Environment
A power distribution utility was upgrading protection and automation equipment at a set of substations, introducing IP-based communication between protective relays, a substation automation controller, and the control center, replacing older serial links.
Challenge
The engineering team understood the electrical protection scheme in detail but had not translated the new IP connectivity into a cyber risk conversation leadership could act on. Risks existed only as informal engineering concerns -- "we should probably firewall that" -- with no owner, no severity ranking, and no visibility above the project team.
Approach
The team built a risk register scoped specifically to the upgrade, using NIST CSF's Identify and Protect categories to structure the conversation: what assets were newly exposed, what protections existed today, and what gap remained. Each entry followed a defensible structure -- asset, threat scenario, existing control, residual risk, and a named owner with a treatment decision (mitigate, transfer, accept, or avoid) rather than a bare severity number. Risks around the automation controller's default credentials and an initially flat network between relays and the control center were explicitly called out, ranked, and assigned before go-live rather than deferred to "phase two."
Outcome
Leadership approved a small budget addition to segment relay traffic from general substation communications before commissioning, based directly on the risk register rather than a late-stage escalation. The register also became the template used for subsequent substation upgrades.