performing-power-grid-cybersecurity-assessment

Assess power grid cybersecurity across substations, EMS systems, and NERC CIP compliance.

954|172|Updated Mar 13, 2026
One-click install
npx skills add https://github.com/xalgord/xalgorix --skill performing-power-grid-cybersecurity-assessment
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: performing-power-grid-cybersecurity-assessment
Source: https://github.com/xalgord/xalgorix/tree/main/internal/tools/skills/data/ot-ics-security/performing-power-grid-cybersecurity-assessment
Command: npx skills add https://github.com/xalgord/xalgorix --skill performing-power-grid-cybersecurity-assessment

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Power grid operators and security assessors need a structured methodology to evaluate the cybersecurity of generation facilities, transmission substations, and EMS control centers while meeting NERC CIP compliance obligations and avoiding dangerous active probing of protection systems.

Core Features & Use Cases

  • Substation Automation Assessment: Evaluates IEC 61850 GOOSE and MMS protocol security, station bus segmentation, and remote access controls with findings mapped to NERC CIP and IEC 62351 references.
  • Grid Architecture Mapping: Documents EMS/SCADA systems, substation RTUs, synchrophasor (PMU) networks, and inter-control-center ICCP/TASE.2 links.
  • Passive-First Safety Guidance: Emphasizes passive traffic capture over active scanning to avoid false breaker trips on live protection systems.
  • Use Case: A transmission operator preparing for a NERC CIP audit uses this Skill to assess 145 substations, confirming unauthenticated GOOSE messaging on the station bus and generating a compliance-ready findings report.

Quick Start

Assess the cybersecurity posture of my 345kV substation automation network and check NERC CIP compliance for IEC 61850 GOOSE and MMS protocols.

Frequently Asked Questions about performing-power-grid-cybersecurity-assessment

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I assess IEC 61850 substation cybersecurity?

Assess IEC 61850 security by passively capturing station-bus traffic to check for unauthenticated GOOSE messages and MMS connections without TLS. Map findings to IEC 62351-6 for GOOSE authentication and IEC 62351-4 for MMS security profiles.

How to verify NERC CIP compliance for power grid systems?

Verify NERC CIP compliance by checking CIP-005 electronic security perimeter controls, CIP-007 system access controls, and remote access management with MFA. Document findings per standard and map each gap to the specific CIP requirement reference.

Can I actively scan substation protection relays during assessment?

No, active scanning near protection relays can cause IED mis-operation and false breaker trips. Use passive traffic capture for station-bus checks, and schedule any active EMS testing in a maintenance window with the grid operator informed.

What tools are used for power grid security assessment?

Common tools include the Dragos Platform for OT threat intelligence, Wireshark with IEC 61850 dissectors for GOOSE and MMS analysis, SEL-3620 security gateways, and the GRIDsure assessment framework from Idaho National Laboratory.

When should I not use a power grid specific assessment approach?

Do not use it for non-BES systems below NERC registration thresholds, general OT assessments without power grid specifics, or physical security reviews of generation facilities without cyber scope. Use a general OT network assessment instead.