Who we work with

Critical Infrastructure & Utilities

Critical infrastructure operators moved from voluntary guidance to enforceable obligation faster than most of their IT environments did.

The regulatory change is the visible part: obligations with reporting timeframes attached, and a requirement to demonstrate a risk management program rather than describe one. The operational reality underneath it moved more slowly. Field devices are the interface to operational systems, remote sites have connectivity that comes and goes, and the recovery plan has usually been tested on paper.

The exposure that gets missed is the boundary between corporate IT and operations. The handset a technician uses to authenticate, receive work and photograph an asset sits on the corporate side of the line and reaches across it. It is rarely in scope for either team.

Continuity is the other half. An incident response plan is worth what its last restore test proved, and the gap between a backup job reporting success and a restore actually completing inside the required window is where most plans fail.

Where the work goes

What we focus on in this sector

Scope is agreed per engagement. These are the areas that consistently carry the most value here.

01

Field endpoints in scope

The devices technicians carry treated as part of the security boundary — managed, monitored and able to lose access automatically when they fall out of policy.

02

Detection that works remote

On-device threat detection that keeps working at sites with no reliable connectivity, and reports when the link returns.

03

Tested recovery, not tested backups

Restores performed and timed against the recovery objectives you have committed to, with the evidence retained.

04

Evidence for the obligation

Reporting that supports the risk management program you have to demonstrate, produced continuously rather than assembled before an audit.

05

Controlled site connectivity

Networks at remote and unattended sites designed for the conditions rather than inherited from an office template.

Outcomes

What changes once it is running properly

  • Field devices inside the security boundary rather than beside it
  • A recovery time you have measured instead of estimated
  • Continuous evidence for the regulatory obligation
  • Detection that does not depend on the site having a link
Services

What usually applies

A few of the organisations we have delivered for

Department of Defence
Department of Defence
Royal Australian Air Force
Royal Australian Air Force
Department of the Prime Minister and Cabinet
Department of the Prime Minister and Cabinet
Department of Foreign Affairs and Trade
Department of Foreign Affairs and Trade
Department of Home Affairs
Department of Home Affairs
Attorney-General’s Department
Attorney-General’s Department
Parliament of Australia
Parliament of Australia
Parliament of New South Wales
Parliament of New South Wales

Common questions

Do you work with operational technology environments?

We work on the IT side of the boundary — the corporate endpoints, identity and connectivity that reach into operations — and we work alongside OT specialists rather than claiming that ground. The handset a technician uses is frequently the least-governed link in that chain, and it is squarely ours.

What does a real restore test involve?

Restoring actual data to a usable state, timed, and comparing that time to the recovery objective you have committed to. A backup job reporting success is not evidence of anything except that the job ran.

Can reporting be aligned to our regulatory obligations?

Yes. The reporting is built from the same operational data either way — the work is in mapping it to the obligation you carry, so it can be produced on a schedule instead of reconstructed under deadline.

Next step

Talk to us about Critical Infrastructure & Utilities

Tell us what the environment looks like today. We will tell you honestly whether this is the right place to start.