Seeing the energy system the way an attacker does, without touching anything
A sector's attack surface is everything an attacker can observe and reach from the outside before touching a single system. This site reconstructs it for Argentine energy, gas and power, from open sources: the physical structure, how the loss of one node propagates, the incidents that already happened, the sector's internet footprint, the activity seen from orbit, and the map of who would have to respond. Nothing comes from scanning anyone.
Gas transmission network and high-voltage power grid (≥220 kV) with generation sized by installed capacity. Source: the gas-network snapshot and the Energy Secretariat's official datasets. This is the base layer the others sit on.
The rule that separates this from a target list
A map that convenes operators to defend themselves and a map that hands an attacker its targets are the same map at different resolutions. The difference is a rule, and this site keeps it without exception:
The aggregate is published, never the target
Everything shown is aggregated to the subsector, region, or autonomous-system level. No page carries the tuple that turns analysis into an attack: named operator → exposed host or IP → port. The detailed inventory of what a company looks like from outside is a private deliverable handed to that company about itself, and it does not live here.
It is the logic by which a sector CERT like Denmark's SektorCERT deploys sensors: it watches the pattern that runs across every company, not any one company's traffic. The pipeline that builds the site includes a check that fails if a published artifact breaks the rule.
The six layers
- Structure & interdependence. The bi-energy physical skeleton and the dependencies between subsectors.
- Cascade impact. If a gas node falls, how many are stranded downstream.
- Known incidents. The fourteen documented cyber incidents in the sector.
- Network exposure. Where the sector's public presence lives, in aggregate.
- Satellite activity. The infrastructure seen at night by VIIRS.
- Who responds. The actors and who can convene the table.
The method details every source and assumption. The limits say what this cannot claim.
Why it exists
The Argentine energy system has no public inventory of its attack surface and no sector incident register with a reporting framework. The critical-infrastructure cybersecurity program financed by the Inter-American Development Bank starts from a 9% baseline, measured in 2021: the share of sectors with critical infrastructure identified, targeting 50% by 2028. This map is a first sweep of that gap, built from what anyone can see.
The empirical work underneath is the register of cyber incidents in energy, with a source for every row.