[HN Gopher] New rule would give electric utilities incentives fo...
       ___________________________________________________________________
        
       New rule would give electric utilities incentives for investing in
       cybersecurity
        
       Author : geox
       Score  : 72 points
       Date   : 2023-06-24 15:29 UTC (7 hours ago)
        
 (HTM) web link (www.federalregister.gov)
 (TXT) w3m dump (www.federalregister.gov)
        
       | Bloating wrote:
       | electric utilities are the poster boys of cronyism... regulatory
       | capture, guaranteed returns by socializing costs.
        
       | imchillyb wrote:
       | Electric Utilities in the USA don't require incentives. The
       | Electric Utility companies are monopolies and regulated by the
       | State. These companies need RULES to follow, or the regulators
       | auction off their property and sell it to someone that will
       | follow THE RULES.
       | 
       | Screw incentivizing this and mandate it instead. Follow the rules
       | or lose your company.
        
       | samstave wrote:
       | This makes me quite mad, actually - we need thee reverse of this
       | bill:
       | 
       | "Act for PENALIZING infrastucture companies, financial companies,
       | utility companies and other key compnents to USA's national
       | security and economy, by failing to invest in cyber securirty,
       | egregious data leaks/losses/deletions as penalized financialy,
       | quartly following audits until complaince is met."
       | 
       | We should be "incentivising them" -- we did that alreadfy, and
       | failed so many times:
       | 
       | * gas tax to people, subsidies to oil companies for cheap gas,
       | better roads and exanding refining capabilities <-- Total failure
       | 
       | * 4 billion 'incentive' to AT&T for high speed internet infra, in
       | the 1990s?(or early 2000s) - they took the money and did nothging
       | with it
       | 
       | * Rail subsidies and many billions wasted on a failed study for a
       | highspeed rail
       | 
       | * Food sunsidy incentives to keep prices low (oh look at all the
       | food processing facilities that blew up, or caught fire during
       | the pandemic and a large inflationary period.
       | 
       | * Bank bailouts to keep people from getting financially destroyed
       | by interest hikes, etc...
       | 
       | * Lets help Ukraine with billions in arms sales and money which
       | loops right back to back-door kick-backs to both actual
       | politicians and defense contractors etc.
       | 
       | (I personally believe we are pummeling Ukraine with billions in
       | un-auditable funds to hide the corrupt kickbacks coming from
       | these to the US politicians, and some of their family members)
       | 
       | Incentives like this are simply a grift act on the taxpayers,
       | again.
       | 
       | --
       | 
       | I know we dont like GPT much in comments - but I find it great
       | for summarizing PDFs from any .gov link:
       | 
       | ---
       | 
       | Title: Incentives for Advanced Cybersecurity Investment Act
       | Summary
       | 
       | The Incentives for Advanced Cybersecurity Investment Act, as
       | outlined in the provided document, aims to encourage and support
       | organizations in investing in advanced cybersecurity measures.
       | The act offers financial compensation in the form of grants and
       | incentives to qualifying entities that make substantial
       | investments in cybersecurity technologies and practices. Here is
       | a summary of the key points regarding compensation and
       | qualifications:
       | 
       | 1. Compensation Offered: The act provides financial support to
       | eligible entities through grants and incentives. The compensation
       | is structured into two categories: Grants for Advanced
       | Cybersecurity Investments (GACIs) and Cybersecurity Investment
       | Tax Credits (CITCs). The specific compensation amounts are
       | detailed in the document and are subject to change over time.
       | 
       | A. Grants for Advanced Cybersecurity Investments (GACIs): GACIs
       | are non-repayable funds granted to qualifying organizations to
       | support their cybersecurity investments. The grants are designed
       | to help cover the costs associated with implementing advanced
       | cybersecurity measures, technologies, and training programs.
       | 
       | B. Cybersecurity Investment Tax Credits (CITCs): CITCs offer
       | eligible entities tax credits based on their investments in
       | advanced cybersecurity. These tax credits aim to provide
       | financial incentives to organizations that invest in
       | cybersecurity technologies and practices.
       | 
       | 2. Qualifications for Applying: To be eligible for the grants and
       | incentives provided by the act, organizations must meet certain
       | criteria. The qualification requirements include:
       | 
       | A. Entity Type: The act is applicable to various types of
       | entities, including but not limited to:
       | 
       | - For-profit organizations
       | 
       | - Non-profit organizations
       | 
       | - Educational institutions
       | 
       | - State, local, tribal, and territorial governments
       | 
       | - Federal government agencies (subject to specific conditions)
       | 
       | B. Cybersecurity Investment: Entities must make a significant
       | investment in advanced cybersecurity technologies, practices, or
       | training programs. The act defines the investment threshold and
       | specifies the qualifying cybersecurity areas.
       | 
       | C. Certification and Compliance: Applicants may need to
       | demonstrate compliance with certain cybersecurity standards or
       | obtain relevant certifications to be considered for the grants
       | and incentives.
       | 
       | D. Reporting and Documentation: Entities are required to provide
       | detailed reports and documentation to substantiate their
       | investments, costs, and compliance efforts. These documents may
       | include receipts, invoices, training records, and other relevant
       | evidence.
       | 
       | It is important to note that the specific details, requirements,
       | and eligibility criteria may vary and are subject to updates. It
       | is recommended to refer to the original document provided for the
       | most accurate and up-to-date information.
        
         | OldGuyInTheClub wrote:
         | I agree. Securing computer systems is a part of doing business,
         | not something that needs wheedling and cajoling. Bottom dollar
         | that these outfits will come for a bailout when (not if)
         | they're compromised.
        
           | samstave wrote:
           | I started to use AutoGPT and Chat GPT to look for grift in
           | congress, along with fines
           | 
           | I was looking up announcements for certain industries /
           | companies who announced large projects granted/influenced by
           | legislation, then grants and associated politicians
           | investments from opensecrets.org... - it was pretty tedious
           | with the free account - Ill need GPT 4 to do what I would
           | like --
           | 
           | It will be great to have 'GovWatchGPT' monitor acts such as
           | these, the companies that apply, granted, success/fail and
           | the politicians they donated to, and whom invested into their
           | companies just prior to an act passing.
           | 
           | Doing things like this between AutoGPT, and ChatGPT - you can
           | see kind of how I was starting to look at congress, but to
           | get current articles and such, had to use autoGPT - but it
           | was having issues saving data...
           | 
           | --
           | 
           | https://chat.openai.com/share/7dd61596-c83a-4c24-98f2-b39b3e.
           | ..
        
       | NoZebra120vClip wrote:
       | Whenever I see the phrase "investment in cybersecurity", I sigh a
       | little bit. It's nice to spend money on important things, and you
       | can seldom improve anything without spending money on it. But
       | cybersecurity is one of the things that you can't improve just by
       | enlarging its budget. You build a culture. You hire personnel who
       | care about it. You train your employees. You set policies and
       | establish structures.
       | 
       | You can't just purchase a "deluxe cybersecurity firewall
       | appliance" and plug it into your network, even if it costs
       | $50,000. I bet that a lot of people believe that's what it takes,
       | though.
       | 
       | Compare this to, say, education funding. It's good to spend more
       | money on schools, right? I mean, teachers gotta be paid, students
       | need (Chrome)books. But I always vote "no" on municipal school
       | bond measures. I believe that money isn't everything, and I
       | believe that it funds the wrong kind of things. The measures
       | always pass, though, so don't worry, I'm not oppressing all the
       | little kids in town.
        
         | buggythebug wrote:
         | It's a utility company - someones uncle booger works there -
         | there will always be zero culture there _face palm_
        
         | nunuvit wrote:
         | Never heard of a hardware vendor accepting payment in the form
         | of company culture.
        
         | carabiner wrote:
         | I worked at an electric utility in the tech side and we had a
         | steady brain drain of guys going to Google, Meta in order to 2x
         | or 3x their TC. Money talks.
        
           | KennyBlanken wrote:
           | https://www.google.com/search?q=US+electric+industry+profits
           | 
           | That seems to be a "management is unwilling to pay enough"
           | problem, not a "the industry is struggling and needs a
           | government handout for relief from the burden of enhancing
           | security" problem.
           | 
           | Congresscritters are demanding we cut "fat" out of basic
           | social assistance programs by increasing requirements from
           | beneficiaries but we're going to give electrical companies,
           | _making half a trillion in profits running basic
           | infrastructure_ , a big handout, with trivial or no
           | requirements?
           | 
           | Pass.
        
         | enkid wrote:
         | Money isn't everything, but it's really hard to run an
         | effective school or cyber security enterprise without money.
        
           | piuantiderp wrote:
           | This is lost to many in the West. There are things you cannot
           | buy or strong arm your way out
        
           | NoZebra120vClip wrote:
           | Well that's a strawman. I've seen churches, corporations, and
           | families being run on amazing shoestring budgets, but you
           | couldn't tell from the outside, because the holder of the
           | purse strings was judicious about spending.
           | 
           | Years ago, I learned a peculiar thing about corporate or
           | municipal budgets: sometimes a line item has to be spent or
           | it won't come back next year. So there is often some strong
           | impetus to spend $XXX,XXX -- or else -- and the deadline
           | comes on June 30, and often that is how you arrive at bad
           | spending decisions, because it's "burning a hole in your
           | pocket".
        
             | enkid wrote:
             | That's not what the word strawman means.
        
               | NoZebra120vClip wrote:
               | "it's really hard to run an effective school or cyber
               | security enterprise without money."
               | 
               | GP is actually understating this; if my budget and
               | revenue is $0, then I cannot run a school or enterprise
               | at all and it will file for bankruptcy and close.
               | 
               | A strawman is the informal fallacy of refuting an
               | argument different from the one being discussed. I never
               | said that a budget should be $0 or "without money".
               | That's a _reductio ad absurdum_.
        
         | bojo wrote:
         | Having helped implement NIST 800-171 for a small enterprise
         | company preparing to work prime government contracts I can
         | assure you it costs money either way.
         | 
         | Time and money spent working with cybersecurity professionals
         | writing SOG/SOPs which map the business practices to the
         | standard. Money spent buying and setting up some of the
         | necessary equipment to handle CUI properly. Time (indirectly
         | money) spent redoing decades old business processes to map to
         | the new paradigm. Time (indirectly money) as the business spent
         | time training their staff up on the components relevant to
         | their business units.
         | 
         | I agree that building a culture is at the root of it, however,
         | that culture alone isn't going to move the needle unless
         | everything else is in place as well. Worse, you have to walk
         | the company through the 5 phases of grief because in general
         | people don't entirely understand what is actually going on and
         | why it's important. "So you can get government prime contracts"
         | is an easy answer, but doesn't erase the confusion behind all
         | of the hand-wavy procedural work required to execute them.
        
           | konschubert wrote:
           | I'm not convinced that implementing cybersecurity standards
           | actually improves security.
        
             | bojo wrote:
             | No disagreements there. What's a better answer though? No
             | one wants to do it, most non-tech people don't understand
             | it, yet the standards and procedures need to improve to
             | reduce the attack surface area - especially for businesses
             | which support critical infrastructure.
        
               | konschubert wrote:
               | You could legally mandate companies to insure themselves
               | against cybersecurity risks.
               | 
               | It's really an interesting idea:
               | 
               | https://www.cato.org/sites/cato.org/files/serials/files/r
               | egu...
               | 
               | This creates a "market for effective practices", because
               | companies that follow good security practices would get
               | cheaper insurance.
               | 
               | But it would allow insurances and companies to figure out
               | dynamically what is cost effective and what isn't.
               | 
               | There would be lots of financial incentive to figure out
               | what protects you effectively and what is just security
               | theatre.
        
               | Veserv wrote:
               | Most companys already do. Unfortunately for the insurance
               | companys their actuarial tables are backwards looking and
               | cyberattacking is one of the fastest growing industrys.
               | 
               | The smart insurance companys are all getting out of
               | cybersecurity insurance because the premiums on the
               | policys they wrote 10 years ago when the average attack
               | cost $1,000 to remediate do not look so good when the
               | average attack now costs $100,000 to $1,000,000 to
               | remediate. Since the expected probability of a successful
               | attack in any given year that requires payout is
               | approaching 100% these days the insurance needs to be
               | priced something like 10x-100x the prevailing prices to
               | be survivable.
               | 
               | Eventually it will shake out once the cyberattacking
               | industry becomes mature because at that point backwards
               | looking projections make sense. Until that time, we are
               | in for a wild ride.
        
         | [deleted]
        
         | kyawzazaw wrote:
         | Don't you need money(investment) to hire personnel, training,
         | etc?
        
         | evanreichard wrote:
         | So just be smart about how you spend your money? Like any other
         | department?
        
           | balderdash wrote:
           | It's not about smarts it's about incentives, if I'm
           | incentivized to buy cybersecurity equipment but there is no
           | incentive or penalty for not actually preventing
           | cybersecurity breaches, a whole bunch of stuff is going to be
           | bought with little effect.
        
         | jlund-molfese wrote:
         | The government only has so many levers it can pull, though.
         | Even if we, the enlightened of HN have some idea of which
         | investments are beneficial (for example, hiring a good CISO
         | instead of buying the $50K cybersecurity box), laws and
         | policies move too slowly and are too hard to change once
         | enacted.
         | 
         | So this situation still seems better than a rule which only
         | benefits companies that hire Cisco Certified Security Posture
         | Experts or something. There's at least a chance that some of
         | these companies have competent CTOs (or equivalents, at smaller
         | utilities) and will spend in the right area.
        
           | balderdash wrote:
           | Government has plenty of levers to pull - they just don't
           | pull them.
           | 
           | Want to have utilities (or any industry) put cyber security
           | front of mind? Just tell them that they are liable for
           | consequential damages for any service outages related to a
           | cyber security incident, and watch how good they get at
           | cybersecurity.
        
         | candiddevmike wrote:
         | All I see here is a government subsidy for security vendors.
         | I'd rather see more liability and insurance requirements for
         | security breaches, including personal liability for executives.
         | Whatever it takes to get past checkbox-driven security.
        
           | gtowey wrote:
           | And schools are just a subsidy for the textbook industry.
           | 
           | Regulation & incentives are literally the tools governments
           | have to shape policy. It's a start, but moving the needle on
           | issues can be hard, slow work -- especially when it seems
           | like so many people have the attitude that if a particular
           | action wasn't the their perfect, preferred solution, then it
           | shouldn't have been done at all.
        
             | hedora wrote:
             | In your analogy, the vendors are the people manufacturing
             | textbooks that are mandatory, but never get opened and
             | cannot be resold on the used market. The regulators are the
             | administrators (or whoever) that require the useless
             | textbooks.
             | 
             | Of course, there are many useful textbooks with none of the
             | above properties, but they don't require complicated
             | incentive structures to ensure they're made mandatory.
        
         | halJordan wrote:
         | This is intensely defeatist. Regulations and compliance are
         | essentially what you described and they work for banks (despite
         | the clever responses I'm sure are incoming). For the critical
         | industry sectors they need to be buying the 50k appliance. And
         | they need to be looking at a checklist that they only want to
         | complete to avoid fines. Culture will accrete later.
        
           | hedora wrote:
           | I disagree with the GP's approach of defunding education to
           | improve education, but I've seen the culture that accretes
           | from checklists and expensive security appliances.
           | 
           | Everyone involved correctly comes to the conclusion that the
           | company's security policy is purely performative.
           | 
           | The people that care leave. The people that don't care about
           | securing the system implement the useless checkboxes and put
           | the standalone box in the correct room (and might even plug
           | it in), then get promoted.
           | 
           | FIPS security certifications are the poster child for this.
           | There's basically no way to get a securely architected system
           | certified, so you end up adding vulnerabilities and (in the
           | best case) a configuration parameter like the old "enable
           | FIPS certification (default off; do not enable unless you are
           | required to do so)" button from windows.
        
           | kortilla wrote:
           | 50k appliance doesn't do shit if people work from their
           | personal laptop and use shared passwords.
           | 
           | The only thing a regulation that mandates a 50k appliance
           | will do is boost the appliance makers sales.
        
             | hinkley wrote:
             | An appliance also externalizes responsibility. I don't need
             | to think of anything, because we have the box that goes,
             | "ping".
        
           | kodah wrote:
           | Regulations are rules, this is a formalized incentive
           | structure. They're a tad different.
           | 
           | Regulation is good to a degree; there's a balance to strike
           | between overly burdensome regulation and regulation which
           | basically may as well not exist. The lines between these are
           | sometimes vague as the times evolve and are also subject to
           | regulatory capture by interest groups (political groups and
           | companies).
           | 
           | The incentive structure generally makes spending money free
           | or more free so long as an entity abides by the guidelines
           | set out by the incentive.
           | 
           | You need both and both need to reflect the correct goals for
           | the times.
        
           | akira2501 wrote:
           | > This is intensely defeatist.
           | 
           | It's realistic.
           | 
           | > Regulations and compliance
           | 
           | Which might be nice. "Do this, or you will be penalized like
           | this." These are marketed as "incentives" which is "Buy
           | something, anything, and here's some abstract additional
           | cash."
           | 
           | > And they need to be looking at a checklist that they only
           | want to complete to avoid fines
           | 
           | The problem here is, you do the checklist, and you get an
           | incentive. I wonder how that's actually going to be
           | implemented?
        
           | Veserv wrote:
           | It emphatically does not work for banks. They spend hundreds
           | of millions of dollars a year and any bank CISO would tell
           | you, off the record, that their systems could be completely
           | breached for less then a million dollars. That is not because
           | they suck at doing it, that is because commercial
           | cybersecurity is just plain garbage. That is literally the
           | best you can get no matter how much you spend and no matter
           | how "good" your people are if you use commercial IT security
           | practices. Nobody does better than that who uses anything
           | from a big brand cybersecurity vendor.
           | 
           | The only reason banks are not totally wrecked by cyberattacks
           | is that:
           | 
           | 1) They actually are being constantly attacked by ransomware
           | and the like, they just do not disclose it; I do not remember
           | the budget line item the payments all go under but it is one
           | of those compliance/administrative ones such as for
           | insurance.
           | 
           | 2) Cyberattacks, contrary to their standard portrayal as
           | always being run by "state-sponsored" groups to make the
           | companys being destroyed look better, are largely run by
           | kids. They are largely unsophisticated on financial and
           | business matters so do not know how much to ask for, how to
           | maximally leverage a breach as a first party (i.e. do not
           | know how to use say investment bank deal details to do
           | effective trades), and how to actually cash out large amounts
           | of money undetectably.
           | 
           | 3) The non cybersecurity processes and fraud detection are
           | actually fairly effective. There are large number of
           | accounting checks in place that make it very hard to do
           | simple hacks (like make the numbers in one account higher)
           | that can not be detected. Banks have the equivalent of very
           | complex, bespoke DRM systems that requires knowledge of
           | financial systems and of their internal processes to crack.
           | As I said before, the hackers are largely financially
           | unsophisticated, so it is very hard for them to do this.
           | 
           | No, it is intensely defeatist to just give up on actually
           | solving the problem and demanding useless security theater in
           | the vain hopes that it will somehow improve the situation.
        
             | samtho wrote:
             | > They are largely unsophisticated on financial and
             | business matters so do not know how much to ask for, how to
             | maximally leverage a breach as a first party (i.e. do not
             | know how to use say investment bank deal details to do
             | effective trades), and how to actually cash out large
             | amounts of money undetectably.
             | 
             | I wonder how many actually sophisticated attackers gain
             | access to banks and other companies and purposefully keep a
             | low profile but skim off low-bandwidth information meant
             | for internal communications only, then aggregate and sell
             | the intel to hedge funds or trade stocks on their own.
             | 
             | Maybe the reason why we think that most attacks are caused
             | by unsophisticated actors is because those are the one who
             | are actually detected.
             | 
             | Just kind of an interesting hypothesis that I've heard
             | variations of before.
        
             | tredre3 wrote:
             | Regulations and rules force banks to be held accountable.
             | Whether or not their cybersecurity prevents all breaches is
             | besides the point. They are incentive in minimizing
             | breaches, and when one occurs they're the one who have to
             | cover the losses (yes I'm sure you're already typing clever
             | examples of banks avoiding responsibility that one time but
             | the fact that we rarely hear about then, as you say
             | yourself, is that they cover it up and refund all the
             | losses themselves).
             | 
             | > demanding useless security theater in the vain hopes that
             | it will somehow improve the situation.
             | 
             | The security theatre required by these new rules might not
             | prevent all breaches, or any breaches, but they will force
             | utilities to be accountable for their failures.
             | 
             | No longer will it be "Oopsie, mean hacker hacked us. Not
             | our fault. Whatchugonna do anyway? Your business had to
             | shutdown because no power/internet? Tough luck I guess".
             | 
             | Now it will be "Oh fuck, hackers got in. We'll have to
             | cover our customers losses and spend millions in PR to spin
             | the story and avoid total bankruptcy."
             | 
             | Do you really not see how that's still an improvement?
        
               | hedora wrote:
               | That's not what regulators do in this space. Instead, the
               | rules are of the form "use certified vendor, and you will
               | be shielded from liability".
               | 
               | Also, the vendors and the people being shielded largely
               | write the rules.
        
               | Veserv wrote:
               | No, liability requirements force banks to be held
               | accountable. They do eat most of the costs of the direct
               | consequences of being hacked. Luckily for them, the
               | people hacking them are still, frankly, inexperienced
               | from a business perspective so their losses have to this
               | point been largely immaterial.
               | 
               | The losses are not low because the cybersecurity
               | processes and regulations are good, they are low because
               | even though the vault is being guarded by the
               | metaphorical equivalent a chihuahua, all they are doing
               | is stealing the pens because they do not know how to pawn
               | the gold in bulk.
               | 
               | This state of affairs is changing very quickly. 15 years
               | ago the hackers were walking into the vault and asking
               | for $1,000 because they were 16 year olds who thought
               | that was a lot of money. Now the good ones are 30 years
               | old and are still walking into the vault, but asking for
               | $10,000,000. Last I saw the number of attacks was
               | increasing 3x year over year and the average ask was
               | increasing 3x year over year.
               | 
               | The entire cybersecurity insurance industry is already
               | underwater at current premiums. I have heard they have
               | basically stopped issuing policys over a few million
               | dollars because it is literally ruinous. It is no longer
               | becoming possible to paper over the omnipresent security
               | deficiencys with insurance, betting on the incompetence
               | of the attackers, and betting only one of you is going to
               | get eaten.
               | 
               | The sensible solution right now would be liability
               | requirements on advertising security. You can not
               | insinuate you are "secure" whatever that even means. You
               | can instead only advertise a dollar amount per customer
               | which is tied to a mandatory bug bounty. If you are a big
               | bank with 100 million customers, you can put up a 10
               | billion dollar bug bounty on breaching your systems and
               | then you can advertise $100 of security on your customer
               | deposits.
               | 
               | This would force them to put their money where their
               | mouth is while not preventing new small companys from
               | existing as long as they truthfully report that they are
               | not providing security. It would also help us pull the
               | customer desired security requirements forward in time
               | instead of waiting for the destruction first.
               | 
               | Absent that, what is going to happen is that everybody
               | keeps lying about their security to trick their customers
               | into trusting them. Then one of them is going to get hit
               | by a truly expensive attack and all the customers will be
               | caught with their pants down.
               | 
               | The only technical solution to this is either dropping
               | reliance on these easily hacked systems, or throwing out
               | all the existing crap that was never designed for
               | security and can thus never be retrofitted to be secure
               | such as Microsoft, Linux, Cisco, and Crowdstrike. Instead
               | we must deploy systems designed for security such as
               | those targeted to conform to the (now deprecated) Orange
               | Book Class A1 or Common Criteria EAL 6/7 systems which
               | are certified and proven to resist nation state attackers
               | such as the NSA.
        
           | balderdash wrote:
           | Regulations and compliance is not what is being proposed
           | here.
        
         | mac-chaffee wrote:
         | > You can't just purchase a "deluxe cybersecurity firewall
         | appliance" and plug it into your network, even if it costs
         | $50,000
         | 
         | Those cost a quarter of a million per year nowadays...
        
       | photochemsyn wrote:
       | Any rational country would just nationalize the electric
       | utilities, as they constitute a natural monopoly and as such
       | there's no real competition. Eliminating the rentier investor
       | class the system makes a lot of sense in this case, as all
       | they're doing is running off with profits that would be better
       | invested in infrastructure (including cybersecurity).
       | 
       | This particular rule will most likely be gamed to increase rates
       | while providing no improvement in security, with a compliant FERC
       | nodding along under the current system of corporate regulatory
       | capture of government.
        
         | htag wrote:
         | Electrification happened ~100 years ago. In 100 years it seems
         | likely a combination of photovoltaic and storage will have
         | rendered the grid largely moot.
         | 
         | The electric utilities might be a natural monopoly today, but
         | moving to nationalize it is addressing yesterday's concerns. If
         | we're spending political capital to nationalize natural
         | monopolies the electric utilities would be very far down my
         | list of priorities.
        
       | balderdash wrote:
       | Utilities are in the business of spending capital so that they
       | can charge rate payers. Any subsidy that does not also include
       | alignment of incentives around outcomes is money wasted.
        
       ___________________________________________________________________
       (page generated 2023-06-24 23:02 UTC)