Industries · Energy and utilities

Energy cybersecurity: the shortest path in is a USB stick

Energy assets outlive the software that manages them, and the networks that matter are often meant to have no route out at all. So the risks that count are the ones that walk in: a contractor’s laptop, a memory stick, a directory that has to stay on site. QS-WAN is built to run entirely inside that boundary.

Three ways in that have nothing to do with the internet
01
A maintenance laptop
02
A memory stick
03
A standing contractor link

None of them are stopped by a firewall at the perimeter.

The constraint

Thirty year assets, and a directory that cannot leave

A substation, a turbine or a pumping station is planned in decades. The control and protection equipment that runs it is chosen once and lives with the asset, which means the security around it has to assume the equipment will not change.

Many of these networks are also meant to have no path to the public internet, and their identity directories stay on site by design. Any tool whose management lives in somebody else’s cloud either gets refused or gets an exception, and the exception is the thing that fails an audit.

Then there is removable media, the plainest risk in the sector. The stick that carries a firmware update is the same shape as the stick that carries something else.

An isolated network with one exception is not an isolated network.
What makes energy different
01

Isolation is the design

Operational networks are separated on purpose, and the management layer has to respect that rather than negotiate with it.

02

Media is the vector

Firmware, configuration and evidence all travel on removable media at some point, usually in somebody’s pocket.

03

Regulation follows the grid

NIS2 puts energy in its scope in the European Union, and the sector already lives with regulators who expect controls to be shown rather than asserted.

How QS-WAN fits an isolated site

Everything inside the boundary, including the console

QS-WAN runs a private network from one console, and QNova Client puts it on the devices that can take it. For an operator, three properties matter.

01

The management layer stays inside

Licensed on your own infrastructure, the console, the gateways and the devices all sit inside the boundary. There is no exception to make and no cloud dependency to explain.

02

Removable media, decided centrally

USB and removable media rules are part of the signed company policy. One rule behaves in reverse compared with the others, and we say so in the documentation rather than leaving it to be discovered: a soft USB mandate means blocked by default.

03

A contractor gets one path, not the site

Each device holds a certificate per gateway membership, and each permitted path is an edge you switch off. The maintenance visit ends and so does the access.

Underneath, the same everywhere

Post-quantum by default

Everything between a device, a gateway and the control plane is post-quantum by default, aligned with FIPS 203, FIPS 204 and CNSA 2.0, and hybrid by design. An asset with a thirty year life deserves key establishment with the same horizon.

Runs where you decide

License it onto your own infrastructure, take a gateway we ship configured, or let us host it. For most operational networks the first option is the only one that passes review.

What you can show

The four questions about an operational site

Regulators and internal audit come back to the same ground. The console answers without a collection exercise.

Q1

Is the operational network really separated?

Gateways, VLANs and the edges between them, each one way, two way, disabled or zero trust, drawn rather than described.

Q2

What is allowed on removable media?

The company policy rules, signed and applied on the device, with the state visible per machine.

Q3

Who reached the site, and from what?

User profiles, devices and one certificate per gateway membership, with a CSV export for the file.

Q4

Are the controls checked?

Assessments per gateway return pass, fail, partially satisfied or not tested, next to a risk score built from 19 indicators.

One caveat for isolated networks. A green confirmation means the change was recorded. A gateway that was offline applies it on reconnect, which on an operational network can be the next maintenance window.

Where it stops

What this does not do on the grid

Energy attracts wide promises. The boundary of this one is narrow and worth stating.

Protection and control equipment

Relays, controllers and their firmware are untouched. This protects the network around them and the devices people carry in.

Physical and operational safety

Safety systems, permits and the engineering behind them belong to other disciplines.

Nobody is watching for you

QuantumNova is a product, not a managed service. The score and the evidence are produced for your people to read.

It does not certify you

The platform helps you answer NIS2 and regulator questions with evidence. Sufficiency is an auditor’s decision.

Start with the site that cannot go to the cloud

If the answer to every tool has been no because the management layer lives outside, that is the useful place to test this. A demonstration is free.

NEWSLETTER

Get weekly tips, product news and early access, straight to your inbox.

Scroll to Top