Energy

Physical isolation for transmission, distribution and substation control

Electricity networks now stretch from corporate trading systems down to IEC 61850 protection inside the substation. When those paths converge, a single compromise can move from an office to a breaker. Control puts a real boundary at every step.

  • Ransomware in EMS and SCADA
  • IT to OT lateral movement
  • Third-party vendor access
  • IEC 61850 substation risk
Back to Utilities
Electrical grid control room with transmission pylons beyond
The exposure in numbers
01
Substation path isolation from corporate IT
100%Substation path isolation from corporate IT
02
Persistent OEM access into protection systems
ZeroPersistent OEM access into protection systems
03
Control modules deployed per electricity zone
6Control modules deployed per electricity zone
04
Evidence for NIS2, NERC CIP and Ofgem
FullEvidence for NIS2, NERC CIP and Ofgem
The Challenge

Electricity control networks are converging faster than they can be defended.

01

IT, OT and market convergence

Trading, settlement and ENCC interfaces sit close to the same control rooms that operate the grid. Attackers traverse those interfaces to reach EMS and SCADA.

02

Legacy protection alongside IEC 61850

Substations carry a mix of legacy RTUs and modern IEC 61850 IEDs. They cannot all be patched on the same cycle without risking operational disruption.

03

Distributed energy resources

Inverter-based resources and DER orchestration multiply the number of remotely reachable controllers across the distribution grid.

Energy

When EMS, SCADA and substation networks are reachable from corporate or vendor estates, every software vulnerability becomes a candidate for a switching incident.

The Scenario

Scenario: Substation vendor remote access compromise

Attackers compromise a protection vendor laptop with persistent VPN access into a transmission substation engineering network. From there they pivot through a shared jump server into the control room SCADA. Operators lose visibility across two grid supply points for several hours. Restoration is delayed because protection setting backups are stored on the same domain that was compromised. With Control, vendor access opens only on a scheduled, authorised window. The substation fabric is physically separate from the control room fabric. Verified baselines for protection settings are held on infrastructure with no live network path to production and require multi-party authorisation to release. The pivot path does not exist.

"We assumed our substations were isolated. They were, until a vendor laptop was trusted on both sides at the same time."

Module deployment · electricity network

Where each Control module is deployed across generation, transmission and distribution.

Electricity operators run a Purdue stack from the corporate estate down to substation protection. Control puts a real boundary between the office, the operations centre and the substations so a problem in one place does not become a blackout in another.

Grounded in NIST SP 800-82 Rev. 3, IEC 62443-3-2, IEC 61850, NERC CIP-005 and NCSC CAF.

L5

Cloud / Internet

External

Market interfaces
Cloud services

Settlement, ENCC and market data.

Settlement, ENCC and market data.

FV-Firebreak module iconFirebreakFV-Validate module iconValidate

Market and cloud traffic terminates at the perimeter.

L4

Enterprise

IT

SOC
SIEM
Active Directory
Trading systems

Office, trading and corporate identity.

Office, trading and corporate identity.

FV-Isolate module iconIsolateFV-Firebreak module iconFirebreak

Office estate cannot reach the industrial DMZ on its own.

L3.5

Industrial DMZ

DMZ · trust boundary

Jump server
Patch & AV
ICCP gateway

Brokered exchange. No straight-through paths into operations.

Brokered exchange. No straight-through paths into operations.

FV-Relay module iconRelayFV-Validate module iconValidateFV-Execute module iconExecute

ICCP and engineering traffic crosses on scheduled, approved routes.

L3

Control centre systems

OT

EMS / DMS
Historian
DERMS

Energy management, distribution management, DER orchestration.

Energy management, distribution management, DER orchestration.

FV-Isolate module iconIsolateFV-Lock module iconLock

Control centre and SCADA on separate fabrics.

L2

Supervisory control

OT

SCADA
HMI
Substation gateway

Control room view of the grid.

Control room view of the grid.

FV-Isolate module iconIsolateFV-Execute module iconExecute

Switching and protection changes need approval before they reach the substation.

L1

Substation control

Field

IEC 61850 IEDs
Protection relays
RTUs

Bay control and protection inside the substation.

Bay control and protection inside the substation.

FV-Lock module iconLock

Bay devices tie to named protection engineers.

L0

Primary plant

Field

Switchgear
Transformers
Sensors
OSS

Crown jewels

Off-network

Detail callout · A

Offline Secure Storage

Protection settings, substation configurations, EMS baselines and the recovery sets you need to restart the grid from a known-good state.

Offline by design · secure by default

Modules & symbols

FV-Firebreak module iconFirebreakPhysical sever
FV-Validate module iconValidateIntegrity check
FV-Isolate module iconIsolateZone boundary
FV-Relay module iconRelayTime-bound path
FV-Execute module iconExecuteApproved action
FV-Lock module iconLockNamed access
DMZ boundaryTrust transition
OSS calloutOff-network detail

Where each module is deployed, and what it does there.

One row per module. Placement on the network, then plain-English purpose at that point.

  1. FV-Isolate module icon

    Isolate

    At every Purdue boundary

    Office, ICCP, control centre and substation fabrics are physically separate. A compromise on the corporate side cannot reach protection.

  2. FV-Firebreak module icon

    Firebreak

    On the L5 to L4 link and the L4 to L3.5 link

    A real off switch on the public and office boundaries when an incident is in flight.

  3. FV-Validate module icon

    Validate

    On the L5 to L4 link and inside the L3.5 DMZ

    ICCP and engineering traffic is checked for origin, integrity and authority before it reaches operations.

  4. FV-Relay module icon

    Relay

    Inside the L3.5 DMZ

    Cross-domain data moves on scheduled routes. Nothing streams unattended into the control centre.

  5. FV-Execute module icon

    Execute

    Inside the L3.5 DMZ and on the L2 to L1 link

    Firmware, settings and switching actions hold until the right authority signs them off.

  6. FV-Lock module icon

    Lock

    On the L3 to L2 link and the L1 to L0 link

    The closer you get to primary plant, the tighter the named access. Standing access into substations is the exception.

Featured In

TechRadar Pro logoYahoo Finance logoChannel Insider logoSecurity Buyer logoSecurityBrief logo

Capabilities

What you get with every deployment

01

Sovereign grid data

Grid control and protection data remains within the agreed jurisdiction in carefully selected Firevault Bunkers.

02

Multi-party control

Critical switching and protection changes require sign-off from both control room and security teams.

03

Regulatory evidence

Continuous compliance evidence for NIS2, NERC CIP and Ofgem cyber expectations.

04

Out-of-band management

Cellular and dedicated paths keep the control plane reachable when primary networks are compromised.

05

Tamper-proof logging

Every access, configuration change and switching command lands in immutable logs on physically separate infrastructure.

06

Verified configuration baselines

Verified baselines of EMS, IED and SCADA configuration enable a known-good restore of control-plane state.

Demo to Live

Adoption Guide

Step 1

Network assessment

Map every path between corporate IT, ICCP, EMS, SCADA and substation networks to identify convergence and persistent vendor connections.

Step 2

Zone architecture design

Design physically separated zones aligned to your control rooms and substation estate, with Control modules at each boundary.

Step 3

Non-production pilot

Deploy in a test environment mirroring an EMS and substation pair with full zone separation, multi-party authorisation and compliance logging.

Step 4

Operational deployment

Full deployment across the grid estate with verified configuration baselines, continuous compliance evidence and 24/7 out-of-band management.

Step 1

Network assessment

Map every path between corporate IT, ICCP, EMS, SCADA and substation networks to identify convergence and persistent vendor connections.

Step 2

Zone architecture design

Design physically separated zones aligned to your control rooms and substation estate, with Control modules at each boundary.

Step 3

Non-production pilot

Deploy in a test environment mirroring an EMS and substation pair with full zone separation, multi-party authorisation and compliance logging.

Step 4

Operational deployment

Full deployment across the grid estate with verified configuration baselines, continuous compliance evidence and 24/7 out-of-band management.

Questions

Frequently Asked

Energy blueprint - PoC

Speak to the team to organise a PoC

Walk through your blueprint with the Firevault team and scope a proof of concept on your estate. 30 minutes, no sales pitch.