Texas Energy & Electric Utilities  •  NERC CIP • ERCOT Grid Security • OT/ICS SOC • SDVOSB

Volt Typhoon is already inside US grid infrastructure. The question is whether you know it.

CISA Advisory AA24-038A confirmed Volt Typhoon has pre-positioned inside US electric, water, and communications infrastructure since 2021 — including Texas ERCOT-connected grid operators. Chinese state-linked actors use living-off-the-land techniques designed to evade standard IT security tools. Texas electric co-ops, municipal utilities, generators, and independent power producers face NERC CIP enforcement, FERC Order 887, and imminent CIRCIA mandatory reporting. CoreRecon delivers OT/ICS-aware 24/7 SOC, 30-min NERC CIP-008 incident response SLA, and SDVOSB advantage for public power entities — at $89–$129/endpoint.

NERC CIP Audits Are Not Optional. NERC CIP-002 through CIP-014 apply to BES-connected assets. FERC Order 887 expanded supply chain security obligations. CIRCIA will mandate 72-hour incident reporting to CISA for critical infrastructure operators including electric utilities. Non-compliance penalties reach $1M/day per violation per day. CoreRecon maps every obligation to a specific tier control.
Threat Context — Volt Typhoon & Energy Sector Targeting

Living-off-the-land.
Already inside. Waiting.

Volt Typhoon (also tracked as BRONZE SILHOUETTE) is a Chinese state-sponsored threat actor targeting US critical infrastructure — specifically electric, water, communications, and transportation sectors. Their tradecraft is designed to defeat standard security tools by avoiding custom malware entirely. They use legitimate Windows utilities, compromised edge devices, and SOHO router botnets as infrastructure. Standard SIEM rules don't catch them. Active threat hunting does.

CISA AA24-038A — February 2024
Volt Typhoon: Pre-Positioned in US Infrastructure
Joint advisory from CISA, NSA, FBI, ACSC, CCCS, NCSC-NZ, NCSC-UK confirmed Volt Typhoon has maintained persistent access inside US critical infrastructure operators for at least 5 years. Electric utilities, water systems, and communications providers in the continental US — including ERCOT-connected Texas entities — are named sectors. The stated purpose: pre-positioning for disruption in the event of a geopolitical conflict with Taiwan. Source: CISA Advisory AA24-038A.
Living-Off-The-Land Tradecraft
No Malware. No IOCs. No Alerts.
Volt Typhoon uses exclusively built-in Windows tools: WMI, PowerShell, ntdsutil, netsh, and legitimate remote administration utilities. No custom malware means no antivirus detections and no standard IOC alerts. Initial access is typically via compromised internet-facing Fortinet, Ivanti, or Cisco network devices. Lateral movement uses stolen credentials and LOLBins. Dwell time in documented incidents: 5+ years before detection. Source: CISA AA24-038A; Dragos VOLTZITE profile.
Ransomware Against Electric Co-Ops — 2024–2025
RansomHub Targets Distribution Utilities
Independent of Volt Typhoon, ransomware groups including RansomHub, BlackCat/ALPHV, and Akira actively target electric co-ops and smaller municipal utilities — organizations with limited security staff, legacy OT equipment, and federal reporting obligations that create leverage. Distribution SCADA systems for load management, metering, and outage management are targeted specifically because billing and customer data disruption triggers regulatory notification obligations under NERC CIP-008 and state PUC rules. Source: E-ISAC Threat Intelligence Reports, 2024–2025.
OT/ICS Exposure — Substations & SCADA
ERCOT Grid: 680+ Substations. Many Exposed.
NERC CIP requires Electronic Security Perimeter (ESP) controls for OT systems — but many Texas distribution utilities and co-ops have aging substation automation equipment running IEC 61850, DNP3, and legacy SCADA protocols without proper ESP boundary controls. Shodan regularly indexes exposed substation RTUs, relay protection devices, and distribution management systems belonging to Texas electric utilities. Exposed OT equipment is a hard NERC CIP-005 finding and a confirmed Volt Typhoon initial access vector. Source: NERC CIP audit findings; CISA ICS-CERT advisories.
Read the full Volt Typhoon Texas infrastructure threat brief →
Regulatory Landscape — Energy Utilities

NERC CIP. FERC. ERCOT.
TX PUC. CIRCIA. CMMC.

Texas electric utilities operate under more overlapping cybersecurity frameworks than any other sector. NERC CIP-002 through CIP-014 for BES assets, FERC Order 887 for supply chain security, Texas PUC Subst. R. 25.367 for cybersecurity monitoring, ERCOT Nodal Protocols, and CMMC for utilities serving DoD installations. Here's every framework mapped to CoreRecon coverage.

Framework Who's in Scope Key Requirements Penalty / Consequence CoreRecon Coverage
NERC CIP-002 through CIP-014 All BES-connected entities: transmission operators, generation operators, distribution utilities with BES-connected assets, co-ops with >100kV facilities CIP-002: BES asset categorization (High/Medium/Low). CIP-003–CIP-007: Access controls, personnel training, physical security, systems management, incident reporting. CIP-008: Incident response plan + 1-hour initial notification. CIP-013: Supply chain risk management. CIP-014: Physical security of critical substations Civil penalties up to $1M/day per violation per day. FERC enforcement referrals. NERC audit findings become public record. Repeated violations escalate to Mitigation Plans and DOE notification Fortress CIP-002 asset inventory, CIP-005 ESP monitoring, CIP-007 security event logging, CIP-008 IR plan + 30-min SLA, CIP-010 configuration management. Command CIP-013 supply chain program, CIP-014 physical perimeter correlation, full audit evidence package
FERC Order 887 Transmission and generation entities subject to NERC CIP; expanded supply chain security obligations effective 2023–2024 Supply chain risk management for operational technology — software updates, remote access, and third-party vendor controls for BES Cyber Systems. Utilities must identify, assess, and respond to supply chain cybersecurity risks in vendor contracts and software procurement FERC enforcement; non-compliance with CIP-013 (which implements Order 887) carries same $1M/day penalty structure as other NERC CIP violations Fortress Vendor access management (JIT provisioning), session recording for third-party OT access, software integrity verification, OT vendor credential vaulting
TSA Security Directive (Pipeline-2021-02C) Natural gas-fired generation operators with pipeline interconnects; gas transmission operators feeding power plants 12-hour CISA incident reporting, Cybersecurity Coordinator designation, cybersecurity program review against TSA measures (access control, segmentation, detection, response, recovery). Overlaps with NERC CIP for dual-regulated gas-fired generation facilities Civil penalties up to $11,904/day. Dual-regulated entities face stacked NERC CIP + TSA exposure for the same incident if notification timelines not met Sentinel TSA 12-hour CISA notification workflow, Cybersecurity Coordinator function, pipeline-generation interface monitoring
Texas PUC Subst. R. 25.367 All Texas electric utilities under PUC jurisdiction: investor-owned utilities, municipally owned utilities (MOUs), electric co-ops (cooperatives) operating in ERCOT Cybersecurity monitoring program requirements: utilities must maintain documented cybersecurity monitoring capabilities for their OT and IT systems, report significant cybersecurity events to PUC, and maintain an Incident Response Plan aligned to NIST CSF or equivalent framework PUC enforcement action; license conditions; public reporting obligation creates reputational exposure in rate case proceedings Sentinel 24/7 OT/IT monitoring, Texas PUC incident reporting support, NIST CSF alignment documentation, IRP development and maintenance
ERCOT Nodal Protocols — Cybersecurity Provisions All ERCOT market participants: QSEs, LSEs, generators, transmission operators; ERCOT market operations system access ERCOT market participant security requirements for market system access, credential management, and incident notification to ERCOT. Market participants must notify ERCOT ISAC of significant cybersecurity events. ERCOT conducts periodic security compliance reviews Market participant suspension; financial penalties; loss of ERCOT market access; settlements for security-related market disruptions Fortress ERCOT market system access monitoring, credential anomaly detection, ERCOT ISAC integration, market participant incident notification workflow
CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act) All critical infrastructure entities including electric utilities; CISA rule finalization in process 72-hour mandatory reporting of significant cybersecurity incidents to CISA; 24-hour reporting for ransomware payments; standardized incident reporting format. Covers IT and OT incidents affecting critical systems Non-compliance penalties and subpoena authority for CISA. Becomes a mandatory overlay on top of existing NERC CIP-008 and TSA reporting. Utilities face dual-clock: 1-hour NERC CIP-008 + 72-hour CIRCIA for the same incident Command Dual-clock incident management (CIP-008 + CIRCIA), pre-built CIRCIA notification templates, 30-min SLA ensures analyst-on-call before any regulatory clock pressure
CMMC Level 2 (DoD Installations) Electric utilities serving Fort Cavazos, JBSA, Fort Bliss, NAS Corpus Christi, and other Texas DoD installations; utilities with DoD contracts for installation power CMMC Level 2: 110 NIST SP 800-171 practices across 14 domains. Applies to utilities handling Controlled Unclassified Information (CUI) in their DoD-connected operations. Utility IT systems that interface with DoD installation infrastructure may be in scope CMMC certification required for DoD contract renewals (Nov 2026 enforcement). Utilities that lose DoD contracts due to CMMC non-compliance lose installation power revenue. SPRS score visible to DoD contracting officers Fortress CMMC Level 2 gap assessment, NIST 800-171 control implementation, SPRS scoring, SSP and POA&M artifacts. SDVOSB status provides contracting advantage for DoD utility work
CoreRecon for Texas Energy Utilities

OT-aware SOC. 30-min SLA.
Built for ERCOT operators.

Generic MSSPs handle IT security. ERCOT grid operators need OT/ICS coverage, NERC CIP audit evidence, and analysts who understand industrial control system protocols — not IT generalists learning what DNP3 means during an active incident. CoreRecon closes that gap.

What standard MSSPs miss in energy utility environments

A typical MDR deployment monitors Windows event logs, EDR telemetry, and network flow data. In an electric utility, that covers less than 40% of the attack surface. Distribution SCADA, substation automation (IEC 61850 GOOSE messages, Sampled Values), RTUs polling via DNP3, and historian replication traffic are all invisible to standard tooling.


Volt Typhoon specifically targets the gap between IT and OT visibility. They achieve initial access on internet-facing devices, move laterally through IT, and pre-position on OT-adjacent systems — all using legitimate tools that generate no standard alerts. Detecting this tradecraft requires baseline behavioral analysis across both IT and OT, combined with active threat hunting for LOTL indicators specific to energy sector intrusions.


CoreRecon deploys passive NTA sensors at the Electronic Security Perimeter (ESP) boundaries defined under NERC CIP-005. We build OT asset inventories aligned to CIP-002 categorization. We monitor DNP3, IEC 61850, and Modbus traffic for anomalies. And we hunt for Volt Typhoon LOTL indicators — not just wait for antivirus to fire.

OT/ICS-Aware Detection
DNP3, IEC 61850, Modbus
Passive NTA sensors at ESP boundaries. Industrial protocol anomaly detection without touching operational systems. CIP-005 ESP boundary monitoring built-in.
NERC CIP-008 Aligned SLA
30-Min Response
CIP-008 requires 1-hour initial notification of a Reportable Cyber Security Incident. Our 30-min SLA ensures an analyst is on the call before your CIP-008 clock hits 30 minutes — leaving time to assess before notification.
SDVOSB Contracting
Public Power Advantage
SDVOSB certification provides preference points on DOE CESER grants, IIJA cybersecurity funds, and DoD installation utility contracts. CoreRecon primes or co-primes on federally-funded energy utility security work.
NERC CIP Audit Evidence
Audit-Ready Packages
CIP-007 security event logs, CIP-008 incident timelines, CIP-010 configuration baselines, CIP-013 supply chain documentation — all formatted for NERC auditor review. No scramble before audits.
Energy Sector Incident Patterns

Three scenarios. Real attack patterns.
Composite, not named.

These are composite incident patterns based on documented attack types affecting Texas and US electric utilities. No specific client names are disclosed. These patterns reflect the types of engagements and findings CoreRecon is operationally positioned to address.

Pattern 1 — Rural Electric Co-Op
Ransomware via Compromised VPN Credential — Distribution SCADA Impact
Attack Pattern
A credential-stuffing attack on a legacy VPN appliance (unpatched, default password not changed) gives attackers IT network access. Lateral movement over 9 days. Ransomware deploys on billing, customer information system (CIS), and distribution management system (DMS) — triggering NERC CIP-008 reporting and Texas PUC notification obligations.
What Was Missing
No EDR on IT endpoints. VPN appliance not monitored. No network segmentation between IT and OT DMZ. Distribution SCADA (DMS) reachable from IT subnet via unsecured historian replication. Lateral movement undetected for 9 days.
CoreRecon Fortress tier: VPN appliance monitoring, EDR on all IT endpoints, DMZ segmentation with east-west monitoring, historian access controls. CIP-008 reporting timeline starts — 30-min SLA means analyst on call within the first hour. Pre-built PUC notification template cuts regulatory response time.
Pattern 2 — Municipal Utility BEC
Business Email Compromise — Wire Fraud on Capital Equipment Purchase
Attack Pattern
A phishing email impersonating a transformer vendor redirects a $280,000 capital equipment wire to an attacker-controlled account. The transaction is for substation infrastructure upgrade — a budget line item visible in public procurement documents. Municipal utility has no email authentication controls (DMARC/DKIM) and no wire transfer verification procedures.
What Was Missing
No DMARC/DKIM enforcement. No BEC detection in email gateway. No callback verification procedure for wire transfers. Accounts payable staff not trained on vendor impersonation patterns. Public procurement data made the attack highly targeted.
CoreRecon Sentinel tier: Email security with DMARC/DKIM enforcement, BEC detection rules tuned for utility vendor impersonation patterns, staff phishing simulation, wire transfer verification workflow. Municipal utilities are specifically targeted because procurement data is public — our BEC ruleset accounts for it.
Pattern 3 — Generator OT Intrusion
Volt Typhoon Pre-Positioning — LOTL via Compromised Fortinet
Attack Pattern
Consistent with CISA AA24-038A Volt Typhoon tradecraft: initial access via compromised Fortinet FortiGate appliance (known CVE, unpatched). Attacker uses native Windows tools (WMI, netsh, ntdsutil) for lateral movement. Credential harvesting from AD. Quiet reconnaissance of DCS/historian network topology over months. No malware deployed — no antivirus detections.
How It's Detected
Standard IT security tools generate zero alerts. Detection requires: behavioral baselines for LOTL tool usage, FortiGate exploitation indicators in network logs, unusual AD reconnaissance patterns, anomalous historian access from unfamiliar hostnames, and active threat hunting for Volt Typhoon TTPs mapped to MITRE ATT&CK ICS.
CoreRecon Command tier: Active threat hunting with Volt Typhoon LOTL indicator packages, FortiGate/Ivanti/Cisco edge device monitoring, AD reconnaissance detection, historian access anomaly alerting, OT asset communication baseline. MITRE ATT&CK ICS mapping for generator/DCS environments. We hunt for VOLTZITE tradecraft proactively — not reactively.
Transparent Pricing — Energy Utilities Edition

Three tiers. NERC CIP mapped.
No enterprise contracts.

10-endpoint minimum. Month-to-month. Designed for co-ops, municipal utilities, generators, and IPPs without dedicated security teams — and scaled to enterprise-grade NERC CIP requirements. Use the endpoint cost calculator to model your specific environment.

Sentinel
$89 / endpoint / month
10-endpoint minimum • Month-to-month
  • 24/7 SOC monitoring — IT network coverage
  • Texas PUC R. 25.367 cybersecurity monitoring program
  • Email security with BEC / vendor impersonation defense
  • MFA enforcement on all remote access (VPN, RDP, VNC)
  • TSA Pipeline 12-hour CISA notification workflow (gas-fired generation)
  • NERC CIP-008 initial incident notification support
  • Monthly threat report with energy sector intel
  • Start Sentinel →
Command
$2,500+ / month
Custom scope • Dedicated vCISO
  • Everything in Fortress
  • 30-min SLA — NERC CIP-008 aligned, pre-authorized OT isolation
  • Active Volt Typhoon LOTL threat hunting
  • NERC CIP-008 full incident response plan + execution
  • NERC CIP-013 supply chain risk management program
  • CIRCIA 72-hour + CIP-008 dual-clock incident management
  • Dedicated vCISO with OT/ICS energy sector experience
  • Annual NERC CIP audit evidence package preparation
  • Get a Command quote →

OT monitoring pricing depends on substation count, SCADA nodes, and ESP boundary topology. An OT network assessment is included in the free posture assessment — we scope sensor placement and asset inventory before quoting OT monitoring. IT/staff endpoint pricing is as listed above. SDVOSB contracting available for IIJA/DOE CESER grant-funded projects.

Frequently Asked Questions

What energy utility operators
and compliance managers ask us.

Yes — but applicability depends on BES (Bulk Electric System) asset classification. NERC CIP applies to assets connected to the BES, which is generally defined as the interconnected electric transmission network above 100kV. Many Texas co-ops and municipal utilities have generation facilities, transmission assets, or distribution substations that qualify as BES-connected. FERC Order 887 and recent NERC BES clarifications have expanded the number of smaller utilities in scope.

Even Low Impact BES facilities must comply with CIP-003-8 (Cyber Security Management Controls including access management and vendor access) and CIP-004-7 (Personnel and Training). The compliance burden is real even for smaller entities. CoreRecon performs a BES applicability assessment during onboarding — we identify which standards apply to which of your assets before building a compliance program.

Both — and the IT/OT boundary monitoring is where Volt Typhoon pre-positioning is detected. Fortress tier deploys passive network traffic analysis (NTA) sensors at your Electronic Security Perimeter (ESP) boundaries, which are required to be defined under NERC CIP-005. These sensors read industrial protocol traffic (DNP3, IEC 61850 GOOSE, Modbus, ICCP) without installing any software on operational PLCs, RTUs, or relay protection devices.

We build an OT asset inventory aligned to NERC CIP-002 BES Cyber Asset categorization during onboarding. The monitoring baseline is established before go-live, so anomalous protocol traffic — like unexpected setpoint commands or unusual historian polling patterns — generates alerts against a known-good baseline rather than generic threshold rules.

NERC CIP audits are evidence-intensive. Auditors want documented proof for every applicable standard — CIP-005 ESP boundary controls, CIP-007 security event logging (R4 requires log review processes), CIP-007-6 patch management records, CIP-008 incident response plan and any documented incidents, CIP-010 configuration baselines. The typical audit preparation process takes 3–6 months when evidence isn't continuously collected.

CoreRecon maintains continuous log archives: 90-day operational retention and 12-month compliance retention for all security events. We generate NERC CIP evidence packages formatted for auditor consumption — security event logs, access attempt records, patch status summaries, ESP boundary change logs, and incident timelines. Command tier includes a dedicated CIP compliance manager who prepares the complete evidence package ahead of each audit cycle, so there's no scramble when NERC schedules an audit.

ERCOT market participants are required to notify ERCOT's Information Security team and ERCOT ISAC of significant cybersecurity events. This overlaps with NERC CIP-008 reporting obligations and the forthcoming CIRCIA 72-hour reporting requirement — creating multiple simultaneous regulatory notification clocks during an incident.

CoreRecon has pre-built notification workflows for ERCOT, NERC E-ISAC, CISA (CIRCIA and standard reporting), and Texas PUC. Our analysts are integrated with E-ISAC threat intelligence feeds, so we're aware of sector-wide threat campaigns before they affect your environment. During an incident, we manage the notification workflow concurrently — you don't have to track three separate regulatory clocks while also managing containment.

Yes. SDVOSB (Service-Disabled Veteran-Owned Small Business) certification is materially relevant for energy utilities in several procurement contexts:

DOE CESER grants: The Department of Energy's Office of Cybersecurity, Energy Security, and Emergency Response (CESER) funds utility cybersecurity programs. Many grant programs have SDVOSB preference components or set-asides.

IIJA Infrastructure Funds: The Infrastructure Investment and Jobs Act allocated $250M+ for energy sector cybersecurity. SDVOSB vendors receive preference points in grant scoring.

DoD Installation Utilities: Utilities serving Fort Cavazos (formerly Fort Hood), JBSA, Fort Bliss, and NAS Corpus Christi may have DoD contract components where SDVOSB certification provides a competitive advantage. CoreRecon can prime or co-prime on DoD-connected utility security contracts.

Municipal Procurement: Many Texas municipalities have SDVOSB preference provisions in their procurement rules that apply to utility services.

Related Tools & Resources

Go deeper on NERC CIP,
Volt Typhoon, and grid risk.

Free Tool
SPRS Score Calculator
NIST 800-171 assessment for utilities with DoD contracts (CMMC Level 2, Fort Cavazos/JBSA/Fort Bliss power contracts) →
Free Tool
Breach Cost Calculator
Model a ransomware event at your utility: NERC CIP penalty exposure, restoration costs, and CIRCIA/PUC notification obligations →
Free Tool
Vendor Risk Scorecard
FERC Order 887 supply chain security assessment for SCADA vendors, software suppliers, and remote access providers →
Threat Intelligence
Volt Typhoon Texas Brief
Full Volt Typhoon threat profile: LOTL TTPs, MITRE ATT&CK ICS mapping, ERCOT-specific targeting indicators, detection guidance →
Related Sector
OT/SCADA Security
Water & Wastewater Utilities
Same OT monitoring expertise — SCADA, PLCs, AWIA Section 2013, EPA enforcement, TCEQ compliance. Texas was hit by CyberArmyofRussia in 2024. →
City IT Oversight
Texas Municipalities
Municipal utilities, public power, and city water systems under shared city IT. CJIS, FEMA BRIC, TX Gov Code 2054, and AWIA stack together. →
Active Breach? 24/7 Emergency Response
Grid event? OT anomaly? NERC CIP clock ticking? We respond in 30 minutes.
No retainer required. OT-aware response team. NERC CIP-008 notification support. ERCOT ISAC coordination.
📞 (800) 955-2596 Or submit emergency intake form →
Free Grid Security Assessment — $2,500 Value

Find out if Volt Typhoon is already in your network.

CoreRecon's energy utility assessment maps your IT and OT attack surface, identifies BES asset NERC CIP obligations, scans for internet-exposed substation equipment and OT access points, and runs Volt Typhoon LOTL indicator checks against your network telemetry. No credit card. No commitment. Delivered in 14 days.

Request your free $2,500 assessment →

Delivered within 14 days  •  OT scan included  •  NERC CIP gap review included  •  SDVOSB-certified team

Free Tool — vCISO ROI Calculator
Fractional vCISO vs. Full-Time Hire — Calculate the Real 3-Year Cost
IBM CODB breach model + compliance penalty exposure + tier recommendation. Know the math before your board asks the question.
Calculate vCISO ROI →
Switching from Deloitte Cyber?
Deloitte's $150K+ Floor Doesn't Pencil for Mid-Market TX Energy Operators
Deloitte Cyber's engagement floors ($150K–$500K+) and Big 4 consulting model aren't designed for TX O&G operators with $50M–$500M revenues. CoreRecon delivers OT-aware endpoint coverage, NERC CIP alignment, and published per-endpoint pricing — built for this market.
Deloitte vs. CoreRecon →