An energy-first cybersecurity platform for solar, storage and the grid | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


Specialised cybersecurity platform SentryOT, created by Romanian energy engineering company Enevo, is designed as “an end-to-end resilience platform for the energy sector”, its developers have said.

Enevo is a leading engineering, procurement and construction contractor in Romania working across the entire energy value chain. It unveiled the SentryOT platform, developed by its in-house cybersecurity division, during the first half of 2025.

The platform is designed for operational technology (OT) including solar and wind power plants, battery energy storage systems (BESS), substations and automated grid networks.

Enevo’s move into cybersecurity was driven by customer demand, with the first request coming from Romania’s transmission system operator.

Mircea Stremtan, director of sales & marketing at SentryOT, told pv magazine Enevo differs from its competitors in cybersecurity due to its background in energy rather than IT.

“Enevo was built around real energy infrastructure, so we understand the operational and physical consequences that a cybersecurity failure can have. We have developed our cybersecurity expertise alongside that experience in the energy sector, rather than starting with an IT cybersecurity platform and adapting it to energy,” Stremtan explained.

“There were already very good cybersecurity solutions on the market, but we saw a need for a platform tailored to the specific requirements of energy infrastructure.”

While demonstrating the platform to pv magazine, Stremtan highlighted that SentryOT first completes an asset inventory highlighting the vendor, model, version and firmware of each device. It then manages the assets over time, checking whether anyone has modified them, whether there are known vulnerabilities in that firmware and whether newer versions are available.

“By mapping how devices talk to each other, within a plant and between plants, you can understand immediately whether there is a malicious communication, for example a rogue or compromised device talking directly to a primary equipment,” he explained.

Stremtan added that while standard approaches in the industry listen to communications and compare them to known attack signatures, the SentryOT model adds a network learning component on top.

“We learn how the infrastructure normally behaves, and if it behaves in any way differently, we flag it,” he explained. “We can see the actual command flows: dispatch sends commands to telecontrol, which closes a coupler or relay and feeds the energy into the grid.”

SentryOT notifies the plant’s dispatch centre of all anomalies, not just attacks. In each case, it raises a flag and an operator decides whether to act and if to escalate national security authorities. This makes the platform specifically valuable to power plants, as unlike a computer, it cannot be restarted or disconnected over every anomaly. 

Stremtan added the SentryOT model brings together the IT, OT and networking sides of the infrastructure in a single view. 

“Traditionally, you might need several different tools and teams to understand what is happening across these areas,” he explained. “By bringing them together, you can see the full chain of an incident and respond much more quickly.”

Alongside the platform itself, Enevo offers 24/7 OT cybersecurity monitoring and energy-specialized incident response through its security operations centre OmniSOC. Around 100 energy production, transmission and storage assets are currently onboarded to OmniSOC, Stremtan said.

He added that while large companies with dozens of plants and in-house expertise can run the technology themselves, the EU’s new cybersecurity law, NIS2, requires operators across the sector to have 24/7 monitoring.

Stremtan said SentryOT was developed before NIS2 but matches its requirements. “For us, it is a great example that the concept we have developed and the needs of the market are covered and regulated Europe-wide,” he said, adding that Romania was one of the first countries to transpose NIS2 into national law.

Stremtan said attacks on energy infrastructure are typically driven by either economic motives or an aim to destabilise a country. “There are private, money-driven attacks, and there are attacks backed by state actors with virtually unlimited resources,” he said. “In today’s geopolitical context, state-actor attacks are increasing.”

He added that the main goal of the EU’s legislation is to bring cybersecurity on the operational side up to a consistently higher level. 

“What is extremely important is that NIS2 is not treated as a box-ticking exercise,” Stremtan said. “It needs to be operationalised, and that means having the technology to actively monitor and the expertise to actively supervise and respond. We protect private IPPs, but they all feed into the grid, so ultimately this is about the stability of individual states and of the EU as a whole.”

——————————————————-


Click Here For The Original Source.