Power-sector cybersecurity, from the boardroom to the control room.

Business and technical analysis for when an audit has a date, the system operator demands a plan, an incident takes assets offline or a control centre is designed or relocated. We lead the work with legal and technical partners, through to closure.

2
Institutions with different requirements: the system operator and ANCI
Business + technical
One plan for the board and the control room
Partners
Legal and technical, under a single lead

Four moments where we help you decide and comply.

  1. An audit with a date

    Arriving ready for the audit

    First what weighs most and can be closed, with the evidence in order.

  2. A system-operator requirement

    A plan the system operator accepts

    Firm dates and follow-through until you are off the list.

  3. After an incident

    Back online, in compliance

    Reporting deadlines, availability and what holds the recovery.

  4. Control centre

    Control centres that comply

    Owner's engineering, independent of whoever builds or operates.

Business and technical analysis, read together.

Every gap has a business cost and a technical requirement. The plan we propose answers both, in the language of each.

  1. Business analysis

    What the board needs to decide

    Exposure to sanctions and the regulator, availability and dispatch, contracts with vendors and the control-centre operator, and the cost of closing each gap against the cost of leaving it.

  2. Technical analysis

    What the control room needs to demonstrate

    Impact classification of each facility, applicability matrix, segmentation and links to the system operator, redundancy, equipment support, time synchronisation and evidence per requirement.

From the board's view to the audit defence.

You enter at the stage your situation needs. Each one delivers something that stands on its own.

  1. Initial governance

    The board's view

    Map of obligations, stakeholders and data flows, contractual risk matrix and an immediate checklist.

  2. Gap assessment

    Where each asset stands against the standard

    Applicability matrix and actionable checklist: item, standard, status, action, priority and owner.

  3. 3 · Owner's engineer

    Control centres compliant by design

    Requirements, design review and support for relocations or upgrades, on behalf of the owner.

  4. Compliance programme

    Gap closure and audit defence

    Programme management through the audit: measured progress, organised evidence and responses to the auditor.

  5. Ongoing support

    Inspections, requests and incidents

    Responses to ANCI, the regulator and the system operator, and support during incidents.

We lead the work; the specialists each case requires join in.

  1. EnergySage leads and is accountable

    A single party accountable for the assessment, the plan and the relationship with the system operator, with the judgment of people who have operated in the sector.

  2. AnguitaOsorio

    Legal and compliance partnership for Law 21.663, ANCI and the sector regulator.

  3. Associated OT and infrastructure specialists

    Auditors and technical specialists who join each engagement as associated consultants, under our direction.

  4. Independent of vendors and integrators

    Implementation is carried out by your O&M or integrator; we set what is required and verify that it is met. Our recommendation answers only to your risk.

Is your company an OIV?

Check the official list of Operators of Vital Importance in the electricity sector. It is a sample of the regulatory intelligence we apply to Chile's grid.

ANCI Exempt Resolution No. 87 · December 17, 2025 · electricity sector

The sector's requirements have become concrete.

Four fronts are moving at once and they land in the same place: operations and the board.

  1. The sector already reports attacks on coordinated facilities

    Coordinated companies in Chile's grid have reported facility disconnections to the system operator with a declared cause of cyberattack. The risk now shows up as availability for dispatch.

  2. A new electric-sector cybersecurity standard, open for public consultation

    It sets out information security management and industrial cybersecurity for every electric company, with deadlines that run from publication and a recurring maturity assessment.

  3. Operators of Vital Importance with their own obligations

    The Cybersecurity Framework Law and ANCI's OIV designation bring cybersecurity into corporate governance: it is a board responsibility, with sanctions and reputational exposure.

  4. A sector standard of its own, built on NERC CIP

    The Electric Sector Cybersecurity Standard builds on NERC CIP and sets its own high-impact criteria, including national transmission above 220 kV and dispatch and control centres, with the controls that category must demonstrate.

Recommended reading Grid cybersecurity: Chile's new standard reaches consultation as the sector already reports attacks

What people usually ask before starting.

Is my company an OIV?

ANCI designated the Operators of Vital Importance in the electricity sector in Exempt Resolution No. 87, published on December 17, 2025. You can check your RUT with the verifier on this page. If your company is not listed, it may still have obligations under Law 21.663 as an essential service provider.

What changes with the standard under consultation?

It covers two fronts overseen by the system operator: information security management for companies that are not OIVs, and industrial cybersecurity for every electric company, based on the Electric Sector Cybersecurity Standard. It defines accountable roles, policies and deadlines that run from publication, and a recurring maturity assessment.

What should we do after an incident?

First, meet the reporting deadlines to the system operator and ANCI and restore availability. Then organise the evidence, the root cause and a plan with firm dates that supports the return to operation before the system operator and the regulator.

Do you work with our current O&M or control-centre operator?

Yes. They execute; we set what is required, review what is delivered and verify compliance. That is why owner's engineering stays independent of whoever builds or operates.

What is a control-centre owner's engineer?

It is the engineering counterpart that represents the owner before integrators and vendors when a control centre is designed, relocated or audited: it sets the requirements, reviews what is delivered and verifies that the result meets the sector standard.

How do we start?

With a conversation about your position: whether your company is an OIV, how your control centres are classified and what the law and the standard will require. That leads to a gap assessment with priorities and deadlines.

How do you protect information about my infrastructure?

Everything we learn about your architecture, assets and gaps is confidential and handled only by the assigned team. Nothing about your operation is shared or published.

Start by knowing where you stand against the standard.

A first conversation about your regulatory exposure and the state of your control centres, direct and to the point.

Write to us at

[email protected]

Open in Gmail Open in Outlook