A UPS used to be a box in the corner that nobody thought about until the power went out. A modern one is a device on your network, with an IP address, that can monitor your power, send alerts and shut your servers down safely. That connectivity is genuinely useful, but it also means the UPS is now part of your attack surface, and a poorly secured management card is a way into the network rather than just a way to watch the power. For a larger or regulated business, it is also a compliance question, because the EU’s NIS2 and DORA rules now expect you to manage the risk of exactly this kind of networked device. This guide explains the attacks that target a UPS, how Eaton’s Network-M3 card is built to stop them, and where it fits into the rules.
No device is unbreakable, and the honest claim is reduction of risk rather than a guarantee. The point is that an unmanaged card leaves every one of these doors open, while a hardened, certified one closes them and tells you when something is trying them.
Why is a UPS a cybersecurity concern?
A networked UPS is a concern because it is an internet-protocol device sitting inside your network that can take action on your equipment, and anything with those two properties has to be secured like any other endpoint. The card that lets you monitor the UPS and trigger a graceful shutdown is, from an attacker’s point of view, a small computer with the ability to power systems down. If it runs old firmware, ships with default credentials, or speaks only unencrypted protocols, it becomes an unmonitored foothold: a place to get onto the network, or a switch that someone else could use to drop your load. Power and building systems are a well-known weak point precisely because they are often installed once and then ignored by the security team. This is not theoretical. Researchers have found serious flaws in widely-used UPS management cards, including remote-takeover bugs and an unsigned-firmware weakness that let an attacker install malicious firmware and stay resident on the device. The fix is not to take the UPS off the network and lose the benefit, but to put a card in it that was designed to be secure.What attacks target a UPS, and how does the M3 stop them?
The attacks on a UPS are the same classes of attack that hit any connected device, and the Network-M3 is built to close each one. The table below maps the common vectors to the control that addresses them.| Attack vector | How the Network-M3 reduces it |
|---|---|
| Default or shared passwords left in place, the most common way in | Enforced credential setup and role-based access control, with a configurable firewall that limits which systems can reach the card at all. |
| Tampered or unsigned firmware installed for persistence | A secure boot process authenticates the firmware before it will run, so altered or unauthorised firmware is rejected rather than executed. |
| Remote exploitation of a network-reachable card | Hardened and independently tested to UL 2900-1, with encrypted protocols and a zero-trust posture that treats every connection as untrusted by default. |
| The card used as a foothold to move across the network | The firewall and zero-trust design limit lateral movement, and intrusion detection and logging surface unusual activity. |
| Malicious or unauthorised shutdown of your load, a sabotage tactic with real precedent | Access controls restrict who can issue shutdown or load-segment commands, and every power event and action is logged and can be alerted. |
| Old, unpatched firmware accumulating known weaknesses | A secure, supported update process and ongoing firmware updates keep known vulnerabilities closed rather than open for years. |
What makes the Eaton Network-M3 different?
The Eaton Network-M3 is, along with Eaton’s Industrial Gateway card, the first UPS connectivity device certified to both UL 2900-1 and IEC 62443-4-2, the recognised standards for the cybersecurity of network-connected products. UL 2900-1 is a software cybersecurity standard for network-connectable devices, covering how the device is built, tested and hardened against known weaknesses. IEC 62443-4-2 is the industrial standard for the security of components in an automation and control system, the framework regulated and industrial sites are increasingly expected to follow. Holding both means the card has been independently assessed against published security requirements rather than simply described as secure in a brochure, which is the distinction that matters when you have to justify a choice to an auditor.Related UPS guides
- Are Eaton UPS worth the price? The total cost of ownership case.
- UPS and power protection hub: the full Eaton range by use case.
What can the Network-M3 actually do?
Once it is on the network and locked down, the card is both a security control and a full management tool. On the security side it provides a secure boot process that authenticates firmware, a zero-trust approach that treats connections as untrusted and detects intrusion attempts, a user-configurable firewall, encrypted communication, certificate handling and role-based user access rather than shared logins, with logging that can be sent to your own systems. On the management side it reports the site’s electrical data, the UPS self-test results, alert logs and logged power events such as blackouts, brownouts and over-voltage, and it sends alerts by email or to monitoring software so problems are seen before an outage rather than after. It triggers automated, graceful shutdown of servers and virtual machines when an outage runs long, sheds non-essential load to protect runtime, and reboots equipment on specific outlet groups. It integrates with Eaton’s power management software and with virtualisation platforms such as VMware, Hyper-V, Nutanix and Citrix, so the shutdown and restart of a virtual environment can be orchestrated cleanly, and it supports an environmental monitoring probe for temperature, humidity and door or contact sensors. The security and the usefulness are the same story: you can safely give the UPS this much control precisely because the card is built to resist being misused.How does the M3 help with NIS2 and DORA?
For a larger or regulated organisation, an audited UPS card is not just good practice, it helps you meet obligations that now apply by law. The NIS2 Directive, which EU member states including Malta have transposed, requires medium-sized and large entities across energy, healthcare, finance, digital infrastructure, manufacturing, public administration and other critical sectors to put cybersecurity risk-management measures in place and to manage the security of their supply chain and the components on their networks. DORA, the Digital Operational Resilience Act, applies the same kind of discipline specifically to financial entities and their technology providers, and it applies directly across the EU. Neither rule names a UPS card, but both expect you to know what is on your network, to control access to it, to keep it patched, to log and report on it, and to account for the third-party components in your estate. An unmanaged, uncertified management card is a visible gap against every one of those expectations. The Network-M3, certified to UL 2900-1 and IEC 62443-4-2, with enforced access control, firmware integrity, logging and a supported update path, is straightforward evidence of due diligence on a device that would otherwise be a hard question in an audit. For Malta’s financial services and iGaming operators, where availability and security are already licensing matters, that is one less unexplained device and one more control you can point to.Which Eaton UPS take the Network-M3?
The Network-M3 fits the connectivity slot on Eaton’s current managed UPS range, so you can standardise on one secure card across the estate. That includes the line-interactive 5P Gen2 and 5PX Gen2, the online 9SX, 9SX Gen2 and 9PX, and the three-phase 93PS and 93T, with the card included as standard on the Gen2 units. Standardising on the same card means one firmware to keep current, one firewall policy to apply and one set of credentials to manage, which is easier to keep secure, and easier to evidence, than a mix of cards from different generations. The card itself has its own product page with the full specification.How Sirap helps
We supply, install and configure the Network-M3 so the security features are actually switched on rather than left at default, which is where most of the real-world risk sits. We set the firewall and access controls, get the card onto your monitoring, connect it to graceful shutdown for your servers or virtual environment, keep the firmware current as part of ongoing support, and help you document the control for your own risk-management and audit needs, all from a team based here in Malta. For the wider range and how the UPS models fit together, see our UPS and power protection hub.Secure your UPS with Sirap
If you are putting a UPS on your network, or you have management cards already in place that nobody has reviewed, talk to us about the Network-M3 and a secure setup. Get in touch and we will work out the right card, the right configuration and the right monitoring for your site.Featured Products in this article
HOW WE DO
Kurt Paris
With an MSc in Software Engineering, and over 15 years in IT Management, Kurt Paris leads technology strategy at Sirap. Zebra Technologies, Domino and Cisco-certified, he helps Maltese businesses build resilient storage & backup infrastructure, Machine Vision & AutoID Automation


