NEWS AND EVENTS

Bremanger Breach: Lessons from a Norwegian Dam Hack

Back to News & Events

Earlier this year, unidentified hackers breached the control system of a Norwegian dam  at Risevatnet, in Bremanger. The hackers discovered that the dam had a Human Machine Interface (HMI) exposed on the Internet and was able to gain access by exploiting a weak password.  

The hackers managed to fully open the gate valve of the dam, and upholding the unauthorized access for about four hours. This resulted in an estimated outflow of 7.2 million liters of water before operators detected the unauthorized activity and restored control.  

Initially the incident was mistaken for a technical malfunction, but through the investigation done by The Police Security Service and The National Criminal Investigation Service, it was discovered the hackers had uploaded a three-minute video to Telegram, showing a screen recording of the control panel connected to the dam.  The video contains a static watermark, naming a pro-Russian cybercriminal group.

The Aftermath – National security authorities’ measures for preparedness:

After observing this targeted, unwanted activity towards digital infrastructure in Norway, the Norwegian National Security Authority (NSM) issued a public warning.  The warning  was directed towards related critical sectors, and named water supply, dams and other infrastructure.  

The incident exposed serious vulnerabilities in critical infrastructure security, particularly regarding outdated control systems connected to the internet without adequate authentication safeguards. It served as a wake-up call for strengthening cybersecurity defenses in industrial control environments and underscored the growing geopolitical risks tied to cyberattacks on essential infrastructure.

How Secure-NOK answers to the security reccomendations

The incident has sharpened Norway’s focus on preparedness and cybersecurity measures and the security authorities have given more thorough official warnings and security recommendations than before. In response, NSM has urged Norwegian organizations to strengthen their defenses by implementing a set of key measures. As an experienced partner for industrial cybersecurity, it’s essential that our solutions assist in answering these measures:

  • Establish thorough logging within digital infrastructure related to industrial control systems and operational technology (OT). NSM is clear on recommending that all digital activity is to be logged, especially focusing on systems connected to industrial control systems and OT. SNOK™, Secure-NOKs proprietary platform for OT-cybersecurity monitoring, provides full activity log in the OT-environment, combined with real-time alerts. This allows easier discovering and ability to handle anomalies quickly, serving as an important tool to reduce risk and strengthen the security readiness.
  • Components of OT or industrial control systems should not have direct remote access via the internet. OT and IT networks should be properly segmented.
    Our solutions provide full overview of which components that are connected to internet, allowing easier identification to remove unwanted external access.
  • Develop and regularly practice incident response plans to reduce negative consequences.
    NSM enhances the importance of preparedness, and rehearsing these plans regularly. The SNOK platform gives you full overview of your OT-systems: logging of all activity in your OT-environment and real-time alerts of suspicious activity. This gives a solid fundament for realistic planning and rehearsing. When employees know how to respond in a critical situation, the damage decreases significantly.  
  • Digital interfaces exposed to the internet should have updated software, firmware, and hardware. Disable unnecessary functionalities. Use geo-blocking where possible.
    Our solutions provide continuous overview of which components that are exposed to internet, which needs to be prioritized for updates or shielding.

The Norwegian National Security Authority (NSM) is Norway’s primary government agency responsible for national protective security and cybersecurity. “

NSMs mission is to strengthen Norway’s ability to counter espionage, sabotage, terrorism and hybrid threats. The agency helps organizations protect civilian and military information, systems, objects and infrastructure that are relevant to national security by giving advice and performing control activities, supervision, security testing and security research

NSM is administratively subordinate to the Ministry of Justice and Public Security. In addition, the Ministry of Defence has authority of NSM with respect to their area of responsibility.

SNOK by Secure-NOK contributes to more robust, secure and stable operations

Secure-NOK provides a modular cybersecurity platform specifically designed for operational technology (OT) environments, offering solutions such as SNOK® Network Intrusion Detection System (NIDS), endpoint monitoring, PLC threat detection, and asset scanning.  

SNOK® can be distributed throughout OT networks for superior visibility and early detection of cyber threats, including non-malware attacks, without disturbing industrial processes. The platform features anomaly-based detection.  

Secure-NOKs Security Center offers specialist services in OT-security

In addition to technology solutions, Secure-NOK offers professional services through its Security Center, including continuous data analysis, consulting, vulnerability assessments, health checks, and tailored OT security training.  

The platform integrates with existing Security Operations Centers (SOC) and is compatible with common incident management systems via REST API. Secure-NOK’s solutions are built to fit industrial needs, highlighting the importance of logging, segmenting OT/IT networks, updating interfaces, and practicing incident response plans for improved cyber resilience.

Nina Hesby Tvedt
Chief Technology Officer
13.02.2026
Follow us on LinkedIn
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Insights from Norway’s cybersecurity experts

April 21, 2026

Sterk oppslutning rundt OT-konferansen 2026 – samler ledende fagmiljøer i Stavanger

OT-konferansen 2026 går av stabelen 29. april i Stavanger, og årets utgave peker seg allerede ut med et program som samler noen av de mest sentrale aktørene innen OT-sikkerhet og industriell digitalisering.

Read more
April 20, 2026

DigiForum: Fra muligheter til kontroll I kommunal sektor

Refleksjoner fra en av de viktigste arenaene for digital sikkerhet i kommunal sektor – og hva vi må tørre å ta inn over oss.

Read more
April 21, 2026

Økt behov for kontroll i komplekse automasjonsmiljøer i olje og gass

Digitaliseringen av olje- og gassindustrien har de siste årene gitt betydelige gevinster i form av effektivisering, bedre datagrunnlag og økt fleksibilitet. Samtidig har utviklingen ført til en betydelig økning i kompleksitet – og dermed også i risiko.

Read more
April 21, 2026

Hvordan få kontroll på OT-miljøet i praksis – erfaringer fra IVAR

For IVAR IKS er stabil drift ikke bare et mål – det er en forutsetning for at samfunnet skal fungere. Som leverandør av vann- og avløpstjenester til rundt 360 000 innbyggere på Nord-Jæren, forvalter virksomheten kritisk infrastruktur der konsekvensene av svikt er umiddelbare og omfattende.

Read more
April 21, 2026

Beredskapsåret 2026: Er vann og avløp i norske kommuner godt nok sikret?

Kommunal vannforsyning er blant samfunnsfunksjonene som omfattes av digitalsikkerhetsloven. Loven trådte i kraft 1. oktober 2025 og stiller grunnleggende krav til digital sikkerhet i virksomheter med særlig betydning for samfunnet. Regelverket innebærer også at ansvaret for digital sikkerhet er tydelig plassert hos virksomhetens øverste ledelse.

Read more
April 21, 2026

See More. Fear Less. – Securenok Reveals Its New Brand Identity

For the past five months, we’ve been deeply engaged in redefining the visual identity and communication strategy of Securenok.

Read more
March 1, 2026

Industrial Security Conference 2025

This year’s conference highlighted that many organizations have made significant progress in terms of plans, policies, and documentation, yet there remains a gap between what is planned and what is actually implemented in OT environments.

Read more
February 13, 2026

How Does Secure-NOK Help Food Manufacturers Manage Cyber Risk?

Download our white paper “Cybersecurity in the Food Industry” for free and gain practical guidanceon how to secure continuity and regulatory compliance in your production environment.

Read more
February 13, 2026

Stricter Security Requirements for Critical Services from 1 October 2025 under theDigital Security Act

O nFriday, 20 June, the Norwegian government decided in a Council of State meeting that the Digital Security Act will enter into force on 1 October 2025. At the same time, the Digital Security Regulation was adopted, entering into force concurrently with the Act.

Read more
February 13, 2026

What does NIS2 require from owners of OT systems to become compliant?

The NIS 2 Directive is the European Union’s updated and strengthened framework for managing cybersecurity risks across critical and important service providers.

Read more
February 13, 2026

Digitalization: Opportunities and New Risks

Digitalization offers enormous opportunities for efficiency, but it also introduces new risks. When OT systems (Operational Technology) are connected to the internet, vulnerability to attacks increases—attacks that threaten not only data, but also lives, health, and critical societal functions.

Read more