SHARE
Facebook X Pinterest WhatsApp

For energy industry, NERC compliance is not security

Written By
thumbnail
Alex Goldman
Alex Goldman
Aug 5, 2009

Complying with the energy industry’s NERC standard will not make energy companies secure, according to a report released today by security company LogLogic.

“Compliance is necessary but not sufficient for security,” Dominique Levin, LogLogic executive vice president of marketing, told InternetNews.com.

“Compliance is a good baseline and helps IT managers justify the security spend, but security and compliance are not the same,” she added. “PCI-compliant companies still get hacked.”

She said that in one case, a company’s auditors decided that NERC rules meant that security had to be applied equally across the network, and that decision made the network less secure as the IT manager could not focus the security spend on protecting critical assets.

Recommended for you...

Facebook Becomes Meta, But Did It Move Too Soon?
Rob Enderle
Oct 29, 2021
Microsoft Gets Rid Of Passwords: I Can Almost Hear Angels Singing
Rob Enderle
Sep 17, 2021
Why AMD Has Been So Successful: Mark Papermaster
Rob Enderle
Sep 9, 2021
Another Crazy Week in Cybersecurity
Paul Shread
Jul 2, 2021
Internet News Logo

InternetNews is a source of industry news and intelligence for IT professionals from all branches of the technology world. InternetNews focuses on helping professionals grow their knowledge base and authority in their field with the top news and trends in Software, IT Management, Networking & Communications, and Small Business.

Property of TechnologyAdvice. © 2025 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.