Scott
Stan, thanks for making time. I know budget season plus whatever's left over from the PSC review probably has your calendar wall to wall right now.
Stan
Yeah, it's been a lot. Between that and NERC CIP evidence collection, I feel like half my team's job is just proving we did the thing, not actually doing the thing. What can I do for you?
Scott
That's actually the perfect opening, because that exact problem is why I asked for the time. That PSC review is a good place to start too. I read through Florida's cybersecurity protections review that covered TECO a couple years back. When something like that lands on your desk, how does it actually turn into a plan the board signs off on?
Stan
Honestly, a lot of spreadsheets. We've got NERC CIP evidence, an internal risk register, whatever the last pen test turned up. Somebody, usually me, stitches that into a story the board can follow.
Scott
And when you're in that room, are you telling them "here's a risk score," or are you telling them "here's what this could actually cost us"?
Stan
Mostly a score. Red, yellow, green. They nod, but I don't think anyone walks out with a real sense of exposure.
Scott
That's the exact gap we built Cordaata to close. We're not another compliance tool sitting next to NERC CIP, we sit on top of what you're already doing. We map how TECO actually operates, and for a utility that's your substations, your OT environment, your grid control systems, not a generic IT checklist, and we price that risk in real dollars using the FAIR model. So instead of red, yellow, green, you walk into that boardroom saying "if this substation control system goes down for four hours, here's the modeled financial exposure."
Stan
Okay, I'll push back a little. Every vendor I talk to says they'll "quantify risk."
Scott
Fair, and you're right to be skeptical. Here's the actual difference. Most of those platforms want you to hand them a risk register you already built, then they dress it up. We build the model with you starting from how the business runs, and it doesn't go stale the day after the audit. NERC CIP already makes you keep evidence current year round. Our model updates the same way, so you're not rebuilding it from scratch every cycle.
Stan
That part I'd take. Right now evidence gathering is basically a fire drill every time an auditor asks a question.
Scott
That's the first real benefit for TECO specifically: it turns compliance from a fire drill into something that's already current when someone asks. Second one, and it connects straight to what you told me about the board: once you can hand your CFO an actual dollar number tied to a specific risk, that budget conversation changes shape. You're not asking for money because you should, you're asking because here's the annualized loss exposure, and here's what this investment removes.
Stan
My CFO would genuinely love that. Every security ask competes with substation upgrades and pole replacement, and we usually lose that fight.
Scott
That's the third one then: prioritization you can actually defend. If you've got five things competing for the same budget, we help you rank them by real financial impact instead of gut feel, so when it's sitting next to a capital project request, you're speaking the same language as whoever's approving it.
Stan
What about third-party exposure? SCADA vendors, contractors touching our systems, that's honestly the part that keeps me up at night.
Scott
That's the fourth. Because we model the business process itself, not just your internal asset list, third-party dependencies show up inside the same exposure number. If a vendor outage or breach would take down something that matters, you see that dollar figure too, not just a vendor questionnaire sitting in a folder somewhere.
Stan
And insurance? Our cyber renewal was rough this year.
Scott
Fifth one, and it's a real trend right now. Insurers are asking for exactly this kind of quantified exposure data more and more. Walking into a renewal with a defensible loss model instead of a checklist tends to change that conversation, sometimes meaningfully on premium.
Stan
Alright. I've sat through a lot of these pitches, Scott. What do you actually want from me next?
Scott
Nothing that needs a purchase order. I'd like thirty minutes with whoever owns your OT and IT asset inventory, and we build one real scenario together, something like a control system outage at a single substation, and show you the actual dollar exposure the model produces. You see it working against your own environment before anyone talks contract.
Stan
I can do that. Let me loop in my architect, we'll find time next week.
Scott
Perfect. One more thing before I let you go. Given the PSC review, is there a specific system or facility that's been the sticking point internally, something you'd actually want us to model first?
Stan
Probably one of our substation control environments. That's the one that comes up every time compliance and operations end up in the same room arguing about priorities.
Scott
Good, that's exactly the kind of scenario that makes this real instead of theoretical. I'll build the scoping call around that specifically, and I'll send a calendar hold today. I appreciate you being straight with me, Stan. This was exactly the conversation I was hoping for.
Stan
Yeah, this one was worth the twenty minutes. Talk soon.