Published assessments of utility cybersecurity through 2025 describe estates in which long-lived operational equipment sits alongside modern IT, with remote access, legacy protocols and limited segmentation recurring as findings.
The Remediation Advice Does Not Fit The Asset
Standard guidance assumes a maintenance window: apply the update, restart, verify. A substation controller, a pump station RTU or a protection relay does not have one. It was commissioned to run continuously for twenty or thirty years, and taking it out of service means taking supply out of service.
Very often no update exists — the vendor no longer supports the product, or no longer exists. The equipment is not unpatched through neglect. It is unpatchable, in a way the software-side argument at 26-0405 only approximates.
Which Makes Segmentation The Only Real Control
If the device cannot be fixed, the answer has to be limiting what can reach it. That is an architecture programme — physical separation, brokered access, monitored one-way paths — funded by a regulated utility on a rate base approved by a public authority.
It competes directly with visible spending on supply reliability and consumer prices, which is the funding structure filed at 26-0729 and 25-0918. The security case has to be made to a regulator whose mandate is affordability.
And The Threat Is Patient By Design
The pre-positioning activity at 25-0522 targets precisely this estate, and does so because the estate cannot change quickly. An adversary that establishes access to equipment with a twenty-year replacement cycle has made an investment with a very long return.
Graded medium: the structural findings are consistent across the assessments we reviewed, which are vendor-published and reflect the populations their products observe.
Built on published sector assessments, listed below, which are vendor research and subject to the telemetry-bias caution at 26-0513. Corrections: corrections@forensicpost.com.