A protection scheme in a digital substation can be disabled two ways. One is a deliberate cyberattack: an intruder spoofs a GOOSE message or injects false Sampled Values onto the process bus, tricking a relay into misreading the state of the network. The other is an engineer making a single incorrect entry in a Substation Configuration Language (SCL) file during a routine update. From the protection scheme’s point of view, the two are functionally identical — and both draw on exactly the same scarce pool of expertise to prevent, which is the connection most coverage of digital substations’ downsides misses by treating cybersecurity and workforce shortages as separate stories.
The three-standard answer to a problem IEC 61850 doesn’t solve on its own
IEC 61850 was built to standardise communication, not to secure it. On its own, the standard has no inherent protection against a device on the network sending false data — which matters more than it once did, because digitising a substation means merging what used to be an isolated operational network with the wider IT environment, creating an attack surface that simply didn’t exist when protection signals travelled down dedicated copper.
The response the industry has converged on is layered rather than singular. IEC 61850 defines what devices communicate. IEC 62351 secures how that communication happens — digital certificates, TLS encryption for sensitive commands, message integrity checks, role-based access control. IEC 62443 hardens the environment those messages travel through — network segmentation into security zones, a four-tier scale of security levels, and system-wide patch management. None of the three does the whole job alone, and running only the first — which is still the common baseline on older or partially digitised sites — leaves exactly the gap that concerns grid-security researchers most: a communication standard everyone agrees on, with no agreement on how to keep it honest.
Standardisation that isn’t quite standard
A second problem sits alongside cybersecurity rather than behind it: interoperability, even under one shared standard. Vendors implement IEC 61850 differently in practice, and the gap between Edition 1 and the current Edition 2/2.1 adds further friction when older and newer equipment share a site — a common situation, since utilities rarely digitise an entire fleet in one pass. The practical consequence lands on the same SCL files discussed above: a configuration error in one of them doesn’t produce an obvious, easily traced fault. It produces a protection scheme that looks fine until the moment it’s needed and isn’t — a failure mode considerably harder to catch than a tripped breaker with a visible cause.
There’s a structural issue underneath both problems, too, that rarely makes it into vendor literature: digital components such as merging units and networked relays have a service life of roughly 10–15 years, against 40–50 years for the primary switchgear and transformers they protect. That mismatch means the digital layer of a substation will be replaced, reconfigured and re-secured multiple times over the physical asset’s life — so the skills required here aren’t a one-off transition cost. They’re a recurring one.
The people problem is the actual bottleneck
Which brings the story to staffing, because all three problems above ultimately come down to whether there are enough people who understand both power protection and network engineering well enough to configure, secure and audit these systems. A joint study by Kearney and IEEE puts the scale starkly: the global power sector will need between 450,000 and 1.5 million additional engineers by 2030 to build and maintain energy infrastructure, and roughly 40% of power-sector executives already report difficulty recruiting the skilled staff they need today.
The UK’s own numbers illustrate why that gap matters specifically for grid infrastructure rather than the power sector in the abstract. National Grid’s Great Grid Upgrade programme alone is projected to support more than 55,000 jobs and contribute £14.5 billion to the economy by the end of the decade, while the broader UK energy sector is estimated to need 400,000 additional roles by 2050 to meet net-zero commitments — against Ofgem’s approved £24 billion investment package, £8.9 billion of which is earmarked specifically for high-voltage network expansion over five years. Money has been allocated; the people to spend it on qualified engineering haven’t yet been trained in the numbers required.
What makes digital substations a sharper version of this general shortage, rather than just a beneficiary of it, is the specific skill combination they demand: protection engineering, Ethernet networking, cybersecurity practice and the ability to read an SCL or GOOSE configuration file the way an older generation of engineers could read a wiring diagram. That combination is scarce enough that specialist training has become its own small industry. DNV’s Energy Academy runs a two-day IEC 61850 course in Arnhem, in the Netherlands, aimed explicitly at utility staff and equipment manufacturers who need to move from theoretical familiarity with the standard to practical competence with it. In the United States, engineering firm TRC has built a dedicated mock digital substation specifically so crews can make their configuration mistakes somewhere other than a live commissioning site — on the reasoning, as the firm puts it, that “the learning curve is steep and live projects aren’t the right classroom.”
Why the distinction stops mattering
None of this is an argument against digital substations — the investment case and the technical case made elsewhere in this series both still hold. It’s a case for taking the workforce gap as seriously as the cybersecurity one, because they aren’t really two problems. An intruder capable of crafting a convincing GOOSE spoof and an engineer capable of correctly writing the SCL file that intruder is trying to imitate draw on nearly the same expertise — the industry simply doesn’t have enough people who possess it, on either side of that line. Closing the gap in Arnhem, in a mock substation in the US, or in whatever training capacity the UK builds against its own 400,000-role target, isn’t a side project to digitisation. It’s the precondition for the rest of it working as intended.







