Live environments, planned outages, and new builds — here’s what that looks like in practice.
Tell us about your environment. We’ll come to you, on site, in the field and build a security program that works around your operational reality, not against it.
Before we arrived, the documented OT network didn’t match the real one. Flat legacy segments and ad‑hoc comms links had created undocumented paths into core control systems — BMCS, Fire, Electrical, Lighting and other station systems, and the SCADA layer above them.
“The risk wasn’t hypothetical. Any one of those undocumented paths was a potential entry point into systems controlling physical infrastructure used by thousands of people every day.”
We engineered security zone architecture aligned with IEC 62443, then implemented it site by site during tightly controlled night works windows. Every cutover plan was sequenced down to the individual device, with immediate rollback available at each step. Nothing moved to production until it had been validated on live traffic by dedicated OT IDS and signed off by operations.
The outcome: a consistent, enforced OT security architecture across the entire network. OT traffic monitored by industrial IDS at every site. Firewalls enforcing defined security zones and conduits. Devices re‑addressed into structured VLANs that match reality on the ground — and zero unplanned operational disruption across the entire program.
11+ live sites, consistent zone and conduit architecture.
Industrial IDS monitoring safety‑critical OT at every location.
Structured OT addressing and VLAN segmentation for simpler operations and incident response.
Tell us about your environment. We’ll come to you, on site, in the field and build a security program that works around your operational reality, not against it.
70+ FortiGate firewalls programmed, tested and staged for operational cutover.
140+ OT IDS sensors configured for real‑time traffic and asset visibility across all SCADA sites.
Coordinated delivery with incumbent, with configurations validated and ready for zero‑disruption cutover.
When we started, the utility needed to replace ageing SCADA firewalls across 70+ operational water and wastewater sites — without disrupting the control systems that keep water flowing for a major Australian city. Legacy firewall infrastructure couldn’t support modern threat detection, and the absence of OT network visibility made it difficult to spot anomalous behaviour across distributed SCADA environments.
“Any firewall that’s past its design life, protecting live SCADA, is a risk you can’t fully quantify. You only see the gaps when you start looking — so the first step is safe visibility.”
We programmed and staged Firewall replacements for every SCADA site, with each configuration validated and ready for cutover. Working in close partnership with the clients incumbent project management framework, we sequenced changes site by site.
Alongside the firewall program, we deployed OT IDS sensors — two per site — to deliver real‑time network traffic monitoring and asset visibility across the entire SCADA estate. The result is a cutover‑ready perimeter upgrade with deep OT insight: firewalls programmed, tested and staged; sensors in place; and the utility able to move into operational cutover without guessing about what’s on the network.
Share your environment details. We’ll come on‑site to design a security program that fits your operations, not fights them.