Microgrids and backup-power systems can support critical loads during grid disruption, but they add concentrated equipment, controls and fuel that may be exposed to theft, sabotage, impact, fire or line-of-sight attack. Security planning should follow the complete power path from source to protected load.
The design team should integrate electrical, controls, fire protection, civil, structural, security and facility operations rather than treating security as a fence added after equipment layout.
Define the critical load and operating modes
List the functions that must remain powered, their duration and the conditions under which the system islands, starts, sheds load or reconnects. Identify manual actions and personnel needed during abnormal operation. A security measure should not prevent safe access to controls, disconnects or emergency shutdown.
Prioritize components whose loss defeats the whole system: switchgear, protection, controls, communications, transformers, fuel and cooling.
Map physical exposure across the power path
Review public roads, parking, roofs, adjacent property and maintenance routes for line of sight and vehicle approach. Consider simultaneous damage to primary and backup feeds where they share rooms, trenches, walls or cable routes.
Use separation, protected routing, hardened enclosures, redundant paths and controlled standoff where consequence justifies them. Preserve ventilation, heat rejection, code clearances and firefighting access.
Protect fuel, batteries and support systems
Fuel theft or contamination, blocked ventilation, damaged cooling and unauthorized battery access can remove resilience without directly attacking the generator. Monitor quantity and condition, control delivery, secure valves and fill points, and define extended-outage refueling.
Energy storage introduces fire, thermal and emergency-response requirements. Physical protection must be coordinated with detection, suppression or control systems, separation distances and responder tactics.
Secure controls and communications
Protect local control panels, network cabinets and remote access equipment from unauthorized physical access. Maintain logs and alert on enclosure entry. Define how operators retain visibility and control if normal communications fail.
Commission cyber and physical scenarios together: loss of a camera, network, controller, sensor or remote command during an outage should trigger clear fallback procedures.
Exercise black-start and degraded conditions
Test system start, islanding, manual operation, load prioritization and refueling under realistic staffing. Include a damaged or inaccessible component. Record recovery time, spare needs and any temporary security required while normal power and perimeter systems are unavailable.
Frequently asked questions
Is a fenced generator automatically secure?
No. Evaluate line of sight, vehicle approach, enclosure resistance, fuel, controls, alarms, response time and bypass routes.
Should primary and backup power use separate routes?
Where consequence warrants, physical diversity reduces common-mode failure. Confirm that apparently redundant feeds do not share one vulnerable room, trench or wall.
What should a resilient-power exercise include?
Test outage detection, start or islanding, critical-load support, manual control, fuel, communications, degraded equipment and safe restoration.
Need to frame a facility decision?
ISCoA helps owners organize physical security exposure, mitigation priorities and evidence requirements before product selection.
Request a preliminary review