Skip to main content
NH

Norsk Hydro ASA

Norsk Hydro ASA is a Norwegian aluminium and renewable energy company with 32,000 employees across 40 countries, operating the full aluminium value chain from raw material to finished products.

When your attack surface spans 140 locations across 40 countries and your core operations include aluminium smelting, hydropower generation, and industrial manufacturing, the threat model isn't theoretical - it's SCADA systems controlling molten metal, OT networks tied to energy grids, and sprawling IT infrastructure supporting 32,000 employees. Norsk Hydro ASA, founded in 1905 and headquartered in Norway, runs the full aluminium value chain from bauxite extraction through finished products, alongside renewable energy production and what remains of its historical chemical operations. The company's scale makes it a case study in converged IT/OT security: protecting industrial control systems that manage physical processes with real-world consequences.

The cybersecurity challenge here is concrete. Hydro operates smelters, power plants, and processing facilities where a compromised control system means more than data loss - it means safety incidents and production shutdowns across critical infrastructure. The company experienced this firsthand in 2019 when a ransomware attack forced multiple plants to switch to manual operations, impacting global aluminium supply. The incident became a widely cited reference point in industrial cybersecurity for how quickly IT intrusions cascade into operational disruption.

Security teams working across Hydro's domains must navigate the intersection of industrial control systems (ICS/SCADA), operational technology (OT), and traditional enterprise IT - all while supporting the company's stated commitment to responsible production and the green transition. With operations spanning Europe, South America, and Asia, the geographic distribution compounds the complexity: different regulatory regimes, varied infrastructure maturity, and supply chain interdependencies that extend well beyond the corporate perimeter. For practitioners who want their work to matter at the physical layer, this is the kind of environment where security decisions have measurable, tangible outcomes.

Open jobs

No open jobs right now.