Industries
Cyber security for energy & utilities.
Grid, metering and distribution systems where an outage is a public safety event.
What is actually going on here
The grid is the infrastructure everything else depends on. A sustained outage is not an IT incident, it is a civil emergency, and that shapes how conservatively this work has to be done. In a decade of grid and utility testing we have caused zero outages, which is the number that matters most in this sector.
The exposure is growing rather than shrinking. Smart meters put millions of connected devices in the field, distributed generation adds control points outside your fence, and demand response systems can be instructed to change load. Each is useful and each expands what an attacker can reach.
We test generation, transmission and distribution environments against IEC 62443 and the CEA cyber security requirements, always with operations staff present and always with a stop condition agreed before anything active begins.
Who regulates you, and what they want
Tick the ones that bind you and we will pull together the evidence each of them actually asks for. Nothing is sent anywhere.
Pick one or more above to see what they expect of you.
What goes wrong in this sector
Grid control system compromise
The nightmare case, and it has happened elsewhere. Entry is through IT, then across a poorly defended boundary into control systems. Every published grid attack has followed roughly this path.
Smart meter and AMI attacks
Millions of devices in physically uncontrolled locations, sharing firmware and often key material. Compromise of the head end system is the high consequence path, because it can reach every meter at once.
Remote terminal unit exposure
RTUs at substations frequently sit on communication links with minimal authentication. Physical access to a remote substation is a real attack path, not a theoretical one.
Distributed generation as an entry point
Solar inverters and battery systems connect to your network but are owned and maintained by somebody else. Their security is your exposure and you usually have no visibility into it.
How we work in this sector
- 01
Passive first, always
Asset discovery and traffic analysis without touching a control device. On a grid network this is the majority of the technical work.
- 02
Prove the IT to OT boundary
Tested from the IT side, thoroughly, because that is the path every real world grid attack has used.
- 03
Substation and field assessment
Physical and logical access at representative substations, since the remote sites are the ones nobody visits.
- 04
Rehearse a grid incident
A tabletop with operations, IT and management together, focused on the decision to island or shed load, which is a business decision made under time pressure.
What we actually keep finding here
Not a threat list copied from a report. These are the patterns that recur across our own engagements in this sector, with an honest note on how often. Where we do not have a precise number we say so rather than inventing one.
- Almost every engagement
The IT to OT boundary is the whole finding
Every published grid attack entered through IT and crossed a boundary that was believed to be tighter than it was.
- Most engagements
Remote substations with weak physical and logical control
RTUs on communication links with minimal authentication, at sites nobody visits between inspections.
- Often
Distributed generation connected on trust
Solar and battery systems owned and maintained by third parties, connected to your network, with no visibility into their security.
- Often
Head end systems that can reach every meter
The high consequence path in an AMI deployment, and the one most worth defending, because compromise there is not one meter but all of them.
Questions worth asking any provider in this sector
Including us. If a provider cannot answer these clearly, that tells you more than any capability slide will. We would rather you asked them than took our word for it.
- 1
What guarantees can you give that testing will not cause an outage?
- 2
Will discovery be entirely passive, and will operations be present for anything active?
- 3
Will you assess sample meters in a lab rather than touching field devices serving customers?
- 4
Will findings map to CEA requirements and IEC 62443 security levels?
- 5
Can you run a grid incident tabletop with operations and management together?
What we deliver in this sector
- Smart metering & AMI security testing
- SCADA and grid control assessment
- CERT-In audit and certification
- Physical and cyber convergence review
- Incident response planning
- Vendor and integrator risk assessment
- Network segmentation validation
- Continuous monitoring rollout
Work in this sector
Named engagements where the client has agreed to be named, and anonymised ones where they have not, which is most of them. Named references are available under NDA.
- Client withheld
Generation company, substation assessment
- Scope
- Physical and logical access assessed at representative remote substations.
- What we found
- RTUs on communication links with minimal authentication, at sites visited only for inspections.
- Outcome
- Link authentication introduced where the equipment supported it, and compensating monitoring where it did not.
- Client withheld
Distribution utility, grid boundary assessment
- Scope
- Assessed entirely from the IT side, where thorough testing carries no risk to operations.
- What we found
- The IT to OT boundary was more permeable than the architecture diagram showed.
- Outcome
- Boundary rebuilt to a zone and conduit model, with an incident tabletop run with operations and management together.
- Client withheld
Utility, smart metering head end
- Scope
- Head end system assessed in a controlled environment with sample meters in a lab. No field meter was touched.
- What we found
- Head end access that would have permitted commands to a very large number of meters at once.
- Outcome
- Privileged access reworked and command issuance placed behind approval with full audit.
Questions we get asked in this sector
Is there any risk of causing an outage?
We design to eliminate it. Discovery is passive, active testing runs only in an approved window with operations present and an agreed stop condition, and nothing writes to a control device on a live system. We have caused zero outages in a decade of this work and we will decline a test rather than risk that.
Can smart meters be assessed without disrupting billing?
Yes. We assess sample meters in a lab and test the head end system in a controlled environment. Field meters serving customers are not touched.
What does CEA compliance actually require of us?
Governance, network segregation, an appointed CISO and incident reporting, with the detail depending on your role in the sector. We map your specific obligation rather than handing over a generic checklist, because generation and distribution are treated differently.
How do we handle third party distributed generation?
Contractually and architecturally. Security requirements in the connection agreement, and a network design that treats those connections as untrusted regardless of what the agreement says. Assume the contract will not be honoured and build accordingly.
Not sure where to start?
Book a 30-minute call with a senior engineer. We will walk through your current posture, the frameworks that bind you, and what a realistic programme looks like.












