
Energy Talks · 2026-04-30 · 21 min
Key moments - from our scoring
Substance score
43 / 100
Five dimensions, 20 points each
Jaron, a senior consultant at Omicron with twelve years of automation technology background, walks through the practical realities of conducting cybersecurity risk assessments on operational technology systems in the power industry. The episode highlights a critical gap between best practice (early-phase assessments) and reality (assessments conducted during or after construction when budgets and timelines are constrained). The discussion centers on Omicron's assessment methodology based on IEC 62443-3-2 (risk assessment and management), which involves identifying system scope, performing initial cyber-physical risk assessments without countermeasures, partitioning systems into zones and conduits, and comparing residual risk against tolerable thresholds. Jaron emphasizes that assessments cannot be templated - each network, product, and customer organization requires customized analysis given their unique maturity levels and constraints. The team deliberately skips IEC 62443-3-3 (compliance checking) in favor of delivering actionable risk scenarios with exploit-ability indicators and mitigation guidance. The true value proposition, Jaron argues, lies in knowledge transfer through well-written reports and workshop discussions rather than simply producing a risk register, enabling customers to improve security posture iteratively rather than treating security as a one-time checkbox.
IEC 62443 has four main parts: part 1 covers general topics and lifecycle; part 2 addresses policies and general information security approach; part 3 focuses on system requirements; and part 4 covers components. Omicron primarily uses IEC 62443-3-2 (risk assessment and management) for assessments, sometimes skipping the IEC 62443-3-3 (system compliance requirements) portion when time or budget constraints exist.
Customers typically engage assessments during or after the building phase because security is treated as an afterthought until legislated requirements or investor mandates force action. By then, energizing is imminent, budgets are fixed, and engineers are unavailable, making remediation costly and infeasible.
Zones are functional groupings of devices with similar security levels and connectivity capabilities. Conduits are the connections between zones; they don't always have to be firewalls and can be direct connections, though segmentation via firewalls is expensive and complex.
The rule of ten is an informal principle that a security problem fixed during the planning phase costs roughly 10 times less to remediate than the same problem fixed after project commissioning, making early assessments far more cost-effective.
Beyond delivering a risk register or output package, a good consultant prioritizes knowledge transfer through detailed reports and workshops so the customer can build internal capability and execute faster and better on future security initiatives.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode covers procedural assessment approaches and mentions the IEC 62443 standard, but relies heavily on abstract process descriptions rather than concrete insights. While the discussion of late-stage assessments being more expensive and the rule of ten principle provide some value, much of the content recycles the same points (assessments are better early, security is ongoing, reports should be tailored) without adding substantive new information a B2B operator would not already know.
If we fixed a problem in planning phase which cost us about ten euros the same problem, fixing it after commissioning would be a much higher amount of money
security isn't a onetime action
The episode follows conventional risk assessment framing and relies on standard IEC 62443 methodologies without introducing contrarian or first-principles thinking. The discussion of zone/conduit architecture and the tension between standard compliance and practical constraints are predictable pain points in OT security already well-documented in the field. No counterintuitive arguments or fresh approaches are presented.
we do most of our assessments according to IAC-SXT-II
zones are groups of devices with a similar security number
Jaron has 12 years of experience in building automation technology and has been at Omicron (an assessment firm) since 2004, making him a relevant practitioner. However, he is primarily a service provider conducting assessments rather than an operator or decision-maker within a power utility or energy asset owner, limiting his perspective to the vendor/consultant side rather than the customer experience or strategic decision-making level.
My name is Jaron. i'm working at Omicron since two thousand and four and am mainly focusing on risk assessments
i've worked somewhere around twelve years for a big vendor building automation technology for energy systems
The episode mentions IEC 62443 standard and zones/conduits as architectural concepts but provides almost no specific examples of real assessments, company names, financial figures, or concrete risk scenarios. The vague 'rule of ten' (10 euros to 100-1000 euros) is illustrative rather than substantive. No named case studies or quantified metrics about assessment outcomes are provided.
If we fixed a problem in planning phase which cost us about ten euros the same problem, fixing it after commissioning would be a much higher amount of money
zone & conduit are most well-known part
The host asks reasonable setup questions but rarely presses back on claims or requests concrete examples. Follow-ups are surface-level ('tell us about yourself', 'how does this work?') rather than probing for specifics. When Jaron makes statements like 'we can't really repeat everything the same way,' the host doesn't push for examples or exceptions. The conversation reads more like a scripted service explanation than a genuine inquiry.
can you tell us a little bit about yourself?
What does the formula correct?
Computed from the transcript - who did the talking, and the words that came up most.
Discover methods, findings, and lessons directly from the energy industry In this episode of Energy Talks, host **Simon Rommer **speaks with his colleague Jaron Stammler , OT Cybersecurity Consultant at OMICRON, about how OT cybersecurity risk assessments are conducted in the power industry. Drawing from current experiences in substations and battery energy storage systems (BESS), they walk through how assessments are initiated, structured, and executed in practice. The discussion also highlights the gap between theory and reality, especially when assessments are performed late in project lifecycles due to regulatory or project constraints. Jaron explains the fundamentals of the IEC 62443-3-2 risk assessment process, including system scoping, risk identification, and zone and conduit modeling, while also addressing common challenges such as missing documentation and limited stakeholder availability. Simon and Jaron also emphasize how cybersecurity is an ongoing process and that effective assessments provide actionable insights, prioritized risks, and practical mitigation strategies tailored to each project. Get more information about security risk assessments at OMICRON .
Transcribed and scored by The B2B Podcast Index.
Welcome to Energy Talks, a regular podcast series featuring expert discussions on power system testing data management cyber security and important trends in the power industry. My name is Simon Romer from The Podcast Team at Omicron And I will be your host. Hello everyone! As you know energy talks episodes that are hosted i'll be covering topics related to OT Cybersecurity in the Power Industry.
In this episode We will talk about some experiences and reoccurring findings that we had during our assessments of substations in battery energy storage systems, etc. So without further delay I welcome Jaron to this episode of Energy Talks! Hello Jaro! Hi so let's start with the easy question first can you tell us a little bit about yourself?
My name is Jaron. i'm working at Omicron since two thousand and four and am mainly focusing on risk assessments But I have history with automation technology. So, i've worked somewhere around twelve years for a big vendor building automation technology for energy systems but also like factories and plants And so was tasked with consulting on those topics of automation technology. You already mentioned trainings in assessment.
This is exactly the topic that we want to discuss today mainly the assessment part. Today we want to talk specifically about how an assessment is built, what do you do during such assessments? So let's start from the beginning. How does our customers find us or come through with a realization that they need help?
This really depends on situation but many customer finds us via word of mouth. so we have had experiences some customers and hopefully satisfied their work sector in the area and so when they need help, they may find us. And this can be multiple things for example assessment as we have done it in the past but also concepts for networks or some just a sparing partner on security questions that are available to them. The training part is always curious to me because what we do, it's basically train the customer through our reports.
So we have three parts in the end that will be going into talk about in a few minutes and I'll go as always for the customer to be more informed afterwards than before. so What we basically do is also training the customer through our assessments. One of those customers I talked to was Jose in a previous episode and he stressed how important it is to have these assessments early, We both know that reality looks quite different. That's absolutely you could say.
sadly because quite nice to start an early phase of the project, but yeah. The reality is sometimes different. Maybe we get called during a planning phase? But mostly we get call doing the building phase already where security's in afterthought...
but it still needed by legislation or required by the investor future asset owner. and this is what gets messy because then you have requirements from the asset owner or from the investor, that it needs to be done and it need to be finished. And energizing needs to happen but they also need to fulfill all the gritties of other requirements. There's another problem here.
I mean do you know the rule of ten? It is like not a real rule. scientific measurement does anything like this. But later if you fix problems then more expensive it will be.
So If we fixed a problem in planning phase which cost us about ten euros the same problem, fixing it after commissioning would be a much higher amount of money. You have to invest kind if you fix that problem for example then I don't know hundred euros or thousand euros? For example with the same problems even though It's yes! The same issue.
so... it is always a problem when we do assessments later on in our project. not really for us i mean its' not an issue we can use. But for the customer, other results is obviously better to have them early or earlier than later just to be able to react more easily and efficiently on those findings.
Also Jose said late in the project you can't really change anything. so what do we need? There's no possibility. there isn't a financial headroom in the budget.
Yeah I mean the financials are one part but often it's not at the bottom. No, five thousand euros for another component or something like this. It's also the time and resources having people doing this during fixing other problems in their project to be on-time. And then I don't know restructuring The network restructoring the IP addresses and everything right?
This is obviously not real feasible In the amount of times such what it often have. yeah We do most of our assessments according to IAC-SXT-II, IV-VIII where we sometimes shorten the process to stay within different constraints maybe due budget or time constraints. So what does the formula correct? IC-SXT-II for IV-III dash three dash two processes look like and why?
Do you focus on a subset of whole standard so that dash three is not the whole standard right now? mean this standard is fairly complex. there are different parts. That's always the first number after the six, two four for three.
So part one is general topic like library and life cycle descriptions. Part Two is on policies procedures in a general approach from information security General. and the part Three is about this system. This obviously where technicians and engineers often are involved most interested.
And there's the part two which is risk assessment Horace management and the part three on their system requirements. And then there's a fourth part of the standard. this is on components, so that another part they can check against components use those components to build secure systems at least idea. So in the dash three dash two which we used for risk assessments strictly defined there are some sub processes and some inputs define by the standard which you could should use to do their assessment.
And the problem is obviously it's time consuming to do exactly like the process, but that I think that's okay because as a reason this process is to be followed. But also they input information suggested by the Standard That at least in our experience not always existent. so We can ask for all of this, but in at least many cases it's not there. So we have to make the best out of it and try to get a sensible and good assessment going even without all information required by standard.
This also implies that you cannot always follow the standards. Especially with availability during final stages The project and then the availability of engineers and network designers is quite low. We also can't really do the workshops that we like and also interviewing, so as you said information is not there. And we have to assume a lot of things.
in general The standard sounds all very strict but I mentioned steps can be argued if needed. So we don't do certifications and accreditations after what we provide us an assessment where the customer has some actionable information at end-of-the day. This part was talking about. when i mention trainings Yeah, I mean it's not really training but we try always to create the report in a way that is so customers can learn something of the report kind.
So maybe include information for one customer which we would expect from next because they have different mindset or knowledge base and so we tried adapt reports. The customer gets most out of it. Not only to have the risk register or something like this, but also... the more information and learning To continue their journey because there is obviously a one-time thing.
But security isn't a onetime action So they need to be continued in some way Or another. Yeah, security always has a process. Maybe let's describe how we do our assessments And approach these kinds Of things. if not enough time.
We still want to provide value. The part where I think personally is the most, let's say room to skip it. Is there a part were we do in Dash three dash three assessment? So checking this system against the requirements of the standard so that dash tree dash two is on the risk assessment process and the dash three dash threes on the system requirements And so you could take compliance check That's the system comply to the rules of the dash three and personally i think that value of this is not so high.
I mean there are good requirements and points you can include in the system also especially if your planning a new, yeah any system apart substation whatever building but inner security assessment i think the values not so hot and so we sometimes Custom wants this also sometimes skip. This part, but we always include like the risk scenarios and We normally do that in a way that we try to Also give some scale. so we use not only Like likelihood at impact input parameters for risks or just say how severe is the risk?
But I'll see you exposure exploit ability as also some indicators on our relevant every is. And then the report often includes some kind of structure depending on the exact project and systems we are looking at. So it's description over risks, so-on... Then also include guidance what to do next?
What is most relevant risk or mitigation measures you can take? How could you continue with the steps that make this system more secure? We sometimes include it in the report or some extra recommend. that really depends on the project.
This is also the paper, the outcome of customers paying us for. I was compared to pen testers and they said at a previous episode That best pen tester are the best consultant In this case not very valuable if they can't transfer their knowledge. So transferring our knowledge means writing good reports where it's clearly stated what we did, how we did and the outcomes also means to our customer. And as you correctly said - What they can do afterwards because security is a process!
It's something that will repeat all of your time…it isn't one-time thing so having some action items after the fact always good and needed. So The outcome is report with threat scenarios & risks As I've already mentioned recommended remediations and provide context with the report. For me, this is the most important part because it's the value that we bring in also to reason why customers and partners come back and task us again for a follow-up project Because we understand energy sector We understand intricacies And were able to bring to light some things others might not see directly.
This also sounds like you're doing same few steps all your time. Well, it's a standard procedure. It might be right in general but the devil is always into details? Yeah sure I mean each network different and also each product different.
so that time we are coming to at the project is always different. So there're also the interactions information available and required bit different. And so We can't really say okay just copy the risks from the last projects for the next. That's not feasible.
thats At least my screens i would Say doesn't work. Even if you can gain some experience and use that experience in the next project, The setup will almost be a bit different. And also as I said the outcome is highly individual. so You may have some customer who has very high maturity rate.
They already know lot of things but need an external view. So results or report must be different than for example for customers. no experience or low-experience in this kind of tasks, and it's projects maybe has never done a risk assessment. And so we have to adapt them then.
therefore each product is different than the network is different at that customs difference all week can't really repeat everything same way. most times you also have two. explain the sixty four for three in general. end what approach into dash three dash two with For example, that we have to identify the system under consideration first.
So what is the scope? Is always a good question at the beginning of such project because the scope also defines your risks and interfaces for outside world. then you need perform an initial cyber security risk assessment. regular listeners off this podcast already know I'm not fond of the word Cyber but in these case it means the cyber physical systems so everything digital end relating to the physical world, so performing an initial cybersecurity risk assessment as it's named in standard where we look at all risks without any countermeasures.
So without having firewalls in place and without having any kind of segmentations or other security related devices then we partition a system under consideration into zones & conduits. I think zone & conduit are most well-known part. The zones are groups of devices with a similar security number. But in reality, it's more like functional grouping not only function of the device but also Functional In the sense that It is possible.
So Not every kind of grouping Is possible With network appliances That I am placed And the conduits Don't always have to be firewalls. It gets really expensive Also really complicated if every conduit between the two zones is a firework. Sometimes, the conduit it's just direct connection without anything in-between and then we check the initial risk If It Exceeds The Tolerable Risk. This Is Also Where We Have To Have The Workshops And To Have Experts From The Customer Again.
Yeah I Mean That'S Very Interesting Often Because Obviously Know Some Things And Assume Some Things. We Have Seen Similar Project But In Each And Every Workshop You Gain a new perspective kind of and learn something you from also from the customer. That's really what I enjoy. so that sad thing is we can't always do it to workshops in there frequency, and also the Detail depth We would like sometimes because their projects as we already discussed up Sometimes in the middle off building project And some times they are higher priorities s let say cyber security risk assessments For example.
i don't know problems with the building structure or the cables whatsoever. If energizing is next week, they're having a workshop with some random security guys that have no impact on the outcome anymore. It's low priority which also reason why having the security assessments in beginning during planning phase are more valuable. So maybe let's summarize our assessment and what we finished after finishing work so you can do it real quick?
Sure I mean... As we said, the actual output more or less is a risk register. So this is something you can use as an input for an ICMS e.g.
, of further future assessments but also to report. and so the reports structured always in similar way as we discussed already. that content differs greatly between projects But structures are more-less than same. There's executive summary then there's explanation on what we did And how?
So like some method What kind of measurements are things we used? and then there is the meat. so they description off the risks. that description after countermeasures descriptions of.
Things implied by those risks, and then this summary also for most urgent topics should be looked at. it's a package and you can visit always what i'm trying to choose the detail level you want too dive into. So you start maybe with the executive summary if we just want to know overview of what their biggest issues are and then, If you decide to drill in deeper You can follow the descriptions of risks Maybe even go over to the risk register To look at ratings and likelihood descriptions and stuff like this.
Your emphasis on report really shows that This is main part our work And during security assessments, we already start writing the report so that we also have something to show for if a customer needs an intermediate review or something. And with it. thanks Jaren for taking time to talk me. do you any last message want give our audience?
Yeah I mean using consultants. projects is often done but i would say good consultant team Providing some input for project should always be to reach temporary shortages of resources, but that's not the only point. I think a really good consultant or consulting team is always of value if you get some knowledge transfer. We already discussed this how this works.
But this is a really important part Not only To deliver some kind of output Some kind of delivery package or whatever? get some knowledge out of this project to be faster, better next time. This is at least in my opinion one way also measure a consulting offer. maybe ask the consultant here talking how they plan to transfer their knowledge so you can understand it and put an emphasis on this part because there are obviously a lot of companies, a lot consultants aiming to help you and that's probably true in most cases at least.
But the last part I would think is something we should as a customer focus on. This is quite nice thing Because We always try build relationships And i think it shows in our work. Thanks for these nice words In the end. thanks For talking with me Sure And also a big thank you to our audience for listening.
To this and other episodes of energy talks, we always welcome your questions and feedback. please send us an email to podcast at omicronenergy.com. Omicron has several years of experience in power system testing data management and cybersecurity and offers the matching solution for your application.
For more information visit our website at omiconenergy. com. Please join us for the next episode of Energy Talks. Goodbye, everyone!
Other episodes covering the same guests and topics, from across The B2B Podcast Index.