Skip to main content
Have a personal or library account? Click to login
The Role of Digital Forensics in Protecting Critical Energy Infrastructure from Cyberattacks Cover

The Role of Digital Forensics in Protecting Critical Energy Infrastructure from Cyberattacks

By:   
Open Access
|Sep 2026

Full Article

Introduciton

Numerous examples worldwide demonstrate that energy infrastructure is among the most vulnerable components of critical infrastructure. As the nature of warfare evolves, energy infrastructure is increasingly being targeted. Energy infrastructure is inherently complex, and this complexity increases with ongoing technological advancements. The digitalization of many infrastructure components offers significant benefits; however, it also introduces numerous threats and risks which must be addressed (Abraham et al., 2025; Cassotta, Sidortsov, 2019; Ene, Savu, 2023). Furthermore, because many energy system components lack integrated security measures within their software, an additional layer of risk emerges, requiring careful consideration. Increasing digitalisation in the energy sector also brings greater risks. As energy infrastructure is a component of critical infrastructure, it is highly susceptible to cyberattacks. Such attacks can damage energy systems, which usually leads to blackouts, disruption of supply chains, financial losses, and threats to national security (Maliarchuk et al., 2019; Nicholas et al., n.d.; Saeed et al., 2024). Cyber operations targeting critical energy infrastructure constitute a strategic priority for several major intelligence and military actors with advanced cyber capabilities and offensive doctrines.

1. CYBERATTACKS AGAINST ENERGY INFRASTRUCTURE

1.1. Current threat landscape

One of the best-known cyberattacks on critical infrastructure was Stuxnet, which targeted the nuclear facility in Natanz, Iran in 2010. Stuxnet was a sophisticated malware designed to attack the SCADA (Supervisory Control and Data Acquisition) systems of the nuclear facility by exploiting multiple zero-day vulnerabilities in the Windows operating system (Bakić et al., 2021; Çetinkaya, Terzi, 2024; Musakhanov D, 2023; Pitman, Crosier, 2024; Saaida, 2023; Selján, 2020; Stevens, 2020; Sumayah Al-Rabiaah, 2018). Stuxnet entered the system via USB drives. After infiltrating the system, the malware reached Siemens PLCs (Programmable Logic Controllers) and began to manipulate the operational speed of the uranium-enrichment centrifuges. At the same time, Stuxnet malware was producing and providing false data to mask all the irregularities and remain unnoticed (Bakić et al., 2021; Çetinkaya, Terzi, 2024; Musakhanov D, 2023; Pitman, Crosier, 2024; Saaida, 2023; Selján, 2020; Stevens, 2020; Sumayah Al-Rabiaah, 2018). As a result, significant damage was done to the centrifuges and the process of the enrichment was disrupted. Stuxnet malware was a first example of physical damage to ICS/OT (Industrial Control Systems/Operational Technology) infrastructure (Bakić et al., 2021; Selján, 2020; Stevens, 2020).

Another well-known example of a cyberattack on energy infrastructure happened in Saudi Arabia in 2017, and this attack is known as Triton or Trisis malware. This malware targeted the safety systems of a petrochemical plant in Saudi Arabia, and it was designed to specifically compromise Schneider Electric's Triconex Safety Instrumented System (SIS) controllers (Akkad et al., 2023; Alelyani, Kumar G R, 2018; Alharbi, 2025; Alkhalifa et al., 2024; Al-Mulhim et al., 2020; Alsaeed, 2021; Jeffries, 2022; Setola et al., 2020). Safety Instrumented Systems (SIS) are the last line of defence in power plant infrastructure, because they automatically shut the plant down in order to prevent explosions or other catastrophic accidents. This example demonstrates how dangerous cyberattacks on energy infrastructure can be.

Another instance of a successful cyberattack resulting in substantial consequences for both the state and the nation is the Colonial Pipeline cyberattacks of May 2021. Colonial Pipeline is the largest fuel pipeline operator in the United States, and it was attacked by ransomware (Bellamkonda Barclays, Bellamkonda, 2024; Dudley, Golden, 2021; Lazarus Gawazah, 2024; Olorunlana, Mohammed, 2025; Pitman, Crosier, 2024). The ransomware encrypted critical systems, which caused a shut-down of the pipeline operations, leading to fuel shortages across the East Coast. This example shows how cyberattacks on energy infrastructure is a national security priority (Bellamkonda Barclays, Bellamkonda, 2024; Dudley, Golden, 2021; Lazarus Gawazah, 2024; Olorunlana, Mohammed, 2025; Pitman, Crosier, 2024). Another example is the power blackouts in Ukraine in 2015 and 2016. Malware named BlackEnergy and Industroyer (CrashOverride) caused power outages across Ukraine. The BlackEnergy malware was spread by phishing emails, and it allowed remote access to infected computers in power distribution companies and access to the SCADA system. Industroyer (CrashOverride) malware directly attacked the industrial protocols EC 60870-5-101/104 and IEC 61850.

The results of cyberattacks on the energy sector and its infrastructure are serious and severe. Attacks usually result in power supply disruptions, blackouts, and physical damage to energy systems. Long lasting blackouts can cause crises in other critical infrastructure sectors which are dependent on electrical power, such as hospitals, transportation networks, and communication systems (Dovhan et al., 2025; Erin Jenne, 2025; Joe Slowik, 2018, n.d.; Pitman, Crosier, 2024; Rector, 2024).

1.2. Research gap

Digital forensic tools and methods were not primarily designed for systems such as Smart Grid and Supervisory Control and Data Acquisition (SCADA), but for classic IT environments. Because of this, existing digital forensics tools are not usually compatible with energy systems and critical infrastructure environment in general (AdelArshad et al., 2018; Mohd Abdullah et al., 2020; Nelufule et al., 2024; Parssinen et al., 2022). Even though digital forensics is not completely integrated into the energy sector, it is still crucial for identifying the mechanisms and exploited vulnerabilities of cyberattacks targeting energy infrastructure (Dimitriadis et al., 2020; Sohl et al., 2015; Spyridopoulos et al., 2013a; Wu, Nurse, 2015). According to some authors (Taleghani, Jabreilzadeh Sola, 2025; US DEPARTMENT OF ENERGY, 2016), digital forensics still remains highly relevant when it comes to determining the method of attack and investigation all of the potential system vulnerability. Bridging technological gaps and adapting digital forensic techniques are essential for enhancing the defence of energy systems against cyberattacks (Adel, 2020; Arshad et al., 2018; Mohd Abdullah et al., 2020; Nelufule et al., 2024; Parssinen et al., 2022). Also, it is important to stress that industrial systems are specific, because they must operate 24/7 without interruptions; pauses or disruption to their operation can have many effects and even cause panic or tensions at the national level. Effective protection of critical energy infrastructure requires a thorough understanding of system vulnerabilities and the methods by which cyberattacks and threats exploit these weaknesses. Additionally, it is essential to accurately investigate which vulnerabilities were exploited following a cyberattack. Digital forensics therefore plays a critical role in the cybersecurity of energy infrastructure and operational technology systems.

1.3. Study objectives

The objective of this study is to examine the role of digital forensics in protecting critical energy infrastructure from cyberattacks, with a particular focus on ICS/OT and SCADA environments. The study aims to identify the key functions of digital forensics in energy-sector defence, including incident detection and analysis, evidence collection and preservation, attack attribution and accountability, forensic readiness, and incident response. Furthermore, the study seeks to analyse the main technical, organizational, and operational barriers which hinder the effective application of digital forensics in energy infrastructure, such as legacy systems, availability constraints, and the limitations of existing forensic tools. Finally, through a comparative case study analysis of major cyber incidents affecting the energy sector, this research evaluates how digital forensics can strengthen defence strategies by supporting proactive security measures, improving resilience, and enabling more accurate attribution of cyberattacks. These objectives are addressed through three research questions focusing on forensic roles, implementation barriers, and defensive impact:

  • Research question 1: What are the main roles of digital forensics in defending energy infrastructure against cyberattacks?

  • Research question 2: What are the main obstacles to applying digital forensics to SCADA (Supervisory Control and Data Acquisition) and other industrial control systems in the energy sector?

  • Research question 3: How does digital forensics contribute to strengthening the defence strategies of the energy sector against cyberattacks?

2. METHODOLOGY

This study uses a systematic literature review, theoretical analysis and comparative case study analysis as a methodology framework to address and answer the three research questions. A comparative case study analysis was conducted by juxtaposing the findings from the literature with four prominent real-world incidents (Stuxnet, Triton/Trisis, the Ukraine blackouts, and the Colonial Pipeline attack).

The relevant literature was collected from leading online scientific databases (IEEE Xplore Digital Library, Google Scholar, ScienceDirect and Scopus) using the following keywords: “Digital forensics in energy sector”, “SCADA forensics”, “ICS/OT cybersecurity”, “Critical infrastructure security”, “Cyberattacks on energy infrastructure”, and “Forensic readiness in industrial control systems”. A systematic literature review was conducted in four stages: identification, screening, eligibility, and inclusion. A visual representation of the systematic literature review is presented in Figure 1.

The study integrates digital forensics into a strategic defence model for critical energy infrastructure. The previous studies and available research are predominantly focused on treating digital forensics as a reactive investigative tool which is usually used after a cyberattack on energy infrastructure has happened, and not proactively as a resilience mechanism supporting detection, response, and regulatory compliance in SCADA/ICS environments. Through the systematic literature review and comparative case study analysis (Stuxnet, Triton, the Colonial Pipeline attack, the Ukraine blackouts), this study is placing digital forensics as an active tool for strengthening defence against cyberattacks on energy infrastructure.

The inclusion criteria for the systematic literature review conducted in this study were: focus on the energy sector and critical infrastructure; presence of a digital forensic or incident analysis component; publication in peer-reviewed journals, conferences, or academically recognized sources; and the inclusion of technical or methodological contributions such as frameworks, models, or case studies related to forensic readiness or SCADA/ICS forensics.

Initially 112 publications were collected and screened, based on the abstract in the screening phase of the systematic literature review process; 7 studies were excluded as they were lacking an OT/ICS or energy-sector operational context. In the next step, 105 publications were screened based on the full text, and 12 were not retrieved due to a lack of a forensic investigation framework, evidence acquisition method, or incident analysis component. The number of reports assessed for eligibility was 93, from which a total of 15 studies were excluded because they did not align with the three defined exclusion criteria, i.e. non-forensic perspectives on cyberattacks; studies without empirical or methodological contribution, which lacked a structured investigation process or validation of forensic frameworks; and studies lacking technical forensic depth or process-level traceability, particularly those which did not address PLC/RTU (Remote Terminal Unit) data acquisition, protocol-aware analysis, or digital artefact validation within SCADA and ICS environments. The final number of studies included in the review was 78.

The study deliberately included both recent and earlier works (from 2005 onwards), because the field of OT/ICS digital forensics remains relatively underexplored and the industrial system generally tends to keep using outdated operating systems. Due to the specificity of the researched domain and the limited number of publications, earlier studies continue to provide relevant insights and foundational concepts which are still applicable to contemporary energy infrastructure.

Figure 1:

Process of systematic literature review

3. RESULTS

The Results section provides answers to the three defined research questions. The questions are answered using the deep and systematic literature review and theoretical analysis. Research question 3 was answered by providing a comparative case study analysis in order to give a real-life example of cyber threats – real cyberattacks which targeted the energy sector and had a potential forensic focus.

Research question 1: What are the main roles of digital forensics in defending energy infrastructure against cyberattacks?

The first role of digital forensics in defending energy infrastructure is incident detection and analysis (Irfan Ahmed, 2012; Kilpatrick et al., 2008, 2006; Kleinmann, Wool, 2014; Mason, Zhou, 2021; Nelufule et al., 2024). The literature highlights the fact that digital forensics helps in the identification of anomalies in SCADA systems and Smart Grid environments by monitoring logs and using protocol-aware techniques. Incident detection helps to strengthen intrusion detection capabilities. Both ICS (Industrial Control Systems) and SCADA environments usually generate a large number of logs and network traces, and the help of digital forensics is crucial to understand this data properly. Within this data lies valuable information about the functionality of the system and, with appropriate forensics, all the information can be analysed properly. Kilpatrick et al. (2008) suggested that protocol-aware analysis of industrial protocols such as Modbus, DNP3, and Siemens S7 improves anomaly detection. Nelufule et al. (2024) on the other hand, argued that distributed log collection enhances situational awareness in Smart Grids environments. Carcano et al. (2011) said that state-based intrusion detection in SCADA systems enables the identification of anomalies within industrial protocols using a comparison of the actual process state with the expected values. They further explained that digital forensics in energy systems is not restricted solely to the analysis of the network and logs, but also includes the analysis of physical signals and processes (Carcano et al., 2011). In this case, the forensic investigation gains an additional dimension, as attack activities can be detected not only in the digital records but also through irregularities in the physical behaviour of the system itself (Ibid.).

After the anomaly has been identified and detected, it must be preserved, because it is digital evidence. The second role of digital forensics handles digital evidence, called evidence collection and preservation. Evidence preservation ensures that the critical parts of energy infrastructure, such as PLC or network logs and traces, are secured and preserved properly (Fabro, 2008; Irfan Ahmed, 2012; Senthivel et al., 2017; Van Der Knijff, 2014). The literature shows that the digital forensics of SCADA is different from IT forensics, and the best example of this is the fact that SCADA evidence cannot be captured by disk imaging, but requires SCADA-specific acquisition methods. Senthivel et al. (2017) stressed the importance of chain-of-custody and log volatility challenges, and Van Der Knijff (2014) suggested that PLCs often overwrite the logs because of limited available memory, which again makes the forensics of energy systems very tricky.

The third role of digital forensics in defending the energy infrastructure is attribution and accountability. This role aids the reconstruction of all the steps the hacker took in order to attack the system (Eden et al., 2016, 2015; Kamlofsky, Romero, 2022; Maglaras et al., 2019; Mittal, 2015). Forensic readiness helps to prepare energy infrastructure against attacks by enhancing logging and employing testbeds in order to reduce response times and increase resilience (Eden et al., 2015; Irfan Ahmed, 2012; Slay, Sitnikova, 2009; Madan Raja et al., 2024; Senthivel et al., 2017; Van Der Knijff, 2014). Forensics readiness is the ability of a particular part of the critical infrastructure (e.g. a power plant) to proactively establish technical, procedural, and organizational measures in advance which enable the rapid, efficient, and legally compliant collection, preservation, and analysis of digital evidence in the event of a security incident. Also, forensics readiness must be integrated within the energy system architecture and organizational policy from the start, and not always added reactively after incidents have occurred (Eden et al., 2015; Irfan Ahmed, 2012; Slay, Sitnikova, 2009; Madan Raja et al., 2024; Senthivel et al., 2017; Van Der Knijff, 2014). Forensic readiness in the energy sector also means that energy infrastructure is not only protected, but also prepared for detecting potential cyber threats at the moment of the cyberattack.

If a cyberattack occurs, digital forensics plays a direct role in incident response and recovery; analysing PLC code changes, mapping the spread of malware, and preserving volatile memory while systems remain operational (Jeffries, 2022; Kamlofsky, Romero, 2022; Mason, Zhou, 2021). Furthermore, Myers et al. (2018) linked forensics readiness to cyber situational awareness in critical infrastructure. They also underlined proactive forensic logging and argued that it significantly improves detection and response to incidents (Ibid.).

Finally, forensics also allows easier alignment with standards and regulations such as NERC CIP (North American Electric Reliability Corporation Critical Infrastructure Protection) and NIS2 (Network and Information Security Directive 2). The policy, regulation, and training support role of digital forensics also encourages training and awareness programmes which strengthen institutional preparedness against cyberattacks on energy infrastructure (Bozhyk et al., 2025; Cusack, Mahmoud, 2018; Eden et al., 2016, 2015; Ene, Savu, 2023). Also, the European Commission (2019) has underlined the importance of integrating digital forensics into critical infrastructure protection frameworks, including cross-border collaboration, evidence handling, and post-incident analysis in Smart Grids. Together, these functions illustrate how digital forensics has moved beyond traditional evidence collection to become a strategic enabler of resilience, compliance, and national security in the energy sector. Table 1 summarizes the digital forensics roles identified in the literature and the corresponding forensics potential in the energy sector.

Table 1:

Digital Forensics Roles and Forensic Potential in Energy Infrastructure

Role of Digital ForensicsForensic Potential
Incident Detection and AnalysisThrough log monitoring, monitoring system behaviour and network traffic, anomalies in SCADA/ICS and Smart Grid systems are identified. Forensics analysis which is protocol-aware (which means that unlike the classic digital forensics approach, this method enables investigators to investigate the operational meaning of transmitted messages within the SCADA and ICS environments) enables more reliable detection of anomalies and enhances interoperability with intrusion detection systems (IDS) (Akkad et al., 2023; Alelyani, Kumar G R, 2018; Carcano et al., 2011; Irfan Ahmed, 2012; Kilpatrick et al., 2008, 2006; Kleinmann, Wool, 2014; Mason, Zhou, 2021; Nelufule et al., 2024).
Evidence Collection and PreservationAcquisition of digital data (PLC code, ladder logic, RTU data, and network traces) is enabled securely and without disrupting operations. When digital evidence is collected, it is crucial to maintain the integrity of the collected evidence by preserving the chain of custody using cryptographic hashing, and SCADA-specific data collection plans (Fabro, 2008; Irfan Ahmed, 2012; Senthivel et al., 2017; Van Der Knijff, 2014).
Attribution and AccountabilityDigital forensics enables the reconstruction of the timeline, steps and actions of the attacker, using PLC forensics, live analysis of memory, and creating an isolated virtual environment in order to safely execute and observe potentially malicious code (sandboxing). Digital forensics in energy infrastructure also enables the attribution and accountability of cyberattacks to the actual attacker or group of attackers. (Eden et al., 2016, 2015; Kamlofsky, Romero, 2022; Maglaras et al., 2019; Mittal, 2015).
Forensic ReadinessIntegrating forensics readiness models into SCADA systems can minimize digital evidence loss, reduce the mean time to response (MTTR), and strengthen organizational resilience against cyberattacks. Forensic readiness models include following elements: the process of identification of potential sources of digital evidence (SCADA logs, PLC memory, network packets, authentication servers); defining a process of evidence collection which ensures integrity through hashing and timestamping; and developing adequate incident response procedures (Eden et al., 2015; Irfan Ahmed, 2012; Slay, Elena Sitnikova, 2009; Madan Raja et al., 2024; Senthivel et al., 2017; Van Der Knijff, 2014).
Incident Response and RecoveryForensics can guide system recovery by tracking malware spread in real time, changes to the PLC code, and volatile memory. Live forensics of SCADA systems can enable safe analysis while the systems remain operational (Jeffries, 2022; Kamlofsky, Romero, 2022; Mason, Zhou, 2021).
Policy, Regulation, and Training SupportDigital forensics helps in enhancing compliance with standards (NERC CIP, NIS2, ISA-99, IEC 62443) and in developing forensic incident response models for strengthening national cyber strategies. The education and training of staff is a crucial part of equipping the energy sector to be able to cope with cyberattacks (Bozhyk et al., 2025; Cusack, Mahmoud, 2018; Eden et al., 2016, 2015; Ene, Savu, 2023).

Digital forensics also supports the identification of attack methods and proxy actors by correlating malware signatures and command-and-control infrastructures across cyber incidents. Such analysis enables the attribution of cyber operations targeting energy infrastructure, particularly in cases involving state or state-sponsored actors employing advanced offensive capabilities.

Research question 2: What are the main obstacles to applying digital forensics to SCADA and other industrial control systems in the energy sector?

Generally speaking the application of digital forensics in an OT/ICS environment is challenging, due to the characteristics of the environment. The literature suggests that the most prominent obstacle in applying digital forensics to SCADA (Supervisory Control and Data Acquisition) environments is legacy system limitations. The software in SCADA/ICS environments is usually outdated and the hardware run on operating systems such as Windows XP or Windows 2000, which are no longer supported or updated with regular security updates (Irfan Ahmed, 2012; Senthivel et al., 2017; Zubair et al., 2022). Modern forensics tools are not compatible with the outdated versions, or even if they can be implemented, the quality of the evidence collected under these circumstances is limited (Spyridopoulos et al., 2013). Also, devices such as PLCs create logs which are usually incomplete and do not capture the required level of detail for forensics investigations (Stirland et al., 2014).

The second barrier to applying digital forensics in SCADA is a lack of standardized, forensic-ready frameworks. This prevents investigators from applying systematic procedures during incident analysis in SCADA and Smart Grid environments (Zakareya, 2018). Due to this lack of fully forensics-ready frameworks, forensic investigations of SCADA systems are often improvised, and this makes it very difficult to compare evidence and findings with other cases of cyberattacks on energy systems, which usually leads to repeated overlooking of important evidence and reliable indicators of cyberattacks (Mohd Abdullah et al., 2020). Nelufule et al. (2024) emphasised that without specialized forensic-ready frameworks for energy systems, digital investigation will be reactive and fragmented.

The third barrier refers to challenges in data acquisition for forensics analysis in ICS. This is because in an ICS environment, assets and equipment such PLCs (Programmable Logic Controllers), RTUs (Remote Terminal Units), and HMIs (Human Machine Interfaces) are normally geographically dispersed. Dispersed assets complicate evidence collection (Irfan Ahmed, 2012). Devices in the energy infrastructure communicate using industrial protocols such as Modbus, DNP3, and S7Comm. Industrial protocols are different from IT protocols, and it can be very challenging to extract data without specialized knowledge. Also, collecting data without disrupting critical processes requires forensic methods which are still underdeveloped (Ahmed et al., 2012; Irfan Ahmed, 2012; Senthivel et al., 2017; Zubair et al., 2022).

The fourth barrier presented in the analysed literature is the complex interconnectivity and cascade effects. Since SCADA systems and Smart Grid environments are densely interconnected, a single compromised part of the network can cause cascading failures across the whole network (Madan Raja et al., 2024). Due to this interconnectedness, forensic timeline reconstruction is very challenging, because an attack can spread across multiple interconnected systems (Parssinen et al., 2022). In highly interconnected systems such as SCADA, it is very difficult to identify and isolate the initial point of compromise from all the other secondary effects, and it also complicates the application of digital forensics in energy infrastructure (Madan Raja et al., 2024; Mohd Abdullah et al., 2020; Parssinen et al., 2022; Sohl et al., 2015).

The fifth barrier to fully and successfully implementing digital forensics in energy infrastructure is the limited number of forensic tools for ICS. Most digital forensics tools are primarily designed for IT environments, and they do not support the OT/ICS environment (Stirland et al., 2014). Most digital forensics tools cannot investigate and analyse PLC ladder logic, historian databases, or the real-time operating systems used in industrial devices (Stirland et al., 2014; Van Der Knijff, 2014; Wu, Nurse, 2015). There is a significant lack of open-source or standardized forensic tools for SCADA systems, smart grid environments, and industrial protocols, resulting in incomplete investigations and analytical limitations.

Live forensics and availability constraints is the sixth barrier. Critical infrastructure must function continuously, and processes must run 24/7 and cannot be easily turned off (Stirland et al., 2014; Van Der Knijff, 2014; Wu, Nurse, 2015). Pausing or shutting down SCADA systems in order to conduct forensic investigation can lead to unacceptable operational disruptions, and because of this, live forensics is often the only option. On the other hand, live forensics introduces risks of volatile data during the acquisition process (Escsjwg et al., 2013). Also, evidence preservation during live forensics is very challenging, because carrying out live analysis on memory dumps and log captures may change system states (Stirland et al., 2014; Van Der Knijff, 2014; Wu, Nurse, 2015). The availability of services (for example electrical energy, water supply) and forensic evidence preservation in ICS are not synchronized, and this is one of the biggest challenges in OT/ICS environments. Maintaining continuous operation of critical processes typically takes precedence, which can delay or limit forensic data collection and incident investigation.

The next barrier is resource and expertise gaps, which refers to the significant lack of trained ICS forensic specialists (Eden et al., 2015; Nelufule et al., 2024; Taleghani, Jabreilzadeh Sola, 2025). The lack of skilled personnel is widely recognized worldwide because of the interdisciplinary nature of OT/ICS cybersecurity. This is partially because of the high costs and limited budgets which do not allow organizations to invest in specialized forensic training or software tools. This gap must be addressed in the future, because forensic capacity in the energy sector will remain limited (Eden et al., 2015; Nelufule et al., 2024; Taleghani, Jabreilzadeh Sola, 2025).

Another barrier is organizational resistance, which refers to the prioritization of rapid recovery and system availability over forensic analysis in OT/ICS environments (Eden et al., 2015; Nelufule et al., 2024). Since OT/ICS environments must be continuously active and cannot be easily paused without serious operational risks, a ‘recovery-first’ mindset in critical situations can often lead to overwriting or loss of critical forensic evidence. Generally, the mindset in the industrial environment is not committed to the forensics aspect, and usually digital forensics is not even listed in the safety audits and risk management practices (Kumar et al., 2022). Organizational resistance is a very complex obstacle to overcome. Staff are usually concerned with providing the service, and in general, industrial environments are not as agile as IT environments. Staff must be regularly trained and provided with a testing environment in order to gain trust in newer, more modern technologies.

The next, very significant obstacle is hybrid physical-cyber failures which relate to physical malfunctions as a result of the cyberattack. Cyberattacks often cause physical malfunctions, as seen in the Stuxnet malware in Iran or Triton malware in Saudi Arabia attacks (Eden et al., 2015; Nelufule et al., 2024; Taleghani, Jabreilzadeh Sola, 2025). Without forensic analysis, physical malfunctions can be wrongly interpreted as mechanical or human error. This misinterpretation can mask the real cause of physical malfunctions such as cyberattacks, and lead to the late detection of infected systems (Eden et al., 2015; Nelufule et al., 2024; Taleghani and Jabreilzadeh Sola, 2025).

The final barrier recognized in the literature is legal and standardization issues. Unfortunately, there are no standardized forensic procedures in ICS environments (Cusack, Mahmoud, 2018), which compromises evidence acquisition. Eden et al. (2015) emphasises that many regulatory gaps slow down the adoption of forensic readiness in energy infrastructures. Also, the lack of synchronized evidence-handling frameworks reduces trust in forensic results (Cusack, Mahmoud, 2018; Eden et al., 2016, 2015; Van Der Knijff, 2014). Regulatory frameworks must be reformed in order to allow the successful integration of digital forensics into the energy sector.

Research question 3: How does digital forensics contribute to strengthening the defence strategies of the energy sector against cyberattacks?

The literature states that forensics investigation helps in reconstructing the timeline of the events prior to an actual cyberattack and the steps the hackers took during an attack on energy infrastructure (Dimitriadis et al., 2020; Taleghani, Jabreilzadeh Sola, 2025; Wu, Nurse, 2015). Furthermore, digital forensics can identify the vulnerabilities exploited by the attackers. In order to make sure systems are forensic-ready, the literature suggests implementing proactive measures such as advanced logging, continuous monitoring, and the adoption of specialized ICS/SCADA forensic frameworks. In this way the role of digital forensics can be more proactive, instead of reactive.

This case study analyses five different types of cyberattacks: reconnaissance (scanning attack); unauthorized parameter change (sabotage); malware injection; denial of service attempt; and insider threat. Table 2 presents all five scenarios, with attack descriptions and examples of potential forensics findings.

Reconnaissance cyberattacks are a very prominent type of cyberattack in the industry or operational technology environment. Reconnaissance cyberattacks are actually the first step in every cyberattack on critical infrastructure, and the initial phase, during which the attack can still be recognized and properly mitigated (Chakraborty et al., 2025; Lewis, 2023; Warwick, DiPalma, 2021; Qin et al., 2024; Spyridopoulos et al., 2013). The main goal of reconnaissance is to gather valuable information about the system, and to identify its vulnerabilities and potential entry points. The steps attackers take in reconnaissance are: port scanning in order to detect all the open ports; network mapping and topology; detecting all the running services; and recognizing the used operating systems. Open-source intelligence (OSINT) is usually a crucial part of reconnaissance attacks, since the adversary is gathering all the available data (Congressional Research Service, 2020; Mahesh Wakchaure et al., 2016; US Department of Energy, 2016). Reconnaissance will not directly compromise systems, but it does leave detectable traces in the system and network logs for a forensics investigator to use and discover the attack. The traces that this type of attack leaves include IP addresses, timestamps, and unusual traffic patterns, and these are crucial for the forensics investigation, as they are certain early indicators of malicious intent. One of the most common techniques used in reconnaissance attacks is port scanning with tools like Nmap. For example, after a scanning attack in which the adversary uses a port scanner to identify potential open ports on the SCADA systems, a considerable amount of evidence is left, and can be discovered using forensic methods. After the scanning attack, the IP address of the attacker is logged, as well as the targeted industrial protocols and connection attempts.

The second type of attack is sabotage. Sabotage refers to the unauthorized manipulation of values, and alteration to PLC devices such as frequency and voltage. This unauthorized change in parameters is logged together with the time when it happens, and digital forensics can help in identifying the exact moment and command that the attacker used. Moreover, after identifying the exact command, the potential vulnerability of the system can be detected and corrected in a timely manner.

The third scenario refers to one of the most common types of attack on critical infrastructure and the energy sector – malware injection. For example, the malware is designed in such a way that it attacks the SCADA system (just as the Stuxnet malware was designed) and, after the attack, the logs will register an ‘unknown’ or ‘invalid’ command, and the anomalies recorded will serve as a crucial indicator of an adapted malware injection. Also, if the attacker tries to exploit vulnerabilities and weaknesses in the communication protocols (Modbus, DNP3, or S7Comm), the forensics logs generated in this case will again record the anomalies and give evidence of a cyberattack. After detecting all the malicious attempts, forensics provides a solution for improving the intrusion detection systems and strengthening the existing defensive strategies.

The next scenario is Denial of Service (DoS), which refers to flooding the SCADA server with a high volume of requests from the same IP address which tend to overload the system. In this case, by conducting the forensics investigation, the logs reveal sudden spike requests and anomalies in traffic which indicates that this is not the normal activity of the network.

The final cyberattack presented in this case study is insider threat. This cyberattack is one of the most difficult threats to cope with, because it comes from inside the organization, sector or system. In the case of insider threat, the logs register numerous repeated login attempts, which is an indication of an attack. In this case, the importance of forensics readiness (monitoring and password change policy) is evident.

Table 2:

Attack Scenarios and Forensic Findings

ScenarioExamples of Forensic Finds
1. Reconnaissance/Scanning AttackThe logs record the attacker's IP address, targeted protocols, and connection attempts. Scanning is the first step of cyber-terrorism; forensics documents the attempt and enables attribution (Kilpatrick et al., 2008, 2006; Spyridopoulos et al., 2013).
2. Unauthorized Parameter Change (Sabotage)In this type of cyberattack, the logs can be investigated because they capture an unauthorized WRITE command and the time when the attack occurred. Analysis of the logs can reveal the exact moment and command of the cyberattack (Onyiego, Elisha Abade, 2020; Yau, 2015).
3. Malware InjectionForensics investigation in this case can enable the early detection of attacks (even when these attacks do not succeed) by investigating the ‘unknown’ or ‘invalid’ command which was registered in the logs after the attack (Iqbal et al., 2019; Kawoosa, Prashar, 2021; Mason, Zhou, 2021; Saeed et al., 2024).
4. Denial of Service (DoS)The logs reveal sudden spikes in requests and anomalies in traffic. Digital forensics techniques can distinguish between normal and abnormal activity, helping to uncover DoS attacks (Carcano et al., 2011; Yang et al., 2014).
5. Insider ThreatThe logs registers repeated login attempts, the use of a default password, and subsequent activity. Cyber-terrorism can also come from the inside; forensic techniques provide the only evidentiary trail of insider actions (Eden et al., 2015; Van Der Knijff, 2014).

4. CASE STUDY – THE FORENSIC POTENTIAL OF THE MAJOR CYBERATTACKS ON ENERGY INFRASTRUCTURE

This case study combines literature findings with real-world cyberattacks on the energy sector, and gives examples of what could be potentially analysed in the digital forensics investigation process. For example, in the Stuxnet attacks, forensics reverse engineering of the malware code and checking of the PLCs and Windows logs revealed that it was designed to physically damage centrifuges in the nuclear plant (Bakić et al., 2021; Selján, 2020; Stevens, 2020; Taleghani, Jabreilzadeh Sola, 2025). In the Triton/Trisis attack, forensic analysis revealed an attack on the safety systems which could have resulted in catastrophe. These real-world examples show that digital forensics is not just a technical tool for investigating cyberattacks and incidents on energy infrastructure, but is also a strategy for strengthening resilience, defence and security policy in critical energy infrastructure. This case study represents the core contribution of this research and the author's synthesis. Table 3 presents systematic mapping of major real-world cyberattacks on energy infrastructure and the forensics potential, and combines theory with practical application. This case study analyses Stuxnet (2010), Triton/Trisis (2017), the Ukraine Power Grid (2015–2016), and the Colonial Pipeline attack (2021) to demonstrate how digital forensics can be used to strengthen resilience in critical energy systems. Table 3 represents the synthesized findings from previous research and the literature included in the systematic literature review (78 studies).

Table 3:

Case study: Major Cyberattacks on Energy Infrastructure – Forensic Potential

CaseDigital Forensic Potential
Stuxnet (2010)
  • Reverse engineering of malware code

  • Correlation of operating system and PLC logs

  • Reconstruction of the attack timeline

  • Attribution through technical signatures and behavioural patterns (Bakić et al., 2021; Çetinkaya, Terzi, 2024; Musakhanov D, 2023; Pitman, Crosier, 2024; Saaida, 2023; Selján, 2020; Stevens, 2020; Sumayah Al-Rabiaah, 2018)

Triton/Trisis (2017)
Ukraine Power Grid (2015–2016)
  • Network traffic forensics of remote access sessions

  • Malware artifact analysis

  • Correlation of SCADA event logs with power outages

  • Reconstruction of operational impact (Dovhan et al., 2025; Jenne, 2025; Slowik, 2018, n.d.; Pitman, Crosier, 2024; Rector, 2024)

Colonial Pipeline (2021)

Conclusion

Digital forensics has great potential to become one of the cornerstones of protection and defence in the energy sector, since it is the ultimate tool for incident detection and analysis, evidence collection and preservation, attribution and accountability, and forensic readiness within SCADA systems and Smart Grid (Carcano et al., 2011; Irfan Ahmed, 2012; Kilpatrick et al., 2008, 2006; Kleinmann, Wool, 2014; Mason, Zhou, 2021; Nelufule et al., 2024). The integration of digital forensics into the energy sector enables the following: anomaly identification; secure evidence collection and preserving the chain of custody; reconstruction of the actions and timeline of cyberattacks; enhancing operation resilience; and regulatory compliance (Carcano et al., 2011; Irfan Ahmed, 2012; Kilpatrick et al., 2008, 2006; Kleinmann, Wool, 2014; Mason, Zhou, 2021; Nelufule et al., 2024). This study focuses on the proactive embedding of digital forensics into the energy sector as a proactive defence capability which can support continuous monitoring, real-time forensics and the long-term resilience of critical energy infrastructure. However, although digital forensics is a valuable tool which can be powerfully used in energy infrastructure, its integration into OT/ICS systems has multiple barriers: legacy system limitations and a lack of forensic-ready frameworks; data acquisition challenges and complex interconnectivity with cascade effects; limited ICS-specific tools and availability constraints; resource and expertise gaps and organizational resistance; the hybrid nature of energy systems; and legal and standardization issues.

The study also analyses five major cyberattack scenarios (reconnaissance/scanning, unauthorized parameter change (sabotage), malware injection, denial of service (DoS), and insider threats) in order to demonstrate how digital forensics can offer concrete solutions and the potential to identify attack indicators, trace adversarial behaviour, and prevent recurrence through adaptive defence strategies. Furthermore, this study applies a case study technique to explain the forensics potential in four major cyberattacks (Stuxnet, Triton, the Ukraine Power Grid attack and the Colonial Pipeline attack). The aim of the case study is to demonstrate how digital forensics can help in enhancing the cyber defence of energy infrastructure, based on the forensics findings of previous cyberattacks on the energy sector. Digital forensics should be viewed not only as a tool for investigating attacks after they have happened, but as an investigative instrument which is crucial to cyber defence and resilience engineering within energy infrastructure.

Notes

[1] AI Disclosure Statement

When preparing this article, the author used Grammarly for sentence-level corrections and language editing. No specific prompt was used, as the tool provided automated suggestions for proofreading and language improvement. The author subsequently reviewed and edited the output as necessary and accepts full responsibility for the content and integrity of the publication.

DOI: https://doi.org/10.2478/cmc-2026-0019 | Journal eISSN: 2463-9575 | Journal ISSN: 2232-2825
Language: English, Slovenian
Page range: 53 - 71
Published on: Sep 30, 2026
Published by: General Staff of the Slovenian Armed Forces
In partnership with: Paradigm Publishing Services
Publication frequency: 4 issues per year

© 2026 Inda Kreso, published by General Staff of the Slovenian Armed Forces
This work is licensed under the Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 License.