The article is organized as follows: First, we give a brief overview of the regulatory context for this study and the complexity of ICT systems. Second, we present our theoretical perspectives followed by presentations of method and data analysis. In the theory section we argue for a distinction between safety and security, introduce the principles of internal control and function based regulatory systems, and conclude why an analysis of complex technologies and functional risk regulations is required. In the section concerning material and methods we present the mixed method applied in this study and give an overview of the interviews, observation studies, document studies, and questionnaire survey. The results and discussion are divided in two sections where the first aims to present different viewpoints concerning function based regulation among the groups of actors, and the second discusses reasons for these viewpoints and security management in the electric power supply sector as such.