Non-routable protocols must be addressed

Mohammad Saad highlights the limitations of current cybersecurity frameworks like NERC CIP

In his Sept. 16, 2026, blog, “Cybersecurity Limits the Path. Engineering Limits the Consequence,” Mohammad Saad addressed an issue fundamental to the cybersecurity and safety of industrial control systems: A device does not have to be IP-routable for its compromise to have safety or reliability consequences. Saad put it plainly: “The valve is not routable” is not the end of the cyber discussion. He explained that while devices such as analog transmitters, hardwired thermocouples, pneumatic actuators and other field devices may not be IP-routable, this does not mean cyber cannot influence the process function in which those devices participate.

A transmitter can correctly measure an abnormal condition while digital logic elsewhere in the control system substitutes, corrupts, delays, or misinterprets that measurement. A valve itself may not be routable while the controller commanding that valve is accessible from an engineering workstation. The physical field device can remain completely healthy while the digital logic determining what to do with its signal has been manipulated. This applies to electric operations as well as other industrial processes. The fundamental cybersecurity question is therefore not simply whether a device can be reached over an IP network, but what authority the digital system has over the physical process.

The electric grid operates on physics, not packets

The electric grid is an extraordinarily complex cyber-physical system. Its reliable operation depends on measurements from sensors, on decisions made by protection and control systems, and on physical actions involving breakers, transformers, generators, motors, and other equipment. Protecting only the routable portions of that system creates a potentially dangerous assumption that if a device communicates using a non- IP-routable protocol, it cannot be a cybersecurity concern.

That assumption is difficult to reconcile with the engineering reality of a cyber-physical system where a compromised sensor does not have to execute malware or contain an IP address or traverse Ethernet. If the resulting information can cause an automated system to operate incorrectly, or cause an operator to make an incorrect decision, then the physical system can still be affected by a cyber event. This is why cybersecurity for critical infrastructure needs to move beyond the question of what can the attacker reach to what can the attacker cause the system to believe, and ultimately to what physical consequence can result from that false information.

The NERC CIP Gap

The NERC CIP framework establishes cybersecurity requirements for specified cyber systems and assets associated with the Bulk Electric System. Its applicability depends on defined categories, impact levels, and electronic-access and cybersecurity criteria. NERC CIP-005 specifically uses routability in defining the Electronic Security Perimeter requirements. CIP-005-5 R1.1 requires applicable Cyber Assets connected to a network via a routable protocol to reside within a defined ESP. NERC's supporting rationale also explains why direct serial, non-routable connections are not subject to the same perimeter-type security requirements as there is no universally applicable firewall or perimeter control for every serial connection. That framework is necessary.

However, the NERC CIPs create a potential gap when cybersecurity boundaries do not align with the engineering boundaries of the physical process. A field device can be outside an electronic security perimeter, or communicate through a hardwired or non-routable protocol, while the information it provides remains essential to operating and protecting the grid. Specifically, many sensors and field devices used in electric operations communicate through non-routable protocols or hardwired signals.

Yet the information they provide can influence protection, control, dispatch, and operator decisions. The cybersecurity question therefore should not end with “Is the sensor routable?” but should begin with “What happens to the grid if the information from that sensor is wrong, unavailable, delayed, or manipulated?” If corrupted sensor information can cause a controller to take the wrong action, or cause an operator to make the wrong decision, the absence of an IP address does not make the cyber risk disappear. The question is whether the NERC CIP framework adequately follows that information through the control system when the sensor, signal, or communication path falls outside conventional network-security boundaries. The concern is what happens when a sensor communicates through a non-routable protocol or hardwired connection when the device or communication path falls outside applicable cybersecurity protections. This is a gap between cybersecurity boundaries and engineering consequences.

Get your subscription to Control's tri-weekly newsletter.

FERC and NERC have recognized that sensors matter

The sensor issue was explicitly raised during the Mar. 20, 2025, FERC/NERC joint workshop on supply-chain risk management. During the discussion, NERC addressed sensors and the relationship between sensor information, cyber assets, and the 15-minute reliability criterion: “Let's go specifically to sensors. If that information provided data to a dispatcher, that could within 15 minutes affect his decision, then it meets the definition of a cyber asset and as such, would fall under the standards,” the NERC representative said. FERC responded: “And every sensor would matter. Because if you're spoofing one sensor, it's got problems there.” The significance of this exchange is important. It recognizes that the cybersecurity significance of a sensor cannot necessarily be determined by whether the sensor itself is IP-routable.

The relevant issue is what can be affected by information from that sensor. That raises an obvious follow-up question. If a sensor can provide information to a dispatcher that can affect a Bulk Electric System decision within 15 minutes, why should the cybersecurity protection associated with that sensor depend on whether its communication protocol is routable? The answer cannot simply be that the sensor is “not a network device.” It is an engineering device providing information that may be used to operate a cyber-physical system.

The Iranian attacks provide a real-world warning

Recent Iranian cyber activity against water systems and other operational technology (OT) environments provides another reason to reconsider cybersecurity models based primarily on network reachability. The important lesson from these incidents is not simply that an attacker can penetrate an Internet-connected network but that physical consequences can occur downstream of the device or communication path through which an attacker initially gains influence.

A controller, engineering workstation, communications converter or other intermediary can provide the pathway through which an attacker changes information used to control a physical process. The final sensor or actuator may not have an IP address but that does not make the resulting physical consequence any less real.  An attacker does not necessarily need to compromise the final physical device — just influence the information or logic that determines how the physical device is operated. This is what Iran has done by compromising water sector operator displays and alarms.

Summary

The electric industry needs to protect the information upon which the grid depends. Ultimately, the grid does not operate on packets, but on physics. A process sensor does not need an IP address to provide bad information. A hardwired signal does not need Ethernet to be manipulated. A valve or relay does not need an IP address for incorrect digital logic to cause it to move at the wrong time.

The critical question is therefore not whether the final device is routable, but whether false, missing, delayed, or manipulated information from that device can affect the operation of the electric system. Recent cyber incidents involving Iran, and the broader activities attributed by U.S. authorities to state-sponsored actors from China and Russia, demonstrate why network reachability alone cannot define the entire cybersecurity problem. Cybersecurity must follow process authority and potential physical consequences, not simply the path of the packet. The electric grid is too important to protect only the things that look like networks.

About the Author

Joe Weiss

Cybersecurity Contributor

Joe Weiss P.E., CISM, is managing partner of Applied Control Solutions, LLC, in Cupertino, CA. Formerly of KEMA and EPRI, Joe is an international authority on cybersecurity. You can contact him at [email protected]

Sign up for our eNewsletters
Get the latest news and updates