Recent Breaches
Breaches
View All →
Energy

Physical isolation for transmission, distribution and substation control

Electricity networks now stretch from corporate trading systems down to IEC 61850 protection inside the substation. When those paths converge, a single compromise can move from an office to a breaker. Firevault Control puts a real boundary at every step.

Back to Utilities
Control

Energy

When EMS, SCADA and substation networks are reachable from corporate or vendor estates, every software vulnerability becomes a candidate for a switching incident.

100%

Substation path isolation from corporate IT

Zero

Persistent OEM access into protection systems

6

Control modules deployed per electricity zone

Full

Evidence for NIS2, NERC CIP and Ofgem

The Challenge

Electricity control networks are converging faster than they can be defended.

IT, OT and market convergence

Trading, settlement and ENCC interfaces sit close to the same control rooms that operate the grid. Attackers traverse those interfaces to reach EMS and SCADA.

Legacy protection alongside IEC 61850

Substations carry a mix of legacy RTUs and modern IEC 61850 IEDs. They cannot all be patched on the same cycle without risking operational disruption.

Distributed energy resources

Inverter-based resources and DER orchestration multiply the number of remotely reachable controllers across the distribution grid.

The Scenario

Scenario: Substation vendor remote access compromise

Attackers compromise a protection vendor laptop with persistent VPN access into a transmission substation engineering network. From there they pivot through a shared jump server into the control room SCADA. Operators lose visibility across two grid supply points for several hours. Restoration is delayed because protection setting backups are stored on the same domain that was compromised. With Firevault Control, vendor access opens only on a scheduled, authorised window. The substation fabric is physically separate from the control room fabric. Verified baselines for protection settings are held on infrastructure with no live network path to production and require multi-party authorisation to release. The pivot path does not exist.

"We assumed our substations were isolated. They were, until a vendor laptop was trusted on both sides at the same time."

Module deployment · electricity network

Where each Control module is deployed across generation, transmission and distribution.

Electricity operators run a Purdue stack from the corporate estate down to substation protection. Control puts a real boundary between the office, the operations centre and the substations so a problem in one place does not become a blackout in another.

Grounded in NIST SP 800-82 Rev. 3, IEC 62443-3-2, IEC 61850, NERC CIP-005 and NCSC CAF.

L5

Cloud / Internet

External

Market interfaces
Cloud services

Settlement, ENCC and market data.

Settlement, ENCC and market data.

FirebreakValidate

Market and cloud traffic terminates at the perimeter.

L4

Enterprise

IT

SOC
SIEM
Active Directory
Trading systems

Office, trading and corporate identity.

Office, trading and corporate identity.

IsolateFirebreak

Office estate cannot reach the industrial DMZ on its own.

L3.5

Industrial DMZ

DMZ · trust boundary

Jump server
Patch & AV
ICCP gateway

Brokered exchange. No straight-through paths into operations.

Brokered exchange. No straight-through paths into operations.

RelayValidateExecute

ICCP and engineering traffic crosses on scheduled, approved routes.

L3

Control centre systems

OT

EMS / DMS
Historian
DERMS

Energy management, distribution management, DER orchestration.

Energy management, distribution management, DER orchestration.

IsolateLock

Control centre and SCADA on separate fabrics.

L2

Supervisory control

OT

SCADA
HMI
Substation gateway

Control room view of the grid.

Control room view of the grid.

IsolateExecute

Switching and protection changes need approval before they reach the substation.

L1

Substation control

Field

IEC 61850 IEDs
Protection relays
RTUs

Bay control and protection inside the substation.

Bay control and protection inside the substation.

Lock

Bay devices tie to named protection engineers.

L0

Primary plant

Field

Switchgear
Transformers
Sensors
OSS

Crown jewels

Off-network

Detail callout · A

Offline Secure Storage

Protection settings, substation configurations, EMS baselines and the recovery sets you need to restart the grid from a known-good state.

Offline by design · secure by default

Modules & symbols

FirebreakPhysical sever
ValidateIntegrity check
IsolateZone boundary
RelayTime-bound path
ExecuteApproved action
LockNamed access
DMZ boundaryTrust transition
OSS calloutOff-network detail

Where each module is deployed, and what it does there.

One row per module. Placement on the network, then plain-English purpose at that point.

  1. Isolate

    At every Purdue boundary

    Office, ICCP, control centre and substation fabrics are physically separate. A compromise on the corporate side cannot reach protection.

  2. Firebreak

    On the L5 to L4 link and the L4 to L3.5 link

    A real off switch on the public and office boundaries when an incident is in flight.

  3. Validate

    On the L5 to L4 link and inside the L3.5 DMZ

    ICCP and engineering traffic is checked for origin, integrity and authority before it reaches operations.

  4. Relay

    Inside the L3.5 DMZ

    Cross-domain data moves on scheduled routes. Nothing streams unattended into the control centre.

  5. Execute

    Inside the L3.5 DMZ and on the L2 to L1 link

    Firmware, settings and switching actions hold until the right authority signs them off.

  6. Lock

    On the L3 to L2 link and the L1 to L0 link

    The closer you get to primary plant, the tighter the named access. Standing access into substations is the exception.

Featured In

TechRadar ProSecurity BuyerYahoo FinanceSecurityBriefChannel Insider

Key Capabilities

Sovereign grid data

Grid control and protection data remains within the agreed jurisdiction in carefully selected Firevault Bunkers.

Multi-party control

Critical switching and protection changes require sign-off from both control room and security teams.

Regulatory evidence

Continuous compliance evidence for NIS2, NERC CIP and Ofgem cyber expectations.

Out-of-band management

Cellular and dedicated paths keep the control plane reachable when primary networks are compromised.

Tamper-proof logging

Every access, configuration change and switching command lands in immutable logs on physically separate infrastructure.

Verified configuration baselines

Verified baselines of EMS, IED and SCADA configuration enable a known-good restore of control-plane state.

Demo to Live

Adoption Guide

Step 1

Network assessment

Map every path between corporate IT, ICCP, EMS, SCADA and substation networks to identify convergence and persistent vendor connections.

Step 2

Zone architecture design

Design physically separated zones aligned to your control rooms and substation estate, with Control modules at each boundary.

Step 3

Non-production pilot

Deploy in a test environment mirroring an EMS and substation pair with full zone separation, multi-party authorisation and compliance logging.

Step 4

Operational deployment

Full deployment across the grid estate with verified configuration baselines, continuous compliance evidence and 24/7 out-of-band management.

Step 1

Network assessment

Map every path between corporate IT, ICCP, EMS, SCADA and substation networks to identify convergence and persistent vendor connections.

Step 2

Zone architecture design

Design physically separated zones aligned to your control rooms and substation estate, with Control modules at each boundary.

Step 3

Non-production pilot

Deploy in a test environment mirroring an EMS and substation pair with full zone separation, multi-party authorisation and compliance logging.

Step 4

Operational deployment

Full deployment across the grid estate with verified configuration baselines, continuous compliance evidence and 24/7 out-of-band management.

Questions

Frequently Asked

Energy blueprint - PoC

Speak to the team to organise a PoC

Walk through your blueprint with the Firevault team and scope a proof of concept on your estate. 30 minutes, no sales pitch.

    Firevault

    Firevault is Offline Secure Storage. Hardware you own, physically disconnected by default, with KYC-verified access. Ransomware-proof by design, not by patch.

    © 2026 Firevault Limited. Disconnect to Protect®