Strommasten mit Stromleitungen neben einer befahrenen Straße mit Autos in einer Abendstimmung

Christian Lettner

17.06.2026

Duration of reading 10 Min

Digital Transformation

Christian Lettner

17.06.2026

Duration of reading 10 Min

When Cybercriminals Tamper with the Power Grid

One step ahead of cyberattacks on smart grids and industrial IoT devices.

keyvisual-ruggedcom-rx1400vpe-rz-lowres-1_original_fa1c3c8c7261c5261c824f45971f118d217a7c09-Kopie-1024x724

When Cybercriminals Tamper with the Power Grid

Imagine that cybercriminals aren’t tampering with a single device, but are using electric car charging stations as a gateway to destabilize an entire power distribution network. Sounds like Hollywood? Not at all; scenarios like this are no longer just theoretical — they are real threats that energy providers and device manufacturers must deal with today. Transformers, battery storage systems, and smart meters are also components of the Industrial Internet of Things (IIoT) that are vulnerable to attacks and must therefore be protected. Successful attacks can result in electricity theft, extortion, or blackouts. This is exactly where CREIS (Cybersecurity and Resilience for System-Critical Energy Infrastructure and Its Automation Systems) comes in — a research project between Graz University of Technology and Siemens, funded by the Austrian Research Promotion Agency (FFG), that aims to fundamentally rethink the cybersecurity of critical energy infrastructure.

The energy transition is inconceivable without digitalization. Sensors, edge devices, and cloud platforms form a tightly integrated IIoT that makes real-time control and predictive maintenance possible in the first place. Modern digitalization platforms show the way forward: cloud-based real-time analysis for smart low-voltage grids. But what is connected is also vulnerable. Forecasts indicate that by 2044, there will be more than 150 million connected devices in use worldwide in the electricity, water, and gas sectors alone. Each and every one of them is a potential point of vulnerability.

“Digitalization and connectivity present enormous opportunities, but they also dramatically increase the attack surface,” says Stefan Mangard, head of the “Secure Systems” research group at the Institute of Information Security at Graz University of Technology (TUG-ISEC) and scientific coordinator of CREIS. “Today, we need to develop device-level security strategies that not only address current threats but also provide protection against classes of attacks that we won’t fully understand for several years.”

In this field, Graz University of Technology ranks among the world’s best: The sensational processor vulnerabilities “Meltdown” and “Spectre” were co-discovered at TUG-ISEC. In addition, ASCON — a scheme for lightweight authenticated encryption developed in Graz — has been selected by the U.S. National Institute of Standards and Technology (NIST) as an international standard.

Holistic Approach

What makes CREIS unique: The project does not view the threat landscape in isolation, but rather takes a holistic approach. The researchers analyze attack vectors on multiple levels simultaneously — ranging from traditional software vulnerabilities to so-called side-channel attacks, in which information is extracted not through the direct data path but via physical side effects such as power consumption or computation time, all the way to indirect attacks via connected infrastructure.

CREIS pursues four key, interrelated lines of research:

1. Analysis of Potential Attacks
The researchers are analyzing components of energy systems using new, expanded attack models. The focus is not only on known vulnerabilities, but also on targeted research into new types of attacks — such as those that combine software and hardware attacks.

2. Expansion of the Co-Simulation Environment
At its core is the expansion of the BIFROST co-simulation framework, which was developed by Siemens. This makes it possible to simulate complex energy systems virtually. Now, BIFROST is to be further developed so that it can also realistically simulate cyberattacks. A real-world demonstration facility is integrated directly into the co-simulation, allowing attacks on the power grid to be replicated in a way that can be scientifically analyzed.

3. Developing New Protective Measures
Based on the insights gained, protective mechanisms are being developed that do not merely identify individual vulnerabilities but address entire classes of attacks — both software-based and hardware-supported. The approaches are implemented as laboratory prototypes and evaluated in the co-simulation environment.

4. Update and Certification Concepts for the Field
In practice, IoT devices in the power grid are often located in hard-to-reach places — such as in substations or distribution boxes. Updates must therefore be installed over-the-air (OTA) or via the power line itself (Power Line Communication). CREIS is researching a holistic update process.

Infographic illustrating the topic of cybersecurity for the power grid© Siemens

“Our research focus at the device level centers on the update mechanisms described above and, for example, the question of how to ensure that only authorized software runs on the devices. At the system level, we are interested in the energy sector. In other words, how attacks on the energy system’s automation can be simulated as realistically as possible, and how such attacks affect the energy system,” explains Konrad Diwold, Senior Key Expert at Siemens Austria.

To ensure that research findings make their way from the laboratory into practical application, the project consortium is focusing on closely integrating simulation and reality. Siemens Austria is the technology partner of the energy research joint venture Aspern Smart City Research (ASCR) in Aspern Seestadt, Vienna. The smart grid test bed there comprises about 30 low-voltage grids, equipped with numerous sensors and components from the Siemens SICAM product family. “The synergy between ASCR and CREIS lies in the fact that the solutions developed can first be tested using realistic test data in the virtual BIFROST environment as part of the funded research project with Graz University of Technology. If this proves successful, a pilot project can be developed based on these results to validate the approaches in the ASCR test bed under real-world conditions and in collaboration with the joint venture partner Wiener Netze. Thanks to the experience we’ve gained from the Seestadt project, we can tailor our methods closely to actual system behavior right from the start and provide our research partners with practical frameworks for their research,” explains Alfred Einfalt, Principal Key Expert for Distributed Energy Systems at Siemens.

© Siemens

Substations such as the one pictured here are part of the real-world laboratory conditions at the Aspern Smart City Research energy research joint venture, where research approaches can be validated.

The economic aspect of this issue is significant. The global market for security systems in energy automation is projected to grow from $8.3 billion in 2024 to approximately $16 billion in 2032. The industrial automation sector as a whole is even larger, with growth projected to rise from 55.9 billion to 115 billion U.S. dollars by 2034. The protection technologies being researched in CREIS are deliberately not limited to the energy sector — they can be applied to other areas of industrial automation, such as the manufacturing industry or building automation.

The regulatory framework also works in CREIS’s favor. With the Cyber Resilience Act (CRA) and the NIS 2 Directive, the European Commission has established clear guidelines for the cybersecurity of digital products and critical infrastructure. Starting in 2025, energy companies, among others, will be required to implement extensive technical and organizational measures. These range from risk identification and incident management to securing the entire supply chain. However, exactly how this is to be implemented at the device and system levels is left up to the manufacturers and operators. CREIS aims to provide concrete, practical answers here.

A Strong Partnership

Another strength of the project lies in the combination of partners. With approximately 70 researchers, TUG-ISEC is Austria’s largest university institute for information security and has been active for about 40 years. On the Siemens side, expertise from two areas is being combined: The research department in Vienna contributes expertise in Industrial IoT, co-simulation, smart grids, and data analytics, while the software and firmware development and R&D team in Graz contributes expertise in the development and testing of cyber-secure industrial automation products — from field devices to the cloud. “The real challenge lies in integrating real hardware with the simulation. This means we have to identify the relevant security characteristics of devices and then model them in such a way that they can be incorporated into the simulation,” says Sandra Dominikus, Siemens’ in-house CREIS project coordinator and product security expert for industrial automation, emphasizing the practical relevance of this approach.

“Our software department develops products and solutions that are used in various industrial applications worldwide. Through the approaches and sample implementations we are developing in this project together with researchers from Graz University of Technology, our developers are gaining exposure to the latest findings in this field. This, in turn, benefits us in the development of security features for our industrial control systems, some of which are also developed and implemented in Graz,” adds Dominikus.

At the end of the three-year project, the results should include more than just scientific publications and laboratory prototypes. The consortium is also planning to issue a report with recommendations specifically aimed at energy companies, equipment manufacturers, and policymakers. The message: Cybersecurity for critical infrastructure is no longer a luxury or a future issue, but a challenge that requires concrete solutions now. CREIS does exactly that: it seeks not merely to play catch-up with attackers, but to counter them with a well-thought-out, scientifically grounded defense strategy — from the chip level all the way up to the entire system.

About the author

Christian Lettner
Christian Lettner

Editor-in-chief hi!tech