---
title: "Utility & Power Grid SCADA Security | Control"
url: https://fire-vault.com/control-for-utilities
description: "Protect power grid SCADA networks and smart metering infrastructure by physically enforcing strict access control on all network data paths. Learn why."
lang: en-GB
---

Utilities

# Physical Isolation for Power Grid and Utility SCADA

Utility networks bridge physical infrastructure and digital control. When those control paths are compromised, the consequences extend far beyond data loss to affect millions of people who depend on essential services.

- SCADA compromise
- Ransomware in EMS
- Third-party vendor access
- DER and smart-meter risk

Back to Control: https://fire-vault.com/solutions/control

Image: Electrical grid control room with transmission pylons beyond (https://fire-vault.com/assets/sector-square-energy-41JUMkCc.jpg)

The exposure in numbers

01

SCADA path isolation from corporate IT

100% SCADA path isolation from corporate IT

02

Persistent remote access to control systems

Zero Persistent remote access to control systems

03

Control modules deployed per utility zone

6 Control modules deployed per utility zone

04

NIS2 and NERC CIP compliance evidence

Full NIS2 and NERC CIP compliance evidence

The Challenge

## Utility control systems face converging threats.

01

### IT/OT Convergence

Smart grid modernisation creates network paths between corporate IT and operational technology that attackers traverse to reach control systems.

02

### Legacy SCADA Systems

Decades-old SCADA and RTU equipment lacks modern security capabilities and cannot be patched without risking operational disruption.

03

### Smart Meter Attack Surface

Advanced metering infrastructure creates millions of network endpoints that expand the attack surface into previously isolated distribution networks.

Utilities

> When utility control systems are reachable from corporate networks or the internet, every software vulnerability becomes a potential service disruption affecting millions of people.

The Scenario

### Scenario: Smart Grid Supply Chain Attack

Attackers compromise a firmware update server for smart meter head-end systems. The malicious update propagates to distribution management systems through the AMI network, eventually reaching SCADA workstations via shared network segments. Operators lose visibility into distribution grid status across an entire region. Restoration takes nine days because backup SCADA configurations were stored on network-attached infrastructure that was also compromised. With Control, the AMI network is physically separated from SCADA systems. Verified control-plane baselines are held on infrastructure that has no live network path to production and require multi-party authorisation to release. The compromised firmware cannot traverse into control systems because the network path does not exist.

"Our penetration test showed that from a compromised smart meter head-end, there were only three hops to the SCADA master. Three hops between a meter and the ability to open breakers across the distribution network."

Module deployment · utility network

## Where each Control module is deployed across a utility network.

Utility estates run along the Purdue model: cloud and corporate at the top, an industrial DMZ in the middle, supervisory and basic control below it, and the physical plant at the bottom. Control puts a real boundary at every level so a problem on one side does not become a problem on the others.

Grounded in NIST SP 800-82 Rev. 3, IEC 62443-3-2, NERC CIP-005 and ENISA Smart Grid guidance.

L5

Cloud / Internet DMZ

External

Customer portal

Cloud services

Public reach, untrusted by default.

Public reach, untrusted by default.

Image: FV-Firebreak module icon (https://fire-vault.com/assets/firebreak-icon-7zSCkB1t.png)
Firebreak
Image: FV-Validate module icon (https://fire-vault.com/assets/vault-icon-CD3Pv4ri.png)
Validate

Public traffic terminates in the DMZ, not in the office.

L4

Enterprise

IT

SOC Detect, respond

SIEM

Active Directory

AMI head-end Meter billing

Office network and customer systems. Not part of operations.

Image: FV-Isolate module icon (https://fire-vault.com/assets/isolate-icon-B9t8fl3o.png)
Isolate
Image: FV-Firebreak module icon (https://fire-vault.com/assets/firebreak-icon-7zSCkB1t.png)
Firebreak

Office estate cannot reach the industrial DMZ on its own.

L3.5

Industrial DMZ

DMZ · trust boundary

Jump server

Patch & AV

Data broker

Brokered exchange between IT and OT. No straight-through paths.

Image: FV-Relay module icon (https://fire-vault.com/assets/relay-icon-CVhJDRO7.png)
Relay
Image: FV-Validate module icon (https://fire-vault.com/assets/vault-icon-CD3Pv4ri.png)
Validate
Image: FV-Execute module icon (https://fire-vault.com/assets/execute-icon-kJl5Gtmk.png)
Execute

Data and commands cross the DMZ on scheduled, approved routes.

L3

Operations systems

OT

Historian

Engineering workstation

MES

Operational records and engineering tools.

Image: FV-Isolate module icon (https://fire-vault.com/assets/isolate-icon-B9t8fl3o.png)
Isolate
Image: FV-Lock module icon (https://fire-vault.com/assets/lock-icon-UU3vOaKE.png)
Lock

Operations systems and SCADA sit on separate fabrics.

L2

Supervisory control

OT

Distribution SCADA

HMI

Control room view of the grid.

Control room view of the grid.

Image: FV-Isolate module icon (https://fire-vault.com/assets/isolate-icon-B9t8fl3o.png)
Isolate
Image: FV-Execute module icon (https://fire-vault.com/assets/execute-icon-kJl5Gtmk.png)
Execute

Control commands need approval before they reach substations.

L1

Basic control

Field

Substation RTUs

Protection relays

PLCs

Substations, breakers, feeders.

Substations, breakers, feeders.

Image: FV-Lock module icon (https://fire-vault.com/assets/lock-icon-UU3vOaKE.png)
Lock

Field devices ties to named engineers.

L0

Physical

Field

Sensors

Switchgear

Transformers

OSS

Crown jewels

Off-network

Detail callout · A

Offline Secure Storage

Grid configurations, protection relay settings, network maps and the recovery sets you need to rebuild from a known-good state.

Offline by design · secure by default

Modules & symbols

Image: FV-Firebreak module icon (https://fire-vault.com/assets/firebreak-icon-7zSCkB1t.png)
Firebreak Physical sever

Image: FV-Validate module icon (https://fire-vault.com/assets/vault-icon-CD3Pv4ri.png)
Validate Integrity check

Image: FV-Isolate module icon (https://fire-vault.com/assets/isolate-icon-B9t8fl3o.png)
Isolate Zone boundary

Image: FV-Relay module icon (https://fire-vault.com/assets/relay-icon-CVhJDRO7.png)
Relay Time-bound path

Image: FV-Execute module icon (https://fire-vault.com/assets/execute-icon-kJl5Gtmk.png)
Execute Approved action

Image: FV-Lock module icon (https://fire-vault.com/assets/lock-icon-UU3vOaKE.png)
Lock Named access

DMZ boundary Trust transition

OSS callout Off-network detail

### Where each module is deployed, and what it does there.

One row per module. Placement on the network, then plain-English purpose at that point.

1. Image: FV-Isolate module icon (https://fire-vault.com/assets/isolate-icon-B9t8fl3o.png)
   Isolate
   At every Purdue boundary
   Each level sits on its own physical fabric. A misconfigured rule on the corporate side cannot create a path into SCADA or the substations.
2. Image: FV-Firebreak module icon (https://fire-vault.com/assets/firebreak-icon-7zSCkB1t.png)
   Firebreak
   On the L5 to L4 link and the L4 to L3.5 link
   Firebreak gives operations a hardware off switch on the public and office boundaries, so a compromise in enterprise cannot ride a live cable into the grid.
3. Image: FV-Validate module icon (https://fire-vault.com/assets/vault-icon-CD3Pv4ri.png)
   Validate
   On the L5 to L4 link, and inside the L3.5 DMZ
   Before any request crosses into the office or down into operations, Validate checks origin, integrity and authority. Unsigned or unexpected traffic does not progress.
4. Image: FV-Relay module icon (https://fire-vault.com/assets/relay-icon-CVhJDRO7.png)
   Relay
   Inside the L3.5 DMZ
   Data flows from L4 into L3 inside scheduled, defined routes. Nothing streams unattended.
5. Image: FV-Execute module icon (https://fire-vault.com/assets/execute-icon-kJl5Gtmk.png)
   Execute
   Inside the L3.5 DMZ and on the L2 to L1 link
   Firmware, configuration and control actions hold until the right approval is in place. Single clicks do not move grid kit.
6. Image: FV-Lock module icon (https://fire-vault.com/assets/lock-icon-UU3vOaKE.png)
   Lock
   On the L3 to L2 link and the L1 to L0 link
   The closer you get to the physical plant, the tighter the named access. Standing access into substations is the exception.

Featured In

Read about Firevault on TechRadar Pro: https://www.techradar.com/pro/uk-startup-put-physical-disconnect-switch-in-its-cloud-storage-offering-to-mitigate-ransomware-attacks-but-will-that-be-enough
Read about Firevault on Yahoo Finance: https://uk.finance.yahoo.com/news/firevault-launches-help-businesses-directors-074500961.html
Read about Firevault on Channel Insider: https://www.channelinsider.com/security/tools-and-platforms/firevault-security-offline-platform-offering/
Read about Firevault on Security Buyer: https://securitybuyer.com/uk-cybersecurity-startup-launches-firevault/
Read about Firevault on SecurityBrief: https://securitybrief.com.au/story/firevault-unveils-offline-digital-vault-to-combat-rising-cyber-risks

Capabilities

## What you get with every deployment

01

### Sovereign Grid Data

All utility control data remains within the agreed jurisdiction in NATO-approved Firevault Bunkers, ensuring sovereign control over national energy infrastructure data.

02

### Multi-Party Control

Critical operations require authorisation from both control room operators and security teams, preventing unilateral access to grid control systems.

03

### Regulatory Evidence

Automated compliance logging generates continuous evidence for NIS2, NERC CIP, and Ofgem security requirements.

04

### Cellular Failover

Out-of-band management ensures control plane access even when primary utility communications networks are compromised.

05

### Tamper-Proof Logging

Every access, configuration change, and control command is recorded in immutable logs on physically separate infrastructure.

06

### Verified Configuration Baselines

Verified baselines of all grid configuration enable restoration of control-plane state during total compromise scenarios.

Demo to Live

## Adoption Guide

Step 1

#### Utility Network Assessment

Map all network paths between corporate IT, SCADA, AMI, and distribution management systems to identify convergence points and persistent connections.

Step 2

#### Zone Architecture Design

Design physically separated zones aligned to your utility operations with appropriate Control modules at each boundary.

Step 3

#### Non-Production Pilot

Deploy in a test environment mirroring your SCADA architecture with full zone separation, multi-party authorisation, and compliance logging.

Step 4

#### Operational Deployment

Full deployment across utility infrastructure with verified configuration baselines, continuous compliance evidence, and 24/7 out-of-band management.

Step 1

#### Utility Network Assessment

Step 2

#### Zone Architecture Design

Step 3

#### Non-Production Pilot

Step 4

#### Operational Deployment

Organise a Demo: https://fire-vault.com/contact

Relevant Control Blueprints

## Deployment patterns that apply here

CP-05 FIRE+VAULT

### Protect Critical Infrastructure

Keep critical systems available, controlled and disconnected from unnecessary exposure.

View blueprint
https://fire-vault.com/control-blueprints/cp-05

CP-04 FIRE

### Enforce Physical Segmentation

Segmentation should not just be logical. It should be physically enforceable.

View blueprint
https://fire-vault.com/control-blueprints/cp-04

CP-02 FIRE

### Contain Active Breaches

When prevention fails, containment must be physical, immediate and provable.

View blueprint
https://fire-vault.com/control-blueprints/cp-02

## Explore More

### Control for Energy

Transmission, distribution and substation control.

Learn more about Control for Energy
https://fire-vault.com/control-for-energy

### Control for Water (utilities)

Treatment, distribution and outstation telemetry.

Learn more about Control for Water (utilities)
https://fire-vault.com/control-for-utilities-water

### Control for Gas (utilities)

Gas SCADA, AGI and PRS control with safety on its own fabric.

Learn more about Control for Gas (utilities)
https://fire-vault.com/control-for-utilities-gas

### Control for Renewables and BESS

Wind, solar and battery sites with strict OEM governance.

Learn more about Control for Renewables and BESS
https://fire-vault.com/control-for-utilities-renewables

### Control for Critical Infrastructure

National-grade security for essential services.

Learn more about Control for Critical Infrastructure
https://fire-vault.com/control-for-critical-infrastructure

### IT/OT Convergence Threat

Physically separate IT from operational technology.

Learn more about IT/OT Convergence Threat
https://fire-vault.com/control-for-it-ot-convergence

Questions

## Frequently Asked

Explore by utility

## Sub-sectors under Utilities

Each sub-sector page carries a dedicated reference architecture and the Control modules that sit at every boundary in that estate.

### Water and wastewater

Treatment SCADA, distribution telemetry and dosing safety with a real boundary between office, telemetry and plant.

Explore
https://fire-vault.com/control-for-utilities-water

### Gas

Transmission and distribution SCADA, AGI and PRS control with safety systems on their own fabric.

Explore
https://fire-vault.com/control-for-utilities-gas

### Renewables and BESS

Wind, solar and battery sites with strict OEM access governance and fleet-to-site separation.

Explore
https://fire-vault.com/control-for-utilities-renewables

### Energy (top-level sector)

Transmission, distribution and substation control across EMS, SCADA and IEC 61850.

Explore
https://fire-vault.com/control-for-energy

Utilities blueprint - PoC

### Speak to the team to organise a PoC

Walk through your blueprint with the Firevault team and scope a proof of concept on your estate. 30 minutes, no sales pitch.

## Structured data

```json
[
  {
    "@context": "https://schema.org",
    "@type": "Organization",
    "@id": "https://fire-vault.com/#organization",
    "name": "Firevault",
    "legalName": "Firevault Limited",
    "url": "https://fire-vault.com",
    "logo": {
      "@type": "ImageObject",
      "url": "https://fire-vault.com/logo.png",
      "width": 200,
      "height": 60
    },
    "foundingDate": "2025-03",
    "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
    "address": {
      "@type": "PostalAddress",
      "addressCountry": "GB",
      "addressLocality": "United Kingdom"
    },
    "contactPoint": [
      {
        "@type": "ContactPoint",
        "contactType": "customer service",
        "email": "hello@fire-vault.com",
        "availableLanguage": "English",
        "areaServed": [
          "GB",
          "EU",
          "US",
          "AE"
        ]
      },
      {
        "@type": "ContactPoint",
        "contactType": "sales",
        "email": "sales@fire-vault.com",
        "availableLanguage": "English",
        "areaServed": [
          "GB",
          "EU",
          "US",
          "AE"
        ]
      }
    ],
    "founder": [
      {
        "@type": "Person",
        "name": "Mark Fermor",
        "jobTitle": "Founder, CTO and CMO"
      },
      {
        "@type": "Person",
        "name": "David Bailey",
        "jobTitle": "Founder and CEO"
      }
    ],
    "areaServed": [
      "United Kingdom",
      "Europe",
      "United States",
      "Middle East"
    ],
    "sameAs": [
      "https://www.linkedin.com/company/firevault",
      "https://x.com/firevaultuk"
    ],
    "slogan": "Disconnect to Protect",
    "brand": [
      {
        "@type": "Brand",
        "name": "Offline Secure Storage"
      },
      {
        "@type": "Brand",
        "name": "Control by Firevault"
      },
      {
        "@type": "Brand",
        "name": "Firebreak"
      }
    ],
    "knowsAbout": [
      "Offline Secure Storage",
      "Physically disconnected data storage",
      "Physical Air Gap Data Protection",
      "Ransomware Protection",
      "Ransomware recovery",
      "3-2-1-1-0 backup rule",
      "AI kill switch",
      "Operational technology security",
      "Critical national infrastructure resilience",
      "Data Sovereignty",
      "GDPR Compliance",
      "NIS2 Compliance",
      "DORA Compliance",
      "NCSC Cyber Assessment Framework"
    ]
  },
  {
    "@context": "https://schema.org",
    "@type": "WebSite",
    "@id": "https://fire-vault.com/#website",
    "name": "Firevault",
    "alternateName": [
      "Firevault",
      "Firevault UK",
      "Firevault Limited"
    ],
    "url": "https://fire-vault.com",
    "publisher": {
      "@id": "https://fire-vault.com/#organization"
    },
    "inLanguage": "en-GB",
    "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
    "potentialAction": {
      "@type": "SearchAction",
      "target": {
        "@type": "EntryPoint",
        "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
      },
      "query-input": "required name=search_term_string"
    }
  },
  {
    "@context": "https://schema.org",
    "@type": "WebPage",
    "@id": "https://fire-vault.com/control-for-utilities#webpage",
    "url": "https://fire-vault.com/control-for-utilities",
    "name": "Utility & Power Grid SCADA Security",
    "description": "Protect power grid SCADA networks and smart metering infrastructure by physically enforcing strict access control on all network data paths. Learn why.",
    "isPartOf": {
      "@id": "https://fire-vault.com/#website"
    },
    "about": {
      "@id": "https://fire-vault.com/#organization"
    },
    "primaryImageOfPage": {
      "@type": "ImageObject",
      "url": "https://fire-vault.com/images/og/og-base-platform.jpg"
    },
    "inLanguage": "en-GB",
    "breadcrumb": {
      "@id": "https://fire-vault.com/control-for-utilities#breadcrumb"
    }
  },
  {
    "@context": "https://schema.org",
    "@type": "BreadcrumbList",
    "@id": "https://fire-vault.com/control-for-utilities#breadcrumb",
    "itemListElement": [
      {
        "@type": "ListItem",
        "position": 1,
        "name": "Home",
        "item": "https://fire-vault.com"
      },
      {
        "@type": "ListItem",
        "position": 2,
        "name": "Utility & Power Grid SCADA Security",
        "item": "https://fire-vault.com/control-for-utilities"
      }
    ]
  }
]
```