An adversary does not need to cross your border to switch off your water.
Power, water, transport and port systems assessed, hardened and watched continuously, by a team with no foreign government to report the findings to.
The systems that keep a country running are now a strategic target, and the attacker does not need to cross a border to reach them. The control networks behind power and water were built for reliability, not for a fight, and many cannot be taken offline to patch. The physical structures they sit on age and crack. Protecting the whole estate means shrinking the cyber attack surface, verifying that the steel and concrete are sound, and defending continuously, including when the network the systems normally rely on is gone.
The Cybersecurity Group's infrastructure hardening assesses and hardens the OT and SCADA systems that cannot simply be rebooted, and its defensive cybersecurity watches them around the clock with incident response already live in power grids, regulated finance and fleets at sea. For isolated and air-gapped sites, the off-grid architectures keep protection in place when connectivity fails, and maritime cybersecurity carries the same discipline into ports and the ships that use them. The NDT Systems House's non-destructive testing verifies the physical estate, using radiography and computed tomography to confirm structural integrity without disassembly. One accountable team holds all of it, with no major-power disclosure obligations, so the map of a nation's weak points does not leave the nation. The outcome is services that stay up under deliberate pressure and an estate whose condition is documented rather than assumed.
Capabilities that solve this
An adversary does not need to cross your border to switch off your water.: questions
Which Unstrat capabilities address "An adversary does not need to cross your border to switch off your water."?
Unstrat brings together Infrastructure hardening, Defensive cybersecurity, Off-grid cybersecurity, Maritime Cybersecurity and Non-destructive testing. The Cybersecurity Group's infrastructure hardening assesses and hardens the OT and SCADA systems that cannot simply be rebooted, and its defensive cybersecurity watches them around the clock with incident response already live in power grids, regulated finance and fleets at sea. For isolated and air-gapped sites, the off-grid architectures keep protection in place when connectivity fails, and maritime cybersecurity carries the same discipline into ports and the ships that use them. The NDT Systems House's non-destructive testing verifies the physical estate, using radiography and computed tomography to confirm structural integrity without disassembly. One accountable team holds all of it, with no major-power disclosure obligations, so the map of a nation's weak points does not leave the nation. The outcome is services that stay up under deliberate pressure and an estate whose condition is documented rather than assumed.
What problem does this solution solve?
The systems that keep a country running are now a strategic target, and the attacker does not need to cross a border to reach them. The control networks behind power and water were built for reliability, not for a fight, and many cannot be taken offline to patch. The physical structures they sit on age and crack. Protecting the whole estate means shrinking the cyber attack surface, verifying that the steel and concrete are sound, and defending continuously, including when the network the systems normally rely on is gone. Power, water, transport and port systems assessed, hardened and watched continuously, by a team with no foreign government to report the findings to.
Can "An adversary does not need to cross your border to switch off your water." be procured as one programme rather than several suppliers?
Yes. Rather than integrating several foreign primes yourself, you acquire Infrastructure hardening, Defensive cybersecurity, Off-grid cybersecurity, Maritime Cybersecurity and Non-destructive testing through one accountable channel, a single team responsible from first briefing through delivery and in-region sustainment. Each capability is sourced from an independent, non-aligned manufacturer, so the programme carries no major-power disclosure rules or political ramifications.
Questions buyers ask
What is critical infrastructure resilience?
It is the discipline of keeping power, water, transport and ports running when they are attacked, from both the control networks behind them and the physical structures they depend on. It means shrinking the attack surface, defending it continuously and verifying that the physical estate is sound. We deliver that as one accountable programme with no foreign government to report the findings to.
See: Infrastructure hardening capabilityOT security capability
Why is OT security different from IT security?
In operational technology a compromise opens a valve or trips a grid rather than corrupting a file, so the consequences are blackouts and closed ports, not lost documents. Much of the installed control base is decades old and was never designed for a hostile network. That is why we treat OT as its own discipline, with assessment, segmentation and monitoring built for control systems rather than office ones.
How do you protect infrastructure that runs off the grid?
The most critical systems are often the ones that cannot phone home to a security cloud: isolated sites, air-gapped enclaves and remote installations. We architect protection for disconnection, with local detection and response and procedures the on-site team can run alone. Everything stays inside your environment rather than sending telemetry to foreign infrastructure.
See: Off-grid cybersecurity capabilityAir-gapped against connected security
Critical infrastructure defence where findings never reach a foreign government
That requirement is the reason this solution exists as a non-aligned build. When protection is outsourced to a foreign-cloud provider, that provider often sees your incidents first and can carry obligations about what it does with the knowledge. Our engagement keeps assessment, monitoring and findings accountable to you alone, across the cyber and physical estate.
See: Defensive cybersecurity capabilityDefensive cybersecurity in the catalogue
Hardening ageing control systems that a foreign vendor still documents
Ageing control systems are often mapped, if at all, only by the foreign vendors who built them, which is a dependency and a risk at once. Hardening is methodical: assess the estate as it actually is, reduce exposure in priority order, segment control from corporate networks and verify the fixes hold. The estate knowledge stays with you rather than with a foreign prime.
See: Infrastructure hardening capabilityInfrastructure hardening in the catalogue
One programme for cyber defence and physical inspection of national infrastructure
Resilience is both a cyber and a structural question, so this solution runs both through one channel. Hardening and continuous defence reduce and watch the cyber attack surface, while non-destructive testing verifies the physical estate without disassembly. One accountable team covers both, rather than leaving the seam between them to two suppliers who each assume the other has it.
See: Non-destructive testing capabilityResilience and civil security solution
Continuous defensive operations for a national grid rather than a one-off audit
An audit is a snapshot; an adversary works continuously, so the defence has to as well. Defensive cybersecurity here is an operations discipline: monitoring across the estate, detection tuned to the threats that matter and response that contains an incident before it becomes a crisis. It can be delivered as a service or built into a national security-operations capability, staged to your staffing reality.
See: Defensive cybersecurity capabilityOffensive against defensive cybersecurity
Protecting ports and shipping as part of national infrastructure
A port can be closed by code as effectively as by blockade, and its operational technology is often decades old and never built for a hostile network. Maritime cyber protection covers vessels, terminals and the supply chain together, treating ships as floating industrial systems rather than office networks. It sits inside the same resilience programme as the grid and water estate.
See: Maritime cybersecurity capabilityMaritime cybersecurity in the catalogue
An adversary does not need to cross our border to switch off our water. How do we defend the systems that run the country?
The threat surface is the control networks behind power, water, transport and ports, plus the physical structures they sit on. We shrink and watch the cyber attack surface with hardening and continuous defence, keep isolated systems protected with architectures built for disconnection, and verify the physical estate with non-destructive inspection. It is one accountable team, with no major-power disclosure obligation attached.
See: Critical infrastructure resilience solutionOT security capability
Our utilities were built by foreign vendors who still hold the only map of them. How do we take back control?
The first move is to rebuild that map yourself: an OT-native assessment of the estate as it actually exists, so the control-system knowledge sits with you rather than a foreign service network. From there, hardening reduces exposure and segmentation limits what a single intrusion can reach. The estate knowledge, the findings and the fixes all stay inside your own organisation.
See: Infrastructure hardening capabilityIT against OT cybersecurity
How do we keep a classified or air-gapped site protected when it cannot reach a security cloud?
You architect for the disconnection instead of pretending it away. Off-grid cybersecurity uses local detection and response, integrity mechanisms that work over intermittent links, and procedures the site team can execute without outside help. Nothing depends on telemetry flowing to a foreign cloud, which is both a resilience choice and a disclosure one.
See: Off-grid cybersecurity capabilityOff-grid cybersecurity in the catalogue
What does a critical-infrastructure resilience programme cost, and can you quote a figure now?
We do not publish price bands, because the cost depends entirely on the size of the estate, its condition and how much of the defence you want run in-house. What we can say is the shape: assessment first, then prioritised hardening, then continuous operations and physical verification, staged to your budget and staffing. A number offered before that scoping would be a guess, and we will not invent one.
See: How we deliverCritical infrastructure resilience solution
How do we verify the physical estate, not just the networks, when much of it is ageing and undocumented?
Non-destructive testing inspects structures, components and stocks without disassembling or damaging them, using radiographic, computed-tomography and related methods. That lets you certify what you own rather than assume it is serviceable, and it can be procured as equipment, a service, or a transfer programme that builds a national inspection capability. The condition data stays with you rather than flowing through a foreign prime.
See: Non-destructive testing capabilityNon-destructive testing in the catalogue
Our OT and IT teams keep arguing over who owns infrastructure defence. How should the two actually be split?
The split matters because a compromise in operational technology opens a valve rather than corrupting a file, so it is a discipline of its own rather than IT security rebranded. We treat OT with native assessment, segmentation between control and corporate networks, and monitoring that understands industrial protocols. The comparison page lays out where the two disciplines differ so the ownership argument is settled on evidence rather than turf.
Is offensive testing worth commissioning on national infrastructure, and who sees the results?
Authorised adversarial testing finds the weaknesses before a real adversary does, and compliance-driven checks have repeatedly failed to predict real intrusions. The hesitation is trust: a foreign-aligned tester rehearsing attacks on your most sensitive systems learns exactly where the bodies are buried. We run it under scoped written authorisation, accountable to you alone, with findings that never travel further than you decide.
See: Offensive cybersecurity capabilityOffensive against defensive cybersecurity





