Energy, utilities & critical infrastructure

Defend the grid against adversaries who are already resident

Nation-state actors do not break into utilities to steal data. They establish quiet, patient access to operational technology and wait for a moment of geopolitical leverage. Guardian Sentinel finds that access, evidences it against NERC CIP, and contains it without ever writing to a relay, an RTU or a turbine controller.

  • NERC CIP-002 to CIP-015
  • TSA Security Directives
  • IEC 62443
  • NIS2 & NCSC CAF
  • FedRAMP High
7 State-sponsored clusters Guardian Labs tracks with confirmed grid pre-positioning Four with demonstrated ICS-specific capability
312 days Median dwell time in utility OT environments before discovery Against 21 days in commercial IT estates
83% Of utility intrusions enter through IT, a vendor or a remote-access path Not a single confirmed case of direct-to-OT internet exposure in 2025
$1.4M Maximum daily NERC CIP penalty exposure per violation Before the reliability and reputational consequences

The adversary

Pre-positioning is the campaign. The attack is optional.

Guardian Labs has tracked the shift since 2021: groups targeting energy infrastructure no longer deploy tooling that gets caught. They live off the land, use the remote-access paths you built for your own engineers, and hold position for a year or more. Detection therefore cannot depend on malware. It has to depend on knowing what normal looks like at every level of the operational estate.

INTRUSION STAGES IT foothold Credential access OT DMZ pivot Control discovery Impact capability Vendor VPN, phishing, edge device CVE Cached tickets, LSASS, shared service accounts Jump host, historian replica, patch relay RTU and relay sweeps, HMI screen capture Protective-relay logic, breaker manipulation GUARDIAN DETECTION DEPTH endpoint + identity identity graph conduit + protocol protocol semantics command validation Where the campaign ends Median Guardian detection point: stage three, when the adversary first authenticates into the operational DMZ using a credential that has never been used from that source. Detection is behavioural, so it does not depend on the adversary bringing a tool with them. Containment closes the conduit and revokes the identity. Nothing in the substation is written to, restarted or reconfigured by Guardian.
Detection depth by intrusion stage. Coverage peaks where the adversary must interact with systems whose behaviour is genuinely stable.

Living-off-the-land, catalogued

Guardian ships 2,100 detections for legitimate binaries used illegitimately — WMI, PowerShell remoting, ntdsutil, scheduled tasks, WinRM, PsExec derivatives — scored against how that binary behaves in your environment rather than a generic corpus. In a utility, the noise floor is low enough that this works.

Threat detection

Sector-specific intelligence

Guardian Labs maintains dedicated tracking on the clusters targeting electricity, gas, water and pipeline operators, with infrastructure indicators, tradecraft notes and detection logic delivered as content updates. E-ISAC and equivalent regional sharing feeds are ingested and correlated automatically.

Threat intelligence

The remote-access inventory

Every utility has more paths into OT than its diagram shows: the relay vendor's dial-back modem, the SCADA integrator's standing VPN, the turbine OEM's monitoring tunnel, the contractor laptop that alternates networks. Guardian enumerates them from observed traffic and identity events, then brokers what remains.

Identity protection

NERC CIP

Compliance evidence as a by-product of operating well

CIP audits fail on evidence, not on intent. Registered entities know what the standards require; what breaks is the ability to prove, on a given date eighteen months ago, that the control was operating. Guardian generates that proof continuously because the proof is the same telemetry the detections run on.

NERC CIP standards, the evidence an auditor typically requests, and the Guardian capability that produces it without a manual collection exercise.
Standard Requirement in practice Guardian capability Evidence produced
CIP-002 Identify and categorise BES Cyber Systems by impact rating Passive asset discovery with automatic classification proposals against your impact criteria Dated asset list with discovery source, categorisation rationale and change history
CIP-005 Electronic Security Perimeter with controlled, logged and encrypted remote access Conduit enforcement at every ESP boundary; brokered interactive remote access with full session recording Per-boundary flow record and a session register with user, asset, duration and recording reference
CIP-007 Ports and services, patching within 35 days, malicious-code prevention, event logging Continuous port and service inventory, patch-state tracking with deviation reporting, behavioural prevention on all in-scope hosts 35-day patch cycle report with exceptions, and an unbroken security-event log with integrity attestation
CIP-008 Incident reporting and response planning, including reportable Cyber Security Incidents Automated incident narrative with detection, containment and notification timestamps; E-ISAC reporting template pre-filled Per-incident timeline and the one-hour reportability determination record
CIP-010 Configuration change management and vulnerability assessments Baseline configuration monitoring with change attribution to a process, a user and a work order Change log showing authorised versus observed configuration, with unexplained deltas isolated
CIP-013 Supply-chain risk management for BES Cyber System vendors Vendor access brokering, vendor software integrity checks and vendor session analytics Per-vendor access report with what they connected to, when, and what they did
CIP-015 Internal network security monitoring inside the Electronic Security Perimeter East-west sensing within the ESP with protocol-aware anomaly detection and retained flow data Continuous internal monitoring record with anomaly disposition and retention proof

Scroll the table sideways to see every column.

CIP-015 raised internal network security monitoring from good practice to obligation. Guardian's east-west sensing inside the ESP was built for exactly this and does not require inline placement. See compliance advisory for audit preparation support.

Grid resilience

Security actions that cannot themselves cause an outage

A security tool that trips a protection scheme is not a security tool; it is an outage with good intentions. Guardian's operational estate behaviour is governed by hard constraints that are enforced in the product, not documented in a runbook.

Control centre Primary and backup SCADA · EMS · historian Guardian aggregation node, read-only feeds Security operations Guardian console + MDR analysts Adjacent to operations, never inline Operational WAN · MPLS, fibre, microwave, cellular and satellite backhaul Transmission substations Generating plant Distribution & field assets IEC 61850, DNP3, relays, IEDs Fanless DIN-rail sensor IEC 61850-3 / IEEE 1613 rated DCS, turbine control, BOP Rack sensor in the plant DMZ OEM tunnel brokered and recorded Reclosers, regulators, AMI, DER Cohort analytics at the head end Certificate and firmware drift 30-DAY LOCAL BUFFER 30-DAY LOCAL BUFFER HEAD-END BUFFER Survives a backhaul outage without losing evidence Bandwidth-capped, compressed, resumable Fleet telemetry aggregated before transport
Sensor topology across a typical utility estate. Security sits alongside operations; every site keeps its own evidence when the link drops.

Constraints enforced in the product

  • No writes to control devices. Guardian has no code path that issues a write, a mode change or a restart to a relay, RTU, PLC or IED. Not disabled by policy — absent from the product.
  • No active scanning inside the ESP by default. Discovery is passive. Optional active queries are per-asset, opt-in, rate-limited and confined to a declared window.
  • Enforcement degrades toward availability. If the sensor loses its management connection, conduits hold their last known-good policy rather than failing closed.
  • Safety systems are excluded from automation. Assets tagged as safety instrumented or protection are permanently out of scope for automated action; they alert to a human, always.
  • Bandwidth is capped per site. Telemetry from a remote substation on a 64 kbps link is budgeted, buffered and compressed, and will not contend with operational traffic.
Substations are not data centres A remote substation has a hardened cabinet, a thermal envelope from −40 °C to +70 °C, a satellite or cellular backhaul, and a maintenance visit twice a year. Guardian's substation sensor is fanless, DIN-rail mountable, IEC 61850-3 and IEEE 1613 rated, and holds 30 days of telemetry locally when the link is down.

Generation, transmission, distribution and beyond

The same platform covers thermal and nuclear generation balance of plant, wind and solar farm SCADA, hydro control, transmission substations, distribution automation, gas compression and transmission pipelines, and water treatment and distribution. Protocol coverage and asset models differ by domain; the console, the identity fabric and the analyst experience do not.

Distributed energy resources

Aggregated DERs and virtual power plants introduce thousands of internet-connected inverters under third-party control into what used to be a closed system. Guardian monitors the aggregator conduits and the DERMS platform as a first- class part of the operational estate, not as an IT afterthought.

OT & SCADA visibility

Command-level understanding of utility protocols

Utility protocols carry operational intent in a handful of bytes. Guardian decodes them fully and validates each command against the operational context — which master, which outstation, which window, which sequence — because that context is what separates a control action from an attack.

IEC 61850, DNP3 and ICCP

Substation automation is where the highest-consequence commands live and where the sequence numbers make tampering detectable. Guardian parses MMS for logical-node and dataset access, tracks GOOSE stNum and sqNum for spoofing, follows Sampled Values for merging-unit health, and validates DNP3 control-relay output blocks against the master that should be issuing them.

ICCP/TASE.2 links to the balancing authority and neighbouring utilities are baselined by bilateral table, so a request for a data object outside the agreed table is an alert rather than a silent success.

Representative detections

  • GOOSE publisher with a non-monotonic state number — classic replay or spoof
  • Protective-relay setting-group change outside a switching order
  • DNP3 direct-operate from a station that has only ever polled
  • ICCP request for an object absent from the bilateral agreement
  • Engineering-tool signature seen from a non-engineering subnet

Distribution automation at fleet scale

Distribution estates trade depth for count: tens of thousands of reclosers, capacitor bank controllers, voltage regulators and smart-grid routers, many on cellular backhaul, many installed by different contractors across two decades. Guardian handles the fleet as a population, detecting cohort deviations — this recloser family suddenly behaving unlike the other four thousand — rather than trying to baseline each device alone.

Field-area network security is included: rogue device detection on the mesh, certificate expiry tracking, and firmware-version drift across the fleet.

Representative detections

  • Mass configuration push to reclosers outside a maintenance window
  • Field device presenting a certificate issued by an unexpected authority
  • AMI head-end issuing remote disconnects at an anomalous rate
  • DERMS aggregator commanding curtailment outside its contracted envelope

Balance of plant and unit control

Generation sites blend a DCS, a turbine control system with its own OEM protocol, an emissions monitoring system, a plant historian and a corporate connection that exists because someone needs the megawatt figures in a spreadsheet by 08:00. Guardian covers Modbus, OPC UA, PROFINET, Foundation Fieldbus HSE and the major turbine-vendor protocols, and treats the OEM monitoring tunnel as the high-risk conduit it is.

Nuclear sites additionally get an isolation-verified deployment mode with no outbound connectivity from the protected estate.

Representative detections

  • Turbine control setpoint written from a host outside the DCS zone
  • OEM monitoring tunnel carrying interactive traffic, not telemetry
  • Historian replication volume changing shape without a schedule change
  • Emissions monitoring host reaching the internet directly

Pipeline, gas and water operations

Since the TSA security directives, pipeline operators must segment IT from OT, enforce access control, monitor continuously and patch on a defined cycle — with an annual architecture review to prove it. Guardian covers linear assets over thin and intermittent links, decodes ROC, BSAP, Modbus and DNP3 across compressor and metering stations, and models leak-detection and SCADA hosts as critical assets in their own right.

Water and wastewater utilities get the same coverage with chemical-dosing systems treated as safety-critical and excluded from automated response.

Representative detections

  • Setpoint change at a compressor station with no matching work order
  • Leak-detection host losing telemetry while SCADA reports normal
  • Chemical-dosing controller receiving writes from an HMI in another plant
  • Remote site reconnecting after outage with an altered configuration baseline

Deployment model

From first tap to audited operation

Guardian deploys into regulated utility environments in a documented sequence that your compliance team can attach to a CIP-010 change record before anything is connected.

Scope & classify

Guardian's team works from your existing CIP-002 categorisation and BES Cyber System list, identifies the ESPs and PSPs in scope, and produces the deployment design as a change package with rollback criteria. Nothing is connected in this phase.

Observe

Sensors are placed at ESP boundaries and inside the perimeter for CIP-015 coverage, fed from TAPs or mirror ports. Within three weeks you have an evidenced asset inventory, a conduit map and a list of remote-access paths — usually longer than the documented one.

Baseline & tune

Protocol and identity baselines are learned across a full operational cycle including a switching season and a planned outage. Detections run in advisory mode; your operations staff confirm which anomalies are genuinely abnormal.

Operate & evidence

Response playbooks go live with safety exclusions enforced, Guardian MDR takes 24/7 coverage with utility-qualified analysts, and CIP evidence packages generate on the schedule your audit calendar expects.

Deployment options

Guardian runs as FedRAMP High cloud, as a customer-managed private deployment in your own data centre, or as a fully isolated on-premise instance with no outbound connectivity for nuclear and defence-adjacent estates.

Trust & security

Data residency

Operational telemetry stays in the region you nominate, with per-site retention policy and cryptographic proof of integrity for the retention period an auditor asks about.

Compliance posture

Exercises & readiness

Guardian facilitates GridEx-aligned tabletop exercises and runs adversary simulations scoped to the OT boundary, so the response plan is tested before the regulator or the adversary tests it.

Adversary simulation

The finding that changed the conversation internally was not an intrusion. It was the inventory: forty-one remote-access paths into the operational estate, of which our documentation knew about nine. Guardian produced that list in nineteen days from passive observation. Everything we have done since started with that page.

Marcus Hedlund
VP Operational Technology Security, investor-owned utility
2,900+ Substations and generating sites monitored by Guardian Across North America, the EU and the UK
0 Guardian-initiated write operations to any control device, ever Architecturally impossible, not merely disabled
19 days Median time to a complete remote-access path inventory Passive observation only

Start with the list of ways in

Guardian will place passive sensors at your ESP boundaries for three weeks and return a complete inventory of operational assets, conduits and remote-access paths, mapped to your CIP-002 categorisation. No agents, no scanning, no writes. The report is yours.