SOC for energy providers and critical infrastructures
Energy providers, water utilities and grid operators carry a double responsibility: data protection under revFADP (revised Federal Act on Data Protection) and supply continuity under StromVG and ISG. A SOC for critical infrastructure monitors IT and OT (control systems, SCADA, remote control) and reports cyber incidents to the National Cyber Security Centre (NCSC) within 24 hours. The core risk is loss of supply. See [SOC as a Service Switzerland](/en/soc/soc-as-a-service-switzerland) for details of the framework and operating model.
Scope: SOC vs control-system vendor support vs classical industrial SOC
Vendor support for control systems (ABB, Siemens, Hitachi Energy and others) maintains system availability and configuration. The SOC monitors security-relevant signals across the whole IT-to-OT chain and takes over detection and response. Traditional industrial SOCs for manufacturing share many patterns (see SOC for manufacturing). Energy providers face additional oversight and must prioritise supply continuity.
An IT outage is unpleasant. A loss of supply is an event of national interest. The SOC has to keep the difference visible at all times.
What has to be monitored
- Control technology and SCADA: process control systems, RTUs, remote control stations, historian.
- Remote-maintenance access from vendors and service providers; often long-lived and weakly monitored.
- Corporate IT close to OT: engineering workstations, MES, data exchange zones, DMZ.
- Identity and access systems, including OT accounts with exception rules.
- Network gateways to neighbouring utilities, exchange connections and market processes.
Regulation for Swiss utilities
- ISG: operators of critical infrastructure (including energy and water supply) report cyber incidents to the National Cyber Security Centre (NCSC) within 24 hours. They must also register with the NCSC. See SOC and ISG reporting.
- StromVG and BFE/ElCom ordinances: supply security and grid stability as protection goals; cyber incidents are increasingly addressed as part of those duties.
- revFADP (revised Federal Act on Data Protection): customer and meter data is personal data; a high-risk incident triggers notification to the FDPIC as soon as possible. See revFADP and SOC.
- The BWL ICT minimum standard for electricity providers serves as a reference for controls and evidence. A SOC puts the monitoring and response requirements into practice.
- Under NIS2, Swiss subsidiaries in the EU can qualify as essential entities and then face EU reporting duties. See NIS2 for Swiss subsidiaries.
Effective detection and response at utilities
- Network segmentation with Zero Trust principles; see Zero Trust and SOC. OT enclaves, brokers for remote maintenance, documented exception lists with expiry.
- Passive OT monitoring (NDR) plus IT EDR; no active agents on control systems without vendor approval. See NDR.
- Threat hunting on vendor and supply-chain signals; historical attacks on utilities went through trusted software and remote maintenance. See Threat hunting Switzerland and Supply-chain attacks.
- Codify the 24h reporting duty into the SOC playbook: detection, assessment, the National Cyber Security Centre (NCSC) form, follow-up communication. See Incident response plan.
- Exercises with crisis staff and grid control: tabletop scenarios switching between IT outage, OT outage and regulatory communication.
Attacks rarely land directly on control systems. They come via a compromised maintenance laptop from a service provider, an updated engineering tool or a phishing email to a grid planner. The SOC therefore sees attacks first on the IT side through identity, EDR and email security, long before OT is affected.
Legal basis and sources
- ISG (SR 128), Art. 74a-74f: Fedlex
- Cybersecurity Ordinance (CSV, SR 128.51): Fedlex
- ISG reporting duty at the National Cyber Security Centre (NCSC) including routing: bacs.admin.ch
- Reporting data security breaches to the FDPIC: edoeb.admin.ch
Frequently asked questions
May the SOC actively intervene in the control system?
The SOC requires explicit approval from grid control and the vendor before intervening in the control system. Active response takes place outside the control system: the SOC blocks accounts, cuts remote maintenance sessions and isolates IT segments.
How fast does a utility have to report an incident?
Under ISG, utilities must report incidents to the National Cyber Security Centre (NCSC) within 24 hours. If an incident involving personal data poses a high risk, they must also notify the FDPIC as soon as possible. The clock starts when the operator becomes aware.
How is vendor remote maintenance controlled?
Brokers control access through MFA, time windows, session recording and automatic revocation after maintenance. The SOC monitors logins, executions and data movements.
Does a co-managed model fit a utility?
A co-managed model fits a utility very well. The internal team knows the grid and processes; the external SOC partner brings 24/7 detection, rules and threat intelligence. See [Co-managed SOC](/en/soc/co-managed-soc).
What does a SOC typically cost for a Swiss utility?
Costs depend on the number of sites and systems, the OT share and additional duties. See [SOC cost Switzerland](/en/soc/soc-cost-switzerland) for cost ranges.
Related terms
- NIS2 NIS2 is a European Union directive setting minimum cybersecurity requirements for important and essential entities.
- Incident Response Incident Response is the structured process of containing, eradicating, and recovering from a security incident.
- SOCaaS SOC as a Service (SOCaaS) is a SOC operated by an external provider and delivered as an ongoing service.
- Ransomware Ransomware is malicious software that encrypts data and demands a ransom for decryption.
- Supply Chain Attack A supply chain attack targets an organisation through a trusted supplier, software, or service provider with access.