Meridian's operational technology security practice has been certified against IEC 62443-2-4, the standard covering security programme requirements for industrial automation service providers. The audit was completed in February and covers our San Francisco, Rotterdam and Singapore operations.
Certification matters here for a practical reason. Asset owners in regulated sectors are increasingly required to evidence the security posture of their suppliers, not only their own. Where that obligation exists, an audited certificate removes a step from the procurement process.
What was assessed
The audit examined our staffing and competency records, the security controls applied to our own engineering environments, how we handle client credentials and remote access, and the procedures governing changes to live control systems. Two minor findings were raised, both relating to record retention periods, and both were closed before the certificate was issued.
Existing clients
No action is required from existing clients. The certificate and the summary audit report are available from your lead engineer on request, and we can provide them directly to your procurement or compliance function.