The utility that could not say what was on its own network
A Saudi utility knew its operational network was flat and could not prove how flat. The first honest asset inventory in its history found 400 devices nobody owned.
A Saudi regional utility operating generation and distribution assets across several governorates
- 412Unregistered devices found on the operational network
- 1 to 9Flat network segmented into nine enforced zones
- 6 hoursContainment time in the first live incident after cutover
The situation
Saudi Arabia's National Cybersecurity Authority addresses industrial control systems directly in its Essential Cybersecurity Controls, which call for network segmentation and continuous monitoring in OT and ICS environments. The framework was restructured in the 2024 revision into four domains and 108 main controls, and the NCA enforces through audits and sector oversight.
For a utility this lands differently than for an office-based organisation. The assets in question run physical infrastructure, cannot be patched on an IT schedule, and in many cases predate the idea that they would ever be networked at all.
The problem
The utility knew its operational network was flat. Engineers had said so for years. What it could not do was describe the shape of the problem, and without that it could not plan segmentation, scope an audit, or answer a regulator.
The immediate obstacle was that nobody knew what was connected. The asset register was maintained in a spreadsheet, last reconciled in 2022, and covered the equipment the utility had procured. It did not cover equipment brought in by contractors, temporary connections that had become permanent, or devices installed during commissioning by vendors who had since left.
There was also a cultural obstacle, and it was the more serious one. Operations regarded the security function as a source of interruptions. Any proposal that might stop a turbine was going to be resisted, and reasonably so: the consequences of a failed change in this environment are not measured in downtime tickets.
What we did
The utility asked for a segmentation programme. We proposed spending the first phase not segmenting anything, and that was received badly.
The argument was that segmenting an inventory you do not have produces a network that is partitioned in the wrong places, which is worse than flat because it creates confidence. If you do not know a device exists, you cannot know which zone it belongs in.
So the first eight weeks produced an inventory, built by passive monitoring rather than active scanning, because active scanning in an OT environment is itself a risk. Passive collection at aggregation points, correlated against procurement records and interviews with site engineers.
It found 412 devices that were not on the register. Most were mundane. Some were not. One was a contractor's laptop that had been connected to the control network since 2021, still joined, still reachable, belonging to a company whose contract had ended.
That finding changed the engagement. Operations stopped treating the programme as an imposition, because the inventory had told them something about their own estate that they wanted to know. The head of OT, who had opened the kick-off by saying he had thirty minutes, chaired the remaining workshops himself.
Segmentation followed the inventory rather than a reference architecture: nine zones drawn around how the plant actually operates, enforced at the boundary, with monitoring at each. Cutover ran zone by zone during planned outages over five months.
The outcome
Nine enforced zones replaced one flat network, with continuous monitoring at each boundary, which is what the control framework asks for and, more usefully, what an incident responder needs.
That was tested sooner than anyone wanted. A commodity malware infection on the corporate side reached the OT boundary four months after cutover and stopped there. Containment took about six hours, against an estimate of several days had the same event happened on the flat network.
The register is now maintained by passive discovery rather than by hand, so it degrades far more slowly than a spreadsheet.
You cannot defend a building whose rooms you have never counted. The utility had been buying locks for years without a floor plan.
We asked for a compliance project and they gave us an inventory. I was annoyed for about a week. Then the inventory found a contractor laptop that had been sitting on the control network since 2021.