Skip to content
CISO Marketplace Services

Energy Sector Security Program

Comprehensive security assessment for energy sector infrastructure, including power generation, distribution systems, and grid security.

In scope

  • Power generation security
  • Distribution system assessment
  • Smart grid protection
  • SCADA system testing
  • Nuclear facility security
  • Renewable energy systems

You receive

  • Energy sector security architecture
  • Grid protection framework
  • SCADA security analysis
  • Regulatory compliance documentation
  • Emergency response procedures

Tiers

Choose the depth.

Core Energy Security Assessment

$95K

One generation or distribution site with up to 250 OT/SCADA assets: architecture review, passive network assessment, SCADA configuration review and IT/OT segmentation testing. No active testing on live control systems.

Sites
1
internal hosts
250
  • OT asset inventory and architecture review
  • Passive SCADA network assessment
  • IT/OT segmentation testing
  • SCADA configuration and remote access review
  • Emergency response procedure review
  • — Smart grid and distribution automation analysis
  • — Active testing of control systems
  • — Compliance documentation
  • — Nuclear facilities
Scope Core Energy Security Assessment

Advanced Energy Security Program

$165K

Up to 3 sites and up to 1,000 OT/SCADA assets: everything in the basic tier, distribution and smart grid analysis, active SCADA testing in maintenance windows or test environments, renewable systems review and a grid protection framework.

Sites
3
internal hosts
1000
  • Everything in the basic tier
  • Distribution system and smart grid assessment
  • Active SCADA testing in agreed windows
  • Renewable energy system review
  • Grid protection framework and compliance documentation
  • — Custom tooling
  • — Monitoring after delivery
  • — Nuclear facilities
  • — More than 3 sites
Scope Advanced Energy Security Program

Enterprise Energy Security Solution

$250K

Full-scope energy security with custom tools, continuous monitoring, and complete compliance management

Sites
8
  • — Remediation engineering or control system replacement
  • — Physical security guarding
Scope Enterprise Energy Security Solution

Members: engagement coupons from the CISO Marketplace coupon book apply to services. There is no blanket discount.

What's inside this engagement

Phase by phase.

How a security assessment engagement runs, what happens in each phase and what you see. Exact scope, tier and timeline are fixed in your proposal and SOW.

  1. 01Scoping

    Systems, sites, stakeholders and the question the assessment must answer.

    You see · Your objectives and constraints.

  2. 02Discovery & evidence

    Documents, configurations and interviews, plus technical testing where the service includes it.

    You see · Access and time with key people.

  3. 03Analysis

    Findings rated by risk to your business, not by a generic score.

    You see · A prioritized view of your risk.

  4. 04Report & debrief

    Executive summary, findings and a remediation roadmap, walked through with your team.

    You see · The report and the debrief.

Commercials

From first call to final report.

  1. 01

    Scoping call

    A practitioner, not a salesperson, walks through targets, constraints and what a good outcome looks like for you.

  2. 02

    Proposal & rules of engagement

    A fixed-scope proposal with tier, price and deliverables. Rules of engagement, contacts and out-of-bounds systems are agreed in writing.

  3. 03

    Sign, then start

    MSA and SOW are signed electronically and the deposit is paid. Only then does testing begin.

  4. 04

    Execution

    Testing runs to the agreed plan. Critical findings are escalated as they are found; you don't wait for the report.

  5. 05

    Report & debrief

    An executive summary plus technical findings with evidence, reproduction steps and fixes, walked through with your team.

  6. 06

    Retest

    Where the tier includes it, we verify your fixes and reissue the report, so auditors and customers see the issues closed.

Timelines are set per engagement in the SOW.

Related

Research

Latest from the blog

All posts on cisomarketplace.com →
Talk to an advisor
Advisor