A NERC audit or a self-identified violation
Usually on vendor remote access or CIP-004 revocation timing.
One unretired VPN account with no MFA shut down the largest fuel pipeline in the United States. The pattern has not changed since. In energy and utilities, identity security is the point where corporate IT meets the operational technology that runs critical infrastructure and was never designed for it, under a regulator that can fine up to $1 million per violation per day and audits access records going back years.
You cannot revoke access you do not know exists.
This page covers the identity side of an energy programme. The plant-floor side — asset discovery, OT monitoring, ICS testing and incident response — is on the OT and ICS security page.
NERC CIP-003-9 became enforceable on 1 April 2026. It extends vendor electronic remote access controls — which previously applied only to medium and high-impact bulk electric system cyber systems — to low-impact ones as well. For many utilities that means a set of sites and systems that were previously out of scope now need vendor access brokered, monitored and terminable, with evidence.
Two more are coming. CIP-003-11, approved by FERC in March 2026 with compliance due in 2029, tightens low-impact requirements further. CIP-015-1, approved after the Volt Typhoon disclosures, requires internal network security monitoring inside the electronic security perimeter. Together they describe a direction: the boundary between corporate and operational is no longer the only line that matters, and what happens inside it has to be watched.
CIP-004 requires that when someone loses authorization — termination, role change, contract end — their access to BES cyber systems is revoked within 24 hours. In an estate where access to control systems is granted through shared operator accounts, local administrator rights and firecall IDs that nobody tracks, that is not a policy problem. It is a discovery problem: you cannot revoke access you do not know exists. Discovery of every privileged and shared account across IT and OT is the first phase of PAM implementation, and in this sector it is the phase that finds the most.
CIP-004 also requires access reviews at least every 15 months and quarterly reviews of who holds authorization. Automating those against the HR system is IGA implementation work, and it is what turns a 24-hour obligation from an aspiration into a report.
The CIP Senior Manager, a role NERC requires to be formally designated, is personally accountable for the compliance program. The CISO usually runs it day to day. Findings carry penalties of up to $1 million per violation per day under FERC's authority, and NERC audits routinely request access records reaching back three years — which means the evidence has to have been collected as the access was granted, not reconstructed when the audit letter arrives. Where a NERC finding is the trigger, that starts with a compliance readiness assessment.
The systems we secure. SCADA, EMS and DCS platforms. ICS and PLCs. Historians including OSIsoft PI. RTUs and field devices through their management consoles. Jump hosts and the IT/OT boundary. Corporate Active Directory and Entra ID. Platform names are trademarks of their respective owners.
Usually on vendor remote access or CIP-004 revocation timing.
Low-impact sites that were previously out of scope and now need brokered vendor access with evidence.
A credential that crossed from the corporate network into control systems. Vendor and emergency access are brought under brokered sessions first, with IoT and SCADA penetration testing to prove the boundary holds. Internal network monitoring inside the perimeter, as CIP-015-1 will require, is a managed SOC engagement.
Where the platform is CyberArk, CyberArk implementation is the delivery route. Service and firecall accounts across the OT estate are handled through service account management, and day-two operations through managed IAM services. All of it connects to the historian and control systems through IAM integration.
That vendor electronic remote access into low-impact BES cyber systems is controlled, monitored and can be terminated — the same expectations that applied to medium and high-impact systems before April 2026. Brokered sessions with recording meet all three.
First by knowing where all of it is, which is discovery. Then by driving revocation from the HR or contractor system automatically rather than from a checklist. The 24-hour clock is only achievable when the access is inventoried and the removal is automated.
Yes, because the controls sit around the control systems rather than on them. Jump hosts, brokered sessions and vaulted credentials leave the SCADA environment untouched. Nothing is installed on a PLC.
Put the MFA in front of them. Access to the control network goes through a brokered session that requires MFA; the control system itself never has to support it.
As the most important line in the estate. Every crossing is a brokered, recorded session, and the credentials that cross it are vaulted and rotated. Internal monitoring inside the perimeter is the next layer, and CIP-015-1 is going to require it.
By collecting it as the access is granted. Session recordings, revocation timestamps and review completions produced by the platform, retained for the years an audit reaches back, and available on request rather than reconstructed under pressure.

Most CyberArk PAM comparisons are written by vendors selling against it. Here is what actually differs, from a team that deploys these platforms.
Aug 25, 2026
PAM secures the accounts with the most system power. Here's what privileged access management does and why attackers go after these credentials first.
Jul 28, 2026
Owning PAM and IGA is not the same as knowing your identity risk. What identity security posture management actually measures.
Jul 27, 2026A free audit is a 30-minute review of your privileged, vendor and emergency access by a certified engineer, with the findings in writing. The Energy blind spot brief covers the pipeline shutdown and the access gap behind it.
Needed for the site to work — page delivery, and the spam protection on our forms. These do not track you and cannot be switched off.
Google Analytics and Microsoft Clarity, so we can see which pages are useful and which are confusing. Clarity hides anything you type into a form. We use this to improve the site, not to identify you.
ZoomInfo WebSights, which tells us which organisation a visit is likely to have come from and which pages were read. With this on, ZoomInfo may also set third-party cookies that help it recognise a visit across other websites, and may share that with its own partners. Turning this off stops all of it.