Energy and Utilities

Every new tool is new CIP scope.

Schedule a meeting

Utilities under NERC CIP and NIS2

Security built for the grid and the utilities behind it

Get log evidence for your CIP audit from servers you own, without touching grid control systems.

Requirements

CIPRequirementARRTECH evidence
CIP-007 R4.1Log events for after-the-fact investigation.Collection from Windows, identity, VPN and firewall sources. →
CIP-007 R4.2.2Alert on detected logging failure.A silent-source alert. →
CIP-007 R4.3Retain at least 90 days.Retention set per source or group. →
CIP-007 R4.4Review at intervals of 15 days or less.Scheduled reports by email, dated. →
CIP-002Security event monitoring is an EACMS.Role-based rights and a console audit log. →

NERC CIP-007

Get CIP-007 R4 evidence without new risk

CIP-007 R4 asks you to log security events, alert when logging fails, keep logs for 90 days and review them at least every 15 days. ARRTECH SIEM runs on servers you own and ships ready NERC CIP reports for that evidence.

CIP-007 R4.2.2

Alert the moment logging fails

CIP-007 R4.2.2 requires an alert when security event logging fails. ARRTECH SIEM raises an alert when any log source stops sending.

Remote sites

Watch remote substations over weak links

Substations often sit on slow or unreliable links. The ARRTECH agent keeps collecting when a link drops, sends the logs encrypted when it returns, and shows when each site last reported.

Volt Typhoon

Spot state-backed intruders early

The 2024 joint advisory on Volt Typhoon recommends learning normal behavior to spot misuse of built-in tools. Cyberdroid AI Detection flags accounts and hosts acting unlike their own history, and changes nothing.

By rule

CIP-002

Security event monitoring is an EACMS. ARRTECH: Role-based rights and a console audit log.

Questions

Is there a CIP report?

Yes. ARRTECH SIEM ships ready NERC CIP reports and dashboards. Your audit still assesses you; ARRTECH does not claim to make you compliant.

What about remote substations?

If a substation’s link drops, the agent holds its logs and sends them, encrypted, when the link returns.

Would we see an attacker like Volt Typhoon?

Cyberdroid AI Detection compares every user, host and application with its own normal behavior, as the joint advisory recommends, and changes nothing.

Who decides a response?

A person. ARRTECH SOAR emails the approver up to five options and waits.

What stays with you?

Anything inside the control systems themselves, the internal network monitoring CIP-015 requires, and the CIP controls that apply to the SIEM itself.

Sources

Guide

What does NERC CIP-007 R4 require?

Log security events, alert when logging fails, keep logs 90 days and review them at least every 15 days.

Is a SIEM in NERC CIP scope?

A SIEM that monitors an Electronic Security Perimeter is an EACMS under CIP-002, so it has its own CIP duties.

How do utilities secure remote substations?

Collect logs from remote sites with an agent that buffers during outages and alerts when a site stops reporting.

Next steps

Spot unusual behavior early. Learns what normal looks like for every user, computer and application from your SIEM, and flags what changes.

Available now

Get the evidence fast. Investigates each finding with read-only queries and hands a person the evidence. It never approves its own work.

Early access

Keep sensitive data in. Checks email, uploads, USB drives and AI prompts before sensitive data leaves the computer.

Respond with a person in charge. Runs incident response steps through your existing tools, with a person approving each decision.

See every system. Collects and signs logs from more than 500 source types and links related events, with a verification tool for every export.

ARRTECH

© 2026 ARRTECH Corporation. All rights reserved.