Secure by Design
Good design saves time and money. Greenfield is the one moment when security is cheap.
A control drawn on the design is a line on a diagram. The same control retrofitted into a running plant is an outage, a change window and a vendor variation.
Secure by Design turns the design and commissioning phase into a durable, structured record of the site: its zone-and-conduit architecture, every system and version deployed, and the boundaries between them. The Site Journal is built at design time with the EPC and OEMs, and then integrated into all ongoing operational security and compliance.
Governance reads its scope from it. Risk reads its crown jewels from it. Operations defends against what it knows is actually there.
Secure by design is security built for life.
Design and validate before build
- Zones and conduits defined against the Purdue reference model, with protocol and flow directions
- Every product, vendor, model and version allocated into security zones
- Physical hardware racking, network design and cabling output to D&C fidelity
Savings from security in-depth
- No annual rediscovery of your estate and usable by third-party advisors and assessors
- Security designed in avoids emergency retrofits, unplanned outages and manual remedies
- Change controlled and routinely checked, so drift is visible and remediated
Stream modules
Site Journal
The single structured record of the site, built once at design and inherited by every other module.
- Zone-and-conduit architecture recorded against the Purdue reference model
- Every system, product and software version deployed, held per site
- Security boundaries, with the protocol and direction of flow across each
- Built with the EPC and OEMs during design and commissioning
- Change-controlled against a baseline, so drift is visible and remediated
- One source of truth that governance, risk and operations all read from
- add feature
Asset Register
A live inventory of everything deployed on the site, allocated into security zones.
- Every product, vendor, model and version on the plant
- Sub-components, libraries and firmware where known (SBOM-aware)
- Each asset allocated to a security zone
- Kept current through change control, not annual rediscovery
- Usable by third-party advisors and assessors without re-scoping
- add feature
Site Designer
Zone-and-conduit modelling and target security levels, from drawings — before the plant is built.
- Define zones and conduits from drawings and specifications, pre-build
- Assign a target security level (SL-T) to each zone
- Record protocol and direction of flow per conduit
- Renewables reference architectures for wind, solar, BESS and DER
- Physical hardware racking, network design and cabling to D&C fidelity
- Validate the design against threat, continuity and recovery scenarios
- add feature
Where automatic discovery falls short
Discovery-based platforms derive their model from observed traffic. That means the model is only as complete as your ability to observe every zone — and the better segmented the plant, the more collection points you need.
Greenfield design for electric projects is deterministic, known from the outset, and changed managed to ensure there is no drift in software and configurations.