For Energy & Utilities

Restarting Operational Control After a Cyber Incident

When the SCADA network goes down and the control room loses trust in everything, the grid does not restart from memory.

What has already happened

Jan 2024, Lviv, Ukraine. FrostyGoop ICS malware sent Modbus commands directly to heating controllers serving 600 apartment buildings. Sub-zero temperatures. 48 hours without heat. The attacker had been inside the network since April 2023, nearly a year before triggering the disruption.

Aug 2024, Halliburton, US. RansomHub ransomware. Systems taken offline across global operations. Customers unable to generate invoices or purchase orders. $35 million in confirmed losses across energy production and distribution clients.

Norsk Hydro (2019) remains the clearest case study: LockerGoga took 60 countries offline, aluminium plants switched to manual, estimated losses reached $71M. Recovery took months.

The pattern

None of these organisations lost operational control because they lacked backups. They lost control because the systems required to trust and use those backups — Active Directory, engineering workstations, SCADA management servers — were gone or compromised in the same sweep.

When you cannot trust your identity layer, you cannot safely restore anything that depends on it. That includes every configuration your grid runs on.

How HyperBUNKER closes the gap

HyperBUNKER is a physically isolated recovery anchor, deployed before an attack so the configuration state your grid depends on survives outside the blast radius. What goes inside for an energy operator:

The regulatory frame

Energy operators sit in NIS2 Annex I, Sector 1, Essential Entities. Article 21(2)(c) requires tested business continuity and disaster recovery capability. NERC CIP-009 requires documented recovery plans for BES Cyber Systems. IEC 62443 requires recovery capability commensurate with the security level of the asset.

HyperBUNKER is the demonstrable piece for any of these frameworks: a physical, tested, physically isolated recovery capability that a supervisory authority or auditor can inspect.