top of page

Substation Cybersecurity in 2026: Key Threats, Standards & Protection Strategies

Writer: VSS Power
VSS Power
Sep 29
6 min read


Substation Cybersecurity in 2026

On 29 December 2025, attackers hit at least 30 wind and solar sites across Poland in one coordinated operation. Their target was the grid connection substations where those plants hand power to the distribution network. Generation carried on, but links to the grid operator were disrupted. For anyone responsible for substation cybersecurity, the message is clear: the substation is now the front line.  


Why Substation Cybersecurity Looks Different in 2026 


Older substations were isolated, proprietary, and hard to reach. Digital ones are the opposite. They have Ethernet process buses, remote engineering access, cellular gateways, and vendor connections. That connectivity brings real operating benefits, but it also gives attackers a route to equipment that switches live high-voltage circuits. Modern substation cybersecurity therefore has to cover engineering, operations and procurement, not just the IT team. 


Lesson from Poland 

CERT Polska discovered that the attackers had obtained access via internet-exposed perimeter devices which were set up to function as VPN concentrators. They then proceeded to enter the substation networks with the intention of damaging the controller firmware and erasing the systems. A subsequent report mentioned an additional method of entry: a private APN, which had for the first time been observed in a real attack. Independent analysis also pointed out that there was little endpoint protection or monitoring of the controllers at the affected sites. The takeaway is that the weak points were remote access and poor visibility, not an unusual exploit. Poland's energy control systems had been breached as a result of exposed VPN access 


Lesson from Ukraine 

In 2022, the Industroyer2 malware was built to speak IEC 60870-5-104 and target high-voltage substations, but it was discovered before it caused impact. The original Industroyer also supported IEC 61850. Attackers understand substation protocols as well as your engineers do, which is why substation cybersecurity must reach the protocol layer. Industroyer2 


Where a Digital Substation Is Exposed 


IEC 61850 cybersecurity begins with a tough nut to crack: the standard was designed for speed and interoperability, and IEC 61850 GOOSE/ sampled values messages are unauthenticated by default. Spurious or replayed messages can confuse protection schemes. In evaluations, you keep seeing the same vulnerabilities over and over: 

  • Internet-facing VPNs and firewalls that are unpatched 

  • Shared vendor credentials and unmanaged remote maintenance 

  • Flat networks where the HMI, gateway and relays share one segment 

  • Controllers and HMIs with no logging or monitoring 

    Substation Cybersecurity Architecture

Standards That Shape Substation Cybersecurity 

IEC 62351 for substations is the security series that sits next to IEC 61850. IEC 62351-6 defines the security of GOOSE and Sampled Values, and IEC 62351-9 defines key management. The 2020 edition of IEC 62351 uses message authentication codes, as RSA signatures are too slow for the 3 ms protection timing limit. IEC 62443 is a zones-and-conduits model that many regulators now reference.  PAC Worldarxiv 

Region 

Key framework 

What it means for substations 

UK 

NIS Regulations 2018; Cyber Security and Resilience Bill 

Bill proposes 24-hour initial and 72-hour full incident reports, plus wider supply-chain duties 

EU 

NIS2 and Network Code on Cybersecurity (2024/1366) 

Recurring risk management for high-impact and critical-impact entities, every three years 

India 

CEA Cyber Security in Power Sector Guidelines 2021 

OT audit at least yearly by CERT-In empanelled auditors; critical and high vulnerabilities closed within a month 

Saudi Arabia 

NCA OTCC-1:2022 

Governance, defence, resilience and third-party controls, informed by IEC 62443 


Three Trends Shaping Substation Cybersecurity 


Renewable connection points are targets. Dragos described the Polish incident as the first major cyberattack to directly target distributed energy resources. Small, unmanned sites with remote access are attractive because they are numerous and often thinly defended, so substation cybersecurity for renewables deserves its own plan. 


Regulators are following the supply chain. The UK Energy Sector Cyber Security Strategy, published on 28 May 2026, plans preliminary supply-chain security principles by the end of 2026. Expect suppliers, EPC contractors and integrators to face the same questions as operators. 


Visibility comes before prevention. You cannot defend assets you have not inventoried. Asset discovery and protocol-aware monitoring are now baseline expectations. 


How to Secure a Digital Substation: Six Practical Steps 


The short answer on how to secure a digital substation: segment the network, lock down remote access, monitor passively, authenticate protection traffic and design security in from day one. If you are asking how to protect substations from cyber attacks on a limited budget, this is the order to work in. 


1. Segment for substation network security 

The station bus, the process bus and the DMZ which is for remote access should all be separated. Firewalled conduits must be used between the zones, and GOOSE traffic should be kept on dedicated, prioritised VLANs. Proper substation network security ensures that if one laptop is compromised, the damage it can cause is limited. 


2. Remove direct internet exposure 

Channel all remote access through a hardened jump host with multi-factor authentication and vendor sessions that are time-limited. Patch the perimeter devices first, and treat cellular and APN connections as untrusted networks. 


3. Deploy a substation intrusion detection system 

Since the substation intrusion detection system operates passively, it does not introduce any delay into the protection traffic. You should select one that understands MMS, GOOSE and IEC-104, is able to learn what normal behaviour is, and issues alerts when new devices are detected or unexpected breaker commands occur. 


4. Authenticate protection traffic 

Where possible, enable IEC 62351-6 together with appropriate key management and carry out testing to verify the timing impact during factory acceptance testing, not after energisation. 


5. Design security into High Voltage Substation design 

Cybersecurity should be incorporated into the design of High Voltage Substations, not added on later. When specifying IEDs, it is necessary to choose ones that have secure boot-up capabilities, role-based access control and the ability to log events. Port policies, sources of time synchronisation and cyber test scripts for both FAT and SAT should all be defined before the procurement process closes. 


6. Prepare to operate through an attack 

Make sure that offline backups of the configuration are kept, together with the local and manual operating procedures and the retained logs. Carry out exercises in which the control-room staff, the protection engineers and the IT personnel are all in the same room. Cybersecurity in relation to substations can only be demonstrated through drills and not through policy documents. 


6 Steps to Secure a Digital Substation

Common Mistakes to Avoid 

The same three mistakes occur over and over again. The first is considering the cybersecurity of a substation to be an IT project, even though protection engineers know what a hazardous command looks like. The second is purchasing monitoring tools without first having an asset inventory, thereby creating blind spots. The third is agreeing to allow vendor remote access only on a temporary basis and then never cancelling it. Eliminating these three mistakes costs much less than having to recover from a wiper attack, and the same corrections also assist with meeting the audit requirements under NIS2, CEA or OTCC. 


Conclusion 


Attackers have already shown they can reach substations through remote access and that they know the protocols. The regulatory picture in the UK, EU, India and the Middle East is tightening at the same time. Strong substation cybersecurity is now a design requirement, an operating discipline and a compliance duty. 


If you are planning a new substation, a digital upgrade or a security review, the engineering team at VSS Power can help you build substation cybersecurity into the design from the start. Contact VSS Power to discuss your project. 

 

Key Takeaways 


  1. The attacks on Poland in December 2025 were carried out through remote access and a lack of visibility, not as a result of unusual exploits. 

  2. The attackers were aware of the protocols used by substations; Industroyer2 used IEC-104,2 and the original version of Industroyer also supported IEC 61850. 

  3. The latency of GOOSE and Sampled Values is not covered by IEC 62351-6 and Part 9, and therefore latency testing is required at FAT. 

  4. Start with the segment, then eliminate direct internet exposure, and finally introduce passive monitoring. 

  5. Design high-voltage substations with cybersecurity in mind since retrofits are more expensive and result in gaps. 


FAQs 


1. What is substation cybersecurity? 

It is the set of technical controls, standards, and operating practices that protect substation automation, protection, and communication systems from cyberattacks. It covers networks, IEDs, remote access and suppliers. 


2. Is IEC 61850 secure by default? 

On the contrary, IEC 61850 was created with interoperability and speed in mind, while IEC 62351 includes authentication and key management for GOOSE, Sampled Values and MMS. 


3. What does IEC 62351 do for substations? 

It ensures that IEC 61850 communications are secured; Part 6 is responsible for the protection of GOOSE and Sampled Values, and Part 9 deals with key management. 


4. How do I protect a substation from cyber attacks? 

Divide the network, get rid of direct access to the internet, use multi-factor authentication when accessing it remotely, install a passive intrusion detection system, and carry out exercises involving manual operation. 


5. Do UK, EU, Indian and Middle East regulations cover substations? 

Yes. Examples include the UK NIS Regulations and Cyber Security and Resilience Bill, the EU NIS2 and Network Code on Cybersecurity, India's CEA guidelines, and Saudi Arabia's NCA OTCC-1:2022. 

Comments


bottom of page