Projects

We secure critical infrastructure while it’s running, and when it isn’t.

Live environments, planned outages, and new builds — here’s what that looks like in practice.

2k+

OT Firewall rules engineered

5k+

OT assets brought under monitoring

1k+

Network segments designed for OT

100+

Critical Sites Secured

Securing a thirty-station rail network without stopping a single train.

Tell us about your environment. We’ll come to you, on site, in the field and build a security program that works around your operational reality, not against it.

A large‑scale OT environment across more than ten metropolitan transport sites. Mixed greenfield and brownfield assets. Safety‑critical systems operating 24/7. Maintenance windows measured in hours, not days

Before we arrived, the documented OT network didn’t match the real one. Flat legacy segments and ad‑hoc comms links had created undocumented paths into core control systems — BMCS, Fire, Electrical, Lighting and other station systems, and the SCADA layer above them.

“The risk wasn’t hypothetical. Any one of those undocumented paths was a potential entry point into systems controlling physical infrastructure used by thousands of people every day.”

We engineered security zone architecture aligned with IEC 62443, then implemented it site by site during tightly controlled night works windows. Every cutover plan was sequenced down to the individual device, with immediate rollback available at each step. Nothing moved to production until it had been validated on live traffic by dedicated OT IDS and signed off by operations.

The outcome: a consistent, enforced OT security architecture across the entire network. OT traffic monitored by industrial IDS at every site. Firewalls enforcing defined security zones and conduits. Devices re‑addressed into structured VLANs that match reality on the ground — and zero unplanned operational disruption across the entire program.

What we delivered
  • OT network segmentation

    11+ live sites, consistent zone and conduit architecture.

  • OT traffic visibility

    Industrial IDS monitoring safety‑critical OT at every location.

  • Addressing and VLAN uplift

    Structured OT addressing and VLAN segmentation for simpler operations and incident response.

Frameworks

From ageing SCADA firewalls to a cutover‑ready, monitored water network.

Tell us about your environment. We’ll come to you, on site, in the field and build a security program that works around your operational reality, not against it.

What we delivered
  • SCADA firewall uplift

    70+ FortiGate firewalls programmed, tested and staged for operational cutover.

  • OT network visibility

    140+ OT IDS sensors configured for real‑time traffic and asset visibility across all SCADA sites.

  • Cutover‑ready deployment

    Coordinated delivery with incumbent, with configurations validated and ready for zero‑disruption cutover.

Frameworks

A major water and wastewater provider supporting a metropolitan Australian water supply. Distributed SCADA assets across more than seventy treatment plants, pump stations and remote sites. Ageing perimeter firewalls, limited OT network visibility.

When we started, the utility needed to replace ageing SCADA firewalls across 70+ operational water and wastewater sites — without disrupting the control systems that keep water flowing for a major Australian city. Legacy firewall infrastructure couldn’t support modern threat detection, and the absence of OT network visibility made it difficult to spot anomalous behaviour across distributed SCADA environments.

“Any firewall that’s past its design life, protecting live SCADA, is a risk you can’t fully quantify. You only see the gaps when you start looking — so the first step is safe visibility.”

We programmed and staged Firewall replacements for every SCADA site, with each configuration validated and ready for cutover. Working in close partnership with the clients incumbent project management framework, we sequenced changes site by site.

Alongside the firewall program, we deployed OT IDS sensors — two per site — to deliver real‑time network traffic monitoring and asset visibility across the entire SCADA estate. The result is a cutover‑ready perimeter upgrade with deep OT insight: firewalls programmed, tested and staged; sensors in place; and the utility able to move into operational cutover without guessing about what’s on the network.

get in touch

Ready to strengthen your OT security posture?

Share your environment details. We’ll come on‑site to design a security program that fits your operations, not fights them.