Capabilities
What an engagement actually involves.
Every item below describes work with a defined input, a defined output and a defined boundary. Where a piece of work depends on something only you can provide — access, documentation, a maintenance window — that is stated rather than discovered later.
Cyber-physical risk assessment
The foundation engagement. We build one model of the system that holds both the electrical and the digital view, then trace which reachable interfaces can influence which physical behaviours. The output is a ranked set of paths, each with the consequence it leads to and the controls currently standing in the way.
BESS and BMS security review
Battery-specific work: how charge and discharge commands are authenticated and bounded, whether protection logic is genuinely independent of the controller that could be compromised, how state of charge and temperature reporting could be falsified, and what the service and debug interfaces expose. Firmware update and signing mechanisms are in scope because they are a standing remote-write path into the device.
OT network and segmentation review
Site architecture assessed against zone-and-conduit concepts from IEC 62443, which is the reference model most asset owners and auditors will recognise. We look at what the segmentation actually enforces rather than what the drawing says, including what happens to it during commissioning and maintenance, when temporary paths tend to become permanent.
Remote access and cloud control review
Usually the shortest route from the public internet to a setpoint. We follow the whole path: how a vendor engineer authenticates, what brokers the session, what they can reach once inside, whether the access is time-bounded, and whether anyone would notice an unusual session. Fleet-management platforms and their APIs are assessed as part of the control system, because that is what they are.
Architecture and design review
Assessment during design or construction, before anything is energised. The cheapest point to change a trust boundary is while it is still a line on a drawing. Deliverable is a set of design-stage findings and requirements that can go straight into the integrator scope.
Threat modelling
Structured modelling against your topology, your vendors and your operating model. Includes the paths people prefer not to model: the contractor with standing access, the shared engineering credential, the commissioning laptop that visits every site.
Security testing and validation
Targeted testing of the paths that matter most, with scope, method and blast radius agreed in writing first. On live plant we default to the conservative option and will say plainly when a test cannot be run safely rather than running a weaker version of it and calling the path clear.
Monitoring and detection design
What to collect from control systems, where to collect it, and what an abnormal control action looks like against a baseline of normal operation. The aim is that an unexpected setpoint change is visible as an event, not reconstructed afterwards from historian data.
Incident readiness for cyber-physical events
Response planning for events that are simultaneously a security incident and an electrical one, where the security team and the operations team have different instincts and both are partly right. Covers decision authority, safe-state procedures and what evidence to preserve without prolonging an unsafe condition.
Supplier requirements and procurement support
Security requirements written into BESS, BMS and integrator contracts in language a supplier can actually be held to, plus technical review of what they answer. Most security questionnaires are answered truthfully and tell the buyer very little; the value is in asking the questions where the answer is checkable.
Scope honesty
What we do not do.
We are not a managed security service and do not monitor your systems around the clock. We do not resell hardware or software, which means there is no product we are steering you toward. We do not certify compliance — we can assess against a standard and tell you where you stand, but a certificate comes from an accredited body, not from us.
If the right answer to your problem is an enterprise IT security firm, or a functional-safety consultancy, or your inverter vendor's own engineering team, we will tell you that early rather than scoping around it.
Not sure which of these you need?
Describe the system. Working out the right scope is part of the first conversation, not something you have to arrive with.