XAGE SECURITY NEXTera ENERGY
Account brief · prepared for NextEra Energy Resources

Operational technology · Generation fleet

Your OT security roadmap is already written. This is what answers it.

NextEra's Power Generation Division has published what it is building: role-based access control, secure remote access, asset inventory automation, hardening and recovery, all under a NERC CIP-aligned programme. Xage did not write that list. We just happen to be the fabric that closes every line on it, agentlessly, across a fleet measured in thousands of sites rather than dozens of data centres.

~33 GW
Renewables and storage backlog with commercial operation dates in 2026–2027
0
Agents to install on legacy controllers, relays, RTUs or historians
$90B+
Capital plan through 2030 — every site arrives needing vendor access on day one
1
Identity fabric covering OT, IT, cloud and AI agents alike

Why now

Three things changed, and all three land on the generation fleet.

On the scattered, thinly staffed, multi-vendor sites that produce the power. That is where tooling built for IT has always stopped.

01

CIP-003-11 moved the fleet into scope

The recent NERC CIP revisions reclassify assets that were historically treated as low-impact, among them substations and distributed energy resources, and subject them to stricter controls.

For an operator whose fleet is distributed energy resources, that re-scopes the entire estate. And the controllers now in scope are the ones that will never run an agent.

02

Security has to move at construction speed

A backlog near 33 GW with commercial operation dates inside two years means sites arriving continuously, each with turbine, inverter, storage and balance-of-plant vendors needing access from the first day of commissioning.

Access provisioned site-by-site by hand does not survive that rate. Identity provisioned as the site comes online does, and it arrives already audit-ready.

03

NextEra is on both sides of the AI trade

You are monetising AI-driven load growth through large-scale power agreements while adopting AI and automation inside your own operations. Those are two different security problems that most vendors make you solve with two different products.

Xage enforces zero trust for AI agents and LLMs at the protocol layer, underneath the AI stack, where a prompt cannot talk its way past the control. The same fabric and the same policy model as the fleet, with one audit trail across both.


The mapping

Your stated initiatives, and what covers each one.

The left column is your programme, described in your own published language. We have only filled in the right.

What NextEra has said it is doing What Xage does about it today
NextEra
Role-Based Access Control
Named as a strategic initiative of the PGD OT cybersecurity programme.
Xage
Identity-based access, enforced to the asset
Granular, just-in-time access controlled down to the individual asset, one level below the network segment it sits in. Roles travel with the identity, so they hold when the asset moves.
NextEra
Secure remote access
Listed alongside the IT/OT separation projects.
Xage
Zero Trust Remote Access, multi-party by design
Built for third-party maintenance crews: access that is scoped, expires on its own, and is attributed to a named person, to and through the OT-IT DMZ. No shared credentials, no standing VPN into the plant.
NextEra
Asset inventory automation
One of the six areas the PGD programme is built around.
Xage
Identity is the inventory
Every asset gets an enforced identity in the fabric, so the register is a by-product of how access works. A scan is stale the week after it runs.
NextEra
Vulnerability management
Runs across SCADA servers, HMIs, PLCs, historians, RTUs, protective relays and metering.
Xage
Hardening as the compensating control
Most of that list cannot be patched on your schedule, and some of it cannot be patched at all. Credential management and automated rotation, plus identity-gated access, reduce exposure on assets whose vendor will not ship a fix.
NextEra
IT/OT separation initiatives
Named alongside centralised OT infrastructure deployments.
Xage
Segmentation without re-architecture
A multi-hop mesh preserves logical separation and protects every interaction and data transfer between devices, applications and users, without ripping and replacing the network you have already paid for.
NextEra
Backup and recovery; OT resiliency
Recovery is one of the five functions the programme is organised around.
Xage
No single point of failure, no cloud dependency
The fabric is distributed by construction and enforces locally. A site that loses its uplink keeps its access controls; a fully air-gapped deployment is a supported configuration.
NextEra
NERC CIP-aligned programme
The framing the whole PGD programme operates under.
Xage
Published control mapping, including low-impact BES
Xage maintains a public NERC CIP control mapping for utility customers and has published specifically on CIP-003-11 and low-impact BES cyber systems, the change that just pulled your DERs into scope.

Why IT-centric tooling stalls here

The constraint is the assets themselves. Most of them cannot host software.

Energy operators reach for IT tools to secure distributed generation because that is what is already licensed. But IT-centric tooling cannot natively secure industrial control systems, and the gap it leaves is magnified across every interconnected OT, IT and cloud boundary in the fleet.

Agentless by design

Asset protection without software on the legacy component. Most OT rollouts stop at the plant fence. This one goes past it.

Selected by NREL

The US Department of Energy's National Renewable Energy Laboratory selected Xage for its clean energy cybersecurity programme.

Fleet-scale enforcement

Runs natively on NVIDIA BlueField DPUs for hardware-accelerated enforcement, with stated support for 10M assets and 400 Gbps throughput.

One dashboard, grid-wide

Utilities serving millions of customers use the fabric for grid-wide policy enforcement and NERC CIP evidence from a single pane.

Written for the people your 10-K actually names

NextEra's annual report assigns accountability for material cybersecurity risk to the vice president and chief information officer, the vice president cybersecurity and the executive director cybersecurity, with board oversight that includes a summary of annual cyber drill results.

Sit with that last one. A board that reads drill results every year will eventually ask why recovery on the generation fleet looks different from recovery on the corporate network. The fleet was never built to be accessed the way the corporate network is. Identity-based enforcement is how those two answers converge, and how the drill summary loses its asterisk.


A first conversation

Forty-five minutes, no deck, one site.

Pick a single operating asset, ideally one that is thinly staffed and about to come into CIP scope. We will work that one all the way down.

  1. Who holds standing access to that site today, including every vendor, and what happens to it when a crew rotates off.
  2. Which assets there cannot be patched on your schedule, and what compensating control currently covers them.
  3. What the CIP evidence for that site costs to assemble by hand, per audit cycle.
  4. What identity-based enforcement would look like on that site, and where it would fall short.
  5. Whether the same policy model extends to the AI and automation you are deploying against the fleet.