Cybersecurity & the Digital Transformation: Key Considerations for Vendor Agreements in the Energy Industry

Morgan Lewis The energy industry faces unique challenges when it comes to cybersecurity and working with vendors on digital transformation projects. Energy is one of the “critical infrastructure sectors” identified in Presidential Policy Directive 21, and with good reason. Cyberattacks on our nation’s energy sector harm not only the energy companies themselves – a reduction in stable energy supply can impact the broader welfare, economic activity, and security of the country. Energy companies also face a complicated matrix of industry-specific regulations that vary by the type of energy produced. Additionally, state law tort claims can be extremely complex and expensive, with a strict standard of care based on continuous energy service (so any interruption in service can imply a breach of duty of care). Because of this increased liability, energy companies must take proactive steps to bolster their cybersecurity, while also keeping pace with the unprecedented digital transformation sweeping the industry. ENERGY VENDORS AND CYBERSECURITY REGULATIONS Though energy companies can increase their resources internally to combat cyberattacks, there is a heightened concern regarding the cyber risks created by outside vendors. As mentioned above, regulation of the US energy depends on the type of energy produced. Since the statutory regime […]

You may also like...