Technical brochure
TB 990 WG D2.51

Implementation of Security Operations Centers (SOC) in the Electric Power Industry as Part of the Situational Awareness System

The electric power industry is undergoing a rapid digital transformation. Smart grids, digital substations, distributed energy resources, advanced metering infrastructure, and the convergence of Information Technology (IT) with Operational Technology (OT) are dramatically expanding the cyberattack surface. Ransomware incidents targeting utilities are rising sharply, and nation-state actors are explicitly targeting energy infrastructure. In this context, Security Operations Centers (SOCs) have evolved from a corporate IT function on the periphery of the utility into a central element of situational awareness — sitting alongside, and increasingly integrated with, the control room. CIGRE Working Group D2.51 [1] has produced a Technical Brochure to help utilities design, implement, and mature these capabilities, drawing on a global survey of 84 professionals across 28 countries and on case studies from five regions.

Members

Convenor (IT)

Yoseph Shneck

J. Hong (US), A. Soares (BR), C. Courtney (NZ), R. Silva (BR), P. Chiewcharat (TH),Y. Schneck (IL), A. Bregar (SI), A. Sengupta (IN)

Introduction

Cybersecurity has moved from a back-office concern to a board-level priority for utilities. CIGRE Working Group D2.51 [1] was established to take stock of how utilities around the world are actually building, running, and maturing their Security Operations Centers, and to capture what is working, what is not, and where the field is heading.

The Working Group asked a deceptively simple question: what does a fit-for-purpose SOC for an electric utility look like in 2025, and what will it have to look like for the rest of the decade? Answering it required combining three perspectives that are rarely brought together in one document: the regulatory perspective (what is being mandated, where, and how fast), the architectural and technological perspective (what platforms, capabilities, and integration patterns are emerging), and the operational and human perspective (what processes, team structures, and skills make a SOC actually effective).

The Technical Brochure draws on a global survey of 84 cybersecurity and operations professionals across 28 countries, case studies of utility SOC implementations in five regions, and a review of the standards landscape spanning IEC, ISO, IEEE, NIST [5], NERC CIP [3], and NIS2.

The 2024–2025 inflection point

Several previously parallel trends are now intersecting. The regulatory environment is tightening fast: NERC CIP-015-1 [2] (Internal Network Security Monitoring) was approved in June 2025 and requires monitoring of internal “East–West” OT traffic, fundamentally shifting the paradigm from perimeter-only security to a detect-and-respond framework. CIP-003-9 expands governance for low-impact Bulk Electric System Cyber Systems. In Europe, the NIS2 Directive [4] is accelerating SOC adoption: NIS2 adopters in the survey report the lowest incident rates (8 per year on average) and the fastest detection times (4 hours) of any group studied.

 

Architectures are shifting toward cloud and hybrid models even as data sovereignty and OT-safety concerns pull in the opposite direction. Artificial Intelligence and Machine Learning have moved from the margins to the mainstream of SOC operations — overall AI/ML adoption stands at 61.9%, with North America leading at 85.7% and Europe at 58.1% (Figure 1) — while the engineering community is, quite reasonably, asking hard questions about model assurance and human-in-the-loop design in safety-critical contexts.

Figure 1 — AI/ML adoption in utility SOCs across regions

Source: D2.51 WG Survey

SOC adoption, architecture, and the IT–OT integration gap

SOC adoption in the electric power sector is now near-universal at 95.2%, but maturity is uneven: only 29.8% of surveyed SOCs have been operational for more than five years. Utilities deploy centralized, distributed, or hybrid SOC architectures, and the choice depends on size, geography, regulatory environment, and operational needs. The current split between deployment models is 62% on-premise, 18% cloud-based, and 20% hybrid.

The single largest practical gap — and the single largest opportunity — lies in IT–OT integration. Only 26.2% of utilities run truly converged IT–OT security operations, with significant regional variation: 50% in Latin America, 38.1% in Asia-Pacific, and 14% in Europe. The utilities that have achieved full integration consistently report markedly better detection and containment performance.

Figure 2 —  Cloud vs On-Premise vs Hybrid

Source: D2.51 WG Survey

Figure 3 —  Key Survey Statistics: SOC in Electric Utilities

Source: D2.51 WG Survey

Core technologies and operational performance

Modern utility SOCs rely on a layered technology stack. Security Information and Event Management (SIEM) platforms are nearly universal at 95.2% adoption, but only 28% have integrated AI-driven analytics — pointing to a clear maturation path. Endpoint and Extended Detection and Response (EDR/XDR) is at 78%, Threat Intelligence Platforms at 48%, Network Detection and Response at 45%, Security Orchestration, Automation and Response (SOAR) at 38%, and User and Entity Behavior Analytics at 35%.

ELECTRA, is the digital magazine of CIGRE, you can obtain access as part of a CIGRE membership. Find out more about joining options here.

Already have an accountSign in

Join

D2

Information systems telecommunications and cybersecurity

This Technical Brochure has been created by a Working Group from the CIGRE Information systems telecommunications and cybersecurity Study Committee which is one of CIGRE's 16 domains of work.
D2 provides guidance, shares knowledge, and develops best practices and publications for the application of information technology to the critical and core business systems in the electricity supply chain, including smart meters, asset performance monitoring and management, energy management systems (EMS), internet of things (IoT) and machine learning/ big data.

Learn more
Top of page