Applied IAM

Identity Security for Energy and Utilities

One unretired VPN account with no MFA shut down the largest fuel pipeline in the United States. The pattern has not changed since. In energy and utilities, identity security is the point where corporate IT meets the operational technology that runs critical infrastructure and was never designed for it, under a regulator that can fine up to $1 million per violation per day and audits access records going back years.

NERC CIPIT/OT boundaryVendor remote access24-hour revocationFirecall IDs
Corporate IT
Vendor remote accessTurbine manufacturers, integrators, maintenance contractors
Active DirectoryEntra ID
IT/OT boundaryAccess control has to happen at the boundary, not on the device
MFAin front
Jump hostbrokered
Control systems
SCADAEMSDCSPLCsHistorians
Cannot run MFA
CIP-004The 24-hour rule
Authorization losttermination, role change, contract endAccess revokedwithin 24 hours

You cannot revoke access you do not know exists.

The OT constraint

Why OT resists everything IT identity assumes

This page covers the identity side of an energy programme. The plant-floor side — asset discovery, OT monitoring, ICS testing and incident response — is on the OT and ICS security page.

  • Systems that cannot run MFA. SCADA, EMS, DCS and PLC environments run on control-system software with decades-long lifecycles. Many cannot take an agent, cannot join a directory and cannot prompt for a second factor. Access control has to happen at the boundary, through jump hosts and brokered sessions, not on the device.
  • Availability comes first. A control that could interrupt a process is a control that will be bypassed, because keeping the lights on outranks everything. Identity controls in OT have to be designed around that priority, not against it.
  • Firecall and emergency access. Operators need break-glass access to control systems immediately in an emergency. Firecall IDs exist for that reason, and they have to be issued instantly, logged completely, and reviewed afterwards without exception.
  • Vendor remote access. Turbine manufacturers, control-system integrators and maintenance contractors with standing remote access into operational networks. This is where most real intrusions into OT begin, and it is what the April 2026 rule change is about.
The rule change

Vendor remote access, and what changed in April 2026

NERC CIP-003-9 became enforceable on 1 April 2026. It extends vendor electronic remote access controls — which previously applied only to medium and high-impact bulk electric system cyber systems — to low-impact ones as well. For many utilities that means a set of sites and systems that were previously out of scope now need vendor access brokered, monitored and terminable, with evidence.

Two more are coming. CIP-003-11, approved by FERC in March 2026 with compliance due in 2029, tightens low-impact requirements further. CIP-015-1, approved after the Volt Typhoon disclosures, requires internal network security monitoring inside the electronic security perimeter. Together they describe a direction: the boundary between corporate and operational is no longer the only line that matters, and what happens inside it has to be watched.

NERC CIP · what changed, and what is coming
  1. March 2026CIP-003-11Approved by FERC
  2. 1 April 2026CIP-003-9Enforceable
  3. 2029CIP-003-11Compliance due
Vendor electronic remote access controls apply to
Before
High-impactMedium-impactLow-impact
Low-impact previously out of scope
From 1 April 2026
High-impactMedium-impactLow-impact
Brokered, monitored and terminable, with evidence
Two more are coming
CIP-003-11Tightens low-impact requirements furtherCompliance due in 2029
CIP-015-1Internal network security monitoring inside the electronic security perimeterApproved after the Volt Typhoon disclosures
CIP-004

The 24-hour rule

CIP-004 requires that when someone loses authorization — termination, role change, contract end — their access to BES cyber systems is revoked within 24 hours. In an estate where access to control systems is granted through shared operator accounts, local administrator rights and firecall IDs that nobody tracks, that is not a policy problem. It is a discovery problem: you cannot revoke access you do not know exists. Discovery of every privileged and shared account across IT and OT is the first phase of PAM implementation, and in this sector it is the phase that finds the most.

CIP-004 also requires access reviews at least every 15 months and quarterly reviews of who holds authorization. Automating those against the HR system is IGA implementation work, and it is what turns a 24-hour obligation from an aspiration into a report.

Accountability

Who signs

The CIP Senior Manager, a role NERC requires to be formally designated, is personally accountable for the compliance program. The CISO usually runs it day to day. Findings carry penalties of up to $1 million per violation per day under FERC's authority, and NERC audits routinely request access records reaching back three years — which means the evidence has to have been collected as the access was granted, not reconstructed when the audit letter arrives. Where a NERC finding is the trigger, that starts with a compliance readiness assessment.

The systems we secure. SCADA, EMS and DCS platforms. ICS and PLCs. Historians including OSIsoft PI. RTUs and field devices through their management consoles. Jump hosts and the IT/OT boundary. Corporate Active Directory and Entra ID. Platform names are trademarks of their respective owners.

Triggers

Where a program usually starts

A NERC audit or a self-identified violation

Usually on vendor remote access or CIP-004 revocation timing.

CIP-003-9 scoping

Low-impact sites that were previously out of scope and now need brokered vendor access with evidence.

An IT/OT boundary incident

A credential that crossed from the corporate network into control systems. Vendor and emergency access are brought under brokered sessions first, with IoT and SCADA penetration testing to prove the boundary holds. Internal network monitoring inside the perimeter, as CIP-015-1 will require, is a managed SOC engagement.

Where the platform is CyberArk, CyberArk implementation is the delivery route. Service and firecall accounts across the OT estate are handled through service account management, and day-two operations through managed IAM services. All of it connects to the historian and control systems through IAM integration.

FAQs

What utilities ask first

That vendor electronic remote access into low-impact BES cyber systems is controlled, monitored and can be terminated — the same expectations that applied to medium and high-impact systems before April 2026. Brokered sessions with recording meet all three.

First by knowing where all of it is, which is discovery. Then by driving revocation from the HR or contractor system automatically rather than from a checklist. The 24-hour clock is only achievable when the access is inventoried and the removal is automated.

Yes, because the controls sit around the control systems rather than on them. Jump hosts, brokered sessions and vaulted credentials leave the SCADA environment untouched. Nothing is installed on a PLC.

Put the MFA in front of them. Access to the control network goes through a brokered session that requires MFA; the control system itself never has to support it.

As the most important line in the estate. Every crossing is a brokered, recorded session, and the credentials that cross it are vaulted and rotated. Internal monitoring inside the perimeter is the next layer, and CIP-015-1 is going to require it.

By collecting it as the access is granted. Session recordings, revocation timestamps and review completions produced by the platform, retained for the years an audit reaches back, and available on request rather than reconstructed under pressure.

Check your IT and OT access before the auditor does

A free audit is a 30-minute review of your privileged, vendor and emergency access by a certified engineer, with the findings in writing. The Energy blind spot brief covers the pipeline shutdown and the access gap behind it.