
By ProTelesis Corporation | ProTelesis Blog
Imperial County is one of North America’s most concentrated renewable-energy regions — and that density sets a higher bar for cybersecurity. The geothermal plants ringing the Salton Sea, the utility-scale solar and wind arrays across the valley floor, and the emerging “Lithium Valley” direct-lithium-extraction industry don’t just need fast internet and a help desk. They need OT/ICS security tuned to control-system telemetry, IT/OT segmentation modeled on real frameworks, secure remote access to unmanned substations, and carrier-diverse connectivity that survives the desert distances between generation sites.
ProTelesis is able to serve Imperial County energy operators and the businesses around them across El Centro, Calexico, Brawley, Imperial, Calipatria, Holtville, and Westmorland with a portfolio purpose-built for operational technology environments — the SCADA networks, programmable logic controllers, and remote terminal units that keep power flowing. Below is a regional view of how that work breaks down, and how to align it with the compliance frameworks reshaping critical-infrastructure security.
Why Imperial County’s OT Security Stakes Are Higher Than Most
Imperial County is recognized as one of the largest renewable-energy generating counties in California. The Salton Sea Geothermal Field is the second-largest geothermal resource area in the United States after The Geysers, with multiple operating plants drawing on hot brine beneath the lakebed. Spread across the valley floor are large utility-scale solar arrays and wind sites, much of it interconnected through the Imperial Irrigation District (IID) — one of California’s largest public power utilities, serving more than 145,000 electric customers across the Imperial and Coachella valleys.
That same geothermal brine is now the foundation of Lithium Valley. Lawrence Berkeley National Laboratory studies have estimated millions of metric tons of recoverable lithium in the region’s geothermal brine, and several developers are building commercial direct-lithium-extraction operations adjacent to the geothermal plants. The county’s Lithium Valley Specific Plan covers tens of thousands of acres near the Salton Sea earmarked for renewable generation, mineral recovery, and battery-related industry. Layered on top of all this is the county’s agriculture, food processing, and cross-border trade and logistics economy.
For a typical office, “good IT” means uptime, backups, and email that works. For a geothermal plant, a solar farm, a substation, or a lithium-extraction facility, “good IT” includes operational technology that, if compromised, can stop generation, damage equipment, or take a piece of the bulk electric system offline:
• Demonstrable alignment with NERC CIP for assets connected to the bulk electric system, plus IEC 62443 and NIST SP 800-82 for the industrial control systems themselves
• IT/OT segmentation built on the Purdue Model, separating enterprise business systems from the control network with enforced zones and conduits
• Hardened, audited secure remote access to substations and generation sites that are often unmanned and miles from the nearest town
• Monitoring tuned to SCADA/ICS telemetry — not just generic enterprise IT alerts that miss control-system anomalies
• Carrier-diverse connectivity engineered for the geographic spread of desert generation sites, where a single fiber cut or cell outage can isolate a substation
The Frameworks Driving Local OT Security Investment
If you operate generation, transmission, or industrial control systems in Imperial County, four frameworks now drive the majority of OT security conversations. They overlap deliberately — and the smart approach is to treat them as one stack rather than four separate audits.
NERC CIP (Critical Infrastructure Protection)
NERC CIP is the set of mandatory, enforceable Critical Infrastructure Protection standards that the North American Electric Reliability Corporation maintains for the bulk electric system, under oversight from the Federal Energy Regulatory Commission (FERC). The standards cover asset categorization, electronic security perimeters, systems security management, personnel and training, incident reporting, recovery planning, and physical security of critical cyber assets. Whether a specific Imperial County asset falls in scope depends on its impact rating and connection to the bulk power system — a determination that should be made deliberately, not assumed away.
IEC 62443 / ISA-99
IEC 62443 (formerly ISA-99) is the international standard for the security of industrial automation and control systems. It organizes a control environment into zones and conduits, defines security levels, and assigns responsibilities across asset owners, integrators, and product suppliers. For a geothermal plant, solar site, or lithium-extraction operation, IEC 62443 is the technical implementation specification that tells you how to segment the control network and what each conduit between zones must enforce.
NIST SP 800-82
NIST SP 800-82, “Guide to Operational Technology (OT) Security,” is the primary U.S. federal guide for securing industrial control systems. Revision 3, published in September 2023, broadened the scope from classic SCADA/ICS to all OT and aligns with the NIST Cybersecurity Framework. It provides a risk-based program skeleton — Identify, Protect, Detect, Respond, Recover — that maps cleanly onto IEC 62443’s technical controls and NERC CIP’s mandatory requirements.
The Purdue Model
The Purdue Enterprise Reference Architecture (the “Purdue Model”) is the layered reference model that underpins all of the above. It divides an environment into levels — from field devices and controllers at the bottom, through supervisory control and site operations, up to the enterprise and DMZ at the top — with a hardened, DMZ-mediated boundary between IT and OT. NERC CIP electronic security perimeters, IEC 62443 zones and conduits, and NIST SP 800-82 all reference Purdue-style segmentation as the baseline. Get the segmentation right and the other three frameworks become far easier to satisfy.
How ProTelesis Maps Services to the Mission
ProTelesis is a managed services provider, network engineering firm, and carrier-class communications specialist. For renewable-energy and industrial operators in Imperial County, our portfolio aligns to the threats, control frameworks, and uptime obligations that come with running critical infrastructure in the desert. For a full view of our capabilities, visit protelesis.com.
Managed OT/ICS Cybersecurity (24×7 SOC, MDR, SIEM)
The mandate: NERC CIP requires security event monitoring, malware prevention, and incident response for in-scope cyber assets; NIST SP 800-82 and IEC 62443 require continuous detection tuned to the control environment — not a generic enterprise SOC that ignores SCADA traffic.
How we help: ProTelesis supports OT and ICS security programs across monitoring, detection, and incident readiness. Depending on your environment, engagements can include managed detection and response spanning IT and OT assets; SIEM and log retention tuned to control-system telemetry such as PLC, RTU, HMI, and historian events; OT-aware detection for protocol anomalies across Modbus, DNP3, and OPC-UA; incident-response planning that accounts for NERC CIP reporting obligations; and vulnerability and patch management scoped to control networks. Scope varies by site — let’s talk about where your coverage stands today.
Network Engineering & IT/OT Segmentation
The mandate: Enforced separation between enterprise IT and the control network, with a hardened DMZ between them — the core of the Purdue Model, IEC 62443 zones and conduits, and NERC CIP electronic security perimeters.
How we help: We design and support segmentation between enterprise and control networks. Typical work includes Purdue-model architecture with defined zones, conduits, and an industrial DMZ; next-generation and industrial firewalls with OT-protocol awareness; IDS/IPS sized for control-network traffic, including passive monitoring where active scanning isn’t safe; and Zero Trust Network Access so engineers and vendors reach controllers through brokered, logged, least-privilege sessions. Every plant is different — let’s look at your current architecture together.
Fiber, SD-WAN & Carrier Redundancy for Remote Sites
The mandate: Generation sites, substations, and extraction facilities are spread across the valley and often unmanned. A single fiber cut or carrier outage cannot be allowed to blind operators to a remote asset.
How we help: We support connectivity design for distributed generation and substation sites. That can include fiber backhaul design and procurement; carrier-diverse SD-WAN combining fiber, fixed wireless, and cellular with automatic failover; 4G/5G failover and out-of-band management; and encrypted, monitored transport for SCADA and telemetry traffic. Available paths vary by location — we start by mapping what’s actually serviceable at your sites.
CMMC / NIST SP 800-171 Compliance-Ready Managed IT
The mandate: A System Security Plan (SSP) and Plan of Action & Milestones (POA&M) that an assessor can trace directly to your environment — not a binder of policies that don’t match how the network runs — backed by a defensible SPRS score under the DoD Assessment Methodology.
How we help: We support 800-171 programs rather than certify them. On the enterprise-IT side this commonly includes managed Microsoft 365 GCC or GCC High with conditional access, enforced MFA, and DLP for Controlled Unclassified Information — GCC High where ITAR- or export-controlled data is in scope; hardened endpoint baselines to CIS Benchmarks and Microsoft Security Baselines, enforced through Datto RMM with documented configuration management and drift detection; endpoint detection and response via Datto EDR, backed by 24×7 Kaseya MDR and SafeAeon SOC coverage with Kaseya SIEM log aggregation and retention; Microsoft 365 and SaaS activity monitoring through Kaseya SaaS Alerts; network visibility and device-configuration backup with Auvik; immutable backup and tested recovery through Redstor; and SSP authoring with ongoing POA&M maintenance plus SPRS score advisory ahead of self-assessment or C3PAO engagements. Certification outcomes depend on your full program and your assessor — we’ll show you where the gaps usually sit.
Physical Security & Perimeter Protection for Unmanned Sites
The mandate: Substations, geothermal pads, and remote arrays sit far from any guard, yet physical access to a controller is the fastest path to a cyber incident. NERC CIP includes explicit physical-security requirements for critical assets.
How we help: We design and integrate physical security for remote, unmanned sites. Typical scope includes IP video surveillance with analytics suited to perimeter intrusion in low-light desert conditions; access control and intrusion detection integrated with your monitoring platform rather than stranded as a separate system; cellular- and solar-capable deployments where wired infrastructure isn’t available; and physical-security network design intended to share space with the OT network without compromising it. Site conditions drive the design — a walkthrough is usually the fastest starting point.
Structured Cabling & Industrial Wireless
The mandate: The physical layer is still the most common single point of failure on a plant or industrial floor — and harsh desert and high-vibration environments are unforgiving.
How we help: We handle cabling and wireless infrastructure for control buildings and distributed assets. That typically covers BICSI-aligned fiber and Cat 6A backbone design, installation, and certification; industrial wireless and point-to-point links for distributed pads, wellheads, and array blocks; ruggedized cabling and enclosures rated for heat, dust, and vibration; and pre-construction IT/OT scoping so connectivity is designed in rather than retrofitted. Bring us in early — the cost difference before and after commissioning is significant.
What “Cyber-Ready” Looks Like at a Remote Generation Site
Use-case spotlight — a representative Imperial County engagement.
The challenge: A renewable operator running generation near the Salton Sea plus several remote substations has a flat network where the SCADA system, the business office, and vendor laptops all share the same address space. Remote access is a shared VPN with a common password. There is no OT-aware monitoring, segmentation is informal, and an offtaker and the operator’s NERC compliance lead are both asking for documented electronic security perimeters and an evidence package.
The first 90 days: Full IT and OT asset inventory and a control-network traffic baseline using passive monitoring. Design of a Purdue-model architecture separating Levels 0–3 (field devices through site operations) from the enterprise and DMZ. Industrial firewalls and an OT DMZ deployed at each boundary. The shared VPN is retired in favor of ZTNA, so each engineer and vendor gets brokered, logged, least-privilege access to only the assets they need.
By month six: 24×7 OT-aware MDR is live with SIEM retention covering controller, HMI, and firewall events. Carrier-diverse SD-WAN with cellular failover connects every substation back to the operations center, eliminating single-circuit blind spots. Electronic security perimeters are documented and mapped to NERC CIP and IEC 62443. Physical-security cameras and access control at the unmanned substations feed the same monitoring platform. The operator walks into the offtaker’s security review with evidence in hand.
The outcome: The interconnection and offtake relationships are protected, the compliance lead has an audit-ready package, and a fiber cut or single carrier outage no longer isolates a remote site.
Built Around Imperial County’s Energy Communities
Imperial County’s renewable-energy footprint isn’t monolithic. Each community carries a different concentration of generation, industry, and infrastructure, and our delivery teams plan engagements accordingly.
El Centro — County Seat & Operations Hub
As the county seat and largest city, El Centro anchors the region’s business, government, and operations-center activity. Many energy operators run back-office and control-room functions here, which makes El Centro a natural hub for operations-center networking, secure remote access into field sites, and compliance-ready managed IT that ties the remote assets together.
Calexico — Cross-Border Trade & Logistics
On the U.S.–Mexico border, Calexico is a major port-of-entry and logistics center. Energy demand here intersects with cross-border trade, warehousing, and food-related industry. Our Calexico engagements often blend resilient connectivity, network segmentation, and physical security for facilities that mix industrial operations with commercial and logistics traffic.
Brawley — Geothermal & Agriculture in the North Valley
Brawley sits in the northern valley near significant geothermal and agricultural activity. Engagements here lean toward OT/ICS security for processing and generation facilities, industrial wireless, and carrier-diverse links connecting plants and field operations back to central monitoring.
Calipatria — Salton Sea Geothermal & Lithium Valley
Calipatria, near the southern shore of the Salton Sea, is at the heart of the geothermal field and the emerging Lithium Valley. This is where SCADA security, Purdue-model IT/OT segmentation, secure remote access to remote pads, and NERC CIP / IEC 62443 evidence work are most concentrated — alongside physical security for sites that may be miles from the nearest staffed building.
Holtville — Agriculture & Distributed Sites
Holtville, “Carrot Capital of the World,” combines agriculture, food processing, and a scattering of distributed energy and irrigation infrastructure. Our Holtville work frequently centers on fiber and fixed-wireless connectivity, network segmentation, and monitoring for facilities spread across the surrounding farmland.
Imperial — Growth Corridor & Pre-Construction Scoping
The City of Imperial is one of the faster-growing parts of the county, with new commercial and industrial build-out. ProTelesis is regularly engaged at the pre-construction phase here — scoping cabling, wireless, segmentation, and connectivity before slabs are poured — so OT-ready architectures are designed in rather than retrofitted.
Westmorland — Remote Generation & Substation Connectivity
Small and rural, Westmorland exemplifies the connectivity challenge that defines so much of the valley: critical infrastructure spread across long distances with limited wired options. Engagements here focus on carrier-diverse SD-WAN, cellular failover, and out-of-band management so remote generation and substation sites stay monitored and reachable.
Why Local Matters for Critical-Infrastructure Work
OT security runs on response time, site knowledge, and the ability to be present when something breaks. The geographic spread of Imperial County’s energy assets — geothermal pads, solar blocks, substations, and extraction sites scattered across the desert — means a problem at a remote site can’t always wait for next-business-day. ProTelesis maintains regional engineering and field-services capability serving Imperial County and the broader Southern California region, with the understanding that a control-system issue is an operations problem, not just a ticket.
For the parts of the work that run off-site — 24×7 SOC monitoring, after-hours maintenance windows, weekend cutovers — we operate the platforms ourselves rather than reselling someone else’s NOC. That matters when generation is on the line and a reporting clock is ticking.
Schedule an OT Security Conversation
If you operate or support renewable generation, substations, or industrial control systems in Imperial County — in El Centro, Calexico, Brawley, Imperial, Calipatria, Holtville, or Westmorland — and an offtaker, regulator, or your own NERC compliance lead is asking about segmentation and evidence, this is exactly the conversation we have every week.
ProTelesis is a managed services provider, network engineering firm, and carrier-class communications partner serving organizations across California, Arizona, Utah, Nevada, and the broader western United States. Our team supports the renewable-energy, utility, industrial, and cross-border economy of Imperial County and the Imperial Valley with managed OT/ICS cybersecurity, IT/OT segmentation, fiber and carrier-redundant connectivity, structured cabling, physical security, and compliance-ready managed IT.
Frequently Asked Questions: OT & SCADA Cybersecurity for Renewable Energy in Imperial County
What is OT (operational technology) security, and why does it matter for Imperial County energy sites?
Operational technology (OT) security is the discipline of protecting the hardware and software that monitor and control physical processes — the SCADA systems, programmable logic controllers (PLCs), remote terminal units (RTUs), and human-machine interfaces (HMIs) that run generation plants, substations, and industrial facilities. It matters in Imperial County because the region’s geothermal plants, utility-scale solar and wind sites, and emerging Lithium Valley extraction operations depend on control systems that, if compromised, can halt generation or damage equipment. Unlike enterprise IT, OT prioritizes safety and availability and cannot simply be rebooted or patched on demand. ProTelesis delivers OT-aware monitoring, segmentation, and secure access designed specifically for these control environments.
What is NERC CIP and which Imperial County energy assets need it?
NERC CIP (Critical Infrastructure Protection) is the set of mandatory, enforceable cybersecurity standards that the North American Electric Reliability Corporation maintains for the bulk electric system, under oversight from the Federal Energy Regulatory Commission (FERC). The standards cover asset categorization, electronic security perimeters, systems security management, personnel training, incident reporting, recovery, and physical security of critical cyber assets. In Imperial County, whether a specific geothermal plant, substation, or generation site falls in scope depends on its impact rating and connection to the bulk power system. ProTelesis helps operators determine scope and build the electronic security perimeters and evidence packages NERC CIP requires.
What is IEC 62443 and how does it apply to renewable generation?
IEC 62443 (formerly ISA-99) is the international standard for the cybersecurity of industrial automation and control systems. It organizes a control environment into zones and conduits, defines target security levels, and assigns responsibilities across asset owners, system integrators, and product suppliers. For a geothermal plant, solar array, or lithium-extraction facility, IEC 62443 is the technical implementation specification that defines how the control network should be segmented and what each conduit between zones must enforce. ProTelesis uses IEC 62443 zones and conduits as the engineering blueprint for IT/OT segmentation across Imperial County energy sites.
What is NIST SP 800-82 and how does it relate to OT security?
NIST SP 800-82 is the U.S. National Institute of Standards and Technology publication titled “Guide to Operational Technology (OT) Security.” Revision 3, published in September 2023, broadened its scope from classic SCADA and ICS to all operational technology and aligned it with the NIST Cybersecurity Framework. It provides a risk-based program skeleton across the functions Identify, Protect, Detect, Respond, and Recover, and maps cleanly onto IEC 62443’s technical controls and NERC CIP’s mandatory requirements. ProTelesis uses NIST SP 800-82 as the program-management backbone that ties an operator’s OT security controls together into one auditable structure.
What is the Purdue Model and why does IT/OT segmentation use it?
The Purdue Model (the Purdue Enterprise Reference Architecture) is the layered reference model for industrial networks that separates an environment into levels — from field devices and controllers at the bottom, through supervisory control and site operations, up to the enterprise and a DMZ at the top. It places a hardened, DMZ-mediated boundary between IT and OT so business systems never connect directly to control systems. The model matters because NERC CIP electronic security perimeters, IEC 62443 zones and conduits, and NIST SP 800-82 all reference Purdue-style segmentation as the baseline. ProTelesis designs Imperial County control networks around the Purdue Model so the other frameworks become far easier to satisfy.
How do remote substations and generation sites get secure connectivity in the desert?
Secure connectivity for remote energy sites combines fiber backhaul where it exists with carrier-diverse SD-WAN, fixed wireless, and cellular failover so that no single circuit outage isolates a site. SCADA and telemetry traffic between substations, plants, and the control center is encrypted and monitored, and out-of-band management keeps a site reachable even when its primary path drops. This matters in Imperial County because geothermal pads, solar blocks, and substations are spread across long desert distances with limited wired options, and operators must stay able to see and control remote assets at all times. ProTelesis engineers carrier-redundant connectivity built specifically for geographically remote generation and substation sites.
What is secure remote access for OT, and why not just use a VPN?
Secure remote access for OT is the controlled, audited way that engineers and vendors reach control-system assets without exposing the entire control network. Zero Trust Network Access (ZTNA) brokers each session, grants least-privilege access to only the specific assets a user needs, and logs every connection — unlike a flat VPN, which often drops a remote user onto the same network as the controllers with broad reach and shared credentials. This distinction matters for substations and generation sites that are frequently unmanned and serviced by outside vendors. ProTelesis replaces shared VPNs with brokered, logged ZTNA access for Imperial County energy operators.
Why does Imperial County need specialized OT cybersecurity compared to other regions?
Imperial County is one of North America’s most concentrated renewable-energy regions, which creates a specialized OT security demand. It hosts the Salton Sea Geothermal Field — the second-largest geothermal resource area in the United States — along with extensive utility-scale solar and wind generation, a major public power utility in the Imperial Irrigation District, and the emerging Lithium Valley direct-lithium-extraction industry. That density means a large number of control systems, substations, and unmanned generation sites spread across the desert, all needing OT-aware monitoring, NERC CIP and IEC 62443 alignment, and resilient connectivity that a typical commercial market never requires. ProTelesis serves that demand directly across the Imperial Valley.
What does OT-aware managed detection and response (MDR) actually monitor?
OT-aware managed detection and response (MDR) is 24×7 security monitoring tuned to the control environment rather than just enterprise IT. It ingests telemetry from PLCs, RTUs, HMIs, and historians alongside firewall and identity logs, and it watches for control-protocol anomalies in traffic such as Modbus, DNP3, and OPC-UA, as well as unexpected changes to controller logic. Because active scanning can disrupt sensitive control devices, it relies heavily on passive monitoring. Defense for energy operators hinges on this because NERC CIP, NIST SP 800-82, and IEC 62443 all require continuous detection and documented incident response. ProTelesis operates an OT-aware SOC and SIEM as part of a single managed portfolio for Imperial County.
Does ProTelesis serve businesses in El Centro, Calexico, Brawley, Imperial, Calipatria, Holtville, and Westmorland?
Yes. ProTelesis serves businesses across Imperial County, California — including El Centro, Calexico, Brawley, Imperial, Calipatria, Holtville, and Westmorland — with managed OT/ICS cybersecurity, IT/OT segmentation, fiber and carrier-redundant connectivity, structured cabling, physical security, and compliance-ready managed IT. Engagements span renewable-energy operators across geothermal, solar, and wind generation, the emerging Lithium Valley industry, agriculture and food processing, and cross-border trade and logistics. Regional engineering and field-services capability supports the geographically distributed nature of Imperial Valley energy infrastructure. ProTelesis tailors each engagement to the site’s risk profile and applicable frameworks.