English / ქართული /








Journal number 2 ∘ Demur SitchinavaMikheil MachitidzeShorena Davitaia
Cybersecurity of Energy Infrastructure in Georgia: Technological and Governance Gaps

Doi.org/10.52340/eab.2026.18.02.12

Energy infrastructure represents one of the most critical components of national infrastructure, as its reliable and uninterrupted functioning directly affects economic stability, social welfare, industrial productivity, and national security. Modern societies rely heavily on continuous electricity supply for the operation of essential services, including transportation systems, telecommunications networks, healthcare institutions, financial services, and government operations. Consequently, the resilience and reliability of energy systems have become a central concern for policymakers, infrastructure operators, and security experts worldwide. Over the past two decades, the energy sector has undergone significant technological transformation driven by the rapid advancement of digital technologies and the increasing integration of information and operational systems. This digitalization has enabled the deployment of advanced monitoring systems, automated operational technologies, data-driven management platforms, and interconnected communication infrastructures that significantly improve the efficiency, flexibility, and reliability of electricity networks. However, the same technological advancements that enhance operational capabilities also introduce new vulnerabilities and expand the cyberattack surface of critical infrastructure systems.
In particular, the integration of Supervisory Control and Data Acquisition (SCADA) systems and Industrial Control Systems (ICS) has fundamentally changed the operational architecture of modern energy infrastructure. These technologies enable real-time monitoring, automated control of generation and transmission processes, remote management of energy facilities, and integration of large-scale data analytics for grid management. While these systems provide significant operational advantages, they also expose energy infrastructure to increasingly sophisticated cyber threats. Unlike traditional information technology environments, operational technology systems were historically designed with reliability and operational continuity as primary objectives rather than cybersecurity protection. As a result, many ICS and SCADA systems rely on legacy software architectures, outdated operating systems, and communication protocols that lack modern security mechanisms such as encryption, authentication, and secure network segmentation. This structural vulnerability significantly increases the potential for cyber intrusions, unauthorized access, malware propagation, and targeted disruption of energy systems.
This study analyzes the current state of cybersecurity within Georgia’s energy infrastructure by examining both technological and governance-related dimensions of cyber resilience. Georgia’s energy sector has undergone substantial transformation in recent years, characterized by increased reliance on digital operational technologies, modernization of electricity networks, and deeper integration into regional energy markets. The country’s electricity system, which is largely based on hydropower generation and interconnected transmission infrastructure, increasingly utilizes digital control systems for dispatch management, grid monitoring, and operational coordination. While these technologies improve efficiency and enable more advanced network management capabilities, they also introduce new security challenges that require systematic risk management and regulatory oversight.
The research focuses on identifying key technological vulnerabilities present in operational technology environments used in the Georgian energy sector. Particular attention is given to issues such as outdated SCADA and ICS platforms, insufficient network segmentation between corporate IT systems and operational control networks, insecure communication protocols used in industrial automation, and limited implementation of advanced access control mechanisms. These technical deficiencies significantly increase the exposure of energy infrastructure to cyber threats, especially in environments where legacy systems continue to operate without adequate security upgrades. Furthermore, the lack of comprehensive monitoring systems and anomaly detection mechanisms reduces the ability of operators to identify and respond to cyber incidents in real time.
In addition to technological vulnerabilities, the study also examines governance-related challenges affecting cybersecurity management in the Georgian energy sector. Although Georgia has adopted a national cybersecurity strategy and several legal instruments addressing information security, the regulatory framework for protecting operational technology in critical infrastructure remains underdeveloped. The absence of sector-specific cybersecurity standards, limited regulatory oversight, and insufficient coordination among government agencies and infrastructure operators create structural gaps in the national cybersecurity architecture.
The analysis presented in this study is conducted within the broader context of internationally recognized cybersecurity frameworks and best practices. In particular, the research evaluates the relevance and applicability of global standards such as the NIST Cybersecurity Framework, the ISO/IEC 27019 standard for information security management in energy utilities, and the IEC 62443 series of standards addressing industrial control system cybersecurity. In addition, the study considers recommendations provided by international organizations such as the European Union Agency for Cybersecurity (ENISA), which actively supports the development of cybersecurity policies and risk management practices for critical infrastructure sectors. By comparing the current state of cybersecurity governance in Georgia with these international frameworks, the research identifies key areas where national policies and operational practices can be strengthened.
Based on the findings of the study, several strategic recommendations are proposed to enhance the cybersecurity resilience of Georgia’s energy infrastructure. These include the development of sector-specific cybersecurity regulations for operational technology environments, the establishment of a dedicated Energy Computer Emergency Response Team (Energy-CERT) responsible for monitoring and responding to cyber incidents in the energy sector, and the implementation of mandatory cybersecurity audits and risk assessments for critical energy operators. Additional recommendations emphasize the importance of modernizing legacy operational technology systems, implementing robust network segmentation policies, strengthening incident detection and response capabilities, and developing specialized cybersecurity training programs for energy sector professionals. The study concludes that strengthening cybersecurity within the Georgian energy sector requires a comprehensive and coordinated approach that integrates technological modernization, regulatory reform, institutional cooperation, and human capital development in order to ensure the long-term resilience and security of the country’s critical energy infrastructure.

Keywords: Cybersecurity, energy infrastructure, industrial control systems (ICS), SCADA systems, operational technology (OT), critical infrastructure protection, energy security.
JEL Codes: L94, Q48, O33, H56, K23

References:
• Georgian National Energy and Water Supply Regulatory Commission (GNERC). (2021). Energy Security Strategy. Tbilisi
• National Security Council of Georgia. (2021). National Cybersecurity Strategy 2021–2024. Tbilisi
• Ministry of Economy and Sustainable Development of Georgia. (2020). Energy Development Strategy 2020–2030. Tbilisi
• Georgia’s Innovation and Technology Agency (GITA). (2022). Sectoral Digital Transformation Research
• Kakauridze Z. (2023). kritikuli inprastrukturis kiberusaprtkhoebis makhasiateblebi. [Features of Critical Infrastructure Cybersecurity. Tbilisi: Georgian Technical University.] in Georgian
• Narmania D., Seturidze R., Maghradze M., Davitaia S., & Machitidze M. (2023). elektroenergetikashi dispetcherizatsiisa da avtomatizirebuli martvis sistemebis (SCADA) shemushavebis aktualuri sakitkhebi. [Current Issues of Electric Power Dispatch Management and Development of Automated Control System (SCADA). Economics and Business, (3), 152–171.] in Georgian.
• European Union Agency for Cybersecurity (ENISA). (2023). Threat Landscape for Industrial Control Systems.
• International Society of Automation (ISA). (2022). ISA/IEC 62443 Series of Standards for Industrial Cybersecurity.
• NIST Special Publication 800-82. (2015). Guide to Industrial Control Systems (ICS) Security, Revision 2.
• World Economic Forum (WEF). (2021). Cyber Resilience in the Energy Sector.
• MITRE ATT&CK for ICS. (2022). Tactics, Techniques and Procedures in Industrial Control Systems.
• Kaspersky ICS CERT. (2023). State of Industrial Cybersecurity in 2023: Global Trends.
• Dragos Inc. (2023). Year in Review: Industrial Cyber Threats and Trends.
• IBM Security. (2024). Cost of a Data Breach Report, 2022–2024 editions.
• PwC. (2022). Cybersecurity in Energy and Utilities: A Shifting Landscape.
• Gartner. (2023). Hype Cycle for Operational Technology Security.
• Seturidze R., Narmania D., Maghradze M., Davitaia S., & Machitidze M. (2023). Ways of improving the management of the supervisory control and data acquisition (SCADA) automated system in electric power. International Journal of Development Research, 13(10), 63921–63928.