CT Municipal Electric Energy Cooperative CMEEC
Regular MeetingNorwich, CT · May 15, 2024
Minutes
MINUTES OF THE
SPECIAL MEETING OF THE
JOINT AUDIT COMMITTEE OF THE
BOARDS OF DIRECTORS OF
CONNECTICUT MUNICPAL ELECTRIC ENERGY COOPERATIVE
AND
CONNECTICUT TRANSMISSION MUNICIPAL ELECTRIC ENERGY COOPERATIVE
May 15, 2024
A Special Hybrid Meeting of the Joint Audit Committee of the Boards of Directors of
Connecticut Municipal Electric Energy Cooperative (“CMEEC”) and Connecticut Transmission
Municipal Electric Energy Cooperative (“CTMEEC” dba Transco) was held via Zoom and in
person at 30 Stott Avenue, Norwich, CT on Wednesday, May 15, 2024 at 10:00 a.m.
The meeting was legally noticed in compliance with Connecticut General Statutes and all
proceedings and all actions thereafter recorded occurred during the publicly open portions of the
meeting.
The Following Committee Members participated in person or Via Zoom:
Bozrah Light & Power: Scott Barber, via Zoom
Groton Municipal Representative: Mark Oefinger in person (arrived at 11:07 a.m.)
Jewett City Department of Public Utilities: Kenneth Sullivan, via Zoom
Norwich Public Utilities: Stewart Peil, via Zoom, Robert Staley, via Zoom
Norwich Municipal Representative: David Eggleston, via Zoom
South Norwalk Municipal Representative: Dawn DelGreco, via Zoom
Third Taxing District, East Norwalk: Kevin Barber, via Zoom
The following Non-Voting Members participated via Zoom:
Bozrah Light & Power: William Ballinger
Jewett City Department of Public Utilities: Louis Demicco, James Derusha
Jewett City Municipal Representative: George Kennedy
Norwich Public Utilities: Christopher LaRose
South Norwalk Electric & Water: Alan Huth
East Norwalk Municipal Representative: Pete Johnson
The following CMEEC Staff participated in person or via Zoom:
Dave Meisinger, CMEEC CEO, in person
Patricia Meek, CMEEC Director of Finance & Accounting, in person
Joanne Menard, CMEEC Controller, in person
Margaret Job, CMEEC Director of Administrative Services, in person
Michael Rall, CMEEC Director of Asset Management, in person
Candice DiVita, CMEEC Financial Analyst, via Zoom
Leslie Williams, CMEEC Principal Accountant, in person
Heidi Winnick, CMEEC Financial & Treasury Analyst, in person
Chantal Maxwell, CMEEC Administrative Coordinator, in person
Lauren Gaudet, CMEEC Administrative and Sustainability Specialist, in person
Linda Audet, CMEEC Human Resource Lead, via Zoom
Ginger Palmer, CMEEC Cyber Systems & Security Manager, in person
The following Invited Guests participated via Zoom:
Greg Bugbee, Novus Insight
Stephanie Hyde, PE-Risk
Others participated via Zoom:
David Silverstone, Esquire, Municipal Electric Consumer Advocate
Ms. Job recorded.
Committee Chair Stewart Peil called the meeting to order at 10:00 a.m. noting for the record that
today’s meeting is being held via Zoom and in person at 30 Stott Avenue, Norwich, CT. He
reminded participants to keep their devices on mute unless speaking to eliminate background
noise and to state their names when speaking for clarity of the record.
Specific Agenda Item
A Public Comment Period
No public comment was made.
B Roll Call
Ms. Job conducted roll call. Committee Chair Peil confirmed a quorum of the Committee
was present.
C Approve the Minutes of the March 20, 2024 Regular Hybrid Meeting of the
CMEEC / CTMEEC Joint Audit Committee
A motion was made by Committee Member Kevin Barber, seconded by Committee
Member Scott Barber to Approve the Minutes of the March 20, 2024 Regular
Hybrid Meeting of the CMEEC / CTMEEC Joint Audit Committee.
Motion passed unanimously.
D Status Updates on Current and Past “Internal Audits”
a. Cybersecurity Gap Analysis
Committee Chair Peil explained that this Committee agreed at its last meeting that
updates on the three listed audits would be discussed at today’s meeting. He then
introduced Ms. Palmer who explained that while CMEEC is in the midst of a multi-year
Cybersecurity Gap Analysis project, it was determined prudent to revisit and update an
overarching risk assessment in order to most appropriately align and apply the relevant
aspects of the ISO 27001 cybersecurity framework to CMEEC’s perceived cyber risks.
She added that Novus and CMEEC agreed to review and conduct a risk-based approach
to the design of the CMEEC cybersecurity plan. Ms. Palmer then introduced Mr. Bugbee
who walked the Committee through the slide deck provided in advance of today’s
meeting.
Mr. Bugbee provided an overview of the approach taken for the Gap Analysis project.
He too noted that the ISO 27001 alignment project had been briefly paused in order to re-
align efforts and resources to focus on cybersecurity risks faced by CMEEC. He added
that a risk management workshop was facilitated by Novus for CMEEC staff in April,
which included risk and business obligation surveys completed by each CMEEC
department. The results of the surveys were compiled by Novus into a risk register. Mr.
Bugbee explained that the next phase of the process will include review and prioritization
of risks adding that the results of the surveys will assist in determining the level of ISO
27001 adoption for CMEEC.
Finally, Mr. Bugbee provided a brief update of the status of the ISO 27001 project
timeline including the performance of a Risk Assessment update scheduled to be
completed in the third quarter of 2024 and the anticipated rollout of a revised approach to
password management to be completed in the fourth quarter of 2024.
Ms. Hyde of PE-Risk offered insight into the focus of current cyber insurance coverage,
noting that phishing email filtering, training, and established incident response plans for
disaster recovery along with secure VPNs are currently the focus of insurance carriers.
She added that her review of CMEEC’s current insurance and risk management program
revealed that CMEEC’s current cyber-related coverage is very good.
b. Implementation of Recommendations Associated with the Review of the
CMEEC Safety Manual
Mr. Rall reminded the Committee that at its meeting on January 9, 2024 he presented a
timeline identifying proposed completion of TRC’s recommendations from its 2023 audit
of CMEEC Safety Manual and Guidelines and that a status on the timeline would be
discussed at a special meeting of this Committee. Mr. Rall then walked the Committee
through the slide deck provided in advance of today’s meeting highlighting completed
and partially completed TRC recommendations. He then discussed status and
considerations for the partially completed TRC recommendations.
Finally, Mr. Rall walked through the proposed timeline of completion dates for certain
remaining tasks under the review of the CMEEC Safety program.
Discussion followed.
c. Results of the Review of the CMEEC Insurance Program
Ms. Audet explained that this Committee requested an audit of CMEEC’s property and
casualty insurance program. She explained that an RFP was released and PE-Risk was
selected to conduct the review. Ms. Audet then introduced Stephanie Hyde of PE-Risk.
Ms. Hyde introduced herself and provided a brief overview of PE-Risk. She explained
that the scope of engagement was to prepare a report providing review and assessment of
CMEEC’s current insurance coverage. Ms. Hyde then highlighted information shared by
CMEEC to facilitate the review.
Ms. Hyde walked the Committee through key findings and recommendations noting that
CMEEC’s existing insurance limits and deductibles seem appropriate and that premiums
are competitively priced. She added that all current coverages are placed with financially
stable insurers and loss history is clean and better than market for similar exposures in
CMEEC’s industry and geographic location. Ms. Hyde did note that PE-Risk
recommends CMEEC evaluate the policy limits under the employment practices liability
program based on number of employees as well as other coverages under this policy.
After discussion and based on PE-Risk’s review of information provided to it by
CMEEC, Ms. Hyde noted that CMEEC’s current insurance coverages appear to be
commercially reasonable for the size and scope of operations. She further highlighted
recommendations to potentially enhance current coverages. Ms. Hyde also walked the
Committee through a deeper dive of CMEEC’s current insurance program observations.
After brief discussion, Committee Chair Peil thanked Ms. Hyde for PE-Risk’s thorough
review and report on the CMEEC insurance program. He stated the Committee is pleased
to see CMEEC’s insurance program is strong.
E Adjourn
A motion was made by committee Member Eggleston, seconded by Committee
Member Kevin Barber to adjourn.
Motion passed unanimously.
The meeting was adjourned at 11:23 a.m.
Agenda
TO: Joint Audit Committee
FROM: Stewart Peil
Joanne Menard, CMEEC Lead
SUBJECT: Notice and Agenda for the Special Hybrid Meeting of the Joint Audit
Committee, Wednesday, May 15, 2024
Attached is the Notice and Agenda for the Special Hybrid Meeting of the CMEEC /
CTMEEC Joint Audit Committee scheduled to be held via Zoom and in person at 30 Stott
Avenue, Norwich, CT on Wednesday, May 15, 2024 at 10:00 a.m.
Zoom instructions: Please contact Margaret Job at mjob@cmeec.org
Members of the public may attend the meeting in person or remotely via Zoom.
AGENDA
Specific Agenda Item
A Public Comment Period
B Roll Call
C Approve the Minutes of the March 20, 2024 Regular Hybrid Meeting of the CMEEC /
CTMEEC Joint Audit Committee
D Status Updates on Current and Past “Internal Audits”
a. Cybersecurity Gap Analysis, Ginger Palmer and Greg Bugbee of Novus Insight
b. Implementation of Recommendations Associated with the Review of the CMEEC
Safety Manual, Michael Rall, Director of Asset Management
c. Results of the Review of the CMEEC Insurance Program, Linda Audet, PE Risk
E Adjourn
Posted this 10th day of May 2024
Get email alerts for Norwich
A daily email when new agendas and minutes are posted.