YekCity
Built from the analysis of real attacks on power and utility networks: a model city with real controllers, on which those attacks can be replayed, detected and practised.
Built from the analysis of real attacks on power and utility networks: a physical model city with real industrial controllers and real protocols, on which exactly those attacks can be replayed, detected and practised. With visible effect, and without risk to a real plant.
Why an IT cyber range is not enough for OT
Classic training environments model web applications, directory services and endpoints. They do not model telecontrol protocols, protection relays, and above all no physical consequence. That connection is what makes OT different: a manipulated packet leads to something coming to a stop.
SOC teams know the theory of industrial attacks and have never seen one. What a switching command does to network traffic, how a firmware change shows itself on a controller, what an alarm looks like when it really is one: none of that can be read, it has to be watched once.
What is inside the model city
Real controllers at model scale. What runs here runs the same way in a plant.
Real controllers
Industrial controllers from several manufacturers, wired as they would be in a plant, with operator panels, drives and sensors. A 3D-printed model of the city makes the effect visible: when an attack gets through, the lights go out.
Real protocols
Telecontrol over IEC 60870-5-104, substation communication over IEC 61850 with GOOSE and MMS, plus Modbus, DNP3, PROFINET, S7 and OPC UA. The protocols in which the documented attacks on power grids took place.
Real network architecture
Segmented along the Purdue model, with a demilitarised zone, control level and process network, firewalls and jump hosts in between. Questions of segmentation can be played through rather than only discussed.
Derived from analysed incidents
It began with the analysis. We worked through the documented attacks on the power and utility networks in Ukraine and the incident on Polish railways, and derived from them what an attacker technically did. The model city was built on that basis, not the other way round.
What can therefore be replayed: manipulation over telecontrol protocols, intervention in substation communication, and attacks on safety controllers. Alongside them, techniques that worked in our own tests, anonymised and prepared for training use.
The sequence is always the same: the attack runs, the effect becomes visible in the model, and a SIEM records alongside. Afterwards it can be traced step by step which event produced which entry, and where detection could have caught it.
Awareness, exercise, the real thing
For decision-making groups there is the short version: an attack on the power supply, two minutes, and at the end the lights go out in the model city while the SIEM beside it logs every step. For a budget decision that is more convincing than any risk matrix.
In the red-blue variant, one group works on the attack chain while the other sits in the analysis and is meant to spot what is happening. Both sides learn the same thing, from opposite ends.
We have used the rig in the energy sector and run incident exercises with it in real security operations centres, that is, with the teams who would actually be at the screen on the day. We have shown it publicly at it-sa in Nuremberg and at IT-Sicherheitstag NRW in Dortmund, among others.
What the environment can represent
Energy supply with generation, transformation and distribution, rail infrastructure, manufacturing and water supply. For documented exercises as part of regulatory evidence, the run can be logged.
The rig also serves as a test bench for our own work: detection rules that do not fire here do not go into production, and testing procedures are rehearsed here before they go into a client plant.
What people ask about YekCity
No. The controllers are real industrial hardware, the protocols are the real ones, and the effect is physically visible. Only the scale is simulated.
Yes. If you want an incident or an architecture replayed, we build the scenario for it. That is the usual route for exercises that are meant to match a specific plant.
Connection to the common platforms is prepared, so that your analysts work in the interface they know from their day job.
The full setup is in our lab. For events and management sessions there is a transportable variant that shows the core.
See the demonstrator in action.
Wir zeigen die Anlage, die Angriffswege und was sich daran prüfen lässt.