• Skip to primary navigation
  • Skip to main content

PMI

  • Home
  • Products
  • Library
    • Videos
      • All
      • Bolt Quality Tests
      • Promotional Videos
      • Support Videos
      • Power Quality Decoded
    • White Papers
      • All
      • Artificial Intelligence
      • Case Studies
      • Communications
        • All Communications
        • Cellular Communications
        • General Communications
      • Distributed Generation
      • IEEE Standards
      • Power Quality
        • All Power Quality
        • Analyzing Waveforms
        • Flicker
        • PQ Data Analysis
        • PQ Theory
      • Products
        • All Products
        • Boomerang
        • Boomerang SCADA
        • Box Recorder
        • Canvass
        • Eagle
        • Flex CT
        • Guardian
        • Merlin™
        • Meter Sockets
        • PQ Canvass
        • ProVision
        • Revolution
        • TLAR
        • Using PMI Recorders
      • Voltage
        • All Voltage
        • CVR
        • Voltage Sag
        • Voltage Unbalance
      • Harmonics
  • Training
    • All
    • PDH Eligible Classes
    • On-Site Training
    • Live Webinars
  • Support
  • Our Company
    • About
    • Contact
    • Join Our Team!
    • Receive our Newsletter
    • PQ Resources
    • Power Quality Solutions
  • Account
  • Cart - 0 items

PQ Canvass and Cybersecurity

← Back to Videos

Transcript

Introduction to PQ Canvass and Cybersecurity

Hello everyone, and welcome to today’s white paper webinar. Today we’re going to be talking about cybersecurity. This is obviously an important topic for utilities given the critical nature of what they do. And because PQ Canvass is a cloud-based application, that raises some cybersecurity concerns from the utility IT perspective.

So here we’re going to talk about how we address that, the types of security scanning and penetration testing we continuously undergo to make sure we’re secure, and the certifications or list of audits we’ve gone through, for example, NERC CIP-013.

PQ Canvass Web Application Security Concerns

Specifically we’re talking about the PQ Canvass web application today. It’s our web application for managing devices, initializing devices, and analyzing data both from recordings and from regularly streaming one-second RMS data.

With a web application, you have very different security concerns. When you have just an application on your computer, if your computer’s off, it’s not doing anything. When you have a web application, it’s accessible to you anywhere, but it also means it’s accessible to people who aren’t you everywhere.

Anything exposed to the internet is getting a constant flow. Most of it’s just nonsense, people just looking for, “Hey, what are you?” But some of it isn’t. Some of it is traffic looking for weaknesses, looking for holes, looking for something to get into. So a web application can never be finished. There will always be new and interesting ways that people try to worm their way in, try to wiggle their way in. And so you need to be on top of that and regularly maintaining your security posture.

Built from the Ground Up

PQ Canvas is something we built completely from the ground up. This is not something we bought off the shelf, one of these website builders. “Hey, start your website in ten minutes. Be on the internet in ten minutes. Plug in a bunch of modules. Who knows who made ’em?” Some kid in his basement made the security module. It’s great. This is something we built from the ground up, every single piece.

From your end, you see a login page. You’re logged in, and then you’re in the application. But what you don’t see is that every single time you are making a request for, “Hey, I’d like to graph some data. I’d like to open this recording. I’d like to start a new recording on this device. I’d like to pull the settings of thresholds from this other device,” in the background, every single request that you make is being revalidated against who you say you are. Do you have permission to talk to this device? Do you have permission to look at this recording?

Hopefully that all looks seamless to you. You don’t have to know that this is all going on in the background, but it is. We are checking every single request that you make. Every single thing that you do, we are revalidating that who you are has permission to do this.

In-House Development and U.S.-Based Data Storage

All of our developers have developed this in-house. This is not contracted out to the lowest bidder and then forgotten about. Our staff is all here at the facility in Virginia. Everybody’s on-site, and also all data that we bring in is stored in data centers here in the United States, specifically with AWS. So when you have devices sending in recordings and streaming data, none of that is ever going overseas. It’s not being exposed overseas. It’s all here.

NERC CIP-013 Compliance

NERC CIP-013 compliance is a part of the supply chain risk management, which means that the bulk electric system entities have to have everybody up and down their supply chain security processes in place. CIP-013 doesn’t do a whole lot to specify what our exact processes are, but it requires that we have processes where we are regularly evaluating our cybersecurity posture. As I mentioned before, what is secure today will not still be secure five years from now, ten years from now, three days from now. You don’t know, so you have to be continually evaluating this.

Third-Party Security Scanning with Intervision

Beyond just looking at ourselves and designing PQ Canvass from the ground up as a secure and protected application that revalidates your authorization, we also have third-party security vendors. For instance, we’re talking here about Intervision. Intervision is a third-party company. There are a lot of security vendors that you can use. This is one that we use because they were able to do both remote scanning and on-site testing of our physical devices.

This particular white paper, we’re not going to talk a whole lot about the physical device penetration testing, though it was very interesting. Maybe we’ll talk about it another time. Right now we’re going to talk about our remote scans.

We are constantly being scanned by Intervision. As new threat definitions come out, as new attacks are created and designed, Intervision’s updating their scans, constantly updating, constantly adding new things to look for.

Scan Report Details

That report comes to us and says, “Hey, here we’ve got an example down here of one of the headers.” Just to give you an idea of how detailed these things are, we scan everything. The PQ Canvass application, all the servers the data is coming into, everything we have gets scanned. To give you an idea, this starts on page one thousand two hundred and six and goes for about a hundred pages, just the PQ Canvass web application section.

This report comes to our software team, our software manager, and Chris, and we look at, okay, what did the scan find? And what concern is what the scan found, and what are we going to do about it?

For instance, right now the top biggest vulnerability in PQ Canvass is that it is possible to determine the time of the remote host. Now this has a very, very low risk score because you already know what time it is. So if you have a time-based authentication protocol, in theory, you could break that by knowing, “Hey, I know what time it is, therefore I can figure out what time the authentication will expire.” Now we are not using a time-based authentication protocol, so we’re not terribly concerned about this, and that’s okay.

Sometimes a scan turns up things that matter, and sometimes it turns up things you go, “Okay, well that’s not really a vulnerability we’re concerned about.” Way down lower in the info section, they’re like, “We’re pretty sure this is a web server.” You’re right. It is. That’s why it’s down in the info section.

Proactive Scanning Before Customer Release

This is something we review regularly, and we are getting our vendor to update anytime we add new services, anytime we add new hosts, anytime we’re working on a demo of something. So before you even see it on the customer end, it’s being scanned and tested. This is not something where we’ll throw it up there and then we’ll scan it later. These are getting scanned long before it comes to customer-facing data, customer-facing applications.

Physical Device Penetration Testing

To wrap things up, we talked about why we’re scanning, what we’re doing for security, and a couple of the basics of the design that we’ve pursued to keep security at the forefront. There’s a couple other white papers about one of our devices that we had scanned. As I mentioned, InterVision has come and also looked at our other current generation products, things like the Seeker. They were on site just fairly recently for the Bolt and trying to break into that from all different angles.

That was a lot of fun as an onset for our software team to succeed in those audits. Very nice to come away with, “Hey, we couldn’t get into it.”

Working with Your IT Group

To wrap up, this is really just a starting point for cybersecurity documentation. Many utilities want more detail or have detailed sets of questions or standard forms for vendors to fill out. So if you’re in that situation, we’re happy to work through your IT group and give them whatever they need to satisfy those cybersecurity requirements. This is really just a starting point for many utilities. We’re used to doing that, and if that needs to be done for your group, just let us know.

Well, thanks for attending everyone, and everyone have a great day.

Have a PQ question? Ask Merlin™ — free. Send it to askmerlin@powermonitors.com or text (540) 383-3144.

Power Monitors, Inc. — Tools you Need. People you Trust.

Power Monitors, Inc. is an industry-leading product design and manufacturing firm based in Mt. Crawford, Virginia. PMI® strives to solve power quality problems by listening to our customers and working with them to design and manufacture products. Total customer satisfaction is the primary goal of all PMI® staff.

24/7 Tech Support 800.296.4120

Resources

  • White Papers
  • Videos
  • Training
  • Live Webinars
  • PQ Resources
  • Support

Company

  • About Us
  • Contact
  • Careers
  • Newsletter
  • Product Registration
  • Terms & Conditions
800 N Main St, Mt Crawford, VA 22841 | Toll Free 800.296.4120 | Fax 540.432.9430
© 2026 Power Monitors, Inc.