Muyni
← Back to Norwich

CT Municipal Electric Energy Cooperative CMEEC

Regular Meeting

Norwich, CT · May 15, 2024

AgendaMinutes

Minutes

MINUTES OF THE SPECIAL MEETING OF THE JOINT AUDIT COMMITTEE OF THE BOARDS OF DIRECTORS OF CONNECTICUT MUNICPAL ELECTRIC ENERGY COOPERATIVE AND CONNECTICUT TRANSMISSION MUNICIPAL ELECTRIC ENERGY COOPERATIVE May 15, 2024 A Special Hybrid Meeting of the Joint Audit Committee of the Boards of Directors of Connecticut Municipal Electric Energy Cooperative (“CMEEC”) and Connecticut Transmission Municipal Electric Energy Cooperative (“CTMEEC” dba Transco) was held via Zoom and in person at 30 Stott Avenue, Norwich, CT on Wednesday, May 15, 2024 at 10:00 a.m. The meeting was legally noticed in compliance with Connecticut General Statutes and all proceedings and all actions thereafter recorded occurred during the publicly open portions of the meeting. The Following Committee Members participated in person or Via Zoom: Bozrah Light & Power: Scott Barber, via Zoom Groton Municipal Representative: Mark Oefinger in person (arrived at 11:07 a.m.) Jewett City Department of Public Utilities: Kenneth Sullivan, via Zoom Norwich Public Utilities: Stewart Peil, via Zoom, Robert Staley, via Zoom Norwich Municipal Representative: David Eggleston, via Zoom South Norwalk Municipal Representative: Dawn DelGreco, via Zoom Third Taxing District, East Norwalk: Kevin Barber, via Zoom The following Non-Voting Members participated via Zoom: Bozrah Light & Power: William Ballinger Jewett City Department of Public Utilities: Louis Demicco, James Derusha Jewett City Municipal Representative: George Kennedy Norwich Public Utilities: Christopher LaRose South Norwalk Electric & Water: Alan Huth East Norwalk Municipal Representative: Pete Johnson The following CMEEC Staff participated in person or via Zoom: Dave Meisinger, CMEEC CEO, in person Patricia Meek, CMEEC Director of Finance & Accounting, in person Joanne Menard, CMEEC Controller, in person Margaret Job, CMEEC Director of Administrative Services, in person Michael Rall, CMEEC Director of Asset Management, in person Candice DiVita, CMEEC Financial Analyst, via Zoom Leslie Williams, CMEEC Principal Accountant, in person Heidi Winnick, CMEEC Financial & Treasury Analyst, in person Chantal Maxwell, CMEEC Administrative Coordinator, in person Lauren Gaudet, CMEEC Administrative and Sustainability Specialist, in person Linda Audet, CMEEC Human Resource Lead, via Zoom Ginger Palmer, CMEEC Cyber Systems & Security Manager, in person The following Invited Guests participated via Zoom: Greg Bugbee, Novus Insight Stephanie Hyde, PE-Risk Others participated via Zoom: David Silverstone, Esquire, Municipal Electric Consumer Advocate Ms. Job recorded. Committee Chair Stewart Peil called the meeting to order at 10:00 a.m. noting for the record that today’s meeting is being held via Zoom and in person at 30 Stott Avenue, Norwich, CT. He reminded participants to keep their devices on mute unless speaking to eliminate background noise and to state their names when speaking for clarity of the record. Specific Agenda Item A Public Comment Period No public comment was made. B Roll Call Ms. Job conducted roll call. Committee Chair Peil confirmed a quorum of the Committee was present. C Approve the Minutes of the March 20, 2024 Regular Hybrid Meeting of the CMEEC / CTMEEC Joint Audit Committee A motion was made by Committee Member Kevin Barber, seconded by Committee Member Scott Barber to Approve the Minutes of the March 20, 2024 Regular Hybrid Meeting of the CMEEC / CTMEEC Joint Audit Committee. Motion passed unanimously. D Status Updates on Current and Past “Internal Audits” a. Cybersecurity Gap Analysis Committee Chair Peil explained that this Committee agreed at its last meeting that updates on the three listed audits would be discussed at today’s meeting. He then introduced Ms. Palmer who explained that while CMEEC is in the midst of a multi-year Cybersecurity Gap Analysis project, it was determined prudent to revisit and update an overarching risk assessment in order to most appropriately align and apply the relevant aspects of the ISO 27001 cybersecurity framework to CMEEC’s perceived cyber risks. She added that Novus and CMEEC agreed to review and conduct a risk-based approach to the design of the CMEEC cybersecurity plan. Ms. Palmer then introduced Mr. Bugbee who walked the Committee through the slide deck provided in advance of today’s meeting. Mr. Bugbee provided an overview of the approach taken for the Gap Analysis project. He too noted that the ISO 27001 alignment project had been briefly paused in order to re- align efforts and resources to focus on cybersecurity risks faced by CMEEC. He added that a risk management workshop was facilitated by Novus for CMEEC staff in April, which included risk and business obligation surveys completed by each CMEEC department. The results of the surveys were compiled by Novus into a risk register. Mr. Bugbee explained that the next phase of the process will include review and prioritization of risks adding that the results of the surveys will assist in determining the level of ISO 27001 adoption for CMEEC. Finally, Mr. Bugbee provided a brief update of the status of the ISO 27001 project timeline including the performance of a Risk Assessment update scheduled to be completed in the third quarter of 2024 and the anticipated rollout of a revised approach to password management to be completed in the fourth quarter of 2024. Ms. Hyde of PE-Risk offered insight into the focus of current cyber insurance coverage, noting that phishing email filtering, training, and established incident response plans for disaster recovery along with secure VPNs are currently the focus of insurance carriers. She added that her review of CMEEC’s current insurance and risk management program revealed that CMEEC’s current cyber-related coverage is very good. b. Implementation of Recommendations Associated with the Review of the CMEEC Safety Manual Mr. Rall reminded the Committee that at its meeting on January 9, 2024 he presented a timeline identifying proposed completion of TRC’s recommendations from its 2023 audit of CMEEC Safety Manual and Guidelines and that a status on the timeline would be discussed at a special meeting of this Committee. Mr. Rall then walked the Committee through the slide deck provided in advance of today’s meeting highlighting completed and partially completed TRC recommendations. He then discussed status and considerations for the partially completed TRC recommendations. Finally, Mr. Rall walked through the proposed timeline of completion dates for certain remaining tasks under the review of the CMEEC Safety program. Discussion followed. c. Results of the Review of the CMEEC Insurance Program Ms. Audet explained that this Committee requested an audit of CMEEC’s property and casualty insurance program. She explained that an RFP was released and PE-Risk was selected to conduct the review. Ms. Audet then introduced Stephanie Hyde of PE-Risk. Ms. Hyde introduced herself and provided a brief overview of PE-Risk. She explained that the scope of engagement was to prepare a report providing review and assessment of CMEEC’s current insurance coverage. Ms. Hyde then highlighted information shared by CMEEC to facilitate the review. Ms. Hyde walked the Committee through key findings and recommendations noting that CMEEC’s existing insurance limits and deductibles seem appropriate and that premiums are competitively priced. She added that all current coverages are placed with financially stable insurers and loss history is clean and better than market for similar exposures in CMEEC’s industry and geographic location. Ms. Hyde did note that PE-Risk recommends CMEEC evaluate the policy limits under the employment practices liability program based on number of employees as well as other coverages under this policy. After discussion and based on PE-Risk’s review of information provided to it by CMEEC, Ms. Hyde noted that CMEEC’s current insurance coverages appear to be commercially reasonable for the size and scope of operations. She further highlighted recommendations to potentially enhance current coverages. Ms. Hyde also walked the Committee through a deeper dive of CMEEC’s current insurance program observations. After brief discussion, Committee Chair Peil thanked Ms. Hyde for PE-Risk’s thorough review and report on the CMEEC insurance program. He stated the Committee is pleased to see CMEEC’s insurance program is strong. E Adjourn A motion was made by committee Member Eggleston, seconded by Committee Member Kevin Barber to adjourn. Motion passed unanimously. The meeting was adjourned at 11:23 a.m.

Agenda

TO: Joint Audit Committee FROM: Stewart Peil Joanne Menard, CMEEC Lead SUBJECT: Notice and Agenda for the Special Hybrid Meeting of the Joint Audit Committee, Wednesday, May 15, 2024 Attached is the Notice and Agenda for the Special Hybrid Meeting of the CMEEC / CTMEEC Joint Audit Committee scheduled to be held via Zoom and in person at 30 Stott Avenue, Norwich, CT on Wednesday, May 15, 2024 at 10:00 a.m. Zoom instructions: Please contact Margaret Job at mjob@cmeec.org Members of the public may attend the meeting in person or remotely via Zoom. AGENDA Specific Agenda Item A Public Comment Period B Roll Call C Approve the Minutes of the March 20, 2024 Regular Hybrid Meeting of the CMEEC / CTMEEC Joint Audit Committee D Status Updates on Current and Past “Internal Audits” a. Cybersecurity Gap Analysis, Ginger Palmer and Greg Bugbee of Novus Insight b. Implementation of Recommendations Associated with the Review of the CMEEC Safety Manual, Michael Rall, Director of Asset Management c. Results of the Review of the CMEEC Insurance Program, Linda Audet, PE Risk E Adjourn Posted this 10th day of May 2024

Get email alerts for Norwich

A daily email when new agendas and minutes are posted.

Report an issue with this meeting