CheckPoint Software > Case Studies > Securing ICS/SCADA Network: A Case Study of Central Hidroeléctrica de Caldas

Securing ICS/SCADA Network: A Case Study of Central Hidroeléctrica de Caldas

CheckPoint Software Logo
Technology Category
  • Automation & Control - Supervisory Control & Data Acquisition (SCADA)
  • Networks & Connectivity - Gateways
Applicable Industries
  • Electrical Grids
  • National Security & Defense
Applicable Functions
  • Logistics & Transportation
  • Quality Assurance
Use Cases
  • Tamper Detection
  • Traffic Monitoring
Services
  • Cybersecurity Services
  • System Integration
About The Customer
Central Hidroeléctrica de Caldas (CHEC) is a major electricity generator and distributor in Colombia. It is part of Grupo EPM, the second-largest business group in Colombia. Founded in 1944, CHEC pioneered the delivery of electricity for street lighting in the coffee-growing region of Caldas. Today, CHEC powers 40 municipalities with 100% electricity coverage in urban areas and 99.62% in rural areas, providing power and illumination for almost half a million customers. As the company grew and consolidated its power generation capabilities, it built transmission and distribution networks to deliver power across the regions. These networks are monitored and controlled by SCADA devices located in power plants and substations.
The Challenge
Central Hidroeléctrica de Caldas (CHEC), a major electricity generator and distributor in Colombia, faced a significant challenge in securing its Supervisory Control and Data Acquisition (SCADA) devices. These devices, located in power plants and substations, monitor and control the transmission and distribution networks that deliver power across the regions. However, these SCADA systems were deployed years ago, before cyber security controls were deemed necessary. As a result, they were vulnerable to cyber attacks that could potentially compromise one or more SCADA devices and gain control of vital systems. Furthermore, power plants generating more than 100 megawatts of power and substations transferring more than 115 KW were required to comply with security controls mandated by the Ministerio de Minas y Energía de Colombia and the Comisión de Regulación de Energía y Gas. The challenge was to secure the SCADA devices to prevent network infiltration by attackers and meet governmental security requirements for power generation plants, all while operating in harsh, inhospitable environments.
The Solution
To address these challenges, CHEC turned to Check Point's 1200R Ruggedized Gateways and R80 Cyber Security Management. The team designed a proof of concept to test the 1200R Rugged gateway in its environment, installing a gateway in one substation in Monitor Mode and a second system in another substation in online mode. The 1200R gateway, designed for deployment in harsh environments, provided integrated security as part of a complete end-to-end Industrial Control System (ICS) security solution. It enabled full visibility and granular control of SCADA traffic, allowing the team to log SCADA protocols, including commands, for forensic analysis. The R80 cyber security management system provided a single pane of glass for managing security across the SCADA environment, with policy, logging, monitoring, event correlation, and reporting in a single system. Multiple team members could work in Check Point R80 simultaneously without conflict, simplifying management across locations. Check Point Smart-1 5050 Appliances were also used to consolidate management for up to 50 systems, delivering full threat visibility and control of SCADA traffic.
Operational Impact
  • The implementation of Check Point's solutions resulted in significant operational benefits for CHEC. Prior to the deployment of Check Point 1200R Appliances, CHEC could not effectively monitor security for SCADA traffic to identify potential threats. With the new system, they gained complete visibility into application traffic from substations and devices. This not only improved their ability to identify and block threats, but also ensured high availability of monitoring and control data. The team now has peace of mind knowing that their SCADA systems are protected. In addition to their own security and technical teams, they have the Check Point experts standing behind them to work on cyber security issues. This has resulted in a significant relief for the team.
Quantitative Benefit
  • Gained visibility and control of SCADA monitoring traffic
  • Consolidated SCADA security management across locations
  • Blocked threats to ensure high availability of monitoring and control data

Case Study missing?

Start adding your own!

Register with your work email and create a new case study profile for your business.

Add New Record

Related Case Studies.

Contact us

Let's talk!
* Required
* Required
* Required
* Invalid email address
By submitting this form, you agree that IoT ONE may contact you with insights and marketing messaging.
No thanks, I don't want to receive any marketing emails from IoT ONE.
Submit

Thank you for your message!
We will contact you soon.