English | Українська
Home Expert blogs Serhiy Yermilov

Serhiy Yermilov: "Cybersecurity is reaching the level of a strategic issue for the future Unified Power System of Ukraine"

31.07.2026

In his personal blog, Serhiy Yermilov – Minister of Fuel and Energy of Ukraine in 2000–2001 and 2002–2004, former Head of the National Agency of Ukraine for Ensuring the Efficient Use of Energy Resources, Honored Power Engineer of Ukraine – continues a series of publications dedicated to the future architecture of the Ukrainian power system. The author consistently builds the concept of a transformational transition from a centralized model to a modern digital power system based on the principles of Smart Grid.

In the seventh part of the blog, Serhiy Yermilov focuses on one of the key challenges of the future energy sector – cybersecurity. According to his expertise, the information architecture of the United Power System of Ukraine should be designed according to the Security by Architecture principle, when protection is built into the basis of the system, and not added as a separate function.

The author offers a vision of a multilayer information topology of the Unified Energy System-2031, built on the principles of Zero Trust, digitalization and readiness to counter AI-driven cyberattacks, emphasizing that it is in the field of cybersecurity that Ukraine has a chance not only to adopt international experience, but also to form new global standards.

Cybersecurity of the Near Future

In my opinion, this issue is already reaching the level of strategic for the future of the Unified Energy System of Ukraine.

An important feature: if we partially restore the physical network, then we actually have to build the information architecture anew, based not on the legacy of the 1980s-2000s, but on the requirements of the 2030s.

A clear understanding is needed here: you cannot simply “add cybersecurity.”

Many energy companies have historically built like this:

SCADA – network – then add firewall – we get cybersecurity.

In 2031, this no longer works.

The future architecture should be built according to the principle: Security by Architecture.

That is, cybersecurity is a property of the system, not a separate subsystem.

What should be the information topology of the UPS-2031?

The answer: not as a single, but as a multi-layered system.

Layer 1. Critical transport layer (Utility Backbone)

The basis: fiber-optic lines; IP/MPLS; segmented architecture; redundant routes.

In fact, this is an analogue of the energy transport network for data where the following should work: EMS; SCADA; PMU; WAMS; inter-center interaction.

Layer 2. Operational Network (OT Network)

A separate operational network. Not a corporate IT network. Not the Internet.

The OT domain is where: digital substations; IED; RTU; RPA; GOOSE; Sampled Values ​​work.

Layer 3. Distributed Energy Domains (DER Domain)

The greatest complexity is millions of devices: inverters; BESS; EV; charging stations; smart meters; heat pumps; home EMS.

They cannot be directly included in the critical circuit of the TSO. Many suppliers from different countries with different risks, so multi-level isolation is required.

Layer 4. Market & Flexibility Layer

A separate domain that allows market participants (network operators and aggregators) to trade flexibility in energy consumption or generation. It combines home batteries, electric vehicles and heat pumps to balance the grid and prevent overloads.

This is where: aggregators; VPP; flexibility markets; energy communities work.

This layer should be separated from operational control systems.

Not: everyone is connected to everyone, but Zero Trust Domains, where each layer has its own trust. Its own authorization. Its own access control.

Ukraine will most likely face a significant problem of AI-enabled cyber attacks. The existing adversary will gain a new ability, and on a scale that is difficult to imagine today, to automatically:

  • analyze the network;
  • build an asset map;
  • search for vulnerabilities;
  • generate exploits;
  • conduct coordinated attacks.

Therefore, the OES-2031 requires not only a standard for the communication protocol (IEC 61850); a common model (CIM); DERMS; ADMS.

Also necessary is the integration of AI into response and monitoring centers (AI-assisted SOC); behavioral analytics; anomaly detection; autonomous incident response; digital twins for cyber polygons.

The information architecture of the Ukrainian Unified Energy System in 2031 should be built as a multi-domain cyber-physical platform with full observability, segmented trust levels, Zero Trust architecture, cryptographic flexibility for transition to post-quantum standards, and built-in ability to counter automated AI-driven cyberattacks.

It is information architecture and cybersecurity that should become the direction where Ukraine is able not to catch up, but to set standards. The experience of attacks on the energy sector, integration with the European system, and the need to build a significant part of the infrastructure practically from scratch create a unique, albeit very expensive, window of opportunity for this.

 

Sergiy Yermilov – Minister of Fuel and Energy of Ukraine in 2000–2001 and 2002–2004, former Head of the National Agency of Ukraine for Ensuring the Efficient Use of Energy Resources, Honored Power Engineer of Ukraine

Share on social networks:

Blogs

All blogs

News

All news