Industry
Technology and security for energy and utilities
Energy and utility operators run control systems with long service lives next to modern IT, under critical infrastructure regulation. Onion Infosec supports the engineering, security and operation of both.
- Sector
- Energy & Utilities
- Segments
- Power generation and grids, Oil and gas, Water and wastewater, Renewables and distributed energy
01Context
Energy, water and fuel supply underpin every other sector.
In these environments availability is a safety property, and a failure has physical consequences and immediate public visibility.
Operators mix control systems that are decades old with modern IT, cloud analytics and large numbers of remote assets. Regulators treat the sector as critical infrastructure and expect demonstrable segmentation, monitoring and recovery capability. The adversaries include persistent, well-resourced groups as well as criminals.
02Technology
What the sector builds and runs.
- Control system modernization
- SCADA and telemetry upgrades, network segmentation between zones, and secure remote access for operators and vendors, planned around outage windows.
- Operational data and AI
- Historian and sensor data moved to cloud analytics for load forecasting, predictive maintenance and asset health, over one-way or brokered paths out of the control network.
- Customer and field systems
- Billing and metering data platforms, customer portals and field workforce applications.
- IT operations and managed services
- Corporate identity, endpoint, network and cloud operations with 24×7 monitoring and support, kept separate from control system administration.
03Risk
The risks that matter most.
- Persistent access by state-aligned actors
- Long-running campaigns that establish and maintain footholds in operator networks for possible later disruption.
- Ransomware with operational impact
- Criminal operations that reach, or force the shutdown of, systems on which control and dispatch depend.
- Remote access and vendor paths
- Maintenance connections and integrator access that recur as routes into control networks.
- Exposed field and distributed assets
- Substations, pumping stations, inverters and metering infrastructure reachable over public or shared networks with weak authentication.
04Regulation and assurance
What you may need to demonstrate.
IEC 62443 is the common technical reference for control systems, with ISO 27001 and ISO 27019 for the management system and NIST SP 800-82 as guidance. NERC CIP is mandatory for the North American bulk electric system, NIS2 applies to energy and water operators in the EU, and TSA directives cover US pipelines. Regional examples include NCIIPC guidance, CEA cyber security guidelines and CERT-In reporting in India.
Which of these apply depends on where you operate and what you do. We scope against your actual obligations.
05Where we usually start
Services that matter most here.
OT
Control system asset inventory, zone and conduit design, secure remote access and passive monitoring, aligned with IEC 62443 and the operator’s safety processes.
Managed SOC and MDR
24×7 monitoring of the corporate network and the IT/OT boundary, where most intrusions into control environments begin.
Incident readiness
Response plans and exercises that bring control room, engineering and IT staff into the same decision process.
Security architecture
Reference designs for segmentation, identity and data flows between control, corporate and cloud environments.
Cloud
Cloud platforms for operational data and analytics that receive data from the control network without creating a route back into it.
Managed services and support
24×7 operation and support of IT platforms and security tooling under documented change control.
