Procurement & Operational Deliverables
What remains with the customer.
Battery Cyber does not deliver abstract risk scores or ephemeral consulting slides. Every engagement produces tangible, engineering-grade operational assets that permanently harden the facility, satisfy regulatory scrutiny, and remain under customer ownership.
The Engineering Dossier
10 Permanent Operational Deliverables
Every Battery Cyber assessment, commissioning engagement, and managed deployment equips your engineering and security teams with verified documentation and tooling:
Verified Asset & Protocol Inventory
A granular, non-intrusively generated inventory of every digital component in the power train: controller make/model, serial numbers, installed firmware hashes, MAC/IP mappings, active listening ports, and observed industrial protocol communications.
• Format: Machine-readable JSON/CSV & interactive asset registerAs-Built OT Architecture Map
Detailed engineering schematics documenting physical and logical network boundaries across the Purdue Enterprise Reference Model: Level 0/1 sensor buses, Level 2 controller networks, Level 3 supervisory networks, industrial DMZs, and external gateway interfaces.
• Format: Vector schematics (SVG/PDF/Visio) & trust boundary mapsRemote-Access & Vendor Register
A definitive register of all external inbound and outbound paths: cellular modems, satellite links, OEM warranty diagnostic tunnels, and cloud telemetry connections, paired with specific vendor ownership and contract alignment.
• Format: Living vendor access matrix with credential expiration policiesPrioritized Engineering Remediation Backlog
An operational action plan categorized by engineering priority, safety consequence, and dispatch risk. Each finding includes specific configuration adjustments, firewall ACL rules, and compensating controls that avoid tripping active processes.
• Format: Jira/ServiceNow-ready tasks & executive remediation roadmapCryptographic Golden Baselines
Cryptographically signed snapshots of verified PLC logic binaries, inverter operating parameters, and EMS setpoints. Provides an unalterable benchmark against which future configuration drift or malicious tampering is instantly identified.
• Format: SHA-256 signature manifests & baseline parameter archivesCold-Start Cyber Recovery Procedure
Step-by-step technical recovery manual enabling site engineers to safely restore control network communications, reload verified controller logic, and re-energize battery blocks following a severe malware or ransomware event.
• Format: Laminated control room standard operating procedure (SOP)RACI Ownership & Governance Model
Clear organizational matrix defining responsibilities across enterprise IT security, plant operations, OEM service managers, and field EPC teams, resolving operational ambiguity before an emergency occurs.
• Format: Enterprise governance matrix & communication hierarchyOperational Incident Containment Playbooks
Pre-approved incident response workflows tailored to critical-power failure modes: isolating compromised remote gateways, safely decoupling market dispatch interfaces, and maintaining local battery cooling during an active cyber attack.
• Format: Scenario-based operational playbooksAssurance & Standards Mapping Evidence
Detailed technical evidence dossiers mapping site controls and test results against international standards: IEC 62443, NIST SP 800-82, NERC CIP, and DOE C2M2 for presentation to regulatory auditors and insurers.
• Format: Audit-ready compliance matrix & evidentiary appendicesDynamic Operational Risk Register
A living quantification of physical and financial risk, balancing cyber exposure against potential power curtailment penalties, battery replacement costs, and grid code compliance liability.
• Format: Board-level executive risk dashboardEnterprise Procurement
Built for procurement teams, insurers, and engineers.
Contact our team to review sample deliverable templates, redacted assessment reports, or discuss an upcoming project scope.
Discuss an environment