CISA Advisory AA24-038A confirmed Volt Typhoon has pre-positioned inside US electric, water, and communications infrastructure since 2021 — including Texas ERCOT-connected grid operators. Chinese state-linked actors use living-off-the-land techniques designed to evade standard IT security tools. Texas electric co-ops, municipal utilities, generators, and independent power producers face NERC CIP enforcement, FERC Order 887, and imminent CIRCIA mandatory reporting. CoreRecon delivers OT/ICS-aware 24/7 SOC, 30-min NERC CIP-008 incident response SLA, and SDVOSB advantage for public power entities — at $89–$129/endpoint.
Volt Typhoon (also tracked as BRONZE SILHOUETTE) is a Chinese state-sponsored threat actor targeting US critical infrastructure — specifically electric, water, communications, and transportation sectors. Their tradecraft is designed to defeat standard security tools by avoiding custom malware entirely. They use legitimate Windows utilities, compromised edge devices, and SOHO router botnets as infrastructure. Standard SIEM rules don't catch them. Active threat hunting does.
Texas electric utilities operate under more overlapping cybersecurity frameworks than any other sector. NERC CIP-002 through CIP-014 for BES assets, FERC Order 887 for supply chain security, Texas PUC Subst. R. 25.367 for cybersecurity monitoring, ERCOT Nodal Protocols, and CMMC for utilities serving DoD installations. Here's every framework mapped to CoreRecon coverage.
| Framework | Who's in Scope | Key Requirements | Penalty / Consequence | CoreRecon Coverage |
|---|---|---|---|---|
| NERC CIP-002 through CIP-014 | All BES-connected entities: transmission operators, generation operators, distribution utilities with BES-connected assets, co-ops with >100kV facilities | CIP-002: BES asset categorization (High/Medium/Low). CIP-003–CIP-007: Access controls, personnel training, physical security, systems management, incident reporting. CIP-008: Incident response plan + 1-hour initial notification. CIP-013: Supply chain risk management. CIP-014: Physical security of critical substations | Civil penalties up to $1M/day per violation per day. FERC enforcement referrals. NERC audit findings become public record. Repeated violations escalate to Mitigation Plans and DOE notification | Fortress CIP-002 asset inventory, CIP-005 ESP monitoring, CIP-007 security event logging, CIP-008 IR plan + 30-min SLA, CIP-010 configuration management. Command CIP-013 supply chain program, CIP-014 physical perimeter correlation, full audit evidence package |
| FERC Order 887 | Transmission and generation entities subject to NERC CIP; expanded supply chain security obligations effective 2023–2024 | Supply chain risk management for operational technology — software updates, remote access, and third-party vendor controls for BES Cyber Systems. Utilities must identify, assess, and respond to supply chain cybersecurity risks in vendor contracts and software procurement | FERC enforcement; non-compliance with CIP-013 (which implements Order 887) carries same $1M/day penalty structure as other NERC CIP violations | Fortress Vendor access management (JIT provisioning), session recording for third-party OT access, software integrity verification, OT vendor credential vaulting |
| TSA Security Directive (Pipeline-2021-02C) | Natural gas-fired generation operators with pipeline interconnects; gas transmission operators feeding power plants | 12-hour CISA incident reporting, Cybersecurity Coordinator designation, cybersecurity program review against TSA measures (access control, segmentation, detection, response, recovery). Overlaps with NERC CIP for dual-regulated gas-fired generation facilities | Civil penalties up to $11,904/day. Dual-regulated entities face stacked NERC CIP + TSA exposure for the same incident if notification timelines not met | Sentinel TSA 12-hour CISA notification workflow, Cybersecurity Coordinator function, pipeline-generation interface monitoring |
| Texas PUC Subst. R. 25.367 | All Texas electric utilities under PUC jurisdiction: investor-owned utilities, municipally owned utilities (MOUs), electric co-ops (cooperatives) operating in ERCOT | Cybersecurity monitoring program requirements: utilities must maintain documented cybersecurity monitoring capabilities for their OT and IT systems, report significant cybersecurity events to PUC, and maintain an Incident Response Plan aligned to NIST CSF or equivalent framework | PUC enforcement action; license conditions; public reporting obligation creates reputational exposure in rate case proceedings | Sentinel 24/7 OT/IT monitoring, Texas PUC incident reporting support, NIST CSF alignment documentation, IRP development and maintenance |
| ERCOT Nodal Protocols — Cybersecurity Provisions | All ERCOT market participants: QSEs, LSEs, generators, transmission operators; ERCOT market operations system access | ERCOT market participant security requirements for market system access, credential management, and incident notification to ERCOT. Market participants must notify ERCOT ISAC of significant cybersecurity events. ERCOT conducts periodic security compliance reviews | Market participant suspension; financial penalties; loss of ERCOT market access; settlements for security-related market disruptions | Fortress ERCOT market system access monitoring, credential anomaly detection, ERCOT ISAC integration, market participant incident notification workflow |
| CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act) | All critical infrastructure entities including electric utilities; CISA rule finalization in process | 72-hour mandatory reporting of significant cybersecurity incidents to CISA; 24-hour reporting for ransomware payments; standardized incident reporting format. Covers IT and OT incidents affecting critical systems | Non-compliance penalties and subpoena authority for CISA. Becomes a mandatory overlay on top of existing NERC CIP-008 and TSA reporting. Utilities face dual-clock: 1-hour NERC CIP-008 + 72-hour CIRCIA for the same incident | Command Dual-clock incident management (CIP-008 + CIRCIA), pre-built CIRCIA notification templates, 30-min SLA ensures analyst-on-call before any regulatory clock pressure |
| CMMC Level 2 (DoD Installations) | Electric utilities serving Fort Cavazos, JBSA, Fort Bliss, NAS Corpus Christi, and other Texas DoD installations; utilities with DoD contracts for installation power | CMMC Level 2: 110 NIST SP 800-171 practices across 14 domains. Applies to utilities handling Controlled Unclassified Information (CUI) in their DoD-connected operations. Utility IT systems that interface with DoD installation infrastructure may be in scope | CMMC certification required for DoD contract renewals (Nov 2026 enforcement). Utilities that lose DoD contracts due to CMMC non-compliance lose installation power revenue. SPRS score visible to DoD contracting officers | Fortress CMMC Level 2 gap assessment, NIST 800-171 control implementation, SPRS scoring, SSP and POA&M artifacts. SDVOSB status provides contracting advantage for DoD utility work |
Generic MSSPs handle IT security. ERCOT grid operators need OT/ICS coverage, NERC CIP audit evidence, and analysts who understand industrial control system protocols — not IT generalists learning what DNP3 means during an active incident. CoreRecon closes that gap.
A typical MDR deployment monitors Windows event logs, EDR telemetry, and network flow data. In an electric utility, that covers less than 40% of the attack surface. Distribution SCADA, substation automation (IEC 61850 GOOSE messages, Sampled Values), RTUs polling via DNP3, and historian replication traffic are all invisible to standard tooling.
Volt Typhoon specifically targets the gap between IT and OT visibility. They achieve initial access on internet-facing devices, move laterally through IT, and pre-position on OT-adjacent systems — all using legitimate tools that generate no standard alerts. Detecting this tradecraft requires baseline behavioral analysis across both IT and OT, combined with active threat hunting for LOTL indicators specific to energy sector intrusions.
CoreRecon deploys passive NTA sensors at the Electronic Security Perimeter (ESP) boundaries defined under NERC CIP-005. We build OT asset inventories aligned to CIP-002 categorization. We monitor DNP3, IEC 61850, and Modbus traffic for anomalies. And we hunt for Volt Typhoon LOTL indicators — not just wait for antivirus to fire.
These are composite incident patterns based on documented attack types affecting Texas and US electric utilities. No specific client names are disclosed. These patterns reflect the types of engagements and findings CoreRecon is operationally positioned to address.
10-endpoint minimum. Month-to-month. Designed for co-ops, municipal utilities, generators, and IPPs without dedicated security teams — and scaled to enterprise-grade NERC CIP requirements. Use the endpoint cost calculator to model your specific environment.
OT monitoring pricing depends on substation count, SCADA nodes, and ESP boundary topology. An OT network assessment is included in the free posture assessment — we scope sensor placement and asset inventory before quoting OT monitoring. IT/staff endpoint pricing is as listed above. SDVOSB contracting available for IIJA/DOE CESER grant-funded projects.
Yes — but applicability depends on BES (Bulk Electric System) asset classification. NERC CIP applies to assets connected to the BES, which is generally defined as the interconnected electric transmission network above 100kV. Many Texas co-ops and municipal utilities have generation facilities, transmission assets, or distribution substations that qualify as BES-connected. FERC Order 887 and recent NERC BES clarifications have expanded the number of smaller utilities in scope.
Even Low Impact BES facilities must comply with CIP-003-8 (Cyber Security Management Controls including access management and vendor access) and CIP-004-7 (Personnel and Training). The compliance burden is real even for smaller entities. CoreRecon performs a BES applicability assessment during onboarding — we identify which standards apply to which of your assets before building a compliance program.
Both — and the IT/OT boundary monitoring is where Volt Typhoon pre-positioning is detected. Fortress tier deploys passive network traffic analysis (NTA) sensors at your Electronic Security Perimeter (ESP) boundaries, which are required to be defined under NERC CIP-005. These sensors read industrial protocol traffic (DNP3, IEC 61850 GOOSE, Modbus, ICCP) without installing any software on operational PLCs, RTUs, or relay protection devices.
We build an OT asset inventory aligned to NERC CIP-002 BES Cyber Asset categorization during onboarding. The monitoring baseline is established before go-live, so anomalous protocol traffic — like unexpected setpoint commands or unusual historian polling patterns — generates alerts against a known-good baseline rather than generic threshold rules.
NERC CIP audits are evidence-intensive. Auditors want documented proof for every applicable standard — CIP-005 ESP boundary controls, CIP-007 security event logging (R4 requires log review processes), CIP-007-6 patch management records, CIP-008 incident response plan and any documented incidents, CIP-010 configuration baselines. The typical audit preparation process takes 3–6 months when evidence isn't continuously collected.
CoreRecon maintains continuous log archives: 90-day operational retention and 12-month compliance retention for all security events. We generate NERC CIP evidence packages formatted for auditor consumption — security event logs, access attempt records, patch status summaries, ESP boundary change logs, and incident timelines. Command tier includes a dedicated CIP compliance manager who prepares the complete evidence package ahead of each audit cycle, so there's no scramble when NERC schedules an audit.
ERCOT market participants are required to notify ERCOT's Information Security team and ERCOT ISAC of significant cybersecurity events. This overlaps with NERC CIP-008 reporting obligations and the forthcoming CIRCIA 72-hour reporting requirement — creating multiple simultaneous regulatory notification clocks during an incident.
CoreRecon has pre-built notification workflows for ERCOT, NERC E-ISAC, CISA (CIRCIA and standard reporting), and Texas PUC. Our analysts are integrated with E-ISAC threat intelligence feeds, so we're aware of sector-wide threat campaigns before they affect your environment. During an incident, we manage the notification workflow concurrently — you don't have to track three separate regulatory clocks while also managing containment.
Yes. SDVOSB (Service-Disabled Veteran-Owned Small Business) certification is materially relevant for energy utilities in several procurement contexts:
DOE CESER grants: The Department of Energy's Office of Cybersecurity, Energy Security, and Emergency Response (CESER) funds utility cybersecurity programs. Many grant programs have SDVOSB preference components or set-asides.
IIJA Infrastructure Funds: The Infrastructure Investment and Jobs Act allocated $250M+ for energy sector cybersecurity. SDVOSB vendors receive preference points in grant scoring.
DoD Installation Utilities: Utilities serving Fort Cavazos (formerly Fort Hood), JBSA, Fort Bliss, and NAS Corpus Christi may have DoD contract components where SDVOSB certification provides a competitive advantage. CoreRecon can prime or co-prime on DoD-connected utility security contracts.
Municipal Procurement: Many Texas municipalities have SDVOSB preference provisions in their procurement rules that apply to utility services.
CoreRecon's energy utility assessment maps your IT and OT attack surface, identifies BES asset NERC CIP obligations, scans for internet-exposed substation equipment and OT access points, and runs Volt Typhoon LOTL indicator checks against your network telemetry. No credit card. No commitment. Delivered in 14 days.
Request your free $2,500 assessment →Delivered within 14 days • OT scan included • NERC CIP gap review included • SDVOSB-certified team