Design. Defend. Operate.

We secure and run the networks that keep plants moving.

PLCs, RTUs, HMIs, the switches between them, and the business network they eventually touch. We design it, we build it, we watch it. And the first job is usually working out what is actually on the network, because the drawings are older than the equipment.

A plant control room: two operator chairs at a desk facing a wall of indicator panels and mimic diagrams.
How we work

Listen before touching.

Most security advice is written for IT. It assumes you can patch on a Tuesday, reboot when you feel like it, and that the worst case is a lost afternoon.

Control networks do not work like that. A controller gets a maintenance window twice a year if you are lucky. An active scan pointed at the wrong device can fault it, and faulting it is not a ticket, it is a stopped line. The engineer who commissioned the cell has long since moved on, and the only surviving documentation is a laminated drawing taped inside the panel door.

So we work the way the plant works. Passive collection while the process is live; active work on a bench, or inside a window that was already booked for something else.

What that costs us
We would rather spend a week on a mirror port than take a production risk to save ourselves a day.

The other half of the job is writing things down. Segmentation that nobody documented decays into a flat network within about two site visits, so every rule we put in gets a reason next to it.

Whoever inherits the estate should be able to tell a decision from an accident. That is the test every deliverable has to pass, and it is why the handover pack matters more than the diagram.

See how an engagement runs

Three jobs

Design it, defend it, operate it.

Clients usually arrive needing one of the three and end up wanting all of them, which suits us, because a network is much easier to defend when you drew it.

Design

Segmentation drawn before anything is racked, an industrial DMZ that means something, vendor-neutral kit specified for the place it is going, and a handover pack that outlives us.

Defend

Asset inventory first, because everything downstream depends on it being right. Then zones, conduits, and somebody actively trying to get in on a scope agreed in writing.

Services

Nine services, in one place.

Four on the design side, two on assessment, three on running it afterwards. Each one links through to what it actually involves.

Products

Two things we build ourselves.

Consulting pays the bills. These two got built anyway, because we wanted them and could not buy them in the shape we needed.

Live

CertPilot

A white-label learning and examination platform. A company runs its own panel on it: its own courses, its own candidates, its own branding on the certificate at the end. We host and maintain the platform; the content and the cohort stay yours.

In development

OT Asset Simulator

A web-based industrial protocol simulator. Virtual OT assets you operate from a browser, with no physical hardware anywhere. Modbus TCP and DNP3 work. BACnet does not yet, and we would rather say so than let you find out during an integration.

Next

Tell us what is bothering you.

An email is enough to start with. Describe the site, the problem, and the deadline if there is one. If it turns out we are the wrong people for the job we will say so, and where we can we will point you at someone better.