Professional Services & Managed Operations

Specialized cybersecurity services for high-voltage infrastructure.

Technology alone cannot defend complex physical assets. Battery Cyber delivers end-to-end engineering, advisory, and 24/7 managed operational services designed specifically for power engineers, asset owners, and OT security leaders.

Scope an engagement View service offerings
SERVICE 01

Security Assessment

Rigorous, non-disruptive cyber-physical risk evaluation across architecture, protocols, and vendor trust chains.

Scope of Evaluation

Our senior OT security specialists conduct in-depth architectural and on-site reviews without disrupting live power generation or battery cycling. We inspect the real-world convergence of digital networks and electrical safety controls.

  • Architecture & Trust Boundaries: Purdue model segmentation, firewalls, VLAN tagging, and industrial DMZ efficacy.
  • Remote Access & Gateways: Cellular modems, OEM support tunnels, satellite backhauls, and VPN configurations.
  • Industrial Protocol Security: Unauthenticated Modbus TCP, DNP3, IEC 61850, and CAN bus vulnerability analysis.
  • Firmware & Hardware Integrity: Controller build hashes, default credentials, exposed JTAG/UART debugging ports.
  • Operational Recovery: Cold-start procedures, backup integrity, and manual override feasibility during cyber failure.

Tangible Customer Deliverables

Every assessment produces engineering-grade documentation ready for executive leadership, insurers, and site operations:

• Verified Asset Inventory Complete hardware, firmware, and IP/MAC mapping
• As-Built Architecture Map Detailed OT network topology & trust boundary diagram
• Attack-Path Analysis Reachability modeling from external to high-voltage controls
• Prioritized Remediation Plan Costed, sequenced engineering backlog with operational workarounds
• Executive & Board Summary Clear, unvarnished risk posture benchmarking against IEC 62443 / NIST SP 800-82
SERVICE 02 • HIGH IMPACT

Secure Commissioning (FAT / SAT)

Cybersecurity integrated into the capital project lifecycle. Validate security before the asset energizes and connects to the grid.

STAGE 01

FAT (Factory Acceptance)

Auditing OEM battery container assemblies, inverter skid controllers, and switchgear PLCs at the factory floor before shipping. Ensuring factory default passwords are eliminated, firmware hashes match vendor baselines, and debug interfaces are permanently disabled.

STAGE 02

SAT (Site Acceptance)

Validating site network cabling, managed switch configurations, firewall rulebases, and cellular gateway provisioning during field installation. Ensuring EPC contractors adhere to contractual cybersecurity specifications prior to energization.

STAGE 03

Handover & Baselining

Establishing cryptographic golden baselines for all controller configurations, verifying remote access approval workflows, and generating clean operational handover documentation for the permanent asset owner.

SERVICE 03

Managed Security Operations

Continuous 24/7 operational cybersecurity monitoring delivered by industrial control system defense specialists.

24/7 OT Telemetry & Protocol Triage

Our Security Operations Center actively monitors passive site telemetry, industrial protocol flows, and gateway communication. Every alert is triaged by engineers who understand the difference between an inverter recalibration routine and an adversary manipulating Modbus coils.

• Zero false alarm fatigue • Protocol-aware triage

Real-Time Configuration Drift Tracking

Continuous tracking of controller setpoints, PLC logic builds, and firewall access lists. Immediate escalation whenever an unauthorized change occurs outside scheduled maintenance windows.

• Baseline integrity • Instant change notification

Vendor Session Governance & Supervision

Active supervision of third-party remote maintenance sessions. Our team validates work orders, facilitates just-in-time access approvals, and maintains forensic session records.

• Third-party accountability • Real-time session oversight

Quarterly Threat & Architecture Reviews

Regular executive briefings evaluating emerging threat actor tactics against power infrastructure, newly disclosed ICS vulnerabilities, and recommendations for continuous defensive hardening.

• Strategic advisory • Executive governance
SERVICE 04

Cyber Maintenance Program

Proactive lifecycle hygiene: firmware reviews, coordinated patching windows, and backup validation.

Firmware & Patch Governance

Evaluating OEM firmware updates in lab environments before production deployment. We schedule and supervise coordinated patch windows that align with grid dispatch outages.

Backup & Cold-Start Validation

Verifying that PLC logic backups, HMI project files, and inverter parameter tables are intact, stored off-site, and capable of restoring site operations during a ransomware event.

Certificate & Key Lifecycle

Managing cryptographic certificate lifecycles for edge gateways, internal VPN concentrators, and mTLS endpoints to prevent unplanned operational outages caused by expired certificates.

SERVICE 05

Incident Readiness & Response

Contain cyber incidents without unnecessarily disrupting power operations or tripping critical loads.

Power-Specific Tabletop Exercises

Scenario-based tabletop simulations testing C-suite, legal, OT engineering, and field operations on complex scenarios: ransomware in the EMS, rogue inverter firmware, or compromised OEM credentials.

Operational Containment Playbooks

Pre-approved incident playbooks designed to isolate compromised digital controllers while maintaining autonomous hardware protection, emergency cooling, and grid synchronization.

Emergency Retainer & Forensics

Guaranteed SLA response from senior industrial incident responders to preserve cryptographic evidence, perform memory forensics on embedded controllers, and safely guide system recovery.

Discuss a services engagement with our engineering leadership.

From pre-energization testing on a 200 MW BESS to enterprise-wide data center power security assessments.

Discuss an environment