SCYTHE 5.3 Released  Read More
Real-World Testing at Electric Substations: A SCYTHE Case Study

Case Study | OT / ICS

Electricity is one of the foundations of modern society: without it, we are on our way to the Stone Age pretty quickly. Defending it is key to assuring we don’t have to, but this is easier said than done. As covered in our post on how to conduct safe and realistic testing in OT, it takes careful planning to move testing into OT, let alone into lower-level operational processes. But we need to explore this scope because it is surface area for adversarial action and ultimately what we need to defend. Employing a defensive control here is not the same as proving it works. This case study shows how adversarial testing inside electric substation production environments validates whether OT cybersecurity architecture performs as intended.

Scope

Adversarial testing in electric substation production environments.

Validate the Architecture, Not Just the Technique

Defensible architecture is the primary defense in OT because endpoint vulnerabilities can be difficult to address, and that’s assuming a patch is even available. I gave a talk at S4 this year, OT Asset Visibility is Overrated, to help asset owners prioritize visibility while building a defensible architecture. The primary objective in this case study is not simply to emulate adversary behavior. It is to validate whether cybersecurity architecture, visibility strategy, segmentation model, and defensive capabilities are performing as intended within real operational environments.

Start With the Attack Path

The approach begins by identifying realistic attack paths and adversary opportunities within the OT environment. It draws on multiple sources of intelligence and architectural context, including network architecture, segmentation boundaries, firewall policy, asset inventories, operational criticality, and threat intelligence.

Emulate Adversaries Safely Inside Production

Once high-value attack paths are identified, purpose-built SCYTHE agents deployed within production OT environments safely emulate adversary activity representative of those paths.

Rather than focusing solely on endpoint-centric testing, SCYTHE agents are positioned to represent the systems and trust relationships that exist within substations, control centers, and supporting OT infrastructure. These agents execute adversary techniques while measuring the effectiveness of existing detection, monitoring, segmentation, and response capabilities.

Production, Not the Lab

A key aspect of the program is that testing occurs within operational environments rather than isolated labs. This allows actual performance evaluation of cybersecurity controls, instead of a simulation, digital twin, or cyber range, against the complexity, constraints, and architectural realities of production OT systems.

The Questions Testing Answers

▪   Can the architecture detect adversary movement across identified attack paths?

▪   Are segmentation boundaries performing as expected?

▪   Do visibility platforms provide sufficient context to understand adversary actions?

▪   Can the cybersecurity stack observe activity occurring near operational crown jewels?

▪   Are there architectural blind spots, implicit trust relationships, or monitoring gaps that reduce the ability to respond effectively?

Results That Inform Design Decisions

The output is not simply a list of successful or unsuccessful techniques. The results assess architectural effectiveness, validate defensive investments, identify visibility gaps, prioritize detection engineering efforts, and inform future cybersecurity design decisions.

The focus is on understanding whether an adversary can achieve meaningful operational objectives, and whether defenses increase the cost, complexity, and likelihood of detection along that path.

From Compliance to Continuous Capability Assessment

This methodology has become an important component of a broader OT cybersecurity program. It supports a transition from compliance-oriented validation toward continuous cybersecurity capability assessment.

By combining architecture analysis, attack path identification, adversary emulation, and operational feedback, the program evaluates cybersecurity defenses in a manner that more closely reflects how sophisticated threat actors would approach critical infrastructure environments.

Rather than asking whether a control is deployed, analysis can evaluate whether it materially changes attacker opportunity, improves observability, or constrains movement toward critical operational assets.

Connecting Intelligence, Architecture, and Controls

One of the most valuable outcomes has been the ability to directly connect threat intelligence, architecture decisions, and defensive controls. Measuring whether a control changes what an attacker can do provides a more meaningful measure of cyber resilience than traditional control validation alone.

OT / ICS Security

Prove Your OT Defenses in Production

See how SCYTHE safely emulates adversaries inside substations, control centers, and supporting OT infrastructure.

Request a demo

References

▪   How Low Can You Go, Bryson Bort and Ian Anderson, SANS. Watch on YouTube

▪   Multiverse of Convergence: Charting IT/OT Threat Overlap, Bryson Bort and Tim Shulz, SANS. Watch on YouTube

▪   UniChat Episode 1, Bryson Bort and Megan Samford, SCYTHE. Watch on YouTube

▪   Beachhead Access in Industrial Control Systems, Megan Samford, SCYTHE, July 2021. The original post is cited in Prioritizing ICS Beachhead Systems for Cyber Vulnerability Testing, Idaho National Laboratory, March 2022. Read the paper (PDF)