
Energy and renewables
Our ICS/OT services follow the Australian Energy Sector Cyber Security Framework (AESCSF), the US Department of Energy's C2M2 and India's Central Electricity Authority (CEA) requirements. We secure the infrastructure from generation through transmission to distribution, including the smart grid.
- Threat Assessment
- Asset Discovery and Management
- Security Risk Assessment
- ICS/OT Penetration Testing
- Network Assessment and Design
- Security Architecture
- Security Monitoring
- Cyber Security Programme Management
- Credential Exposure Monitoring
- Incident Response Readiness
- Operational Resilience
What we most often find
- Corporate and control networks joined by the domain, the historian or a shared engineering laptop
- Standing vendor remote access into plant controllers and substations
- Fleets of generation sites with no single asset register
- Incident plans that never mention the plant or the reporting clock
- Frameworks we work to
- AESCSF · DOE C2M2 · CEA (India)
- Systems in scope
- Generation · Transmission · Distribution · Smart grid
- The regulatory picture
- In Australia, electricity, gas and liquid fuel are SOCI sectors: asset register, 12 and 72 hour incident reporting, and a CIRMP with a recognised framework, usually AESCSF SP-1 or above. In India, the CEA power sector regulations bind generation at 50 MW or more and all transmission and distribution from 1 April 2027, with six-hour incident reporting under CERT-In.
Read more: The SOCI Act and CIRMP: what they ask of your operational technology · IEC 62443 explained for asset owners









