Content
Services
Industries
Talk to an expert

SOC for the energy sector: how to monitor IT and OT

· 7 min read · Network Secure

At an energy company, the SOC watches two worlds at once: the corporate network, with email, ERP and remote access, and the operational network, home to the systems that run power plants, substations and feeders. In that second world, the priority is not protecting data but keeping the physical process running safely. That changes what the SOC collects, how it detects and how it responds.

Why generation, transmission and distribution are a special case

NIST SP 800-82 Rev. 3, the operational technology (OT) security guide NIST published in 2023, sums up the difference: in IT, the classic order of priority is confidentiality, integrity and availability; in OT, availability and human safety come first, because a control system that is unavailable or tampered with has physical effects. In the power sector, that means load shedding, equipment damage or risk to field crews.

Three characteristics make the environment different for whoever is monitoring it:

  • Long-lived assets. Protection relays, RTUs, PLCs and SCADA workstations run for many years, with firmware that does not always accept patches or agents.
  • Industrial protocols. Modbus, DNP3, IEC 60870-5-104 and IEC 61850 were designed for reliability and real-time performance, not authentication. In many deployments, a valid command is executed without checking who sent it.
  • Geographic spread. Scattered substations and plants depend on telecom links and on remote access by vendors.

IT/OT convergence: the path attackers take

Operational networks are no longer islands: metering and maintenance data flow between the control center, the ERP and the cloud. A phishing email on the corporate network or a leaked vendor credential can become a bridge to supervisory control. It is the same risk described on Network Secure's industrial and OT cybersecurity page.

The SOC's first task, then, is to understand the separation between the corporate and operational networks. The IEC 62443 series organizes this into zones (groups of assets with similar requirements) and conduits (the controlled paths between them), the subject of part 3-2. For the SOC, every conduit is a privileged observation point: everything that crosses from IT to OT should be expected, authorized and logged.

Passive visibility: seeing without touching

In IT, the SOC gains visibility through EDR agents and active scanning. In OT, both practices call for caution: scans can freeze sensitive equipment, and many vendors do not support third-party software on their systems. NIST SP 800-82 advises care with active techniques and a preference for passive methods.

The alternative is passive network monitoring: copies of traffic taken from a mirrored port (SPAN) or a TAP on operational network switches, analyzed by sensors that understand industrial protocols. With that, the SOC can:

  • Build the inventory. Learn which assets talk to each other, over which protocol and how often, without sending a single packet.
  • Establish a baseline. Control networks are predictable, and deviations from the pattern are a strong signal.
  • Read the content of commands. Tell a value read apart from a write, an operating mode change or a program download to a PLC.

Passive is not everything. SCADA servers, engineering workstations and jump servers run ordinary operating systems and should send logs to the SOC like any critical server. The network sensor covers what cannot take an agent.

Detection based on MITRE ATT&CK for ICS

MITRE ATT&CK for ICS is the public matrix of tactics and techniques observed in attacks on industrial control systems. It includes tactics that do not exist in the enterprise matrix, such as Inhibit Response Function (preventing protections and alarms from working) and Impair Process Control (manipulating control of the process), along with physical impact. Using this matrix helps the SOC design use cases that make sense for energy:

  • Unusual remote access. A vendor session outside the agreed window, from an unusual source, or one that bypasses the jump server.
  • Unauthorized command. A write to a relay or PLC coming from a host that normally only reads data, or a breaker-open command issued from outside the control center.
  • Logic or mode change. A program download, a switch to program mode or a change to protection settings with no matching work order.

The value lies in correlation: the attacker who triggers a compromised-credential alert on the corporate network may show up hours later on the engineering workstation. Whoever sees only one side sees two isolated events; whoever correlates sees the attack. Mapping coverage against the matrix also helps measure SOC maturity.

Response that cannot take down operations

In IT, isolating an endpoint is a fast, safe response. In OT, isolating a SCADA workstation or cutting a substation link can cause exactly the effect the attacker wanted: loss of visibility or control. That is why response in a power environment follows its own rules:

  1. Playbooks written with operations engineering. Every containment action in OT needs an owner, preconditions and a known effect on the process.
  2. Contain at the boundary first. Blocking the IT/OT conduit, ending remote sessions and disabling accounts is usually safer than touching control assets.
  3. Decide on degraded operation. Know in advance whether manual or local operation is possible, and for how long.
  4. Validated recovery. Restore controller configurations and logic from known-good copies, preserving evidence first, as part of the resilience plan.

The SOC detects, investigates and recommends; shutting anything down in operations remains the decision of whoever is accountable for the power system. The incident response plan must make this split clear before the incident, not during it.

What regulation requires

In Brazil, ANEEL Normative Resolution No. 964/2021, in force since July 1, 2022, sets the guidelines and minimum content of the cybersecurity policy for electric sector agents. It applies to concessionaires, permit holders and authorized operators of electric power services or facilities, and to the entities responsible for system operation, energy trading or the management of sector charge funds. Among the points that relate directly to the SOC:

  • Ability to prevent, detect and respond. The policy must set objectives to that end and mechanisms to keep incidents on the corporate network or the facilities network from affecting operations.
  • Notification. Higher-impact incidents that substantially affect facilities, operations, services to users or data must be reported to the designated sector coordination team as soon as the agent becomes aware of them, with an analysis of cause, impact and mitigation actions.
  • Maturity and testing. Annual application of at least one cybersecurity maturity model, and scenario simulations to test response capability and time.

Beyond the resolution, ONS, Brazil's national grid operator, maintains an operational routine with minimum cybersecurity controls for the environment that connects to the operation of the interconnected system. For the "how", the technical references are the ISA/IEC 62443 series and NIST SP 800-82 Rev. 3, with governance organizing the evidence.

Frequently asked questions

Does the SOC need to sit inside the operational network?

No. Passive sensors sit in the operational network and send data over controlled paths. The SOC analyzes without having command access to control systems.

Can the same SIEM used for IT also cover OT?

Yes, and it is desirable for correlating both sides. What changes are the sources, the use cases (based on ATT&CK for ICS) and the response playbooks.

Does ANEEL Resolution 964/2021 require a SOC?

Not in those words. It requires the ability to prevent, detect and respond to incidents and to report the higher-impact ones. Continuous monitoring is one of the most direct ways to meet those points.

Can the SOC shut down operational equipment on its own?

It should not. Actions that affect the physical process are decided by operations, based on agreed playbooks. The SOC acts at the boundary and on accounts.

Sources consulted: ANEEL Normative Resolution No. 964 of December 14, 2021, published in Brazil's Official Gazette (Diário Oficial da União) on 12/22/2021 (arts. 1, 4, 6 and 11); NIST SP 800-82 Rev. 3, Guide to Operational Technology (OT) Security (2023); ISA/IEC 62443 series, especially part 3-2; MITRE ATT&CK for ICS. This article is educational, is not a legal opinion on regulatory obligations and does not replace a technical assessment of each agent's environment.

Official references

Read next