Strengthening cyber resilience for critical energy infrastructure in the Netherlands
Challenge
As its electricity and gas networks became more digital and connected, the organisation needed to manage growing cyber risks across the systems supporting critical energy services.
Approach
Resillion performed 50+ penetration tests across 40+ business-critical applications, energy fraud systems, APIs and SCADA systems from an attacker’s perspective.
Results
400+ vulnerabilities assessed and high-risk findings reported, helping strengthen the resilience of the Netherlands’ critical energy infrastructure and support ongoing regulatory compliance.
Our client is a leading European energy network operator responsible for managing critical electricity and gas distribution infrastructure. It also develops the digital technologies and services that support a more connected, sustainable energy system. Its systems underpin the reliable delivery of energy to homes, businesses and essential services across the Netherlands.
As a critical energy infrastructure organisation, it must also comply with the Critical Entities Resilience Act, which places requirements on organisations to strengthen the resilience of essential services and protect them from disruption.
When energy is available, we rarely think about the infrastructure behind it. But when it’s disrupted, the impact quickly reaches beyond technology, affecting our ability to heat and light our homes, work, travel, communicate and carry-on everyday life.
As the energy network operator’s digital estate expanded, so did the need for consistent, independent security assurance across new and existing applications.
The challenge: Securing an expanding digital estate
The organisation needed a way to keep security testing aligned with ongoing application development while also assessing existing systems that had not previously undergone formal penetration testing. The objective was to identify vulnerabilities early and reduce the risk of disruption to critical operations.
For critical energy infrastructure, cyber security is ultimately about protecting the services people depend on every day. Independent security testing helps organisations find weaknesses before attackers can exploit them, giving them the opportunity to address risk before it becomes disruption
The approach: Independent penetration testing for critical systems
Resillion has supported the organisation with penetration testing since 2019, providing independent security assurance as its application landscape and cyber risk have evolved.
Across the programme, Resillion has:
- Tested 40+ applications and platforms
- Delivered 50+ penetration tests
- Identified and assessed 400+ vulnerabilities
- Classified findings according to technical risk, impact and likelihood
- Future-proofed infrastructure security against changing regulation and evolving critical system and application architecture with a scaled testing approach
Each engagement is tailored to the technology and scope of the system being assessed. Security specialists test applications and platforms from an attacker’s perspective, identify vulnerabilities, investigate potential attack paths and provide clear findings that classify technical risk, impact and likelihood so remediation can be prioritised effectively.
This means the organisation can understand not simply whether a vulnerability exists, but how it could potentially be exploited and where immediate action is required.
Resillion has assessed a wide range of technologies, including:
Business-critical applications, including a big data platform that ingests, processes and presents business data to analysts.
Energy fraud detection systems, using information from multiple sources and automated analysis to identify potential fraud across the energy network.
External and internal web applications and APIs, including platforms supporting file exchange and applications that help maintenance engineers locate pipes, junctions, substations and other critical infrastructure.
Cloud and on-premises infrastructure, including the organisation’s main Kubernetes clusters and associated CI/CD infrastructure.
Network equipment, including routers connecting equipment in electrical substations to the wider OT environment.
Energy-specific operational systems, including SCADA equipment management solutions.
Over the course of the relationship, the scope and volume of testing has grown significantly. As an energy grid operator, the organisation operates in a highly regulated critical infrastructure environment, where resilience, information security and regulatory assurance are increasingly important. Resillion’s testing has helped support this shift by giving the organisation independent visibility of technical risk across the systems that underpin essential energy services.
Resillion has scaled its support in line with this increasing demand, helping the organisation maintain consistent security assurance across both new and existing systems.
The results: Reducing cyber risk across critical applications
The ongoing programme has given the organisation clearer visibility of security risk across the digital systems that support reliable energy for consumers in the Netherlands.
Resillion has:
The result is a stronger, more informed security assurance programme that helps the organisation protect critical services, support compliance with regulations such as the Critical Entities Resilience Act, and reduce the likelihood of cyber risk becoming operational disruption. For consumers, this means greater confidence that the energy services they rely on every day remain secure, resilient and available.