Case Study
Strengthening resilience in digital substations through secure authentication
As transmission networks become increasingly digital, securing critical communications is essential to safeguarding national infrastructure. This project explores how secure authentication aligned with IEC 62351 can be implemented within IEC 61850 systems—helping utilities reduce cyber risk while maintaining the performance and reliability of next-generation substations.

Key takeaways

Secure IEC 61850 authentication is achievable without compromising protection performance

Vendor readiness varies, requiring a phased, multi-vendor strategy

A viable framework is emerging for the transition toward Zero Trust digital substation architectures

Practical testing environments accelerate validation and increase confidence in deployment

Executive Summary

Secure authentication in IEC 61850

As SSEN Transmission accelerates the deployment of digital substations, securing IEC 61850 communications has become critical to protecting national infrastructure. SSEN Transmission approached PNDC to evaluate the feasibility of implementing secure authentication aligned with IEC 62351. The study delivered a clear roadmap for strengthening substation cybersecurity without compromising operational reliability. This feasibility study examines the practical implementation of authentication mechanisms within IEC 61850-based systems for transmission utilities. It aims to assess current industry practices, vendor capabilities, and emerging technologies to ensure secure communication between Intelligent Electronic Devices (IEDs) and control systems. The findings provide actionable insights and recommendations to support SSEN Transmission in strengthening its cybersecurity posture while maintaining operational reliability.

The Challenge

IEC 61850 standard enables high speed, interoperable substation automation—but its original design prioritised performance and interoperability over security. As digital substations become increasingly connected, SSEN Transmission identified growing exposure to cyber threats such as Generic Object-Oriented Substation Event (GOOSE) spoofing, Manufacturing Message Specification (MMS) session hijacking, and man in the middle attacks. Traditional “trust by default” models were no longer sufficient for a modern transmission network.

The Objective

SSEN Transmission sought a practical, evidence based assessment of:

  • Authentication and security readiness across its IED estate
  • Vendor support for IEC 62351 security mechanisms
  • Feasible pathways to secure IEC 61850 without impacting protection performance

The Approach

The feasibility study followed a structured methodology:

Review of IEC 62351 and substation cybersecurity best practices

Assessment of SSEN Transmission’s existing IED capabilities

Identification of protocol level and implementation gaps

Design of a secure MMS over TLS (Transport Layer Security) test framework

Figure 1 Testing secure authentication in IEC 61850 substations

Diagram
Figure 1: Testing secure authentication in IEC 61850 substations

Key Insights

Vendor support for IEC 62351 features varies significantly

Legacy deployments lack cryptographic integrity for critical messaging

Secure MMS over TLS is feasible with careful configuration

Practical tools exist to validate authentication in live environments

Figure 2: Simplified test setup for secure MMS communication

Diagram
Figure 2: Simplified test setup for secure MMS communication.

Outcomes & Value

The study delivered:

A clear feasibility assessment for secure IEC 61850 authentication

Actionable recommendations for endpoint hardening, identity governance, and secure communications

A fully defined test plan for future live demonstrations

PNDC were a key partner in delivering our SD 1 IEC 61850 authentication proof of concept. Their team brought real expertise and a practical, delivery-focused approach – gathering current market insight, carrying out vendor engagement, and documenting clear recommendations. This work has strengthened our roadmap for implementing secure IEC 61850 communications.

 

Future Demonstration and Capability Opportunities

Looking ahead, PNDC is well-positioned to support further exploration, demonstration, testing, and validation of secure IEC 61850 digital substation concepts where required. While the focus of this study was on feasibility and readiness, PNDC has invested in Europe’s first fully operational digitised virtual substation (i.e., a replica environment integrating real primary and secondary plant, multi-vendor IEDs, and advanced simulation capabilities), which provides a unique platform for future work.

This environment can be used o design and test secure digital substation architectures under representative operational conditions. It enables controlled experimentation with authentication, interoperability, performance, and resilience prior to deployment on live networks.
RTDS lab at PNDC's Wardpark

An example of PNDC’s broader capability in this area is its collaboration with long-term strategic partner UK Power Networks (UKPN) on the Constellation programme. This world-first initiative explores how substations can host powerful computing platforms, transforming them into intelligent, distributed hubs capable of analysing large volumes of operational data in real time. Such approaches support dynamic network reconfiguration, improved asset utilisation, and increased integration of renewable generation.

Strengthen your digital substation cybersecurity strategy
Partner with PNDC to assess risk, validate secure architectures, and accelerate the adoption of authenticated IEC 61850 communications.
Building on these foundations, PNDC supports future activities aligned with utility needs, including:
  • Demonstrating validated configuration approaches, including testing governance models, security controls, and operational workflows in realistic environments.
  • Developing and validating reference architectures for secure IEC 61850 digital substations that can be replicated across networks.
  • Exploring interoperability and legacy integration, addressing coexistence between modern IEC 61850 systems and established operational technology assets.
  • Assessing long-term cyber resilience, evaluating how security controls perform across the full asset lifecycle—not only at commissioning.
These capabilities provide a flexible foundation for future phases of work, helping utilities progress from feasibility studies to live validation and operational assurance when timing, resources, and priorities align.

Get in touch →

Connect with PNDC’s project lead, Dr Kinan Ghanem, on LinkedIn.
View all Case Studies