In substations, power plants and control centres, cybersecurity is now firmly on the agenda.
But from OMICRON’s experience working with utilities across live operational technology (OT) environments, focusing on cyber threats alone often overlooks a more immediate challenge – how these systems actually behave in day-to-day operation.
What the electrical testing and diagnostics specialist consistently observes is that the most significant risks are not always advanced cyberattacks. More often, they are hidden operational issues – misconfigurations, inconsistencies, and visibility gaps – that build up over time and only surface under stress.
Across multiple deployments in substations and control networks, a clear pattern emerges. Cyber risk and operational performance are tightly linked and treating them separately creates blind spots.
“In our experience, the most critical risks in power system OT environments are rarely the ones you are actively looking for, but the ones you cannot yet see,” said Amro Mohamed, OMICRON’s Cybersecurity Lead.
The unseen risk
Most OT systems are well engineered and validated during commissioning. Architectures are defined, communication flows are documented, and configurations are tested against the intended design.
However, once systems are in operation, they evolve. Devices are replaced, settings are adjusted, remote access is introduced, and multiple teams interact with the same network over time.
This is not unusual, but it is rarely reassessed, often because nothing appears obviously wrong.
When utilities gain better visibility into network behaviour, the findings are often unexpected, particularly during post‑incident reviews or routine validation exercises. Not necessarily cyber incidents, but gaps; devices communicating in unexpected ways, undocumented connections, and configurations that no longer reflect engineering intent.
Hiding in plain sight
Many of the most impactful risks encountered are operational rather than purely cyber, and are often revealed when utilities gain better visibility into how OT communications behave in practice.
Inconsistent VLAN configurations can affect the delivery of critical messages across the network. Mismatches between RTUs and IEDs can result in missing or unreliable data at SCADA level. Differences between system configuration files and live systems can lead to communication failures that are difficult to trace.
Time synchronisation is another recurring issue. Even small deviations can complicate event analysis and delay fault investigations when precise timing is essential.
Individually, these issues may appear manageable. Together, they create a fragile operating environment – one that performs under normal conditions but becomes unpredictable during disturbances.
Operational discipline
While external threats often dominate the discussion, many vulnerabilities originate within the network itself.
Untracked devices, undocumented external connections, and unnecessary services all increase exposure. Insufficient network segmentation further amplifies risk, allowing issues to propagate more easily across systems.
In OMICRON’s experience, these conditions are rarely the result of poor design, but of gradual change without continuous validation. This is where operational discipline and cybersecurity become inseparable. This is especially true where IT and OT responsibilities overlap but are not fully aligned.
From visibility to resilience
The turning point for many utilities is gaining visibility into real system behaviour.
With that visibility, the approach shifts from reactive troubleshooting to proactive improvement. Instead of addressing isolated issues, teams can identify and resolve systemic weaknesses before they impact operations.
Many of the most effective improvements are straightforward: removing unnecessary services, validating configurations, tightening access, and maintaining accurate asset visibility.
These actions improve not only cybersecurity posture, but also operational reliability and confidence in system performance.
Resilience requires both perspectives
The key takeaway is simple: in modern power system OT environments, cyber and operational risks cannot be separated.
Utilities that continue to treat them independently will face increasing challenges as systems become more complex. Those that integrate both perspectives will be better positioned to maintain reliability, manage risk, and meet evolving expectations.
Ultimately, resilience is not defined by system design alone. It is defined by how systems perform in the real world, especially under pressure.
For utilities looking to better understand their current OT risk exposure, starting with visibility into real network behaviour is often the most effective first step.
For more information, visit www.omicroncybersecurity.com
This article appears in the May/June 2026 edition of Utility. Subscribe HERE.




