Electric cooperatives have been building cybersecurity muscle thanks in part to a regimen embodied in the RC3 program.
Short for Rural Cooperative Cybersecurity Capabilities, RC3 ran for just under five years and produced a range of resources, including risk assessments, tabletop exercise toolkits, workshops and technical outreach. Users from G&Ts serving nearly 2 million people to distribution co-ops with less than 4,000 members have lauded the program for helping improve their cybersecurity posture.
“RC3 is one of NRECA’s greatest additions to the program in the 20 years I’ve been in the co-op industry,” says Trina Zager-Brown, general counsel and manager of member services at White River Electric Association in Meeker, Colorado. “It has given structure and stature to how electric co-ops have recognized the importance of cybersecurity.”
The Colorado Rural Electric Association used RC3 resources to create a Rural Electric Cyber Achievement Program and Cyber Force, a team of co-op staffers who facilitate tabletop exercises.
“NRECA, Cynthia and her team developed exercises that are sophisticated, top-level but still relevant for small co-ops,” says Zager-Brown, who is also the facilitator-coordinator for Cyber Force.
Marc Child, information security program manager at Great River Energy in Maple Grove, Minnesota, called out a voucher program arranged through RC3 that gives co-op participants access to prestigious SANS™ cybersecurity training.
“People who didn’t normally get selected for SANS courses got training,” he says. “The value of that voucher cannot be overstated.”
The Association of Illinois Electric Cooperatives now conducts RC3 self-assessments at member co-ops in a two-day process that identifies potential vulnerabilities across their networks.
“Several CFOs and operations managers have come up to me to say they were kind of hesitant to dedicate that time, but they were really glad they stuck it through,” says Dan Gerard, the statewide’s chief technology officer “RC3 is applicable across all departments of a co-op. No department goes untouched by the assessment.”
Paul Hofman, vice president for information technology at Central Iowa Power Cooperative in Cedar Rapids, says one of RC3’s biggest impacts is helping co-op boards appreciate the need for allocating cybersecurity resources.
“A lot of directors didn’t grow up with cyber-risks,” he says. “To help them understand, RC3 put meat on the bones of the need and how they can impact it.”
He says another benefit has been satisfying state governments that additional cybersecurity regulations for electric cooperatives are not needed.
“RC3 is a big reason for the statewide to go to regulators and say, ‘We are being very proactive,’” Hofman says.
The final NRECA report notes that the RC3 team was “thrilled” to see co-ops taking independent efforts to further the program and listed several areas where additional work could be taken up.
“RC3 laid the groundwork,” Child says. “We need to keep it going.”
Visit cooperative.com/programs-services/bts/rc3 for more information.