Electric, gas, steam and energy operations
Utility OT Assurance and Forensic Readiness
Can your utility isolate a business-network incident while preserving essential operations? GDF examines IT/OT boundaries, vendor access, recovery and incident evidence through separately scoped technical work.
Prove the controls that support continuity
A diagram can show separation between IT and OT while identity, remote access, historian services or engineering support still cross the boundary. We work with security, operations and engineering to document those dependencies and evaluate approved isolation and recovery procedures.
The initial scope can cover one access path, a plant or a defined group of facilities. Each site retains its own configuration and responsibility record. Shared corporate controls can be examined once where appropriate, with site evidence showing how each installation inherits and operates them.
Independent technical audit support
Define the applicable audit requirements, systems and evidence. Disclose prior design or implementation work and establish any independence or specialist-review requirements before accepting the assignment.
IT/OT boundary validation
Map dependencies, identity and authorized routes across operational boundaries. Review isolation procedures and approve bounded validation with the operating engineer.
Vendor access and commissioning
Examine account approvals, gateways, session attribution and revocation. A new plant, microgrid, storage integration or controls handover can provide a defined acceptance-testing scope.
Forensic and recovery readiness
Agree on incident intake, authority, preservation, secure transfer, logging prerequisites and response terms. Review backups and test a representative recovery workflow under approved conditions.
New York Part 1200: IT assurance and a forensic-vendor relationship
New York's Part 1200 took effect June 1, 2026. The Public Service Commission describes the adopted rule as an IT cybersecurity regime, with industry-specific OT rulemaking separate. It is not a universal SCADA penetration-testing mandate.
For covered utilities, section 1200.18 requires a yearly qualified third-party IT audit and includes the ability to segment IT from OT during an incident. Section 1200.19 requires a contractual relationship with a qualified third-party forensic vendor. That requirement does not prescribe a retainer price or prepaid-hours arrangement.
Coverage, exclusions, phased controls and first-cycle audit timing must be checked for the actual entity. The first annual certification is due June 30, 2027. GDF's technical work supports the owner's evidence and readiness decisions; the owner and its advisers determine legal obligations and compliance status.
Official sources: New York PSC adoption announcement (opens in a new tab); PSC adoption order and Part 1200 (opens in a new tab); NIST Guide to Operational Technology Security (opens in a new tab).
Methodology
Separate the audit, validation and response work
-
Establish applicability
Confirm the legal entity, facilities, operating arrangements, audit boundary and requirements with the client and appropriate specialist.
-
Approve safe methods
Start with diagrams, interviews, records and passive evidence. Define operating windows, stop authority, exclusions and recovery arrangements before active work.
-
Validate selected controls
Review isolation, vendor access, identity, logging and restoration against the agreed scope. Record what was tested and what remains untested.
-
Report for action
Deliver management consequences and engineering evidence, with priorities, assigned corrective actions and practical retest criteria.
-
Establish response readiness
Check counsel, insurer and incumbent-vendor arrangements. Define incident authorization, preservation, transfer and actual response labor separately from the audit.
-
Schedule assurance
Agree on remediation verification, change-triggered testing, recovery exercises and a bounded annual work allocation.
Evidence commonly examined
Evidence reviewed
- IT/OT diagrams, asset boundaries and service dependencies
- Identity, vendor-access and segmentation configurations
- Isolation procedures, monitoring and time-source records
- Configuration baselines, backups and recovery exercises
What you can expect
What you receive
- Technical audit or assessment report for the agreed scope
- Boundary and vendor-access findings with supporting evidence
- Corrective-action ownership and remediation-verification plan
- Forensic-readiness procedures and separately defined response terms
Frequently asked
Common questions
Does Part 1200 apply to every utility?
No. Applicability and exclusions depend on the legal entity and regulatory definitions. Do not apply a water threshold to electric or gas operations or assume municipal utilities are covered.
Is this the same as NERC CIP compliance work?
No. NERC obligations require separate registration, asset and impact-category analysis. GDF's NERC CIP audit-evidence service supports defined technical work; sector-specialist qualifications and compliance mapping must be established for each engagement.
Can this cover energy plants outside New York?
Yes, the technical scope can address utility plants, microgrids, storage and building-control dependencies. New York rules are not applied to facilities outside their coverage. Scope follows the operating environment, buying event and client authority.
Does an assurance agreement include unlimited incident response?
No. Annual assurance has an agreed work allocation. Travel, implementation, specialist engineering and incident-response labor are separately defined unless expressly included.
Talk with an examiner
Discuss your utility and operating boundary
Tell us the utility or facility type, location, audit or commissioning deadline and the systems involved. We will discuss authority, specialist needs and operating constraints before proposing the technical scope. Do not submit sensitive control-system records through this form.
Since 1992 · 24/7 dispatch · Court-tested experts
Related capabilities