Skip to main content
Smart grid

YekCity

Built from the analysis of real attacks on power and utility networks: a model city with real controllers, on which those attacks can be replayed, detected and practised.

Der Demonstrator YekCity, eine Miniaturstadt mit Umspannwerk und Wasserwerk

Built from the analysis of real attacks on power and utility networks: a physical model city with real industrial controllers and real protocols, on which exactly those attacks can be replayed, detected and practised. With visible effect, and without risk to a real plant.

The problem

Why an IT cyber range is not enough for OT

Classic training environments model web applications, directory services and endpoints. They do not model telecontrol protocols, protection relays, and above all no physical consequence. That connection is what makes OT different: a manipulated packet leads to something coming to a stop.

SOC teams know the theory of industrial attacks and have never seen one. What a switching command does to network traffic, how a firmware change shows itself on a controller, what an alarm looks like when it really is one: none of that can be read, it has to be watched once.

The setup

What is inside the model city

Real controllers at model scale. What runs here runs the same way in a plant.

Real controllers

Industrial controllers from several manufacturers, wired as they would be in a plant, with operator panels, drives and sensors. A 3D-printed model of the city makes the effect visible: when an attack gets through, the lights go out.

Real protocols

Telecontrol over IEC 60870-5-104, substation communication over IEC 61850 with GOOSE and MMS, plus Modbus, DNP3, PROFINET, S7 and OPC UA. The protocols in which the documented attacks on power grids took place.

Real network architecture

Segmented along the Purdue model, with a demilitarised zone, control level and process network, firewalls and jump hosts in between. Questions of segmentation can be played through rather than only discussed.

Foundation

Derived from analysed incidents

Physischer OT-Simulator YekCity Umspannwerk, Gebaeude, Verkehrssteuerung und Wasserwerk als Modell, gesteuert von echten Steuerungen mit industriellen Protokollen. CONTROL ROOM REAL PLCS · MODBUS · S7COMM IEC 61850 · IEC 60870-5-104 >_ MODEL CITY POWER · TRAFFIC · WATER YEKCITY · IEC 61850, IEC-104, MODBUS

It began with the analysis. We worked through the documented attacks on the power and utility networks in Ukraine and the incident on Polish railways, and derived from them what an attacker technically did. The model city was built on that basis, not the other way round.

What can therefore be replayed: manipulation over telecontrol protocols, intervention in substation communication, and attacks on safety controllers. Alongside them, techniques that worked in our own tests, anonymised and prepared for training use.

The sequence is always the same: the attack runs, the effect becomes visible in the model, and a SIEM records alongside. Afterwards it can be traced step by step which event produced which entry, and where detection could have caught it.

Use

Awareness, exercise, the real thing

OT-Trainings in zwei Stufen Professional arbeitet remote an einem virtuellen Wasserwerk ueber drei Ebenen und schliesst mit Pruefung und Notfalluebung ab. Expert steht in Praesenz vor echten Steuerungen und schreibt die Erkennungsregeln selbst. PROFESSIONAL 4 DAYS · REMOTE · 32 UNITS L2 HMI · OPC UA L1 MODBUS TCP L0 PUMP · TANK VIRTUAL WATERWORKS TEST 40 QUESTIONS EXERCISE WITH ROLES EXPERT 3 DAYS · ON SITE INSTRUMENTATION REAL PLCS modbus: function 6; WRITE THE RULES YOURSELF OT TRAINING · PROFESSIONAL, EXPERT

For decision-making groups there is the short version: an attack on the power supply, two minutes, and at the end the lights go out in the model city while the SIEM beside it logs every step. For a budget decision that is more convincing than any risk matrix.

In the red-blue variant, one group works on the attack chain while the other sits in the analysis and is meant to spot what is happening. Both sides learn the same thing, from opposite ends.

We have used the rig in the energy sector and run incident exercises with it in real security operations centres, that is, with the teams who would actually be at the screen on the day. We have shown it publicly at it-sa in Nuremberg and at IT-Sicherheitstag NRW in Dortmund, among others.

Sectors

What the environment can represent

Energy supply with generation, transformation and distribution, rail infrastructure, manufacturing and water supply. For documented exercises as part of regulatory evidence, the run can be logged.

The rig also serves as a test bench for our own work: detection rules that do not fire here do not go into production, and testing procedures are rehearsed here before they go into a client plant.

Common questions

What people ask about YekCity

No. The controllers are real industrial hardware, the protocols are the real ones, and the effect is physically visible. Only the scale is simulated.

Yes. If you want an incident or an architecture replayed, we build the scenario for it. That is the usual route for exercises that are meant to match a specific plant.

Connection to the common platforms is prepared, so that your analysts work in the interface they know from their day job.

The full setup is in our lab. For events and management sessions there is a transportable variant that shows the core.

Trusted by
Next step

See the demonstrator in action.

Wir zeigen die Anlage, die Angriffswege und was sich daran prüfen lässt.

Telephone
0231 39814905
Mon–Fri · 9am–5pm CET
Email
info@yekta-it.de
PGP key available
Location
Dortmund
Ruhrallee 9 · 44139