Services

Engineering for facilities that cannot fail.

Security engineering for operational technology, from the first drawing to decades of operation. Every engagement is scoped to the facility's country, sector and type, its supply chain, and the pressures acting on it from outside.

What we do

Seven ways to engage

Each service applies IEC 62443, the international series for the security of industrial automation and control systems, at a different moment in the life of a facility or a product.

Transactions

Acquisition Facility Diligence

What is really running, before you sign.

  • A full as-is model of the facility in two weeks, from passive collection and the documents in the data room
  • IEC 62443 risk assessment: the worst case first, then a detailed assessment against target security levels
  • Findings ranked by what they change in the deal: price, conditions on the seller, and the cost of connecting the site to your network
How it works
New build

New construction

Security specified with the design, not added after commissioning.

  • Security requirements and target security levels written into the specification (IEC 62443-3-3)
  • Zones, conduits and requirements for integrators and suppliers (IEC 62443-2-4 and 62443-4-2)
  • Factory and site acceptance testing of the security functions before handover
How it works
Brownfield

Refits and upgrades

Upgrading a running plant without stopping it, and without leaving it exposed while the work is under way.

  • A baseline of what is actually installed and connected
  • Segmentation and compensating controls for equipment that cannot be patched
  • Led from experience as lead engineer, CISO and program manager on large capital DCS upgrade projects
How it works
Compliance

IEC 62443 engineering compliance, full integration

The whole series applied as one programme, from the asset owner's policies to the components on the floor.

  • The asset owner's security programme (IEC 62443-2-1)
  • Risk assessment, zones, conduits and target security levels (IEC 62443-3-2)
  • Verification of system and component requirements (IEC 62443-3-3 and 62443-4-2) and of service providers (IEC 62443-2-4)
How it works
Technical authority

Lead engineer

One accountable engineer on the owner's side, across designers, integrators and contractors.

  • Technical authority for OT security through design, build and acceptance
  • Design reviews, test witnessing and sign-off
  • The role held as lead IEC 62443 engineer on New Zealand's City Rail Link
How it works
Continuous

Continuous digital twin assessment

A cyber-physical model of the facility, kept current with its own telemetry and with the law that applies to it.

  • A facility model built on the eight-layer cyber-physical digital twin
  • Telemetry from the facility's own systems, compared against the model (in development)
  • The compliance position traced to the researched record for the facility's country, with each fact's evidence level
How it works
Product

CRA conformance

For manufacturers of industrial and OT products sold into the EU: the most likely route to conformity with the Cyber Resilience Act, and the work to get there.

  • Classification of the product and its conformity route, including whether a notified body is needed
  • Annex I requirements traced to IEC 62443-4-1 and IEC 62443-4-2 through Eigenia's Requirements Traceability Matrix
  • Vulnerability handling, Article 14 reporting, SBOM and support period, with the obligations per market
How it works

Scoping

Every engagement starts from five facts

The same control system faces different obligations and different threats in Rotterdam and in Riyadh. These five facts set the scope, the applicable law and the evidence the work has to produce.

  1. 01

    Location

    The country sets the law: cybersecurity and critical infrastructure statutes, incident reporting deadlines, and the authorities the operator answers to.

  2. 02

    Sector

    Energy, water, transport and the other regulated sectors carry sector rules on top of national law.

  3. 03

    Facility type

    A substation, a port terminal and a datacenter have different control systems, safety cases and failure modes.

  4. 04

    Supply chain and value chain

    Who built and maintains the systems, where the components come from, and who depends on what the facility produces.

  5. 05

    External pressures

    Threat activity against the sector, geopolitical exposure, grid and climate stress, and disruption in the supply chain.

Check a location

Choose a country, sector and facility type to see the regulatory baseline an engagement starts from. Every item links to its source.

Choose a country or territory to see its regulatory baseline.

Selected engagements

Two decades in the field

The engagements behind these services, as listed on the About page.

Public transit
Lead IEC 62443 engineer on New Zealand's City Rail Link · network, wireless, CCTV, building management and physical access for new stations and tunnels
Railroad
Segmented OT architectures and Positive Train Control programs for North American Class I freight railroads · field operations bridged to enterprise systems
Nuclear energy
Security architecture and cyber-physical patterns for a nuclear installation · where the safety case is everything and the margin for error is zero
Hyperscale datacenters
Cyber-physical risk models for high-density AI compute halls · the liquid-cooling loops, power trains and thermal limits where a control fault becomes a physical loss · the actuarial case a board can act on
Energy & grid
Australia: grid stability and battery energy storage (BESS) · Deep Fission nuclear installation, Australia
Netherlands
Four years with Fox IT across industrial, port, energy and logistics clients
Manufacturing
A manufacturing center of excellence · digital transformation for MES (manufacturing execution systems)
Logistics & warehousing
Warehouse and logistics digital transformation · 3PL and 4PL integration

Enquire

Tell us about the facility

The scope you chose above is attached to the message. Enquiries go to jim@eigenia.nl.

Scope attached

No scope chosen. You can choose one above, or describe it in your message.

This Site Uses No Cookies

Eigenia does not set cookies. The only thing stored in your browser is one preference, saved in local storage, noting that you have seen this notice.