The Five ICS Cybersecurity Critical Controls and the Electric Sector, published by SANS Institute in March 2024, applies five ICS-specific cybersecurity controls to the unique risks facing power grid generation, transmission, and distribution operations. The paper draws on findings from the SANS 2023 ICS/OT Cybersecurity Survey and examines real-world attack frameworks affecting the electric sector, including Pipedream and CrashOverride.
Key findings:
- The energy sector is the most likely target for a cyberattack that could impact the safety and reliability of operations, according to the referenced SANS 2023 ICS/OT Cybersecurity Survey
- Nearly 40% of ICS environment compromises originate from the IT business network, making perimeter defense between IT and ICS a top priority
- Pipedream (also known as Incontroller) is a scalable ICS-specific attack framework capable of affecting a wide variety of vendor programmable logic controllers (PLCs)
- Pipedream can abuse legitimate ICS network protocols, including OPC-UA, Modbus, and proprietary control protocols, without deploying traditional malware
- The 2016 CrashOverride (Industroyer) attack caused a blackout at a transmission-level substation by abusing the IEC-104 protocol to send repetitive disconnect breaker commands
- Applying standard IT incident remediation directly to ICS environments can produce ineffective or disastrous results, per US Department of Homeland Security guidance
- An ICS DMZ, also referred to as level 3.5 in the Purdue Model, is identified as a must-have buffer between the internal industrial network and external corporate or internet-facing systems
- Multifactor authentication is required wherever feasible for remote access from any IT network, the internet, or vendor support sites into ICS environments
- The five ICS Cybersecurity Critical Controls are: an ICS-specific incident response plan, defensible control system network architecture, ICS network visibility and monitoring, secure remote access, and risk-based vulnerability management
The paper's central argument is that IT and ICS security cannot be treated as interchangeable disciplines: the two environments differ in mission, risk surface, and consequence, with ICS incidents carrying the potential for physical damage and loss of life rather than just data loss. Applying the five controls with engineering input, rather than copying IT security practices wholesale, is presented as the path to both compliance and genuine operational safety in electric power environments.
This paper is a technical guidance document rather than a survey, drawing its evidentiary base from the SANS 2023 ICS/OT Cybersecurity Survey, publicly documented attack frameworks (Pipedream, CrashOverride), and established engineering standards including the Purdue Model.