Case study · Grid operator
Zero-trust access for 40,000 field devices
Identity-based access replaced shared credentials on substation and field equipment.

- Client
- Grid operator
- Industry
- Energy & resources
- Practices
- Security & risk, Operations
- Duration
- 20 weeks, then managed service
Context
A transmission and distribution operator with 1,200 substations and 3,000 field engineers.
Challenge
Engineers reached substation devices with shared passwords kept in a spreadsheet, and the regulator had flagged it as a critical finding.
Approach
How the work ran
- WK 0–4FrameMapped every access path to substations and agreed a target: no shared credentials anywhere.
- WK 4–8ProvePut 50 substations behind an access broker tied to people, devices and work orders.
- WK 8–20BuildRolled out to all 40,000 devices in regional waves, with session recording for audit.
- Access broker
- PKI
- Azure AD
- IEC 62443 zones
- Splunk
Results
What changed
40,000
Devices enrolled
0
Critical audit findings in two cycles
12min
Median time to grant access
“Our auditors asked for the evidence and we sent a link.”
Related work
More from this route
Still sharing passwords in the field?
We will map your access paths to substations and plants in a two-week review.
Review your field accesshello@speey.com
