Strengthening cyber resilience for critical energy infrastructure in the Netherlands 

Challenge

As its electricity and gas networks became more digital and connected, the organisation needed to manage growing cyber risks across the systems supporting critical energy services.

Approach

Resillion performed 50+ penetration tests across 40+ business-critical applications, energy fraud systems, APIs and SCADA systems from an attacker’s perspective.

Results

400+ vulnerabilities assessed and high-risk findings reported, helping strengthen the resilience of the Netherlands’ critical energy infrastructure and support ongoing regulatory compliance.

Our client is a leading European energy network operator responsible for managing critical electricity and gas distribution infrastructure. It also develops the digital technologies and services that support a more connected, sustainable energy system. Its systems underpin the reliable delivery of energy to homes, businesses and essential services across the Netherlands. 

As a critical energy infrastructure organisation, it must also comply with the Critical Entities Resilience Act, which places requirements on organisations to strengthen the resilience of essential services and protect them from disruption. 

When energy is available, we rarely think about the infrastructure behind it. But when it’s disrupted, the impact quickly reaches beyond technology, affecting our ability to heat and light our homes, work, travel, communicate and carry-on everyday life. 

As the energy network operator’s digital estate expanded, so did the need for consistent, independent security assurance across new and existing applications.

Modern dutch houses with solar power electricity

The challenge: Securing an expanding digital estate

The organisation needed a way to keep security testing aligned with ongoing application development while also assessing existing systems that had not previously undergone formal penetration testing. The objective was to identify vulnerabilities early and reduce the risk of disruption to critical operations.

For critical energy infrastructure, cyber security is ultimately about protecting the services people depend on every day. Independent security testing helps organisations find weaknesses before attackers can exploit them, giving them the opportunity to address risk before it becomes disruption

Antonio Russu, Global Head Cyber Security, Resillion

The approach: Independent penetration testing for critical systems

Resillion has supported the organisation with penetration testing since 2019, providing independent security assurance as its application landscape and cyber risk have evolved. 

Across the programme, Resillion has:

  • Tested 40+ applications and platforms 
  • Delivered 50+ penetration tests 
  • Identified and assessed 400+ vulnerabilities 
  • Classified findings according to technical risk, impact and likelihood 
  • Future-proofed infrastructure security against changing regulation and evolving critical system and application architecture with a scaled testing approach

Each engagement is tailored to the technology and scope of the system being assessed. Security specialists test applications and platforms from an attacker’s perspective, identify vulnerabilities, investigate potential attack paths and provide clear findings that classify technical risk, impact and likelihood so remediation can be prioritised effectively. 

This means the organisation can understand not simply whether a vulnerability exists, but how it could potentially be exploited and where immediate action is required. 

Team reviewing test cases and automation on laptop and monitors

Resillion has assessed a wide range of technologies, including: 

1

Business-critical applications, including a big data platform that ingests, processes and presents business data to analysts. 

2

Energy fraud detection systems, using information from multiple sources and automated analysis to identify potential fraud across the energy network. 

3

External and internal web applications and APIs, including platforms supporting file exchange and applications that help maintenance engineers locate pipes, junctions, substations and other critical infrastructure. 

4

Cloud and on-premises infrastructure, including the organisation’s main Kubernetes clusters and associated CI/CD infrastructure. 

5

Network equipment, including routers connecting equipment in electrical substations to the wider OT environment. 

6

Energy-specific operational systems, including SCADA equipment management solutions. 

Over the course of the relationship, the scope and volume of testing has grown significantly. As an energy grid operator, the organisation operates in a highly regulated critical infrastructure environment, where resilience, information security and regulatory assurance are increasingly important. Resillion’s testing has helped support this shift by giving the organisation independent visibility of technical risk across the systems that underpin essential energy services. 

Resillion has scaled its support in line with this increasing demand, helping the organisation maintain consistent security assurance across both new and existing systems.

The results: Reducing cyber risk across critical applications

The ongoing programme has given the organisation clearer visibility of security risk across the digital systems that support reliable energy for consumers in the Netherlands. 

Resillion has: 

Inside a workspace built for testing

Safer energy operations – Identified and assessed 400+ vulnerabilities, including high-risk findings and a smaller number of critical findings, giving the organisation greater visibility of weaknesses across systems supporting critical energy operations.

Colleagues discussing data in facility

Focused remediation – Helped prioritise remediation through technical risk classification, describing the likely impact and likelihood of findings so teams could focus effort and investment on the vulnerabilities presenting the greatest potential threat.

Partnership that shapes your testing strategy

Actionable next steps – Provided clear, actionable reporting to support remediation planning, translating technical findings into practical steps for reducing risk across critical applications and infrastructure.

Cyber Resilience Act readiness scaled

Future-ready assurance – Scaled testing in line with growing security and regulatory requirements, helping the organisation maintain assurance as new applications are introduced and critical systems evolve, supporting the continued availability and resilience of essential energy services

The result is a stronger, more informed security assurance programme that helps the organisation protect critical services, support compliance with regulations such as the Critical Entities Resilience Act, and reduce the likelihood of cyber risk becoming operational disruption. For consumers, this means greater confidence that the energy services they rely on every day remain secure, resilient and available.