
Operating reality
You own the plant. You do not always own the control system.
On most units, the turbine control platform and a good share of the packaged equipment sit under an OEM service agreement. Approved configurations, patch baselines, supported software versions and who is permitted to touch what are contractual matters before they are technical ones. A security recommendation that ignores that position is not conservative, it is simply unimplementable, and it costs the program credibility with the plant manager on first reading.
The second constraint is time. Cyber work competes for the same outage that the boiler inspection, the hot gas path and the generator rewind are competing for, against a schedule fixed long in advance and an owner's engineer who will not surrender hours to an activity that cannot state its duration. Anything that cannot be staged, pre-staged or proven offline tends to be deferred to the next major outage, which may be several years away.
Fleets compound both. Combined-cycle, thermal, hydro and, increasingly, renewables and storage sit under one operating company with control vintages spanning decades and no common engineering baseline. What is a routine change on a recently retrofitted unit is a warranty conversation on the one next to it.
So the discipline is consequence, sequencing and contract. Establish what a compromise could actually do to unit availability, decide what is worth an outage hour, and write the specification so the OEM, the owner's engineer and the outage planner can all approve the same document.
On a generating unit the real currency is the outage hour. A recommendation that cannot state its duration will not be bought, however sound it is.
Operational priorities
Four things generation programs have to get right.
These decide whether a station program is executed or carried forward another outage cycle, well before any question of tooling arises.
01 · Work to the outage calendar
The outage is the only realistic change window, and its scope closes long before it opens. Assessment has to finish early enough for remediation to enter the work list as a costed, durationed job, with the parts staged and the method statement written. Anything arriving after the freeze waits for the next cycle.
02 · Design inside the OEM agreement
Turbine control and vendor-supplied packages carry approved configurations and warranty conditions. Controls are specified so they sit around those systems rather than inside them, and anything requiring OEM involvement is identified early enough to be negotiated rather than discovered during the outage.
03 · Separate a trip from a safety event
An unplanned trip is a commercial and reliability consequence. A defeated protective function is a different category altogether. Consequence analysis keeps the two apart, so investment goes to the paths that could reach protection and availability rather than being spread evenly across a flat asset list.
04 · Govern the data leaving the plant
Performance reporting, dispatch signaling and fleet analytics all depend on data crossing out of the plant. That interface is worth designing deliberately, with a defined direction of flow and a named owner, rather than accumulating as a set of historical point-to-point connections nobody has reviewed.
In scope
Five environments we work in.
Safety instrumented systems and turbine protection are out of scope. They are reviewed on paper and by configuration where the operator permits, and are never a cybersecurity testbed.
Unit control and DCS
The distributed control system with its operator stations and controller networks, alarm management, unit start and shutdown sequences, and the interfaces through which the unit is actually run.
On most stations this is where the flat network lives: engineering and operator functions on one segment, and a historian quietly bridging into corporate reporting. We work from DCS configuration, network drawings and passively collected traffic — no active scanning, no polling of controllers, and no change to alarm or sequence logic. Consequence is expressed as what a compromise could do to unit availability and to the ability to start, not as an asset count.
Turbine and OEM systems
Turbine control, excitation and governor platforms and the condition monitoring that usually accompanies them — nearly always under an OEM service agreement carrying an approved configuration and a warranty position.
These are reviewed through documentation, configuration exports and separation evidence. Nothing is interrogated live, and nothing is proposed inside the OEM boundary without the OEM in the conversation. The useful findings are generally about what surrounds the platform in any case: which networks reach it, under which credential, and whether the vendor's remote path is brokered or standing. Where OEM involvement is genuinely required, it is identified early enough to be negotiated rather than discovered during the outage.
Balance of plant
Water treatment, fuel handling and gas conditioning, HRSG and boiler auxiliaries, cooling water, compressed air, emissions monitoring and the electrical auxiliaries — usually a mixture of PLC platforms and vendor skids bought across different projects.
Balance of plant is routinely under-assessed because it is not the unit, and it can still stop the unit. A skid arrives sealed, with its own controller, its own unmanaged switch and a support connection agreed in procurement. Each package is reviewed by configuration and by contract, and zoning is drawn around what the process genuinely depends on rather than around how the cable was run.
Plant network and historian
The plant LAN and its switching, the historian, performance and condition monitoring, and the interface carrying dispatch signaling, market data and corporate reporting off site.
This boundary accumulates. Point-to-point connections were each added for a reason that made sense at the time, each with a different owner, and no review has considered them together. We rebuild the picture from firewall rule sets and routing, establish a stated direction of flow and a named owner for each path, and design a boundary that can be evidenced. Collection is passive throughout, from span or tap points that already exist.
Engineering and vendor access
Engineering workstations, configuration and version control, project archives, jump hosts, and every remote path used by plant engineers, OEM service teams, contractors and specialist analysts.
During an outage this population expands sharply and temporarily, which is exactly when access control is weakest. We inventory each path against the agreement that created it, then design brokered, privileged-managed access that holds through an outage peak rather than only in steady state, with a defined revocation event. Vendor agreements are treated as design constraints, so changes are written to be raised at renewal rather than imposed mid-term.
Related solutions
Where generation engagements usually start.
Each stands alone. Most operators begin on one unit, time the work to land before the next outage freeze, and reuse the result across the fleet.
Questions from this sector
What station and fleet teams ask us first.
Our next major outage is eighteen months away. Is there any point starting now?
That is close to the ideal starting position, not a reason to wait. The work list for that outage closes long before the outage opens, and a costed, durationed job with a method statement and staged parts has to exist before the freeze date to get on it at all. Assessment begun now lands with time to spare.
A good deal of remediation is also not outage work. Access brokering, credential separation, firewall policy, backup and recovery, and monitoring can usually be done while the unit runs, under normal change control.
Our OEM agreement means nobody touches the turbine controller.
We treat that as a design constraint rather than an obstacle to argue with. Turbine control, excitation and governor platforms are reviewed by documentation, configuration exports and separation evidence, and are never interrogated live. Approved configuration and warranty position are recorded as inputs to the design.
In practice most of the exposure sits around the platform rather than inside it — which networks reach it, which credentials are used, and whether the OEM's remote path is brokered or standing. Those can be addressed without opening the agreement at all.
Our fleet spans four control vintages. Whatever you design for one unit will not fit the next.
Correct, if the design is written at platform level. It is written instead at the level of zones, conduits and required outcomes — what must be separated from what, which flows are permitted in which direction, and what evidence each control produces — then applied per platform.
That way a recently retrofitted unit and one awaiting a control upgrade can hold the same stated position by different means, and the fleet reports one standard rather than four.
The OEM already streams condition monitoring data out of our plant. Is that the exposure?
Not by itself. Outbound performance and condition data with a stated direction of flow, a defined dataset and a named owner is a reasonable arrangement, and it usually earns its place commercially.
What is worth examining is whether the same connection is also a return path — whether the appliance that exports data can accept a session inbound, whether it sits in the plant network or in a demilitarized zone, and who can reach the unit through it. That is a question about the interface design, not about the analytics.
We are not a registered asset. What obligation are we actually working to?
Then the reference is an engineering standard rather than a compliance obligation, and that is a workable position. For most unregistered generators the useful pairing is ISA/IEC 62443 with NIST SP 800-82, applied to the scope you choose rather than the scope a regulator assigns.
The practical driver is more often commercial than regulatory: an offtaker, an insurer, a lender or a parent company asking what the station's position is. We write the program so it answers that question in evidence rather than in assertion.
Next step
Start with one unit, ahead of the next outage.
A single representative unit establishes effort, disruption and value, and produces a specification the outage planner can cost and the rest of the fleet can reuse.
- No active scanning — passive collection and configuration review only
- SIS and turbine protection out of scope — reviewed on paper, never interrogated live
- Sequenced to the outage plan — scope closed before the freeze date, not after
- OEM agreements respected — warranty and approved configuration treated as design constraints
- Vendor-independent — specifications written to be tendered competitively
Questions from this sector
What operators in this industry ask first.
What are the OT cybersecurity risks in power generation?
A generating station runs a dense mix of vendor-specific control systems, turbine and boiler controls, safety systems, balance-of-plant packages and a plant historian, most of them supported remotely by their OEMs. The risks that matter are those that could affect unit availability, trip behaviour, or the integrity of protection and safety functions.
How does InnovAKT approach OEM-supported control systems?
By working with the support agreement rather than against it. InnovAKT documents what each OEM connection allows, designs a brokered access path that satisfies the support obligation without granting standing access, and coordinates any change on a vendor-supported system with the vendor so warranty and support remain intact.
Can renewable and distributed generation be secured the same way?
The method carries; the architecture does not. Wind, solar and battery assets are numerous, unstaffed, remotely managed and often supplied with a manufacturer's cloud connection as standard. Their security is an exercise in fleet governance, secure remote access and procurement language more than in plant hardening.