Securing criticalinfrastructure.
Astra is a pure-play ICS/OT cyber security consultancy. We work directly with the control systems that keep power, water, ports, rail, mines and plants running, from Perth and Hyderabad.
One focus.
Protecting industrial control systems and operational technology is all we do. Not an IT security team with an OT practice on the side: consultants, engineers and service partners who work hands-on with the systems themselves.
Two bases, one team.
Perth, Western Australia and Hyderabad, India. A global view of the threats to critical infrastructure, and consultants who understand each sector's operations, regulators and standards.
The problems Astra solves
Operational resilience
Strategies and measures that make critical infrastructure systems harder to disrupt, so operations keep running and downtime stays short.
Regulatory complexity
Guidance and tailored solutions for the regulatory requirements that apply to each sector, in each country, so compliance is designed in rather than bolted on.
Incident response
Incident response planning, training and tabletop exercises, so the team is prepared and responds quickly when something happens in an ICS environment.
Hidden ICS risk
ICS cyber risks are often misreported, which misplaces focus and effort. We work through the priorities, the operating environment and the technology, then act on what is actually there.
How typical attacks happen.
Most reported intrusions into an industrial facility follow a similar pattern: in from outside, across the office, through the boundary, into the control room, down to the controllers. Every one of our services sits on that route. Watch the path run, or pick a level to read what happens there.
Outside
Internet, vendors, suppliers
What arrives here
Exposed remote access, a leaked password, a supplier's laptop. Most intrusions begin with something already reachable from the internet.
Where we stop it
Penetration testing finds the exposed path before an attacker does. Credential exposure monitoring catches the leaked login before it is used.
Programme management holds the whole route together: one plan, one owner, one report to the board.
Industries
Every sector runs different processes, protocols and regulators. We bring industry-specific knowledge to each, and engineer solutions in line with IEC 62443, NIST SP 800-82, NIS2 and the sector's own frameworks.
Assess, design, operate, respond.
We combine years of experience in industrial environments with a hands-on approach: consultants, engineers and service partners who work directly with control systems to find and close the gaps. Assessment, design, implementation, training and managed services.
Assess
Know what you have, what threatens it and what matters most.
Design
Architecture and networks built for the sector's requirements.
Operate
Monitoring, programme management and exposure watch, day to day.
Respond and Recover
Ready before the incident, resilient through it.
What makes Astra different
Laser-focused on critical infrastructure
A pure-play ICS/OT security company. We work across sectors and bring industry-specific knowledge to meet country-specific criteria, aligned with IEC 62443, NIST SP 800-82 and NIS2.
No red tape
Operational resilience does not exist in isolation. We partner with clients to understand their specific needs and goals, then co-develop the solutions that meet them.
Depth of experience
Industrial automation, cyber security, network design and management consulting, gained globally, and kept current as the industry's demands change.
Industry partnerships
Access to specialist resources in ICS/OT operations, architecture, control systems and instrumentation engineering, so recommendations are grounded in how plants actually run.
The full lifecycle
Risk and vulnerability assessment, ICS security engineering, managed services, incident response and recovery. Clients are covered at every stage, not handed off between vendors.
Written for the people who run the plant
Plain-language guides to the standards, the regulations and the work: what they ask, what an assessor looks for, and where to start.
7 minute readThe SOCI Act and CIRMP: what they ask of your operational technologyAustralia's critical infrastructure law, read from the control room.Read the guide
8 minute readIEC 62443 explained for asset ownersZones, conduits and security levels, and what an assessment against the series actually produces.Read the guide
6 minute readYou cannot secure what you cannot see: building an OT asset inventoryWhy the inventory comes first, how to build one without touching the process, and what it has to hold.Read the guide

ASTRICS, our operational intelligence platform
Astra builds ASTRICS: an operational intelligence platform for industrial cyber security. One shared operational understanding of a site, read by every capability in the platform.
Credentials
Our team holds the certifications that matter for ICS security work, and the general security and network credentials that underpin it.
GIAC Global Industrial Cyber Security Professional
ISA/IEC 62443 Cybersecurity Risk Assessment Specialist
GIAC Certified Incident Handler
GIAC Advisory Board
Certified Information Systems Security Professional
Certified Information Systems Auditor
SABSA Chartered Security Architect
Cisco Certified Network Associate
Find out how we can help you be secure and operationally resilient.
Tell us about the site, the systems and what you are trying to achieve. A consultant will reply.










