Power plants, electric networks, renewables and energy storage

Power & Energy Cybersecurity Assessment

Protect the systems that generate, deliver and manage power. GDF reviews control networks, vendor access, operational dependencies and recovery within an agreed technical scope.

Illustrative power and energy infrastructure.

Start with the facility and the operating decision

A generating plant, electric network, solar or wind site, battery system and microgrid can have different owners, control systems and responsibilities. Scope the actual systems and connections before selecting the work.

GDF works with the people responsible for cybersecurity, engineering and operations to review the agreed environment. The starting question might be whether a business-network incident could reach plant controls, whether a vendor's access can be revoked or whether records and backups would support recovery.

A project can focus on one connection, a plant change or a defined group of sites. Shared corporate services may be examined once, with site-specific records showing how each installation depends on them.

Choose the power and energy work you need

Scope follows the plant, network or fleet. These are technical work options, with qualifications and operating responsibilities agreed for the assignment.

Establish the current position

Cybersecurity Assessment

Review control networks, remote connections, supporting identities, vendor access, logging and recovery dependencies.

Receive a system and responsibility map, supported findings, an action register and management and technical reports.

Discuss an energy assessment

Review a change before accepting its cyber risk

Access & Recovery Checks

Examine selected access paths, proposed corrections and recovery dependencies for a new integration, vendor handover, site change or unresolved finding.

Agree the target, method, operating window, stop authority and recovery arrangements. Cybersecurity review does not include electrical commissioning or changes to protection settings.

Discuss a plant or system change

Keep readiness current across defined sites

Ongoing Cybersecurity Review

Agree on a calendar for site and vendor changes, selected corrective actions, incident-evidence reviews and tabletop or representative recovery exercises.

Set the sites, review dates, outputs and specialist allocation. Continuous monitoring, emergency response and engineering implementation are separately agreed services.

Discuss a scheduled program

Connect cybersecurity findings to the operation

  • Generation: plant control networks, engineering workstations, historian services and authorized remote support.
  • Electric networks: selected substation, communications and control-center dependencies, with engineering authority and operational exclusions established first.
  • Renewables and storage: site controllers, inverter-management interfaces, gateways, vendor services and fleet or aggregator connections included in the scope.
  • Microgrids and district energy: the agreed generation, storage, building-control and supporting network connections.

These examples define questions to discuss at scoping. They are not a claim that every asset, protection system or specialist field service is included.

Know which accounts and connections can reach the controls

Review network records, account inventories, gateways, engineering access and relevant session evidence. Identify who approves a vendor connection, which systems it can reach, whether its use can be attributed and how access is removed.

Examine the services that cross a business-network and control-network boundary, including identity, communications, support and data collection. Compare intended restrictions with configuration records and specifically authorized validation. An architecture drawing alone does not show that a boundary holds.

Agree on methods that respect operating constraints

Begin with interviews, existing diagrams, configuration records and approved passive evidence. Engineering and operations identify fragile systems, maintenance windows, stop-work contacts and recovery requirements.

Active testing requires explicit authorization for the system, technique, timing and operating conditions. A laboratory or representative asset may be the appropriate place to validate a concern. Excluded and untested areas remain visible in the report. Safeguards reduce risk; they do not guarantee that disruption is impossible.

The scope identifies any electrical, protection, process-control, OEM or integrator expertise the work needs. A general cybersecurity assessment does not authorize changes to plant logic, protection settings or live equipment.

Check what isolation, examination and restoration would require

Review the logs, time sources, account history and configuration records needed to understand a selected incident. Agree who can isolate a connection, preserve evidence and authorize further work while essential operating support is maintained.

Examine the backups, software versions, licenses, communications, vendor support and people needed to restore a selected function. A backup record is not a demonstration of successful restoration. A tabletop or representative restore exercise has its own approved scope and conditions.

Receive clear findings and accountable next steps

  • System and responsibility map: the facilities, operational dependencies, supporting services, vendors and authorized owners examined.
  • Access and boundary findings: the observed condition, supporting records, affected operation and remaining uncertainty.
  • Corrective-action register: responsible owners, agreed priorities and the evidence needed to assess a correction.
  • Recovery and incident-readiness record: the selected dependencies, preservation responsibilities, exercise results and untested areas.
  • Management and technical reports: decision-focused summaries and restricted detail for engineering and security teams.

Review the existing assessment and its open findings before ordering replacement work. Follow-up testing, engineering changes, independent audit and recurring reviews each have a defined scope.

Use the requirements that apply to your systems

NERC CIP work requires the responsible entity, registration, asset category, applicable requirement version and implementation dates to be established. Renewable generation and battery storage are not automatically outside the Bulk Electric System. A distribution or local energy asset is not automatically subject to the same requirements as a covered bulk-electric system.

DOE's distribution and distributed-energy cybersecurity baselines can inform technical reviews for those environments. They are guidance, not a universal federal compliance mandate. NIST's final Guide to Operational Technology Security addresses operating safety, reliability and performance alongside security.

For a defined NERC evidence assignment, see NERC CIP Audit Evidence Support. For New York utility IT audit and incident-readiness work, see Utility Cybersecurity Audit & Incident Readiness. Neither the general assessment nor a site visit automatically constitutes a formal regulatory audit or certification.

Official references checked October 7, 2026 (UTC): NERC CIP-015-2; NERC battery-storage and hybrid-resource guidance; DOE distribution and DER baselines.

Common questions

Can one engagement cover several plants or energy sites?

Yes, when each facility, owner, access permission and operating boundary is recorded. Shared services can be reviewed where appropriate, with site records showing the dependencies and exceptions.

Does this include penetration testing of live controls?

Only when the written scope specifically authorizes the target, method, timing and operating conditions. Records and passive evidence are useful starting points. Some systems are unsuitable for active production testing.

Can you assess solar, wind, batteries and microgrids?

The technical scope can address agreed control-network, gateway, remote-service and fleet dependencies. Specialist equipment and electrical or process work require the appropriate qualified participants and separate authorization.

Will this certify NERC CIP or New York utility compliance?

No. The assessment provides the agreed technical findings and records. Formal audits, applicability decisions, certifications and submissions have separate qualifications and accountable roles.

Is continuous monitoring or emergency response included?

No service name establishes those commitments. Agree any monitoring, response availability, staffing and response labor separately. Scheduled reviews have defined dates, sites and deliverables.

Discuss your power or energy facility

Start with the facility type, general location, systems involved and the decision or timing the work must support. Identify the engineering, operations and security contacts who can authorize the assignment.

Keep network diagrams, credentials, detailed vulnerabilities and incident evidence out of the initial inquiry. Approved information exchange is arranged separately.

Discuss Power & Energy Cybersecurity

Privacy center

Choose your site settings

Optional technology stays off until you choose otherwise. You can change these browser settings at any time. Access to the core site does not depend on optional technologies.

Technology preferences
Sale or cross-context sharing: not used GDF does not sell or share website personal information for cross-context behavioral advertising.