Cybersecurity
The Iberian Blackout: Lessons for Critical Energy Infrastructure
The blackout that brought Spain and Portugal to a standstill shows how fragile energy grids are and why visibility into OT assets is decisive.

When Half the Iberian Peninsula Goes Dark
A large-scale power outage left much of Spain and Portugal in the dark, affecting millions of people within a few hours. The effects spread far beyond household lighting: halted transport, intermittent communications, struggling airports, hospitals and emergency services forced to operate in degraded conditions.
The exact dynamics are still under analysis. The most credible hypothesis points to an extreme imbalance in temperatures that would have destabilized the grid, even though two hacker groups claimed responsibility for the event without any technical confirmation. Beyond attribution, the message for those who manage critical infrastructure is clear: the cause matters less than the ability to see, understand and react in time.
Why Energy Grids Are So Fragile
Modern energy infrastructure is a web of physical and digital components. This makes it efficient, but also exposed on multiple fronts:
- Dependence on complex control systems. SCADA and ICS govern generation, transmission and distribution. Anomalous behavior in these systems can go unnoticed until it is too late.
- Cascading effects. Grids are deeply interconnected: a fault at a single transmission point can spread quickly to neighboring grids, amplifying a local problem until it becomes continental.
- Operational errors and neglected maintenance. Not everything is a cyberattack. Misconfigurations, postponed maintenance and poorly tested procedures remain concrete and frequent causes.
- Threats that are hard to anticipate. Extreme environmental events, such as temperature spikes, are difficult to prevent and put stress on components designed for more ordinary conditions.
Whether the origin is an attack, a fault or the weather, what makes the difference is how quickly an organization spots the anomaly and frames it in the context of its own plant.
The Operational Lessons
The Iberian episode brings out a few concrete priorities for those who manage OT and industrial environments.
1. An Asset Inventory, Always Up to Date
You cannot protect what you do not know. You need a detailed inventory of all devices on the network, IT and OT, along with their firmware versions, protocols and relationships. It is the foundation of any resilience strategy.
2. Continuous Anomaly Monitoring
Beyond the static map of assets, you need to observe behavior: unexpected traffic, out-of-sequence commands, drift in process parameters. Passive monitoring makes it possible to catch these signals without interfering with production, a non-negotiable requirement in critical plants.
3. Playbooks and Field Drills
An incident response plan is only worth something if it has been tested. Tabletop exercises and predefined playbooks reduce reaction times in the moment that truly counts, turning chaos into procedure.
The MON5 Angle
These are the points where the difference is decided between suffering an event and governing it. The MON5 approach starts from complete visibility into OT assets, so you know at any moment what is connected and how it communicates. On this foundation sits the correlation of vulnerabilities with the real context of the plant: not an abstract list of CVEs, but priority grounded in what is genuinely exposed and critical for that production process.
Finally, anomaly monitoring without stopping production: observing control systems in a non-intrusive way means intercepting drift and suspicious behavior before they turn into service outages. The Iberian blackout is a reminder that resilience cannot be improvised: it is built by knowing your own infrastructure, day after day.
Analysis and commentary by MON5 based on public-domain research and data from the OT/ICS sector.
Related articles

Cybersecurity
OT cybersecurity in oil & gas: refineries, pipelines and terminals under pressure
In oil & gas, cybersecurity is intertwined with process safety: a cyber incident can become a physical one. Risks, safety systems and strategies for refineries, pipelines and terminals.
Cybersecurity
OT Cybersecurity for Local Utilities: Waterworks, Power Grids and Waste Plants with Zero Internal Resources
Local utilities (water operators, power distributors, waste treatment plants) are NIS2-regulated entities with security resources close to zero. SCADA systems 15 to 20 years old connected to the internet, run by a single technician: how to set up OT security from this starting point.

Cybersecurity
Cybersecurity in Water Networks: The Water/Wastewater Sector as a Forgotten Critical Infrastructure
Water and wastewater treatment plants are critical infrastructures with often obsolete OT systems and exposed remote connections. A sector that industrial cybersecurity still struggles to reach.
Do you have visibility into your OT network?
MON5 maps assets, vulnerabilities and anomalies in real time — without stopping production.