Eagle Creek Renewable Energy acquires, enhances, and operates small hydroelectric power facilities across the United States. The company's portfolio spans 85 facilities with a combined capacity of 690 megawatts, distributed across 18 states, collectively powering over 260,000 homes. The operational footprint represents a significant attack surface: distributed industrial control systems (ICS) managing physical infrastructure connected to regional power grids.
For cybersecurity professionals, the threat model centers on operational technology (OT) security. These facilities rely on SCADA systems and programmable logic controllers that govern turbine operations, water flow, and grid interconnection. The challenge is compounded by geographic distribution - securing 85 remote sites across 18 states means dealing with varied network topologies, legacy equipment, and inconsistent physical access controls. Rehabilitation of older hydroelectric infrastructure introduces additional risk, as legacy systems were not designed with modern security architectures in mind.
Eagle Creek's environmental mission - operating in harmony with the environment - translates to a focus on system reliability and integrity rather than data monetization. The company has been operating since 2010, with no public funding rounds suggesting a privately held, operationally focused organization. The security team would likely work across domains including ICS/SCADA hardening, network segmentation between IT and OT environments, incident response for physical infrastructure, and compliance with NERC CIP standards governing bulk electric system security.






