Key takeaways
Secure IEC 61850 authentication is achievable without compromising protection performance
Vendor readiness varies, requiring a phased, multi-vendor strategy
A viable framework is emerging for the transition toward Zero Trust digital substation architectures
Practical testing environments accelerate validation and increase confidence in deployment
Executive Summary

As SSEN Transmission accelerates the deployment of digital substations, securing IEC 61850 communications has become critical to protecting national infrastructure. SSEN Transmission approached PNDC to evaluate the feasibility of implementing secure authentication aligned with IEC 62351. The study delivered a clear roadmap for strengthening substation cybersecurity without compromising operational reliability. This feasibility study examines the practical implementation of authentication mechanisms within IEC 61850-based systems for transmission utilities. It aims to assess current industry practices, vendor capabilities, and emerging technologies to ensure secure communication between Intelligent Electronic Devices (IEDs) and control systems. The findings provide actionable insights and recommendations to support SSEN Transmission in strengthening its cybersecurity posture while maintaining operational reliability.
The Challenge
IEC 61850 standard enables high speed, interoperable substation automation—but its original design prioritised performance and interoperability over security. As digital substations become increasingly connected, SSEN Transmission identified growing exposure to cyber threats such as Generic Object-Oriented Substation Event (GOOSE) spoofing, Manufacturing Message Specification (MMS) session hijacking, and man in the middle attacks. Traditional “trust by default” models were no longer sufficient for a modern transmission network.
The Objective
SSEN Transmission sought a practical, evidence based assessment of:
- Authentication and security readiness across its IED estate
- Vendor support for IEC 62351 security mechanisms
- Feasible pathways to secure IEC 61850 without impacting protection performance
The Approach
Review of IEC 62351 and substation cybersecurity best practices
Assessment of SSEN Transmission’s existing IED capabilities
Identification of protocol level and implementation gaps
Design of a secure MMS over TLS (Transport Layer Security) test framework

Key Insights
Vendor support for IEC 62351 features varies significantly
Legacy deployments lack cryptographic integrity for critical messaging
Secure MMS over TLS is feasible with careful configuration
Practical tools exist to validate authentication in live environments

Outcomes & Value
A clear feasibility assessment for secure IEC 61850 authentication
Actionable recommendations for endpoint hardening, identity governance, and secure communications
A fully defined test plan for future live demonstrations
PNDC were a key partner in delivering our SD 1 IEC 61850 authentication proof of concept. Their team brought real expertise and a practical, delivery-focused approach – gathering current market insight, carrying out vendor engagement, and documenting clear recommendations. This work has strengthened our roadmap for implementing secure IEC 61850 communications.
Future Demonstration and Capability Opportunities
Looking ahead, PNDC is well-positioned to support further exploration, demonstration, testing, and validation of secure IEC 61850 digital substation concepts where required. While the focus of this study was on feasibility and readiness, PNDC has invested in Europe’s first fully operational digitised virtual substation (i.e., a replica environment integrating real primary and secondary plant, multi-vendor IEDs, and advanced simulation capabilities), which provides a unique platform for future work.

An example of PNDC’s broader capability in this area is its collaboration with long-term strategic partner UK Power Networks (UKPN) on the Constellation programme. This world-first initiative explores how substations can host powerful computing platforms, transforming them into intelligent, distributed hubs capable of analysing large volumes of operational data in real time. Such approaches support dynamic network reconfiguration, improved asset utilisation, and increased integration of renewable generation.
- Demonstrating validated configuration approaches, including testing governance models, security controls, and operational workflows in realistic environments.
- Developing and validating reference architectures for secure IEC 61850 digital substations that can be replicated across networks.
- Exploring interoperability and legacy integration, addressing coexistence between modern IEC 61850 systems and established operational technology assets.
- Assessing long-term cyber resilience, evaluating how security controls perform across the full asset lifecycle—not only at commissioning.

