Design

Security Architecture & Design

Security designed into the plant before it is built.

On a new build or major expansion, security is cheapest and least disruptive to get right before procurement is locked and cable is pulled.

What This Engagement Covers

Retrofitting security into a plant that is already running is always harder, slower and more expensive than designing it in. On a greenfield project the constraints that make brownfield work difficult — no downtime, unpatchable equipment, vendor warranty restrictions — have not been created yet.

We work alongside your project and automation teams from specification through commissioning, so that the security architecture is part of what gets procured, built and accepted, rather than a set of findings raised after handover.

Included in Scope

Requirements & Specification

Security requirements written into the specification and tender documents, so obligations sit with the vendor before award rather than becoming your problem afterwards.

  • Security requirements defined for the project scope
  • Obligations written into tender and contract documents
  • Vendor responses reviewed against the specification

Zone & Conduit Design

A segmentation model aligned to the Purdue reference architecture, defining which systems may talk to which, and through what.

  • Zone and conduit model for the target architecture
  • IT/OT DMZ definition and data flow matrix
  • Remote access paths defined for vendors and integrators

Acceptance Testing

Security test cases built into factory and site acceptance testing, so problems surface while the vendor is still on the hook.

  • Security test cases added to FAT and SAT
  • Verification at commissioning
  • Documentation and drawings handed over to operations

Standards Applied

Work on this engagement is mapped to the standards below, alongside whichever Indian obligations apply to your sector.

IEC 62443Purdue ModelNIST SP 800-82

Common Questions

When in the project should we involve you?
As early as the specification is being written. The single highest-value moment is before tender, because that is when security obligations can still be placed on the vendor at no extra cost. Involving us at FAT is still useful, but by then the architecture is largely fixed and changes carry commercial consequences.
Our project has already started. Is it too late?
No, though the options narrow as the project progresses. If procurement is done, we focus on what can still be influenced: network design, DMZ and remote access, hardening, and building security cases into acceptance testing. We will be direct about which decisions are already locked.
Do you work alongside our automation vendor?
Yes. We are vendor-neutral, so our role is to define what the architecture must achieve and verify that what is delivered meets it. That works whether the plant is being built on Siemens, Rockwell, Schneider, ABB, Honeywell, Emerson or Yokogawa.

Part of a Wider Practice

This is one of five OT engagements

Design, assessment, implementation, monitoring and training. Most programmes combine several — see how they fit together.

Back to OT Cybersecurity Services

Ready to Modernize?

Schedule a deep-dive session with our senior architects to explore how we can accelerate your digital roadmap.

Book Consultation

Ready to scope this engagement?

Tell us about your environment and we will come back with a scope, not a brochure.