HomeSecurityResearch into 100+ energy systems reveals critical vulnerabilities

Research into 100+ energy systems reveals critical vulnerabilities

An OMICRON study has revealed widespread vulnerabilities in operational technology (OT) networks of substations, power plants and control centers worldwide. Based on data from more than 100 facilities, the analysis highlights recurring technical, organizational and operational issues that leave critical energy infrastructure vulnerable to cyber threats.

See also: Ivanti EPMM: Exploiting zero-day vulnerabilities – UPDATE NOW

vulnerabilities
Research into 100+ energy systems reveals critical vulnerabilities

The findings are based on several years of development of OMICRON’s StationGuard intrusion detection system (IDS) in protection, automation and control (PAC) systems. The technology, which passively monitors network traffic, has provided deep visibility into real-world OT environments. The results highlight the growing attack surface in energy systems and the challenges operators face in securing aging infrastructure and complex network architectures.

StationGuard deployments, often performed during security assessments, have uncovered vulnerabilities such as outdated devices, insecure external connections, weak network segmentation, and incomplete asset inventories. In many cases, these security weaknesses were discovered within the first 30 minutes of connecting to the network. In addition to security risks, the assessments have also uncovered operational issues such as VLAN misconfigurations, time synchronization errors, and network redundancy issues.

In addition to technical deficiencies, the findings highlight organizational factors that contribute to these risks — including unclear responsibilities for OT security, limited resources, and siloed departments. These findings reflect a growing trend across the energy sector: IT and OT environments are rapidly converging, yet security measures often fall short.

The ability to detect security incidents is an integral part of most security frameworks and guidelines, including the NIST Cybersecurity Framework, IEC 62443, and the ISO 27000 series of standards. In substations, power plant control systems, and control centers, many devices operate without standard operating systems, making it impossible to install endpoint detection software.

See also: SolarWinds: Critical RCE vulnerabilities in Web Help Desk

Research into 100+ energy systems reveals critical vulnerabilities
Research into 100+ energy systems reveals critical vulnerabilities

In such environments, detection capabilities must be implemented at the network level.

OMICRON StationGuard deployments typically use network mirror ports or Ethernet TAPs to passively monitor communication. In addition to detecting intrusions and cyber threats, IDS technology provides key benefits such as visualizing network communication, identifying unnecessary services and dangerous network connections, automatically creating an asset inventory, and detecting device vulnerabilities based on this inventory.

The report is based on years of IDS installations, with the first installation dating back to 2018. Since then, several hundred installations and security assessments have been conducted at substations, power plants and control centers in dozens of countries. The findings are grouped into three categories: technical security risks, organizational security issues and operational issues.

In most cases, critical security and operational issues were identified within minutes of connecting the IDS to the network.

Typically, sensors were connected to mirror ports in OT networks, often at gateways and other critical network entry points, to capture key communication flows. In many substations, bay-level monitoring was not necessary, as multicast propagation made traffic visible elsewhere in the network.

See also: Two serious vulnerabilities in n8n allow RCE

Research into 100+ energy systems reveals critical vulnerabilities

Accurate asset inventories are essential for the security of complex energy systems. Creating and maintaining such inventories manually is time-consuming and error-prone. To address this, OMICRON used both passive and active methods for automated asset discovery.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS