Cybersecurity inside connected generation, protected operations

Every new renewable site adds opportunity—and exposure. Building security into every layer of technology ensures innovation doesn’t outpace cybersecurity.

Cybersecurity, generation, operational insights

  • Increasingly decentralized and secure renewable generation assets are helped with standards, such as North American Electric Reliability Corporation Critical Infrastructure Protection standard 015-1 and IEC 62443 secure by design standards.
  • Navigating information technology and operational technology (IT/OT) convergence can help cybersecurity.
  • Steering through supply chain risks can help set a cybersecure foundation.

As the world of industrial cybersecurity has changed, so too has the power industry and how industrial facilities are powered. Renewable energy solutions have become more affordable, and their value as a generation source has increased dramatically. Utilities have taken notice and have begun rapidly building and acquiring renewable generation assets—wind turbines, solar farms, hydro generation, and more.

Alongside the rise in integration of renewable energy comes increased attention on utilities. One of the key reasons power generators are expanding their capacity is that they are recognized as critical infrastructure. Electrification is increasing around the globe, and the demand for power has never been higher. As a result, power organizations are increasingly becoming targets for cyber-attacks, so a strong cybersecurity posture must be a central part of any plan to add generation capacity.

In fact, new standards such as the North American Electric Reliability Corporation Critical Infrastructure Protection standard 015-1 (NERC CIP-015-1) increase this pressure, requiring network security monitoring on systems with external, routable communication, which is common in distributed renewable assets. While many sites do not generate enough power to fall under NERC CIP-015-1 today, that may not be the case forever.

Moreover, as more organizations are exploring the use of artificial intelligence (AI), they are quickly discovering strong cybersecurity practices are a core prerequisite for implementing AI technologies as these often rely on cloud connectivity. The teams that implement secure architectures to properly protect their assets are also building the secure infrastructure they will need to leverage AI for competitive advantage in an increasingly challenging global marketplace.

Figure 1: As renewable energy integration grows and electrification accelerates, power organizations need greater visibility into these assets, which creates greater risk. As a critical infrastructure, utilities must make cybersecurity a core part of every generation expansion plan. Courtesy: Emerson

Many organizations are looking for ways to integrate their new generation assets securely but find the process challenging. Fortunately—by focusing on secure strategies for decentralization, carefully navigating challenges at the information technology (IT)/operational technology (OT) convergence, and managing supply chain risk—teams can build a strong foundation for more cybersecure operation across the lifecycle of their assets (Figure 1).

Decentralized and secure renewable assets: Standards

Renewable assets are typically installed and operated differently from traditional generation sources. First and foremost, renewable generation assets are frequently distributed, often in unmanned facilities. These remote sites are then connected to a distant control center where they are managed by centralized teams.

Solar fields and wind farms can easily be situated hours away from the control center and there may not be a person onsite for weeks at a time. If such a site loses connectivity to the control center, either through infrastructure failure or malicious activity, it can significantly impact operations. Those challenges can lead to outages, and potentially to fines and reputation loss.

To help avoid these complications, forward-thinking organizations plan—in the earliest stages— how they will service and maintain decentralized assets, as well as what systems will be in place for secure remote management. Decentralized sites will need redundant networking solutions so that a single failure or attack on a networking device cannot disrupt the entire system. In addition, they will need alternative networking paths—such as secure remote access through public internet or private fiber optics—or even radio frequency or microwave.

Figure 2: The best control solutions will have network redundancy built in, allowing secure remote access that is separate from the typical network path. Courtesy: Emerson

Organizations will want to ensure they have control technologies built to support secure, redundant communication. The best control solutions will have network redundancy built in, allowing secure remote access that is separate from the typical network path (Figure 2).

Operations teams should also consider the added physical security needs that emerge from being decentralized and remote. If the facility has nobody onsite, security risk increases. Unmanned buildings should be secure and monitored remotely to keep unauthorized individuals out. However, ensuring onsite software systems are secure by design per IEC 62443 standards is also important. Control technologies built following IEC 62443-4-2 Security Level 2 are designed specifically to protect against malicious activity, further helping protect remote systems.

Figure 3: Built-in cybersecurity layers—such as applied in the Emerson Power and Water Cybersecurity Suite software—strengthen control software without compromising performance or reliability. Courtesy: Emerson

The most advanced control software will be designed in parallel with cybersecurity solutions that can be layered on top, such as a power and water cybersecurity suite. Teams should seek out automation software that can be paired with fit-for-purpose mitigating control solutions, built to deliver additional layers of security without impacting the performance or reliability of critical systems (Figure 3).

Navigating IT/OT convergence, cybersecurity

As power generation companies explore cybersecurity software to protect their systems, it will be important to examine existing agreements and relationships with traditional IT vendors. Many of the technologies in the renewable energy space look like IT technologies, which can easily lead to the perception that any IT cybersecurity solution will work. However, controls for renewable energy assets are still OT solutions, and OT systems have very particular behaviors and design that can cause conflicts with traditional IT components.

For example, many IT cybersecurity solutions continually update from the cloud. This provides the ability to be up to date with the latest definitions, indicators of compromise, and common vulnerabilities and exposures. But allowing these types of prompt updated protection can cause problems, so teams should still perform risk assessments to identify the risk versus the reward. If a cybersecurity solution installs an update from the cloud that has not been validated and may create a conflict with the control system, it could lead to a power outage.

Ultimately, successfully bringing in new cybersecurity solutions will require extra validation, testing, and tuning of IT products to make sure they do not negatively impact performance and reliability of OT systems. Fortunately, IT and OT have similar goals. Both want to ensure systems are protected and that they can be accessed securely. Often, accomplishing those goals means finding a way for both teams to understand the other’s goals and objectives so they can architect the best solution to meet everyone’s needs.

Today, many organizations are using their automation solution provider as an ally and resource to help navigate the complexity of the IT/OT convergence. Automation suppliers with decades of experience in the power industry have deep knowledge of IT and OT needs and industry trends, as well as the capacity to validate cybersecurity tools against their automation solutions. An expert automation supplier with power industry expertise can typically act as a liaison between OT and IT groups, helping both teams collaborate to identify and architect the perfect solution for their unique application.

Steering through supply chain risks

Another important consideration to help ensure cybersecure operation is to evaluate the risk brought by entities supplying an organization’s technologies. Project teams should regularly evaluate vendors to ensure they have a plan to deliver a secure lifecycle for their products.

One key element of delivering a secure lifecycle for products is following best practices for secure design. The most advanced automation suppliers will carry International Society of Automation IEC 62443 certification on their products, demonstrating that they follow best practices for secure design. Such products will not only have a reduced threat footprint on release, they will also have strong mechanisms in place to address discovered vulnerabilities across the lifecycle of the equipment.

It is also important to ensure that suppliers have a strong history of automation equipment development. Not only does a long history help ensure that the supplier will be there to support the product across its lifecycle—particularly as new cybersecurity threats emerge—it also ensures there is little to no risk that the company is creating intentional backdoors into its products.

Another benefit of suppliers with a long history of expertise in industry is that they will evaluate their own suppliers, helping drive security all the way down the supply chain. Expert automation software companies perform regular risk assessments on all vendors across their supply chains, evaluating their cybersecurity maturity and ability to handle issues.

The most advanced automation solution providers should also offer other cybersecurity support. They will provide cybersecurity guidebooks tailored for specific industries, helping project teams develop concrete cybersecurity plans with best practices, strong risk assessment, and a clear understanding of the current threat landscape.

Moreover, a strong solution provider with decades of industry experience will also help teams maintain their cybersecurity posture long-term. No cybersecurity solution is set-and-forget because cybersecurity is an ever-evolving journey. The best automation solutions providers will therefore keep a finger on the pulse of trending threats and continually update their solutions, always providing the best possible security.

Setting a cybersecure foundation

The rise of renewable energy is a critical enabler for the rapid expansion of electrification around the world. As power suppliers add more renewable generation capacity, they increase the sustainability and cost-effectiveness of their operations, while also improving reliability as they continually diversify their portfolios.

However, renewables operations must also be secure operations. Like any energy generation, renewable generation is critical infrastructure, so cybersecurity should be a primary concern. The cybersecurity landscape is complex and the distributed nature of renewables can further increase that complexity, but working closely with industry experts to navigate challenges will ensure best practices, while also maintaining continuous flexibility to shore up defenses as threats evolve.

Nicholas Janouskovec is the business development manager for Emerson’s cybersecurity solutions and services for the power and water industries. Edited by Mark T. Hoske, editor-in-chief, Control Engineering, WTWH Media, [email protected].

Keywords

Industrial cybersecurity, industrial generation, layered cybersecurity

Consider this

As you expand or update generating resources, are connections cybersecurity.

You also might like

Get more Control Engineering cybersecurity help.

https://www.controleng.com/industrial-cyber-security

Written by

Nicholas Janouskovec, Emerson

Nicholas Janouskovec is the business development manager for Emerson’s cybersecurity solutions and services for the power and water industries. As the cybersecurity business development manager, he is responsible for setting the direction of Emerson's global security solutions business including establishing product and service roadmaps and providing sales support. Janouskovec received a Bachelor of Science from Appalachian State University majoring in Political Science and minoring in Business Administration, a master’s from Appalachian State in Public Administration and is a certified Global Industrial Cybersecurity Professional.