Skip to content
StrikeCyberStrikeCyber
Research

Cyber Security for Energy, Utilities and Industrial Operators

June 6, 2026·4 min readPenetration TestingIndustry Briefings

Industrial and energy operators face a specific version of the security problem. A cyber incident does not merely expose data; it can halt production, damage equipment or create a safety hazard. The systems involved were designed for reliability and longevity rather than for security, and they cannot be replaced on a security timeline.

Who Is Attacking and Why

Ransomware crews target industrial operators because downtime is immediately and quantifiably expensive, which makes rapid payment more likely. The 2021 pipeline incident that disrupted fuel supply across the eastern United States, and the meat processing incident the same year, both established the pattern publicly.

Notably, in several major cases the operational systems themselves were not encrypted. The corporate environment was compromised, and production was halted as a precaution because the operator could not establish whether control systems were affected. That distinction matters: an operator does not need its controllers compromised to lose production. It needs to be unable to prove they were not.

State-aligned actors target critical infrastructure for strategic positioning. CISA has issued repeated advisories describing intrusions that appear to be establishing presence for potential future disruption rather than pursuing immediate gain, which is a materially different threat model and requires detection tuned for patience rather than for smash-and-grab.

The Regulatory Picture

NERC CIP applies to the bulk electric system and is genuinely mandatory, with audits and financial penalties. It is among the few US cybersecurity regimes with real enforcement teeth, covering asset identification, electronic security perimeters, personnel screening, incident reporting and recovery planning.

TSA security directives apply to designated pipeline and rail operators, issued following the 2021 pipeline incident and revised since. They require cybersecurity implementation plans, assessment programs and incident reporting.

Water systems carry requirements under the America's Water Infrastructure Act, including risk and resilience assessments and emergency response plans.

Most other industrial operators are not subject to mandatory cybersecurity regulation and rely on NIST CSF, IEC 62443 or customer requirements. Manufacturing in particular is largely unregulated, which does not make it less targeted.

The Boundary Problem

The most consistent finding across industrial assessments is that the separation between corporate IT and the control environment is considerably more permeable than the operator believes.

Operators frequently describe their control network as air-gapped or tightly segmented, sincerely and on the basis of a network diagram that was accurate when it was drawn. Assessment finds vendor remote access appliances installed for a commissioning project and never removed, data historians with an interface in each network and routing enabled, engineering workstations connected to corporate wireless for updates, and physical uplinks from a facility expansion nobody documented.

Every one of those was added by a competent person solving a real problem. Nobody assembled them into a single picture. We have written up a representative case in the air gap that was not.

The other recurring finding is credential sharing across the boundary: engineering accounts that are also valid in the corporate domain, which connects an ordinary phishing compromise directly to production control.

Assessing Without Risking Production

This is the part operators are right to be cautious about, and the caution should shape the method rather than prevent the assessment.

Corporate IT assessed conventionally, because that is where intrusions begin and where standard techniques are appropriate.

Passive assessment as the default in the OT environment. Traffic analysis and configuration review establish what is present, how it is connected and what is exposed, without sending anything unexpected to a controller.

Active testing only with control engineers present, outside operational windows, with a rollback plan and an agreed stop condition. Some tests are simply not appropriate against equipment running a live process, and a provider who does not say so should be declined.

The boundary tested specifically and thoroughly, because that is where the finding that matters usually is.

Industrial protocols understood rather than scanned. Many control protocols provide no authentication by design. That is expected and is not itself the finding. The finding is what can reach them.

What Actually Reduces Risk

The remediation that follows these assessments is structural.

Reduce the number of crossing points between corporate and control environments to one, properly instrumented with multi-factor authentication and session recording. Most of the risk in these environments comes from the number of crossings rather than the strength of any individual control.

Separate credentials completely, so a corporate compromise yields nothing operationally.

Move historians and reporting to a one-way data flow, so process data leaves without anything entering.

Segment inside the control environment so unauthenticated protocols are reachable only from systems that legitimately need them.

And validate the network diagram against discovered reality on a cadence, because that single practice is what would have caught the accumulated connectivity years earlier.

To discuss an assessment of your IT and OT environment, get in touch.

Frequently asked questions

What regulations apply to US energy and industrial operators?

It depends on the sector. NERC CIP applies to the bulk electric system with mandatory, auditable requirements and financial penalties. TSA security directives apply to designated pipeline and rail operators. Water systems carry requirements under the America's Water Infrastructure Act. Most other industrial operators are unregulated for cybersecurity and rely on frameworks like NIST CSF and IEC 62443.

Is it safe to test an OT environment?

Yes, when scoped responsibly. Active scanning of legacy control equipment carries genuine operational risk because older controllers can respond badly to unexpected traffic and may be controlling a physical process. Responsible assessment uses passive traffic analysis and configuration review as the default, with active testing only alongside control engineers, outside operational windows, and with a rollback plan.

What is the most common finding in industrial assessments?

Undocumented connectivity between corporate IT and the control environment. Operators frequently describe their control network as air-gapped or tightly segmented, and assessment finds multiple paths that were each added for a legitimate reason and never assembled into a single picture.

What is IEC 62443?

An international standard series for industrial automation and control system security, covering the asset owner, the system integrator and the product supplier. It introduces zones and conduits as a way to reason about segmentation and security levels. It is widely used as a voluntary framework where no mandatory regime applies, and it is more specific to OT than NIST CSF.

Why do attackers target industrial operators?

Ransomware crews target them because production downtime creates immediate and quantifiable loss, which makes rapid payment more likely. State-aligned actors target them because critical infrastructure is a strategic objective, and CISA has issued repeated advisories about intrusions positioned for disruption rather than for immediate gain.

Ready to take the offensive?

StrikeCyber specializes in penetration testing and red teaming engagements that deliver actionable findings. Connect with us for a free consultation.

No obligation, no sales pressure. A senior operator replies within one business day.

(877) 657-8496Free Consultation