Η ΡΑΑΕΥ, σε συνέχεια της από 9 Ιουλίου 2025 πρόσκλησής της για συμμετοχή στη Δημόσια Διαβούλευση επί της κοινής πρόταση όλων των ΔΣΜ της Ένωσης σχετικά με τη μεθοδολογία της κλίμακας ταξινόμησης κυβερνοεπιθέσεων σύμφωνα με τα οριζόμενα στο άρθρο 37
(8)του κατ’ εξουσιοδότηση Κανονισμού (ΕΕ) 2024/1366 σχετικά με ειδικούς τομεακούς κανόνες για τις πτυχές της κυβερνοασφάλειας στις διασυνοριακές ροές ηλεκτρικής ενέργειας, δημοσιοποιεί τον ακόλουθο πίνακα συμμετεχόντων στη διαβούλευση, καθώς και το περιεχόμενο των επιστολών που υποβλήθηκαν στο πλαίσιο αυτής. Διευκρινίζεται ότι η Αρχή δεν έχει ακόμη τοποθετηθεί επί του περιεχομένου της πρότασης που τέθηκε σε δημόσια διαβούλευση. Η Αρχή ευχαριστεί τους συμμετέχοντες για τη συμβολή τους στην εν λόγω Δημόσια Διαβούλευση. Συμμετέχοντες Ημερομηνία αποστολής: 22.07.2025 Αριθμός πρωτοκόλλου ΡΑΑΕΥ: I-399424 Αποστολέας: MOTOR OIL 0000964669 Ρυθµιστική Αρχή Αποβλήτων Ενέργειας και Υδάτων 23/07/2025 Α. Π.: Εισερχ. I-399424 Αποστολέας: Anastasiou Vasilis Ημερομηνία Αποστολής: Τρίτη, 22 Ιουλίου 2025 Προς: Κεντρικό Πρωτόκολλο Αποδέκτες: info@raaey.gr info@raaey.gr Κοινοποιήσεις: Θέμα Εγγράφου: Δημόσια Διαβούλευση ΡΑΑΕΥ Cyber-Attack Classification Scale Methodology Δεν λαμβάνετε συχνά μηνύματα ηλεκτρονικού ταχυδρομείου από vanastasiou@moh.gr. Μάθετε γιατί αυτό είναι σημαντικό To whom it may concern, We have the following suggestion regarding the public consultation. Considering the guidelines presented in the Cyber-Attack Classification Scale Methodology (CACSM), specifically referring to the tactic "Credential access" as shown on page 11, it is noted that attackers with at least limited asset access can cause impacts classified as either 33% medium gravity or 66% high gravity. Given the critical role of Renewable Energy Source (RES) plants and Energy Storage Stations, particularly those directly connected to Transmission System Operators (TSOs) mainly, but also to Distribution System Operators (DSOs), it is evident that some of these installations inherently belong to high-impact or critical-impact perimeters based on their load contributions and operational significance. Furthermore, it must be acknowledged that several RES plants and Energy Storage Stations rely significantly on cloud-based applications for control purposes. According to the worst-case scenario approach mandated by the NCCS, in the absence of specific risk assessments, one must assume cloud security in such applications to be inadequate. Common security issues include default credentials, absence of mandatory Multi-Factor Authentication (MFA), lack of cyber expertise, and insufficient security-oriented design practices. Additionally, security monitoring and logging for these cloud-based solutions, as well as the related RES and storage infrastructures, are frequently fragmented and decentralized. This dispersion of oversight increases the risk that malicious actors could establish persistence across multiple independent systems without detection, potentially escalating unnoticed until a significant threshold of damage is reached. Given these considerations, we strongly suggest that all RES plants, Energy Storage Stations, Heat Pumps, EV Charging Stations, and other distributed loads should initially be classified within at least a high-impact perimeter. To effectively manage cybersecurity in these environments, it is recommended that: a. Entities receive compliance certification aligned with NIS2, NCCS and any equivalent regulatory frameworks. This certification would allow authorities to regularly monitor cybersecurity maturity and overall compliance. b. Comprehensive risk assessments are conducted specifically targeting the Operational Technology (OT) environment to clearly identify potential risks and vulnerabilities. c. Continuous centralized monitoring and Security Operations Center (SOC) services are implemented and maintained indefinitely to ensure consistent and proactive management of cybersecurity threats, regardless of subsequent risk profile demonstrations. Only through this structured approach, including certification, dedicated OT risk assessments, and ongoing SOC services, can we adequately safeguard these critical energy infrastructures and provide transparency and control to regulatory authorities. Thank you in advance, Vasilis Anastasiou