← The Key2XS journal
ASSA Abloy Cliq

USE CASE: Sabotage via Compromised Contractor Access at NorthGrid Power Station

Jun 03, 2025 · 3 min read · by the Key2XS team

USE CASE: Sabotage via Compromised Contractor Access at NorthGrid Power Station

In short: A realistic scenario: saboteurs reach NorthGrid Power Station's critical systems through a compromised contractor's ungoverned key access. The case shows which CER-mandated controls — identity-linked rights, instant revocation, audit trails — would have stopped it.

USE CASE: Sabotage via Compromised Contractor Access at NorthGrid Power Station (Part 5 of our CER Series)

A detailed use case of a fictional security incident in the energy sector, designed to illustrate how the Critical Entities Resilience (CER) Directive applies in practice:

Context

NorthGrid Power Station, a large EU-based operator of gas-fired power plants, is classified as a critical entity under the CER Directive. It supplies electricity to over 2 million residents and several hospitals, data centers, and municipal services in its region.

As required by the CER Directive, NorthGrid maintains a Business Continuity Plan (BCP), performs regular risk assessments, and has upgraded its physical and logical access controls. However, third-party contractors are still granted access to certain plant areas using RFID-based key cards administered through a legacy system.

 


 

The Incident

Threat

An external contractor employed by NorthGrid’s HVAC subcontractor has his credentials cloned after leaving his RFID keycard unattended in a public co-working space. The attacker, an eco-extremist posing as a technician, uses the cloned keycard and contractor uniform to gain unauthorized physical access to a critical control room.

Breach

The attacker manually overrides cooling systems, causing a turbine to shut down. The plant is forced to go offline for six hours, resulting in regional brownouts and emergency generator activation at two hospitals.

 


 

Response & Legal Impact under the CER Directive

 

1. Immediate Obligations

 

2. Compliance Failures Identified

 

3. Consequences

 


 

Mitigation Measures Taken

 


 

Lessons Learned

This incident demonstrates how even a single weak link — such as a contractor’s outdated access method — can create systemic risk in a critical entity. Under the CER Directive, organizations must treat third-party risk, physical security, and accountability as interconnected priorities. Failure to do so has legal, financial, and human consequences.

Written by the Key2XS team

Key2XS is founder-run. Questions about this piece land with the people who built the platform. Talk to us.

Govern the keys you already have

See identity, policy and physical keys in one 30-minute demo, scoped to your estate.