Vertical

SOC for energy providers and critical infrastructures

Energy providers, water utilities and grid operators carry a double responsibility: data protection under revFADP (revised Federal Act on Data Protection) and supply continuity under StromVG and ISG. A SOC for critical infrastructure monitors IT and OT (control systems, SCADA, remote control) and reports cyber incidents to the National Cyber Security Centre (NCSC) within 24 hours. The core risk is loss of supply. See [SOC as a Service Switzerland](/en/soc/soc-as-a-service-switzerland) for details of the framework and operating model.

All

Scope: SOC vs control-system vendor support vs classical industrial SOC

Vendor support for control systems (ABB, Siemens, Hitachi Energy and others) maintains system availability and configuration. The SOC monitors security-relevant signals across the whole IT-to-OT chain and takes over detection and response. Traditional industrial SOCs for manufacturing share many patterns (see SOC for manufacturing). Energy providers face additional oversight and must prioritise supply continuity.

Short version

An IT outage is unpleasant. A loss of supply is an event of national interest. The SOC has to keep the difference visible at all times.

What has to be monitored

  • Control technology and SCADA: process control systems, RTUs, remote control stations, historian.
  • Remote-maintenance access from vendors and service providers; often long-lived and weakly monitored.
  • Corporate IT close to OT: engineering workstations, MES, data exchange zones, DMZ.
  • Identity and access systems, including OT accounts with exception rules.
  • Network gateways to neighbouring utilities, exchange connections and market processes.

Regulation for Swiss utilities

  • ISG: operators of critical infrastructure (including energy and water supply) report cyber incidents to the National Cyber Security Centre (NCSC) within 24 hours. They must also register with the NCSC. See SOC and ISG reporting.
  • StromVG and BFE/ElCom ordinances: supply security and grid stability as protection goals; cyber incidents are increasingly addressed as part of those duties.
  • revFADP (revised Federal Act on Data Protection): customer and meter data is personal data; a high-risk incident triggers notification to the FDPIC as soon as possible. See revFADP and SOC.
  • The BWL ICT minimum standard for electricity providers serves as a reference for controls and evidence. A SOC puts the monitoring and response requirements into practice.
  • Under NIS2, Swiss subsidiaries in the EU can qualify as essential entities and then face EU reporting duties. See NIS2 for Swiss subsidiaries.

Effective detection and response at utilities

  1. Network segmentation with Zero Trust principles; see Zero Trust and SOC. OT enclaves, brokers for remote maintenance, documented exception lists with expiry.
  2. Passive OT monitoring (NDR) plus IT EDR; no active agents on control systems without vendor approval. See NDR.
  3. Threat hunting on vendor and supply-chain signals; historical attacks on utilities went through trusted software and remote maintenance. See Threat hunting Switzerland and Supply-chain attacks.
  4. Codify the 24h reporting duty into the SOC playbook: detection, assessment, the National Cyber Security Centre (NCSC) form, follow-up communication. See Incident response plan.
  5. Exercises with crisis staff and grid control: tabletop scenarios switching between IT outage, OT outage and regulatory communication.
What utilities often underestimate

Attacks rarely land directly on control systems. They come via a compromised maintenance laptop from a service provider, an updated engineering tool or a phishing email to a grid planner. The SOC therefore sees attacks first on the IT side through identity, EDR and email security, long before OT is affected.

Legal basis and sources

  • ISG (SR 128), Art. 74a-74f: Fedlex
  • Cybersecurity Ordinance (CSV, SR 128.51): Fedlex
  • ISG reporting duty at the National Cyber Security Centre (NCSC) including routing: bacs.admin.ch
  • Reporting data security breaches to the FDPIC: edoeb.admin.ch

Frequently asked questions

May the SOC actively intervene in the control system?

The SOC requires explicit approval from grid control and the vendor before intervening in the control system. Active response takes place outside the control system: the SOC blocks accounts, cuts remote maintenance sessions and isolates IT segments.

How fast does a utility have to report an incident?

Under ISG, utilities must report incidents to the National Cyber Security Centre (NCSC) within 24 hours. If an incident involving personal data poses a high risk, they must also notify the FDPIC as soon as possible. The clock starts when the operator becomes aware.

How is vendor remote maintenance controlled?

Brokers control access through MFA, time windows, session recording and automatic revocation after maintenance. The SOC monitors logins, executions and data movements.

Does a co-managed model fit a utility?

A co-managed model fits a utility very well. The internal team knows the grid and processes; the external SOC partner brings 24/7 detection, rules and threat intelligence. See [Co-managed SOC](/en/soc/co-managed-soc).

What does a SOC typically cost for a Swiss utility?

Costs depend on the number of sites and systems, the OT share and additional duties. See [SOC cost Switzerland](/en/soc/soc-cost-switzerland) for cost ranges.

Continue reading in this cluster
SOC as a Service in Switzerland: The Complete Guide
SOC as a Service is an externally operated Security Operations Center that monitors your environment around the clock, detects attacks and triggers the response. According to Mandiant M-Trends 2026, attackers went undetected for a median of 14 days in 2025. With a SOC that detects and assesses around the clock, typical detection time becomes much shorter.
SOC & ISG: The 24-hour cyber-incident reporting duty in Switzerland
Since 1 April 2025, the Swiss Information Security Act (ISG, SR 128, Art. 74a-74f) imposes a cyberattack reporting duty on critical infrastructure operators. Operators must report cyberattacks to the National Cyber Security Centre (NCSC) within 24 hours of detection. Operators need 24/7 detection and documented response processes to meet this deadline reliably. A SOC delivers these two building blocks.
SOC for manufacturing: monitoring IT and OT together
During an incident, manufacturers lose production, not data. A SOC for manufacturing monitors the IT network and OT environment (PLC, HMI, legacy systems). It stops ransomware before the production line goes down. The core risk is not encryption; it is downtime.
Zero Trust and SOC: from principle to effective detection
Zero Trust is an architecture principle, not a product category. No network, device or account is trusted implicitly, and every request is continuously authenticated and authorised. For the principle to work you need a SOC that correlates identity, device and network signals and detects violations of the defined policies. Without detection Zero Trust stays a diagram; without a Zero Trust foundation the SOC runs in circles. Frame and operating model in detail on [SOC as a Service Switzerland](/en/soc/soc-as-a-service-switzerland).
Supply-chain attacks: when the supplier becomes the entry point
Supply-chain attacks do not target the organisation directly but a service provider, a software update or a library in the supply chain. Cases such as SolarWinds, 3CX or XZ-Utils show that attacks often take effect weeks to months later, simultaneously across many target environments. For Swiss organisations, detection in their own SOC matters most, alongside prevention through vendor risk management, SBOM and signature verification. The SOC detects suspicious activity from legitimate software and segments third-party access. During an incident, it identifies which impacts trigger notification duties under revFADP (revised Federal Act on Data Protection), FINMA and ISG.