NERC CIP · CIP-009 · BES Cyber Systems

Volt Typhoon is already inside US bulk electric infrastructure. Your CIP-009 recovery plan assumes they aren't.

CISA, the FBI, and the NSA published the joint advisory in February 2024. State-sponsored adversaries have been pre-positioned inside US critical infrastructure, including the bulk electric system, for years. CIP-009 was written for the moment that pre-positioning becomes activation. Most utility recovery plans were not. They assume a working Active Directory, an intact engineering workstation, a jump host the adversary does not already control.

If your last recovery exercise tested a hardware failure, you have not actually tested CIP-009.

What CIP-009 actually requires

CIP-009-6 governs Recovery Plans for BES Cyber Systems. Three requirements do the work.

R1: Recovery plans must specify activation conditions, roles and responsibilities, processes for backup and storage of information, and processes to preserve data for forensic analysis.

R2: Plans must be implemented and tested. Annual full operational exercise for High Impact BES Cyber Assets. Every 36 months for Medium Impact with External Routable Connectivity. The word "tested" is what an auditor reads first.

R3: Plans must be reviewed annually, updated when materially changed, and communicated to those with a documented role in execution.

What pre-positioning actually means

Volt Typhoon is the named example. It is not the only one. The intrusion has already happened. Initial access, often years ago, often through edge equipment on the IT side. Living-off-the-land techniques: no malware to detect. Lateral movement to OT-adjacent systems: jump hosts, engineering workstations, historians, dual-homed devices. Quiet reconnaissance of the SCADA environment. Adversary persistence inside the systems your recovery plan depends on.

When activation occurs, the recovery infrastructure CIP-009 calls for, the engineering workstation golden images, the configuration management servers, the Active Directory that authenticates your recovery operators, the backup repositories themselves, is already inside the adversary's reach. The recovery layer is part of the breach.

What the vault holds for a utility

The 8TB inside HyperBUNKER holds the artifacts that determine whether the utility can restart operations on day one of recovery, with the adversary still in the IT estate: SCADA project files and PLC/RTU configuration backups, HMI golden images, engineering workstation golden images, IEC 61850 SCD files for substation automation, protection relay settings, DCS configurations, OT-side credential and certificate material segregated from the production Active Directory, and the CIP-009 testing evidence pack itself, generated by the vault, tamper-evident, and audit-ready.

Does HyperBUNKER replace existing OT backup tools?

No. The vault sits behind the working OT backup tier. Existing software handles fast restores and granular recovery for routine cases. HyperBUNKER holds the recovery artifacts that survive when the OT backup infrastructure itself is the target, or when the adversary has been inside the estate for months.

How does this fit with the CIP-005 Electronic Security Perimeter?

The vault sits outside the ESP. By design. The ESP is a logical perimeter enforced at network devices. HyperBUNKER is a physical perimeter enforced by hardware disconnect. The two are complementary: the ESP defends the production environment, the vault holds what survives if the ESP is breached.