For energy industry, NERC compliance is not security | Internet News

For energy industry, NERC compliance is not security

Written By
Alex Goldman
Alex Goldman
Aug 5, 2009
1 minute read

Complying with the energy industry’s NERC standard will not make energy companies secure, according to a report released today by security company LogLogic.

“Compliance is necessary but not sufficient for security,” Dominique Levin, LogLogic executive vice president of marketing, told InternetNews.com.

“Compliance is a good baseline and helps IT managers justify the security spend, but security and compliance are not the same,” she added. “PCI-compliant companies still get hacked.”

She said that in one case, a company’s auditors decided that NERC rules meant that security had to be applied equally across the network, and that decision made the network less secure as the IT manager could not focus the security spend on protecting critical assets.

Internet News Logo

InternetNews is a source of industry news and intelligence for IT professionals from all branches of the technology world. InternetNews focuses on helping professionals grow their knowledge base and authority in their field with the top news and trends in Software, IT Management, Networking & Communications, and Small Business.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.