Nine sectors.One discipline.

Every sector runs different processes, protocols and regulators. We bring industry-specific knowledge to each, and engineer solutions in line with IEC 62443, NIST SP 800-82, NIS2 and the sector's own frameworks.

High-voltage transmission lines and wind turbines at dusk

Energy and renewables

Our ICS/OT services follow the Australian Energy Sector Cyber Security Framework (AESCSF), the US Department of Energy's C2M2 and India's Central Electricity Authority (CEA) requirements. We secure the infrastructure from generation through transmission to distribution, including the smart grid.

What we most often find

  • Corporate and control networks joined by the domain, the historian or a shared engineering laptop
  • Standing vendor remote access into plant controllers and substations
  • Fleets of generation sites with no single asset register
  • Incident plans that never mention the plant or the reporting clock
Frameworks we work to
AESCSF · DOE C2M2 · CEA (India)
Systems in scope
Generation · Transmission · Distribution · Smart grid
The regulatory picture
In Australia, electricity, gas and liquid fuel are SOCI sectors: asset register, 12 and 72 hour incident reporting, and a CIRMP with a recognised framework, usually AESCSF SP-1 or above. In India, the CEA power sector regulations bind generation at 50 MW or more and all transmission and distribution from 1 April 2027, with six-hour incident reporting under CERT-In.

Read more: The SOCI Act and CIRMP: what they ask of your operational technology · IEC 62443 explained for asset owners

Open-pit mine haul road under evening light

Mining

From pit operations to port logistics, mining faces its own cyber security challenges. Our ICS/OT services are tuned to that journey: every process from ore extraction to shipment by road, rail and port gets robust digital defences and better resilience.

What we most often find

  • Pit-to-port estates spread over hundreds of kilometres, with satellite and radio links nobody monitors
  • Autonomous haulage, fleet management and processing plant control on the same flat network
  • Contractor-run sites where the mine does not hold the credentials to its own systems
  • Rail and port loading systems shared with third parties
Frameworks we work to
IEC 62443 · NIST SP 800-82
Systems in scope
Pit and plant control · Processing · Rail and road logistics · Port loading
The regulatory picture
Mining is not a SOCI sector, though a mine's rail, port and power assets can be. Customers, insurers and safety regulators increasingly expect the same discipline, and IEC 62443 and NIST SP 800-82 are the references.

Read more: You cannot secure what you cannot see: building an OT asset inventory · How a threat assessment uses MITRE ATT&CK for ICS

Offshore platform lit at night

Oil and gas

From exploration to refining and distribution by pipeline and ship, oil and gas operations demand a resilient cyber security posture. Our ICS/OT services address API 1164, Saudi Arabia's NCA OTCC, Qatar's ICS Security Standard and NIST SP 800-82.

What we most often find

  • Pipeline SCADA reachable from the corporate network through the historian or a support VPN
  • Offshore and remote sites supported entirely by vendors from onshore
  • Safety instrumented systems sharing infrastructure with basic process control
  • Legacy operating systems on operator stations that cannot be patched
Frameworks we work to
API 1164 · NCA OTCC · Qatar ICS Security Standard · NIST SP 800-82
Systems in scope
Exploration and production · Refining · Pipelines · Shipping
The regulatory picture
Gas processing, pipelines and liquid fuel are within Australia's SOCI energy sector. API 1164 is the reference for pipeline control-system security and IEC 61511 requires a security assessment of the safety system. In India, refineries and pipelines fall within NCIIPC's scope and captive power at 50 MW or more is under the CEA regulations.

Read more: The SOCI Act and CIRMP: what they ask of your operational technology · IEC 62443 explained for asset owners

Container cranes over a terminal at night

Marine ports

Maritime shipping and ports anchor global trade and supply chains. With expertise in threat modelling, ICS risk assessment and implementing the IMO guidelines, we secure the systems that matter: positioning, navigation and timing (AIS, ARPA), cargo handling, vessel traffic, automated cargo movement and communication networks.

What we most often find

  • Terminal operating systems and crane automation reachable from the same network as the office
  • Stevedores, shipping lines and agents with accounts nobody has reviewed
  • Vessel traffic and navigation systems dependent on GNSS with no fallback tested
  • No plan for a cyber incident that stops the terminal
Frameworks we work to
IMO guidelines · IEC 62443
Systems in scope
PNT: AIS and ARPA · Cargo handling · Vessel traffic services · Automated cargo movement
The regulatory picture
Ports are within Australia's SOCI transport sector. Ships carry cyber risk in their safety management systems under IMO MSC.428(98), and the port's interfaces with them inherit it. India's port authorities operate under the Indian Ports Act and NCIIPC's transport sector scope.

Read more: The SOCI Act and CIRMP: what they ask of your operational technology

Rail signals and track at a junction at dusk

Rail

Rail is the arteries and veins of a nation's transport and logistics, and needs expert advice across an intricate network. Our ICS/OT services follow RISSB AS 7770 and CENELEC EN 50159 to protect train control systems, switching and signalling, onboard systems, rolling stock and station controls.

What we most often find

  • Signalling and interlocking networks that have grown links to the corporate estate over decades
  • Rolling stock with cellular connectivity and vendor diagnostics nobody has assessed
  • Station and passenger systems sharing infrastructure with train control
  • Safety assurance and cyber security argued by different teams
Frameworks we work to
RISSB AS 7770 · CENELEC EN 50159
Systems in scope
Train control · Switching and signalling · Onboard and rolling stock · Station controls
The regulatory picture
Rail is within Australia's SOCI transport sector. AS 7770 is the Australian rail cyber security standard and EN 50159 governs safety-related communication. Indian Railways applies its own ICT security policy and RDSO guidance.

Read more: The SOCI Act and CIRMP: what they ask of your operational technology · Incident response for OT: why the IT playbook fails on the plant floor

Water treatment clarifiers at first light

Water

Water underpins everyday life. Our ICS/OT services focus on the complex infrastructure and processes of the sector, from monitoring systems to distribution networks and wastewater treatment, with security tailored to each utility.

What we most often find

  • Dozens of small sites on radio and cellular telemetry with default credentials
  • Chemical dosing and treatment control reachable through a single remote access path
  • Contractors and councils sharing SCADA access
  • Backups of controller logic that have never been restored
Frameworks we work to
IEC 62443 · NIST SP 800-82
Systems in scope
Treatment · Distribution · Monitoring and telemetry · Wastewater
The regulatory picture
Water and sewerage is a SOCI sector in Australia: register, incident reporting and a CIRMP for the asset classes named in the rules, alongside state health and economic regulators. In India there is no sector rule; obligations come from the IT Act and CERT-In Directions and from the contracts schemes are built under.

Read more: The SOCI Act and CIRMP: what they ask of your operational technology · IEC 62443 explained for asset owners

Airport apron and control tower at night

Transportation

Air and public transport connect a globalised world, from long-haul journeys to the daily commute. Our ICS/OT services are engineered for that complexity, safeguarding every touchpoint: flight communication and air traffic management, metro and light rail, smart freeways and urban transit payment gateways.

What we most often find

  • Airport and transit operational systems procured piecemeal from many vendors, with many remote paths
  • Intelligent transport systems on public networks
  • Payment and passenger systems connected to operational ones
  • No single view of what is critical across the network
Frameworks we work to
IEC 62443 · Sector regulators
Systems in scope
Air traffic management · Metro and light rail · Smart freeways · Transit payments
The regulatory picture
Aviation and public transport assets are within Australia's SOCI transport sector, with sector regulators adding their own requirements. In India, transport is within NCIIPC's scope and airports sit with BCAS and the Airports Authority of India.
Robotic arms on an automated production line

Manufacturing

Where precision and efficiency meet, the infrastructure behind production lines, machinery controls and supply-chain logistics has to be secure. Our ICS/OT services are built for this industry, from robotic automation systems to inventory management networks.

What we most often find

  • Production halted by ransomware that never touched a controller, because the MES and the file shares did
  • Robot and machine vendors with permanent remote access
  • Industrial IoT and quality systems added to the plant network without assessment
  • No inventory of the software running on the line
Frameworks we work to
IEC 62443 · NIST SP 800-82
Systems in scope
Production lines · Machinery control · Robotic automation · Inventory networks
The regulatory picture
Most manufacturing is outside SOCI unless the facility is a food and grocery or other named asset. IEC 62443 is the reference customers and insurers ask for. In India the CERT-In Directions apply, and captive power at 50 MW or more is under the CEA regulations.

Read more: IEC 62443 explained for asset owners · You cannot secure what you cannot see: building an OT asset inventory

Chemical plant pipework and columns at night

Chemical

For clients in the chemical sector we prioritise safeguarding proprietary processes and continuous operation, and build a comprehensive defence against cyber threats that could jeopardise production integrity, product quality or workplace safety.

What we most often find

  • Safety instrumented systems not separated from basic process control
  • Batch and recipe management reachable from the business network
  • Vendor support access into the DCS with no session control
  • Cyber security absent from process hazard analysis
Frameworks we work to
IEC 62443 · Process safety standards
Systems in scope
Process control · Safety instrumented systems · Batch and recipe management · Utilities
The regulatory picture
Major hazard facilities carry process safety obligations under state work health and safety law, and IEC 61511 requires a security risk assessment of the safety instrumented system. IEC 62443 is the reference for the rest of the plant.

Read more: IEC 62443 explained for asset owners · The Purdue model and OT network segmentation, without the religion

Working in a sector we have not named? Ask.

The discipline is the same: understand the process, the systems and the regulator, then secure them in that order.