Skip to main content
Have a personal or library account? Click to login
The Role of Digital Forensics in Protecting Critical Energy Infrastructure from Cyberattacks Cover

The Role of Digital Forensics in Protecting Critical Energy Infrastructure from Cyberattacks

By:   
Open Access
|Sep 2026

Figures & Tables

Figure 1:

Process of systematic literature review

Table 1:

Digital Forensics Roles and Forensic Potential in Energy Infrastructure

Role of Digital ForensicsForensic Potential
Incident Detection and AnalysisThrough log monitoring, monitoring system behaviour and network traffic, anomalies in SCADA/ICS and Smart Grid systems are identified. Forensics analysis which is protocol-aware (which means that unlike the classic digital forensics approach, this method enables investigators to investigate the operational meaning of transmitted messages within the SCADA and ICS environments) enables more reliable detection of anomalies and enhances interoperability with intrusion detection systems (IDS) (Akkad et al., 2023; Alelyani, Kumar G R, 2018; Carcano et al., 2011; Irfan Ahmed, 2012; Kilpatrick et al., 2008, 2006; Kleinmann, Wool, 2014; Mason, Zhou, 2021; Nelufule et al., 2024).
Evidence Collection and PreservationAcquisition of digital data (PLC code, ladder logic, RTU data, and network traces) is enabled securely and without disrupting operations. When digital evidence is collected, it is crucial to maintain the integrity of the collected evidence by preserving the chain of custody using cryptographic hashing, and SCADA-specific data collection plans (Fabro, 2008; Irfan Ahmed, 2012; Senthivel et al., 2017; Van Der Knijff, 2014).
Attribution and AccountabilityDigital forensics enables the reconstruction of the timeline, steps and actions of the attacker, using PLC forensics, live analysis of memory, and creating an isolated virtual environment in order to safely execute and observe potentially malicious code (sandboxing). Digital forensics in energy infrastructure also enables the attribution and accountability of cyberattacks to the actual attacker or group of attackers. (Eden et al., 2016, 2015; Kamlofsky, Romero, 2022; Maglaras et al., 2019; Mittal, 2015).
Forensic ReadinessIntegrating forensics readiness models into SCADA systems can minimize digital evidence loss, reduce the mean time to response (MTTR), and strengthen organizational resilience against cyberattacks. Forensic readiness models include following elements: the process of identification of potential sources of digital evidence (SCADA logs, PLC memory, network packets, authentication servers); defining a process of evidence collection which ensures integrity through hashing and timestamping; and developing adequate incident response procedures (Eden et al., 2015; Irfan Ahmed, 2012; Slay, Elena Sitnikova, 2009; Madan Raja et al., 2024; Senthivel et al., 2017; Van Der Knijff, 2014).
Incident Response and RecoveryForensics can guide system recovery by tracking malware spread in real time, changes to the PLC code, and volatile memory. Live forensics of SCADA systems can enable safe analysis while the systems remain operational (Jeffries, 2022; Kamlofsky, Romero, 2022; Mason, Zhou, 2021).
Policy, Regulation, and Training SupportDigital forensics helps in enhancing compliance with standards (NERC CIP, NIS2, ISA-99, IEC 62443) and in developing forensic incident response models for strengthening national cyber strategies. The education and training of staff is a crucial part of equipping the energy sector to be able to cope with cyberattacks (Bozhyk et al., 2025; Cusack, Mahmoud, 2018; Eden et al., 2016, 2015; Ene, Savu, 2023).
Table 2:

Attack Scenarios and Forensic Findings

ScenarioExamples of Forensic Finds
1. Reconnaissance/Scanning AttackThe logs record the attacker's IP address, targeted protocols, and connection attempts. Scanning is the first step of cyber-terrorism; forensics documents the attempt and enables attribution (Kilpatrick et al., 2008, 2006; Spyridopoulos et al., 2013).
2. Unauthorized Parameter Change (Sabotage)In this type of cyberattack, the logs can be investigated because they capture an unauthorized WRITE command and the time when the attack occurred. Analysis of the logs can reveal the exact moment and command of the cyberattack (Onyiego, Elisha Abade, 2020; Yau, 2015).
3. Malware InjectionForensics investigation in this case can enable the early detection of attacks (even when these attacks do not succeed) by investigating the ‘unknown’ or ‘invalid’ command which was registered in the logs after the attack (Iqbal et al., 2019; Kawoosa, Prashar, 2021; Mason, Zhou, 2021; Saeed et al., 2024).
4. Denial of Service (DoS)The logs reveal sudden spikes in requests and anomalies in traffic. Digital forensics techniques can distinguish between normal and abnormal activity, helping to uncover DoS attacks (Carcano et al., 2011; Yang et al., 2014).
5. Insider ThreatThe logs registers repeated login attempts, the use of a default password, and subsequent activity. Cyber-terrorism can also come from the inside; forensic techniques provide the only evidentiary trail of insider actions (Eden et al., 2015; Van Der Knijff, 2014).
Table 3:

Case study: Major Cyberattacks on Energy Infrastructure – Forensic Potential

CaseDigital Forensic Potential
Stuxnet (2010)
  • Reverse engineering of malware code

  • Correlation of operating system and PLC logs

  • Reconstruction of the attack timeline

  • Attribution through technical signatures and behavioural patterns (Bakić et al., 2021; Çetinkaya, Terzi, 2024; Musakhanov D, 2023; Pitman, Crosier, 2024; Saaida, 2023; Selján, 2020; Stevens, 2020; Sumayah Al-Rabiaah, 2018)

Triton/Trisis (2017)
Ukraine Power Grid (2015–2016)
  • Network traffic forensics of remote access sessions

  • Malware artifact analysis

  • Correlation of SCADA event logs with power outages

  • Reconstruction of operational impact (Dovhan et al., 2025; Jenne, 2025; Slowik, 2018, n.d.; Pitman, Crosier, 2024; Rector, 2024)

Colonial Pipeline (2021)
DOI: https://doi.org/10.2478/cmc-2026-0019 | Journal eISSN: 2463-9575 | Journal ISSN: 2232-2825
Language: English, Slovenian
Page range: 53 - 71
Published on: Sep 30, 2026
Published by: General Staff of the Slovenian Armed Forces
In partnership with: Paradigm Publishing Services
Publication frequency: 4 issues per year

© 2026 Inda Kreso, published by General Staff of the Slovenian Armed Forces
This work is licensed under the Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 License.