Hard drive destruction for electric utilities and cooperatives under NERC CIP-011
CIP-011-3 Requirement R2 says a BES cyber asset leaves your control only after its media has been sanitized or destroyed, and that you can prove it. We destroy at the control center or the substation, inside your physical security perimeter under your escort, and hand you the serial-level record your regional entity will ask for at the next audit. Cooperatives, municipals, and investor-owned utilities across the ReliabilityFirst footprint.
What the rules require
- NERC CIP-011-3, Requirement R2Before reuse or disposal of a BES cyber asset (or an associated EACMS, PACS, or protected cyber asset), take action to prevent the unauthorized retrieval of BES cyber system information from its data storage media, and keep evidence. Destruction is the action; the media log is the evidence.
- NERC CIP-011-3, Requirement R1An information protection program for BCSI, including how it is handled and disposed of on any media, not only inside BES cyber systems. Engineering workstations, historians, and the laptops used for field maintenance hold BCSI too.
- NERC CIP-006 and CIP-004Physical access to the perimeter is escorted and logged, and vendor personnel with unescorted access or BCSI access need personnel risk assessments. Our crews work escorted, and our technicians have already passed criminal background checks.
- NERC CIP-013Supply chain risk management: the vendor risk assessment your program requires before we are engaged. Our due diligence kit is built to answer it.
- Audits and penaltiesRegional entities (ReliabilityFirst for most of our nine states) audit every three years and ask for the R2 evidence by asset. Violations carry penalties of up to $1 million per day per violation, and CIP-011 findings are among the most common in the industry.
- Customer data on the business sideBilling systems, customer portals, and smart-meter data fall under state privacy and breach laws and, for cooperatives with financial services, the GLBA Safeguards Rule. The same truck handles the corporate IT refresh as the control-center decommission.
How we handle it
We come to the site that holds the asset: the control center, the substation, the generating plant, or the cooperative headquarters. Media is removed under your escort inside the physical security perimeter, logged by serial against the asset identifier your CIP program uses, and destroyed at the truck before the asset is released, so there is no interval in which a drive with BCSI is outside your control. Crew names go to you ahead of time for badging; our technicians are U.S. citizens with criminal background checks, and we work within your CIP-004 and CIP-006 procedures rather than around them.
Utility media is not only hard drives. Protective relays and RTUs carry SD and compact-flash cards; HMIs and engineering workstations carry SSDs; historians and EACMS servers carry drive arrays; PACS controllers hold badge databases; field laptops hold configuration files. We disintegrate flash and solid-state media to 2 mm particles on NSA-listed equipment, degauss and shred magnetic drives, and open every device to confirm what is inside, logging “none found” when a slot is empty so your evidence covers the whole asset, not only the drives you knew about.
The Certificate of Destruction and media log are written so an auditor can trace each row to an asset in your inventory: asset ID, media serial, method, equipment, date, two technicians, your witness. Keep them with your R2 evidence and the retirement record. We schedule around outage windows, with weekends available on request for emergency circumstances, and for a control-center refresh we can process the full rack set in one visit.
Where we do it
Columbus, Akron, Cincinnati, Dayton, Toledo, Cleveland, Pittsburgh, Detroit, Lansing, Fort Wayne, Indianapolis, Charleston, Louisville, Wheeling, and everywhere else we go.
Read next
Questions from electric utilities and cooperatives
Does CIP-011 R2 require destruction, or is sanitization enough?
R2 requires action that prevents unauthorized retrieval of BCSI before reuse or disposal, and evidence that it was taken. Sanitization is permitted; destruction is the action whose evidence is simplest to defend, because the certificate and log show the media no longer exists rather than that a tool reported success. For assets leaving your control, we recommend destruction.
Can you work inside our physical security perimeter?
Yes, escorted, under your CIP-006 procedures. Crew names and citizenship go to you ahead of the visit for badging, phones stay in the truck, and the machines never leave the truck, which parks where you direct. You may inspect the equipment at any time.
Do your technicians need CIP-004 personnel risk assessments?
Escorted vendors normally do not, and our process does not require unescorted access or access to BCSI. If your program requires it anyway, our technicians have current criminal background checks and will complete your PRA process.
What about the flash cards in relays and RTUs?
SD and compact-flash cards are disintegrated to 2 mm on the same NSA-listed equipment as SSDs, because degaussing does nothing to flash memory. Bring the relay or the card; we log either by serial.
What evidence do we get for the audit?
A digitally signed Certificate of Destruction and a media log with one row per item: your asset identifier, the media serial, make and model, method, equipment, date, two technician IDs, seal numbers, and your witness. It is the R2 evidence for each asset and it references your inventory, not ours.
Do you serve cooperatives and municipal utilities?
Yes. Cooperatives and municipals hold the same relays, the same billing systems, and the same audit exposure as the investor-owned utilities, usually with a smaller IT staff. Most of our nine states sit in the ReliabilityFirst region, and next-day service covers Ohio, western Pennsylvania, southern Michigan, and northern West Virginia.
More answers on the FAQ.
