PDN

Cybersecurity and Energy Issues (2)

5 min readPart 2 of 2

Illustration for the article: Cybersecurity and Energy Issues (2)

The energy winter reminds us of a somewhat forgotten reality: the continuity of electricity, heating, gas or services run by critical infrastructure is never guaranteed. In periods of heightened geopolitical tension, energy networks become not only a prime target, but also a potential multiplier of chaos. When it comes to security, the question is therefore no longer only how to protect systems, but how to maintain operational continuity, limit the domino effect and ensure structural resilience capable of absorbing an incident, even a serious one.

The operational security of critical infrastructure no longer rests solely on prevention or on isolated technical measures. It requires a systemic approach, combining resilience engineering, intelligent segmentation, coordination among stakeholders, frequent simulations and the ability to restore services under degraded conditions.

In this second part, we therefore try to analyze how best to secure this critical infrastructure.

AgencePDN gets pirated content removed: see our solutions by sector.

Continuity: Going Beyond Simple IT Security

Energy operators have long thought of security as a partitioning centred on IT systems. Yet service continuity encompasses the whole ecosystem: industrial control, logistics, remote transmission, suppliers, subcontractors, high-voltage substations, sensors, and even the human management of repair crews. An attack no longer aims only to infiltrate a system, but to disrupt a set of interdependent processes.

A robust policy must include:

  • the continuity of industrial operations
  • the preservation of the safety of physical installations
  • the ability to operate in a degraded situation
  • internal and external communication
  • coordination with public authorities

Each axis helps ensure that a digital failure does not turn into a human or economic catastrophe. To that end, resilience can no longer be thought of in terms of isolated actions; it becomes a true fabric.

Segmentation: Breaking the Chains of Interdependence

Segmentation is one of the most critical pillars, and one of the most often poorly implemented. Energy infrastructure frequently inherits historical architectures, stacked up over decades, in which all the networks are interconnected, sometimes invisibly. This configuration allows an attacker to move around more easily once inside.

Three levels of segmentation are generally distinguished:

  • logical segmentation (subnets, VLANs, flow control)
  • physical segmentation (distinct zones, separate equipment, dedicated industrial firewalls)
  • operational segmentation (limiting dependencies between sites, processes or production lines)

The goal is not only to prevent an attack, but to contain the impact. Successful segmentation is not necessarily there to stop the intrusion, but it turns a potentially massive attack into a localized incident, making it possible to spread and absorb the consequences, and therefore to minimize them.

In addition, segmentation must be accompanied by very strict access policies. In winter, field teams, sometimes facing difficult conditions, may be tempted to bypass restrictions to save time. Resilience therefore requires a constant trade-off between security and operability, so that the system does not become needlessly rigid, while security is preserved.

Organizing Resilience

Operational resilience must never be confused with redundancy. Having two identical systems does not guarantee that one will survive an attack that exploits a shared vulnerability. True resilience involves diversity of mechanisms, technologies, suppliers and response procedures.

Energy operators must therefore develop several layers:

  • geographic redundancy, which means the ability to switch between several physical sites
  • technological redundancy: using alternative systems that do not share the same flaws
  • human redundancy: teams trained in multiple procedures, including manual ones
  • software resilience: the ability to quickly isolate failing segments

A good practice is to document the “breaking points” which, if compromised, lead to cascading collapses. In an energy system, these breaking points can be a transformer substation, a remote-control interface, a single sensor supplier, or even a simple unencrypted protocol linking two industrial subsystems.

Resilience also requires modernizing ageing technologies. Many infrastructures still run on unsecured protocols, sometimes impossible to update without replacing an entire industrial chain. This budgetary and logistical challenge is one of the central knots of energy cybersecurity. The point is not to replace everything, but to prioritize vital areas, to ring-fence the oldest systems so that they do not become entry points, and to reinforce perimeter defences, in order to avoid the domino effect as far as possible.

Crisis Anticipation and Simulations

Incident simulation is arguably the most powerful tool for containing crises, and yet it is also the most underused. Many operators carry out annual exercises, often compliance-driven, with predictable and controlled scenarios. Yet today’s attacks are designed to defeat precisely what is anticipated. A credible simulation must:

  • include extreme scenarios, notably internal sabotage, total outage, loss of control
  • provide for communication breakdowns between teams
  • simulate human errors, deliberately introduced
  • include external partners (public authorities, service providers)
  • extend over time

The aim is to detect invisible flaws. A well-run simulation always reveals surprises: undeclared dependencies, forgotten configurations, missing up-to-date documentation, or incompatibility between theoretical procedures and the reality on the ground.

The energy winter imposes an additional constraint: an extreme cold snap can saturate the grid; a cyberattack and a physical incident occurring simultaneously add further strain to the systems. Exercises must therefore consider combined crises.

Building an Internal Culture of Continuity

No technical strategy can make up for an organization in which the logic of continuity is not understood. Operators must train their teams not only in IT security, but in decision-making in degraded situations, and in particular in prioritizing in an emergency context.

A culture of continuity also means recognizing an essential fact: in some situations, the priority is no longer protecting the system, but protecting people and preserving the infrastructure physically.

Teams must sometimes be ready to take certain systems offline, stop processes, isolate entire network segments, even if this causes a temporary loss of service. Continuity is also the ability to regain control quickly and effectively after a shutdown.

Join us in mid-January, after the holidays, for our 2025 year in review. In the meantime, if you have a film, a series, software or an ebook to protect, don’t hesitate to call on our services by contacting one of our account managers; PDN has been a pioneer in cybersecurity and anti-piracy for more than ten years, and we are bound to have a solution to help you. Happy reading, and see you soon!

Share this article

On the same topic

Is your content pirated? We can get it removed.