios can be paused and resumed at your convenience, and the responses will be automatically saved. 

Incident Response Tabletops are not a replacement for GridEx. However, they are complementary to GridEx and they can be used in a more on-demand format. GridEx is a well-established, remote, distributed grid exercise simulation event performed across North America every two years. It is led by NERC’s E-ISAC, which helps facilitate the development of scenarios, manages, and leads the event. Our scenarios can help entities improve, prepare, and practice for real-world incidents and other simulated events such as GridEx. The best way to use these two tools together is to use our scenarios to test, improve and hone incident response capabilities on a continuous basis and use GridEx as a way to test and grade capabilities and progress every two years. 

Cyber Resilience Assessment

Cyber Resilience Assessment logo

ReliabilityFirst’s Cyber Resilience Assessment allows entities to evaluate their cyber resilience posture, as well as measure effectiveness. This tool will characterize the operational resilience of an entity’s BPS infrastructure in the presence of cyber attacks.

The assessment output is an extensive report that will give BPS operators the ability to identify areas of improvement through deeper insights into components and processes that impact cyber resilience.

The BPS depends upon interconnected Operational Technology (OT), Information Technology (IT), communication networks, and infrastructure to maintain a reliable grid. Cybersecurity threats evolve rapidly and critical infrastructure is an appealing target for threat actors. As cyber threats targeting the energy sector continue to grow, entities must be prepared to defend against, respond effectively, and recover fast when incidents occur.

By evaluating cyber resilience, entities are challenged to test their strengths while also identifying gaps in operations, organizational, personal, and physical security.

Insider Threat Assessment

Insider Threat Assessment logo

ReliabilityFirst’s Insider Threat Assessment allows entities to evaluate their program’s maturity against multiple practice areas in relation to insider threats. Understanding potential insider threat behavior is not only about identifying signs of negative behavior, but also understanding what processes and incentives your organization has in place to empower employees to do the right thing and help identify where there may be an unwitting insider threat. 

Energy critical infrastructure with a large and dispersed cyber and physical footprint brings its own challenges to ensuring reliability, security, and resilience of the BPS. Insider threat risk management is not covered under enforceable NERC cyber or operational standards, although some aspects of insider threat are broadly addressed under NERC Reliability Standards CIP-004 (Cyber Security – Personnel & Training), CIP-006(Cyber Security – Physical Security of BES Cyber Systems), CIP-007 (Cyber Security – System Security Management), and EOP-004 (Event Reporting).

In order to holistically address risks from insiders to reduce the potential for disruptions to the BPS, awareness of best practices regarding insider threats is important, as well as assessing an existing program or establishing and building a new one. 

Incident Response Tabletops

Incident Response Tabletops logo

ReliabilityFirst’s Incident Response Tabletops allow entities to evaluate their incident response and recovery posture, as well as measure effectiveness by performing simulated cyber or physical incident exercises. All 17 tabletop scenarios within our Incident Response category are based on both real life adversaries threatening the energy landscape and real types of attacks. These include threat groups like SANDWORM, Volt Typhoon, Dragonfly, and more while attacks include Denial of Service, Ransomware, Social Engineering, and more.

The potential for disruptions in the BPS can be attributed to the dependence and vulnerabilities of the computer network interconnecting corporate systems, substations, generation plants, control centers, and physical security of those assets. Our Incident Response Tabletops work to promote and enhance grid reliability, security and resilience by enhancing the entities’ capabilities to respond to various types of cyber or physical security incidents. 

These on-demand scenarios and drills prepare our entities for a real-life cyber or physical security incident. Our scenarios help by:

  • Supporting risk management
  • Providing qualitative insights to improve resiliency
  • Motivating BPS operators and IT to work together
  • Educating entities on factors contributing to grid resilience