Skip to main content

Industries

Cyber security for energy & utilities.

Grid, metering and distribution systems where an outage is a public safety event.

Regulators and frameworks

  • CEA
  • CERT-In
  • IEC 62443
Talk to a energy specialist

What is actually going on here

The grid is the infrastructure everything else depends on. A sustained outage is not an IT incident, it is a civil emergency, and that shapes how conservatively this work has to be done. In a decade of grid and utility testing we have caused zero outages, which is the number that matters most in this sector.

The exposure is growing rather than shrinking. Smart meters put millions of connected devices in the field, distributed generation adds control points outside your fence, and demand response systems can be instructed to change load. Each is useful and each expands what an attacker can reach.

We test generation, transmission and distribution environments against IEC 62443 and the CEA cyber security requirements, always with operations staff present and always with a stop condition agreed before anything active begins.

Who regulates you, and what they want

Tick the ones that bind you and we will pull together the evidence each of them actually asks for. Nothing is sent anywhere.

Pick one or more above to see what they expect of you.

What goes wrong in this sector

  • Grid control system compromise

    The nightmare case, and it has happened elsewhere. Entry is through IT, then across a poorly defended boundary into control systems. Every published grid attack has followed roughly this path.

  • Smart meter and AMI attacks

    Millions of devices in physically uncontrolled locations, sharing firmware and often key material. Compromise of the head end system is the high consequence path, because it can reach every meter at once.

  • Remote terminal unit exposure

    RTUs at substations frequently sit on communication links with minimal authentication. Physical access to a remote substation is a real attack path, not a theoretical one.

  • Distributed generation as an entry point

    Solar inverters and battery systems connect to your network but are owned and maintained by somebody else. Their security is your exposure and you usually have no visibility into it.

How we work in this sector

  1. 01

    Passive first, always

    Asset discovery and traffic analysis without touching a control device. On a grid network this is the majority of the technical work.

  2. 02

    Prove the IT to OT boundary

    Tested from the IT side, thoroughly, because that is the path every real world grid attack has used.

  3. 03

    Substation and field assessment

    Physical and logical access at representative substations, since the remote sites are the ones nobody visits.

  4. 04

    Rehearse a grid incident

    A tabletop with operations, IT and management together, focused on the decision to island or shed load, which is a business decision made under time pressure.

What we actually keep finding here

Not a threat list copied from a report. These are the patterns that recur across our own engagements in this sector, with an honest note on how often. Where we do not have a precise number we say so rather than inventing one.

  • Almost every engagement

    The IT to OT boundary is the whole finding

    Every published grid attack entered through IT and crossed a boundary that was believed to be tighter than it was.

  • Most engagements

    Remote substations with weak physical and logical control

    RTUs on communication links with minimal authentication, at sites nobody visits between inspections.

  • Often

    Distributed generation connected on trust

    Solar and battery systems owned and maintained by third parties, connected to your network, with no visibility into their security.

  • Often

    Head end systems that can reach every meter

    The high consequence path in an AMI deployment, and the one most worth defending, because compromise there is not one meter but all of them.

Questions worth asking any provider in this sector

Including us. If a provider cannot answer these clearly, that tells you more than any capability slide will. We would rather you asked them than took our word for it.

  1. 1

    What guarantees can you give that testing will not cause an outage?

  2. 2

    Will discovery be entirely passive, and will operations be present for anything active?

  3. 3

    Will you assess sample meters in a lab rather than touching field devices serving customers?

  4. 4

    Will findings map to CEA requirements and IEC 62443 security levels?

  5. 5

    Can you run a grid incident tabletop with operations and management together?

What we deliver in this sector

  • Smart metering & AMI security testing
  • SCADA and grid control assessment
  • CERT-In audit and certification
  • Physical and cyber convergence review
  • Incident response planning
  • Vendor and integrator risk assessment
  • Network segmentation validation
  • Continuous monitoring rollout

Work in this sector

Named engagements where the client has agreed to be named, and anonymised ones where they have not, which is most of them. Named references are available under NDA.

  • Client withheld

    Generation company, substation assessment

    Scope
    Physical and logical access assessed at representative remote substations.
    What we found
    RTUs on communication links with minimal authentication, at sites visited only for inspections.
    Outcome
    Link authentication introduced where the equipment supported it, and compensating monitoring where it did not.
  • Client withheld

    Distribution utility, grid boundary assessment

    Scope
    Assessed entirely from the IT side, where thorough testing carries no risk to operations.
    What we found
    The IT to OT boundary was more permeable than the architecture diagram showed.
    Outcome
    Boundary rebuilt to a zone and conduit model, with an incident tabletop run with operations and management together.
  • Client withheld

    Utility, smart metering head end

    Scope
    Head end system assessed in a controlled environment with sample meters in a lab. No field meter was touched.
    What we found
    Head end access that would have permitted commands to a very large number of meters at once.
    Outcome
    Privileged access reworked and command issuance placed behind approval with full audit.
All case studies

Questions we get asked in this sector

Is there any risk of causing an outage?

We design to eliminate it. Discovery is passive, active testing runs only in an approved window with operations present and an agreed stop condition, and nothing writes to a control device on a live system. We have caused zero outages in a decade of this work and we will decline a test rather than risk that.

Can smart meters be assessed without disrupting billing?

Yes. We assess sample meters in a lab and test the head end system in a controlled environment. Field meters serving customers are not touched.

What does CEA compliance actually require of us?

Governance, network segregation, an appointed CISO and incident reporting, with the detail depending on your role in the sector. We map your specific obligation rather than handing over a generic checklist, because generation and distribution are treated differently.

How do we handle third party distributed generation?

Contractually and architecturally. Security requirements in the connection agreement, and a network design that treats those connections as untrusted regardless of what the agreement says. Assume the contract will not be honoured and build accordingly.

Not sure where to start?

Book a 30-minute call with a senior engineer. We will walk through your current posture, the frameworks that bind you, and what a realistic programme looks like.