Services

Nine services, three jobs.

Design it, defend it, operate it. Clients usually arrive needing one of the three and end up wanting all of them, which suits us, because a network is much easier to defend when you drew it.

Design

Design, deliver, document. In that order.

The engineering half. Drawings before racking, and a handover pack that outlives us.

  • Segmentation
  • Industrial DMZ
  • Vendor-neutral
A numbered patch panel with blue and grey patch leads run between ports.

Network design

Switching, routing, firewalls, and wireless where it cannot be avoided. The segmentation gets drawn before anyone racks anything, and each rule ships with a note saying what it is for. Resilience is designed against the failure you can actually afford, not against a diagram that looks symmetrical.

System integration

Making equipment from different vendors agree with each other. SCADA, historians, building management, access control, the hand-off into ERP. Most of it is protocol translation and stubborn testing rather than anything clever, and the value is in the testing.

Custom software development

Small, sharp tools for the gap between two products that were never meant to talk. Protocol bridges, data extraction, dashboards, internal web apps. We write it so your team can read it, and you get the source.

Hardware supply

Switches, firewalls, industrial gateways, servers and panel gear, specified for the place it is going. Temperature range, vibration, DIN rail, fanless where dust is a problem. Quotes show the support renewal up front instead of hiding it in year three.

Defend

Find out what is really there, then prove where it breaks.

Assessment work, from a first asset inventory through to somebody actively trying to get in.

  • Passive first
  • Purdue levels 0–3.5
  • Zones and conduits
An open control cabinet: PLC modules and network switches on DIN rail above rows of numbered terminal blocks.

OT and ICS cyber security

Asset inventory first, because everything downstream depends on it being right. We map the estate against the Purdue levels you actually have rather than the textbook picture, work out where the zones and conduits ought to sit, and cost what enforcing them would really take. Collection is passive wherever the process is live. IEC 62443 gives us the vocabulary for zones, conduits and security levels, and we use it as a design language, not as a certificate to sell you.

Penetration testing

External perimeter, internal network, web and API, and the identity stack that quietly connects them. On the OT side the scope gets agreed in writing and we test carefully: the industrial DMZ, jump hosts, engineering workstations, and the remote-access path a vendor opens on a Friday afternoon and forgets. Anything that touches live control gear either waits for a window or gets tested on a bench.

Operate

Somebody watching, around the clock.

Security and availability from the same desk, because at 3am nobody cares which one it was.

  • 24×7
  • Alert on change
  • A human who calls
A plant control room lined with switchboard panels, indicator lamps and selector switches.

SOC 24×7

Monitoring, triage, and a person who picks up the phone. Detections are tuned for the estate we are actually watching, which on the OT side usually means alerting on change: a device that was not there yesterday, a conversation that has never happened before, a controller dropped into program mode. Signatures written for a Windows fleet do not help much that far down.

24×7 monitoring and NOC

Availability, not only security. Link state, latency, interface errors, disk, UPS runtime, and whether last night's backup actually completed instead of merely starting. This is the unglamorous half of the service. It is also the half that gets called first.

Network administration

The day-to-day: changes, firmware, certificates before they expire, access reviews, and the configuration backups everyone assumes are running. We do this as overflow for a team that is stretched, or as the whole function for a site that does not have one.

Next

Not sure which of the three you need?

Most sites need a bit of all three and cannot say in what order. Describe the estate and the thing that is worrying you, and we will tell you what we would do first.