Securing the Systems the Grid, the Pipeline, and the Public Depend On
OT/ICS monitoring, converged physical security, and audit-ready compliance governance for electric utilities, pipeline and rail operators, water systems, and generation facilities — delivered across Armorstack’s four portfolios: VERITY, CORE, SENTRY, and CITADEL.
Oil & Gas Pipelines
Rail & Surface Transportation
Water & Wastewater Systems
Generation & Nuclear Facilities
Downtime Isn’t an Inconvenience — It’s a Public Safety Event
Electric utilities, pipeline operators, rail systems, and water utilities sit at the intersection of operational technology (OT), physical infrastructure, and a dense, overlapping web of federal and industry regulation. A single control-system intrusion or an unsecured substation doesn’t just cost revenue — it can cascade into grid instability, environmental release, or loss of essential service to a community. Armorstack’s converged model treats the cyber and physical layers of critical infrastructure as one problem, because attackers already do.
Five Frameworks Every Critical Infrastructure Operator Should Know
These are the real, named standards that govern OT/ICS and physical security for critical infrastructure — not generic best practice, but the actual frameworks regulators and auditors will hold you to.
NERC CIP
The North American Electric Reliability Corporation’s Critical Infrastructure Protection standards are the mandatory, FERC-enforceable cybersecurity and physical security requirements for owners and operators of the Bulk Electric System. The current CIP standard set runs from CIP-002 (BES Cyber System categorization) through newer additions like CIP-013 (supply chain risk management), CIP-014 (physical security of transmission stations and control centers), and CIP-015 (internal network security monitoring). CIP-003-9, tightening requirements for lower-impact environments, becomes enforceable April 1, 2026.
Source: North American Electric Reliability Corporation (nerc.com/standards)TSA Security Directives
Following the 2021 Colonial Pipeline ransomware attack, the Transportation Security Administration issued Security Directives requiring pipeline and LNG facility operators to report cyber incidents, name a cybersecurity coordinator, and test contingency plans — most recently updated in 2023 as SD Pipeline-2021-02D. In November 2024, TSA proposed a rule to make these requirements permanent regulation and extend comparable cyber risk-management obligations to rail and other surface transportation operators.
Source: Transportation Security Administration (tsa.gov/sd-and-ea); Federal Register, Nov. 7, 2024CISA’s 16 Critical Infrastructure Sectors
Under Presidential Policy Directive 21, the Cybersecurity and Infrastructure Security Agency coordinates 16 designated critical infrastructure sectors — including Energy, Transportation Systems, and Water and Wastewater Systems — each assigned a federal Sector Risk Management Agency. This framework drives information sharing and risk coordination; binding compliance obligations still flow from your sector’s actual regulator (NERC/FERC, TSA, EPA, etc.).
Source: Cybersecurity and Infrastructure Security Agency (cisa.gov/topics/critical-infrastructure-security-and-resilience)NIST SP 800-82 Rev. 3
Published by NIST in September 2023 and retitled “Guide to Operational Technology (OT) Security” (from “Guide to Industrial Control Systems Security”), this guidance covers SCADA, distributed control systems, PLCs, and building automation. It organizes protection into 19 control families mapped to the NIST Cybersecurity Framework’s Identify, Protect, Detect, Respond, and Recover functions.
Source: National Institute of Standards and Technology, NIST SP 800-82r3 (csrc.nist.gov)IEC 62443
Developed jointly by the International Electrotechnical Commission and ISA (as ISA/IEC 62443), this international standards series addresses security across the full lifecycle of industrial automation and control systems — asset owners, system integrators, and product suppliers alike. It defines a zones-and-conduits architecture model, four Security Levels (SL 0–4), and seven Foundational Requirements. In 2021, IEC recognized it as a horizontal standard applicable across sectors including energy, water, and transport.
Source: International Electrotechnical Commission / ISA Global Cybersecurity Alliance (isagca.org)How Armorstack Secures Critical Infrastructure
One converged model, four coordinated portfolios — each mapped directly to the standards above.
Continuous OT/ICS Monitoring
Passive network monitoring and threat detection purpose-built for SCADA, DCS, and PLC environments — the IT/OT boundary, protocol-aware traffic analysis, and anomaly detection Sentry brings to control-system networks without disrupting operational uptime, aligned to the control families in NIST SP 800-82 Rev. 3 and IEC 62443’s zones-and-conduits model.
Physical Security for Substations & Generation Sites
Access control, video surveillance, and AI-driven analytics for substations, generation facilities, pump and compressor stations, and other unmanned or lightly staffed critical sites — directly supporting NERC CIP-014’s physical security requirements for transmission stations and control centers.
NERC CIP Audit Readiness & Governance
vCISO-led compliance governance, evidence management, and FAIR-based risk quantification to keep BES Cyber System categorization, CIP-013 supply chain documentation, and CIP-015 monitoring evidence audit-ready year-round — not assembled in a scramble before the next NERC compliance window.
Resilient IT Backbone
Hardened, redundant network and infrastructure services for the corporate-IT side of the house — segmented cleanly from OT per IEC 62443’s zones model, so a phishing incident on the business network never becomes a control-system incident.
Critical Infrastructure Security & Compliance Questions
What is NERC CIP and does it apply to my organization?
NERC CIP is the mandatory set of cybersecurity and physical security reliability standards enforced by the North American Electric Reliability Corporation, under FERC oversight, for owners and operators of the Bulk Electric System. If your organization owns or operates BES Cyber Systems — generation, transmission, or control-center assets affecting grid reliability — CIP compliance is very likely mandatory, with FERC-enforceable penalties for violations.
Are TSA Security Directives only for oil and gas pipelines?
Not for long. The original 2021 directives targeted pipeline and LNG facility operators after the Colonial Pipeline attack and were updated in 2023 (SD Pipeline-2021-02D). TSA’s November 2024 proposed rule would formalize these requirements in permanent regulation and extend comparable cyber risk-management obligations to rail and other surface transportation operators — so the scope is actively expanding.
How does IEC 62443 relate to NIST SP 800-82?
They’re complementary. NIST SP 800-82 Rev. 3 is a U.S. government risk-management guide mapped to the NIST Cybersecurity Framework. IEC 62443 is an international standards series with defined Security Levels, a zones-and-conduits model, and role-specific requirements for asset owners, integrators, and suppliers. Most mature OT security programs reference both.
Do the CISA critical infrastructure sectors carry their own compliance requirements?
Not directly. CISA’s 16-sector framework, established under Presidential Policy Directive 21, is a risk-coordination structure — each sector has a federal Sector Risk Management Agency (e.g., DOE for Energy, TSA/DOT for Transportation Systems). Your binding compliance obligations come from your sector’s actual regulator, not from the CISA framework itself.
What does an Armorstack Critical Infrastructure Assessment look at?
A structured review of your OT/ICS network architecture and segmentation, physical security controls at substations, generation sites, or pump/compressor stations, your NERC CIP or TSA directive documentation and evidence readiness, and detection/response coverage across the IT-OT boundary — benchmarked against the specific standards that apply to your sector.
We’re a smaller municipal utility or co-op — does any of this apply to us?
Yes, though scope varies by BES impact rating (high, medium, or low). Even low-impact BES Cyber Systems carry baseline NERC CIP obligations, and CIP-003-9’s April 1, 2026 enforcement date specifically tightens requirements for lower-impact environments. We right-size the assessment to your actual regulatory footprint rather than over-scoping.
Ready to Close the Gap Between Compliance and Real Resilience?
Talk to Armorstack about a Critical Infrastructure Assessment — scoped to the standards that actually govern your sector, not a generic checklist.
Schedule a Consultation