Skip to main content
Loading...
The Calibre Brief · Episode 31

FERC Approves Virtualization Standards for Grid Cybersecurity Compliance | The Calibre Brief Ep. 31

3 min watch Narrated from reporting by jason.ellis

About this episode

In this episode of The Calibre Brief, we explore the recent changes to grid cybersecurity rules following FERC's approval of new NERC standards. These revisions integrate virtualized operations into the CIP compliance framework, marking a notable shift in regulatory acknowledgment of virtual assets and shared infrastructure.

While virtualization presents opportunities for improved recovery, redundancy, and workload security, it also introduces risks, particularly concerning hypervisors and shared systems. The episode examines these risks, drawing on examples like the 2023 ESXiArgs ransomware campaign to highlight potential vulnerabilities.

However, questions remain about implementation and oversight. FERC's order does not mandate virtualization but requires clear criteria for "per system capability" exceptions, yet this oversight framework is still developing. Whether virtualization will enhance or jeopardize grid resilience depends on future compliance and regulatory evolution.

Key topics

Key moments

  1. 0:07 The electric grid increasingly relies on software that can move…
  2. 0:18 Picture a control application restored from a known-good…
  3. 0:44 In March 2026, FERC approved Order 919, revising eleven CIP standards…
  4. 1:14 That recovery promise carries a concentrated risk
  5. 1:55 Approval is only the start
  6. 2:25 FERC did not make the grid virtual
  7. 2:41 At The Calibre Brief from Calibre Code USA, should utilities…

Transcript

Show transcript

Welcome to The Calibre Brief, a Calibre Code USA production.

The electric grid increasingly relies on software that can move between machines. Regulators have changed the rules, but shared systems may change the risks.

Picture a control application restored from a known-good virtual-machine image after its server fails. It no longer belongs to one labeled box in one rack. Yet cybersecurity rules were built around physical hardware and fixed boundaries. Grid computing had begun to change beneath that model, creating a compliance problem before it became a policy change.

In March 2026, FERC approved Order 919, revising eleven CIP standards to accommodate virtualization. The order does not tell utilities to virtualize. It recognizes virtual cyber assets, shared infrastructure, and logical security boundaries. That lets a control workload restart on healthy hardware and supports tighter workload-level separation, often called microsegmentation.

That recovery promise carries a concentrated risk. A hypervisor console controls many virtual workloads on shared hardware. A compromise could reach beyond one machine. The 2023 ESXiArgs ransomware campaign encrypted thousands of VMware ESXi hypervisors worldwide after exploiting a vulnerability with an available fix. This shows risk, not a grid attack. FERC adopted a per system capability exception, but NERC must create criteria and mandatory reporting.

Approval is only the start. The standards took effect May 26, but their requirements will become enforceable in stages over several years. Secure virtualization demands architecture, patching, isolated management systems, monitoring, and skilled staff. Larger utilities may have more capacity for that work than smaller municipal or cooperative systems, leaving uneven protection across the grid.

FERC did not make the grid virtual. It admitted that virtual operations had outgrown a hardware-only rulebook. Now accountability must follow the shared infrastructure too.

At The Calibre Brief from Calibre Code USA, should utilities self-document cybersecurity exceptions, or report each one promptly to an external reliability authority? Comment below, like and subscribe on YouTube, and follow the podcast.

Download the transcript as plain text