Securing the systems the grid, the pipeline, and the public depend on
OT/ICS monitoring, converged physical security, and audit-ready compliance governance for electric utilities, pipeline and rail operators, water systems, and generation facilities — operated across Verity, Core, Sentry, and Citadel.
Oil & gas pipelines
Rail & surface transportation
Water & wastewater systems
Generation & nuclear facilities
Downtime isn’t an inconvenience — it’s a public safety event
Electric utilities, pipeline operators, rail systems, and water utilities sit at the intersection of OT, physical infrastructure, and overlapping federal regulation. A control-system intrusion or unsecured substation can cascade into grid instability, environmental release, or loss of essential service. AI and remote operations tools expand the attack surface further. Armorstack treats cyber and physical layers as one problem — because attackers already do.
Five frameworks every critical-infrastructure operator should know
These are the real, named standards that govern OT/ICS and physical security for critical infrastructure — not generic best practice, but the actual frameworks regulators and auditors will hold you to.
NERC CIP
The North American Electric Reliability Corporation’s Critical Infrastructure Protection standards are the mandatory, FERC-enforceable cybersecurity and physical security requirements for owners and operators of the Bulk Electric System. The current CIP standard set runs from CIP-002 (BES Cyber System categorization) through newer additions like CIP-013 (supply chain risk management), CIP-014 (physical security of transmission stations and control centers), and CIP-015 (internal network security monitoring). CIP-003-9, tightening requirements for lower-impact environments, becomes enforceable April 1, 2026.
Source: North American Electric Reliability Corporation (nerc.com/standards)TSA Security Directives
Following the 2021 Colonial Pipeline ransomware attack, the Transportation Security Administration issued Security Directives requiring pipeline and LNG facility operators to report cyber incidents, name a cybersecurity coordinator, and test contingency plans — most recently updated in 2023 as SD Pipeline-2021-02D. In November 2024, TSA proposed a rule to make these requirements permanent regulation and extend comparable cyber risk-management obligations to rail and other surface transportation operators.
Source: Transportation Security Administration (tsa.gov/sd-and-ea); Federal Register, Nov. 7, 2024CISA’s 16 Critical Infrastructure Sectors
Under Presidential Policy Directive 21, the Cybersecurity and Infrastructure Security Agency coordinates 16 designated critical infrastructure sectors — including Energy, Transportation Systems, and Water and Wastewater Systems — each assigned a federal Sector Risk Management Agency. This framework drives information sharing and risk coordination; binding compliance obligations still flow from your sector’s actual regulator (NERC/FERC, TSA, EPA, etc.).
Source: Cybersecurity and Infrastructure Security Agency (cisa.gov/topics/critical-infrastructure-security-and-resilience)NIST SP 800-82 Rev. 3
Published by NIST in September 2023 and retitled “Guide to Operational Technology (OT) Security” (from “Guide to Industrial Control Systems Security”), this guidance covers SCADA, distributed control systems, PLCs, and building automation. It organizes protection into 19 control families mapped to the NIST Cybersecurity Framework’s Identify, Protect, Detect, Respond, and Recover functions.
Source: National Institute of Standards and Technology, NIST SP 800-82r3 (csrc.nist.gov)IEC 62443
Developed jointly by the International Electrotechnical Commission and ISA (as ISA/IEC 62443), this international standards series addresses security across the full lifecycle of industrial automation and control systems — asset owners, system integrators, and product suppliers alike. It defines a zones-and-conduits architecture model, four Security Levels (SL 0–4), and seven Foundational Requirements. In 2021, IEC recognized it as a horizontal standard applicable across sectors including energy, water, and transport.
Source: International Electrotechnical Commission / ISA Global Cybersecurity Alliance (isagca.org)How Armorstack Secures Critical Infrastructure
One converged model, four coordinated portfolios — each mapped directly to the standards above.
Shadow AI and cyber operations, with a 24/7 SOC.
Passive, protocol-aware OT/ICS monitoring across the IT/OT boundary without disrupting uptime — NIST 800-82 / IEC 62443 aligned.
Physical security on the same record as cyber and identity.
Substations, generation sites, pump/compressor stations — supports NERC CIP-014 physical security expectations.
Governance that survives the board and the auditor.
NERC CIP evidence readiness (BES categorization, CIP-013 supply chain, CIP-015 monitoring), TSA directive documentation, AI/remote-ops governance.
Infrastructure that stays observable as AI workloads scale.
Hardened corporate-IT backbone segmented from OT so a phishing incident never becomes a control-system incident.
Critical Infrastructure Security & Compliance Questions
What is NERC CIP and does it apply to my organization?
NERC CIP is the mandatory set of cybersecurity and physical security reliability standards enforced by the North American Electric Reliability Corporation, under FERC oversight, for owners and operators of the Bulk Electric System. If your organization owns or operates BES Cyber Systems — generation, transmission, or control-center assets affecting grid reliability — CIP compliance is very likely mandatory, with FERC-enforceable penalties for violations.
Are TSA Security Directives only for oil and gas pipelines?
Not for long. The original 2021 directives targeted pipeline and LNG facility operators after the Colonial Pipeline attack and were updated in 2023 (SD Pipeline-2021-02D). TSA’s November 2024 proposed rule would formalize these requirements in permanent regulation and extend comparable cyber risk-management obligations to rail and other surface transportation operators — so the scope is actively expanding.
How does IEC 62443 relate to NIST SP 800-82?
They’re complementary. NIST SP 800-82 Rev. 3 is a U.S. government risk-management guide mapped to the NIST Cybersecurity Framework. IEC 62443 is an international standards series with defined Security Levels, a zones-and-conduits model, and role-specific requirements for asset owners, integrators, and suppliers. Most mature OT security programs reference both.
Do the CISA critical infrastructure sectors carry their own compliance requirements?
Not directly. CISA’s 16-sector framework, established under Presidential Policy Directive 21, is a risk-coordination structure — each sector has a federal Sector Risk Management Agency (e.g., DOE for Energy, TSA/DOT for Transportation Systems). Your binding compliance obligations come from your sector’s actual regulator, not from the CISA framework itself.
What’s in the first engagement?
A structured review of your OT/ICS network architecture and segmentation, physical security controls at substations, generation sites, or pump/compressor stations, your NERC CIP or TSA directive documentation and evidence readiness, and detection/response coverage across the IT-OT boundary — benchmarked against the specific standards that apply to your sector.
We’re a smaller municipal utility or co-op — does any of this apply to us?
Yes, though scope varies by BES impact rating (high, medium, or low). Even low-impact BES Cyber Systems carry baseline NERC CIP obligations, and CIP-003-9’s April 1, 2026 enforcement date specifically tightens requirements for lower-impact environments. We right-size the assessment to your actual regulatory footprint rather than over-scoping.