---
title: "Energy Grid SCADA Security by Firevault - Control for elect…"
url: https://fire-vault.com/control-for-energy
description: "Physically isolate transmission and distribution SCADA, IEC 61850 substations and DER control. Evidence for NIS2, NERC CIP and Ofgem."
lang: en-GB
---

Energy

# Physical isolation for transmission, distribution and substation control

Electricity networks now stretch from corporate trading systems down to IEC 61850 protection inside the substation. When those paths converge, a single compromise can move from an office to a breaker. Control puts a real boundary at every step.

- Ransomware in EMS and SCADA
- IT to OT lateral movement
- Third-party vendor access
- IEC 61850 substation risk

Back to Utilities: https://fire-vault.com/control-for-utilities

Image: Electrical grid control room with transmission pylons beyond (https://fire-vault.com/assets/sector-square-energy-41JUMkCc.jpg)

The exposure in numbers

01

Substation path isolation from corporate IT

100% Substation path isolation from corporate IT

02

Persistent OEM access into protection systems

Zero Persistent OEM access into protection systems

03

Control modules deployed per electricity zone

6 Control modules deployed per electricity zone

04

Evidence for NIS2, NERC CIP and Ofgem

Full Evidence for NIS2, NERC CIP and Ofgem

The Challenge

## Electricity control networks are converging faster than they can be defended.

01

### IT, OT and market convergence

Trading, settlement and ENCC interfaces sit close to the same control rooms that operate the grid. Attackers traverse those interfaces to reach EMS and SCADA.

02

### Legacy protection alongside IEC 61850

Substations carry a mix of legacy RTUs and modern IEC 61850 IEDs. They cannot all be patched on the same cycle without risking operational disruption.

03

### Distributed energy resources

Inverter-based resources and DER orchestration multiply the number of remotely reachable controllers across the distribution grid.

Energy

> When EMS, SCADA and substation networks are reachable from corporate or vendor estates, every software vulnerability becomes a candidate for a switching incident.

The Scenario

### Scenario: Substation vendor remote access compromise

Attackers compromise a protection vendor laptop with persistent VPN access into a transmission substation engineering network. From there they pivot through a shared jump server into the control room SCADA. Operators lose visibility across two grid supply points for several hours. Restoration is delayed because protection setting backups are stored on the same domain that was compromised. With Control, vendor access opens only on a scheduled, authorised window. The substation fabric is physically separate from the control room fabric. Verified baselines for protection settings are held on infrastructure with no live network path to production and require multi-party authorisation to release. The pivot path does not exist.

"We assumed our substations were isolated. They were, until a vendor laptop was trusted on both sides at the same time."

Module deployment · electricity network

## Where each Control module is deployed across generation, transmission and distribution.

Electricity operators run a Purdue stack from the corporate estate down to substation protection. Control puts a real boundary between the office, the operations centre and the substations so a problem in one place does not become a blackout in another.

Grounded in NIST SP 800-82 Rev. 3, IEC 62443-3-2, IEC 61850, NERC CIP-005 and NCSC CAF.

L5

Cloud / Internet

External

Market interfaces

Cloud services

Settlement, ENCC and market data.

Settlement, ENCC and market data.

Image: FV-Firebreak module icon (https://fire-vault.com/assets/firebreak-icon-7zSCkB1t.png)
Firebreak
Image: FV-Validate module icon (https://fire-vault.com/assets/vault-icon-CD3Pv4ri.png)
Validate

Market and cloud traffic terminates at the perimeter.

L4

Enterprise

IT

SOC

SIEM

Active Directory

Trading systems

Office, trading and corporate identity.

Office, trading and corporate identity.

Image: FV-Isolate module icon (https://fire-vault.com/assets/isolate-icon-B9t8fl3o.png)
Isolate
Image: FV-Firebreak module icon (https://fire-vault.com/assets/firebreak-icon-7zSCkB1t.png)
Firebreak

Office estate cannot reach the industrial DMZ on its own.

L3.5

Industrial DMZ

DMZ · trust boundary

Jump server

Patch & AV

ICCP gateway

Brokered exchange. No straight-through paths into operations.

Image: FV-Relay module icon (https://fire-vault.com/assets/relay-icon-CVhJDRO7.png)
Relay
Image: FV-Validate module icon (https://fire-vault.com/assets/vault-icon-CD3Pv4ri.png)
Validate
Image: FV-Execute module icon (https://fire-vault.com/assets/execute-icon-kJl5Gtmk.png)
Execute

ICCP and engineering traffic crosses on scheduled, approved routes.

L3

Control centre systems

OT

EMS / DMS

Historian

DERMS

Energy management, distribution management, DER orchestration.

Image: FV-Isolate module icon (https://fire-vault.com/assets/isolate-icon-B9t8fl3o.png)
Isolate
Image: FV-Lock module icon (https://fire-vault.com/assets/lock-icon-UU3vOaKE.png)
Lock

Control centre and SCADA on separate fabrics.

L2

Supervisory control

OT

SCADA

HMI

Substation gateway

Control room view of the grid.

Control room view of the grid.

Image: FV-Isolate module icon (https://fire-vault.com/assets/isolate-icon-B9t8fl3o.png)
Isolate
Image: FV-Execute module icon (https://fire-vault.com/assets/execute-icon-kJl5Gtmk.png)
Execute

Switching and protection changes need approval before they reach the substation.

L1

Substation control

Field

IEC 61850 IEDs

Protection relays

RTUs

Bay control and protection inside the substation.

Image: FV-Lock module icon (https://fire-vault.com/assets/lock-icon-UU3vOaKE.png)
Lock

Bay devices tie to named protection engineers.

L0

Primary plant

Field

Switchgear

Transformers

Sensors

OSS

Crown jewels

Off-network

Detail callout · A

Offline Secure Storage

Protection settings, substation configurations, EMS baselines and the recovery sets you need to restart the grid from a known-good state.

Offline by design · secure by default

Modules & symbols

Image: FV-Firebreak module icon (https://fire-vault.com/assets/firebreak-icon-7zSCkB1t.png)
Firebreak Physical sever

Image: FV-Validate module icon (https://fire-vault.com/assets/vault-icon-CD3Pv4ri.png)
Validate Integrity check

Image: FV-Isolate module icon (https://fire-vault.com/assets/isolate-icon-B9t8fl3o.png)
Isolate Zone boundary

Image: FV-Relay module icon (https://fire-vault.com/assets/relay-icon-CVhJDRO7.png)
Relay Time-bound path

Image: FV-Execute module icon (https://fire-vault.com/assets/execute-icon-kJl5Gtmk.png)
Execute Approved action

Image: FV-Lock module icon (https://fire-vault.com/assets/lock-icon-UU3vOaKE.png)
Lock Named access

DMZ boundary Trust transition

OSS callout Off-network detail

### Where each module is deployed, and what it does there.

One row per module. Placement on the network, then plain-English purpose at that point.

1. Image: FV-Isolate module icon (https://fire-vault.com/assets/isolate-icon-B9t8fl3o.png)
   Isolate
   At every Purdue boundary
   Office, ICCP, control centre and substation fabrics are physically separate. A compromise on the corporate side cannot reach protection.
2. Image: FV-Firebreak module icon (https://fire-vault.com/assets/firebreak-icon-7zSCkB1t.png)
   Firebreak
   On the L5 to L4 link and the L4 to L3.5 link
   A real off switch on the public and office boundaries when an incident is in flight.
3. Image: FV-Validate module icon (https://fire-vault.com/assets/vault-icon-CD3Pv4ri.png)
   Validate
   On the L5 to L4 link and inside the L3.5 DMZ
   ICCP and engineering traffic is checked for origin, integrity and authority before it reaches operations.
4. Image: FV-Relay module icon (https://fire-vault.com/assets/relay-icon-CVhJDRO7.png)
   Relay
   Inside the L3.5 DMZ
   Cross-domain data moves on scheduled routes. Nothing streams unattended into the control centre.
5. Image: FV-Execute module icon (https://fire-vault.com/assets/execute-icon-kJl5Gtmk.png)
   Execute
   Inside the L3.5 DMZ and on the L2 to L1 link
   Firmware, settings and switching actions hold until the right authority signs them off.
6. Image: FV-Lock module icon (https://fire-vault.com/assets/lock-icon-UU3vOaKE.png)
   Lock
   On the L3 to L2 link and the L1 to L0 link
   The closer you get to primary plant, the tighter the named access. Standing access into substations is the exception.

Featured In

Read about Firevault on TechRadar Pro: https://www.techradar.com/pro/uk-startup-put-physical-disconnect-switch-in-its-cloud-storage-offering-to-mitigate-ransomware-attacks-but-will-that-be-enough
Read about Firevault on Yahoo Finance: https://uk.finance.yahoo.com/news/firevault-launches-help-businesses-directors-074500961.html
Read about Firevault on Channel Insider: https://www.channelinsider.com/security/tools-and-platforms/firevault-security-offline-platform-offering/
Read about Firevault on Security Buyer: https://securitybuyer.com/uk-cybersecurity-startup-launches-firevault/
Read about Firevault on SecurityBrief: https://securitybrief.com.au/story/firevault-unveils-offline-digital-vault-to-combat-rising-cyber-risks

Capabilities

## What you get with every deployment

01

### Sovereign grid data

Grid control and protection data remains within the agreed jurisdiction in carefully selected Firevault Bunkers.

02

### Multi-party control

Critical switching and protection changes require sign-off from both control room and security teams.

03

### Regulatory evidence

Continuous compliance evidence for NIS2, NERC CIP and Ofgem cyber expectations.

04

### Out-of-band management

Cellular and dedicated paths keep the control plane reachable when primary networks are compromised.

05

### Tamper-proof logging

Every access, configuration change and switching command lands in immutable logs on physically separate infrastructure.

06

### Verified configuration baselines

Verified baselines of EMS, IED and SCADA configuration enable a known-good restore of control-plane state.

Demo to Live

## Adoption Guide

Step 1

#### Network assessment

Map every path between corporate IT, ICCP, EMS, SCADA and substation networks to identify convergence and persistent vendor connections.

Step 2

#### Zone architecture design

Design physically separated zones aligned to your control rooms and substation estate, with Control modules at each boundary.

Step 3

#### Non-production pilot

Deploy in a test environment mirroring an EMS and substation pair with full zone separation, multi-party authorisation and compliance logging.

Step 4

#### Operational deployment

Full deployment across the grid estate with verified configuration baselines, continuous compliance evidence and 24/7 out-of-band management.

Step 1

#### Network assessment

Step 2

#### Zone architecture design

Step 3

#### Non-production pilot

Step 4

#### Operational deployment

Organise a Demo: https://fire-vault.com/contact

Relevant Control Blueprints

## Deployment patterns that apply here

CP-05 FIRE+VAULT

### Protect Critical Infrastructure

Keep critical systems available, controlled and disconnected from unnecessary exposure.

View blueprint
https://fire-vault.com/control-blueprints/cp-05

CP-04 FIRE

### Enforce Physical Segmentation

Segmentation should not just be logical. It should be physically enforceable.

View blueprint
https://fire-vault.com/control-blueprints/cp-04

CP-02 FIRE

### Contain Active Breaches

When prevention fails, containment must be physical, immediate and provable.

View blueprint
https://fire-vault.com/control-blueprints/cp-02

CP-01 FIRE

### Stop Kill-Chain Ransomware

Stop ransomware moving, spreading or reaching the crown jewels.

View blueprint
https://fire-vault.com/control-blueprints/cp-01

## Explore More

### Control for Utilities

The parent view across power, water and gas networks.

Learn more about Control for Utilities
https://fire-vault.com/control-for-utilities

### Control for Critical Infrastructure

National-grade security for essential services.

Learn more about Control for Critical Infrastructure
https://fire-vault.com/control-for-critical-infrastructure

### IT/OT Convergence Threat

Physically separate IT from operational technology.

Learn more about IT/OT Convergence Threat
https://fire-vault.com/control-for-it-ot-convergence

### Control for Renewables

Wind, solar and battery sites with heavy OEM remote access.

Learn more about Control for Renewables
https://fire-vault.com/control-for-utilities-renewables

Questions

## Frequently Asked

Energy blueprint - PoC

### Speak to the team to organise a PoC

Walk through your blueprint with the Firevault team and scope a proof of concept on your estate. 30 minutes, no sales pitch.

## Structured data

```json
[
  {
    "@context": "https://schema.org",
    "@type": "Organization",
    "@id": "https://fire-vault.com/#organization",
    "name": "Firevault",
    "legalName": "Firevault Limited",
    "url": "https://fire-vault.com",
    "logo": {
      "@type": "ImageObject",
      "url": "https://fire-vault.com/logo.png",
      "width": 200,
      "height": 60
    },
    "foundingDate": "2025-03",
    "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
    "address": {
      "@type": "PostalAddress",
      "addressCountry": "GB",
      "addressLocality": "United Kingdom"
    },
    "contactPoint": [
      {
        "@type": "ContactPoint",
        "contactType": "customer service",
        "email": "hello@fire-vault.com",
        "availableLanguage": "English",
        "areaServed": [
          "GB",
          "EU",
          "US",
          "AE"
        ]
      },
      {
        "@type": "ContactPoint",
        "contactType": "sales",
        "email": "sales@fire-vault.com",
        "availableLanguage": "English",
        "areaServed": [
          "GB",
          "EU",
          "US",
          "AE"
        ]
      }
    ],
    "founder": [
      {
        "@type": "Person",
        "name": "Mark Fermor",
        "jobTitle": "Founder, CTO and CMO"
      },
      {
        "@type": "Person",
        "name": "David Bailey",
        "jobTitle": "Founder and CEO"
      }
    ],
    "areaServed": [
      "United Kingdom",
      "Europe",
      "United States",
      "Middle East"
    ],
    "sameAs": [
      "https://www.linkedin.com/company/firevault",
      "https://x.com/firevaultuk"
    ],
    "slogan": "Disconnect to Protect",
    "brand": [
      {
        "@type": "Brand",
        "name": "Offline Secure Storage"
      },
      {
        "@type": "Brand",
        "name": "Control by Firevault"
      },
      {
        "@type": "Brand",
        "name": "Firebreak"
      }
    ],
    "knowsAbout": [
      "Offline Secure Storage",
      "Physically disconnected data storage",
      "Physical Air Gap Data Protection",
      "Ransomware Protection",
      "Ransomware recovery",
      "3-2-1-1-0 backup rule",
      "AI kill switch",
      "Operational technology security",
      "Critical national infrastructure resilience",
      "Data Sovereignty",
      "GDPR Compliance",
      "NIS2 Compliance",
      "DORA Compliance",
      "NCSC Cyber Assessment Framework"
    ]
  },
  {
    "@context": "https://schema.org",
    "@type": "WebSite",
    "@id": "https://fire-vault.com/#website",
    "name": "Firevault",
    "alternateName": [
      "Firevault",
      "Firevault UK",
      "Firevault Limited"
    ],
    "url": "https://fire-vault.com",
    "publisher": {
      "@id": "https://fire-vault.com/#organization"
    },
    "inLanguage": "en-GB",
    "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
    "potentialAction": {
      "@type": "SearchAction",
      "target": {
        "@type": "EntryPoint",
        "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
      },
      "query-input": "required name=search_term_string"
    }
  },
  {
    "@context": "https://schema.org",
    "@type": "WebPage",
    "@id": "https://fire-vault.com/control-for-energy#webpage",
    "url": "https://fire-vault.com/control-for-energy",
    "name": "Energy Grid SCADA Security by Firevault - Control for elect…",
    "description": "Physically isolate transmission and distribution SCADA, IEC 61850 substations and DER control. Evidence for NIS2, NERC CIP and Ofgem.",
    "isPartOf": {
      "@id": "https://fire-vault.com/#website"
    },
    "about": {
      "@id": "https://fire-vault.com/#organization"
    },
    "primaryImageOfPage": {
      "@type": "ImageObject",
      "url": "https://fire-vault.com/images/og/og-base-platform.jpg"
    },
    "inLanguage": "en-GB",
    "breadcrumb": {
      "@id": "https://fire-vault.com/control-for-energy#breadcrumb"
    }
  },
  {
    "@context": "https://schema.org",
    "@type": "BreadcrumbList",
    "@id": "https://fire-vault.com/control-for-energy#breadcrumb",
    "itemListElement": [
      {
        "@type": "ListItem",
        "position": 1,
        "name": "Home",
        "item": "https://fire-vault.com"
      },
      {
        "@type": "ListItem",
        "position": 2,
        "name": "Energy Grid SCADA Security by Firevault - Control for elect…",
        "item": "https://fire-vault.com/control-for-energy"
      }
    ]
  }
]
```