Shift Left for Greater Grid Cybersecurity and Resilience


There is an urgent need to strengthen visibility and security validation into modernization before risks reach live power grid operations. A coordinated cyberattack on Poland’s energy sector at the end of 2025 shows how cyber risks can breach physical grid operations. According to CERT Polska, attackers targeted numerous distributed energy resources (DERs), including more than 30 wind and solar farms and a combined heat-and-power plant supplying heat to nearly 500,000 customers. They damaged industrial control equipment, disrupted communications with the distribution system operator, and attempted to deploy destructive malware. Electricity generation and heat delivery continued, but the intent was clear: turn digital access into operational disruption.

The consequences of major power grid disruptions can be far-reaching. The International Energy Agency notes that a major blackout can affect homes, schools, communications, financial services, and transport within seconds, with recent outages producing economic losses that collectively run into billions of dollars. While not all blackout examples were attributed to cyberattacks, they demonstrate the social and economic consequences if a cyber intrusion succeeds. That is why grid cybersecurity must shift left: moving visibility, threat modeling, security validation, and resilience testing earlier into system design and integration, before DERs and connected assets reach live operations.

Figure 1. Modern energy infrastructure is increasingly connected across operational technology, information technology, and DERs. Source: Grid Cybersecurity for Modern Energy Infrastructure

Connectivity is rewriting the grid’s risk model

Grid modernization is turning the electric system into a more observable, flexible, and responsive technology platform. Smart sensors improve situational awareness. Digital substations accelerate control and protection. DER systems such as wind and solar farms, battery storage, electric vehicles, and virtual power plants add new ways to balance supply and demand. These capabilities are essential to a more dynamic grid, but every connection also creates another pathway that must be understood, monitored, and secured.

This is especially important where information technology and operational technology (OT) converge. Conventional enterprise cybersecurity is designed primarily to protect data and systems. In grid environments, a cyber event can also alter physical processes: opening a breaker, changing a protection setting, disrupting communications, or obscuring the operating state of an asset. Availability and safety therefore sit alongside confidentiality and integrity as engineering requirements.

Legacy equipment compounds the challenge. Many operational assets were designed for long service lives, not frequent patch cycles or exposure to modern threat techniques. Utilities cannot simply replace every device or take critical systems offline whenever a vulnerability appears. They need a risk-based approach that combines segmentation, access control, asset intelligence, high-fidelity network telemetry, and tested response procedures.

Moving visibility inward with new regulations

The regulatory direction is clear. In June 2025, the U.S. Federal Energy Regulatory Commission approved NERC CIP-015-1, establishing internal network security monitoring requirements for high- and medium-impact bulk electric system cyber systems. The significance extends beyond compliance. Perimeter controls remain necessary, but they cannot reveal every instance of lateral movement or anomalous activity after an adversary gains access. Internal monitoring helps operators establish normal behavior, detect deviations, preserve evidence, and investigate incidents more effectively.

Non-compliance can also carry substantial financial consequences. Confirmed violations of mandatory NERC Reliability Standards are evaluated according to factors that include the requirement’s Violation Risk Factor, the applicable Violation Severity Level, and the duration of the violation.

Fines can exceed $1 million per violation for each day that it continues, although the amount imposed depends on the seriousness of the violation and the organization’s remediation efforts. Systemic failures involving multiple standards can result in significantly larger aggregate penalties: a 2019 enforcement action involving 127 Critical Infrastructure Protection violations resulted in a $10 million penalty.

The distribution grid presents a related but different challenge. NERC Critical Infrastructure Protection standards apply to the bulk electric system, while distribution networks and many distributed energy resources fall under other jurisdictions. U.S. Department of Energy and National Association of Regulatory Utility Commissioners guidance addresses this gap with voluntary cybersecurity baselines for electric distribution systems and distributed energy resources. Its priorities include asset inventory, network segmentation, documented topology, secure remote access, log collection, incident preparedness, and third-party validation of cybersecurity controls.

Together, these developments point to a broader change: grid cybersecurity is becoming an operating discipline, not a periodic audit exercise.

Figure 2. IT–OT convergence expands the grid attack surface and increases the need for visibility into East–West traffic. Source: Grid Cybersecurity for Modern Energy Infrastructure

Cultivating a “test first” mindset for cyber resilience

Resilience begins with knowing what is connected and how it normally communicates. Passive network taps and packet brokers can provide copies of traffic to security and analytics tools without inserting an active device into the production path. Access to network visibility can expose unmanaged assets, unexpected protocol use, unusual communications, and potential lateral movement across network segments.

Visibility alone, however, is not proof of resilience. Grid operators and solution providers also need to validate whether defenses perform as intended under realistic conditions. That means emulating credible traffic, faults, congestion, malware, denial-of-service activity, and protocol manipulation in a controlled environment, then measuring whether monitoring, detection, and response systems identify the right signals without disrupting operations.

This test-first mindset matters because a control that is configured is not necessarily a control that is effective. Security architectures should be challenged before deployment, after major changes, and as threats evolve. The goal is not to predict every attack. It is to reduce blind spots, verify detection paths, and give operators evidence that people, processes, and technology can work together when an incident occurs.

Securing grid modernization as momentum builds up

The grid will only get more interconnected, widening the exposure to cyber risks. Electrification, distributed generation, intelligent control, and data-driven operation are already reshaping energy infrastructure. The practical task is to build security into that transformation from design through operation.

For grid modernization professionals, three questions deserve attention:

  1. Can we see the assets and communications that matter?
  2. Can we detect behavior that departs from an established baseline?
  3. Have we validated our defenses under realistic operational conditions?

A connected grid must, above all, be a resilient grid. Stronger visibility, continuous monitoring, and repeatable security validation help convert cybersecurity from a defensive layer into an engineering capability – one that supports reliable power delivery as the energy system continues to evolve.

Explore Keysight’s grid cybersecurity resources for modern energy infrastructure:

Grid Cybersecurity for Modern Energy Infrastructure

Contact us for expert advice on grid modernization.

www.keysight.com/find/grid

limit
3