Energy Sector Cyber Security Assessment and Advisory

Yellow circular logo with intertwined abstract shapes next to "Business Continuity Management (BCM).
EASMLens external attack surface management platform logo
NSPM network security policy management logo
PhishLens phishing simulation and awareness logo

Energy sector cyber security advisory helps electricity, gas and liquid fuel organisations understand their cyber maturity, meet the Australian Energy Sector Cyber Security Framework (AESCSF) and SOCI Act obligations, and protect the operational technology that keeps the lights on. Security Solution Consultants (SSC) works with energy utilities, generators, network operators, retailers and distributed energy providers across Australia and New Zealand, from AESCSF self-assessments to SCADA and OT security reviews.

Solar farm, wind turbines and transmission towers at sunset, representing energy sector cyber security in Australia and New Zealand
The energy transition is connecting more of the grid, and widening its attack surface.

Smart grids, distributed energy resources, electric vehicle charging and digital substations are changing how energy is generated and delivered. Every new connection brings efficiency and flexibility, and also new paths for attackers into systems that were never designed to be online. Our job is to help you modernise without increasing systemic risk.

Our energy sector cyber security services

  • AESCSF assessments. Independent or facilitated assessments against AESCSF version 2, scored by Maturity Indicator Level and compared with your target Security Profile.
  • Security Profile gap analysis and uplift. A prioritised roadmap from your current position towards SP-1, SP-2 or SP-3, with effort and cost ranges.
  • SOCI Act and CIRMP advisory. Building and assessing your Critical Infrastructure Risk Management Program and the evidence for your board-approved annual report.
  • SCADA and OT security assessments. Architecture, segmentation, remote access, asset visibility and monitoring of operational technology, aligned with ISA/IEC 62443.
  • OT and IT convergence architecture. Secure designs for industrial DMZs, vendor remote access and data flows between enterprise and control systems.
  • Incident readiness. OT-aware incident response plans and exercises, including SOCI incident reporting timeframes.
  • Board and executive reporting. Clear reporting of maturity, risk and progress for boards that must approve the CIRMP annual report.

AESCSF: maturity indicator levels and security profiles

The AESCSF is the energy sector’s cyber security maturity framework, developed with industry and government and run with the Australian Energy Market Operator (AEMO). Version 2, released in 2023, aligned the framework with the US Cybersecurity Capability Maturity Model (C2M2) version 2.1, added a cyber security architecture domain and refreshed third-party risk management.

ConceptWhat it means
DomainsEleven domains covering areas such as asset, change and configuration management; threat and vulnerability management; risk; identity and access; situational awareness; incident response and continuity; third-party risk; workforce; architecture; program management; and Australian privacy management.
Maturity Indicator Levels (MIL)Each practice sits at a maturity level, from MIL-1 (initiated) through MIL-2 (performed) to MIL-3 (managed), building on the level below.
Security Profiles (SP-1 to SP-3)Target states that bundle practices into a single goal matched to an organisation’s criticality. Higher criticality means a higher target profile.
Criticality assessmentDetermines which Security Profile applies, based on the organisation’s role and impact in the energy system.
AESCSF LiteA simplified version for smaller and lower-criticality participants, including distributed and consumer energy resource providers.

We help you confirm your criticality and target profile, assess each practice with evidence, identify the anti-patterns that hold back maturity, and turn results into a roadmap your board can track. Read our AESCSF compliance guide for Australian energy firms for more detail.

SOCI Act obligations for energy assets

Electricity, gas and liquid fuel assets are among the critical infrastructure asset classes covered by the Security of Critical Infrastructure Act 2018. Depending on the asset, responsible entities may need to:

  • Register asset ownership and operational information
  • Maintain a Critical Infrastructure Risk Management Program covering cyber and information security, personnel, supply chain, and physical security and natural hazards
  • Comply with a recognised cyber security framework under the CIRMP rules, such as the AESCSF at the relevant profile
  • Submit a board-approved annual CIRMP report within 90 days of the end of the Australian financial year
  • Report cyber incidents having a significant impact to the Australian Signals Directorate within 12 hours, and other incidents with a relevant impact within 72 hours

As SOCI compliance consultants, we link your AESCSF assessment and CIRMP so one body of evidence supports both. See also our enterprise risk management and CIRMP advisory and CIRMP enhancements article.

SCADA, ICS and OT security assessment

Open industrial control cabinet with PLCs, network switch and cables, padlocked, representing OT and SCADA security
Operational technology needs security designed for safety and availability first.

Operational technology protects physical processes, so availability and safety come first and change has to be managed carefully. Our OT assessments are designed for that reality. We review documentation and architecture, interview engineers and operators, and use passive techniques where possible rather than active scanning of live control systems.

  • SCADA and control system architecture, zones and conduits
  • Network segmentation between enterprise, DMZ and control networks
  • Remote access for staff and vendors, including multi-factor authentication and session control
  • OT asset inventory, firmware and configuration management
  • Identity and privileged access to engineering workstations and control systems
  • Logging, monitoring and OT-aware detection
  • Backup, recovery and incident response for control systems

Findings are mapped to ISA/IEC 62443, AESCSF practices and your CIRMP, so each recommendation shows which obligation it supports. Our industrial cyber security article explains why uptime alone is no longer the measure of resilience.

Monitoring the grid

Electricity grid control room with a curved video wall showing an abstract network map and operators in silhouette, representing grid monitoring and situational awareness
Situational awareness across IT and OT is essential for early detection.

Visibility is the foundation of resilience. We help energy organisations plan OT-aware monitoring, integrate OT security events with the enterprise security operations centre, centralise log management and align threat intelligence with sector-specific threats, so unusual activity in control environments is seen and acted on quickly.

Identity and access in critical environments

Credential misuse and insecure remote access remain among the most common ways into operational environments. We review role-based access, privileged access management, vendor accounts, multi-factor authentication and access reviews across substations, control rooms and enterprise systems. See our identity and access management advisory.

Securing the energy transition

As Australia and New Zealand add rooftop solar, community batteries, grid-scale storage, electric vehicle charging and smart meters, more control decisions are made by software, often through third-party platforms and cloud services. That creates new dependencies: aggregators that can switch thousands of devices at once, vendors with remote access to many sites, and data flows between market systems and field equipment. We help organisations assess these new dependencies, set security requirements in contracts and designs, and extend their AESCSF and CIRMP coverage to new assets before they go live rather than after.

What you receive

  • A criticality and target Security Profile confirmation
  • An AESCSF assessment with practice-level scores, evidence and anti-patterns
  • An OT and SCADA security assessment report mapped to ISA/IEC 62443
  • A prioritised uplift roadmap towards your target profile, with owners and cost ranges
  • CIRMP evidence and a board briefing to support the annual report
  • Optional ongoing tracking of maturity and actions in GRCLens

Continuous AESCSF tracking with GRCLens

An AESCSF assessment is a snapshot; sustained maturity needs structure. GRCLens, the GRC platform built by SSC, tracks Maturity Indicator Levels by practice, Security Profile progress, control gaps, evidence and remediation actions, links them to your CIRMP risk register, and produces executive dashboards for the board. Your IEC 62443 program can run alongside it.

Who we work with

  • Electricity generators, transmission and distribution network operators
  • Gas and liquid fuel operators and pipeline owners
  • Energy retailers and market participants
  • Distributed energy, battery, solar and EV charging providers
  • New Zealand electricity and gas sector participants strengthening cyber resilience

Related services: cyber security maturity assessment, incident response and recovery and certification and accreditation. To discuss an AESCSF assessment, contact our energy team.

Frequently asked questions

The Australian Energy Sector Cyber Security Framework is the energy sector's cyber security maturity framework, run with AEMO. It assesses practices across eleven domains by Maturity Indicator Level and compares results with a target Security Profile based on the organisation's criticality.

Version 2, released in 2023, aligned the framework with C2M2 version 2.1, added a cyber security architecture domain, refreshed third-party risk management and expanded coverage across electricity, gas and liquid fuels.

SP-1, SP-2 and SP-3 are target maturity states. Each bundles a set of practices at specific Maturity Indicator Levels. Organisations with higher criticality are expected to reach a higher profile.

The CIRMP rules require responsible entities to comply with a recognised cyber security framework, and the AESCSF at the relevant profile is one of the recognised options. Other options include the Essential Eight, ISO/IEC 27001 and the NIST Cybersecurity Framework.

Within 90 days of the end of the Australian financial year, which is 28 September for a year ending 30 June. The report must be approved by the entity's board, council or other governing body.

Only when it is safe and agreed with your engineers. Our OT assessments rely mainly on documentation, architecture review, interviews and passive analysis, because availability and safety come first in operational environments.