Skip to content
Acasă » General Interest » Cybersecurity solutions should provide the full picture of the infrastructure, not isolated alerts

Cybersecurity solutions should provide the full picture of the infrastructure, not isolated alerts

    26 August 2026
    Digitalization
    Gabriel Avăcăriței

    For an operator of critical infrastructure, detecting a cyber incident is only the beginning of the problem. The more important questions are whether the attack has changed the behaviour of the physical process, which equipment has been affected, what commands have travelled through the system and how quickly the operator can contain the incident and restore normal operation.

    The distinction between cyber detection and operational impact was at the centre of an Enevo workshop held during the CIGRE Paris Session 2026. Using the architecture of an electricity substation and a simulated attack, the discussion focused on a key issue for operators: security tools can generate hundreds of alerts, but an industrial organisation ultimately needs to understand the attack in the context of the infrastructure it is trying to protect. The CIGRE Paris Session is taking place from August 23 to 28 at the Palais des Congrès in Paris.

    Mircea Stremțan, Sales Director SentryOT, Enevo Group, described succinctly what early warning means in operational technology: “you have a cyber event that is propagating through the network and has this operational impact.” A suspicious IP address, an unusual login or malware is not the final consequence. In an energy system, the consequence may be a changed configuration, an unauthorised control command, a disconnected asset or an interruption of the physical process.

    The simulated attack started with a device physically connected to a switch inside a substation, continued with scanning, attempts to use known credentials and activity on control equipment, and eventually reached an engineering workstation. The critical issue shifted from cyber alerts to “Has my infrastructure’s behaviour changed in any way? Was the attack successful? Were there any commands that propagated to the infrastructure and disrupted its operations?”

    In the scenario, unauthorised commands ultimately reached primary equipment. The example changes the perspective on cyber resilience: a security operations centre may establish that an attack exists, but the operator needs to see the path from initial access through the network to the operational consequence. The closer a cyber incident gets to the physical process, the less useful isolated alerts become.

     

    Making the cybersecurity budget more efficient

    The same logic changes the economic discussion around cybersecurity. Alexandru Suditu, General Manager SentryOT, brought the discussion to the perspective of the person approving the expenditure: “I’m the CFO and I have a very tight budget, fixed resources and I need to invest in cybersecurity. Why am I doing it?”

    The answer cannot be to accumulate security products for their own sake. Cybersecurity expenditure has to support an operational objective: reduce risk, limit financial impact, support compliance, speed up incident response and bring systems back online. The challenge is to make the cybersecurity budget more efficient so that it supports both recovery and compliance with regulatory reporting requirements.

    Energy companies may already have firewalls, endpoint detection, network monitoring and logs from control equipment, but they still need to gather evidence during a crisis. Integration becomes valuable when it reduces the time required to understand what happened and what must be done next.

     

    First, know your infrastructure

    The workshop repeatedly returned to the idea of asset visibility. “Cyber resilience means understanding what your infrastructure is, what you are monitoring and, from the outset, what the potential vulnerabilities are,” one of the speakers said.

    An asset inventory in this context is more than an IT register. In a substation, the operator may need visibility over primary equipment, automation and telecontrol systems, RTUs, SCADA-related equipment, process switches, engineering workstations and the communications between them. Topology matters because two devices with the same technical vulnerability do not necessarily carry the same operational risk.

    A useful picture of the infrastructure therefore includes what equipment exists, where it is located, how it communicates, what systems can reach it, which vulnerabilities are known and what role the equipment actually plays in the physical process. The information supports prevention, but becomes equally important during an incident, when investigators need to understand how an attacker can move through the system.

     

    Monitoring and response, not the illusion of passive protection

    The discussion challenged a model in which cybersecurity is treated mainly as a set of barriers around an industrial system. Firewalls, endpoint protection, data diodes and other defensive tools remain necessary, but their presence cannot be treated as a guarantee that the infrastructure is safe.

    Alexandru Suditu referred to two myths. The first is that an industrial network is physically isolated. Operational environments still have contractors, maintenance work, portable equipment and devices that at some point interact with the protected infrastructure. The second is that antivirus or another endpoint product provides sufficient protection. The conclusion was concise: “you always need to monitor.” The important extension is the ability to react as soon as suspicious behaviour appears. Preventive controls can reduce the attack surface, but resilience depends on what the organisation can see and do after a control has been bypassed.

    The OT (operational technology) environment also complicates automatic intervention. A cybersecurity system cannot, by default, block a suspicious communication flow without understanding the industrial process behind it. The same path may carry a control or safety action needed to protect the installation. Response therefore requires operational context and, in many cases, a qualified human decision rather than an automatic cyber response.

     

    Prioritise vulnerabilities by consequence, not only by score

    Known vulnerabilities are another area where operational context matters. Public databases can show which vulnerabilities are associated with an asset, but generic severity does not necessarily identify the most important risk inside a particular plant or grid installation.

    The experts argued for assessing a vulnerability together with the role of the equipment, network topology, the layers of security an attacker would have to bypass and the potential operational impact. A vulnerability with the highest generic criticality may sit on an asset with relatively lower operational consequences, while a lower-ranked vulnerability may expose equipment whose failure would have a much larger impact on operations.

    Vulnerability management therefore becomes a risk-allocation exercise. For management, the practical question is not simply which vulnerabilities have the highest score, but where limited cybersecurity resources can deliver the greatest reduction in operational and financial exposure.

     

    Cybersecurity, network and operations teams need to work from the same picture

    Once an incident occurs, no single department has all the knowledge required to resolve it. The workshop identified the need to bring together network and telecommunications specialists, operational teams responsible for SCADA, protection and control systems, and cybersecurity personnel investigating the incident.

    Each group needs different information. Networking specialists need to understand how the attacker communicated through switches, firewalls and security zones. The cybersecurity team needs indicators of compromise, affected systems and evidence for the investigation. The operational team needs to know which devices were acted upon, which commands were issued and whether physical intervention is necessary.

    The common requirement is situational awareness. Incident response, in the terms used during the discussion, is substantially about “facilitating communication between all the stakeholders and quickly gaining an overview of the situation.” A shared picture helps specialists decide what to isolate, what to inspect and what to restore first.

    The objective is not to promise that we can prevent every attack. It is to know the infrastructure well enough to recognise abnormal behaviour, connect the digital event to its operational consequence, bring the right teams into the response and restore the physical process before a cyber incident turns into a prolonged operational crisis.

     

    Article distributed with the support of Schneider Electric

    About Schneider Electric

    Schneider Electric creates impact by maximising the value of energy and resources, connecting progress with sustainability. We are a global leader in electrification, automation and digitalization, providing AI-driven IoT solutions for smart industries, infrastructure, data centres and buildings.

    With 150,000 employees in over 100 countries we promote diversity and innovation. Schneider Electric România, with 27 years in business and more than 300 employees, runs operations in Armenia and Moldova and provides support in 17 languages for 26 countries through the Bucharest Hub.

    Autor: Gabriel Avăcăriței

    Gabriel Avăcăriței is a journalist and communicator with over a decade of experience in Romania’s energy sector. Since 2013, he has been Editor-in-Chief of Energynomics, the country’s leading B2B communication platform for the energy industry. He moderates all Energynomics conferences and debates, bringing clarity and depth to discussions among policymakers, business leaders, and innovators. Under his leadership, Energynomics has evolved into the most comprehensive editorial project in Romania’s energy field, combining a news website, quarterly magazine, and a wide portfolio of industry events that inform and connect the energy community.

    Leave a Reply

    Your email address will not be published. Required fields are marked *