top of page

Cybersecurity for Power and Utilities

7 days ago
4 min read

The electric grid is one of the most interconnected control systems ever built, and it is changing faster than at any time in its history. Renewables, battery storage and smart devices at the grid edge are adding thousands of new connected assets, while substations and generating plants run equipment intended to last for decades. For utilities large and small, cybersecurity is now part of keeping the lights on.

A wide and varied footprint

Power systems span several very different environments, each with its own control systems and risks.

  • Generation includes thermal, hydro, nuclear, wind and solar plants. Larger plants run distributed control systems and safety systems that look much like those in process industries.

  • Transmission moves power at high voltage across long distances, controlled from energy management systems (EMS) in central control centres and monitored through substations along the network.

  • Distribution delivers power to homes and businesses through distribution substations, feeders and field devices such as reclosers, capacitor banks and switches, often managed through SCADA or an advanced distribution management system (ADMS).

  • Distributed energy resources (DER), such as rooftop solar, battery storage, electric vehicle charging and microgrids, connect through inverters, aggregators and often cloud platforms that sit outside the utility's direct control.

Substations sit at the heart of all of this. They contain protection relays, bay controllers, RTUs, gateways and communication equipment, and many are remote and unstaffed.

The protocols that run the grid

Two protocol families are especially important.

DNP3 is widely used in North America for communication between control centres and substations or field devices. It is reliable and well suited to utility needs, but many deployments run without authentication or encryption. A secure authentication extension exists, though adoption has been uneven.

IEC 61850 is the international standard for substation automation. It supports fast messaging between protection and control devices within the substation, including GOOSE messages used for protection functions. Because these messages are time-critical, they are often sent without authentication, so the security of the substation network itself is critical. The IEC 62351 series addresses security for these and other power system protocols, and adoption is growing in newer equipment.

Older serial protocols and vendor-specific links remain common too, frequently converted to Ethernet through gateways that deserve close attention.

Lessons from Ukraine

The attacks on Ukraine's grid remain the clearest public examples of cyberattacks causing power outages.

In December 2015, attackers gained access to the networks of three regional distribution companies, used remote access to the operators' own control systems to open breakers, and cut power to roughly 225,000 customers for several hours. They also disabled communication devices, wiped computers and flooded customer call centres. Power was restored largely by sending crews to operate equipment manually.

In December 2016, a transmission substation near Kyiv lost power for about an hour. Investigators later identified malware, named Industroyer or CrashOverride, capable of speaking grid protocols directly to switch equipment.

The US government has attributed both attacks to a Russian military intelligence unit commonly tracked as Sandworm. Key lessons for utilities everywhere include the danger of remote access paths into control systems, the value of manual operating capability and the need to detect unusual activity before it reaches the operations network.

NERC CIP and its limits

Diagram of the power system from generation and transmission through substations to distribution and distributed energy resources, with NERC CIP scope covering the bulk electric system
NERC CIP covers the bulk electric system; many distribution, municipal and DER assets fall outside it but still face real risk.

In North America, the NERC Critical Infrastructure Protection (CIP) standards are mandatory for entities that own or operate parts of the bulk electric system, which generally covers higher-voltage transmission and larger generating facilities. In the US they are enforced through NERC and FERC, and in Canada they are adopted and enforced through provincial authorities. The standards cover areas such as asset categorization, electronic and physical security perimeters, access management, configuration management, incident response and recovery.

NERC CIP has substantially raised the baseline for large utilities. However, much of the grid falls outside its scope. Most distribution systems are not part of the bulk electric system, so many distribution utilities, municipal utilities and cooperatives have few or no mandatory cybersecurity requirements for those assets. Many DER installations also sit outside CIP. These organizations still face real risk, and in many cases they serve hospitals, water systems and other critical customers.

For utilities outside CIP, frameworks such as IEC 62443, the NIST Cybersecurity Framework and the US Department of Energy's Cybersecurity Capability Maturity Model (C2M2) provide useful structure without imposing a compliance regime.

Priority actions

Whether or not your organization is subject to NERC CIP, the following steps deliver strong value:

  1. Inventory your assets, including relays, RTUs, gateways, communication equipment and DER interfaces. Passive monitoring in control centres and substations can help build this picture safely.

  2. Secure remote access into control centres and substations, with multi-factor authentication, individual accounts and session monitoring. This applies to vendors and field staff alike.

  3. Segment networks between corporate IT, control centres and substations, and within substations where practical.

  4. Manage relay and device settings with change control and regular comparisons against approved configurations.

  5. Review DER and third-party connections, including inverter platforms and aggregators, and understand what control they could exert over your system.

  6. Monitor for unusual activity, particularly unexpected DNP3 or IEC 61850 commands and new connections to substation networks.

  7. Prepare for manual operations and practise incident response with operations, protection and controls, and IT teams together.

How QBits Networks can help

We work with power and utility organizations, from those subject to NERC CIP to smaller distribution and municipal utilities outside its scope. Our OT visibility snapshots, network segmentation reviews and IEC 62443 gap assessments help you understand your substation and control centre networks and decide where to focus. Tell us what you need through our contact page and we'll scope it with you.

bottom of page