Dispersion is the defining constraint
A manufacturing plant concentrates its risk inside a fence. A distribution utility spreads it across a service territory, in cabinets that are unstaffed for weeks and reachable over links that terminate in places nobody visits routinely.
This changes the security problem in two ways. Physical access assumptions that hold inside a plant do not hold at a pole-mounted cabinet or a rural substation. And monitoring has to work over constrained links, which is why sensors buffer locally and forward compactly rather than assuming continuous connectivity back to a central platform.
It also changes what lateral movement looks like. In a plant an attacker moves between cells. In a utility they move between sites, and the telemetry network that makes the utility operable is the same network that makes that movement possible.
The protocol estate
Energy uses a broader protocol set than most sectors, and the differences between them matter operationally.
IEC 61850 governs substation automation, with MMS carrying configuration and control operations and GOOSE carrying time-critical protection messages between intelligent electronic devices. GOOSE in particular operates on millisecond timescales, which is why any security control that adds latency to it is unacceptable and why passive observation is the only viable approach.
DNP3 and IEC 60870-5-104 carry supervisory telemetry across wide areas, connecting dispersed sites back to a control centre. Both predate authentication as a design consideration. Secure variants exist; the installed base largely does not run them.
Modbus persists on auxiliary and balance-of-plant equipment, and OPC UA appears at boundaries where operational data feeds analytics or market systems.
- IEC 61850 MMS, for substation configuration and control
- IEC 61850 GOOSE, for millisecond protection messaging between IEDs
- DNP3, for wide-area supervisory telemetry
- IEC 60870-5-104, widely used outside North America for the same role
- Modbus, on auxiliary and balance-of-plant equipment
- OPC UA, at analytics and market-system boundaries
Protection systems and the cost of a false action
Intelligent electronic devices in a substation exist to trip breakers when conditions demand it, within milliseconds. Their correct operation is what prevents equipment damage and keeps people safe.
That makes them a high-consequence target and, equally, a place where an over-eager security control causes the harm it was meant to prevent. Signal never actively polls protection equipment. It observes the traffic, tracks configuration and firmware against baselines, and escalates when settings change outside an authorised window, without ever transmitting to the device.
NERC CIP as continuous evidence
For bulk electric system operators in North America, NERC CIP is a regulatory obligation with audit consequences rather than a framework to aspire to. The reporting burden is substantial and traditionally reconstructed from several systems shortly before an audit window.
A monitoring platform changes that for the controls that rest on operational data. Asset categorisation depends on a complete and current inventory. Electronic security perimeter requirements depend on knowing what actually crosses a boundary. Configuration change management depends on a baseline and a record of drift against it. Each of those is a by-product of continuous monitoring rather than a separate collection exercise.
Signal reports continuous evidence against NERC CIP alongside IEC 62443-3-3, NIST SP 800-82r3 and AWWA G430, with each control carrying a score, a status and a drill-through to the underlying data.
Where sensors go in a dispersed estate
Substation coverage generally means a sensor per station on the station bus, which is where IEC 61850 traffic and engineering access are both visible. Control centres warrant their own coverage, since that is where supervisory traffic converges and where an intrusion has the widest reach.
The links between them are the highest-value observation points, because crossing between sites is precisely what an attacker moving through the estate has to do, and telemetry links carry far lower volumes than a station bus, which makes anomalies more visible against the baseline.
Generation, transmission and distribution differ
Generation looks closest to process manufacturing: a concentrated site, a turbine or boiler control system, a distributed control system, and a defined perimeter. Transmission concentrates on high-voltage substations with sophisticated protection and the strictest regulatory attention. Distribution is the most dispersed and increasingly the most connected, as automation and metering push intelligence towards the edge of the network.
A programme covering all three should not treat them as one environment. The asset population, the protocols, the physical access assumptions and the regulatory scope differ enough that a uniform approach will over-invest in one and under-serve another.
Frequently asked questions
What makes energy OT security different from manufacturing?
Geographic dispersion. A utility runs hundreds of mostly unstaffed sites connected by wide-area telemetry, so physical access assumptions differ, monitoring must tolerate constrained links, and lateral movement means moving between sites rather than between cells.
Can you monitor IEC 61850 GOOSE traffic safely?
Passively, yes. GOOSE operates on millisecond timescales for protection messaging, so nothing that adds latency is acceptable. Observing mirrored traffic imposes no delay because the sensor is not in the path, which is why passive collection is the only viable approach for protection networks.
Are DNP3 and IEC 60870-5-104 secure?
Not inherently. Both were designed for private telemetry links and carry supervisory commands without proving who sent them. Secure variants exist but the installed base largely does not use them, so monitoring the traffic and baselining what each link normally carries is what provides assurance.
How does continuous monitoring help with NERC CIP?
It produces evidence as a by-product of operations for the controls resting on operational data: asset categorisation from a current inventory, electronic security perimeter from observed boundary traffic, and configuration change management from baselines and recorded drift. That replaces reconstruction before an audit with a live record.
Where should sensors go in a substation estate?
One per station on the station bus, where IEC 61850 traffic and engineering access are both visible, plus coverage at control centres where supervisory traffic converges. The telemetry links between sites are the highest-value observation points, because crossing between sites is what lateral movement requires.
Do generation, transmission and distribution need the same approach?
No. Generation resembles process manufacturing with a defined perimeter. Transmission concentrates on high-voltage substations under the strictest regulatory attention. Distribution is the most dispersed and increasingly the most connected. Treating all three identically over-invests in one and under-serves another.
Part of the cluster
OT Cybersecurity
The pillar page for operational technology security.