The Smart Grid (SG) is a cornerstone of modern society, providing the energy required to sustain billions of lives and thousands of industries. Unfortunately, as one of the most critical infrastructures of our World, the SG is an attractive target for attackers. The problem is aggravated by the increasing adoption of digitalisation, which further increases the SG's exposure to cyberthreats. Successful exploitation of such exposure leads to entire countries being paralysed, which is an unacceptable -- but ultimately inescapable -- risk. This paper aims to mitigate this risk by elucidating the perspective of real practitioners on the cybersecurity of the SG. We interviewed 18 entities, operating in diverse countries in Europe and covering all domains of the SG -- from energy generation, to its delivery. Our analysis highlights a stark contrast between (a)research and practice, but also between (b) public and private entities. For instance: some threats appear to be much less dangerous than what is claimed in related papers; some technological paradigms have dubious utility for practitioners, but are actively promoted by literature; finally, practitioners may either under- or over-estimate their own cybersecurity capabilities. We derive four takeaways that enable future endeavours to improve the overall cybersecurity in the SG. We conjecture that most of the problems are due to an improper communication between researchers, practitioners and regulatory bodies -- which, despite sharing a common goal, tend to neglect the viewpoint of the other `spheres'.
翻译:智能网(SG)是现代社会的基石,它提供了维持数十亿生命和数千个产业所需的能源。不幸的是,作为我们世界最关键的基础设施之一,SG是袭击者最有吸引力的目标之一。这一问题由于日益采用数字化而更加严重,这进一步增加了SG对网络威胁的暴露。成功利用这种暴露导致整个国家瘫痪,这是不可接受的 -- -- 但最终是不可避免的 -- -- 风险。本文件旨在通过阐明实际从业者对SG网络安全的看法来减轻这一风险。我们采访了18个实体,这些实体在欧洲不同国家运作,覆盖了SG的所有领域 -- -- 从能源生产到交付。我们的分析突出表明了(a)研究和实践之间以及(b)公共和私营实体之间的鲜明对比。例如:一些威胁似乎远不如相关文件中所说的那样危险;一些技术范例对从业者有用,但得到文献的积极宣传;最后,从业者可能低估或过高地估计了他们自己的网络安全能力。我们从四个实体的角度,从能源生产到交付。我们的分析突出表明了(a)研究和实践之间的鲜明对比,但也是(b)公共实体与私人实体之间的严重差异,尽管我们仍努力改进了监管机构之间的共同观点。