Skip to content
  • Solutions
  • Markets
  • Resources
  • About
Set Up A Call
Back

Solutions

The PCI Platform

New

A secure, reliable, high-performance, cloud-native foundation that powers our full-spectrum suite of solutions and natively integrates AI-enabled enterprise analytics

View the platform

AI

New

Insights

Hot

Security

Hot

Technology

Hot

Solutions

Energy Trading

ETRM

PCI ETRM

End-to-end energy trading, risk, and scheduling in one system

  • ETRM
  • Front Office: Gas & Fuels
  • Front Office: Power
  • Middle Office
  • Back Office
  • ETRM
  • Front Office: Gas & Fuels
  • Front Office: Power
  • Middle Office
  • Back Office

Bid-to-Bill

GenManager®

From first forecast to final bill, across every market

  • Bid-to-Bill
  • Forecasting
  • Market Participation
  • Scheduling & ISO Integration
  • e-Tagging
  • Meter Data Management
  • Settlements and Billing
  • Bid-to-Bill
  • Forecasting
  • Market Participation
  • Scheduling & ISO Integration
  • e-Tagging
  • Meter Data Management
  • Settlements and Billing

Portfolio Optimization

GenTrader®

Maximize portfolio value with integrated optimization

  • Portfolio Optimization
  • Energy Trading Optimization
  • Energy Storage Optimization
  • Forecaster
  • Long-Term Planning
  • Mid-Term Planning
  • Sustainable Energy
  • Portfolio Optimization
  • Energy Trading Optimization
  • Energy Storage Optimization
  • Forecaster
  • Long-Term Planning
  • Mid-Term Planning
  • Sustainable Energy

Transmission & Reliability

Transmission

New
Manage transmission rights, congestion, and settlements
  • Transmission
  • Transmission Scheduling
  • e-Tagging
  • Transmission Portfolio Opt.
  • BA Operations
  • Energy Accounting
  • Transmission
  • Transmission Scheduling
  • e-Tagging
  • Transmission Portfolio Opt.
  • BA Operations
  • Energy Accounting

Outage Management

New

Plan and coordinate outages with built-in compliance

  • Outage Management
  • Operator Logging
  • Gen. Outage Management
  • Trans. Outage Management
  • Line Rating Management
  • Outage Management
  • Operator Logging
  • Gen. Outage Management
  • Trans. Outage Management
  • Line Rating Management
Back

Markets

PCI Clients Map

Markets We Serve

A Global Footprint

PCI Energy Solutions serves utility companies, independent power producers, and wholesale power traders. We support customers in every organized market in North America and maintain a global presence across five continents.

Markets

Markets

North America

50%+ of North American power is optimized using the PCI Platform

Latinoamerica

PCI da soporte al 90% de la capacidad de generación eléctrica en México

Europe

HOT

PCI has a foothold in Europe with a growing presence

Australia

HOT

Modern outage management  tailored to Australia’s NEM and WEM utilities

Market Chatbots

ISO Bot

Popular

Ask energy market questions of an AI trained on ISO/RTO manuals

M+ Bot

New

AI assistant dedicated to up-to-date SPP Markets+ documentation

CEN Bot

New

Chatbot de IA sobre el mercado eléctrico CENACE

Back

Resources

promotional graphic for "Price Any DA/RT Trade in Under 5 Seconds: Live Demo with DART Trader" webinar

Webinar

Price DA/RT Trades in Under 5 Seconds

June 9, 2026

Register Now

Resources

Thought Leadership

Blog

New

Our industry thought leadership

  • ETRM
  • Market Participation
  • Gas & Fuels Management
  • Portfolio Optimization
  • Settlements and Billing
  • Generation Outage Management
  • ETRM
  • Market Participation
  • Gas & Fuels Management
  • Portfolio Optimization
  • Settlements and Billing
  • Generation Outage Management

Newsletter

Subscribe

Updates on product launches &more 

  • ETRM
  • Market Participation
  • Gas & Fuels Management
  • Portfolio Optimization
  • Settlements and Billing
  • Generation Outage Management
  • ETRM
  • Market Participation
  • Gas & Fuels Management
  • Portfolio Optimization
  • Settlements and Billing
  • Generation Outage Management

Webinars & Events

HOT

Live & on-demand discussions 

  • ETRM
  • Market Participation
  • Gas & Fuels Management
  • Portfolio Optimization
  • Settlements and Billing
  • Generation Outage Management
  • ETRM
  • Market Participation
  • Gas & Fuels Management
  • Portfolio Optimization
  • Settlements and Billing
  • Generation Outage Management

Case Studies

HOT

Real-world customer results

 

  • ETRM
  • Market Participation
  • Gas & Fuels Management
  • Portfolio Optimization
  • Settlements and Billing
  • Generation Outage Management
  • ETRM
  • Market Participation
  • Gas & Fuels Management
  • Portfolio Optimization
  • Settlements and Billing
  • Generation Outage Management

Customer Portal

INFOCUS Conference

Apr

Connect, learn, and shape our future

  • ETRM
  • Market Participation
  • Gas & Fuels Management
  • Portfolio Optimization
  • Settlements and Billing
  • Generation Outage Management
  • ETRM
  • Market Participation
  • Gas & Fuels Management
  • Portfolio Optimization
  • Settlements and Billing
  • Generation Outage Management

Product Trainings

New

Hands-on remote training

  • ETRM
  • Market Participation
  • Gas & Fuels Management
  • Portfolio Optimization
  • Settlements and Billing
  • Generation Outage Management
  • ETRM
  • Market Participation
  • Gas & Fuels Management
  • Portfolio Optimization
  • Settlements and Billing
  • Generation Outage Management

Issue Tracker

New

Track, manage, and resolve issues 

  • ETRM
  • Market Participation
  • Gas & Fuels Management
  • Portfolio Optimization
  • Settlements and Billing
  • Generation Outage Management
  • ETRM
  • Market Participation
  • Gas & Fuels Management
  • Portfolio Optimization
  • Settlements and Billing
  • Generation Outage Management

Product Documentation

New

Guides, references, and release notes

 

  • ETRM
  • Market Participation
  • Gas & Fuels Management
  • Portfolio Optimization
  • Settlements and Billing
  • Generation Outage Management
  • ETRM
  • Market Participation
  • Gas & Fuels Management
  • Portfolio Optimization
  • Settlements and Billing
  • Generation Outage Management
Back

About

A trusted partner since 1992

Our Values

Customer Success

Central

We succeed by creating happy customers

Continuous Improvement

New

We continually grow, adapt, and get better

Enlightened Awareness

New

Our character is revealed through our actions

Connectedness

New

Our genuine connections drive shared success

About Us

About

People

Careers

Hiring

Build the future of energy software

  • ETRM
  • Market Participation
  • Gas & Fuels Management
  • Portfolio Optimization
  • Settlements and Billing
  • Generation Outage Management
  • ETRM
  • Market Participation
  • Gas & Fuels Management
  • Portfolio Optimization
  • Settlements and Billing
  • Generation Outage Management

Leadership

HOT

Meet the leaders driving our vision

 

  • ETRM
  • Market Participation
  • Gas & Fuels Management
  • Portfolio Optimization
  • Settlements and Billing
  • Generation Outage Management
  • ETRM
  • Market Participation
  • Gas & Fuels Management
  • Portfolio Optimization
  • Settlements and Billing
  • Generation Outage Management

Connect

Contact Us

New

Talk with our experts today

  • ETRM
  • Market Participation
  • Gas & Fuels Management
  • Portfolio Optimization
  • Settlements and Billing
  • Generation Outage Management
  • ETRM
  • Market Participation
  • Gas & Fuels Management
  • Portfolio Optimization
  • Settlements and Billing
  • Generation Outage Management

Newsroom

New

Company news & announcements

  • ETRM
  • Market Participation
  • Gas & Fuels Management
  • Portfolio Optimization
  • Settlements and Billing
  • Generation Outage Management
  • ETRM
  • Market Participation
  • Gas & Fuels Management
  • Portfolio Optimization
  • Settlements and Billing
  • Generation Outage Management
  • Blog
  • How Do You Handle Cybersecurity and Third-Party Risk Management?
Share this post
Picture of Peter Samoray

Peter Samoray

Laptop computer with code displayed on the screen

How Do You Handle Cybersecurity and Third-Party Risk Management?

April 25, 2023
/
Cybersecurity

When a data breach occurs, and you have to tell your shareholders or customers that business-sensitive information or their personal information may have been compromised by one of your third-party vendors, nobody is going to look at the third-party vendor — they’ll be looking at the primary organization that was entrusted to protect the data and manage third-party risk appropriately.

A data breach often involves significant amounts of time, resources, and cost to fix a problem caused by a third-party risk that was not managed. However, regardless of how much you clean things up, no remediations will stop the reputational damage that will continue to cost your organization in lost business.

You cannot ignore the potential consequences of properly managing third-party risk.

Read our blog post, “How Can Generative AI Be Used in Cybersecurity?”

The "risk" of not managing third-party vendor cyber risk

In addition to managing third-party vendor risk and maintaining customer trust, cyber insurance is becoming necessary. Meanwhile, insurance premiums are increasing annually as the risk of cyber-attacks and the costs associated with a data breach increase. Effective third-party vendor risk management could make the difference between the cost of your premiums or insurers deeming your organization ineligible for coverage.

According to the global IBM Data Breach Report for 2022:

  • The average cost of a data breach in the U.S. is $9.44M
  • For 83% of companies, it’s not a matter of whether a data breach will occur but when and how prepared they will be to deal with such an event.

 

With today’s increasing integration of applications and interfaces between your organization and your third-party vendor, all aspects of cybersecurity hygiene come into play as your third-party vendor risks become your organizational risks.

There needs to be an examination of the multiple layers of third-party vendors with traceability and accountability at each level for cybersecurity and privacy practices that may impact your organization’s overall security and ability to fulfill regulatory compliance laws.

Organizations' Views of Third Parties (Adapted from ISACA.org: Managing Third-party Risk)

Third-party vendor risk management is critical to a solid cybersecurity and privacy program in both the public and private sectors.

The Department of Energy (DOE) has developed a concise Cybersecurity Capability Maturity Model for the Energy Sector C2M2 v2.1 June 2022, which spells out in several sections the importance of reviewing your third-party vendor’s cybersecurity practices. This process includes assessments of their third-party vendors’ security practices.

The Federal Trade Commission (FTC) cautions organizations that contract third-party vendors to manage sensitive personal data and security practices that should be in place.

The Cybersecurity and Infrastructure Security Agency (CISA) developed a Cyber Resource Hub to provide multiple resources to help the public and private sectors assess risk and their security processes, which can help manage third-party vendors.

Tips to lower your risk of third-party vendor risk management

One of the best ways to prevent a data breach is to understand why it would happen.

Malicious actors can have several motivating factors for breaking into an organization. Those factors could be financially or politically motivated, or the malicious actor is seeking vindication or plain old bragging rights among the hacker community. These motivating factors can help you understand why your organization may be a target.

Malicious actors may not always try to attack your organization head-on; they may go in through your employees, guests, or third-party vendors — whatever is the easiest method.

Below are some essential tips to help your organization manage third-party vendor risk and the best practices associated with each.

  1. Assess your third-party vendors’ security posture. Understand both their security and privacy program through an assessment. Understand what frameworks and security maturity model(s) their security and privacy programs are aligned with and their vulnerability management process, which could include external audits, certifications, and scanning. Request documented evidence regarding audit reports, security assessment certifications, or vulnerability remediations.
  2. Educate on compliance requirements. Ensure your third-party vendors thoroughly understand any global regulatory compliance laws and requirements your organization must comply with and any cascading requirements the third party needs to align with. Sharing these requirements with your third-party vendor will help your organization and benefit the third party in marketing their ability to support such global requirements.
  3. Employee awareness. People are often the weakest link in most organizations and one of the top causes of data breaches through poor security practices, phishing attacks, or a general lack of training on security best practices. Ensure that both your organization and your third-party employees are regularly training and testing on security and privacy best practices and appropriate actions to take.
  4. Collaborate regularly. Collaborate with your third-party vendors’ security teams to understand the shared risks, changing threat landscape, intel, and best practices. Having ongoing transparent dialogue will help your organization and third-party vendor organization increase their security postures, which is ultimately the goal of all security departments.
  5. Stay in touch. Vendor risk management is not a one-time activity; at least annually, there needs to be consistent monitoring. There may be changes in the third-party vendor’s security and privacy program and posture that your organization needs to be aware of, and your organization may need to communicate any changes in security requirements that your third-party vendor will need to support.

 

One of the best ways to manage third-party vendor risk is to understand your organizational and third-party risks and what factors would play into either organization being attacked.

We recently hosted a cybersecurity webinar for public power utilities: “Evolving Cybersecurity Threats & Challenges to Public Power.” Request the slides for this webinar and find more information in an additional blog post: “Can You Spot a Cyberattack?“

Picture of Peter Samoray

Peter Samoray

Peter has over 18 years of cybersecurity experience within multiple sectors, from automotive, defense, telecommunications, retail, consulting, and software development. Peter holds a BA in psychology from Wayne State University, an MS in information systems from the University of Detroit-Mercy, and a certificate in change leadership from Cornell University. Of late, his focus has been on improving the human factor of cybersecurity. Peter maintains the following certifications: CISSP, CISM, CISA, CIPP/US, CIPP/EU, and PMP.

Related blog posts

Loading...
Dec 09
About Us,Cybersecurity

PCI Achieves SOC 2 Type II Attestation, Reinforcing Security for 2026 & Beyond

open laptop
Feb 18
About Us,Cybersecurity

PCI Successfully Completes SOC/FISMA Examinations for 2024

Abstract image to help portray "secure code development training"
Feb 05
Cybersecurity

Secure Code Development Training: How to Reduce Risk & Build Secure Software

Related press

Loading...
transmission lines
May 18
ETRM,power scheduling,US Bilateral Markets,US ISO/RTO Markets

Associated Electric Cooperative Inc. Modernizes Complex Power & Gas Operations with PCIs’ ETRM Platform

california skyline to accompany PCI Energy Solutions blog post "How Will the CAISO Extended Day Ahead Market Work?"
May 07
CAISO,EDAM,US ISO/RTO Markets

PCI Energy Solutions Powers Successful Launch of First CAISO EDAM Wave

mountain silhouette in the west
Apr 02
SPP RTO,US ISO/RTO Markets

PCI Energy Solutions Empowers Key Utilities for Historic SPP RTO Expansion Go-Live

PCI Energy Solutions

PCI Energy Solutions

Also known as Power Costs, Inc.

Connect with us

U.S. 1+ 405.447.6933

Sales 1+ 405.701.7301

301 David L. Boren Blvd., Suite 2000
Norman, OK 73072

Contact us

We’re Hiring! 

Linkedin Twitter
  • Platform
  • PCI AI
  • PCI Insights
  • Our Technology
  • Cybersecurity
  • AWS Partnership
  • Solutions
  • ETRM
  • Bid-to-Bill
  • Portfolio Optimization
  • Transmission
  • Outage Management
  • Customer Portal
  • INFOCUS Conference
  • Product Trainings
  • Product Documentation
  • Issue Tracker
  • About
  • Careers
  • About Us
  • Leadership
  • Newsroom

Subscribe to our newsletter

Subscribe

© Power Costs, Inc. 2026 | All Rights Reserved.

  • Privacy Policy
  • Sitemap
Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}

Request More Information

  • This field is for validation purposes and should be left unchanged.

Name
I am not a robot 🤖

Solutions

Energy Trading and Optimization

  • ETRM
  • Market Participation
  • Gas & Fuels Management
  • Portfolio Optimization
  • Settlements and Billing
  • Generation Outage Management
  • ETRM
  • Market Participation
  • Gas & Fuels Management
  • Portfolio Optimization
  • Settlements and Billing
  • Generation Outage Management

Transmission and Reliability

  • Transmission Outage Management
  • Transmission Scheduling
  • e-Tagging
  • Balancing Authority Operations
  • Energy Accounting and Meter Data Management
  • Transmission Outage Management
  • Transmission Scheduling
  • e-Tagging
  • Balancing Authority Operations
  • Energy Accounting and Meter Data Management

Sustainable Energy

  • Energy Trading Optimization
  • Energy Storage Optimization & Trading
  • Hydrogen
  • Hydropower
  • Carbon Intensity
  • Forecasting
  • Energy Trading Optimization
  • Energy Storage Optimization & Trading
  • Hydrogen
  • Hydropower
  • Carbon Intensity
  • Forecasting

Platform

  • PCI AI
  • PCI Insights
  • Our Technology
  • Cybersecurity
  • AWS Partnership
  • PCI AI
  • PCI Insights
  • Our Technology
  • Cybersecurity
  • AWS Partnership

Markets

  • North America
  • Latinoamerica
  • Europe
  • Australia
  • North America
  • Latinoamerica
  • Europe
  • Australia

Energy Market AI Chatbots

  • ISO Bot (North American Markets)
  • M+ Bot (New Market)
  • CEN Bot (Mexico)
  • ISO Bot (North American Markets)
  • M+ Bot (New Market)
  • CEN Bot (Mexico)

Resources

Thought Leadership

  • Blog
  • Newsletter
  • Webinars & Events
  • Case Studies
  • Blog
  • Newsletter
  • Webinars & Events
  • Case Studies

Customer Portal

  • INFOCUS User Conference
  • Product Trainings
  • Product Documentation
  • Issue Tracker
  • INFOCUS User Conference
  • Product Trainings
  • Product Documentation
  • Issue Tracker

About Us

  • About
  • Leadership
  • Newsroom
  • Contact Us
  • About
  • Leadership
  • Newsroom
  • Contact Us

Careers