RISKORIA ADVISING & PROFESSIONAL SERVICES D.O.O. · ZAGREB+385 97 737 1345INFO@RISKORIA.EU

Energy

Electricity, gas, oil and heating rely on operational technology, so most of the risk sits in industrial systems and with suppliers.

What the Act requires of this sector

Energy is the first sector of Annex I of the Act. The competent authority for cyber security requirements is the central state authority for cyber security, that is the Security and Intelligence Agency (SOA), and the competent CSIRT is the national cyber security centre (NCSC-HR).

The category follows size: entities above the ceilings for medium-sized enterprises are essential, and medium-sized ones important. In addition, the authority may classify an entity regardless of size under the special criteria of Article 11, if it is the sole provider in an area for instance.

The sector’s particularity is operational technology. For measures 5 and 6, Annex II states expressly which sub-measures apply to it without restriction and which depend on a risk assessment, so that line has to be drawn in writing rather than verbally.

Where this sector usually gets stuck

Separating office and operational networksThe most common finding is that the boundary exists on paper but not in the configuration.
Vendor remote access to equipmentAccess without records, with permanent accounts and shared passwords.
Legacy industrial systemsSystems that cannot be patched require compensating controls, not excuses.
Operational continuityA plan that has not been rehearsed rarely survives the first hour.

What we do for you

01A readiness review across the thirteen measures02A review of the office and operational network boundary03Rules for vendor remote access04A risk register for operations and the business05A continuity plan and an exercise06Preparing the evidence file for the audit

Who from the sector falls in scope

WHOCATEGORYNOTE
Electricity: generation, transmission, distribution, supplyEssential or importantBy size, with possible classification under Article 11
Gas: transmission, distribution, storage, supplyEssential or importantBy size
Oil and oil products: transport, storage, productionEssential or importantBy size
District heating and coolingEssential or importantBy size
Hydrogen: production, storage, transmissionEssential or importantBy size

The category is set by the competent authority and the level of measures by the national risk assessment; both are explained in the overview of the Act.

CASE FROM PRACTICE · DENMARK, MAY 2023

Coordinated attack on 22 energy companies

The attacks came in two waves and eleven companies were directly compromised. The first wave exploited a then unknown firewall vulnerability. A risk assessment that covers only the office network cannot see this scenario; SCADA systems, controllers and telemetry have to be in scope.

SOURCE: SektorCERT, the Danish CSIRT for critical infrastructure, incident report, 2023.

Frequently asked questions

The questions energy companies ask first, mostly about operational technology and suppliers.

Does the law apply to smaller distributors and heating utilities?

It does. In energy, smaller entities are often above the ceiling for medium-sized enterprises, and the competent authority may classify them regardless of size under Article 11.

Do industrial control systems have to be in scope?

They do. A risk assessment covering only the office network misses most of the risk. SCADA systems, controllers and telemetry go into the asset register like everything else.

How do we handle remote access by equipment suppliers?

Named accounts instead of shared ones, access opened on request and closed after the job, and a record of every session. It is also one of the most common audit findings.

What if a system cannot be patched without vendor approval?

Compensating measures apply, together with a written justification of why patching is not possible. A missing patch is not in itself a finding; a missing justification is.

How often is the continuity plan tested?

At least once a year, and by exercise rather than by reading. The exercise minutes are the evidence for the business continuity measure.

Do all measures apply to operational technology?

Not in full. For measure 5, Annex II states that sub-measure 5.4 applies to OT subject to a risk assessment, while the rest apply in full. For measure 6, sub-measures 6.1, 6.3 and 6.5 apply in full, while 6.2 and 6.4 depend on a further assessment.

What if a system cannot be taken down for a change?

Then a change window is planned and, until it opens, a compensating measure applies. What matters is that the deferral has a deadline, a justification and an owner, because without those it looks like a failing in an audit.

Do sectoral rules apply alongside the Act?

They do. Alongside the Cybersecurity Act, energy also has critical infrastructure legislation and sectoral requirements, so the first step is to separate what falls under which, so the same work is not done twice.

Related pages

The pages that set out in full what energy has to show in measures and evidence.

Let us look at where your network boundary sits.

Half an hour, no obligation. We look at where your office network ends and the operational network begins.

Book a callINFO@RISKORIA.EU · +385 97 737 1345