Is Your Utility Site Ready for a Private Network Survey? A Complete Domain-by-Domain Readiness Guide
A 20-question, six-domain diagnostic — EMI environment, power ownership, SCADA/protection relay integration, NERC CIP/IEC 61850 compliance, and HV safety access logistics — surfaces the gaps that turn a routine RF survey into a wasted site visit or a costly security rework after deployment
Utilities sites present some of the most challenging RF environments in private networking: high-voltage equipment generates significant electromagnetic interference, substations are dense metal enclosures that shape propagation unpredictably, and distributed linear assets — pipelines, transmission corridors, pump stations — require coverage across long corridors with limited backhaul. Commissioning an RF survey before that EMI picture, along with SCADA segmentation architecture and critical infrastructure compliance status, is actually resolved is one of the more expensive sequencing mistakes a utilities private network programme can make. TeckNexus has launched a Private Network Site Survey Readiness Checklist for utilities, a 20-question diagnostic across six domains that generates a utilities-specific checklist, required documents list, and field validation sequence before a formal survey is commissioned.
Site profile: SCADA segmentation and critical infrastructure compliance set the baseline
Beyond four standard context questions — site type (substation/switchyard, generation plant, renewables, distributed linear assets, or operations centre), deployment stage, in-scope use cases, and programme urgency — the checklist asks two questions specific to utilities risk. Whether the private network needs to carry SCADA, RTU or protection relay traffic, and whether IT/OT segmentation architecture has actually been defined, matters because SCADA connectivity requires strict segmentation that has to be designed around before survey — confirming this early prevents the kind of rework that’s genuinely costly once physical deployment has started, not a detail to resolve alongside it.
The second baseline question addresses critical infrastructure compliance and hazardous environment classification directly. Substations and generation facilities may fall under NERC CIP, NIS2, or IEC 62443 obligations that impose specific security and access requirements. Sites where CI regulation likely applies but hasn’t been formally assessed are flagged as a genuine gap: compliance requirements need to be assessed before security architecture is defined, since engaging with them after design begins routinely requires costly rework rather than a straightforward retrofit.
Domain A — Physical environment: where coverage failures actually originate
The physical environment domain names utilities-specific challenges directly: high-voltage equipment generating significant EMI, dense metal substation enclosures, and distributed linear assets requiring coverage across long corridors with limited backhaul all combine to make capturing the full environment picture essential before survey design. Accurate site maps or CAD drawings, validated against field reality, remain foundational for RF propagation modelling — surveys proceeding on manual field measurement alone carry materially higher design risk, particularly across a substation’s dense metal enclosure geometry.
RF propagation environment is scored from open through mixed, dense industrial, to extreme — a scale that at a utility site spans everything from an open transmission corridor to a fully enclosed switchgear building. Dynamic obstructions matter less at fixed substations than at active generation or maintenance sites, where moving vehicles and large machinery — cranes, gantries — can affect coverage during operations, and sites with both need the most conservative design margin. Known interference sources — dense existing Wi-Fi, industrial machinery generating electrical noise, TETRA or other private radio systems already in use, and adjacent radar or microwave systems — round out the domain, though at utilities sites the equipment-generated EMI question in Domain D carries at least as much weight as this general interference survey.
Domain B — Power and backhaul: the most common deployment blocker
Power and backhaul availability at planned radio locations is named as one of the most common deployment blockers. Mains power within 5 metres of all planned locations sits at the strong end of the spectrum; multiple locations with no nearby power source sits at the other, directly determining whether additional civil work is required. Backhaul follows the same logic — fibre or Ethernet within 20 metres of every planned location is the target, but for distributed linear assets and remote substations specifically, running new cable is very often the longest-lead item in the entire programme, meaning sites with significant gaps need wireless backhaul designed in from the outset rather than treated as a fallback.
Domain C — OT systems and devices: the most security-sensitive domain
OT integration in utilities environments is named as the most security-sensitive aspect of any private network deployment. SCADA/EMS/DMS platforms, protection relays and IEDs carrying IEC 61850 GOOSE/SV traffic, asset management and predictive maintenance systems, video management systems for critical infrastructure perimeter security, and safety instrumented systems for emergency shutdown each carry specific connectivity, latency and — critically — segmentation requirements that have to be confirmed before survey, since retrofitting segmentation architecture after physical deployment is one of the more expensive forms of rework in this domain.
Device inventory status matters independently of raw count: a documented inventory of device types, quantities and locations changes the design conversation materially compared to an estimated count with no formal record. And SLA requirements — latency, throughput, availability, handover — need to be defined specifically for the most demanding use case, since protection relay communication in particular carries tight, safety-relevant performance requirements that shape the entire RF and segmentation design.
Domain D — Spectrum and critical infrastructure compliance: what shapes vendor selection
Spectrum selection at utilities sites has to account for EMI interference from HV equipment, potential coexistence with legacy TETRA or private microwave systems already in operational use, and critical infrastructure regulatory requirements simultaneously — status ranges from licensed spectrum already secured through CBRS with SAS registration not yet initiated to spectrum options not yet evaluated at all. Critical infrastructure and cybersecurity standards — NERC CIP in North America, IEC 62443 for OT cybersecurity, NIS2 for the EU energy sector, IEC 61850 for substation communication and protection specifically, ISO 27001, and national sector-specific energy regulation — directly determine security architecture requirements before vendor engagement, and need to be confirmed before RF design is finalised.
Domain E — Survey logistics: HV safety and critical infrastructure vetting
Utilities site access involves safety requirements most industrial sites don’t carry: HV safety inductions, permit-to-work systems specifically for live electrical environments, and in some jurisdictions formal critical infrastructure access vetting for survey personnel. The checklist treats every one of these as needing confirmation before the survey team travels to site, since a technically well-prepared substation still produces a wasted, potentially unsafe visit if HV permit-to-work requirements or critical infrastructure vetting weren’t arranged in advance.
From readiness diagnosis to field-ready checklist
The output translates all six domains into what a deployment partner needs before mobilising: a utilities-specific site survey checklist, required documents list, and field validation sequence — sequenced so that SCADA segmentation architecture, critical infrastructure compliance, EMI environment, and HV safety access are resolved before the RF survey team is commissioned, given how directly each reshapes network design and security architecture after the fact.
Utility OT/IT teams, grid operators and technology leads planning a private network deployment can take the free, vendor-neutral readiness checklist directly and receive a complete readiness report across all six domains.
Related Tool: Security Assessment for Utilities (with Palo Alto Networks)
Once site readiness is confirmed, assess the security posture of the SCADA/OT segmentation architecture this checklist surfaces — calibrated to NERC CIP, NIS2 and IEC 62443 requirements.





