How do you secure a power station?
You secure a substation through a combination of physical measures, strict access control systems and digital security. Because substations are part of critical infrastructure, there are legal requirements and sector-specific guidelines that operators must comply with. Do you have questions about the security of your location? Feel free to contact us and we will help you further.
Which threats pose the greatest risk to a substation?
The greatest risks to a substation are unauthorized access, sabotage, theft of equipment, and cyberattacks on the control systems. Because a power outage has immediate and major societal consequences, substations are an attractive target for both criminals and malicious actors with political or economic motives.
In practice, security experts distinguish three main categories of threats:
- Physical threats: burglary, vandalism, copper theft and sabotage of equipment such as transformers and switchboards.
- Human threats: dissatisfied employees, social engineering, or unauthorized visitors attempting to gain access to secured zones.
- Digital threats: ransomware, attacks on SCADA systems and other industrial control networks that can directly affect power supply.
An effective security plan takes all three categories into account simultaneously, because an attack on one area often exposes a weak point in another.
Which physical security measures are mandatory for electricity substations?
In the Netherlands, substations are subject to obligations under the Network and Information Systems Security Act (Wbni) and the guidelines of the Nuclear Safety and Radiation Protection Authority, supplemented by sector-specific standards from grid operators. Specifically, this means that substations must be equipped with at least fencing, access control, and detection systems.
The most common mandatory or strongly recommended physical measures are:
- Fences or walls surrounding the site with a minimum height that makes climbing difficult
- Secured access gates with controlled entry and exit
- Lighting around the site and at critical installations
- Intrusion detection and alarm systems linked to a monitoring center
- Camera surveillance with sufficient resolution and coverage
In addition to these basic measures, regulators expect operators to have an up-to-date security plan and to evaluate it periodically. For larger or more critical stations, additional requirements may apply, such as anti-ram systems at access gates or bulletproof enclosures for switch cabinets.
How do you secure access to a power station?
Access to a substation is secured by a layered access control system that combines identification, verification, and registration. Only authorized personnel may enter the installation, and every access attempt is recorded for audit and analysis.
A good access system for a substation typically consists of multiple layers:
- Perimeter access: a secure gate with a card reader or intercom system for entering the premises.
- Building access: a second verification step at the entrance to the building or switch room, often via a PIN code in combination with an access card.
- Zone management: Zones with different access rights are created within the station, so that a technician does not automatically have access to all critical areas.
- Visitor registration: External parties such as contractors or inspectors are registered, guided, and provided with temporary access rights.
Modern access management systems utilize electronic locks, biometric readers, or smart cards that are centrally managed. This allows an administrator to remotely modify or revoke access rights without needing to be physically present.
What is the difference between physical and cybersecurity at power stations?
Physical security protects the location, equipment, and people against tangible threats such as burglary and sabotage. Cybersecurity protects the digital systems and networks that control the installation against attacks via software, networks, or connected devices. Both forms are inextricably linked at power stations.
Physical security
Physical security focuses on the premises, buildings, and equipment. Examples include fencing, camera systems, access gates, and security personnel. The goal is to keep unauthorized persons out and to prevent or quickly detect damage to installations.
Cybersecurity
Cybersecurity protects SCADA systems, industrial control networks, and communication links that regulate power supply. Attacks on these systems can be carried out remotely without the need for an attacker to be physically present. Measures include network segmentation, firewalls, patch management, and continuous monitoring of network traffic.
In practice, both disciplines reinforce each other. An attacker who gains physical access to a server room can compromise digital systems. Conversely, a digital attack can open doors or disable camera systems. Therefore, an integrated security plan always addresses physical and cybersecurity together.
Which monitoring technology is used at power stations?
At substations, surveillance technology is deployed that continuously detects and records threats, even outside office hours. The most commonly used technologies are camera systems, motion detection, perimeter detection, and alarm systems linked to a manned control room.
Specific technologies applied in the sector:
- IP camera systems with video analysis: smart cameras that automatically recognize anomalous behavior, such as people entering a restricted zone or stationary vehicles at an entry gate.
- Perimeter detection: sensors in or on fencing that detect vibrations, climbing attempts, or cutting, and immediately activate an alarm.
- Infrared detection: thermal cameras that detect people or vehicles on the site even in the dark or in poor weather conditions.
- Access logs: electronic registration of every access attempt, including time, location, and identity of the user.
- Control room connection: All alarms are forwarded to a 24/7 manned control room that can respond immediately and, if necessary, dispatch emergency services.
The choice of specific technology depends on the size of the station, the risk classification, and the environment. A station in an urban area imposes different requirements than a remote transformer station.
How do you draw up a security plan for a substation?
A security plan for a substation is drawn up by first conducting a risk analysis, subsequently determining appropriate measures, and finally establishing procedures for daily management, incident response, and periodic evaluation. The plan must align with legal requirements and the specific characteristics of the location.
Follow these steps as a guide:
- Risk analysis: Map out all threats, assess the probability and impact of each scenario, and prioritize based on risk.
- Determine security level: Determine, based on the risk analysis, what level of security is required and which standards apply.
- Select measures: choose a combination of physical measures, technological systems, and procedural agreements that cover the identified risks.
- Establish procedures: Describe who has access, how visitors are treated, how incidents are reported, and who is responsible for which action.
- Train employees: Ensure that all involved parties know the procedures and how to act in the event of an incident or alarm.
- Evaluate and update: Conduct an audit at least annually and adjust the plan in the event of changes to the installation, the threat situation, or regulations.
A good security plan is not a static document, but a living instrument that grows with the environment. Preferably engage a specialized security partner to review the risk analysis and the plan against current insights and industry standards. Contact us contact Sellox for a no-obligation consultation about the security of your power station.
Frequently Asked Questions
How often must the security plan of a substation be reviewed?
A security plan must be evaluated and updated at least once a year. In addition, an interim review is necessary in the event of significant changes, such as an expansion of the installation, a change in the threat situation, new legislation and regulations, or following a security incident. Regularly testing the plan against current industry standards ensures that security remains effective and compliant.
What should I do if a security incident occurs at a power station?
In the event of a security incident, immediately follow the incident response plan set out in the security document: contact the control room, inform the responsible administrator, and ensure the location is secured without disturbing any evidence. Depending on the severity of the incident, also involve the police, the grid operator, or the supervisory authority. After the incident has been handled, a thorough analysis is mandatory to prevent recurrence and to adjust the security plan where necessary.
Which certifications or standards are relevant for the security of power stations in the Netherlands?
Relevant standards and frameworks include the Network and Information Systems Security Act (Wbni), the NEN-EN-IEC 62351 standards for cybersecurity of energy systems, and the IEC 62443 series for industrial automation. In addition, major grid operators such as Tennet and Liander apply their own security guidelines that contractors and operators must comply with. It is strongly recommended to assess, together with a certified security partner, which standards specifically apply to your location.
How do you handle security during maintenance work by external contractors?
During maintenance by external parties, it is essential to grant temporary, strictly limited access rights that automatically expire upon completion of the work. Contractors are always registered, provided with a visitor badge, and, where possible, accompanied by an authorized employee. Also ensure that external parties sign a confidentiality agreement in advance and are aware of the applicable security procedures at the location.
What are the most common mistakes in the security of power stations?
Common mistakes include failing to revoke access rights for departed employees or completed contractors in a timely manner, the lack of network segmentation between IT and OT systems, and neglecting perimeter security in favor of digital measures or vice versa. Another common pitfall is an outdated security plan that no longer aligns with the current installation or threat situation. A comprehensive and regularly evaluated security plan prevents these vulnerabilities.
Is camera surveillance alone sufficient as a security measure for a power station?
No, camera surveillance alone is absolutely insufficient for the security of a power station. Cameras are a valuable detection and recording tool, but without additional measures such as perimeter detection, access control, and an active monitoring center connection, they offer no active protection. Effective security always requires a layered approach in which physical, technological, and procedural measures complement and reinforce each other.
How do you select the right security partner for a substation?
Choose a security partner with demonstrable experience in the energy sector and knowledge of both physical and cybersecurity of critical infrastructure. Verify that the party is familiar with relevant laws and regulations, such as the Wbni, and ask for references from similar projects. A good partner not only carries out the installation process but also provides support with the risk analysis, the drafting of the security plan, and its periodic evaluation.