Power-sector cybersecurity, from the boardroom to the control room.
Business and technical analysis for when an audit has a date, the system operator demands a plan, an incident takes assets offline or a control centre is designed or relocated. We lead the work with legal and technical partners, through to closure.
- 2
- Institutions with different requirements: the system operator and ANCI
- Business + technical
- One plan for the board and the control room
- Partners
- Legal and technical, under a single lead
Four moments where we help you decide and comply.
-
An audit with a date
Arriving ready for the audit
First what weighs most and can be closed, with the evidence in order.
-
A system-operator requirement
A plan the system operator accepts
Firm dates and follow-through until you are off the list.
-
After an incident
Back online, in compliance
Reporting deadlines, availability and what holds the recovery.
-
Control centre
Control centres that comply
Owner's engineering, independent of whoever builds or operates.
Business and technical analysis, read together.
Every gap has a business cost and a technical requirement. The plan we propose answers both, in the language of each.
-
Business analysis
What the board needs to decide
Exposure to sanctions and the regulator, availability and dispatch, contracts with vendors and the control-centre operator, and the cost of closing each gap against the cost of leaving it.
-
Technical analysis
What the control room needs to demonstrate
Impact classification of each facility, applicability matrix, segmentation and links to the system operator, redundancy, equipment support, time synchronisation and evidence per requirement.
From the board's view to the audit defence.
You enter at the stage your situation needs. Each one delivers something that stands on its own.
-
Initial governance
The board's view
Map of obligations, stakeholders and data flows, contractual risk matrix and an immediate checklist.
-
Gap assessment
Where each asset stands against the standard
Applicability matrix and actionable checklist: item, standard, status, action, priority and owner.
-
3 · Owner's engineer
Control centres compliant by design
Requirements, design review and support for relocations or upgrades, on behalf of the owner.
-
Compliance programme
Gap closure and audit defence
Programme management through the audit: measured progress, organised evidence and responses to the auditor.
-
Ongoing support
Inspections, requests and incidents
Responses to ANCI, the regulator and the system operator, and support during incidents.
We lead the work; the specialists each case requires join in.
-
EnergySage leads and is accountable
A single party accountable for the assessment, the plan and the relationship with the system operator, with the judgment of people who have operated in the sector.
-
AnguitaOsorio
Legal and compliance partnership for Law 21.663, ANCI and the sector regulator.
-
Associated OT and infrastructure specialists
Auditors and technical specialists who join each engagement as associated consultants, under our direction.
-
Independent of vendors and integrators
Implementation is carried out by your O&M or integrator; we set what is required and verify that it is met. Our recommendation answers only to your risk.
Is your company an OIV?
Check the official list of Operators of Vital Importance in the electricity sector. It is a sample of the regulatory intelligence we apply to Chile's grid.
ANCI Exempt Resolution No. 87 · December 17, 2025 · electricity sector
The sector's requirements have become concrete.
Four fronts are moving at once and they land in the same place: operations and the board.
-
The sector already reports attacks on coordinated facilities
Coordinated companies in Chile's grid have reported facility disconnections to the system operator with a declared cause of cyberattack. The risk now shows up as availability for dispatch.
-
A new electric-sector cybersecurity standard, open for public consultation
It sets out information security management and industrial cybersecurity for every electric company, with deadlines that run from publication and a recurring maturity assessment.
-
Operators of Vital Importance with their own obligations
The Cybersecurity Framework Law and ANCI's OIV designation bring cybersecurity into corporate governance: it is a board responsibility, with sanctions and reputational exposure.
-
A sector standard of its own, built on NERC CIP
The Electric Sector Cybersecurity Standard builds on NERC CIP and sets its own high-impact criteria, including national transmission above 220 kV and dispatch and control centres, with the controls that category must demonstrate.
Recommended reading Grid cybersecurity: Chile's new standard reaches consultation as the sector already reports attacks
What people usually ask before starting.
Is my company an OIV?
ANCI designated the Operators of Vital Importance in the electricity sector in Exempt Resolution No. 87, published on December 17, 2025. You can check your RUT with the verifier on this page. If your company is not listed, it may still have obligations under Law 21.663 as an essential service provider.
What changes with the standard under consultation?
It covers two fronts overseen by the system operator: information security management for companies that are not OIVs, and industrial cybersecurity for every electric company, based on the Electric Sector Cybersecurity Standard. It defines accountable roles, policies and deadlines that run from publication, and a recurring maturity assessment.
What should we do after an incident?
First, meet the reporting deadlines to the system operator and ANCI and restore availability. Then organise the evidence, the root cause and a plan with firm dates that supports the return to operation before the system operator and the regulator.
Do you work with our current O&M or control-centre operator?
Yes. They execute; we set what is required, review what is delivered and verify compliance. That is why owner's engineering stays independent of whoever builds or operates.
What is a control-centre owner's engineer?
It is the engineering counterpart that represents the owner before integrators and vendors when a control centre is designed, relocated or audited: it sets the requirements, reviews what is delivered and verifies that the result meets the sector standard.
How do we start?
With a conversation about your position: whether your company is an OIV, how your control centres are classified and what the law and the standard will require. That leads to a gap assessment with priorities and deadlines.
How do you protect information about my infrastructure?
Everything we learn about your architecture, assets and gaps is confidential and handled only by the assigned team. Nothing about your operation is shared or published.
Start by knowing where you stand against the standard.
A first conversation about your regulatory exposure and the state of your control centres, direct and to the point.