ANRE: Grid cybersecurity investments recognized in tariffs — NRG-IA
Legislație & Reglementări Author: Ioana BuzoaicaCybersecurity is now part of the grid investment equation. ANRE assures operators that justified costs can be recovered through existing tariff mechanisms.
In power grids, investments are usually visible in kilometers of lines, transformers, and modernized substations. Cybersecurity is far less visible, but it can become decisive for an operator's ability to control and keep infrastructure running during an attack. The President of the National Energy Regulatory Authority (ANRE), George-Sergiu Niculescu, sent a direct message to operators following the RO 3.0 conference dedicated to energy security: " There is no reason for an operator to delay a necessary cybersecurity investment citing the fear that ANRE will not recognize its costs, as long as they are necessary, properly substantiated, and documented. " This stance shifts cybersecurity from a secondary technical expense to a necessary investment for the safe operation of energy infrastructure. For transmission and distribution system operators, whose revenues are regulated, the ability to recover costs through tariffs is a direct factor in investment decisions. Cybersecurity enters the regulated investment mechanism ANRE's methodologies for the current regulatory period allow for the consideration of justified costs associated with transmission and distribution activities and establish the mechanisms through which eligible investments enter the regulated asset base. For distribution, the framework is set by ANRE Order No. 67/2024. For transmission, Order No. 68/2024 stipulates that a recognized cost must be necessary, timely, efficient, and reflective of market conditions. This screening remains valid for cybersecurity as well. The ANRE president's statement does not mean automatic recognition of any IT purchase or expense. Operators must demonstrate the necessity of the investment, substantiate it, and document it according to regulatory rules. However, the institutional message is unambiguous: the fear that a justified investment in cyber protection will not be recognized must not be used as an excuse to delay it. Niculescu summarizes the Authority's position in even more direct terms: " We have created the regulatory framework. Operators must invest and protect their infrastructure. " Cyberattacks can cross over from IT to physical grid operations The risk does not only concern computers and administrative systems. Modern power grids use digital systems for monitoring, communications, automation, and control. An attack that reaches operational systems can impair the operator's ability to control physical equipment and processes. The International Energy Agency points out that severe cyber incidents in the electricity sector can lead to the loss of control over devices and processes, equipment damage, and service interruptions. The most famous precedent remains Ukraine. In December 2015, a coordinated attack on distribution companies knocked out at least 27 substations and left approximately 225,000 consumers without electricity for between one and six hours . The attackers penetrated control systems and remotely operated grid equipment. This example demonstrates that cyber risk in the energy sector can produce a measurable physical consequence: power outages. DNSC warns of growing pressure on the energy sector Romania is not starting from a purely theoretical risk. The Director General of the National Cyber Security Directorate (DNSC), Dan Cîmpean, stated in 2026 that attacks and attempted attacks on the energy sector are constantly increasing and that Romanian energy companies have already been affected by incidents. There is no confirmed cyberattack in current public documentation that has caused a national power outage in Romania. However, there is enough hostile activity for energy infrastructure protection to be treated as an operational obligation, not an optional investment. The legal framework points in the same direction. Emergency Ordinance (OUG) No. 155/2024, through which Romania transposed the European NIS2 directive, obliges target entities to adopt proportionate technical, operational, and organizational measures to manage cyber risks. Furthermore, the electricity sector has a dedicated European framework. Delegated Regulation (EU) 2024/1366 establishes requirements for the cybersecurity of cross-border electricity flows, risk assessment, monitoring, and incident management. The ANCPI incident shows the cost of critical system downtime Niculescu also cited the cyberattack on the National Agency for Cadastre and Land Registration (ANCPI) as an example of the effects when critical digital infrastructure becomes unavailable. On July 14, 2026, ANCPI detected unauthorized access to its infrastructure. The technical investigation later confirmed a ransomware attack that encrypted and deleted part of the virtualization infrastructure hosting the institution's applications. The e-Terra system, email services, and other applications became unavailable, and the fully digitalized nature of the workflow temporarily prevented both the registration of new requests and the resolution of those already…