Why DNV Is Urging Energy Operators to Rebuild Resilience
DNV, a risk management and assurance firm with deep ties to the energy sector, has published a new paper telling power providers, grid operators and energy managers to stop treating resilience as a compliance exercise and start building it into everyday investment decisions. The paper, From Concern to Control: Rethinking energy resilience for the new threat era, argues that the threat environment facing energy infrastructure has changed fundamentally over the past decade.
The company's own survey of more than 1,000 senior energy professionals found that over half said their organisations lacked a clearly defined and regularly updated resilience strategy. DNV argues that gap is no longer tenable in a period shaped by geopolitical tension, climate-related extreme weather, faster digitalisation, AI adoption and deepening supply-chain dependencies.
DNV's answer is a continuous four-step cycle: analyse risks and build a modern threat profile, prioritise investments using risk scoring, implement changes within existing asset-management processes, and continually check and validate defences through stress-testing. The paper points to the April 2025 blackout in mainland Spain and Portugal, which disrupted transport, telecoms and hospitals, as an example of how technical and organisational weaknesses can cascade into a national emergency.
The framework is already backed by named industry work. Siemens Energy is partnering with DNV on operational technology cybersecurity guidance for offshore wind, while Fortum and E-REDES contributed to DNV Cyber's Energy Cyber Priority 2025 research. DNV has also worked with Nordic transmission system operators Fingrid, Statnett and Svenska Kraftnät on substation cybersecurity.
Inside DNV's Framework and Its Industry Alliances
Why the survey finding should worry operators
DNV's most striking data point is not the existence of geopolitical and cyber threats, but the admission from more than half of 1,000-plus senior professionals that their organisations do not have a current, clearly defined resilience strategy. If that pattern reflects the wider industry, a large share of operators is effectively relying on outdated asset-planning assumptions while the risk environment becomes more interconnected.
From compliance box to capital decision
The paper's core argument is that resilience should not be a bolt-on project that loses momentum. By recommending that implementation be woven into existing asset-management processes, DNV is pushing energy boards and management teams to make resilience part of capital allocation rather than a standalone annual exercise. The four-step cycle also uses the bow-tie diagram from health and safety practice, suggesting a common language for risk that crosses operational, cyber and regulatory teams.
Siemens Energy, Fortum and the Nordic TSOs point to standardisation
The named partnerships signal where the sector's immediate priorities lie. The Siemens Energy project on offshore wind OT cybersecurity addresses a known gap: fragmented individual approaches have left investors unsure how to compare cyber risk. The substation work with Fingrid, Statnett and Svenska Kraftnät extends the same logic to transmission systems. These collaborations are not proof of the framework's success, but they do show that large operators are seeking shared standards rather than solving problems independently.
What the DNV Framework Means for Energy Operators and Partners
For energy operators
- Compare your current resilience planning against DNV's four steps, particularly whether the first step includes a modern threat profile and mapped barriers.
- Given the survey finding that over half of energy professionals lack an updated strategy, board-level questions should test whether resilience is embedded in asset management rather than treated as a separate project.
- For offshore wind developers and regulators, track the Siemens Energy-DNV joint guidance project as a likely early benchmark for OT cybersecurity expectations.
- Transmission system operators should review the substation cybersecurity work done with Fingrid, Statnett and Svenska Kraftnät when considering how to test response, restart and recovery plans.
Risk & Opportunity Assessment
| Commercial Risk | Medium | DNV's survey of more than 1,000 senior energy professionals found over half lacked a clearly defined and regularly updated resilience strategy, leaving operators exposed to costly disruptions from aging assets, extreme weather and supply chain problems. |
| Competitive Risk | Medium | Operators that adopt a standardised resilience approach may improve their standing with investors and regulators, while laggards face unclear risk profiles, particularly in offshore wind OT cybersecurity where approaches are fragmented. |
| Regulatory Risk | Medium | DNV calls for closer energy company-government cooperation and the paper points to fragmented individual cybersecurity approaches as a problem; this could invite more prescriptive regulation if voluntary standardisation stalls. |
| Reputation Risk | High | The paper cites subsea pipeline sabotage, cyberattacks on grid operators, missile threats to LNG tankers and terminals, and the April 2025 Spain-Portugal blackout; a resilience failure can quickly escalate into public and political scrutiny. |
| Technology Disruption | High | DNV identifies rapid digitalisation and AI as part of a fundamentally changed threat landscape, while OT cybersecurity for offshore wind remains fragmented and substation cyber threats are a focus of joint research. |
| Commercial Opportunity | High | DNV's frameworks and partnerships with Siemens Energy, Fortum and Nordic TSOs create an opportunity to shape standardised resilience and cybersecurity services, and early adopters may present clearer risk profiles to investors. |
Comments 0