Skip to main content

Infrastructure hardening: use cases

The systems that keep a country running are now the front line, and most of them run on control networks that were never built to be attacked. The Cybersecurity Group provides OT-native security for SCADA and industrial control systems, environments where downtime means blackouts, spills or settlement failures, with deep coverage of the IEC 61850, Modbus and DNP3 protocols and zero tolerance for false positives on air-gapped networks. Hardening is the work of shrinking the attack surface rather than only watching it: monitoring platforms tell an operator what is on the network and what looks wrong, while hardening changes the thing that was wrong. Its research has surfaced zero-days at gigawatt scale and holds entries on the US NIST register, its substation-security technology for IEC 61850 environments is government-lab validated and live-deployed, and it has defended over 3 GW of generation and secured 7.5 billion financial accounts.

Where it is used

01
Starting on an old, undocumented estate

Much of the installed control base is decades old, was never designed for hostile networks, and is documented, if at all, by the foreign vendors who built it. A hardening programme therefore begins by assessing the estate as it actually is rather than as the drawings claim, then prioritises reduction of exposure, segments control networks from corporate ones so a business-network intrusion cannot reach the plant, and verifies that the fixes hold. Doing that work with the operators who run the systems keeps the resulting detailed map of the estate in national hands instead of with a foreign vendor, which is where a control-system map otherwise quietly ends up.

02
OT that cannot be taken offline

SCADA and industrial control systems will not tolerate the downtime or the false positives that IT security takes for granted, which is why applying enterprise patterns to them misses the point. Passive monitoring works anywhere a switch can be spanned, so every credible vendor leads with it; what breaks in isolated environments is the cloud dependency that a hosted platform assumes. The brief here specifically covers air-gapped networks with zero tolerance for false positives, because in a substation or a payments switch acting on a bad alert can trip generation or stop settlement. Air-gap operation and the signature-update path both belong in a tender as written requirements rather than assumptions.

03
Substations and protocol coverage

Substations are where the IT-security playbook fails most visibly, because the protocols are real-time and the equipment predates the threat model. Substation-security technology built for IEC 61850 environments, validated by a government laboratory and live-deployed rather than piloted, sits alongside zero-day discovery credited on the US NIST register. Protocol coverage runs to IEC 61850, Modbus and DNP3 including air-gapped networks, and the honest procurement step is to give every bidder the operator's own protocol inventory and make them answer against it line by line, then ask which of those protocols each supplier's researchers have personally broken rather than merely listed.

04
Hardening does not replace monitoring

Hardening reduces what an attacker can reach; monitoring and response deal with what still gets through, so the two are complements rather than alternatives. Many operators run a detection platform alongside a hardening programme rather than choosing between them, and the defensive practice here runs alongside the hardening work with security operations blocking more than 100,000 threats a day across grids, regulated finance and fleets at sea. Priced against an OT monitoring subscription, hardening is scoped engineering work with a defined end state rather than a cost that recurs and scales with sites and assets, so the fair comparison is total programme cost over five years including any hosting and data-residency terms.

05
One programme across several estates

Grids and payment systems fail differently, yet the discipline underneath them is closer than most buyers expect: both are real-time, both are unforgiving of downtime, and both are defended by too few people. The practice covers power and energy, financial infrastructure, industrial control systems and national infrastructure from one team, and it extends to the OT behind ports where terminal control systems matter as much as grid ones. Because it is OT-native and delivered through one accountable channel, a state can harden several critical estates under a single line of accountability rather than several foreign vendors, and it is worth asking which named engineers actually work across both the grid and the payment side.

06
One resilience programme, cyber and physical

Offensive assessment against the control estate finds the weaknesses, hardening reduces the exposure they reveal, and defensive operations watch what remains around the clock, so running the three through one accountable channel means each stage informs the next rather than arriving as disconnected contracts. The programme also pairs cyber hardening with non-destructive inspection that certifies the physical estate: hardening shrinks the attack surface of the control systems while inspection verifies the structures they run. Where this reference carries no audited figures, the capability should be judged on method, OT-native assessment, a prioritised roadmap, segmentation and verification, executed with the operator's own people and leaving no foreign disclosure line on what is found.

Infrastructure hardening

Part of these mission applications

Contact us

Tell us the requirement. Specifications and the export position are confirmed in briefing, not published here.