The American Public Power Association recently announced the inaugural set of public power utility Cybersecurity Accelerator Program (CAP) designees.
CAP helps public power utilities assess and improve the maturity of their cybersecurity programs, including the information technology and operational technology capabilities, governance practices, workforce preparation, incident response processes, and risk management activities that support reliable and resilient operations.
Included among the initial set of public power utility CAP designees are:
• Beaches Energy Services (Florida)
• Brownsville Public Utilities Board (Texas)
• Central Coast Community Energy (California)
• City of College Station (Texas)
• City of New Bern (NC)
• Clear River Electric & Water District (Rhode Island)
• Cleveland Utilities (Tennessee)
• Coldwater Board of Public Utilities (Michigan)
• Cowlitz PUD (Washington)
• Easton Utilities Commission (Maryland)
• Grand Haven Board of Light & Power (Michigan)
• Greenville Utilities Commission (NC)
• Hannibal Board of Public Works (Missouri)
• Holland Board of Public Works (Michigan)
• Hudson Light and Power Department (Mass.)
• Kansas City Board of Public Utilities (Kansas)
• Littleton Electric Light & Water Departments (Mass.)
• Missouri Public Utility Alliance (Missouri)
• Northern Wasco County People's Utility District (Oregon)
• Peabody Municipal Light Plant (Mass.)
• Riviera Utilities (Alabama)
• Roseville Electric (California)
• Snohomish County PUD (Washington)
• Southern Minnesota Municipal Power Agency (Minnesota)
• Stowe Electric Department (Vermont)
• Vernon Public Utilities (California)
• Wisconsin Rapids Water Works & Lighting Commission (Wisconsin)
• Zeeland Board of Public Works (Michigan)
Through the program questionnaire, utilities can assess their cybersecurity capabilities and practices across four main categories:
• Internal controls: the processes, practices, and technical safeguards that are essential for maintaining the confidentiality, integrity, and availability of your networks and data.
• Cybersecurity governance and training: the roles, responsibilities, structure, and resources that guide an organization’s security strategy, provide accountability, and ensure employees follow secure practices.
• Cyber incident response: the structured processes and procedures organizations use to detect, contain, and recover from cybersecurity events.
• Cyber risk management: the process of identifying, assessing, prioritizing, and mitigating risks to critical systems and data to reduce the likelihood and impact of cyber incidents.
Utilities that demonstrate implementation of core cybersecurity practices across all four categories may receive Gold, Platinum, or Diamond desigation based on their overall CAP score and utility size. Each level reflects a progressively stronger demonstration of cybersecurity program maturity within the applicable utility-size category.
CAP is designed not only to recognize utilities that demonstrate strong cybersecurity practices, but also to help every participating utility better understand and communicate its current capabilities, identify opportunities for improvement, prioritize future investments, and measure progress over time.
APPA will continue supporting public power utility cybersecurity by connecting CAP findings with relevant guidance, training, tools, and other resources. Whether or not a utility receives a designation, participation can provide a valuable foundation for understanding current capabilities and planning measurable improvements.
Earlier this year, Rob Denaburg, senior manager for cybersecurity at APPA, noted that participating in CAP has several benefits, which include allowing public power utilities to benchmark their cybersecurity performance against peers and identify areas for improvement.
