An example of why the NERC CIP-compliance-based approach including version 4 with its “bright lines” is deficient can be demonstrated with the following examples. The bright line approach is meant to set a minimum threshold before an asset needs to be considered critical and a cyber assessment made.