Professional Practice in Cybersecurity Risk Management for Industrial Control Systems at Power Distribution Substations in Abuja

📖 ABSTRACT/OVERVIEW

Industrial control systems including SCADA and distributed control systems at power distribution substations in the Federal Capital Territory are increasingly connected to corporate networks and external communication links, creating cybersecurity vulnerabilities that could be exploited to disrupt electricity supply or damage substation equipment. This study examines professional practice in cybersecurity risk management for ICS environments at six power distribution substations operated by the Abuja Electricity Distribution Company. A cybersecurity risk assessment methodology based on the IEC 62443 industrial automation and control system security standard was applied at each substation, encompassing asset inventory and network architecture review, vulnerability scanning, communication protocol security analysis, and physical security assessment. Findings reveal that all six substations had unpatched software vulnerabilities in SCADA workstations, three substations lacked network segmentation between the operational technology and corporate IT networks, and default authentication credentials had not been changed on two substation RTUs. Risk prioritization using a consequence-likelihood matrix identified nine critical risk scenarios requiring immediate remediation. A cybersecurity improvement programme encompassing network segmentation, patch management procedures, authentication hardening, and incident response planning is documented and costed. The study provides a cybersecurity management framework applicable to other distribution network operators in Nigeria's increasingly digitized power sector. Keywords: ICS cybersecurity, SCADA security, substation, IEC 62443, power distribution Abuja

Need Complete Chapters of the Above Topic?

Get high-quality, Zero-AI research materials with current citations.

Request via WhatsApp 💬