Overview
A regional energy grid operator preparing a multi-year deployment of new substations and control-system upgrades faced a familiar tension: accelerate delivery to meet growing demand, while proving readiness for the requirements of the Critical Entities Resilience (CER) Directive. The deployment would expand operational complexity across multiple sites, introduce new vendors, and increase the digital footprint of operational technology (OT). Leadership needed a clear answer to a straightforward question: How ready is the organization to comply—and what must be fixed before commissioning?
To obtain a defensible, repeatable view of readiness, the operator conducted a CER Directive readiness assessment using AISAR systems—a structured approach that connects Asset, Impact, Scenario, Assessment, and Remediation into a single operational workflow.
Context and Challenge
The operator manages a distributed network that includes substations, field devices, remote terminal units, communications links, and a control center. The new deployment introduced:
- Additional substations and upgraded protection relays
- Wider use of remote access for maintenance and vendor support
- Greater interdependence between grid operations and external service providers
- A more complex incident landscape, spanning physical hazards and cyber threats
The CER Directive’s expectations around risk assessments, resilience measures, incident handling, and continuity demanded more than policy-level statements. The operator needed to demonstrate that resilience was embedded in design and operations—especially as new sites came online.
Key obstacles emerged early:
-
Fragmented visibility across assets and sites
Asset inventories existed in multiple tools and spreadsheets, and the “system-of-systems” view was incomplete. For CER readiness, the operator needed a consolidated perspective of critical functions and supporting assets. -
Inconsistent risk language between engineering, security, and operations
Engineering prioritized reliability and safety; security teams focused on threats and controls; operations cared about response time and uptime. A shared model was missing. -
Unclear mapping between requirements and real controls
Some measures were in place (e.g., access control, maintenance routines), but evidence was scattered, and ownership was ambiguous. -
Deployment pressure and change risk
New substations were being built while legacy sites remained in service. The operator needed an approach that supported continuous assessment, not a one-time audit.
Approach: AISAR-Based Readiness Assessment
The operator structured the assessment around AISAR systems to ensure that compliance readiness was tied to real operational risk and actionable remediation.
1) Asset: Establish a “criticality-aware” asset model
Instead of building a single exhaustive inventory from day one, the operator used a criticality-first approach:
- Defined essential services and critical functions (e.g., maintaining grid stability, restoring power after a fault, executing switching operations safely)
- Mapped those functions to:
- Control center systems and OT networks
- Substation automation components
- Communications infrastructure
- Physical security systems
- Key suppliers and service dependencies
This created a service-to-asset chain that was sufficient for decision-making and could be expanded over time.
Outcome: A coherent asset model that connected business impact to operational components—crucial for CER-aligned risk assessment.
2) Impact: Quantify what “material disruption” means operationally
The assessment defined impact categories and thresholds tailored to grid operations:
- Safety impact (personnel and public)
- Service continuity (outage duration and load affected)
- Operational integrity (ability to monitor and control the network)
- Regulatory and contractual exposure
- Environmental impact (where relevant)
Rather than relying on generic risk matrices, teams agreed on what constitutes unacceptable disruption for the operator’s geography and operational responsibilities. Where numeric thresholds were sensitive or varied by region, the operator used tiered impact levels with clear descriptions.
Outcome: A consistent impact model used across engineering, OT security, physical security, and continuity planning.
3) Scenario: Build credible, CER-relevant disruption scenarios
AISAR scenarios were designed to cover both foreseeable hazards and blended events. Workshops produced scenario families such as:
- Physical intrusion or tampering at a remote substation during low staffing hours
- Communications outage affecting multiple substations and impairing visibility
- Ransomware impacting supporting IT systems that enable OT operations (e.g., identity services, patch distribution, logging)
- Misconfiguration during commissioning leading to protection relay malfunction
- Extreme weather causing site access constraints and cascading failures in supply lines
For each scenario, the operator documented:
- Trigger conditions and early warning indicators
- Affected services and assets (from the asset model)
- Expected impacts (from the impact model)
- Existing preventive and detective controls
- Response and recovery steps, including manual fallbacks
Outcome: Scenarios that were concrete enough to test and improve resilience—without being limited to purely cyber or purely physical viewpoints.
4) Assessment: Evaluate readiness against CER obligations using evidence
The assessment phase connected CER expectations to operational evidence. Rather than a checklist-only approach, each requirement area was evaluated through:
- Control existence: is a measure defined and implemented?
- Control effectiveness: does it work under realistic conditions?
- Control coverage: does it apply consistently across sites and new deployments?
- Evidence quality: can the operator show it reliably (procedures, logs, maintenance records, training records, test results)?
Focus areas included:
- Governance and accountability for resilience measures
- Risk assessment cadence and update triggers (e.g., commissioning, vendor changes)
- Incident detection, escalation, and coordination across teams
- Business continuity and disaster recovery alignment with OT realities
- Supply chain and third-party access governance
- Training and exercising (tabletops and operational drills)
To avoid “paper compliance,” the operator emphasized walkthroughs and site-level validation, especially at locations undergoing upgrades.
Outcome: A defensible readiness picture with clear ownership and evidence trails.
5) Remediation: Convert findings into an engineering-compatible plan
Remediation actions were structured so they could be executed without derailing the deployment schedule:
- Classified actions into:
- Immediate (blocking commissioning or increasing near-term risk)
- Near-term (to complete within a defined period post go-live)
- Programmatic (multi-site improvements requiring investment planning)
Examples of remediation themes included:
- Standardizing remote access pathways and approval processes for vendors
- Tightening configuration management for commissioning changes
- Improving segmentation boundaries and monitoring at OT/IT interfaces
- Aligning incident response runbooks with on-call realities and site constraints
- Establishing consistent evidence collection (maintenance logs, access logs, test attestations)
The plan explicitly mapped each remediation to:
- The scenario(s) it reduced
- The impact category it protected
- The CER requirement area it supported
- The operational owner responsible for completion
Outcome: A practical backlog integrated into engineering, security, and operations planning.
Results
The readiness assessment produced outcomes that supported both compliance confidence and operational resilience.
- Clear readiness baseline: Leadership gained a structured view of strengths, gaps, and risk concentration across sites and systems.
- Reduced ambiguity in responsibilities: Ownership for resilience measures—especially those spanning physical security, OT, and IT—became explicit.
- More resilient commissioning path: The operator identified a small set of high-impact blockers early enough to address them without major schedule disruption.
- Improved evidence posture: Documentation and testing artifacts were organized into a consistent, repeatable format, improving audit readiness and internal assurance.
- Better cross-team coordination: A shared asset-impact-scenario language reduced friction between engineering delivery teams and operational responders.
Where quantitative metrics were used, they were treated as approximate, serving primarily to prioritize action rather than to claim precise risk reduction.
Key Takeaways
- Compliance readiness is operational readiness. The fastest path to CER alignment is tying requirements to service continuity, safety, and real disruption scenarios.
- Start with critical functions, not perfect inventories. A criticality-aware asset model enables meaningful assessment early, and can mature over time.
- Scenarios unify physical, cyber, and process risks. CER readiness improves when teams assess blended scenarios, including commissioning and supplier-driven risks.
- Evidence matters as much as controls. A control that exists but cannot be demonstrated consistently will fail under scrutiny and during real incidents.
- Remediation must fit deployment reality. A prioritized, owner-assigned remediation backlog—mapped to scenarios and impacts—prevents assessment findings from becoming shelfware.
By using AISAR systems as a unifying structure, the operator turned CER Directive readiness from a compliance exercise into a practical resilience program—one that could keep pace with an evolving energy grid deployment.