Skip to content

Author

Saman A. Zonouz

1 paper indexed here

We haven’t gathered this author’s papers yet. Follow them and we’ll fetch their work.

Not the right person? Other researchers publish under this name.

Sep 2026

Beyond the Checklist: Modernizing Cybersecurity Regulation for the U.S. Power Grid

The NERC CIP standards have been mandatory for more than fifteen years and are widely regarded as a baseline for securing the bulk power system, yet little is known about how the people who implement, audit, and write them experience the regulatory lifecycle in practice. Drawing on interviews with twenty two auditors, utility implementers, and standard drafters, this article synthesizes firsthand accounts of where compliance succeeds and where it creates friction. We find that prescriptiveness can hinder flexibility and encourage a check the box mentality, that the burden of proving compliance increasingly competes with substantive security work, and that workforce shortages and a persistent gap between information technology auditors and operational technology environments compound these difficulties across the lifecycle. Because the ultimate purpose of the standards is to prevent cyber events from producing physical harm, we connect these findings to the power engineering literature on cyber-physical risk in substations and argue for a shift from compliance-driven practice toward engineering-based methods that use system modeling, risk quantification, and analysis of cascading effects. We close with a roadmap for modernization built on risk-based auditing, flexible standards, specialized auditor training, and automation, with the goal of moving beyond mere compliance toward measurable operational resilience.

Sena Şahin, Burak Sahin, Robin Berthier et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.