A practical guide for operators, engineering and security teams

Prepare for a Power & Energy Cybersecurity Assessment

Prepare facility boundaries, system records, operating constraints and specialist responsibilities for a power and energy cybersecurity assessment.

Illustrative power and energy infrastructure.

Record the facility, assets and owners

Identify the generating plant, electric-network assets, renewable sites, storage systems or microgrid included in the request. Record site owners, operators, vendors and the engineering, operations and security contacts who can authorize work.

Choose the operating question

Describe whether the need concerns an assessment, a new integration, an open finding, vendor access, incident evidence or recovery. Supply existing summaries and action lists through an agreed exchange so new work can build on what is already known.

Prepare relevant records

  • Available architecture, asset, network and supporting-service records.
  • Engineering and vendor-access accounts, gateways and approvals.
  • Relevant control-system, historian, site-controller and fleet-service interfaces.
  • Configuration baselines, change records, backups and restoration evidence.
  • Incident responsibilities, logs, time sources and previous exercise results.

Identify specialist responsibilities and exclusions

Agree who provides plant, electrical, protection, OEM and integrator expertise. Set operating windows, sensitive assets, allowed methods, stop authority and recovery arrangements. The assessment does not authorize live equipment changes or protection-setting changes.

Establish the requirements in scope

For a NERC-related assignment, the responsible entity supplies the applicable registration, asset categorization, requirement versions and review period. Distribution and distributed-energy reviews may use DOE's sector guidance. New York utility IT audit work has its own scope; do not substitute one program for another.

Keep the initial inquiry broad

Start with the facility type, location, role and timing. Keep diagrams, credentials and incident records out of the marketing form. Information handling is agreed before controlled records are exchanged.

Review Power & Energy Assessment Deliverables ยท Discuss the assessment

Privacy center

Choose your site settings

Optional technology stays off until you choose otherwise. You can change these browser settings at any time. Access to the core site does not depend on optional technologies.

Technology preferences
Sale or cross-context sharing: not used GDF does not sell or share website personal information for cross-context behavioral advertising.