A Coordinated Electric System Interconnection Review—the utility’s deep-dive on technical and cost impacts of your project.

Gap Analysis Explained

Date icon D

January 17, 2022 | Blog

What is Gap Analysis & Risk Assessment? | Keentel Engineering Company

NERC, also known as The North American Electric Reliability Corporation, issued CIP (Critical Infrastructure Protection) cyber security standards in 2003. These were introduced to safeguard the electrical systems. However, in 2006, FERC (the Federal Energy Regulatory Commission) approved the proposed standards, thereby making them mandatory. Hence, CIP cyber security standards became enforceable across all bulk power system users, operators and owners.Furthermore, those bulk power system users or operators who failed to take the needed security precautions and steps were therefore exposed to the electric cooperative and greater risk such as:


  • High chances of service disruption
  • Regulatory fines/penalties

All this has led to the increasing demand for gap analysis and risk assessment. Companies like Keentel Engineering can help utility and IPPs perform a gap analysis. This Risk Assessment utilizes a risk-based approach much needed to identify critical infrastructure vulnerabilities throughout the entire enterprise. It helps:


  • Protect network access points along with cyber assets
  • Assess its effectiveness against the industry standards
  • Determine and evaluate current risk
  • Build an improved security posture
  • Successfully meet compliance requirements


Gap Analysis—Areas of Focus

Gap analysis focuses on the following areas:

  • Ensuring sensitive data is secure
  • Providing sufficient information for making better risk management decision
  • Ensuring the network is secure
  • Ensuring the systems are securely configured
  • Managing, protecting, and securing confidential customer data and BES cyber assets

Therefore, a gap analysis is designed to assist the organization in identifying potential gaps in the security processes and systems. This analysis is primarily designed to help organizations prepare for the process of attaining NERC CIP compliance. Throughout the process, the assessors work cohesively with the organization’s technical, management, and assurance teams, providing a clear picture of the company’s overall compliance.


Although no NERC entity is 100 percent immune to cyber attacks, a proactive and all-encompassing strategy can indeed eliminate or lower many threats. Hence, getting your security right is crucial for compliance and reliability.

Therefore, it makes sense to invest in gap analysis to get a clear idea of the current state of your security and desired state in compliance with CIP NERC requirements. Moreover, the recommendations provided in the gap analysis should be immediately implemented and used to address and minimize the risks adequately.



A bald man with a beard is wearing a suit and a white shirt.

About the Author:

Sonny Patel P.E. EC

IEEE Senior Member

In 1995, Sandip (Sonny) R. Patel earned his Electrical Engineering degree from the University of Illinois, specializing in Electrical Engineering . But degrees don’t build legacies—action does. For three decades, he’s been shaping the future of engineering, not just as a licensed Professional Engineer across multiple states (Florida, California, New York, West Virginia, and Minnesota), but as a doer. A builder. A leader. Not just an engineer. A Licensed Electrical Contractor in Florida with an Unlimited EC license. Not just an executive. The founder and CEO of KEENTEL LLC—where expertise meets execution. Three decades. Multiple states. Endless impact.

A group of construction workers are standing next to each other with their arms crossed.

Let's Discuss Your Project

Let's book a call to discuss your electrical engineering project that we can help you with.

A bald man with a beard is wearing a suit and a white shirt.

About the Author:

Sonny Patel P.E. EC

IEEE Senior Member

In 1995, Sandip (Sonny) R. Patel earned his Electrical Engineering degree from the University of Illinois, specializing in Electrical Engineering . But degrees don’t build legacies—action does. For three decades, he’s been shaping the future of engineering, not just as a licensed Professional Engineer across multiple states (Florida, California, New York, West Virginia, and Minnesota), but as a doer. A builder. A leader. Not just an engineer. A Licensed Electrical Contractor in Florida with an Unlimited EC license. Not just an executive. The founder and CEO of KEENTEL LLC—where expertise meets execution. Three decades. Multiple states. Endless impact.

Leave a Comment

Related Posts

A man in an orange vest is typing on a laptop computer.
By SANDIP R PATEL May 30, 2025
Explore the latest updates from NERC.com and what modernization means for power engineers and grid operators across the U.S.
A row of power lines are silhouetted against a blue sky at sunset.
By SANDIP R PATEL May 30, 2025
Dive deep into power system stability analysis with PSSE, TSAT, and PSCAD/EMTDC—from positive sequence to EMT simulations.
A man wearing a hard hat and safety glasses is using a tablet computer.
By SANDIP R PATEL May 30, 2025
Learn how power system operators can manage data for inverter-based resources (IBRs) using advanced information management practices.
A man is sitting at a desk in front of a computer monitor.
By SANDIP R PATEL May 30, 2025
Understand model accuracy and validation methods in EMT and PSPD simulations for inverter-based resources using top simulation tools.
A man and a woman are looking at a map.
By SANDIP R PATEL May 30, 2025
Explore best practices to ensure design stability in power systems and stay ahead of NERC reporting requirements in upcoming compliance cycles.
Change Management Process in Power Systems
By SANDIP R PATEL May 30, 2025
Discover how structured change management enhances planning and operations in modern power systems for greater reliability and compliance.
PJM Manual 14G Interconnection Services By Keental Engineering
By SANDIP R PATEL May 28, 2025
Navigate PJM generation interconnection with Keentel Engineering. We specialize in queue management, POI support, CIRs, feasibility studies, and SCADA compliance.
NERC Level 3 Alert IBR Generator Owners Compliance Checklist Power System Modeling Model Accuracy
By SANDIP R PATEL May 23, 2025
Get your compliance checklist for NERC Level 3 alerts. Essential reading for IBR generator owners navigating updated NERC requirements.
Integrative Applications of IEEE C57 Series Standards for Reliable and Compliant Substation Design
By SANDIP R PATEL May 21, 2025
Explore how IEEE C57 series standards support transformer reliability, substation diagnostics, and utility compliance in modern substation design.