• Sector: Electricity Transmission & Critical National Infrastructure (CNI)
  • Delivery Scope: Network & Domain Separation, Active Directory, Firewall Segmentation, Substation Readiness Engineering, Managed Service Handover
  • Compliance Standards: UK NIS Regulations, Enhanced UK Cyber Assessment Framework (CAF), IEC 62443
  • Scale: 100+ Remote Transmission Substations

Project Impact at a Glance


100+


Transmission substations surveyed and upgraded

IEC 62443


Industrial cyber security compliance standard met

Enhanced CAF


Aligned to UK critical infrastructure regulations

Zero Disruption


Continuous energy transmission during delivery

The Challenge: Decoupling Complex OT Networks Across Remote Environments


Our client’s operational technology (OT) systems were historically tied to corporate shared infrastructure. Meeting NIS regulations and the UK Enhanced Cyber Assessment Framework required them to establish an independently governed, highly secure network domain across 100+ substations without interrupting grid power transmission.

  1. Regulatory Demands: National critical infrastructure requirements dictated segregated identity and network perimeters to prevent lateral intrusion from IT to OT systems
  2. Remote Physical Environments: Equipment had to be staged and deployed across remote, rugged substation environments
  3. Continuous Transmission: Power transmission is critical national infrastructure; installation, firewall zoning, and cutover carried a zero-tolerance policy for service interruption

The Solution: Multi-Year Network & Domain Separation Programme


Sword was chosen as strategic delivery partner to design and deploy an independent network and identity domain, implementing strict IEC 62443 zoning and deploying ruggedised equipment across more than 100 transmission sites

Substation Discovery & Physical Audits

Surveyed more than 100 substation environments to evaluate power conditioning, rack space, resilience, and environmental limits

Autonomous Domain & Firewall Zoning

Engineered a greenfield Active Directory and identity framework, deploying firewall micro-segmentation aligned with IEC 62443 to isolate substation assets from corporate domains

Ruggedised Deployment & Managed Handover

Configured, tested, and staged hardened network hardware through a verified supply chain model, producing as-built documentation for ongoing managed service support

Measurable Business Outcomes


Efficiency Gain

Delivered a scalable network architecture aligned with upcoming multi-million-pound capital investment frameworks

Regulatory Compliance

Isolated grid operations behind verified IEC 62443 security boundaries, achieving compliance with NIS and Enhanced UK CAF mandates

User Experience

Completed upgrades across 100+ high-voltage substations with zero disruption to public grid transmission

Future-Proof Scalability

Built greenfield Active Directory and dedicated security perimeters that operate completely independently of group corporate networks

"Sword was appointed as strategic technology partner to lead the design and delivery of a multi-year Network and Domain Separation Programme... applying strict governance and validation processes, with designs reviewed by Technical Design Authority and risk teams."

Head of OT and Cyber, UK TNO

More Information

All hardware is pre-staged, hardened, and tested in controlled workshop environments before dispatch, minimising installation time and failure risk in remote substations

All hardware is pre-staged, hardened, and tested in controlled workshop environments before dispatch, minimising installation time and failure risk in remote substations

Need help?

Whether you are strengthening operational resilience, securing critical infrastructure, or improving organisational preparedness, our UK-based experts are ready to support your mission-critical operations

Speak to a subject matter expert

Privacy Preference Center