The core issue around powergrids is that the PLCs in use have little to no security (many cases too old to have an real security).
Further in SCADA Safety takes precedence over security. If you need to hit the SCRAM button on a nuclear reactor, you can't have a cumbersome authentication procedure.
So NIST has a set of guidlines for security which generally boil down to physical security and DMZs. Anything that needs remote connection has to have its rx pins cut (for older devices).
It's not as bad as advertised, but security is defensibly taking a back seat.
If you're really curious, give NIST.SP.800-82r2 a read.