Luminus expands OT security across generation assets

Luminus expands OT security across generation assets

Luminus is extending operational technology security across its generation portfolio. SecureOT will cover thermal, hydro, wind, and battery assets through vendor-neutral inventory, vulnerability management, and risk prioritisation.


IN Brief:

  • Luminus is deploying SecureOT across thermal, hydroelectric, wind, and battery installations.
  • The platform provides asset visibility, vulnerability management, and contextual risk prioritisation across mixed-vendor systems.
  • Internal teams are progressively incorporating additional operational technology assets after the initial implementation.

Luminus is expanding a common operational technology cybersecurity platform across its Belgian thermal, hydroelectric, wind, and battery assets.

Using Rockwell Automation’s SecureOT system, the electricity producer is building a consistent view of connected control equipment, software, network devices, vulnerabilities, accounts, and configuration risks. Because the platform is vendor-neutral, information from mixed automation environments can be assessed without replacing established control systems or imposing one manufacturer’s architecture across every site.

The implementation began through a joint deployment involving Luminus and Rockwell Automation specialists, after which internal cybersecurity teams started incorporating further operational technology assets. That model allows the system to expand with the generation portfolio while retaining operational knowledge within the organisation.

SecureOT combines asset discovery, inventory, vulnerability information, patch status, configuration data, account information, and operational context. Risk can then be prioritised according to the function and exposure of each asset, rather than applying vulnerability severity scores without considering whether the affected equipment is accessible, redundant, or critical to generation.

Software-based sensors and manufacturer-approved communications are used to examine operational environments without depending solely on mirrored network traffic. Individual endpoints can be profiled through more than 1,000 data points, including firmware, installed software, user accounts, security controls, patch status, and configuration.

Alignment with IEC 62443 and the European Union’s NIS2 requirements forms part of the programme. Both frameworks extend beyond technical controls into governance, risk management, access, incident handling, supplier exposure, business continuity, and the protection of essential services.

Mixed generation estates carry uneven cyber risk

A diversified power portfolio rarely operates on a uniform technology base. Hydroelectric installations may include equipment commissioned over several decades, while battery and wind assets can contain newer controllers, remote-service connections, cloud interfaces, and manufacturer-specific monitoring platforms.

Thermal stations add distributed control systems, turbine controls, safety systems, protection, emissions monitoring, and extensive auxiliary plant. Modern Ethernet-connected equipment often operates alongside serial devices and proprietary protocols that were designed before continuous external connectivity became routine.

Although engineering teams may hold accurate drawings and maintenance records, a continuously updated inventory of firmware, software versions, interfaces, user accounts, and installed security controls is harder to maintain. Temporary vendor access, component replacement, portable engineering workstations, and configuration changes can alter the operating environment between periodic audits.

Continuous discovery can reduce those gaps, provided the monitoring method does not interfere with control-system performance. Techniques commonly used in corporate IT, including aggressive scanning and automated patching, can disrupt older industrial devices, invalidate tested configurations, or create an unacceptable plant trip risk.

Vulnerability information also requires operational context. A severe weakness on an isolated and redundant device may require less immediate intervention than a moderate vulnerability on a remotely accessible controller supporting an essential process. Maintenance windows, safety consequences, spare-part availability, and vendor support all affect the remediation programme.

Where patching is impractical, compensating controls can reduce exposure through network segmentation, application allowlisting, controlled remote access, additional logging, removable-media controls, and stricter account management. Those measures require testing against plant operating procedures rather than implementation as generic IT policies.

NIS2 has placed greater responsibility on management structures across essential energy infrastructure. Incident reporting, supplier assurance, evidence of risk control, and business-continuity planning now sit alongside the technical work of securing controllers, networks, servers, and engineering stations.

Luminus’s decision to build internal deployment capability supports that broader operating model. A software platform can identify assets and rank risks, but plant knowledge remains necessary to assess consequences, approve changes, coordinate outages, and determine whether a proposed security intervention is compatible with safety and availability.

Cyber-secure automation, storage, and connected electrical infrastructure also featured prominently as power systems occupied a larger role at Hannover Messe. The convergence of operational equipment, analytics, and remote services is increasing the quantity of data exchanged beyond the traditional plant boundary.

Generation assets will acquire further interfaces as batteries provide ancillary services, renewable plants respond to network instructions, and central engineering teams use remote analytics for condition monitoring. Each connection can improve operating performance while increasing the importance of identity, configuration, communications, and supplier-access control.

Consistent visibility across the Luminus portfolio should make inherited equipment, unsupported software, dormant accounts, and configuration differences easier to identify. Maintaining that value will require inventories to remain current and risk information to feed routine engineering, maintenance, procurement, and lifecycle decisions.

As the deployment expands, its performance will be determined by the relationship between technical monitoring and operational action. Cybersecurity platforms can expose weaknesses across a mixed generation estate, although sustained resilience depends on whether those findings lead to controlled remediation without undermining the availability of the assets being protected.


  • NESO increases day-ahead interconnector restrictions

    NESO increases day-ahead interconnector restrictions

    NESO is increasing day-ahead restrictions across four electricity interconnector links. The change covers routes to Norway, Denmark, Belgium, and France where forecast flows could create unresolved British system-security constraints.


  • Denny–Wishaw transmission reinforcement enters consent phase

    Denny–Wishaw transmission reinforcement enters consent phase

    SP Energy Networks has advanced another major Scottish transmission reinforcement. Denny–Wishaw combines 400kV uprating, new overhead line, substation extensions, transformers, and cable work to release around 1GW of renewable capacity.