Confluence Security

Industries

Critical Infrastructure and Utility Security

In critical infrastructure, the deliverable is as much the documentation as the hardware. Confluence Security designs physical security for substations, water and wastewater sites, telecom perimeters and remote unmanned locations, and produces the assessment and plan evidence an auditor expects to see.

Utility physical security work is graded twice. Once by whether the site is actually harder to attack, and once by whether you can prove on paper that you evaluated the threat, planned the mitigation and verified it. A camera system that cannot produce that evidence has done half the job.

The sites themselves are unforgiving. Many have no staff, marginal power, no wired network, extreme temperature swings and no tolerance for nuisance alarms. That drives a different equipment and analytics posture than an office building.

CIP-014 scope

Identified assets

Applies to specifically identified critical stations and substations.

Third-party review

Required

CIP-014 requires review of the physical security plan.

AWIA obligations

Assessment plus plan

Risk and resilience assessment and emergency response plan.

Remote sites

Solar and cellular

Often the only practical power and network.

Electric substations and control centers under CIP-014

The NERC CIP physical security standard, CIP-014, is narrower than it is usually described. It applies to specifically identified critical transmission stations and substations, and to the primary control centers that operationally control them, rather than to every asset a utility owns. The identification process itself is part of the standard.

For assets in scope, the standard drives an evaluation of threats and vulnerabilities specific to that station, and a documented physical security plan that addresses those findings, including resiliency or security measures, law enforcement coordination and timelines for implementation. Both the risk assessment and the physical security plan require review by an unaffiliated third party.

What that means for us practically: the camera and detection design has to trace back to a specific documented threat, and the as-built package has to make that traceability obvious. We produce coverage maps, detection zone diagrams and verification records built for that review rather than as an afterthought.

Confirm current requirements against the standard as enforced, because the CIP family is revised regularly.

  • Threat and vulnerability evaluation tied to the specific station.
  • Documented physical security plan with implementation timelines.
  • Third-party review of both the assessment and the plan.
  • As-built documentation designed to support that review.

Water and wastewater under AWIA

America's Water Infrastructure Act obligations center on a risk and resilience assessment and an emergency response plan, both certified and periodically revised. The assessment covers malevolent acts and natural hazards against physical barriers, the physical infrastructure, monitoring practices and the operational technology environment.

AWIA does not hand you a camera specification. It requires that you assessed the risk and that your emergency response plan describes the strategies and resources you use to improve resilience, including physical security. Camera and access systems are how many of those strategies get implemented and evidenced.

Typical scope on a water site: plant entry and gate control with plate recognition, perimeter detection along fence lines, chemical storage and feed rooms, finished water and clearwell access, control room access, and remote pump, lift and tank sites.

Telecom, data center and pipeline perimeters

These sites share a pattern: a hard perimeter, a small number of high-consequence openings, and a strong need for audited access rather than broad camera coverage.

Design emphasis goes to layered perimeter detection, mantrap or vestibule entry with anti-passback, cage and cabinet level access where colocation applies, and continuous coverage of every door into the white space. Pipeline and energy sites add valve stations, meter sites and tank batteries, which are usually remote and unmanned.

Remote unmanned sites

The hard problem in this vertical is the site with no power and no network. Solar plus cellular is usually the only practical answer, and it imposes a strict power budget that shapes every other decision.

That budget favors low-power imaging with on-camera analytics so the radio only wakes for real events, event-based rather than continuous recording, local storage with scheduled or on-demand offload, and hardware rated for the temperature range the site actually sees rather than the one on a datasheet.

Detection is analytics-based by necessity. Passive motion in an unlit desert or mountain site produces alarms all night. Line crossing, loitering and object-left-behind rules with a verified human review step keep the alarm volume low enough that responders keep responding.

Talk-down speakers work well at these sites. A remote voice describing what somebody is wearing ends most fence-line trespass events without a dispatch.

  • Solar and cellular with a documented power budget.
  • On-camera analytics so the radio only wakes for real events.
  • Local storage with scheduled offload rather than continuous streaming.
  • Temperature and enclosure ratings matched to the site, not the catalog.

Controlled access and audit evidence

Controlled spaces in this vertical often carry a two-person rule and a requirement that every entry is attributable. Access control has to log the credential, the door state and the escort, and the camera has to prove the number of people who entered.

The audit package matters as much as the install. We deliver device inventories with firmware levels, network segmentation diagrams, coverage and detection zone maps, commissioning verification records, credential authorization lists and a maintenance log format your compliance team can keep using after we leave.

Common questions

What does NERC CIP-014 require for physical security?

For specifically identified critical transmission stations and substations, and the control centers that operationally control them, CIP-014 drives an evaluation of threats and vulnerabilities specific to that station and a documented physical security plan addressing the findings, with implementation timelines and law enforcement coordination. Both the risk assessment and the plan require unaffiliated third-party review. It does not apply to every asset a utility owns.

Does AWIA require security cameras?

AWIA requires a risk and resilience assessment and an emergency response plan, not a specific camera system. The assessment covers malevolent acts and natural hazards against physical barriers, infrastructure, monitoring practices and operational technology. Cameras and access control are common ways to implement and evidence the resilience strategies your plan describes.

How do you secure a remote site with no power or network?

Solar power plus a cellular link, designed against a real power budget. Use on-camera analytics so the radio only transmits on a genuine event, record locally with scheduled offload rather than streaming continuously, and use line crossing and loitering rules instead of passive motion so the site does not alarm all night. Talk-down audio resolves most fence-line events without a dispatch.

Talk through the practical next step.

Tell us which sites are in scope and which standard you are documenting against. We will design the detection and deliver the audit package with it.

Contact Confluence Security

We'll get back to you ASAP

Kindly provide your contact info and a team member will get in touch shortly.

Address
6105 S. Main St. Suite #200
Aurora, CO 80016

Contact form