Enhancing Cybersecurity in the Energy Grid: From Monitoring to Engineered Resilience

Keon McEwen, Black & VeatchEmerging Technologies, Fall 2026 Emerging Technologies

The energy grid is becoming more connected, intelligent, and operationally dependent on digital systems every year. As utilities modernize infrastructure, integrate distributed assets, expand remote operations, and adopt data-driven tools, cybersecurity is no longer a support function on the sidelines of grid reliability; it’s part of the reliability mission itself.

In my work around operational technology (OT) cybersecurity, one thing has become clear: Cyber risk now sits at the intersection of physical operations, business priorities, and engineering decisions. It can no longer be treated as a narrow IT issue. It has to be addressed as part of how organizations design, operate, maintain, and recover critical infrastructure.

In practice, I still see organizations place perimeter defenses, compliance activities, and periodic assessments at the center of their cybersecurity programs. Those elements still matter, but they are no longer sufficient on their own. Today’s grid requires a broader approach, one that combines visibility, disciplined governance, supply chain assurance, incident readiness, and security-by-design across the full infrastructure lifecycle.

In other words, the goal is no longer to be just secure enough to comply. The more practical goal is to be resilient enough to keep operating through disruption, make informed decisions under pressure, and recover quickly when incidents occur.

WHY THE GRID IS DIFFERENT

The electric grid differs from a traditional business operation in cybersecurity terms because cyber incidents in OT environments can have direct physical effects. A compromised business system may interrupt administrative operations, but a compromised OT system can affect generation, transmission, power quality, protection schemes, or operational visibility where reliability matters most.

That distinction grows more important as legacy systems become increasingly connected, digitally monitored, and remotely operated. Smart sensing, automation, remote diagnostics, and analytical tools help operators improve performance and make better decisions faster. But every new interface, remote pathway, integrated service, and vendor dependency also expands the attack surface.

When I look at grid cybersecurity, I tend to frame it less as a technology problem and more as an operational and engineering problem with cybersecurity consequences. Improperly secured connections between IT and OT, internal and third parties, or field assets and centralized systems can create pathways that adversaries may exploit.

FROM POLICY TO OPERATIONAL GOVERNANCE

Policy remains essential because it establishes the baseline for how an organization intends to operate, what it values, and which controls it expects its people to follow. But in today’s environment, policy alone is not enough.

Cybersecurity governance now has to keep pace with changes in remote access, third-party services, engineering design, and tools enabled by artificial intelligence (AI). That takes practical coordination across operations, engineering, cybersecurity, procurement, and vendor management.

The real test of governance is not whether a policy exists. It’s whether the organization can make sound decisions consistently, especially when a project is moving fast, a vendor needs access, or an operational issue needs to be solved quickly.

Once accountability is established, the next challenge is deciding how much trust should be granted to users, devices, vendors, and systems as they interact with operational environments.

ZERO TRUST, ADAPTED FOR OPERATIONS

As OT environments become more interconnected, Zero Trust cybersecurity principles are gaining attention across critical infrastructure. My view is that Zero Trust is useful in OT only when it’s adapted to operational reality. It should not mean copying enterprise IT security models directly into plants, substations, control centers, or field networks. These environments have safety requirements, uptime constraints, and legacy technologies that demand a more careful and tailored approach.

Still, the core ideas of Zero Trust are increasingly relevant: stronger identity and access control, better asset visibility, secure communications, effective segmentation, and an assumption that trust should not be granted simply because a user or device is already inside the network boundary.

For utilities, this means building security in layers and reducing unnecessary implicit trust. Done carefully, that can limit lateral movement, improve accountability, and strengthen resilience without compromising operations.

Those same principles also shape how organizations evaluate internal visibility, because access decisions are only as strong as the asset, identity, and communication data behind them.

MONITORING IS EVOLVING INTO OBSERVABILITY

Monitoring remains one of the most important building blocks in industrial cybersecurity, but the conversation is shifting toward a broader concept: observability.

The question is no longer simply whether an organization collects logs or receives alarms. The more important question is whether it has enough visibility across assets, communications, identities, remote access paths, and process behavior to understand what normal looks like and identify meaningful deviations early.

This matters in OT because cyber incidents often don’t look like cyber incidents at first. They may appear as a device malfunction, control instability, process upset, or unexplained operational disruption. Without adequate internal visibility, organizations may struggle to distinguish equipment failure from malicious activity until the impact becomes much larger.

That makes internal monitoring increasingly important. A lesson I keep coming back to is simple: If you cannot see it, you cannot confidently investigate it. Watching the perimeter isn’t enough. Organizations also need insight into what’s happening inside trusted environments so they can detect abnormal behavior, investigate events quickly, and support faster containment and recovery.

With governance setting accountability and observability and improving situational awareness, organizations are better positioned to evaluate advanced capabilities such as AI without treating them as a substitute for operational understanding.

AI IN OT: OPPORTUNITY AND RISK

AI has moved from an emerging concept to an operational consideration. Across the energy sector, AI-enabled capabilities are being explored for anomaly detection, predictive maintenance, operational decision support, and performance optimization.

These capabilities can offer meaningful advantages, but they also introduce new questions. How is the model trained? What data is it using? Who validates its output? What happens if it misclassifies an event or behaves unexpectedly? And how much authority should an AI-enabled function have in an environment where safety and uptime are critical?

I don’t think the answer is to avoid AI. The better answer is to be deliberate about where it fits, what it depends on, and how much authority it should have. In OT environments, I would treat AI like any other critical capability: Understand it, test it, monitor it, and integrate it with human oversight and fail-safe thinking. Used well, AI can improve visibility and decision-making. Used carelessly, it can introduce new risks into already complex environments.

The same disciplined approach should extend beyond internal tools to external providers, products, and services that increasingly support grid operations.

SUPPLY CHAIN RISK NOW A CORE CYBERSECURITY ISSUE

One of the biggest shifts in recent years is the growing recognition that supply chain risk is central to grid cybersecurity. Utilities depend on equipment manufacturers, software providers, system integrators, managed services, contract engineers, and remote support relationships. That means the attack surface extends far beyond the organization itself.

Cybersecurity must therefore include a closer look at vendor remote access, software integrity, patch provenance, contractual security requirements, and the processes used to introduce updates or changes into the environment.

This is also where management of change becomes stronger cyber control. In practical terms, third-party laptops, removable media, temporary engineering access, service updates, and support connections all need to be tracked, authorized, and evaluated in the context of cyber risk, not just operational convenience.

Effective change management creates traceability, provides early warning signs, and helps organizations prevent avoidable exposure before a small issue becomes a major incident. Even with strong governance, visibility, access control, AI oversight, and supply chain discipline, utilities must still plan for the possibility that disruption will occur.

RESILIENCE MEANS RECOVERY, NOT JUST PROTECTION

Resilience remains as important as ever, but organizations are becoming more precise about what it should mean in practice. It includes preparedness, detection, containment, response, recovery, and follow-through. It also requires meaningful ways to measure progress.

Organizations often focus heavily on prevention, but the most mature programs also invest in how they will operate during disruption and how quickly they can restore stability afterward. In real-world response planning, success is not measured only by whether every threat was blocked. It’s also measured by how effectively the organization can continue operations, recover trust in the system, and reduce the time and cost of disruption.

Incident response in OT must also remain a cross-functional discipline. Operators, engineers, network personnel, cybersecurity staff, and external experts all have a role because OT events often require technical interpretation before they can be correctly classified. Distinguishing between equipment failure, process upset, misconfiguration, and malicious activity takes both visibility and experience.

The most durable resilience strategy is the one that reduces preventable weaknesses before systems are installed, commissioned, or connected to operational environments.

THE STRONGEST DEFENSE STARTS IN DESIGN

One of the most important shifts in the industry is the recognition that the best time to address cyber risk is before assets are deployed. Secure-by-design and cyber-informed engineering (CIE) approaches push cybersecurity upstream into architecture, design, procurement, and implementation rather than leaving it as a later retrofit exercise.

For energy projects, that means asking cybersecurity questions early. Do the switches and communication paths support the necessary security capabilities? Is remote access necessary, and if so, how will it be controlled? Does the architecture provide the right segmentation? What visibility will operators have once the environment is live? How will vendors connect? How will changes be governed over time?

These are engineering questions as much as cybersecurity questions. In my experience, answering them early is one of the most reliable ways to reduce long-term risk, avoid costly retrofit work, and improve resilience before the system ever becomes operational.

RESILIENCE: THE REAL DESTINATION

The energy grid’s cybersecurity challenge is no longer simply about protecting connected assets from external attacks. It is about building systems that can withstand modern threat conditions while continuing to support reliable operations in a highly connected, fast-changing environment.

The strongest programs treat cybersecurity as part of the lifecycle, not something added after design, procurement, or commissioning decisions have already been made.

Compliance remains important, but compliance is not the destination. The real objective is resilience: the ability to detect earlier, respond faster, recover with confidence, and design infrastructure that is harder to disrupt in the first place.

As the grid becomes more digital and intelligent, cybersecurity must be more than a control function. It must become a design principle for the future of energy infrastructure. 

Keon McEwen, Head of Solutions Development and Industrial Cybersecurity at Black & Veatch, has a history in cybersecurity. He started his career as an electrical engineer in control systems and process control engineering. From there, he was drawn into cybersecurity, where he used his knowledge of operations technology (OT) and industrial control systems (ICS) to help protect power systems. McEwen joined Black & Veatch, which has offered cybersecurity services for more than 15 years, to help expand their industrial cybersecurity services by establishing a dedicated department focused on building solid consistency across projects.